Privacy Policy — Kidea

Effective date: March 10, 2025
Last updated: August 11, 2026

Kidea (“we”, “our”, or “us”) is a learning app designed for children and young people. This Privacy Policy explains what information we collect, how we use it, and your rights, especially for users under 13. Please read it with your child or teen if they use the app.

Kidea is operated by Esa Tanskanen, located in Finland, who acts as the data controller for the personal data described in this policy. For contact details, see section 12 (Contact).

By using Kidea, you agree to this Privacy Policy.


1. Introduction

Kidea is primarily intended for users aged approximately 7–18 years and their parents or teachers. We take privacy seriously and follow applicable laws, including the Children’s Online Privacy Protection Act (COPPA) in the United States and the General Data Protection Regulation (GDPR) in the European Union/EEA.

Kidea does not include sign-in or account creation. There is no username, password, or email address, and we never ask a child for one. The app also does not include an age-gate flow. Profile names are optional, and profile names are stored only on the device.

Kidea does use a small number of technical and analytics identifiers that are not tied to a real-world identity, and it includes usage analytics and crash reporting provided by Google Firebase. Sections 2.1, 2.7, and 5 explain exactly what that involves. Kidea does not collect the device advertising identifier on either platform, and ads shown in the app are non-personalised.


2. Information We Collect

“Personal information” means information that identifies an individual or a device—for example, an account identifier, name, email address, or similar data.

2.1 Technical identifiers for security and service operation

2.2 Information stored on your device

The following information is stored on your device and is not stored on our servers:

2.3 Information we store on our servers

When you use features that need our servers, we receive and store:

2.4 Content sent to create study materials

When you create or use study content (e.g. chapters, learning steps, songs, or adventures), we send to our servers the information needed to generate that content. When you create a chapter from photos of textbook or chapter pages, we send those images to our servers and to Google Cloud Vision for text extraction (OCR) only; the images are processed in memory and not stored by us or by Google for this purpose. For other study content we send only text and metadata—for example: chapter text, terms, definitions, bullet points, character descriptions, and language.

Text the learner writes. Some features send the learner’s own words to our servers and on to our AI provider so they can be responded to or assessed. This happens when the learner answers an exam question or a written exercise that the app asks the AI to grade, and when the learner takes part in the “Discussion with AI” language practice feature, where the conversation so far is sent with each turn so the AI can reply and give a correction. This text is processed to produce the answer, grade, or correction and is not stored on our servers after the request completes — the conversation and results are kept on your device. Please encourage learners not to type personal details (real names, addresses, contact details) into free-text fields; nothing in the app requires them.

All of the content described in this section is processed by our servers and by service providers (AI providers such as OpenAI for content generation and MusicGPT for music/song generation from lyrics, and cloud providers such as Google Cloud for infrastructure and services such as text-to-speech) to generate study materials, images, speech, or music. Content sent to our AI providers is used only to generate the requested study materials and is not used by us, or permitted to be used by them, to train AI models, in line with our agreements with those providers. We do not store photos you send for this purpose; they are processed only to generate the requested materials.

2.5 Optional “Share chapter”

If you choose to share a chapter, the app may upload a limited snapshot to our servers so we can give you a link for others to open in Kidea. That snapshot includes only transformed study aids from chapter creation—for example book and chapter names as labels, summary, key points and terms from the initial chapter bundle, and language—not full book text, photos, audio, your profile name, grades, or other personal results, and not separate “all terms” or “all bullets” expansions. We do not upload original source pages or copyrighted body text. We store that snapshot for approximately 30 days, after which it is deleted. Sharing is voluntary; recipients need the app to use the link as intended.

2.6 In-app feedback

The app may invite you to send feedback — for example about your experience or about the contents of a chapter. This is entirely voluntary; you can dismiss the prompt and keep using the app.

If you do send feedback, we store the text you wrote, a label identifying which part of the app it came from, the time it was sent, and your installation identifier (so we can recognise duplicate or abusive submissions). We use it to understand problems and improve the app. Feedback is readable by us in an internal admin view, and batches of recent feedback may be sent to our AI provider (OpenAI) to produce a short summary for us.

Please do not type personal information into the feedback box — we do not need your name, address, school, or contact details to act on feedback. If a child sends feedback containing personal details, a parent or guardian can ask us to delete it using the contact details in section 12.

2.7 Analytics and crash diagnostics

Kidea uses Google Firebase for product analytics, crash reporting, and remote configuration. This helps us see which features are used and where the app breaks. It is not used for advertising, for building profiles about learners, or for tracking anyone across other apps or websites.

No advertising identifier. The app is configured so that no advertising ID is collected on Android (the AD_ID permission is removed from the app) or on iOS, and analytics data is not linked to advertising.

On iOS, Kidea uses Firebase Analytics and Remote Config; crash reporting via Crashlytics is currently used on Android only.


3. How We Use the Information

We use the information we collect to:

We do not use personal information for advertising directed to children beyond what is permitted under child-directed ad policies (e.g. contextual, non-personalized ads). We do not sell personal information, and we do not use your content or your child’s content to train AI models.

3.1 Our legal bases (EU/EEA)

If you are in the EU or EEA, the GDPR requires us to have a legal basis for each purpose. Ours are:

PurposeLegal basis
Providing the study features you ask for (creating chapters, exercises, speech, songs, grading answers, AI practice conversations)Performance of a contract — Art. 6(1)(b)
Processing purchases and subscriptions, applying school codes, and keeping entitlements correctPerformance of a contract — Art. 6(1)(b)
App attestation, fraud and abuse prevention, usage limits, server logs, and service securityLegitimate interests — Art. 6(1)(f): protecting the service and other users from abuse and controlling the cost of generation
Product analytics and crash diagnostics (section 2.7)Legitimate interests — Art. 6(1)(f): understanding which features are used and fixing faults
Showing non-personalised, child-directed ads on the ad-supported tierLegitimate interests — Art. 6(1)(f): funding a free tier without tracking or profiling users
Sharing a chapter, and sending feedbackConsent — Art. 6(1)(a); you choose to start each of these, and you may withdraw by asking us to delete the data
Keeping records we are legally required to keep (for example accounting records for purchases)Legal obligation — Art. 6(1)(c)

Where we rely on legitimate interests, we have weighed those interests against the rights of our users, and we take particular account of the fact that many of them are children. That is why analytics is limited to app usage and diagnostics, why no advertising identifier is collected, why ads are non-personalised, and why we do not profile learners or track them across other services. You have the right to object to processing based on legitimate interests — see section 7.


4. Where Data Is Stored


5. Third Parties and Subprocessors

ServicePurposePrivacy / policies
Google AdMobNon-personalized, child-directed adsGoogle Privacy Policy, Families policy
Google PlayIn-app purchases and billing (Android); Play Integrity app attestation (Android)Google Play terms
Google Firebase — AnalyticsApp usage analytics (no advertising ID, no cross-app tracking)Firebase Privacy & Security
Google Firebase — CrashlyticsCrash and error diagnostics (Android)Firebase Privacy & Security
Google Firebase — Remote ConfigDelivering feature settings to the appFirebase Privacy & Security
Google Cloud FirestoreStoring entitlements, usage limits, rewarded-ad records, and feedbackGoogle Cloud Privacy
Apple App StoreIn-app purchases and billing (iOS); App Attest app attestation (iOS)Apple Privacy Policy
Google Cloud VisionOCR for creating study materials from photos of pagesGoogle Cloud Privacy
OpenAIAI content generationOpenAI Privacy Policy
MusicGPTMusic/song generation from lyricsMusicGPT Privacy Policy
Google CloudInfrastructure, TTS, other servicesGoogle Cloud Privacy
Spotify (optional)Optional music integrationSpotify Privacy Policy (if used)

We do not sell personal information. Photos sent for OCR are processed in memory and are not stored by us or our service providers.


6. Parents’ Rights

Users under 13

Kidea is designed to minimize personal-data collection for all users, including children under 13. Kidea does not include sign-in, account creation, or an age-gate flow, and we do not knowingly collect a child’s name, email address, postal address, phone number, precise location, photographs of the child, or any other directly identifying personal information. The app never asks for any of these.

We use technical identifiers for internal operations such as security, fraud prevention, usage limits, and service integrity, and for the app analytics and crash diagnostics described in section 2.7. Analytics is limited to app usage and fault diagnosis: no advertising identifier is collected, ads are non-personalised, and we do not build behavioural profiles of children or track them across other apps or websites.

Users are not required to provide more personal information than is necessary. For example, a profile name is optional and never leaves the device.

The one place where a child could type personal information into Kidea is a free-text field — the feedback box (section 2.6) or a written exercise answer (section 2.4). None of these require personal details, and we ask that they not be entered. If you believe a child has submitted personal information to us, contact us using the details in section 12 and we will delete it.

Your rights as a parent or guardian

You may:

To do any of this, please contact us using the details in section 12. We will respond within a reasonable time (e.g. as required by law, such as within 30 days under COPPA).


7. Your Data Protection Rights (EU/EEA)

Depending on your location, you may have the right to:

You also have the right to withdraw consent at any time where we rely on it (for example for a shared chapter or for feedback you sent), without affecting processing that already took place. See section 3.1 for which basis applies to which purpose.

In Finland, the supervisory authority is the Office of the Data Protection Ombudsman.

To exercise these rights — including objecting to analytics or to any other processing based on legitimate interests — contact us using the details in section 12 (Contact). Because Kidea has no accounts, please tell us which installation you mean; we may need to ask you for the installation identifier shown in the app so we can find the right records, and if we cannot identify any data as yours we may not be able to act on the request.


8. Retention and Deletion


9. Security

We use reasonable technical and organizational measures to protect the information we process—for example, secure connections (HTTPS), access controls, and secure storage. No system is completely secure; we encourage you to use a secure device and to keep account and device access limited to trusted persons.


10. App Permissions


11. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the current version at https://www.dancingmanatee.com/kidea/privacy.html (and in the app where applicable). Where required by law, we will notify you of significant changes (e.g. in the app or by email). The “Last updated” date at the top shows when the policy was last revised.


12. Contact

Data controller: Esa Tanskanen (individual trader), Finland

For privacy questions, parental requests (access, deletion, or refusal of further collection), or any concern about your or your child’s data:

We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. Privacy requests are handled by the controller directly at the address above.

We will respond as required by applicable law (e.g. COPPA in the United States, GDPR in the EU/EEA — normally within one month).


This policy is designed for users and parents. If you need it in another language or format, please contact us. This policy is provided in English; translations, if any, are for convenience and the English version prevails in case of conflict, except where mandatory local law requires otherwise.