It's 9:40 PM. The kids are finally down, you're scrolling your phone in the dark before you follow them, and a headline about an AI chatbot and a teenager stops your thumb cold. Right underneath that tab is the one where you signed your own seven-year-old up for a bedtime story service that uses AI to write the chapters. You close the headline, open the other tab, and actually read what you agreed to for the first time.
"AI" isn't one thing, and neither is "safe"
That gut-check is fair, and it deserves a real answer instead of either extreme — not "AI near your kid, absolutely not," and not "it's fine, don't worry about it." The honest answer is that AI bedtime stories cover a wide range of products doing very different things, with very different risk profiles, and lumping them together is exactly how a legitimately useful service and a genuinely reckless one both hide behind the same three-word label.
The distinction that matters most is whether your kid talks to the AI, or whether the AI writes something a grown-up reviews before your kid ever sees it. Common Sense Media's age-and-stage guidance on AI chatbots recommends steering clear of AI companion apps entirely for kids five and under, and real caution through age twelve — but that guidance is about tools kids interact with directly, in real time, with no adult in the exchange. A bedtime story your kid receives as finished content, after a human has already read it, is a different category of thing. Both get called "AI for kids." They are not the same product, and they don't carry the same risk.
So the useful question isn't "is AI safe." It's a short list of specific, checkable things — the kind you can actually verify from a privacy policy and an About page in five minutes, instead of taking anyone's word for it.
The six-question checklist
1. Does a human read it before your kid does? Not a spot-check, not a sample — every single piece of content, every time. If a service can't tell you plainly who reads what and when, assume nobody does.
2. What does it actually need to know about your child? A first name and a rough age range is enough to personalize a story. Full birthdate, photos, voice recordings, or a last name are not needed for this and shouldn't be asked for. More data collected than the product requires is a red flag on its own, independent of anything else.
3. Is your child's data used to train the AI? This is answerable in plain language in any real privacy policy — either the story content and any information you submit trains the model, or it doesn't. "We may use data to improve our services" is not an answer to this question; it's a way of avoiding it.
4. Does your kid talk to the AI, or does a parent operate it? This is the chatbot-versus-content distinction again, and it's worth checking directly. A service where your child types, speaks, or chats with the model in real time is a fundamentally different risk than one where a parent sets preferences and the child only receives the finished result.
5. Can you see, edit, or delete everything yourself? Not "email support and wait" — an actual self-serve option to see what's stored about your child and remove it, on your schedule, not theirs.
6. Is there a fast, easy way to flag something wrong? Every AI system occasionally produces something off — a strange turn, a tone that doesn't land, a detail that's just wrong. The question isn't whether that ever happens; it's how quickly and easily you can report it and how the service says it responds.
Why #3 just got a real legal answer
Until recently, "is my kid's data being used to train the AI" was mostly a matter of trust — you asked, and you hoped the answer was true. That changed with the FTC's amended Children's Online Privacy Protection Rule, the first substantial update to COPPA in over a decade, with compliance required as of April 2026. The amended rule states that using a child's personal information to train or otherwise develop AI technologies isn't considered a normal, bundled part of running an online service — it now requires separate, verifiable parental consent, called out on its own rather than buried in a general terms-of-service agreement. In plain terms: a company can no longer quietly train its model on your kid's data under the umbrella of "providing the service." It has to ask you, specifically, first.
That doesn't mean every service complies, or that reading the fine print stops mattering. It does mean question three on the checklist above isn't just a nice-to-have anymore — it's something a service is legally required to be straight with you about.
What this checklist looks like at Moontuck
We think a service should be able to answer all six questions in one paragraph, so here's ours. Every chapter is drafted by AI and then read, with an actual person's eyes, before it's approved — that review is the whole product, not a feature we added later. We collect a first name, an age range, and one chosen story world — no last name, no birthdate, no gender, no photos. Your child's data is never used to train any AI model, by us or by our AI provider, under our published privacy policy; the writer prompt improves over time from what we observe, not from your kid's information. Your child never logs in, types, or talks to anything — you set preferences and read the chapters together, the same as you'd read any book. You can see, edit, or delete everything about your account and your kid's profile yourself, instantly, no ticket required. And if a chapter is ever off, one email gets a real person looking at it, the same day.
The honest test for any AI product near your kid isn't whether AI touched it. It's who's standing between the model and your kid, and what they're allowed to see about your family to do that job.
Whichever service you land on, keep the checklist. Ask the six questions, read the actual policy instead of the marketing page, and let a service earn a straight answer to all six before your kid's name is in it.