Ready for COPPA 2.0? Scan your app for privacy violations and dark patterns before the April 22, 2026 deadline.
Legacy compliance tools scan for cookies. Halo scans for liability.
Detect illegal SDKs, unauthorized data collection, missing consent flows, and biometric data leakage. 20 rules covering the full COPPA 2.0 Final Rule.
Catch dark patterns, manipulative UI, infinite scroll, streak pressure, and attention-hijacking mechanics. Go beyond compliance to conscience.
Add runhalo scan to your GitHub Actions. Continuous compliance on every PR. Catch violations before they ship.
Safe Harbor certification costs $15k+. Halo is free. Run it before you pay for the audit — fix the obvious issues first.
Here's what we found.
MIT · Ages 8-16
Unauthorized audio recording: getUserMedia({audio: true})
2 unwarned external links in child-facing views
Tufts/MIT · Ages 5-7
Direct microphone access: new AudioRecord(MIC)
Open Source LMS
7 audio/tracking issues including UGC without PII filtering
7 unwarned external links to social media
COPPA 2.0 enforcement begins April 22, 2026. Penalties are assessed per child, per day. A platform with 10,000 underage users that collected data without consent for 30 days faces a theoretical maximum of $16.3 billion.
The FTC isn't waiting. Disney settled for $10M in December 2025. IXL Learning and PowerSchool face active litigation right now.
Don't wait for a Civil Investigative Demand.
| Category | Old Rule | New Rule |
|---|---|---|
| Personal Info | Name, email, identifiers | Now includes biometrics (voice, face, gait) |
| Audience | "Child-Directed" only | New "Mixed Audience" — if kids can access it, you're liable |
| Data Retention | "Reasonably necessary" | Strict necessity with explicit timeframes |
| Safe Harbor | Self-regulatory programs | Tighter oversight, public membership disclosure |
Check the boxes that apply to your product.
No signup. No config. Just scan.
npx runhalo scan .
Each finding includes the rule, penalty, and fix suggestion
Add to CI/CD for continuous compliance on every PR
CLI, 20 COPPA rules, VS Code extension, JSON/SARIF output, .haloignore
Pro features coming soon — CI/CD dashboard, compliance reports, scan history
COPPA compliance is the floor, not the ceiling. Halo's ethical design linter catches dark patterns, manipulative mechanics, and attention-hijacking — the things regulation hasn't caught up with yet.
npx runhalo scan . in any Node.js project. Pro features (CI/CD dashboard, compliance reports, scan history) are coming soon.