Back to blog

Does an AI Toy Record My Child? What Actually Happens to Your Child's Voice Data

It is the question almost every parent asks within thirty seconds of picking up a talking toy: is this thing listening to my child all the time, and where does what it hears end up? It is a good question, and the honest answer is that it depends entirely on the product, which is exactly the problem.

This article walks through what actually happens to a child's voice between the moment they speak and the moment a toy replies, what the law requires in the United States and Europe, what has gone wrong in this industry before, and the five checks that let you tell a well-designed product from a careless one. No marketing shortcuts, and we will hold ourselves to the same test at the end.

Does a talking toy record everything it hears?

Well-designed ones do not. A responsible connected toy uses either push-to-talk, where the child presses a paw or a button to speak, or a wake trigger, where audio is only captured after a specific cue. In both cases the microphone is not streaming your kitchen conversations to a server all day.

Badly designed ones can and have. Germany's Federal Network Agency banned the My Friend Cayla doll in February 2017 precisely because the device collected and transmitted what it heard with weak controls over who could connect to it. NPR reported at the time that the regulator advised parents who already owned the doll to deactivate it, on the grounds that it could function as an unauthorised surveillance device.

So the honest answer is that "AI toy" tells you nothing about recording behaviour. The mode of capture does. Before you buy, find out whether the microphone opens on a button press, on a wake word, or continuously, and whether you can see or change that setting yourself.

Where does my child's voice actually go?

In most conversational toys, the audio leaves the toy. The typical path is: the toy captures a short audio clip, sends it over your home Wi-Fi to a cloud server, a speech recognition system converts it to text, a language model generates a reply, that reply is turned back into speech, and it comes back to the toy. All of that usually takes under two seconds.

The privacy question is not really about the trip. It is about what happens at the far end. Is the audio deleted immediately after transcription, or stored? Is the transcript stored? For how long? Is it used to train models? Is it shared with any third party? Two products with identical hardware can answer those four questions completely differently, and only one of them is being careful.

The Congressional Research Service laid this out for legislators in its briefing on smart toys and children's online privacy, and the mechanics have not changed since. What has changed is how much regulators expect companies to disclose.

Ten years of voice data lessons from connected toysDocumented incidents and the rules that followed2015Hello Barbie ships. Every reply travels to a cloud server for processing.Feb 2017A CloudPets database is left exposed online. Voice messages recorded by children are accessible andransomed.Feb 2017Germany's Federal Network Agency bans the My Friend Cayla doll and tells parents to deactivate it.Oct 2017The FTC clarifies that a child's voice recording is personal information under COPPA.Jan 2018VTech pays 650,000 dollars to settle FTC charges after a breach touching 6.4 million children.Jun 2026UNICEF asks companies to minimise conversational data and ban secondary uses.Sources: NPR, Troy Hunt, FTC, UNICEF. Compiled by Ted&Co, 2026
Notice the pattern: the rules in this industry were written after the failures, not before them. That is why reading a privacy policy still matters more than trusting a category.

What does the law actually require?

In the United States, a child's voice recording is personal information. The Children's Online Privacy Protection Act requires verifiable parental consent before an operator collects it from a child under 13. The FTC made this explicit in its October 2017 enforcement policy statement on voice recordings, published in the Federal Register in December 2017.

There is one narrow carve-out worth understanding, because good products are built around it. The FTC said it would not pursue enforcement where a company collects an audio clip purely as a replacement for typed words, such as issuing a command or a search, and then deletes the file immediately. Three conditions apply: it cannot be used to request personal information like a name, the deletion policy must be stated clearly in the privacy policy, and the file cannot be used for anything else before destruction.

In Europe, the General Data Protection Regulation treats voice as personal data and, where consent is the legal basis, requires it to come from a parent or guardian for children under 16, or under 13 in member states that lowered the threshold. Practically, that means an EU-facing product needs a real parental account, not a tick box on a toy.

What has actually gone wrong before?

Three cases are worth knowing, because they explain why parents are right to be sceptical.

CloudPets sold plush toys marketed as "a message you can hug". In late 2016 and early 2017, its database was left accessible online without a password. Security researcher Troy Hunt documented how voice messages recorded by children were exposed and then held to ransom. The company was slow to respond.

VTech suffered a breach affecting 6.4 million children. In January 2018 it paid 650,000 dollars to settle FTC charges that it had collected children's personal information without proper parental notice and consent, and had claimed in its privacy policy that data was encrypted when it was not. It also agreed to 20 years of independent security audits.

More recently, testing by the PIRG Education Fund found AI chatbot toys on sale that would tell a child where to find dangerous objects in the house, including explaining how to light a match. That is a content failure rather than a data failure, but it comes from the same root cause: shipping fast without testing against how children actually behave.

How do I read a privacy policy in five minutes?

You do not need to read the whole thing. Use your browser's find function and search for five words. If any of them return nothing useful, that itself is the finding.

Search the policy for these five words

  1. Retention or delete. How long is audio kept? "Immediately after transcription" is the strong answer. Silence is the weak one.
  2. Third party or share. Anything about advertising partners, data brokers or analytics resale is a red flag on a children's product.
  3. Training. Is your child's voice used to improve the model? You should be able to find a clear yes or no.
  4. Camera. If there is one, you want to know exactly what triggers it. Toys with no camera at all sidestep an entire category of risk.
  5. Parental consent. Is there a real verified parent account, and can you delete everything from it?

What does a careful design look like in practice?

The business recommendations UNICEF published in June 2026 give a usable definition. They ask companies to practise data minimisation, especially for sensitive conversational data, to limit retention tightly, to document the lawful basis and purpose, and to prohibit secondary uses including third party sharing unless a lawful basis exists.

They also ask companies to give parents accessible tools and guidance, to avoid marketing the product as a trusted confidant, and never to advertise to children inside the interaction. None of these are technically hard. They are commercial choices, and a company that has not made them has usually decided not to.

For our part, Ted has no camera at all, only a microphone and a speaker. Setup runs through a parent account in the Ted&Co app, where you choose the language, the topics, the tone and whether the toy uses push-to-talk or automatic listening. There is no subscription and no advertising, which removes the commercial incentive to keep a child engaged for longer. The certifications, including GDPR and COPPA alignment, are listed on our security and certifications page, and the specifics of what we store are on the FAQ. Check them against the five-word test above rather than taking our word for it. If you want a broader view of the category first, we have also written about what 2026 research actually shows about AI companion toy safety.

Frequently asked questions

Do AI toys listen all the time?

Not if they are well designed. Most reputable connected toys capture audio only after a button press or a specific wake trigger, and the microphone is otherwise inactive. Some poorly designed products have transmitted continuously, which is why Germany banned the My Friend Cayla doll in 2017. Check the capture mode in the product documentation before you buy.

Is a child's voice recording personal data under the law?

Yes. Under the US Children's Online Privacy Protection Act, voice recordings have counted as personal information since the 2013 rule update, and verifiable parental consent is required before collecting them from a child under 13. Under the European GDPR, voice is personal data, and consent for children under 16, or under 13 in some member states, must come from a parent or guardian.

Can a connected toy be hacked?

Any internet-connected device can be attacked, and children's toys have been. The CloudPets database was left exposed and ransomed in 2017, and a VTech breach reached 6.4 million children. The meaningful questions are whether the company encrypts data, how long it retains it, and whether it has independent security auditing. A product that stores nothing is a far smaller target.

Do AI toys need a subscription?

Some do and some do not, and it matters more than it looks. A subscription model creates a commercial incentive to keep a child engaged, which is exactly the pattern UNICEF asks companies to disable for child users. Ted is a one-off purchase with unlimited conversations and no recurring fee.

Should I worry about a toy with a camera?

A camera adds a whole category of risk that a microphone does not: visual footage of your home and your child's face, with all the storage, transmission and breach exposure that implies. If a product has a camera, you should know exactly what triggers recording, where the footage goes, how long it is kept and how to disable it. Ted has no camera.

Sources