Privacy policy
Last updated: 6 October 2026.
Who we are
Kalimo is a reading app for children aged 4 to 10. The account belongs to the parent: a child has no account, no email address and no password.
Data controller: the publisher of the Kalimo app, reachable at contact@kalimoapp.com.
In short
- No advertising and no selling of data. The only measurements handled by another company are app launch counts and crash reports, with Expo (see below).
- The app does not read the phone's advertising ID.
- Kalimo never records your child's voice.
- You can delete your account and all your children's data at any time, in the app or by email.
The parent's data
- Email address, first name and last name: to create and manage the account, and to send the verification and new-password emails.
- Password: never kept in readable form. It is kept hashed by SuperTokens, the sign-in service we host ourselves on our server.
- If you turn notifications on (they are off by default): the phone's notification address (an Expo token), the app's language and the phone's time zone, to send at most one reading reminder a day, at a suitable time, and to announce new stories for your children's class; and the kinds of message you chose. The log of reminders sent (the day and the kind of message) is erased after 30 days; the list of stories already announced is kept while the account and the story exist, so the same one is never announced twice.
The child's data
For each profile, the parent gives:
- a nickname, which does not need to be the child's real first name;
- an avatar: the colour of a parrot, picked from a list, never a photo;
- the school year, from CP to CM2 (French primary school years). We ask for neither age nor date of birth.
While the app is used, it records:
- progress in each story, and favourite stories;
- coins earned and spent, and the parrot companion (its name, outfits, scenery and food);
- words misread, counted per day and erased after 30 days;
- read-aloud accuracy (the number of words read correctly and of words read, per level);
- how long read-aloud listening ran, per day;
- the days the child read (one date per day, nothing else), for their reading week and streak;
- a narration speed suited to the child (a single number).
This data runs the app and shows the parent how each child is progressing. We never collect the child's real name, email address, phone number, date of birth, photo or location.
It is kept as long as the account exists and erased with it. An inactive account is not deleted automatically: you can delete it at any time.
The child's voice
During read-aloud, the microphone's sound is streamed live, through Kalimo's server, to Deepgram, a speech recognition service, on its European endpoint (api.eu.deepgram.com). It is used to recognise the words read, to colour them on screen.
- Kalimo never records this sound: it passes through our server without being stored.
- We ask Deepgram not to use this sound to train its models (the
mip_opt_outoption). According to Deepgram's documentation, data from these requests is retained only for the duration necessary to process them. - Deepgram also receives the proper names on the page being read (words from the story), never the child's nickname or anything about the child or you.
- Kalimo keeps only the daily listening time, the read-aloud accuracy and the misread words described above.
The story voices
Stories are told by synthetic voices from Cartesia and ElevenLabs. These services receive only the story's text, the chosen voice and the language, never any data about you or your children.
How the app runs
The app uses two tools from Expo, the platform it is built on:
- Expo Insights, at each launch: a random identifier for the installation, the app version, the phone's system and its version. Expo also sees the IP address.
- EAS Observe: the same kind of random identifier, start-up timings, the phone model, its system, battery and network type; after a crash, the error message, its technical trace and the country.
No child, no parent and no screen is attached to either.
Notifications
They are off by default. If you turn them on in the parent area, messages go through Expo's notification service, then through Google (Firebase Cloud Messaging) on Android or Apple on iPhone. Firebase uses an installation identifier, which is not the advertising ID. A message never contains the child's nickname or anything about their reading; it may contain the parrot's name. It also carries, without showing it, the technical id of the profile it is about, so the app opens in the right place: that code says nothing about the child. To choose that profile, we compare how many pages each child read in the week, without storing anything more.
Emails
The verification and new-password emails are sent by Brevo, which receives your address and the message. They show a picture of the parrot, the same for everyone, which cannot tell us whether you opened the email.
Hosting and storage
- Kalimo's server (the app's server, the database and the sign-in service) is a virtual private server rented from Hostinger, located in France (Paris).
- Illustrations, story voices and the words those voices speak are stored with Backblaze B2, in a United States region. This storage holds no data about you or your children.
- The server keeps technical logs to run and stay secure. They never contain the child's voice. A server backup, if one exists, may hold the account's data for as long as it is kept. No period is set yet for these logs and backups.
- Some providers are based outside the European Union, mainly in the United States: Expo, Google, Apple, Cartesia, ElevenLabs, Deepgram (which receives the voice on its European endpoint) and Backblaze (which stores no data about you).
Who can see your data
The Kalimo team, from its administration console, can find an account by its email address to help you, export it, correct it or delete it. Each of these actions is written to a log that keeps the account's internal identifier and the names of the fields changed, never their content.
Deleting your account
In the app, in the parent area, or without the app, by writing to us: the steps are on the Delete your account page. Deleting erases the account, your children's profiles and everything attached to them.
Why we process this data
- The account, the children's profiles, read-aloud and the account emails: to provide the service you ask for by creating an account.
- Notifications: with your consent, which you withdraw by turning them off in the parent area.
- Launch counts and crash reports: our legitimate interest in running the app and fixing its errors.
- A child's data is given by their parent, who creates and manages the child's profile from their own account.
Your rights
You can ask for access to your data, a copy, a correction or its deletion, or object to a processing, by writing to contact@kalimoapp.com. You can also complain to the CNIL, the French data protection authority (cnil.fr).