The Apitor robot toys case has become a wake-up call for parents and regulators. U.S. authorities found that Apitor, a Chinese manufacturer of educational robot kits, illegally collected children’s precise location data through its mobile app. The practice violated the Children’s Online Privacy Protection Act (COPPA), raising alarms about how connected toys handle sensitive information.
How the Data Was Collected
Apitor designs STEM-based robot toys for children aged 6 to 14. To operate the toys, kids had to download a companion app. The app demanded geolocation access, supposedly to connect with the devices. However, researchers found that it transmitted exact location data to a server in China via a third-party software development kit. The app continued tracking children even when it was not in use, leaving parents unaware of the ongoing data collection.
Regulatory Action Against Apitor
The Federal Trade Commission (FTC) determined that Apitor violated COPPA by failing to notify parents or secure consent before gathering sensitive information. The Department of Justice filed a formal complaint in September 2025 after regulators referred the case. Authorities imposed a suspended $500,000 penalty on Apitor, enforceable if the company misrepresented its financial status.
Compliance Measures Required
As part of the settlement, Apitor must:
- Obtain verified parental consent before collecting any data from children under 13
- Inform parents about all data practices clearly and transparently
- Delete any information collected without consent
- Retain personal data only for as long as necessary for the toy’s function
Broader Concerns with Connected Toys
The Apitor robot toys case highlights growing risks tied to internet-connected devices for children. Smart toys often include apps and third-party integrations, creating multiple points of vulnerability. Without strict oversight, these products can collect sensitive information such as location, identifiers, or even voice recordings.
Conclusion
The violation involving Apitor robot toys proves that privacy risks are not limited to traditional apps or websites. Connected toys, marketed as educational tools, can still expose children to serious data threats. Parents must remain vigilant, and developers must prioritize compliance with child privacy laws. COPPA is clear: children’s data cannot be collected without parental consent.


0 responses to “Apitor Robot Toys Violate COPPA by Collecting Children’s Location Data”