Skip to content

Kik investigation: Connecticut AG on sensitive data and age

Filip LuchianencoUpdated 3 min read

Last updated: 2026-10-03

On September 8, 2026, Connecticut Attorney General William Tong announced an investigation into MediaLab.AI Inc., owner of the Kik messaging app. The release announces a new civil investigative demand, a request for records on "MediaLab's data processing, content moderation and age assurance practices" under the Connecticut Data Privacy Act (CTDPA) and the Connecticut Unfair Trade Practices Act (CUTPA). The matter is at the investigation stage, and the release's statements about Kik are the Attorney General's allegations.

What is the Connecticut Attorney General investigating at Kik?

Data processing, content moderation and age assurance. On privacy, the release states:

The Office of the Attorney General first issued a notice of violation under the Connecticut Data Privacy Act (CTDPA) to MediaLab in July 2025, noting numerous deficiencies in Kik's privacy notices and consumer rights mechanisms. Those included the processing of sensitive data without first obtaining proper consent, including data related to race or ethnic origin, religious beliefs, health, sex life or sexual orientation, genetic data, biometric data, and precise geolocation data, among other violations.

Per the release, "the company has only partially addressed those privacy deficiencies despite repeated inquiries".

Is Kik safe for kids? What the Attorney General alleges

On age checks, the release states: "Today, Kik uses no technological tooling to monitor for underage users, relies on reactive review of reported or manually discovered content, and has conducted no audits or reviews of the effectiveness of its age determination processes."

Date Event, as stated in the AG release
September 2023 MediaLab "claims" it limited new Kik users to 18+
September 2024 Kik website still advertised the app as appropriate for children over 13
February 5, 2025 Terms of Service updated to restrict minors
February 8, 2025 Google Play listed Kik with a "Teen" rating
June 2025 Age restriction added to the privacy notice
July 2025 CTDPA notice of violation sent to MediaLab
After February 2026 Website description of Kik as an app for "young adults" removed
September 8, 2026 New civil investigative demand announced

On October 3, 2026, the Google Play listing (kik.android) showed "Mature 17+" and "100,000,000+" downloads, and the App Store listing showed "18+". MediaLab had not responded to NBC Connecticut's request for comment by the evening of September 8.

Which Connecticut rules cover sensitive data and minors?

In July 2025, § 42-520(a)(4) required a controller to "not process sensitive data concerning a consumer without obtaining the consumer's consent". Since July 1, 2026, § 42-520(a)(1)(D) also requires the processing to be "reasonably necessary" for its purposes. Sensitive data includes every category the Attorney General listed; the July 2025 text covered genetic and biometric data only when processed to uniquely identify an individual. Precise geolocation data is location accurate to within a 1,750-foot radius.

Where a controller has actual knowledge, or wilfully disregards, that a user is under 18, § 42-529a as amended from July 1, 2026 allows precise geolocation collection only where "strictly necessary" and with a signal to the minor for "the entire duration of such collection". A direct messaging feature offered to minors must have safeguards that, as a default setting, "prevent any adult from sending any unsolicited communication" to a minor unless the two are already connected. That clause excludes services whose "predominant or exclusive function" is direct messaging of text, photos or videos visible only to the sender and the recipient and "not posted publicly". Since October 1, 2026, Connecticut also bans the sale of precise geolocation data.

Under § 42-525, the Attorney General has "exclusive authority" to enforce the core CTDPA sections, a violation is an unfair trade practice under CUTPA, and there is no private right of action. § 42-529e sets the same terms for the minors' sections, § 42-529a included. Since January 1, 2025, an opportunity to cure a CTDPA violation is at the Attorney General's discretion. Where a court finds a wilful CUTPA violation, the Attorney General may recover a civil penalty of up to $5,000 for each violation (§ 42-110o(b)).

Has Kik been sued?

Yes, by Nevada. On August 15, 2025, the Nevada Attorney General filed State of Nevada v. MediaLab AI, Inc. and Kik, Case No. A-25-925766-C, in Clark County District Court. The Nevada release lists claims under the Nevada Deceptive Trade Practices Act, negligence, products liability and unjust enrichment. Filings after the complaint are on the Clark County docket.

Related: state app store age signal laws and the New Jersey Kids Code Act.

Kik app precise location data: what a CITT scan and capture show

When I scan a messaging app, the static report lists the location permissions declared in the manifest and the SDKs found in the binary, each with its file and line. Presence shows the code is in the build; only a capture shows that data was sent. A capture of sign-up and first session on a test device shows whether coordinates were sent, to which hosts, and whether a consent screen came first. The tester sets the test account's age, so a capture covers that one stated age. See what a scan checks and the limits of a scan.

I run these investigations for lawyers and for researchers working with lawyers, on one app or many in bulk. Sign up for a CanITrustThat (CITT) account to run your own research, let us run an investigation for you, or browse the scanned apps.

App privacy law, applied to real apps.

Posts on new laws, fines and studies, and teardowns of the apps those laws apply to.

How we use your address: privacy notice. Prefer a feed reader? Use the RSS feed.