Privacy Policy

Last updated: May 29, 2026

1. About this Privacy Policy

This Privacy Policy describes how Kalyaki collects, uses, stores, and protects information when you and your child use the Kalyaki mobile application or visit https://kalyaki.com (together, “the service”).

The service is operated by Egor Sharapov, a Sole Professional licensed by the Dubai Development Authority (Sole Professional License No. 107100), registered at Building 16, Ground Floor, Dubai Internet City, Dubai, United Arab Emirates. For purposes of applicable data-protection laws, Egor Sharapov is the data controller of the personal data described in this Policy.

This Policy is incorporated into the Terms of Service at https://kalyaki.com/terms.

2. In brief

Plain-language summary, for parents in a hurry:

The detailed sections below explain each of these points and your rights.

3. What information we collect

From the mobile app

For each drawing your child completes, the app uploads to our servers:

No other information about the drawing session is uploaded.

When you make an in-app purchase, our purchase-processing partner Adapty receives the transaction details from Apple and shares with us:

Apple processes the actual payment; we do not receive your payment-card number, billing address, CVV, or any other payment information.

When you redeem a class code (issued to schools and educators who license Kalyaki for classroom use), the app sends the entered code together with the profile identifier to our server. Our server validates the code, consumes it, and grants the corresponding entitlements to that profile. We retain a redemption record that includes the redeemed code, the profile identifier, and the date and time of redemption. Where a class code is linked to a particular school or educator account, that affiliation is stored alongside the redemption record so that we can report classroom activation counts back to that school or educator. We do not share children’s first names, ages, drawings, or learning progress with schools or educators.

From the website (kalyaki.com)

When you visit the site, our infrastructure provider records standard server logs: your IP address, the page or asset requested, a timestamp, and your browser’s user-agent string. These logs are used only for security, troubleshooting, and basic operational diagnostics.

The site does not set any first-party cookies.

The site uses one third-party analytics service, PostHog, to measure ad-campaign effectiveness. Each pageview and each click on the App Store download badge is recorded together with: the URL visited, the referring page, any UTM campaign parameters present in the URL, your browser’s user-agent string, and an approximate location derived from your IP address. The site does not embed any other third-party trackers, analytics pixels, marketing tags, or social media SDKs.

PostHog is configured in cookieless mode: it does not set cookies, does not write to your browser’s local storage, and does not create a persistent visitor identifier. Each visit is treated as anonymous and cannot be linked to your other visits or to any other website. PostHog receives this data at us.i.posthog.com, operated by PostHog Inc. in the United States. You can opt out at any time by using a browser-level analytics blocker or by enabling your browser’s Do Not Track setting.

From the device

The mobile app does not collect, access, or transmit:

4. How we use this information

We do not use any of this data for behavioral profiling, advertising, marketing to children, or sale to third parties.

5. Service providers (subprocessors)

We rely on the following service providers to operate the service. Each is bound by its own privacy and security commitments and processes data only on Kalyaki’s instructions.

The mobile app does not use any third-party analytics providers, advertising networks, marketing-automation tools, or crash-reporting SDKs. The marketing site’s only third-party analytics provider is PostHog, configured as described above and in Section 3; we do not use Google Analytics, Mixpanel, Amplitude, Firebase Analytics, advertising networks, marketing-automation tools, or session-recording SDKs anywhere.

6. Where data is stored & international transfers

Drawings and metadata are stored in Cloudflare and AWS regions that may include locations outside the United Arab Emirates, typically in the United States or the European Union. Where personal data is transferred across borders, we rely on the standard contractual safeguards and certifications offered by our service providers.

All data is encrypted in transit (HTTPS) and at rest (using the default encryption provided by AWS S3 and Cloudflare).

7. Retention & deletion

Uploaded drawings and profile metadata are retained on our servers indefinitely for AI model training, unless you request earlier deletion.

Purchase records (the anonymous Apple transaction identifier, the product purchased, the transaction timestamp, and the associated profile identifier) are retained for as long as Apple and applicable tax, audit, and refund regulations require — typically several years — and as needed to honor your purchases on new devices. Purchase records do not contain payment-card details.

Class-code redemption records (the redeemed code, the profile identifier, the date and time of redemption, and any associated school or educator affiliation) are retained for as long as the underlying classroom license is active and for a reasonable period thereafter to handle support and audit requests.

In-app “Delete Account” (Settings → Delete Account) wipes the local profile and all on-device database records — drawings stored in the device’s gallery, profile name and age, learning progress, badges, and the profile identifier. This local wipe does not delete server-side records, because once the local profile is removed, the device no longer holds the link between the profile UUID and the child’s real first name; we cannot re-associate the server-side data to a real person without your help.

Server-side deletion is available on request. Email hello@kalyaki.com with one of the following, and we will delete the records and confirm by email within 30 days:

8. Children’s privacy

Kalyaki is designed for children ages 3–8 used under the supervision of a parent or legal guardian. We treat children’s privacy as a priority.

If you believe we have collected information from a child without appropriate parental consent, please contact hello@kalyaki.com and we will investigate and delete the records.

9. Your rights

As the parent or legal guardian of a child whose data is processed by Kalyaki, you may exercise the following rights on behalf of your child:

Depending on your country of residence, you may have additional statutory rights — for example under the United Arab Emirates’ Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), the UK or EU General Data Protection Regulation (GDPR), or California’s Consumer Privacy Act (CCPA). We honor requests asserting these rights regardless of jurisdiction.

To exercise any of these rights, email hello@kalyaki.com. Please include the profile_id (visible in the app’s Settings before deletion) or, if the profile has already been deleted on the device, the child’s first name and the approximate dates of use, so that we can locate the relevant records. We aim to respond within 30 days.

10. Security

We protect data using these practices:

No system can be guaranteed completely secure, but we work to apply reasonable, industry-standard practices for the scale of the service.

11. Changes to this Policy

The “Last updated” date at the top of this page tracks revisions. Material changes — such as the introduction of a new category of data we collect, a new subprocessor, or a change to our retention practice — will be highlighted in a notice on kalyaki.com and, where reasonable, in the app, at least 14 days before they take effect.

By continuing to use the service after the revised Policy takes effect, you accept the changes. If you do not accept the revised Policy, stop using the service and contact us to request deletion of your child’s records.

12. Contact

Questions about this Privacy Policy or your rights under it? Contact us:

When emailing about a privacy request, please include “Privacy Request” in the subject line so we can route it quickly.