Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
This provision establishes that Child Users under 13 (or applicable local age of digital consent) are registered without name, email, or phone number, using only a non-identifying username. The policy asserts COPPA compliance by limiting collection to what is necessary for internal service operations and committing to delete inadvertently collected additional data.
This analysis describes what Duolingo's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the operational framework for COPPA compliance, including the categories of data excluded from collection for Child Users and the parental notification mechanism triggered at first logout. The policy separately states that all users under 16 receive additional protections including non-personalized advertising and disabled third-party behavioral tracking.
The updated policy removes explicit language stating that Android users and website users are not subject to audio collection for product improvement purposes. Previously, the policy authorized audio collection only from iOS users, with an explicit carve-out for Android and web users. The revised language now states that all users may choose not to share audio within app Settings, suggesting audio collection may now occur across all platforms unless the opt-out mechanism is used. The practical operational effect of this change depends on whether Duolingo implements audio collection on Android and web platforms, which the policy change does not explicitly confirm. You can decline audio sharing for product improvement by adjusting the setting within the app.
View change record →Under this provision, Child Users under 13 are enrolled with minimal data collection and receive non-personalized advertising, disabled third-party behavioral tracking, and restricted social features. Parents receive a notification email at first logout describing Duolingo's privacy practices for Child Users and the mechanisms available to access, change, or delete their child's information.
Cross-platform context
See how other platforms handle Child User Data Collection and COPPA Compliance and similar clauses.
Compare across platforms →Monitoring
Duolingo has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Duolingo treats Child Users (meaning users under the age of 13 in the United States or another age of digital consent in their country) differently to ensure their parents are in control and we only collect the bare minimum information we need to make Duolingo work. Child Users are permitted to create a Duolingo account, but instead of using an email address, we ask them to register using a username that is not tied to their real name. We do not collect their name, email address, phone number, or any other personal information. With regards to the Children's Online Privacy Protection Act ('COPPA'), Duolingo collects personal information from children under the age of 13 for the sole purpose of performing internal operations of the Service. If we discover that we have unknowingly collected additional personal information from these children, we will delete it.Excerpt from Duolingo's Privacy Policy
1) REGULATORY LANDSCAPE: This provision directly addresses COPPA, which is enforced by the FTC and requires verifiable parental consent before collecting personal information from children under 13. The policy asserts compliance through minimal collection rather than verifiable parental consent prior to registration. The FTC's COPPA Rule and associated guidance describe permissible activities that may proceed without prior parental consent, including internal operations. The policy's parental notification mechanism (email sent at first logout) does not constitute verifiable parental consent under COPPA's consent-first model. 2) GOVERNANCE EXPOSURE: Medium. The policy's COPPA approach relies on the 'internal operations' exception rather than verifiable parental consent prior to account creation. This approach is consistent with how some platforms address COPPA for minimal-data-collection scenarios, but the adequacy of the notification-at-first-logout mechanism as a substitute for prior consent may require evaluation against current FTC guidance. The additional protections for users under 16 (non-personalized ads, disabled behavioral tracking) align with GDPR Article 8 and similar frameworks. 3) JURISDICTION FLAGS: U.S. deployments are subject to COPPA FTC enforcement. EU and EEA deployments involving users under 16 engage GDPR Article 8, which requires parental consent for users below the applicable national age of digital consent (which varies between 13 and 16 across EU member states). UK deployments engage the UK Children's Code (Age Appropriate Design Code), which imposes privacy-by-design requirements for services likely to be accessed by children. 4) CONTRACT AND VENDOR IMPLICATIONS: The policy states that third-party behavioral tracking and analytics are disabled for Child Users, which should be verified against the operational implementation of FullStory, Session Replay, and advertising SDK configurations. Institutions deploying Duolingo in school contexts should confirm that the Child User protections apply in their specific deployment configuration. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should verify that the parental notification email mechanism is reliably triggered at first logout and accurately describes data collection practices. The policy's assertion that no personal information beyond what is necessary for internal operations is collected from Child Users should be verified against actual data flows, including any SDK or analytics libraries that may be active. Parents wishing to access, modify, or delete their child's data should contact privacy@duolingo.com.
This provision establishes the operational framework for COPPA compliance, including the categories of data excluded from collection for Child Users and the parental notification mechanism triggered at first logout. The policy separately states that all users under 16 receive additional protections including non-personalized advertising and disabled third-party behavioral tracking.
Under this provision, Child Users under 13 are enrolled with minimal data collection and receive non-personalized advertising, disabled third-party behavioral tracking, and restricted social features. Parents receive a notification email at first logout describing Duolingo's privacy practices for Child Users and the mechanisms available to access, change, or delete their child's information.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Duolingo.