1. Controller and privacy contact
The operator identified in the provider box and legal notice is the controller under the General Data Protection Regulation. Privacy enquiries may be sent to the email address shown there.
Where a request concerns a child profile, Kumilo normally handles it through the adult who manages the family account. Kumilo may perform a proportionate identity and authority check before disclosing, changing or deleting family data. Do not email passwords, one-time codes, children's photos or conversation content.
2. A short explanation for children
Kumilo needs some information to explain a question at the right level, such as your nickname, age level, language and what you type, say or show in an allowed object photo. Artificial-intelligence computer programs help create and safety-check the answer, story or illustration.
An adult manages your profile. You do not need your own email address, and you should never enter your full name, address, passwords, documents or other private secrets. You can always ask a trusted adult what is stored or ask them to delete something.
3. Website, contact and necessary technical data
When the website is requested, its host Vercel processes necessary connection and security data such as IP address, time, requested URL, browser or device information and error data. This is needed to deliver the site, keep it stable and defend it from attacks. The website currently loads no advertising, audience-measurement or social-media scripts and sets no non-essential tracking cookies. Necessary storage may operate without a choice banner where it is used solely to provide the website requested by the visitor.
When someone emails Kumilo, the sender address, content, attachments and delivery data are processed to answer the request, prevent abuse and keep any necessary evidence. Support messages should not contain children's content or credentials. They are retained only for handling, evidence and legal obligations.
4. Parent account, sign-in, sessions and devices
For a connected parent account, Kumilo processes an internal account ID, status and timestamps and, depending on the enabled sign-in method, the provider, provider subject, verified email address and technical audience. Email addresses and necessary provider tokens are encrypted on the server; sessions use hashed refresh tokens. Google sign-in is supported, while Apple or passwordless email data is processed only when that method is actually enabled for the relevant platform.
For device binding, integrity checks and abuse prevention, Kumilo processes a hashed installation ID, platform, app, package and build versions, last-seen time, session information and device or store-integrity results. App sign-in and installation secrets are held in protected device storage.
Kumilo keeps versioned records of the managing adult's permissions, including consent type, policy version, language, time and, where applicable, country and trust evidence from the sign-in route. Permission may be withdrawn for the future; a required core function may then no longer be available.
5. Child profiles and information supplied by adults
Children do not have independent login accounts. The managing adult may provide a nickname, optional birth year, resulting age band, language, avatar colour, settings and permissions for voice, photos and other features. A child's full name, email address and exact home address are not required.
This profile information usually comes from the managing adult. It is used to organise the family, adapt wording and presentation, synchronise approved devices and enforce parental choices. Use a nickname that does not directly identify the child outside the family.
6. Questions, AI answers, photos and voice
Text questions, selected profile and conversation context, and derived instructions are sent through the Kumilo backend to OpenAI to moderate input, identify intent and safety risks, and create age-adapted answers, discoveries, stories or follow-up questions. Kumilo attempts to remove obvious contact details and secrets first, but those filters cannot recognise every private detail.
An allowed photo is resized, reoriented and re-encoded as a new JPEG on the server. It passes privacy and safety checks, is sent to OpenAI for moderation and explanation and, only when needed as an image reference, is placed briefly in private Cloudflare R2 storage and supplied to fal.ai through a signed URL that lasts only a few minutes. The raw photo is not stored as a discovery attachment; a deletion queue and time-based fallback remove the temporary copy.
In voice mode, microphone audio is transmitted to OpenAI during a time-limited Realtime session. Kumilo does not retain raw audio or a separate full transcript on its server. The question text derived from a spoken turn is nevertheless handled like a typed question and may remain in the encrypted local chat and, where the guardian has approved synchronisation, in the encrypted family chat history.
Image prompts and, where selected, the temporary reference are sent to fal.ai and the selected Google image model. The Kumilo backend retrieves and normalises the generated image and stores it privately; the app receives only a short-lived download URL. Answers and images are checked automatically. These checks and AI outputs are not decisions that produce legal or similarly significant effects within Article 22 GDPR.
7. Personalisation, local app data and discoveries
Kumilo stores completed structured discoveries containing their title, subject, explanation, facts, quiz, follow-up questions and, where applicable, a private image key. There is no separate server field for the original raw question, although a subject or generated result may still reveal what the question concerned.
Profiles, chats, answers and gallery entries are encrypted on the device. A raw image URI is not written into the persisted local chat. After explicit cloud-synchronisation approval, Kumilo also stores the bounded family chat history encrypted on its servers so it can be restored on another authorised device. The database does not contain the plaintext. The application cleanup exempts private image files while a saved chat references them, but the current independent R2 storage rule may still remove server-generated images after approximately 35 days. An older synchronised chat may therefore remain without its image. Local chats remain until the managing adult deletes them or technical capacity limits remove older items; gallery objects are normally removed after 30 days or when the gallery limit is exceeded.
8. Safety, usage and operational metadata
For safety, cost control, fault diagnosis and limited product operations, Kumilo stores pseudonymous family, installation, session or profile IDs together with feature, input type, language, age band, provider, model, token and cost counts, latency, success or error. Safety events contain the review stage, decision and abstract categories. These tables contain no raw questions, images, audio or full transcripts.
When the managing adult reports an AI output as problematic, Kumilo stores the reported generated output — such as its title, answer text and limited visual metadata — together with the report category, source and content type, language, age band, pseudonymous family, installation, profile, message and report identifiers, a content fingerprint, review status and timestamps. This is used to examine the specific report, investigate safety issues and document its handling. The report does not additionally contain the original raw question, uploaded photo, audio or a transcript and is normally deleted after 90 days.
Backend and infrastructure logs may also contain IP address, timestamp, route, status, device or browser characteristics and technical errors. Application logs redact secrets, authentication headers, signed URLs and image data. Logs are retained in accordance with data minimisation only as long as required for operation, security, fault analysis or legal evidence.
9. Purchases and store data
If paid products are enabled, Kumilo processes a pseudonymous billing owner, store, product, transaction and subscription status, purchase and entitlement dates, hashed or encrypted store tokens and limited store evidence. Kumilo does not receive payment-card details; Apple, Google or the merchant identified in the checkout handles payment. This processing does not occur while billing is disabled.
10. Purposes and legal bases
Kumilo processes necessary account, profile, input, session and billing information to enter into and perform the contract with the managing adult and to take requested pre-contract steps under Article 6(1)(b) GDPR. Statutory retention, disclosure and protection duties rely on Article 6(1)(c).
Operational security, fraud and abuse prevention, minimal fault analysis, deletion enforcement and the establishment or defence of legal claims rely on Article 6(1)(f). The legitimate interests are a safe, economically operable and accountable service; because children merit particular protection, content is minimised, access is restricted and short default periods are used.
Where optional camera, microphone, synchronisation or other processing legally requires consent, it relies on Article 6(1)(a) together with Article 8 GDPR and applicable national rules. Device access also follows the applicable terminal-equipment rules. Consent is voluntary and may be withdrawn for the future without affecting earlier lawful processing. A requested AI feature cannot work without the data necessary to provide it.
11. Recipients and processors
Only personnel and providers that need information for the relevant purpose receive it. Credentials for AI and infrastructure services remain exclusively on the Kumilo backend.
- Hetzner: servers, API and encrypted database in Germany.
- Cloudflare R2: private object storage with the EU jurisdiction selected for temporary references and generated images.
- Amazon Web Services: encrypted recovery backups and, only when enabled, delivery of parent email in the Frankfurt region.
- OpenAI: Moderation, Responses and Realtime processing of necessary text, image and voice input.
- fal.ai and selected image models: illustrations from a prompt and, where applicable, a temporary private reference.
- Vercel: static website delivery and technical security data.
- Google and Apple: depending on platform, sign-in, device integrity, app distribution and store billing; an email provider only if an email route is enabled.
12. Processing outside the EU and provider retention
Not all processing takes place exclusively within the European Union. For transfers to recipients in third countries, Kumilo uses, depending on the recipient and its status, an adequacy decision including a valid EU-US Data Privacy Framework certification or EU Standard Contractual Clauses with supplementary risk assessment. A copy of, or information about, relevant safeguards may be requested through the privacy contact.
OpenAI is currently used through the standard global API endpoint; neither exclusive EU data residency nor Zero Data Retention is enabled for Kumilo. Kumilo sets store=false and background=false for Responses and disables Realtime tracing and optional application-supplied prompt-cache keys. OpenAI does not train its models on API content under its API terms, but may retain standard abuse-monitoring logs for up to 30 days and exceptionally longer for safety or legal duties. store=false is not a ZDR commitment.
For fal.ai, Kumilo requests no durable input or output storage, uses private access and short object lifetimes. The exact processing region and actual downstream partner-model retention are not currently confirmed as exclusively European or immediate deletion. Kumilo therefore makes no broader promise about those points.
13. Retention periods
Kumilo deletes or anonymises information when its purpose ends unless an overriding duty or documented protection need applies. The current technical configuration uses these principal periods:
- Access tokens: 10 minutes; refresh tokens: normally 30 days; absolute account session: no more than 90 days.
- Temporary image reference: signed access for a few minutes; deletion immediately after processing, with a technical fallback after approximately one hour at the latest.
- Structured discoveries: 30 days. Server-generated images that are not referenced by a saved, cloud-synchronised family chat enter the application cleanup after 30 days. A chat reference exempts an image from that cleanup, but the current independent R2 storage rule may still remove server-generated images after approximately 35 days. Image availability is therefore not promised until chat, profile or account deletion.
- Realtime session and completed provider-operation data: 30 days; no server-side raw audio recording.
- Pseudonymous AI-usage and safety metadata: 90 days.
- AI content reports submitted by the managing adult, including the reported output and limited identifier and review metadata: 90 days. Deleting only the affected child profile does not immediately remove an existing report; its direct profile link is cleared and the report remains available for safety review until expiry. Deleting the family account removes the report.
- Encrypted provider tokens in a failed revocation queue: no more than 7 days.
- Billing and claim evidence for enabled purchases: normally up to 400 days after the later of deletion or entitlement end; mandatory statutory periods may take priority.
- Encrypted local chats: until manual deletion, account deletion on that device or displacement by technical capacity limits. Encrypted family chat history: until manual deletion, deletion of the related child profile or deletion of the family account. Local gallery objects normally 30 days.
- Support and technical access logs: according to handling, security and statutory needs, kept as briefly as reasonably possible.
14. Deletion, backups and necessary deletion markers
A child profile can be deleted separately in the protected parent area. Related profiles, consents, discoveries and private objects are deleted or placed into durable deletion queues. An AI content report that has already been submitted is not immediately removed by profile deletion alone: its direct profile link is cleared and it remains available for safety review until its 90-day period expires. Family-account deletion requires recent reauthentication and also removes those reports; provider links are revoked where possible. Local information on other disconnected devices must also be removed on those devices. Deleting an account does not automatically cancel a store subscription, which must be cancelled in the relevant store.
Encrypted database backups roll off within 35 days. They are used only for recovery, not as an active archive, and recorded deletions are reapplied after a restoration.
After account deletion, type-separated, repeatedly hashed deletion markers remain without a family, account or clear-text identifier. Session and refresh markers expire within 400 days. A hashed installation marker and an unlinkable technical deletion receipt currently have no scheduled expiry so that a long-offline device cannot recreate a deleted family and completed deletion can be proven. The original identifiers cannot practicably be reconstructed from these digests.
15. Rights and complaints
Subject to applicable law, individuals have rights including access, correction, erasure, restriction, portability and objection. Consent may be withdrawn at any time for the future. Where processing relies on legitimate interests, a person may object for reasons relating to their particular situation; Kumilo will continue only where compelling grounds or legal claims justify it.
Requests may be made through the privacy contact. A complaint may also be lodged with a data-protection authority, particularly in the place of residence, place of work or place of the alleged infringement. Exercising rights is free unless a request is manifestly unfounded or excessive.
16. Children, countries and guardian-managed access
Kumilo is designed for adult-managed profiles for ages 4 to 16. Children do not have independent accounts. The managing adult creates the family account and child profiles, signs in, chooses the settings and provides the permissions presented in the product; Kumilo records those permissions against the applicable policy version. That person must have the parental responsibility and authority required where they live. Age limits, consent requirements and available features may differ by country.
The service is not currently blocked solely because it is accessed from the United States or the United Kingdom or because an age band includes a child under 13. The current account and permission flow is a guardian-managed product control; it is not a government identity check and is not represented as replacing every country-specific verifiable-parental-consent or age-assurance procedure. The managing adult may use Kumilo only where doing so is lawful for them. Kumilo may adjust safeguards, features or availability where a legal or technical assessment requires it.
17. No advertising, data sale or significant AI decisions
Kumilo does not sell personal information, share it for cross-context behavioural advertising or show personalised advertising to children. It does not build advertising profiles across other websites or apps, so a browser Do Not Track signal does not currently trigger any additional advertising processing.
Age level, language and recent conversation context affect only presentation and explanation within the learning service. Kumilo does not use them to make an automated decision about a contract, school grade, access to education or another outcome with legal or similarly significant effect.
18. Security and changes
Safeguards include encrypted local storage, encrypted sensitive server fields and backups, separate server-side credentials, private object storage, short-lived download URLs, role and network controls, input and output checks, minimised data and limited logging. No technical measure can guarantee absolute security.
Kumilo updates this notice when purposes, providers, features, law or retention materially change. Material changes will be clearly presented in the app or on the website and, where required, submitted for renewed consent. Earlier processing remains assessed under the legal basis that applied at that time.