Privacy Policy
This English text is a convenience translation. The binding original is the Vietnamese version; where the two differ, the Vietnamese version prevails.
You are considering putting an app into your child's hands, so you deserve to know exactly what it does with your family's data. This page describes what the software actually does — briefly, and without hiding the inconvenient parts at the bottom.
The 30-second version
- No advertising, no tracking. The app contains no third-party analytics, crash reporting or advertising kit.
- It talks to exactly one server — the project's own. No CDN, no outside service.
- A child's voice never leaves the device. The feature is off by default.
- You can delete your account inside the app, and deletion is immediate and permanent.
- No account required. Every lesson works without signing in, and nothing leaves the device when you use it that way. Signing in only adds syncing between iPad and iPhone — see section 9.
1. Who is responsible
Digi Dinos Joint Stock Company decides how data in Dino Kids is processed. Any question or request about data should go to dinokids@digidinos.com.
2. What we hold
2.1 When you create an account
| Data | Why it is needed |
|---|---|
| The name you enter | Names the household and appears in the account area |
| Email address | Identifies the account at sign-in |
| Password | We store only a hash. We do not keep the original and cannot read it |
| Device identifier | Generated at random by the app so you can see and remove each signed-in device |
That device identifier is not an advertising identifier. The app does not read Apple's IDFA or IDFV, does not ask for tracking permission, and reads no operating system's advertising identifier at all — the app generates the value itself, at random.
Since September 2026 that identifier survives deleting the app: on iPhone and iPad it lives in the Keychain, on Android it is derived from a value particular to the device. Before that it went away with the app, and that failed in a way few people expect — every reinstall added one more row to your device list for the same physical device, until nobody could tell which row to remove. The “Remove device” button in the account area takes that device off your account and signs it out immediately.
Alongside this identifier, when you sign in the app sends exactly two further things so you can tell one device from another in the list: the operating-system family — the string the operating system reports for itself, “ios” on iPhone and iPad, “android” or “macos” elsewhere — and a fixed label built from that string (“Dino Kids · ios”). The app does not send the model or the operating-system version.
2.1b When you sign in with Apple or Google
Besides email and password, you can create an account with Sign in with Apple or with a Google account. Each operating system offers exactly one of the two, and on iPhone and iPad that one is Apple. If you choose this route, what leaves your device for our server is a single identity token signed by Apple or Google — nothing else.
| Data | Why it is needed |
|---|---|
| The provider's user identifier | Recognises you on later sign-ins. It is specific to our app and cannot be used to find you anywhere else |
| Email address | Identifies the account, exactly as it would if you had registered with an email yourself |
| Your name | Apple sends it exactly once, on the first authorisation, so a new account has a display name. There is no second time |
Our server verifies the signature on that token itself and takes out only the items above. We receive no contacts, no photographs, no friend list, no history and nothing else from Apple or Google, and we send them nothing beyond the token itself for verification.
If you pick Apple's “Hide My Email”, all we ever see is a relay address of the form …@privaterelay.appleid.com. Mail reaches that address, so the account works normally, and your real address never becomes known to us.
An account made this way has no password — there is nothing for us to store, not even a hash. When your identity has to be proved again, for instance when deleting the account, you press that same provider's button once more.
2.1c When you open the app — the version check
Every time it opens, the app asks the server exactly one question: “is there a newer version on the store than the one I am running?”. That question does not require signing in, and that is a condition rather than a convenience: a device running a badly outdated version is usually a device where nobody ever created an account.
Three things travel with the question: the device identifier from 2.1, the operating-system family, and the app version you are running. We keep them in a separate table so we can answer “how many devices are still on an old version” — that is, so we can tell whether a bug fix has actually reached everyone.
That table holds no email address, name or IP address, and it carries no ready-made link to an account. If the device has signed in at some point, we can match the identifier to your account — because you told us about that device yourself when you signed in. A device that has never signed in leaves nothing to match against, and stays that way.
2.2 A child's profile
Display name, avatar, whole-year age (optional), favourite colour and a few learning preferences. No date of birth and no photograph — the avatar is a supplied drawing or an emoji. The app never asks for camera access and never reads your photo library.
The display name is yours to type. A nickname is perfectly fine, and for a small child we encourage it.
2.3 Learning records and artwork
Once you are signed in, the app syncs to the server: child profiles, artwork (including the image files), per-lesson progress, stars, badges, day streaks and the paint box a child has mixed. The timestamp of each session is rounded down to the minute rather than recorded to the second.
Synced artwork can only be fetched after authentication, and only within your household: the request must carry a valid session token, and when someone asks for another household's picture the server answers “not found” rather than confirming that the picture exists. The image files are not served over any public path. That is what lets a child colour on the iPad and see the result on an iPhone signed in to the same account.
2.4 Recordings made by an adult
If you use the voice-recording feature, the adult audio files are uploaded so they can be reused on other devices on the same account. This is a recording of your real voice, and it does leave the device — we say so at the point where microphone access is requested.
These files can only be fetched after authentication: the request must carry a valid session token, the device and account must still be active, and the recording must belong to that household. They are not served over any public path.
2.5 A child's voice — it stays on the device
This is the most sensitive category, and it is handled the most strictly.
- The “listen to your child read” feature is off by default. While it is off, the microphone button does not appear.
- Recognition runs on the device itself. No audio is sent anywhere, including to us.
- Each attempt saves a short file on the device for you to play back. There is no path that would carry it to the server — no endpoint, no matching table.
- The device keeps only the 400 most recent attempts per child; older ones delete themselves, file and record alike.
- You can delete a single attempt or all of them at any time, in the adults-only area.
Because these files sit in the app's own data area, they are included in your iCloud or computer backup, like any other app data. That is your backup with Apple, not a flow of data towards us.
2.6 When you write to us through the contact form
The contact page has a form. What you type into it — name, email address, the kind of enquiry and the message — is sent straight to the project inbox as an email, and is not stored in our database: no table, no column, no admin screen for reading it back. It sits in a mailbox, exactly as it would if you had written to us yourself.
We use your name and email only to answer that message. No mailing list, no advertising, and we pass it to nobody.
The form sets no cookie and runs no JavaScript. To keep spam out, the server limits how many messages one IP address may send per minute; that counter lives in a temporary cache, expires by itself, and is not tied to your identity.
3. What we do not do
- We do not sell, rent or trade your data with anyone.
- We do not use your data for advertising, and we show no advertising.
- We do not use your artwork, voice or schoolwork to train artificial-intelligence models.
- We do not track you across other apps or websites.
- We do not build behavioural profiles to infer a child's personality or ability.
4. Third parties
Inside the app: none. We have reviewed every library and component that gets loaded — there is no Firebase, Crashlytics or Sentry, and no analytics, crash-reporting, advertising or measurement kit of any kind.
On the server side: we use Google's text-to-speech service to generate the model voice for the lessons in advance. What is sent is only the lesson wording written by adults — none of your data or your child's passes through it. The app on your device never calls that service.
The first time “listen to your child read” is switched on, the device may download a recognition language pack from Apple. Only the request for the pack goes out; no audio goes with it.
Email passes through Google. The project mailbox and our outgoing mail server are both Google services. That means messages you send through the contact form, and messages we send you — email confirmation, password reset — travel through Google's infrastructure and rest in that mailbox. We say so plainly because the paragraph above states that none of your data passes through a Google service; that is true of the recorded voices, and would be false if we left this out.
5. Who can read the data
| Who | What they can read |
|---|---|
| You | All of your household's data, through the app |
| Our administrators | The list of accounts (name, email, last sign-in) and the list of devices. There is no screen anywhere for viewing a child's artwork or listening to your family's recordings. |
| Operations engineers | Technically, whoever administers the server and database can reach the data stored on it — this is true of any self-hosted system. That access is limited to a small number of people and is used only to operate the service, fix faults, or comply with the law. |
The boundary between households is enforced on the server: no route returns another household's data.
6. Where the data lives
On servers we run ourselves, on Digi Dinos infrastructure. We do not use third-party cloud storage for user data.
7. How long we keep it, and how to delete it
7.1 Deleting your account
You can delete your account inside the app, in the adults-only area. An account with a password is confirmed with that password; an account made with Apple or Google has no password, so it is confirmed by pressing that provider's button once more. A final confirmation box follows either way. You do not have to write and ask us to do it for you.
When you delete your account we delete immediately and permanently, with no waiting period:
- all of your household's data on the server — account, child profiles, artwork, progress, badges, paint box, voice recordings;
- the files on disk as well: the artwork directory and the recordings directory;
- every session token on every device in the household, so those devices sign out at once.
After deletion, that email address can be used again for a new account.
7.2 Deleting one child
Deleting a child's profile permanently removes that profile, their learning records and their artwork, image files included. Before deleting, the app tells you how many pictures will be lost. Voice recordings are not deleted along with it, because they belong to the household as a whole and are shared between children.
7.3 Signing out
An ordinary sign-out leaves the data on the device. If you are passing the device on to someone else, use “sign out and erase the data on this device”.
7.4 Retention
Our server does not delete data on a timer. There is no scheduled job that clears out old user data. Data stays until you delete your account or a child's profile. If you want data gone, the certain and immediate way is the delete function in the app.
There is one exception in the other direction: when a profile or a recording is deleted, we keep an empty marker recording that the item was removed, so other devices on the same account know to remove it too. The marker holds no content, only an identifier and a timestamp.
8. Children
The app is designed for young children used under adult supervision. The adult who creates the account decides what data about their child is entered. A child cannot create an account, cannot buy anything, cannot message strangers, and there is no social feature in the app. Settings, statistics and recording management all sit behind a gate a child cannot pass on their own.
If you believe your child has given us data in a way you did not intend, write to us and we will delete it.
9. What you should know about signing in
Signing in means syncing, and signing in is optional. The first screen offers “Start without an account”. Choose it and every lesson works. The app still downloads lessons and audio from our server — that is how the pre-school section gets its content, since that section is not bundled inside the app. Nothing travels the other way: child profiles, artwork, progress, stars and badges all stay on the device, and the app sends no name or identifier that would single out your device. That download is like opening a web page: the server sees the IP address the request came from, not which child is using the app.
Once you are signed in, child profiles and artwork sync both ways with the server, and the app has no dedicated toggle for that — signing in and syncing go together. Put another way, the switch that decides whether data reaches our server is whether you sign in.
You can change your mind at any time and lose nothing: if a child uses the app for a month without an account and a parent signs in later, the profiles, artwork and progress already there are pushed up on the first sync.
10. Your rights
You can view and change your household's data inside the app, and delete your account at any time as described in section 7. If you would like a copy of your data, want us to correct something, or wish to complain about how we handle data, write to dinokids@digidinos.com. We reply within a reasonable time.
11. When this policy changes
We update this page and change the effective date at the top. If a change genuinely affects you — for instance if we start collecting something we did not collect before — we also give notice by email to the registered address before it takes effect.
The Vietnamese version is the binding original. The Japanese and English versions are for reference; where they differ, the Vietnamese version applies.
12. Contact
dinokids@digidinos.com — the project's only point of contact, for questions and data requests alike.
← Back to the overview