Guide

COPPA and Under-13 Messaging: When It Applies to a School Platform

COPPA is invoked constantly in edtech procurement and understood rarely. It is a rule about operators collecting personal information online from children under 13, and a great deal of what a district communications platform does falls outside it entirely — while a small and specific part of what some platforms do falls squarely inside. Knowing which is which saves a lot of misdirected questionnaire time.

Last reviewed 2026-08-04 ยท Kastr is pre-launch; we publish dated status rather than logos.

Does COPPA attach? Seven communications scenarios
ScenarioWho provides the dataCOPPA analysisWhat to ask the vendor
District pushes a roster of student names to the platformThe districtNot collection from a child; other frameworks governFERPA terms and the state statute, not COPPA
Guardian creates an account with their own detailsAn adultOutside the ruleNothing COPPA-specific
Under-13 student logs in and sends a messageThe childSquarely insideWhat is collected, retained, and on whose consent
Under-13 student's device identifier is logged on a family appThe child, passivelyPersistent identifiers countAnalytics SDKs, advertising identifiers, crash reporters
Student replies to a school SMS from a family phoneAmbiguousDepends on the surface and what is retainedWhether inbound content is stored and for how long
Photo of a child uploaded by a teacherAn adultNot collection from the child, but sensitiveStorage, sharing scope and deletion
Third-party advertising or analytics in a child-facing appThe child, via the third partyThe operator is responsible for itThe full list of SDKs in any family or student app

Column three is an orientation for scoping a procurement conversation, not a legal determination. The COPPA Rule has been amended and the FTC publishes current guidance and business compliance material; confirm the current requirements with counsel before relying on any of this.

The school consent route, and its conditions

The Federal Trade Commission's long-standing guidance has been that a school may provide consent on behalf of parents for an operator's collection of personal information from students, in the educational context, where the information is collected solely for the use and benefit of the school and for no other commercial purpose. That route is what makes most school edtech workable at all.

The conditions are what matter, and they are conditions on the vendor's conduct rather than on the district's paperwork:

  • Solely for the school's use and benefit. Product improvement, benchmarking against other districts, and model training are the three places this quietly breaks. Read the use-limitation clause.
  • No commercial purpose. No advertising, no selling, no family-facing upsell built on data collected from children.
  • The school must have enough information to make the decision. That means the vendor tells the district what is collected, how it is used, and what the retention and deletion positions are — before, not after.
  • Parents retain rights. A parent can ask to review what has been collected about their child and to have it deleted, routed through the school.

The FTC has amended the COPPA Rule and publishes updated business guidance; the direction of travel has been toward tighter limits on retention and on third-party disclosure. Confirm current requirements rather than relying on guidance summaries, including this one.

What to actually ask a communications vendor

Four questions resolve nearly all of it.

  1. “Does a student under 13 ever hold an account or a login on your platform?” If no, most of COPPA does not engage and the conversation moves to FERPA and your state statute. If yes, everything below matters.
  2. “List every third-party SDK, analytics tool and crash reporter in any app a child could use.” This is the question that finds real problems. Operators are responsible for what their embedded third parties collect, and advertising identifiers in a children's app are the classic finding.
  3. “What inbound content from students is retained, and for how long?” A reply from a student's phone is content, and content is retained by default in most systems.
  4. “Is there any advertising, recommendation or monetisation surface anywhere in the product?” Not “do you advertise to children” — any surface at all, including a free family tier with a paid upgrade.

Our answers: Kastr has no advertising, no recommendation system and no monetisation surface anywhere, and clause 9.4 makes that permanent rather than current. There is no push-notification infrastructure and no device-token registration, because we send SMS, email and voice only. We have no photo or video sharing and no attachment upload path at all, which removes an entire category of child-image handling risk by simply not having the feature. Students exist in the identity model as people with student roles, and the retention class for a student record is derived from that role at creation.

Where COPPA gets confused with things it is not

COPPA is not FERPA. Different statute, different regulator, different subject. FERPA is about education records held by the district. COPPA is about an operator collecting information online from a child. A vendor answering a FERPA question with a COPPA statement, or vice versa, has not understood the question.

COPPA is not a state student privacy statute. The SOPIPA-family statutes reach vendor conduct regardless of the child's age and regardless of who supplied the data. In most communications procurements those state statutes do more work than COPPA does.

“COPPA compliant” on a marketing page means very little on its own. The rule's requirements depend on what the operator collects and from whom. A platform that collects nothing from children is trivially compliant and should say so in those words rather than displaying a badge.

The under-13 question that actually bites in communications. It is not the student account. It is the family device. A parent-facing app installed on a shared household tablet, used by a nine-year-old, with an analytics SDK collecting persistent identifiers, is the scenario that has produced real enforcement interest in adjacent categories. If a vendor offers a family app, ask for the SDK list in writing. If they hesitate, that is the finding.

This page describes what a statute asks of a vendor. It is not legal advice, statutes are amended, and section numbering moves. Confirm the current text with your own counsel or your state education agency before you rely on any of it in a contract or a procurement file.

Questions people actually ask

Does COPPA apply to a school parent communication app?

Often not directly, because the data is supplied by the district and the accounts are held by adults. It engages where a child under 13 uses the service themselves, or where a child-facing surface collects persistent identifiers through embedded third parties. Scope the question by asking whether a child ever holds a login.

Can a school give consent on behalf of parents under COPPA?

FTC guidance has long supported a school consent route in the educational context, where information is collected solely for the use and benefit of the school and for no other commercial purpose. The conditions attach to the vendor's conduct, so read the use-limitation clause carefully and confirm current requirements with counsel.

What is the difference between COPPA and FERPA?

FERPA governs education records held by a district and the disclosure of information from them. COPPA governs operators collecting personal information online from children under 13. They overlap in edtech but answer different questions, and a vendor conflating them is a signal about the quality of the rest of their answers.

What should we ask about third-party SDKs in a family app?

Ask for the complete list, in writing, including analytics, crash reporting and any advertising identifiers, and ask what each collects. An operator is responsible for what embedded third parties do on a child-facing surface, and this is where the real findings are.

One price. Every feature. Locked for three years.

$3.50 per student per year under 5,000 students. No tiers, no add-on modules, no per-message fees. Published on the site because you should not have to book a call to learn a price.