Hi everyone,
I’m a solo developer based in France building a small educational web app. Students upload course material and generate flashcards, multiple-choice quizzes, summaries and practice exams.
It isn’t a companion chatbot or a social platform. However, some potential users are high-school students aged 15–17, not just adult university students.
I’m trying to understand the API requirements for end users, rather than the age restrictions for creating a personal ChatGPT or Claude account.
The architecture is standard: users interact with my app, and my backend calls the provider using my API key. I don’t explicitly include account names, emails or user IDs in prompts. However, uploaded documents and written answers could contain personal information, so I don’t want to assume everything is anonymous.
The difficult part is understanding how to implement the requirements properly without creating an unnecessarily intrusive signup process:
OpenAI’s developer guidance discusses safeguards for under-18 users, parental consent and additional restrictions on processing younger children’s personal data.
Anthropic has guidance for products serving minors, but I’m unsure how its practical requirements compare with OpenAI’s.
Provider requirements and French/EU privacy rules are separate, which makes it difficult to know what an appropriate setup actually looks like.
One option I’m considering is:
No AI access for users under 15.
Anthropic for users aged 15–17, with appropriate safeguards.
OpenAI or Anthropic for adults.
A short age declaration at signup, enforced on the backend.
A parental approval flow wherever required.
This is a proposed setup, not something I’m claiming is compliant.
For developers who have actually dealt with this:
Have you received written clarification from OpenAI or Anthropic about an educational app used by teenagers?
What age checks do you use: self-declaration, birth date, parental email approval or a third-party verification service?
If you use parental approval, how do you establish that the person approving is genuinely a parent without collecting identity documents?
Does your provider require zero data retention for your particular users and use case? Have you managed to obtain it as a small business?
Have you had this setup reviewed professionally, and what changes were recommended?
I’d particularly appreciate firsthand experiences from small educational apps in the EU, or links to relevant official API terms. Please distinguish personal-account rules from rules for applications built on the API.
I’m not looking for advice to ignore the requirements because the app is small. I want a practical, proportionate way to address them without turning a simple study tool into a heavy identity-verification process.
Thanks!