Privacy Policy — Kidu
com.dim.mymatcher, iOS bundle com.dim.mymatcher.MyMatcher
1. Overview
Kidu is a game app for young children built around their own family photos. This policy describes what information Hezi Dimri ("we") handles, what stays on the device, what is sent to our servers, and how a parent can delete it. Kidu is designed for children and follows the Google Play Families and Apple Kids Category policies: it contains no advertising, no third-party analytics, no external links outside a parental gate, and its only purchases are two one-time products that a parent buys behind the parental gate (full access, and an extra character credit).
2. What stays on the device
- Family photos. The photos a parent selects, and any photos the app scans on the device to find more pictures of the same family members, are read and stored only on the device. They are never uploaded.
- Face data. To recognise the same family member across photos, the app computes face embeddings (numeric descriptors) on the device. These stay on the device, are never uploaded, and are deleted with the app data.
- Names and tags. The names a parent assigns to family members, and which photo shows whom, are stored on the device only.
- Game progress and settings. Stored on the device only.
Cloud backup of this data is disabled at the operating-system level (allowBackup=false).
3. What is sent to our servers — creating a character
Kidu can turn a family member into an animated game character. This is the only feature that sends any image data off the device, and it only happens when a parent explicitly starts it.
- What is sent: a cut-out of the chosen person or pet only (the subject is segmented from the photo on the device; the background and everyone else in the photo are removed before anything leaves the phone), the character's name, and the chosen art style.
- Processed ephemerally, never stored: the cut-out is held in server memory only for the duration of the generation, passed to the image-generation services below, and discarded. We do not keep the cut-out, and it is not used for any other purpose.
- Service providers: generation uses Google Gemini (Google LLC) and AutoSprite (autosprite.io) as processors acting on our behalf, under our instructions, for this purpose only. They are not permitted to use the image for their own purposes.
- What is stored (user-generated content): the resulting animated character — the generated sprite sheets and a small preview — is stored in Firebase Cloud Storage and Cloud Firestore (Google LLC) under the account's identifier, so the character survives reinstalls and device changes. This generated content is the only image data we retain. It is linked to the account and deleted with it (section 6).
4. Account
- Anonymous by default. On first launch the app creates a random anonymous identifier in Firebase Authentication. No email, name, or other personal information is required to use Kidu.
- Optional email sign-in. A parent may create an account with an email address and password (behind the parental gate) to keep generated characters across devices. We store the email address and a hashed password in Firebase Authentication and nothing else about the parent.
- On-device machine learning (ML Kit). Face detection, image labeling and subject segmentation run on the device with Google ML Kit. Your photos are not sent to Google. ML Kit does send Google anonymous diagnostics about the API itself (device model, OS version, app version, a per-installation diagnostic identifier, latency and error codes) as described in Google's ML Kit terms; this contains no image data and is not shared further.
- Push notification token. On Android, the app may register a Firebase Cloud Messaging token so it can notify the parent when a character is ready. The token identifies the app installation, not a person.
5. What we do not do
- No advertising and no advertising identifiers.
- No third-party analytics or tracking SDKs.
- No sale of data, and no sharing with third parties beyond the service providers named in section 3.
- No collection of location, contacts, or device identifiers beyond what Firebase Authentication and Cloud Messaging need to function.
- No behavioural profiling of children.
6. Deletion
- In the app: Grown-ups area → Account → Delete the account. This deletes the account in Firebase Authentication, every generated character and its files on our servers, and the local copies. The next launch starts fresh.
- Local data (photos, face data, names, progress) is deleted by uninstalling the app or clearing its data.
- By email: write to dimrihezi@gmail.com with the email address of the account and we will delete it within 30 days.
7. Children's privacy
Kidu is intended to be set up and supervised by a parent or guardian; the child plays, the parent decides. Account creation, character creation, and every setting live behind a parental gate. We do not knowingly collect personal information from a child directly. If you believe a child has provided personal information without a parent's consent, contact us and we will delete it.
8. Security & retention
Data in transit is encrypted (HTTPS). Server-side data is held in Google Cloud / Firebase with access restricted to the account that created it. Generated characters are retained until the account is deleted. Image cut-outs sent for generation are not retained at all.
9. Changes
Changes to this policy are published at this address with a new effective date.
10. Contact
Hezi Dimri — dimrihezi@gmail.com
1. כללי
קידו היא אפליקציית משחקים לילדים צעירים סביב תמונות המשפחה שלהם. מסמך זה מתאר איזה מידע חזי דימרי ("אנחנו") מטפלים בו, מה נשאר במכשיר, מה נשלח לשרתים שלנו, ואיך הורה יכול למחוק אותו. קידו מיועדת לילדים ופועלת לפי מדיניות Google Play Families ו‑Apple Kids Category: אין בה פרסומות, אין אנליטיקס של צד שלישי, אין קישורים חיצוניים מחוץ לשער ההורים, והרכישות היחידות בה הן שני מוצרים חד-פעמיים שהורה קונה מאחורי שער ההורים (גישה מלאה, וקרדיט דמות נוסף).
2. מה נשאר במכשיר
- תמונות המשפחה. התמונות שההורה בוחר, וכל תמונה שהאפליקציה סורקת במכשיר כדי למצוא עוד תמונות של אותם בני משפחה, נקראות ונשמרות במכשיר בלבד. הן לעולם לא מועלות.
- נתוני פנים. כדי לזהות את אותו בן משפחה בתמונות שונות, האפליקציה מחשבת במכשיר מאפייני פנים מספריים (embeddings). הם נשארים במכשיר, לא מועלים, ונמחקים עם נתוני האפליקציה.
- שמות ותיוגים. השמות שההורה נותן לבני המשפחה, ומי מופיע באיזו תמונה, נשמרים במכשיר בלבד.
- התקדמות במשחקים והגדרות. במכשיר בלבד.
גיבוי ענן של נתונים אלה מבוטל ברמת מערכת ההפעלה (allowBackup=false).
3. מה נשלח לשרתים — יצירת דמות
קידו יכולה להפוך בן משפחה לדמות משחק מונפשת. זו התכונה היחידה ששולחת נתוני תמונה מחוץ למכשיר, והיא מופעלת רק כשהורה מתחיל אותה במפורש.
- מה נשלח: גזיר של האדם או חיית המחמד שנבחרו בלבד (הדמות מופרדת מהתמונה במכשיר; הרקע וכל מי שמופיע בתמונה מלבדה מוסרים לפני שמשהו עוזב את הטלפון), שם הדמות וסגנון הציור שנבחר.
- עיבוד זמני, ללא שמירה: הגזיר מוחזק בזיכרון השרת רק למשך היצירה, מועבר לשירותי יצירת התמונה שלהלן, ונמחק. איננו שומרים את הגזיר, והוא אינו משמש לשום מטרה אחרת.
- ספקי שירות: היצירה משתמשת ב‑Google Gemini (Google LLC) וב‑AutoSprite (autosprite.io) כמעבדים הפועלים מטעמנו, לפי הוראותינו, למטרה זו בלבד. אסור להם להשתמש בתמונה למטרותיהם.
- מה נשמר (תוכן שנוצר על ידי המשתמש): הדמות המונפשת שנוצרה — גיליונות הספרייט ותצוגה מקדימה קטנה — נשמרת ב‑Firebase Cloud Storage וב‑Cloud Firestore (Google LLC) תחת מזהה החשבון, כדי שהדמות תשרוד התקנה מחדש והחלפת מכשיר. התוכן שנוצר הוא נתוני התמונה היחידים שאנחנו שומרים. הוא מקושר לחשבון ונמחק איתו (סעיף 6).
4. חשבון
- אנונימי כברירת מחדל. בהפעלה הראשונה האפליקציה יוצרת מזהה אנונימי אקראי ב‑Firebase Authentication. לא נדרשים אימייל, שם או מידע אישי אחר כדי להשתמש בקידו.
- התחברות באימייל — אופציונלית. הורה יכול ליצור חשבון עם כתובת אימייל וסיסמה (מאחורי שער ההורים) כדי לשמור את הדמויות שנוצרו בין מכשירים. אנחנו שומרים את כתובת האימייל וסיסמה מוצפנת ב‑Firebase Authentication ותו לא.
- למידת מכונה במכשיר (ML Kit). זיהוי פנים, תיוג תמונות והפרדת דמות מהרקע רצים במכשיר באמצעות Google ML Kit. התמונות שלכם אינן נשלחות לגוגל. ML Kit כן שולח לגוגל נתוני אבחון אנונימיים על ה‑API עצמו (דגם מכשיר, גרסת מערכת, גרסת אפליקציה, מזהה אבחון להתקנה, זמני תגובה וקודי שגיאה) כמתואר בתנאי ML Kit של גוגל; הם אינם כוללים נתוני תמונה ואינם משותפים הלאה.
- אסימון התראות. באנדרואיד האפליקציה עשויה לרשום אסימון Firebase Cloud Messaging כדי להודיע להורה כשדמות מוכנה. האסימון מזהה את ההתקנה, לא אדם.
5. מה אנחנו לא עושים
- אין פרסומות ואין מזהי פרסום.
- אין אנליטיקס או מעקב של צד שלישי.
- אין מכירת נתונים, ואין שיתוף עם צדדים שלישיים מעבר לספקי השירות שבסעיף 3.
- אין איסוף מיקום, אנשי קשר או מזהי מכשיר מעבר לנדרש לפעולת Firebase Authentication ו‑Cloud Messaging.
- אין פרופיל התנהגותי של ילדים.
6. מחיקה
- בתוך האפליקציה: אזור מבוגרים ← חשבון ← מחיקת החשבון. פעולה זו מוחקת את החשבון ב‑Firebase Authentication, כל דמות שנוצרה וקבציה בשרתים שלנו, ואת העותקים המקומיים. ההפעלה הבאה מתחילה מחדש.
- נתונים מקומיים (תמונות, נתוני פנים, שמות, התקדמות) נמחקים בהסרת האפליקציה או בניקוי הנתונים שלה.
- באימייל: כתבו ל‑dimrihezi@gmail.com עם כתובת האימייל של החשבון ונמחק אותו תוך 30 יום.
7. פרטיות ילדים
קידו מיועדת להגדרה ולפיקוח של הורה או אפוטרופוס; הילד משחק, ההורה מחליט. יצירת חשבון, יצירת דמות וכל הגדרה נמצאות מאחורי שער הורים. איננו אוספים ביודעין מידע אישי ישירות מילד. אם לדעתכם ילד מסר מידע אישי ללא הסכמת הורה, פנו אלינו ונמחק אותו.
8. אבטחה ושמירה
נתונים בתעבורה מוצפנים (HTTPS). נתונים בצד השרת מוחזקים ב‑Google Cloud / Firebase עם גישה מוגבלת לחשבון שיצר אותם. דמויות שנוצרו נשמרות עד מחיקת החשבון. גזירי תמונה שנשלחו ליצירה אינם נשמרים כלל.
9. שינויים
שינויים במדיניות זו מתפרסמים בכתובת זו עם תאריך תחולה חדש.
10. יצירת קשר
חזי דימרי — dimrihezi@gmail.com