Table of Contents
What Happens to Your Child's Data When an App Goes Bankrupt or Shuts Down
When apps shut down, kids' photos, messages, and profiles often disappear or get sold. Learn COPPA deletion rules and how to protect your child's data before it's too late.
In early 2023, a social learning app popular with middle schoolers announced it was shutting down with 30 days’ notice. Parents scrambled to download their children’s content — creative projects, messages with friends, progress achievements accumulated over three years. Some managed. Most didn’t log in fast enough. The servers went dark and the data went with them. This happens more than most parents realize. According to data from Crunchbase, over 2,000 consumer apps shut down or were acquired annually between 2020 and 2024. Each closure carries the same question: where does the data go? For apps that collected information from children under 13, the answer involves a specific legal framework — and it doesn’t always protect what parents assume it does.
Key Takeaways
- When apps shut down, user data is typically sold as an asset to buyers, archived, or simply deleted — there is no guarantee of any specific outcome
- COPPA requires verifiable parental consent before collecting children’s data, but does not mandate permanent data deletion upon app closure
- The FTC has intervened in app closures to protect children’s data in high-profile cases, but most closures happen without regulatory oversight
- Parents should download or export any content they care about before an app shows signs of financial distress
- Data sold during bankruptcy acquisitions can go to buyers who operate under entirely different privacy policies
- Practical protection: use apps that allow data export, and export quarterly
What COPPA Actually Requires — and What It Doesn’t
The Children’s Online Privacy Protection Act (COPPA) governs how operators collect personal information from children under 13. It requires parental consent before collection, mandates privacy notices, and requires operators to maintain “reasonable” security. The FTC enforces it and has levied significant fines — including a $170 million penalty against Google/YouTube in 2019.
What COPPA does not require: guaranteed data deletion if the company shuts down. The law requires operators to delete data that is no longer necessary for the purpose for which it was collected — but “no longer necessary” is a legal judgment call, not an automatic trigger on shutdown.
When a company goes bankrupt, its assets — including user data — become part of the bankruptcy estate. A bankruptcy court can authorize the sale of that data to a buyer who becomes the new “operator” under a new privacy policy. The FTC has historically monitored high-profile cases and intervened when buyers attempted to materially change privacy practices. In the 2015 closure of ToysRUs (which operated a children’s web portal), the FTC required data destruction rather than sale. But FTC intervention is the exception, not the rule, and is more common in high-profile cases involving large user bases.
Real App Closures: What Actually Happened to the Data
Vine (2016)
Twitter shut down Vine, the short video platform that had millions of teen users. Twitter gave users a tool to download their videos. Eventually Twitter itself was acquired by private owners, and the data question came full circle — illustrating how acquisition chains can move data through multiple sets of hands.
Google+ (2019)
Google shut down the consumer version of Google+ after a data breach affected user data. Google provided a data takeout tool (part of Google Takeout) and gave users 10 months of notice. This is considered a model closure — extended notice, robust export tools, clear deletion timelines.
Musical.ly → TikTok (2018)
Musical.ly was acquired by ByteDance and transitioned to TikTok. The FTC later fined TikTok $5.7 million in 2019 for COPPA violations related to data Musical.ly collected from children. The acquisition didn’t erase the prior data — it transferred it. This case established that buying a company’s data assets creates COPPA obligations for the new owner.
Parler (2021)
Following deplatforming, a security researcher captured and archived approximately 70TB of Parler data — including videos with metadata — before the service went offline. While not a children’s app, this illustrates what happens when data isn’t properly secured during an abrupt closure: third parties can capture it before any deletion occurs.
Club Penguin Online (2020)
An unofficial fan recreation of Disney’s Club Penguin was shut down by Disney, and its operator was arrested for child sexual abuse material. The official Disney Club Penguin had been shut down in 2017; Disney gave several months of notice and offered downloadable memories. The contrast illustrates how legitimate operators handle closures versus unofficial platforms.
What Typically Happens to Data in Different Closure Types
| Closure Type | Data Outcome | COPPA Implications | Parent Action Window |
|---|---|---|---|
| Planned shutdown (voluntary) | Usually deleted or archived; often export tools offered | Operator still responsible until close | Days to months (read notices) |
| Acquisition | Data transfers to buyer under new privacy policy | Buyer becomes new COPPA operator | Before acquisition closes |
| Bankruptcy sale | Data sold as asset; new owner’s policy governs | FTC may intervene in child-data cases | Very short — monitor news |
| Sudden closure / insolvency | Data may be abandoned or held by hosting providers | Minimal legal protection | Often no warning |
| Government seizure | Data held by authorities indefinitely | Beyond COPPA framework | No action possible |
The Data Export Habit: What to Download and When
The most reliable protection requires no legal knowledge — just consistent behavior. If your child creates anything on an app, download it. Period.
Priority 1 — Download immediately:
- Photos and videos posted to any platform
- Creative projects (drawings, game builds, written stories)
- Completed educational coursework or certificates
Priority 2 — Export quarterly:
- Friend/contact lists (export to a contacts app)
- Account settings and linked account information
- Any purchased content receipts
How to export on major platforms:
Google (including YouTube, Gmail, Google Classroom): Visit takeout.google.com and select the products to export. You can schedule quarterly automatic exports.
Apple: Visit privacy.apple.com → Data and Privacy → Request a copy of your data. Available for photos, messages (iMessage), and App Store history.
Discord: User Settings → Privacy & Safety → scroll to “Request all of my Data.” Discord emails a download link within 30 days.
Roblox: Roblox does not offer a full data export tool. Downloaded screenshots of builds, saved place files from Roblox Studio, and recorded videos are the only reliable preservation method.
Minecraft:
World files are stored locally on the device — no account export needed. Back up the world folder (found in %AppData%\.minecraft\saves on Windows) to an external drive or cloud storage.
Signs an App May Be Approaching Closure
Parents can often read the warning signs before an official announcement:
- Layoffs announced at the parent company
- No app updates for 6+ months
- Investor funding announcements stop (check Crunchbase)
- Social media accounts go quiet
- Negative news coverage about the company’s business model
- The app’s rating drops sharply due to unaddressed bugs
- Support tickets go unanswered for weeks
Any of these signals is reason to trigger an immediate export of your child’s data before access is lost.
What Parents Can Do Right Now
Step 1: List every app your child uses that holds any personal data — photos, messages, profiles, game progress.
Step 2: For each app, find the “data export” or “download my data” option. Most are buried in account settings under “Privacy” or “Security.”
Step 3: For apps with no export function (some gaming apps fall into this category), take screenshots of anything your child cares about and save to a dedicated folder.
Step 4: Set a calendar reminder for quarterly data exports. Google Takeout can be automated.
Step 5: Before letting your child create an account on any new app, check who owns it (company and parent company), when they last updated the app, and whether they have an explicit data retention policy.
Internal Links
For more on COPPA and how it protects children’s online information, see our guide on kids’ online privacy and COPPA. To understand the broader landscape of protecting children online, read our overview of cybersecurity and digital literacy for kids.
What to Watch For Over the Next 3 Months
Month 1: Complete the data export for your child’s top 3 apps. Set calendar reminders. If any app requires jumping through unusual hoops to export data, note that as a red flag for the app’s transparency.
Month 2: Research the parent companies behind the top apps your child uses. Know who owns what. Note their last funding rounds and whether they’re profitable businesses or venture-funded startups still searching for a business model — the latter are higher closure risks.
Month 3: Teach your child (in age-appropriate terms) that anything they create online might not be theirs forever. For kids 10+, this is a real conversation worth having: “We download your Minecraft worlds every few months because we want to keep them safe.” This normalizes the habit without creating anxiety.
Red flag: If your child’s app stops pushing updates and the developers go quiet on social media for more than 60 days, treat that as a pre-closure signal and export immediately.
Frequently Asked Questions
If an app promises to delete data when I close my account, do they have to follow through?
Under COPPA, operators are required to delete children’s data when it’s no longer necessary. If you close your child’s account, the operator should delete the associated personal information. However, “deletion” may not cover data already shared with third-party advertising or analytics partners. Sending a formal written deletion request (via email to the privacy contact in their privacy policy) creates a record if you ever need to escalate to the FTC.
Can I request deletion of my child’s data from an app before it shuts down?
Yes. Under COPPA, you have the right to review and delete the personal information an operator has collected from your child. Contact the app’s privacy team (usually found at the bottom of their privacy policy page) and submit a formal deletion request. Most legitimate operators will comply within 30–45 days. Document your request with a screenshot or email copy.
What happens to my child’s in-app purchases when an app shuts down?
In most cases, they’re gone. Virtual currency, in-game items, and subscription credits are generally non-refundable under standard terms of service when a platform shuts down voluntarily. In bankruptcy cases, there’s occasionally a small claims process as part of the bankruptcy estate, but recovery is rare. This is an argument against making large in-app purchases on any platform — especially smaller, venture-funded apps.
Are there laws that protect children’s data better than COPPA?
Several states have passed stronger protections. California’s Age-Appropriate Design Code (AB 2273) requires apps to give children’s privacy priority in their design by default. The UK’s Age Appropriate Design Code preceded this and has been influential globally. At the federal level, the Children and Teens’ Online Privacy Protection Act (COPPA 2.0) has been proposed to extend protections to ages 13–16 and add data minimization requirements. As of 2026, COPPA 2.0 remains pending in Congress.
About the author
Ricky Flores is the founder of HiWave Makers and an electrical engineer with 15+ years of experience building consumer technology at Apple, Samsung, and Texas Instruments. He writes about how kids learn to build, think, and create in a tech-saturated world. Read more at hiwavemakers.com.
Sources
- Federal Trade Commission. (2024). Children’s Online Privacy Protection Rule (COPPA). https://www.ftc.gov/legal-library/browse/rules/childrens-online-privacy-protection-rule-coppa
- Federal Trade Commission. (2019). “Google and YouTube Will Pay Record $170 Million for Alleged Violations of Children’s Privacy Law.” https://www.ftc.gov/news-events/news/press-releases/2019/09/google-youtube-will-pay-record-170-million-alleged-violations-childrens-privacy-law
- Federal Trade Commission. (2019). “Video Social Networking App Musical.ly Agrees to Settle FTC Allegations That It Violated Children’s Privacy Law.” https://www.ftc.gov/news-events/news/press-releases/2019/02/video-social-networking-app-musically-agrees-settle-ftc-allegations-it-violated-childrens-privacy
- California Legislative Information. (2022). AB 2273: California Age-Appropriate Design Code Act. https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202120220AB2273
- Identity Theft Resource Center. (2024). 2023 Annual Data Breach Report. https://www.idtheftcenter.org/publication/2023-annual-data-breach-report/
- Crunchbase. (2024). Startup Failure and Acquisition Trends 2020–2024. https://www.crunchbase.com