Privacy Policy for Kalimo
Last updated: 29 September 2026 · Version: 1.0 · Deutsche Fassung
Kalimo is an iPhone app that parents and other grown-ups use to create illustrated bedtime stories for their children and read them aloud. The text and pictures are made with artificial intelligence (AI). This policy covers the app and the website kalimostories.com.
The short version
- Kalimo is made for grown-ups. A grown-ups' gate protects the settings. Children look at the books and tap the pictures; they don't enter any data themselves.
- No account with an email address. The app creates an anonymous account the first time it starts. We don't need your name, phone number or address.
- The AI never gets your children's names. The AI services only see placeholders such as "{{HERO_1}}"; your iPhone fills in the names. The names are kept in your family library on our server, so your books look the same on all your devices.
- The AI does get your children's age, looks, favourite things and fears. That is how the stories and pictures are made. The providers are Google, Anthropic, OpenAI and, only if you turn on videos, ByteDance, reached through Vercel. Before the first story, the app asks for your explicit permission.
- The photo is optional. If you use it, it goes once to Google Gemini, which is asked to describe hair, skin and eye colour. We do not store the photo.
- No ads, no tracking, no analytics tools. We don't sell data.
- You can delete everything. In the grown-ups' area, "Delete account and all data" removes your data from the iPhone and from our server.
1. Who is responsible
Malte Schiebelmann
Salzmannweg 12
14469 Potsdam, Germany
Email: hi@kalimostories.com
More details are in our legal notice (Impressum).
[[DATA PROTECTION OFFICER: add name and contact if one is appointed; otherwise delete this paragraph.]]
2. Who Kalimo is for
Kalimo is for parents and other adults with parental responsibility or care duties ("you"). The stories are for children aged about 3 to 8. Only grown-ups set up profiles, enter data, start stories and change settings, behind a grown-ups' gate (a sum or Face ID). Children only use the app to look at the books and be read to.
The data about your child comes from you (Art. 14 GDPR). Please only enter data about children you have parental responsibility for, or whose parents have agreed.
3. What we process and why
3.1 Anonymous account
When the app first starts, it signs in to our server anonymously and gets a random account ID. The sign-in details are kept in your iPhone's keychain. The account keeps your books and profiles safe and the same on all your devices.
- Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).
3.2 Your children's profiles and your family library
You can set up a profile for each child. It contains:
- first name, age and gender or pronouns (he, she, neither)
- language and how exciting the stories may be
- looks (hair colour and style, skin tone, eye colour, glasses, freckles, clothes)
- favourite things, and things that must not appear in stories ("fears")
- siblings, friends, pets and cuddly toys, each with a name, kind, short description and pronouns
Your family library also holds:
- characters you keep from a story
- the books themselves: text, pictures and, if chosen, short videos
- which names appear in which book
- favourites and bookmarks (where you stopped reading, and which path you chose)
This data is kept on your iPhone and in your family library on our server (see section 5). It is linked to your account ID, and only you can access it.
- Purpose: to write personal stories, and to keep your library safe and the same on all your devices.
- Legal basis: the consent you give on your child's behalf (Art. 6(1)(a) GDPR), and performance of our contract with you (Art. 6(1)(b) GDPR).
- Skin tone: it may indirectly suggest ethnic origin, so we only store and process it if you give it, and only with your explicit consent (Art. 9(2)(a) GDPR).
- Without this data Kalimo cannot write personal stories. Most fields are optional.
Please don't enter health information. Under "fears", write things like "spiders" or "thunderstorms", not diagnoses or medical details. Please also don't write other people's names in free-text fields (ideas, wishes, feedback), such as "Grandma Helga": we can only replace the names you set up in the profiles.
3.3 Making stories with AI
When you start a story, our server puts together a request and replaces your children's and their companions' names with placeholders. The request contains:
- the children's age, pronouns and looks
- favourite things, things that must not appear, and the companions' descriptions
- the topic or your own idea, mood, time of day, length and language
- any characters you kept
AI models from these providers work on the request:
| Task | Model | Provider |
|---|---|---|
| Writing the story, checking your own ideas are suitable for children, revising pages | Gemini | |
| Proofreading the story | Claude | Anthropic |
| Painting the pictures | GPT Image | OpenAI |
| Checking pictures for mistakes | Gemini | |
| Short videos (only if you turn videos on) | Seedance | ByteDance |
All requests go through Vercel's AI Gateway, which passes them to the providers. We keep the finished text and pictures in your family library, and your iPhone fills in the names when it shows them.
- Legal bases: your explicit consent, which the app asks for before the first story (Art. 6(1)(a) and Art. 9(2)(a) GDPR), and performance of our contract (Art. 6(1)(b) GDPR).
- Withdrawing consent: you can withdraw it at any time in the grown-ups' area. No new stories are made after that; existing books stay readable until you delete them.
[[TRAINING: only add once Vercel's and the providers' terms are checked, e.g. "The providers may not use the data to train their models and keep it for at most [[X]] days." Otherwise delete this paragraph.]]
Automated decisions: when you type your own story idea, an AI model checks it before the story is made. It turns down unsuitable topics, and you can then try another idea. This is not a decision with legal effect under Art. 22 GDPR.
AI-generated content: all stories, pictures and videos in Kalimo are made with AI.
3.4 A photo for your child's looks (optional)
When you set up a profile, you can take or choose a photo of your child so that Kalimo can suggest their looks. This is what happens:
- The app shrinks the photo and removes metadata such as where it was taken.
- Our server sends it once, through Vercel, to Google Gemini, which is asked only to describe hair colour and style, skin tone, eye colour, glasses and freckles.
- You see the suggestions and can change them. Only what you accept is kept, as text.
We do not store the photo, on our server or in the app. It is not used for facial recognition or identification, and it is not used to make the story's pictures. How long Google technically keeps such a request depends on its terms [[check and, if possible, state the period]].
- Legal basis: your explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR). You give it by tapping "Take photo" or "Choose photo" after reading the notice in the app.
- Without a photo: you can simply pick the looks yourself.
3.5 Camera, photos and Face ID
The app asks for camera access only for the photo in section 3.4. If you choose a photo from your library, you pick it in the iOS photo picker, and the app only sees the one photo you choose.
If you wish, the app uses Face ID for the grown-ups' gate. iOS checks your face on your device; we receive no face data.
3.6 Notifications
If you allow notifications, Kalimo lets you know, for example, when the first pages of a book are ready. For this we store:
- a random device ID and Apple's push token
- language, time zone and app version
- your notification settings
Apple delivers the notifications (Apple Push Notification service). They contain names only as placeholders; your iPhone fills in the names when the notification arrives.
- Legal basis: performance of our contract (Art. 6(1)(b) GDPR) and § 25(2) no. 2 TDDDG.
- Turning them off: at any time, in the app or in iOS Settings.
- Promotional notifications: we only send them if you have agreed separately.
3.7 Reporting a page
The flag in a book lets you report a page that doesn't look right. We then store:
- the reasons you chose and your comment (the app first replaces known names with placeholders)
- language and app version
- a copy of the page (text with placeholders, the picture's description, a reference to the picture)
We read reports ourselves, together with the records of that book's AI requests (section 3.9), and turn them into test cases so the mistake doesn't happen again. [[IF EMAIL IS ON: We also receive reports by email through the service Resend.]]
- Legal basis: our legitimate interest in safe, child-appropriate and correct stories (Art. 6(1)(f) GDPR).
3.8 Feedback and ratings
After the first book, Kalimo asks how you like it. We store your answer, reasons and comment, together with language, app version, what prompted the question and how many books have been read. We store an email address only if you give one so that we can reply. [[IF EMAIL IS ON: We also receive feedback by email through Resend.]]
If you choose "Great", the app shows Apple's rating dialog. Apple, not us, processes what you enter there.
- Legal bases: our legitimate interest in improving Kalimo (Art. 6(1)(f) GDPR). For the email address, your consent (Art. 6(1)(a) GDPR).
3.9 Records of AI requests, and costs
For each book we record the requests to the AI models and their answers: instructions, text, model, timing and errors. Pictures appear in the records only as a storage reference. The records contain no names (placeholders only), but they do contain the other details from section 3.3. For each request we also store the model, cost and duration, and for each account the costs per day, so that a daily limit applies.
- Purpose: finding mistakes, improving the stories, and preventing misuse and unexpected costs.
- Legal basis: our legitimate interest (Art. 6(1)(f) GDPR).
3.10 Technical logs
When the app or the website contacts our servers, our service providers process technically necessary access data: IP address, time, requested address, status code and technical details of the device. They do so to run and secure their services, and delete the data after a short time under their own terms [[check Supabase's, Vercel's and Cloudflare's periods, e.g. "within 7 days"]].
- Legal basis: our legitimate interest in secure, reliable operation (Art. 6(1)(f) GDPR).
3.11 Storage on your iPhone
The app stores on your device:
- your library, with its pictures
- the sign-in details and the invite code (in the keychain)
- settings, such as the night filter or the grown-ups' gate
- the names for notifications (in an area only Kalimo can reach)
- a technical reading log without names or story text, which stays on the device
This is strictly necessary for the service you asked for (§ 25(2) no. 2 TDDDG).
If you share a book as a PDF, the PDF contains the names. You decide where it goes.
3.12 No ads, no tracking
Kalimo has no ads and no third-party analytics, tracking or advertising SDKs, and it does not use the advertising identifier. We don't sell personal data or use it for advertising.
3.13 Purchases
Kalimo currently offers no in-app purchases. [[IF ADDED LATER: Apple handles purchases and subscriptions. We receive no payment details, only which purchases belong to your account (Art. 6(1)(b) GDPR).]]
3.14 Website
Cloudflare (Cloudflare Pages) hosts our website kalimostories.com. Visiting it only produces the technical logs in section 3.10. On the start page, a small program at Cloudflare checks your browser's language setting to show the page in German or English; it stores nothing. The website sets no cookies and uses no analytics or tracking services.
Cloudflare (Email Routing) forwards emails to hi@kalimostories.com to our mailbox. We use your message and email address only to reply to you (Art. 6(1)(b) or (f) GDPR) and delete them once your request is settled.
4. Recipients and processors
We only share data with service providers that process it on our behalf under contracts according to Art. 28 GDPR, and with Apple to deliver notifications.
| Recipient | Purpose | Data | Location |
|---|---|---|---|
| Supabase, Inc. | Server, database, storage, sign-in | all data in section 3 except the photo (which only passes through) | servers in Ireland (Dublin), EU; company in the USA |
| Vercel Inc. | AI Gateway (passing requests to the AI providers) | requests and answers from 3.3, the photo from 3.4, technical logs | USA |
| Cloudflare, Inc. | Website hosting, DNS, forwarding emails to hi@kalimostories.com | the website's technical logs, emails to us | USA |
| Google (Gemini) | Text, checking ideas and pictures, photo features | requests from 3.3, pictures, the photo from 3.4 | USA [[check]] |
| Anthropic PBC (Claude) | Proofreading stories | story plan and chapter drafts (with placeholders) | USA |
| OpenAI (GPT Image) | Pictures | picture descriptions with looks, reference pictures | USA |
| ByteDance (Seedance) | Short videos, only if turned on | one picture and a motion description | [[check]] |
| Apple Inc. / Apple Distribution International Ltd. | Delivering notifications, rating dialog, App Store | push token, notification text (with placeholders) | Ireland / USA |
| [[Resend, Inc.]] | [[Email for reports and feedback, if turned on]] | [[the report or feedback, and your email address if given]] | [[USA]] |
We reach the AI providers through Vercel; [[check whether they act as Vercel's sub-processors or are contracted directly]].
We only disclose data to authorities where the law requires us to (Art. 6(1)(c) GDPR).
5. Transfers outside the EU
Some recipients are based in the USA or process data there. For the USA, the European Commission's adequacy decision (the EU-U.S. Data Privacy Framework) applies to recipients certified under it. Where a recipient is not certified, we use the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR). [[For ByteDance/Seedance: add the location and safeguard.]] You can ask for a copy of the safeguards at hi@kalimostories.com.
6. How long we keep data
| Data | How long |
|---|---|
| Profiles, characters, books, bookmarks, account ID | until you delete your account |
| A single book or profile that you delete | removed from your library and your devices straight away. The book's request, pictures and records stay on the server until you delete your account [[or: for up to X days, once automatic deletion is in place]] |
| The photo from section 3.4 | not stored by us |
| Records of AI requests | 180 days; for reported books, until you delete your account |
| Cost records | until you delete your account |
| Reports and feedback (including an email address) | until you delete your account [[or set a shorter period]] |
| Push token and device details | until you turn off notifications, delete the app (Apple then reports the token as invalid) or delete your account |
| Service providers' technical logs | according to their periods (section 3.10) |
Legal retention obligations remain unaffected.
Deleting your account: in the grown-ups' area, "Delete account and all data" immediately deletes:
- your account
- all profiles, characters, books and pictures
- the records, reports, feedback and device entries on our server
- all data on that iPhone
[[BACKUPS: if backups are set up, give their deletion period here, e.g. "Data disappears from backups within X days."]]
7. Your rights
You have the right to:
- access your stored data (Art. 15 GDPR)
- rectification of incorrect data (Art. 16 GDPR). You can change most details directly in the app
- erasure (Art. 17 GDPR), directly in the app (see section 6)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- withdraw consent with effect for the future (Art. 7(3) GDPR), in the grown-ups' area or by email
- complain to a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is: the Brandenburg Commissioner for Data Protection and Access to Information (LDA), Stahnsdorfer Damm 77, 14532 Kleinmachnow, Germany, www.lda.brandenburg.de
Right to object (Art. 21 GDPR): where we process data on the basis of legitimate interests (sections 3.7 to 3.10), you can object at any time on grounds relating to your particular situation.
You can also exercise these rights on your child's behalf. Write to hi@kalimostories.com. Because your account is anonymous, please include the account ID shown in the grown-ups' area under "story server", so that we can find your data.
8. Security
Connections between the app, the website, our server and our service providers are encrypted (TLS). Your data can only be accessed with your account. Pictures are delivered through short-lived signed links that expire after one hour. Sign-in details are kept in your iPhone's keychain. Only we, as the operator, have access to the server.
9. For users in the USA (COPPA)
Kalimo is directed at parents. We do not collect data directly from children: grown-ups set up profiles behind the grown-ups' gate, and we ask for a parent's permission before the first story. Sections 3 and 4 say which data we process, why, and who receives it; section 6 says how long we keep it.
Parents can at any time:
- review, change or delete their child's data, in the app or by email
- refuse further collection by withdrawing their consent
We do not disclose the data to third parties other than the service providers that run the service.
10. Changes to this policy
We update this policy when Kalimo, our service providers or the law change. The current version always applies; the date at the top shows when it was last updated. You can find it in the grown-ups' area of the app and at https://kalimostories.com/en/privacy. If we want to use your data for new purposes, or anything else significant changes, we will tell you in the app beforehand. If a change needs your consent, we will ask you first.
This policy is available in German and English. If the two differ, the German version prevails.