Privacy Policy - Poikilingo Bilingual Flashcards

At Poikilingo, we create safe and playful language learning experiences for children. This Privacy Policy applies to the Poikilingo Bilingual Flashcards mobile application (iOS and Android; bundle ID compoikilingo.bilingual.flashcards. Other Poikilingo products may have their own, separate privacy terms. Poikilingo Flashcards is designed as a children's app and is built to collect as little information as possible.

Effective Date: July 25th, 2026.

1. Who we are

Poikilingo Flashcards is operated by Poikilingo ApS, Guldringen 27, 4320, Lejre, Denmark (“Poikilingo”, “we”, “us”). If you have any questions about this policy or your privacy, contact us at support@poikilingo.com.

2. Our approach to children’s privacy

Poikilingo Bilingual Flashcards is intended for use by children together with their parents or guardians. We follow a privacy-by-design approach and comply with the Children’s Online Privacy Protection Act (COPPA) and the EU GDPR, including the rules protecting children (“GDPR-K”). We deliberately minimise the data we handle, and information relating to a child is never used to market or advertise to that child.

3. Information stored only on the device

When you set up a child profile, the following is stored locally on your device and is not transmitted to us or to any third party:

  • Nickname — a free-text display name you choose for the child. It is treated as personal information and stays on the device; it is never sent to our analytics or servers.
  • Avatar — a picture chosen from a set of avatars built into the app. No photographs are uploaded or taken.
  • Age range — a broad band (0–2, 3–4, 5–7, or 8+). We store a band, never a date of birth, to minimise personal data.
  • Languages — the language the child is learning and the language they already know.
  • Display and screen-time settings — such as caption options, landscape lock, and the parent-set time limit.
  • Learning activity log — an on-device record of interactions (for example, which words were heard) used to award stickers and rewards. This log stays on the device.

You can delete this information at any time by removing the profile in the app or by uninstalling the app.

4. Information we process

The app processes a limited amount of information to run and improve the service:

  • Usage analytics (de-identified). We use Google Firebase Analytics in a children’s consent mode: advertising storage, advertising user data, and ad personalisation are all disabled. We collect only non-identifying usage events — for example that a category was opened, a card was viewed, audio was played, or a setting was changed — described by content identifiers and language codes (such as category_id, word_id, and locale). These events do not include the child’s nickname or any other personal identifier, and no advertising identifier (Apple IDFA or Android Advertising ID) is collected or transmitted.
  • Crash and stability diagnostics. We use Google Firebase Crashlytics to receive crash reports and technical diagnostics (such as device model, operating-system version, and app version) so we can fix problems. These reports are used only to keep the app working.
  • Content delivery / technical data. Lesson content (images and audio) is streamed from our hosting provider. As with any internet request, the provider processes standard technical data such as your device’s IP address and general device/OS information to deliver the content. We do not use this to build a profile of a child.

We do not combine the above with the on-device profile information in Section 3.

5. What we do NOT do

  • We do not show advertising, and the app contains no advertising SDK.
  • We do not collect advertising identifiers (IDFA / Android AD_ID) from children, and the app does not request the AD_ID permission.
  • We do not use behavioural or interest-based advertising, remarketing, or ad targeting of any kind.
  • We do not collect precise location, contacts, phone number, microphone, camera, or photos.
  • We do not require an account or login, and we do not ask children for personal contact information.
  • We do not offer in-app purchases or subscriptions.
  • We do not sell personal information or share it with data brokers.

6. Third-party services

The app relies on the following third parties strictly to operate. We encourage you to review their privacy practices:

  • Google Firebase (Analytics and Crashlytics) — usage analytics and crash reporting, configured for child-directed use with advertising features disabled. See Google’s Privacy Policy.
  • Our content hosting/CDN provider — delivers lesson images and audio.
  • Your device’s operating system share feature — if you use “share with a friend”, the standard iOS/Android share sheet is used. This is initiated by an adult action and is not a social-network or chat feature; we do not receive the contents of what you share.

We do not integrate advertising networks, marketing-attribution SDKs, or social-login providers in this app.

7. How we use information

We use the limited information described above only to: provide and personalise the learning experience on the device; keep the app stable and fix crashes; and understand, in aggregate and without identifying any child, how features are used so we can improve the app. We rely on parental consent and our legitimate interest in operating a safe, functional children’s app as the legal bases under GDPR; where consent is the basis, a parent provides it on the child’s behalf.

8. Parental rights and choices

Parents and guardians can, at any time:

  • Review and delete the on-device profile information by editing or removing the profile, or by uninstalling the app.
  • Contact us at support@poikilingo.com to ask what information we hold, to request deletion, or to withdraw consent. Under GDPR you also have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your local data-protection authority.

Because analytics events are de-identified and contain no identifier we can tie back to a specific child, we may be unable to locate a specific child’s analytics records; we will honour deletion of any information that is reasonably identifiable.

9. Data retention

On-device information (Section 3) remains until you delete the profile or uninstall the app. De-identified analytics and crash data are retained by our providers for their standard retention periods and then deleted or further aggregated.

10. International transfers

Our service providers (including Google) may process data on servers located outside your country, including in the United States. Where required, such transfers are covered by appropriate safeguards (for example the EU Standard Contractual Clauses).

11. Security

Data transmitted by the app is protected in transit using industry-standard encryption (HTTPS/TLS). No method of transmission or storage is completely secure, but we take reasonable measures to protect the limited information the app handles.

12. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by a new “Effective date” at the top and, where appropriate, notified in the app or on our website.

13. Contact Us

Questions regarding this Privacy Policy should be directed to us via:

Scroll to Top