Kidea (“we”, “our”, or “us”) is a learning app designed for children and young people. This Privacy Policy explains what information we collect, how we use it, and your rights, especially for users under 13. Please read it with your child or teen if they use the app.
Kidea is operated by Esa Tanskanen, located in Finland, who acts as the data controller for the personal data described in this policy. For contact details, see section 12 (Contact).
By using Kidea, you agree to this Privacy Policy.
Kidea is primarily intended for users aged approximately 7–18 years and their parents or teachers. We take privacy seriously and follow applicable laws, including the Children’s Online Privacy Protection Act (COPPA) in the United States and the General Data Protection Regulation (GDPR) in the European Union/EEA.
Kidea does not include sign-in or account creation. There is no username, password, or email address, and we never ask a child for one. The app also does not include an age-gate flow. Profile names are optional, and profile names are stored only on the device.
Kidea does use a small number of technical and analytics identifiers that are not tied to a real-world identity, and it includes usage analytics and crash reporting provided by Google Firebase. Sections 2.1, 2.7, and 5 explain exactly what that involves. Kidea does not collect the device advertising identifier on either platform, and ads shown in the app are non-personalised.
“Personal information” means information that identifies an individual or a device—for example, an account identifier, name, email address, or similar data.
AD_ID permission and does not collect an advertising identifier on either platform.The following information is stored on your device and is not stored on our servers:
When you use features that need our servers, we receive and store:
When you create or use study content (e.g. chapters, learning steps, songs, or adventures), we send to our servers the information needed to generate that content. When you create a chapter from photos of textbook or chapter pages, we send those images to our servers and to Google Cloud Vision for text extraction (OCR) only; the images are processed in memory and not stored by us or by Google for this purpose. For other study content we send only text and metadata—for example: chapter text, terms, definitions, bullet points, character descriptions, and language.
Text the learner writes. Some features send the learner’s own words to our servers and on to our AI provider so they can be responded to or assessed. This happens when the learner answers an exam question or a written exercise that the app asks the AI to grade, and when the learner takes part in the “Discussion with AI” language practice feature, where the conversation so far is sent with each turn so the AI can reply and give a correction. This text is processed to produce the answer, grade, or correction and is not stored on our servers after the request completes — the conversation and results are kept on your device. Please encourage learners not to type personal details (real names, addresses, contact details) into free-text fields; nothing in the app requires them.
All of the content described in this section is processed by our servers and by service providers (AI providers such as OpenAI for content generation and MusicGPT for music/song generation from lyrics, and cloud providers such as Google Cloud for infrastructure and services such as text-to-speech) to generate study materials, images, speech, or music. Content sent to our AI providers is used only to generate the requested study materials and is not used by us, or permitted to be used by them, to train AI models, in line with our agreements with those providers. We do not store photos you send for this purpose; they are processed only to generate the requested materials.
If you choose to share a chapter, the app may upload a limited snapshot to our servers so we can give you a link for others to open in Kidea. That snapshot includes only transformed study aids from chapter creation—for example book and chapter names as labels, summary, key points and terms from the initial chapter bundle, and language—not full book text, photos, audio, your profile name, grades, or other personal results, and not separate “all terms” or “all bullets” expansions. We do not upload original source pages or copyrighted body text. We store that snapshot for approximately 30 days, after which it is deleted. Sharing is voluntary; recipients need the app to use the link as intended.
The app may invite you to send feedback — for example about your experience or about the contents of a chapter. This is entirely voluntary; you can dismiss the prompt and keep using the app.
If you do send feedback, we store the text you wrote, a label identifying which part of the app it came from, the time it was sent, and your installation identifier (so we can recognise duplicate or abusive submissions). We use it to understand problems and improve the app. Feedback is readable by us in an internal admin view, and batches of recent feedback may be sent to our AI provider (OpenAI) to produce a short summary for us.
Please do not type personal information into the feedback box — we do not need your name, address, school, or contact details to act on feedback. If a child sends feedback containing personal details, a parent or guardian can ask us to delete it using the contact details in section 12.
Kidea uses Google Firebase for product analytics, crash reporting, and remote configuration. This helps us see which features are used and where the app breaks. It is not used for advertising, for building profiles about learners, or for tracking anyone across other apps or websites.
No advertising identifier. The app is configured so that no advertising ID is collected on Android (the AD_ID permission is removed from the app) or on iOS, and analytics data is not linked to advertising.
On iOS, Kidea uses Firebase Analytics and Remote Config; crash reporting via Crashlytics is currently used on Android only.
We use the information we collect to:
We do not use personal information for advertising directed to children beyond what is permitted under child-directed ad policies (e.g. contextual, non-personalized ads). We do not sell personal information, and we do not use your content or your child’s content to train AI models.
If you are in the EU or EEA, the GDPR requires us to have a legal basis for each purpose. Ours are:
| Purpose | Legal basis |
|---|---|
| Providing the study features you ask for (creating chapters, exercises, speech, songs, grading answers, AI practice conversations) | Performance of a contract — Art. 6(1)(b) |
| Processing purchases and subscriptions, applying school codes, and keeping entitlements correct | Performance of a contract — Art. 6(1)(b) |
| App attestation, fraud and abuse prevention, usage limits, server logs, and service security | Legitimate interests — Art. 6(1)(f): protecting the service and other users from abuse and controlling the cost of generation |
| Product analytics and crash diagnostics (section 2.7) | Legitimate interests — Art. 6(1)(f): understanding which features are used and fixing faults |
| Showing non-personalised, child-directed ads on the ad-supported tier | Legitimate interests — Art. 6(1)(f): funding a free tier without tracking or profiling users |
| Sharing a chapter, and sending feedback | Consent — Art. 6(1)(a); you choose to start each of these, and you may withdraw by asking us to delete the data |
| Keeping records we are legally required to keep (for example accounting records for purchases) | Legal obligation — Art. 6(1)(c) |
Where we rely on legitimate interests, we have weighed those interests against the rights of our users, and we take particular account of the fact that many of them are children. That is why analytics is limited to app usage and diagnostics, why no advertising identifier is collected, why ads are non-personalised, and why we do not profile learners or track them across other services. You have the right to object to processing based on legitimate interests — see section 7.
| Service | Purpose | Privacy / policies |
|---|---|---|
| Google AdMob | Non-personalized, child-directed ads | Google Privacy Policy, Families policy |
| Google Play | In-app purchases and billing (Android); Play Integrity app attestation (Android) | Google Play terms |
| Google Firebase — Analytics | App usage analytics (no advertising ID, no cross-app tracking) | Firebase Privacy & Security |
| Google Firebase — Crashlytics | Crash and error diagnostics (Android) | Firebase Privacy & Security |
| Google Firebase — Remote Config | Delivering feature settings to the app | Firebase Privacy & Security |
| Google Cloud Firestore | Storing entitlements, usage limits, rewarded-ad records, and feedback | Google Cloud Privacy |
| Apple App Store | In-app purchases and billing (iOS); App Attest app attestation (iOS) | Apple Privacy Policy |
| Google Cloud Vision | OCR for creating study materials from photos of pages | Google Cloud Privacy |
| OpenAI | AI content generation | OpenAI Privacy Policy |
| MusicGPT | Music/song generation from lyrics | MusicGPT Privacy Policy |
| Google Cloud | Infrastructure, TTS, other services | Google Cloud Privacy |
| Spotify (optional) | Optional music integration | Spotify Privacy Policy (if used) |
We do not sell personal information. Photos sent for OCR are processed in memory and are not stored by us or our service providers.
Kidea is designed to minimize personal-data collection for all users, including children under 13. Kidea does not include sign-in, account creation, or an age-gate flow, and we do not knowingly collect a child’s name, email address, postal address, phone number, precise location, photographs of the child, or any other directly identifying personal information. The app never asks for any of these.
We use technical identifiers for internal operations such as security, fraud prevention, usage limits, and service integrity, and for the app analytics and crash diagnostics described in section 2.7. Analytics is limited to app usage and fault diagnosis: no advertising identifier is collected, ads are non-personalised, and we do not build behavioural profiles of children or track them across other apps or websites.
Users are not required to provide more personal information than is necessary. For example, a profile name is optional and never leaves the device.
The one place where a child could type personal information into Kidea is a free-text field — the feedback box (section 2.6) or a written exercise answer (section 2.4). None of these require personal details, and we ask that they not be entered. If you believe a child has submitted personal information to us, contact us using the details in section 12 and we will delete it.
You may:
To do any of this, please contact us using the details in section 12. We will respond within a reasonable time (e.g. as required by law, such as within 30 days under COPPA).
Depending on your location, you may have the right to:
You also have the right to withdraw consent at any time where we rely on it (for example for a shared chapter or for feedback you sent), without affecting processing that already took place. See section 3.1 for which basis applies to which purpose.
In Finland, the supervisory authority is the Office of the Data Protection Ombudsman.
To exercise these rights — including objecting to analytics or to any other processing based on legitimate interests — contact us using the details in section 12 (Contact). Because Kidea has no accounts, please tell us which installation you mean; we may need to ask you for the installation identifier shown in the app so we can find the right records, and if we cannot identify any data as yours we may not be able to act on the request.
We use reasonable technical and organizational measures to protect the information we process—for example, secure connections (HTTPS), access controls, and secure storage. No system is completely secure; we encourage you to use a secure device and to keep account and device access limited to trusted persons.
We may update this Privacy Policy from time to time. We will post the current version at https://www.dancingmanatee.com/kidea/privacy.html (and in the app where applicable). Where required by law, we will notify you of significant changes (e.g. in the app or by email). The “Last updated” date at the top shows when the policy was last revised.
Data controller: Esa Tanskanen (individual trader), Finland
For privacy questions, parental requests (access, deletion, or refusal of further collection), or any concern about your or your child’s data:
We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. Privacy requests are handled by the controller directly at the address above.
We will respond as required by applicable law (e.g. COPPA in the United States, GDPR in the EU/EEA — normally within one month).
This policy is designed for users and parents. If you need it in another language or format, please contact us. This policy is provided in English; translations, if any, are for convenience and the English version prevails in case of conflict, except where mandatory local law requires otherwise.