In January of this year, security researchers discovered that an AI toy called Bondu had left more than 50,000 children’s chat transcripts exposed on a publicly accessible web console. No password. No authentication. Just a searchable archive of conversations between children and their toy — names, questions, secrets, fears, and the kind of unguarded things children say when they think they’re talking to a friend.
The Bondu incident was unusual only in how visible the failure was. The underlying issue — connected toys collecting, storing, and inadequately protecting children’s private data — is widespread.
What Smart Toys Actually Collect
Modern connected toys are more capable than they appear. A toy that responds to a child’s voice, remembers their name, learns their preferences, or answers questions is necessarily collecting and processing data to do those things. The question is where that processing happens and what the toy’s manufacturer does with the results.
Voice Recordings
Any toy with a microphone that responds to voice commands is recording audio at minimum during activation, and often beyond it. That audio has to be processed to generate a response, and in many cases it is sent to cloud servers. The recordings themselves may or may not be retained after processing.
Face and Image Data
Toys with cameras — interactive dolls, educational tablets, video story companions — can capture video and still images. Face recognition features require facial data. Even toys that use cameras only for AR effects may be processing visual data in ways their privacy policies don’t clearly explain.
Usage Patterns and Conversation Content
Connected toys that learn from interactions are building a profile of the child over time. Preferences, questions, conversation topics, emotional states as expressed in voice and words — this data is what makes personalisation work. It is also what makes the data privacy question meaningful.
Location and Device Data
Where a toy connects from, on what network, at what times. Indirect identifiers that can contribute to a profile even when the toy doesn’t have GPS.
Parent Account Data
The account the parent creates to activate and manage the toy. Email address, payment information, device information, the child’s name and age. This data sits alongside the child interaction data in the same system.
Where That Data Goes
Most smart toy data ends up on the manufacturer’s cloud servers. This is unavoidable when the toy’s functionality depends on cloud processing — voice recognition, personalised responses, and AI-generated content require server-side computation that can’t run on a toy’s limited hardware.
The question is what happens to that data once it’s there.
Data Retention
Few toy manufacturers specify how long they retain audio recordings, conversation logs, or interaction data. Indefinite retention is common by default. Some services delete audio after processing; others keep it to improve their AI systems.
Third-Party Processing
Toy companies are not AI companies. Most of the voice processing, natural language understanding, and AI features in smart toys are built on top of third-party platforms. When a toy processes speech, that audio may pass through one or more third-party services before a response comes back, each with their own data retention practices.
AI Training
Conversation data from children is valuable training data. Whether a specific toy uses children’s interactions to train AI models — or shares data with third parties who do — is often not clearly disclosed in toy packaging or setup flows.
Real-World Failures
The Bondu incident earlier this year wasn’t isolated. The history of connected toy security failures is consistent.
VTech (2015): Hackers accessed the accounts of 4.8 million adults and more than 6.3 million children. The data included children’s names, birthdates, genders, photos, and — for some toys — audio recordings.
My Friend Cayla (2017): German authorities banned the toy and classified it as an illegal surveillance device. The toy broadcast audio over Bluetooth with no authentication, and the service had inadequate security protecting children’s conversations.
CloudPets (2017): 800,000 user accounts and 2.2 million voice messages were exposed due to an unsecured database, including voice messages exchanged between children and parents.
The pattern across these incidents is consistent: data was collected, retained, and inadequately secured. The value of the data to attackers and the inadequacy of security practices proved a reliable combination.
A 2024 investigation found serious security gaps in multiple popular connected toys, including unencrypted data transmission and improperly secured APIs that exposed children’s interaction logs.
The Regulatory Landscape
COPPA has governed children’s online privacy in the United States since 2000. Amendments that took full effect earlier this year significantly strengthened it: stricter parental consent requirements, expanded data categories covered — now explicitly including voice recordings, facial images, and precise geolocation — new limits on targeted advertising to minors, and higher penalties for violations.
The gap between the regulatory requirement and what many toys actually do in practice remains significant. Enforcement is uneven. Small toy manufacturers, particularly those manufacturing overseas, often operate outside effective regulatory reach. Parental consent forms are frequently written in ways that obscure what data is actually being collected.
State laws are filling some gaps. California’s Age-Appropriate Design Code and similar legislation in other states imposes design requirements — default privacy settings, data minimisation requirements, prohibitions on certain manipulative design patterns — that go beyond federal law. But state-by-state coverage is inconsistent.
What Parents Can Do
Before Buying
The right time to evaluate a smart toy’s privacy practices is before it enters the house. Questions worth answering:
- Does the toy require a cloud account? What data does the account collect?
- Where is voice or video data processed — on-device or in the cloud?
- What is the manufacturer’s data retention policy?
- Has the toy passed independent privacy or security review?
- What third-party services does the toy use for AI features?
Mozilla’s Privacy Not Included project reviews consumer technology products, including toys, against defined privacy standards. It’s a useful starting point before purchase.
Review Permissions After Setup
After setup, review connected permissions and privacy settings before a child uses the toy. This includes whether the toy can record continuously or only when activated, who can access the parent account, and what data sharing can be limited through settings.
Limit What the Toy Knows
A toy that personalises around a child’s name, school, location, and daily schedule holds more meaningful data than one that doesn’t. Personalisation features often require explicit input — the child or parent provides information that then becomes part of the interaction data. Providing less information limits the resulting profile.
Understand That Delete May Not Mean Delete
Requesting deletion of a child’s data from a smart toy manufacturer requires using the deletion rights under COPPA or applicable state law. Simply removing the app or account is often not sufficient — data may remain on manufacturer servers until a specific written deletion request is made and confirmed. Keep a copy of the request and a record of any response.
Separate Toy Accounts From Primary Family Accounts
Create a dedicated email address for toy accounts rather than using a primary family email. Use a guest WiFi network for connected toys rather than your main home network. These steps limit the data connection between the toy’s profile and your household’s primary accounts and reduce exposure if a toy platform is breached.
The Deeper Issue
A child’s relationship with a toy is qualitatively different from an adult’s relationship with a service they’ve chosen and consented to. Children don’t understand that the toy is connected, that their conversations are stored, or that what they say might end up on servers operated by companies they’ve never heard of.
When children share things with toys — worries, friendships, events from their day, what’s happening at home — they’re sharing in the assumption of privacy that all genuine play involves. The fact that the toy is simultaneously operating as a data collection device isn’t visible to them, and in many cases isn’t adequately disclosed to their parents.
That asymmetry — genuine, trusting engagement from a child; data extraction operating behind it — is what makes the privacy stakes in connected toys different from those in adult consumer products. The data is uniquely sensitive, the subject cannot meaningfully consent, and protection depends on regulatory enforcement and manufacturer responsibility that has historically been inconsistent.
Protecting What Gets Preserved
The memories of childhood that are worth keeping — photos, videos, audio of a child’s voice at different ages, family milestones — are worth storing somewhere you control rather than as a byproduct of a connected toy’s data collection.
daftei stores photos, videos, audio recordings, and documents under AES-256 encryption at rest and TLS 1.3 in transit, with no advertising, no data selling, and no AI training on your content. The 5 GB free tier covers personal use; unlimited storage is available on Pro at $5.99 per month or $44.99 per year.
If you want a private record of your child’s early years, keeping it in your own controlled archive — where you decide what’s retained, who has access, and what happens to it over time — is different in kind from what a smart toy’s data infrastructure offers.