Skip to main content

Privacy Policy

This policy explains what data every Easy Language (Tomojoyo Digital) app and web service collects, what it is used for, and how you stay in control of it.

Last updated: 21 August 2026 Effective from: 21 August 2026

1. The short version

  • No ads and no trackers. We ship no advertising SDKs, no third-party analytics, no pixels, and we never read advertising identifiers (Android Advertising ID / Apple IDFA).
  • Most data never leaves the device. Learning progress, practice scores, and preferences are stored locally.
  • Accounts are optional and belong to adults. Some apps offer an account so progress can be restored on another device. Accounts are registered by a parent or guardian, never by a child.
  • Voice is scored, then discarded. We keep no archive of children’s voice recordings.
  • We never sell or rent personal data to anyone, in any form.
  • You can request deletion at any time, from inside the app or by emailing easylanguage.pare@gmail.com.

This summary is here for readability. The sections that follow are the binding text in full.

2. What this policy covers

This policy applies to every mobile app, web app (PWA), and website published by Easy Language (Tomojoyo Digital) — whether installed from Google Play, the Apple App Store, or opened directly in a browser. We refer to them collectively as the "Services".

Any new app we release falls under the same policy from day one, unless that app ships an additional, clearly-disclosed notice inside the app itself.

This policy does not cover third-party services you may use alongside our apps — for example Google Play, the App Store, or your device’s built-in speech recognition. Those services have their own privacy policies.

3. Who is responsible for your data

Easy Language (Tomojoyo Digital) acts as the data controller under Indonesian Law No. 27 of 2022 on Personal Data Protection ("UU PDP") and as the data controller under the General Data Protection Regulation (GDPR) for users in Europe.

ItemDetail
PublisherEasy Language (Tomojoyo Digital)
Privacy emaileasylanguage.pare@gmail.com
AddressPare, Kabupaten Kediri, Jawa Timur, Indonesia
Response timeWithin 7 business days

We are not required to appoint a Data Protection Officer, as our processing is limited in scale and involves no large-scale systematic monitoring. All privacy requests are handled directly through the address above.

4. What we collect

We only collect what an app genuinely needs in order to work. Most of it stays on your device; the last column shows what actually reaches our servers.

CategoryExamplesPurposeSent to our servers?
Parent account dataName or nickname, email address, password (stored as a one-way hash, never as plain text)Creating and securing the account, restoring progress, sending essential account emailsYes — only if you choose to create an account
Child profileNickname or initials, approximate age or school year, chosen avatarMatching lesson difficulty and separating progress between siblingsYes — only if an account exists
Learning progressCompleted levels, practice scores, streaks, badgesShowing progress, resuming lessons, suggesting what to learn nextOnly with an account; without one it stays on the device
Speaking practice audioShort clips of a child repeating a word or sentenceScoring pronunciation and giving instant feedbackNot stored. See Voice processing
Avatar photo (optional)One image you pick from the gallery or take with the cameraUsed as the child’s profile picture inside the appNo — kept on the device unless you turn on account sync
In-app purchasesPurchase or subscription status, verification token from the app storeUnlocking paid content and restoring purchases on a new deviceYes — with no card data. See Purchases
Technical & diagnostic dataDevice model, OS version, app version, language, error logsFixing crashes and delivering the right content packagePartly — in minimal form, never used for profiling
IP addressThe IP recorded when the app contacts our serversBasic security, abuse prevention, and content deliveryYes — held briefly in server logs

5. What we never collect

To leave no room for doubt, we never collect, access, or ask for:

  • Precise (GPS) or network-based approximate location.
  • Contacts, phone book, SMS, call history, or calendar.
  • A list of the other apps installed on your device.
  • Advertising identifiers such as the Android Advertising ID (GAID) or Apple IDFA.
  • Biometric data: fingerprints, face scans, or voiceprints used for identification.
  • Credit card numbers, bank details, or any other payment credentials.
  • Health data, political opinions, sexual orientation, or any other special category of personal data unrelated to learning.
  • Photos or videos from your gallery beyond the single avatar image you pick yourself.
  • Voice recordings kept permanently or archived for any purpose.

6. How we use the data

We use what we collect strictly for the following purposes:

  1. Running the app — showing lessons, saving progress, and resuming where a child left off.
  2. Matching content to a child’s level — difficulty is chosen from practice results, never from behavioural or commercial profiles.
  3. Giving speaking feedback — scoring pronunciation live, then discarding the audio.
  4. Managing accounts and purchases — verifying sign-in, resetting passwords, restoring purchases on a new device.
  5. Keeping the service secure — detecting abuse, rate-limiting, and preventing unauthorised access.
  6. Fixing defects — analysing error logs so bugs can be repaired in the next release.
  7. Meeting legal obligations — for example retaining transaction records for tax and accounting purposes.

7. Legal bases for processing

For users in Indonesia we rely on Article 20 of the UU PDP. For users in Europe and the UK we rely on Article 6 GDPR. Specifically:

Processing activityLegal basis
Providing the core features you asked forPerformance of a contract (UU PDP Art. 20(2)(b) / GDPR Art. 6(1)(b))
Microphone, camera, and gallery accessConsent given through the system permission dialog, withdrawable at any time
Creation of a child profile by a parentParental or guardian consent (UU PDP Art. 25 / GDPR Art. 8)
Security, abuse prevention, bug fixingLegitimate interests balanced against your rights (GDPR Art. 6(1)(f))
Retention of purchase recordsLegal obligation under tax and accounting law

Where the basis is consent, you may withdraw it at any time without affecting processing carried out beforehand. Revoking microphone access, for instance, simply disables speaking practice — the rest of the app keeps working.

8. Device permissions we request

Every permission is requested at the moment its feature is about to be used, with a short in-app explanation. All of them are optional; declining only disables the related feature rather than blocking the app.

PermissionWhen askedWhyIf declined
MicrophoneWhen a child taps the speak button in a pronunciation exerciseBriefly capturing speech so it can be scoredSpeaking exercises are skipped; everything else still works
CameraWhen choosing a child’s avatar photoTaking a single profile pictureYou can still pick one of the built-in illustrated avatars
Gallery / PhotosWhen choosing a child’s avatar photoSelecting one existing imageSame as above
InternetAutomaticallyDownloading lessons, syncing accounts, verifying purchasesThe app runs on content already stored on the device
NotificationsWhen you switch on study remindersSending the reminders you configured yourselfNo notifications are sent
Device storageAutomatically, in the app’s private areaStoring offline lessons and progressCannot be disabled — the app requires it

You can revoke any permission at any time via Device settings → Apps → (app name) → Permissions on Android, or Settings → Privacy & Security on iOS.

9. Voice and speaking practice

Several of our apps train pronunciation and speaking. This section spells out exactly what happens to your child’s voice, because we know it is the most sensitive part.

How it flows

  1. 1

    Capture is momentary

    The microphone is live only while a child holds or taps the speak button, usually for a few seconds. There is no background recording, and the system microphone indicator is always visible while it is on.

  2. 2

    Speech becomes text

    Conversion happens on the device where an offline recognition model is available. On devices without one, the app uses the operating system’s built-in recognition (Google Speech Services on Android, Speech Recognition on iOS), so short clips are processed by that OS provider under their own privacy policy.

  3. 3

    Text is compared to the target

    The app compares the recognised text with the word or sentence that should have been spoken and calculates a similarity score.

  4. 4

    Audio is deleted

    The temporary audio file is removed from the device as soon as it has been scored — at the latest when the practice session ends. Only the score is kept, never the sound.

If you would rather no OS speech service be involved at all, simply decline the microphone permission. The app will skip all voice-based exercises and remains fully usable.

10. Children and the parent’s role

Our Services are designed for children but intended to be used with, or under the supervision of, a parent or guardian. We treat any data relating to a child as requiring heightened protection.

  • Only adults may register. Sign-up is addressed to parents or guardians and includes a confirmation that the registrant is at least 18 years old.
  • Minimal child data. We encourage nicknames or initials rather than full names. We never ask for a child’s home address, school, phone number, or full date of birth.
  • No ads and no trackers, in line with the Google Play Families Policy and App Store Kids Category guidelines.
  • No social features. There is no chat, no direct messaging, no public comments, and no way for a child to share content with strangers.
  • External links and purchases sit behind a parental gate — a simple challenge a young child is unlikely to pass.
  • Parental consent can be withdrawn at any time by deleting a child profile or the whole account.

A full account of our compliance with COPPA, Google Play Families, and the App Store Kids Category is on the Children’s Privacy page.

11. Third parties involved

We keep outside involvement to a minimum. This is the complete list of third parties that may process data when you use our Services:

PartyData involvedWhy they are involved
Google Play BillingPurchase status, purchase token, your Google account email (not passed on to us)Processing payments and subscriptions on Android. We only receive confirmation that a purchase is valid.
Apple App Store / StoreKitPurchase status and transaction receiptsProcessing payments and subscriptions on iOS, by the same mechanism.
OS speech recognition (Google / Apple)Momentary voice clips on devices without offline recognitionConverting speech to text so pronunciation can be scored.
Hosting and CDN providerIP address, request time, app versionHosting our servers and delivering lesson content quickly.
Google Play & App Store (store statistics)Aggregate data: install counts, versions, crash reportsSupplied automatically by the stores to every developer, aggregated and without individual identities.

None of the parties above are permitted to use your data for their own purposes. We do not use Firebase Analytics, Google Analytics, the Meta SDK, the TikTok SDK, ad networks, attribution tools, or behavioural heatmaps.

Should we ever need to add a new provider, this policy will be updated before the change takes effect.

12. Advertising and tracking

Because there are no ads, none of the tracking infrastructure that accompanies them exists either. We do not read advertising identifiers, do not fingerprint devices, do not embed conversion pixels, and do not follow users across apps or sites.

Since we do not track users, signals such as Do Not Track and Global Privacy Control change nothing about our behaviour — there is simply no tracking to switch off.

13. In-app purchases

Some apps offer paid content or subscriptions. All payments are processed by Google Play Billing or the Apple App Store, never by us.

  • We never receive, see, or store card numbers, bank details, or payment credentials.
  • All we receive is a digital receipt from the store confirming that a purchase is valid, plus whether a subscription is currently active.
  • Transaction records are retained for as long as tax and accounting law requires, even after your account is deleted.
  • Purchases always sit behind a parental gate so a child cannot buy anything without your knowledge.
  • Refund requests follow Google Play or Apple policy, as they are the official seller of record.

The full commercial terms are in the Terms of Service.

14. Where data lives and how long we keep it

Where it is stored

Local data lives in the app’s private storage area on your device, which the operating system shields from other apps. Account data lives on servers we rent from a professional hosting provider, with data centres in Indonesia and/or Singapore.

How long we keep it

Type of dataRetention period
On-device learning progressUntil you uninstall the app or clear its data
Account data and child profilesWhile the account is active, then erased once a deletion request is processed
Dormant accountsWe delete accounts untouched for 24 consecutive months, after notifying the owner by email
Speaking practice audioDeleted immediately after scoring; never archived
Error logsAt most 90 days, then removed automatically
Server logs containing IP addressesAt most 30 days, for security purposes
Purchase transaction recordsAs required by tax and accounting law, typically 5 to 10 years

Once a retention period ends, data is permanently deleted or anonymised so it can no longer be linked to a person.

15. How we protect data

We apply reasonable technical and organisational safeguards:

  • All traffic between the apps and our servers is encrypted with HTTPS/TLS.
  • Passwords are stored as one-way hashes using a modern algorithm — we cannot read them ourselves.
  • Sign-in sessions use short-lived tokens that can be revoked.
  • Access to production systems is limited to the people who need it and protected by two-factor authentication.
  • On-device data sits in the app’s sandboxed private storage, isolated by the operating system.

No system is perfectly secure. In the event of a personal data breach we will notify affected users and the competent authority within 3×24 hours of becoming aware, per Article 46 of the UU PDP, and within 72 hours under the GDPR for European users. Security reports are genuinely welcome — send them to easylanguage.pare@gmail.com.

16. Your rights over your data

Under the UU PDP and the GDPR, you — as the parent or guardian acting for your child — hold the following rights:

RightWhat it means for you
AccessRequest a copy of the personal data we hold about you and your child.
RectificationCorrect inaccurate or incomplete data, directly from the profile screen in the app.
ErasureRequest deletion of the account and all associated data.
RestrictionAsk us to pause processing of certain data while a dispute is resolved.
ObjectionObject to processing that relies on our legitimate interests.
PortabilityReceive your data in a structured, machine-readable format (we provide a JSON file).
Withdraw consentRevoke any permission you previously granted, at any time, without giving reasons.
ComplaintLodge a complaint with the data protection authority in your jurisdiction.

To exercise any of these, email easylanguage.pare@gmail.com from the address registered to the account. We reply within 7 business days and complete requests within 30 days at the latest. This is free of charge, except for excessively repetitive requests.

To protect you, we may ask for additional verification before acting on sensitive requests — for example confirming a message we send to the registered email address.

17. Deleting your account and data

You can delete your account at any time, without giving a reason, either from inside the app or by email.

Step-by-step instructions, the list of what gets erased, and what we must keep for legal reasons are on the Delete Account & Data page.

18. International data transfers

Our servers are located in Indonesia and/or Singapore. If you use the Services from another country, your data will be transferred to those regions for processing.

For users in Europe and the UK, such transfers are covered by Standard Contractual Clauses with our hosting provider, together with supplementary measures including encryption in transit and access restrictions. For Indonesian users, transfers follow Article 56 of the UU PDP, either to countries with an equivalent level of protection or under binding contractual safeguards.

20. Changes to this policy

We may update this policy when features change, a new provider is introduced, or regulations shift. Each version shows a "Last updated" date at the top of the page.

If a change is material — a new category of data, or a new purpose — we will announce it with a prominent in-app notice, and by email to account holders, at least 30 days before it takes effect. Where the law requires fresh consent, we will ask for it first.

Continuing to use the Services after a new policy takes effect means you accept it. If you disagree, you may stop using the Services and request deletion of your data.

21. Contact us

Questions, objections, or requests about personal data can be sent to:

ChannelDetail
Emaileasylanguage.pare@gmail.com
PublisherEasy Language (Tomojoyo Digital)
AddressPare, Kabupaten Kediri, Jawa Timur, Indonesia
Response timeWithin 7 business days

If you feel a complaint has not been handled adequately, you have the right to complain to the data protection authority in your jurisdiction. In Indonesia, complaints may be addressed to the competent personal data protection authority established under the UU PDP.

Questions about privacy?

Easy Language (Tomojoyo Digital)

Email us

Back to top