This Privacy Policy (the “Policy”) describes what data is processed when the RomaTalk mobile application (the “App”) is used, for what purpose and on what legal basis, as well as what rights you have as a user.
Please read this document carefully. By installing and using the App, you confirm that you have read this Policy.
1. Who we are (data controller)
The developer of the App and the operator (controller) of personal data processing is:
- Developer: Serhii Lypii, sole trader (eenmanszaak)
- Address: Juliana van Stolbergstraat 28, 4532 AZ Terneuzen, the Netherlands
- KvK (Chamber of Commerce): 99817039
- Contact email: serhii@lypii.nl
- Website: https://apps.lypii.nl/romatalk/
For any questions related to privacy and data processing, you can write to us at the email address indicated.
2. The main points in brief (summary)
RomaTalk is an offline augmentative and alternative communication (AAC) app that helps non-verbal children and children with developmental differences to communicate using picture cards with voice output.
- The App works completely offline and does not require registration, sign-in or the creation of an account.
- All your data (child profile, cards, photos, audio recordings, settings) is stored only locally on your device. We have no access to it.
- The App has no ads, no analytics systems, no trackers and no crash reports that transmit data to third parties.
- The only case in which data leaves the device: when the “RomaTalk Pro” subscription is bought or restored, a receipt (purchase token) is sent to our server to verify its authenticity. The child's name, photos, voice recordings or card content are not transmitted.
- Speech synthesis is performed by the built-in engine of your operating system on the device.
Full details are given below.
3. Scope
The Policy applies to the RomaTalk app for Android and iOS, distributed through Google Play and the Apple App Store.
The Policy does not apply to third-party services through which the App is distributed or payments are processed (Google Play, Apple App Store), nor to the operating system of your device (including its built-in speech synthesizer). The processing of data by these services is governed by their own privacy policies (see section 8).
4. Core principles (privacy by default)
The App is designed according to the principles of privacy by design and data minimization:
- Local storage. Data is created and stored on your device and remains under your control.
- No accounts. We do not create an account for you and do not identify you as an individual.
- Minimization. The App requests only those permissions that are necessary for its functions, and only at the moment the corresponding function is used.
- No tracking. We do not track your behavior or your location and do not build user profiles.
5. What data is processed and where it is stored
All the data listed below is entered by you and stored locally on the device (in the protected database of the app and in its internal files). We, as the developer, do not receive and do not store this data on our servers.
5.1. Child profile
- The child's name (which you enter yourself).
- Gender (for the choice of voice output and design options).
- Avatar color.
5.2. User cards and categories
- Card names and captions.
- Photos that you add to the cards (taken with the camera or chosen from the gallery).
- Audio recordings of your voice, if you record the voice output of a card.
- Categories, order, “Favorites” marks and other properties of the cards.
5.3. Usage data (on the device only)
- Local history of card use (counter and time of last use) for the “Recent” function.
5.4. Settings
- Interface and playback settings (grid size, speech rate, theme, language and similar).
5.5. Parent area and security
- The PIN of the parent area is never stored in plain form. Only its cryptographic hash (SHA-256 with a random salt) is stored, in the protected storage of the device (Keychain on iOS / Keystore on Android).
- A flag showing that biometric unlocking is enabled (Face ID / fingerprint), which is performed by means of the operating system. Biometric data is processed by the OS and is not transmitted to us.
Important: deleting the App or using the data reset function in the App removes all the local data listed from the device.
6. Data we do NOT collect
We do not collect and do not transmit to us or to third parties:
- geolocation data;
- contacts, calendar, list of apps;
- advertising identifiers (Advertising ID / IDFA);
- analytics data or data on behavior in the app;
- crash reports containing your data;
- card content, photos, audio recordings or the child's name.
The App contains no ads and no third-party advertising or tracking SDKs.
7. The only transfer of data outside the device: purchase verification
If you make the one-time purchase “RomaTalk Pro” (or restore a purchase made earlier), the App sends a request to our verification server at:
https://apps.lypii.nl/romatalk/api/verify.php
- What is transmitted: the platform type (ios or android), the product identifier and the receipt / purchase token issued by the store (Google Play or App Store).
- What is NOT transmitted: the name or gender of the child, photos, audio recordings, card content, device identifiers, advertising identifiers.
- Purpose: to confirm that the purchase is genuine and to activate the Pro features. The server returns a signed confirmation (entitlement), the authenticity of which the App verifies locally.
- Legal basis (GDPR): performance of a contract — providing you with the feature you paid for (Art. 6(1)(b) GDPR).
- The connection is made over the secure HTTPS protocol.
- Storage: the receipt is used exclusively to verify the purchase and is not retained by us in order to create a profile of you. Technical web server logs (if they are kept by the hosting provider) may be stored temporarily for a limited period determined by the hosting settings, and are used only to ensure the security and correct operation of the service. We do not link the receipt to your identity and do not use it for profiling or marketing.
Donations (“tips”) are processed by the app store directly and do not cause any request to our server.
8. Payments and third-party services (processors)
The App uses a limited range of third-party services:
- Google Play (Google) / Apple App Store (Apple) — distribution of the App and processing of payments for in-app purchases. Payment details (bank card data and similar) are processed directly by the store; we do not receive, do not see and do not store them. These companies act as independent controllers with regard to payment data.
- Hostinger — the hosting provider that hosts our purchase verification server and processes the corresponding requests on our behalf (data processor). Privacy policy
We do not sell your data and do not transfer it to third parties for marketing purposes.
9. App permissions and the purposes they are used for
The App requests permissions only as they become necessary and uses them strictly locally:
| Permission |
What it is used for |
| Microphone |
Recording a parent's voice for the voice output of a card. The recording is saved locally. |
| Camera |
Taking a photo for a card. On Android the system camera app is used. |
| Photo gallery / photos |
Choosing an existing photo for a card. |
| Face ID / biometrics |
Unlocking the parent area by means of the OS. |
| Internet access |
Only for the verification of Pro purchases (see section 7). The other functions do not require the internet. |
| OS speech synthesis settings |
Help with installing a missing voice through the system settings. |
Data obtained through the camera, the microphone and the gallery is used exclusively locally and is not transmitted anywhere.
10. Speech synthesis (voice output)
The voice output of the card text is performed by the built-in speech synthesizer of your operating system on the device itself. Priority is given to your own audio recording, if there is one. The text of the cards is not sent to any cloud speech synthesis services.
If the required voice is not present on the device, the App may suggest installing it through the system settings of your operating system. The download is performed by your OS, not by our App and not by our servers.
11. Children's privacy
RomaTalk is an app intended for use by children under the supervision and management of parents, guardians, teachers or specialists. We take the protection of children's data seriously.
- We do not collect children's personal data on our servers. The name and gender of the child are entered by an adult and are stored only locally on the device.
- App configuration and purchases are protected by a parent area with a PIN, so that the child cannot accidentally change settings or make a purchase.
- The App has no ads and no behavioral tracking of children.
- We aim to comply with the applicable requirements for the protection of children's data, including the US Children's Online Privacy Protection Act (COPPA), the provisions on the protection of children's data in the GDPR (EU) and the Google Play Families Policy.
The only outgoing transfer of data (the purchase token, section 7) is not personal data of the child and is initiated by an adult's action when making a purchase.
If you believe that we have become aware of any personal data of a child contrary to this Policy, contact us at serhii@lypii.nl and we will take the necessary measures.
12. Disclosure of data to third parties
We do not sell, do not rent out and do not transfer your data to third parties, except:
- processors acting on our behalf for the verification of purchases (section 8);
- where this is directly required by law, on a lawful request from a public authority, or in order to protect our rights, the safety of users or to prevent fraud.
Since the content of your cards, the photos, the recordings and the child's name do not leave the device, we are technically unable to transfer this data to anyone.
13. International data transfers
The purchase verification server is hosted with the hosting provider Hostinger. If the processing of the purchase token takes place on servers located outside the European Economic Area (EEA), we ensure that the appropriate legal safeguards provided for by the GDPR are in place (in particular, the EU standard contractual clauses). If the servers are located within the EEA, no international transfer of data takes place.
Your other data does not leave the device and is therefore not subject to international transfer.
14. Data retention and deletion
- Local data (profile, cards, photos, recordings, settings) is stored on the device until you delete it manually, use the data reset function in the App, or delete the App.
- Deleting the App leads to the deletion of all local data, including the entries in the protected storage.
- Purchase verification data on the server side is processed to the extent and for the period indicated in section 7.
15. Your rights
Depending on your jurisdiction (in particular, under the GDPR for users in the EEA and the CCPA/CPRA for residents of California), you may have the following rights:
- the right of access to the data and to receive a copy of it;
- the right to rectification of inaccurate data;
- the right to erasure (the “right to be forgotten”);
- the right to restriction of processing and to object to it;
- the right to data portability;
- the right to withdraw consent where the processing is based on it;
- the right to lodge a complaint with a supervisory authority for data protection.
How to exercise your rights in practice. Since almost all of your data is stored locally and is under your full control, you can view, change and delete it yourself, right in the App (including a complete data reset). To exercise your rights in respect of data related to purchase verification, contact us at serhii@lypii.nl. We will reply within the time limits set by applicable law.
For residents of California: we do not sell and do not share personal information within the meaning of the CCPA/CPRA.
For users in the EEA: you have the right to lodge a complaint with a data protection supervisory authority. For the Netherlands this is Autoriteit Persoonsgegevens.
16. Legal bases for processing (GDPR)
We process data on the following bases:
- Performance of a contract (Art. 6(1)(b)) — providing the functions of the App, including the verification and activation of Pro purchases.
- Legitimate interest (Art. 6(1)(f)) — ensuring security and protection against fraudulent purchases; in doing so we aim to minimize the data processed.
- Consent (Art. 6(1)(a)) — where it is required (for example, access to the camera, the microphone or the gallery is granted by you through the system permissions).
The processing of data that does not leave your device takes place under your control; we have no access to it.
17. Data security
We take reasonable technical and organizational measures to protect data:
- storing data locally on the device, in an area isolated for the App;
- storing the PIN only as a hash with a random salt in the protected system storage;
- using a secure HTTPS connection for the verification of purchases.
No method of storing or transmitting data can be absolutely secure, however we aim to use generally accepted protection measures. The security of the device itself (password, encryption, access by third parties) is your responsibility.
18. Changes to the Policy
We may update this Policy from time to time. The current version is always available at https://apps.lypii.nl/romatalk/privacy with the date of the last update indicated. In the event of material changes we will notify you in the App or by another available means. Continued use of the App after the changes take effect means that you agree to the updated Policy.
19. Contacts
For any questions about this Policy or about the processing of data:
This document is presented in English. Where versions in other languages exist, in the event of a discrepancy in interpretation the version in Dutch (NL) prevails.