NoMiLudo Privacy Policy
Last updated: 23 August 2026
NoMiLudo is an educational game for young children. It is designed so that a family can play it without giving us anything at all.
This document is the hosted copy required by the App Store and Google Play. The same information is shown inside the app, under Parent Dashboard → Privacy, in every language the app supports. If the two ever disagree, that is a bug. Please report it.
The short version
- We do not run ads, analytics, or any third-party tracking.
- There is no link that leaves the app. The one thing that can be bought is the full version, and it sits behind the parental gate.
- The camera and microphone are off by default, are switched on only by a grown-up from behind a parental gate, and what they capture never leaves the device.
- The game is fully playable with no account and no internet connection.
- Cloud sync is optional. Only if a parent signs in with Google does anything at all leave the device.
Camera
The Funny Faces mode shows a child a mirror of themselves and asks them to touch a part of their own face or pull a face.
- The mode is hidden entirely until a parent enables Camera Games in the Parent Dashboard, which is behind a parental gate. Enabling it is the moment the operating system's camera permission prompt appears.
- While the mode runs, each video frame is analysed on the device by Google's MediaPipe face and hand landmark models, which are bundled in the app and run offline.
- Each frame is discarded immediately after it is analysed. No image, video, screenshot or face landmark data is ever recorded, stored, uploaded or shared with anyone. Nothing is written to our servers or to any file.
- Nothing is processed for the purpose of identifying or recognising a person. There is no face database, no matching and no biometric identifier.
- The camera is released the moment the mode is left, the app is backgrounded, or the screen is closed.
Microphone
Some levels let a child answer out loud instead of tapping.
- Voice answers are off by default and are switched on only by a grown-up in the Parent Dashboard, behind the parental gate. That is the moment the operating system's microphone permission prompt appears. The app never asks for the microphone during gameplay.
- Speech is converted to text by the device's own speech recognition (Apple's on iOS, Android's on Android, the browser's on the web). We do not record, store or transmit audio. Only the recognised text is compared against the expected answer, in memory, and then discarded.
- Note that the device's built-in speech recognition may itself be a service of Apple or Google, governed by their platform privacy policies and the settings you control on your device.
Data stored on the device
The app saves the following in its own local storage on the device:
- Child profile name, avatar emoji and colour theme
- The child's birth month and year, only if a parent chooses to enter it. It is optional and can be skipped. We deliberately never ask for, and cannot store, a full date of birth. The month is all that is needed for the one thing it is used for: suggesting which game modes suit that age when the profile is created. It is never used to identify anyone and is never shared.
- Levels unlocked, stars earned and high score
- Settings: language, volume, music, hints, playback speed, which modes are visible, and whether voice answers and camera games are enabled
- Whether camera or microphone permission was granted on this device (deliberately kept out of anything that syncs)
You can delete all of it at any time by deleting the profile, or by uninstalling the app.
Purchases
NoMiLudo is free to download with part of the game open, and a single purchase, not a subscription, opens the rest.
- The purchase is handled entirely by Apple or Google. We never see your name, your payment details or your store account, and no purchase information is sent to us or to anyone else.
- The app stores one thing about it: a flag on this device recording that the full version was bought. It is deliberately kept out of cloud sync, in the same way the camera and microphone grants are. A purchase belongs to the store account that made it, not to a child's profile.
- To move the purchase to another device, use Restore in the Parent Dashboard. That asks the store, not us.
- The offer is only reachable from behind the parental gate, so a child cannot reach it on their own.
Optional cloud sync
Cloud sync exists so a family's progress can move between devices. It is entirely optional and off unless a parent signs in.
- Signing in uses Google Sign-In and can only be started from behind the parental gate.
- If, and only if, a parent signs in, we store in Google Firebase (Firebase Authentication and Cloud Firestore):
- The parent's Google account identifier, email address, display name and profile photo URL
- For each child profile: the name, avatar, colour, the optional birth month and year, and the progress and settings listed above
- Every document is stored under the signed-in parent's own account identifier and is readable and writable only by that account. This is enforced by server-side security rules.
- We do not sell, rent or share any of this with anyone. It is not used for advertising, profiling or any purpose other than syncing your own progress back to you.
- Google acts as our data processor for this storage. See https://firebase.google.com/support/privacy.
Deleting your data
- Delete a profile (Profiles → Manage → 🗑️, behind the parental gate). Removes that child's data from the device and from the cloud. If the device is offline, the deletion is remembered and retried on the next connection.
- Sign out. Stops all syncing. Data already in the cloud stays until you delete the profile.
- Reset progress (Parent Dashboard → Settings). Clears stars and unlocked levels for the active profile.
- Uninstall the app. Removes everything stored on the device.
To have any remaining cloud data erased, contact us at the address below and we will delete it.
Children's privacy
NoMiLudo is intended for children and is designed to comply with COPPA, the GDPR (including Art. 8), and the Apple Kids Category and Google Play Families requirements.
We collect no personal information from a child directly. The only child-related information that can ever leave the device (a profile's name, avatar and the optional birth month) is entered by a parent from behind the parental gate, and only leaves the device at all if that parent has also deliberately signed in with their own Google account. There is no advertising, no analytics, no tracking, no social features, no user-to-user communication, no user-generated content sharing and no way to contact anyone from inside the app. The single in-app purchase described above is reachable only from behind the parental gate.
Changes
If this policy changes materially, the updated version will be published here and in the app before the change takes effect.
Contact
Questions, or a request to delete data: [email protected]