← all articles

What a child's tablet is collecting

Hand a seven-year-old a tablet and the device starts generating data before they open a single app. The operating system logs boot events, the Wi-Fi radio announces itself to the router, and any account signed in during setup starts syncing. None of this requires the child to do anything except turn the thing on. The interesting part isn’t that a kid’s tablet collects data, almost every connected device does, it’s which layers are collecting, what they’re collecting for, and how much of it is visible to the parent who bought the thing.

The operating system is the first collector

Whether it’s a Fire tablet, an Android tablet running a kids’ launcher, or an iPad with Screen Time enabled, the base OS is doing telemetry before any third-party app gets involved.

On Android and Fire OS, this includes diagnostic data (crash logs, battery stats, app install and uninstall events) sent back to Google or Amazon, plus an advertising identifier attached to the device. That identifier, called the Google Advertising ID on Android or the Amazon Advertising ID on Fire OS, exists specifically so different apps on the same device can be tied to the same profile for ad targeting. A kids’ profile on a Fire tablet through Amazon Kids (formerly FreeTime) restricts content access, but the underlying device identifier and Amazon’s usage logging for that profile, what was watched, for how long, which titles were skipped, still feed Amazon’s recommendation systems.

Apple’s approach differs at the account level. If a child has an Apple ID managed through Family Sharing, Apple ties app purchases, iCloud backups, and Screen Time reports to that ID. Screen Time itself is a genuinely useful parental tool, but it works by generating a detailed log of app usage time, website visits in Safari, and content requests, and that log is visible to whichever account holds parental oversight, plus it’s stored somewhere (locally and in iCloud if sync is on).

None of this is unique to children’s devices. It’s the same telemetry an adult’s phone generates. The difference is that a child’s usage pattern, which apps, for how long, at what time of day, builds a fairly complete behavioral profile of a minor, and the child has no say in whether that logging happens.

Apps bundle in trackers you never see

This is where most of the actual exposure lives, and it’s largely invisible from the tablet’s home screen. Free kids’ games and “educational” apps commonly ship with third-party software development kits (SDKs) baked into the app binary, most often for advertising and analytics. Common ones in this category include ad networks like AppLovin, ironSource, and Unity Ads, and analytics platforms that track session length and in-app behavior.

Here’s the mechanism: when the app loads, these SDKs collect device-level signals, the advertising ID mentioned above, IP address, device model, OS version, and sometimes a list of other apps installed on the device, and send them to the SDK provider’s servers. This happens regardless of whether the app displays an ad in that session, because the SDK is also there to build a profile for future ad auctions. If a child plays three different free games that all embed the same ad network’s SDK, that network can, in principle, correlate the same advertising ID across all three, building a cross-app usage picture without ever asking the child anything directly.

Apps aimed explicitly at children under 13 in the US are supposed to operate under COPPA, the Children’s Online Privacy Protection Act, which restricts this kind of data collection for verified child users and has resulted in FTC enforcement actions against companies that shipped tracking SDKs in kids’ apps anyway. That’s background context, not a guarantee. App store listings don’t reliably disclose which SDKs are inside a given binary, and enforcement happens after the fact, not before an app is published. A “Made for Kids” badge on an app store listing reflects a developer’s self-certification, not an independent audit of what the code actually does.

Parental control tools collect data too

It’s worth being direct about this because it’s counterintuitive: the software you install to monitor or restrict your kid’s tablet is itself a data collector, and in some cases a more thorough one than the apps it’s watching.

Tools like Google Family Link, Qustodio, Bark, or Amazon’s Kids dashboard need visibility into app usage, web browsing, and sometimes message content or search terms in order to function. That means a company you’re trusting to protect your child’s privacy now holds a log of their behavior, stored on that company’s servers, governed by that company’s own data retention and breach history. This isn’t an argument against using these tools, screen time limits and content filtering solve real problems, it’s a reason to read what a specific tool actually logs and where that log lives before assuming “parental control” is synonymous with “private.”

The network layer sees everything unencrypted

Every tablet, kid’s or otherwise, talks to a Wi-Fi router, and the router (and by extension your ISP) can see which domains the device is contacting, even when the content of that traffic is encrypted via HTTPS. Router-level logs, if enabled, can show a timeline of every service a device connected to across a day. If a household is running a family safety product at the router or DNS level, that product is doing content filtering by intercepting and inspecting DNS queries, which is a legitimate way to block categories of sites, but it also means that layer sees every domain the tablet visits, not just the blocked ones.

Public or shared Wi-Fi, less common for a kid’s tablet than a home network, adds another party that can see connection metadata. This is standard networking behavior, not something specific to children’s devices, but it’s part of the full picture of who can technically observe usage patterns.

What actually reduces the collection

There’s no single setting or app that removes a child’s device from all of the above at once, and treating any one tool that way sets up a false sense of security. What you can do is address each layer on its own terms.

At the OS level, both Android and iOS let you reset or delete the advertising identifier and limit ad tracking system-wide (Settings > Google > Ads on Android, Settings > Privacy > Tracking on iOS), which reduces cross-app correlation without needing every app to cooperate. On Fire tablets, Amazon’s ad tracking opt-out is under Settings > Preferences > Advertising ID.

At the app level, reviewing permissions before install matters more than reviewing them after. A drawing app asking for microphone access or a puzzle game asking for location has no functional reason to need either, and Android and iOS both let you deny specific permissions while keeping the app installed. Sticking to apps distributed through a curated kids’ section of an app store isn’t a guarantee, as noted above, but it’s a meaningfully smaller pool than the open app store.

At the network level, a DNS-based filter run on the router (rather than relying solely on device-level parental apps) gives you one point of visibility instead of trusting each app’s own settings, and it works even on devices where you can’t install additional software.

None of this adds up to the tablet being untrackable or the child’s usage being invisible to every third party. That’s not a realistic bar for a networked device, and anyone telling you a single app or setting gets you there is selling something. The realistic goal is reducing the number of parties collecting data and being specific about which layer each control actually touches, the OS, the apps, the parental tool, or the network, rather than assuming one fix covers all four.

If you want more breakdowns like this one, on what your own devices are actually doing rather than what the marketing copy claims, you can find the rest of our explainers on the home page.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →