Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that OpenAI Services are not directed to children under 13, that OpenAI does not knowingly collect personal data from that age group, and that users aged 13 to 17 must have parental or guardian permission to use the Services; the policy also discloses a teen account linking feature that allows parents or guardians to manage settings and receive safety alerts.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the minimum age requirement for Service use, provides a reporting mechanism for suspected under-13 data collection, and creates a parental permission requirement for users aged 13 to 17, with a linked account feature that permits parental oversight of teen user settings and safety alerts.
Interpretive note: The mechanism by which parental permission for users aged 13 to 17 is established and verified is not described in the policy text, creating ambiguity about how this requirement operates in practice.
The updated policy explicitly discloses that OpenAI receives information from advertisers and other data partners for Free and Go users, and uses this data to personalize ads and measure ad effectiveness. The policy now states that Free and Go users can control what data OpenAI uses to personalize ads through advertising controls in account settings. This represents clarified disclosure of an existing practice rather than a new authorization.
View change record →The updated privacy policy now explicitly states that OpenAI receives information from advertisers and other data partners, which is used to personalize ads shown to Free and Go users and to measure the effectiveness of those ads. For example, the policy notes that OpenAI could receive information about purchases users make from advertisers. The policy now includes a dedicated section on ad personalization and measurement as a primary use of personal data for these user tiers. You can manage what data OpenAI uses for ad personalization by accessing the advertising controls in your account settings or by using the Data Controls option.
View change record →The updated policy now explicitly authorizes OpenAI to promote products and services to users through direct marketing on third-party properties and to share limited information with select marketing partners (who are not service providers) to support these efforts. The policy states that some marketing partners may receive information through cookies and similar technologies. The revised terms establish that these marketing practices are subject to user choices and controls, with additional information and opt-out options available. You can make choices about the use of your information for third-party product promotion purposes through controls referenced in the policy.
View change record →Under this provision, users under 13 are excluded from OpenAI Services, and users aged 13 to 17 must have parental or guardian permission. Parents and teen users may optionally link accounts to enable parental management of settings and receipt of safety alerts, with account unlinking available at any time.
Cross-platform context
See how other platforms handle Children and Minor User Requirements and similar clauses.
Compare across platforms →Monitoring
OpenAI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Our Services are not directed to, or intended for, children under 13. We do not knowingly collect Personal Data from children under 13. If you have reason to believe that a child under 13 has provided Personal Data to OpenAI through the Services, please email us at privacy@openai.com. We will investigate any notification and, if appropriate, delete the Personal Data from our systems. Users under 18 must have permission from their parent or guardian to use our Services.Excerpt from OpenAI's Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages the Children's Online Privacy Protection Act (COPPA), enforced by the FTC, which prohibits the collection of personal data from children under 13 without verifiable parental consent. The policy's 'do not knowingly collect' standard tracks COPPA's baseline requirement, though COPPA's safe harbor and actual knowledge standards are complex. State laws in California, Illinois, and other jurisdictions may impose additional obligations regarding minor user data, including the California Age-Appropriate Design Code Act. The EU's GDPR sets minimum ages for consent that vary by member state, addressed through the separate EEA policy. 2) GOVERNANCE EXPOSURE: Medium. The policy relies on a 'not knowingly' collection standard rather than affirmative age verification for the under-13 threshold, which is a standard COPPA compliance posture but which carries residual risk of inadvertent collection. The parental permission requirement for users aged 13 to 17 is stated but the mechanism for establishing that permission is not detailed in the policy text, which creates ambiguity about how compliance is verified in practice. 3) JURISDICTION FLAGS: California's Age-Appropriate Design Code Act and similar state minor data protection laws may impose obligations beyond COPPA's minimum requirements, including default privacy protections and design requirements for services likely to be accessed by minors. The policy's cross-context behavioral advertising carve-out for users known to be under 18 reflects awareness of these statutes. EU and UK jurisdictions have separate age of consent requirements addressed in the separate policy. 4) CONTRACT AND VENDOR IMPLICATIONS: Organizations deploying OpenAI Services in educational contexts should assess whether FERPA or COPPA obligations are triggered, and whether the consumer policy or a separate educational agreement governs their deployment. The policy explicitly excludes API data from this privacy policy, so API-based educational deployments would be governed by the applicable customer agreement. 5) COMPLIANCE CONSIDERATIONS: Platform operators and institutional deployers should review whether their implementation of OpenAI Services could result in access by users under 13 or 17, and whether additional age verification mechanisms are warranted. The reporting mechanism at privacy@openai.com for suspected under-13 data collection should be noted in any incident response procedures involving potential COPPA violations.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes the minimum age requirement for Service use, provides a reporting mechanism for suspected under-13 data collection, and creates a parental permission requirement for users aged 13 to 17, with a linked account feature that permits parental oversight of teen user settings and safety alerts.
Under this provision, users under 13 are excluded from OpenAI Services, and users aged 13 to 17 must have parental or guardian permission. Parents and teen users may optionally link accounts to enable parental management of settings and receipt of safety alerts, with account unlinking available at any time.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.