Apitor Technology markets programmable robot toys to children between the ages of six and fourteen, paired with a free companion app that lets kids control and reprogram the robots from an Android or iOS device. On Android devices, using the toy requires enabling location sharing in the app. According to a federal complaint, that requirement was not a technical formality — it opened a channel through which a third-party software developer based in China collected children's precise geolocation data, without notifying parents or obtaining their consent, as required under U.S. law.DOCUMENTED
The complaint, filed by the Department of Justice at the FTC's request, alleges that Apitor integrated a third-party software development kit called JPush into its app.DOCUMENTED That kit allegedly allowed its developer to collect location data from child users and use it for any purpose, including advertising — all while Apitor's own privacy policy claimed the company complied with the Children's Online Privacy Protection Rule.DOCUMENTED
- Apitor Technology is based in Shenzhen, China, and sells programmable robot toys marketed to children ages 6 to 14.
- The companion Android app allegedly required location sharing to function and collected and shared precise location data via a third-party SDK called JPush.
- Neither the account-registration nor the guest-mode option in the app prompted users to provide verifiable parental consent, according to the complaint.
- The alleged conduct has continued since at least 2022.
- The settlement includes a $500,000 civil penalty, suspended based on Apitor's inability to pay.
- The order requires 10 years of compliance monitoring and deletion of collected geolocation data absent express parental consent.
What the complaint alleges
The Children's Online Privacy Protection Rule, known as COPPA, requires operators of websites, apps, and other online services that have actual knowledge they are collecting personal information from children under 13 to notify parents about what information is being collected and to obtain verifiable parental consent before collecting it.REVIEWED The FTC's complaint alleges that after Android users downloaded the Apitor app, it began collecting and sharing users' precise location data with JPush's servers “unbeknownst to child users and their parents.”DOCUMENTED Neither of the app's two entry points — registering for an Apitor account or continuing as a guest — prompted users to provide verifiable parental consent to the collection of a child user's geolocation information, according to the complaint.DOCUMENTED
Christopher Mufarrige, Director of the FTC's Bureau of Consumer Protection, said in the agency's announcement that “Apitor allowed a Chinese third party to collect sensitive data from children using its product, in violation of COPPA.”DOCUMENTED The case is notable for placing legal responsibility for the third-party SDK's conduct on Apitor itself, the app developer, rather than treating the outside vendor's data practices as a separate matter beyond the developer's control.
A lesson about embedded code
Privacy lawyers who reviewed the case have described it as a reminder to app developers that embedding a third-party software development kit does not insulate a company from that vendor's data practices — the FTC's theory of liability rested on Apitor's own app enabling the collection, regardless of which company's code actually executed it.REVIEWED Software development kits like JPush are commonly used across mobile apps to add functionality such as analytics or push notifications, but they often come bundled with data-collection capabilities that the app developer integrating them may not fully audit or disclose.
Terms of the settlement
Under the proposed order, Apitor must obtain verifiable parental consent before it, or any party acting on its behalf, collects, uses, or discloses personal information from children under 13.DOCUMENTED The order also requires the company to delete a child's personal information at a parent's request and to retain any personal information collected from children only for as long as reasonably necessary to fulfill the purpose for which it was collected.DOCUMENTED The settlement includes a $500,000 civil penalty, which is suspended based on the company's stated inability to pay — meaning the fine would become due in full only if Apitor is later found to have misrepresented its financial condition.DOCUMENTED
Neither of the app's two entry points — creating an account or continuing as a guest — prompted users to provide verifiable parental consent to geolocation collection, the complaint alleges.
Why the case matters
The order also requires ten years of compliance monitoring and mandates that any future marketing for Apitor's robots include a clear and conspicuous disclosure if the company intends to collect geolocation or other COPPA-protected data, along with a request for explicit consent.DOCUMENTED The Commission voted 3-0 to refer the complaint and proposed order to the Department of Justice for filing.DOCUMENTED For parents evaluating connected toys generally, the case is a reminder that a location-sharing permission requested by a children's app is not a purely technical prerequisite for functionality — it is a data flow that, absent explicit consent processes, can end up on servers controlled by a company the parent never agreed to share information with in the first place.
Why connected toys draw particular scrutiny
Programmable and app-connected toys occupy a specific niche in children's privacy enforcement because, unlike a purely physical toy, they require an ongoing data connection to function at all — a permission structure that a young user, and often a parent glancing at an app install screen, may not fully parse before granting access.REVIEWED Regulators have brought a string of cases in this category over the past several years targeting connected toys, smart watches, and similar products marketed to children, reflecting a consistent view that the convenience of app-based functionality does not reduce a manufacturer's underlying COPPA obligations — if anything, the requirement for continuous data flows raises the stakes for getting consent right.REVIEWED
The involvement of a third-party SDK developed and operated from China adds an additional dimension regulators have flagged with increasing frequency: once a U.S. company's app hands data to an SDK from an overseas developer, tracing what happens to that data — who else may access it, and under what legal regime it is subsequently stored or used — becomes considerably harder for both the company and, ultimately, for the American parents whose children's information is involved.
Sources behind this report
Have documents relevant to this story? Reach us through our tips channel.