Small data footprint, plain-language choices
Privacy Policy
This policy explains what Talking Robot processes, what it deliberately does not collect, and how voice requests are handled.
Last updated: 16 September 2026
Kenzi does not store microphone recordings in Talking Robot’s database or file storage. With a grown-up’s permission, audio is transmitted to OpenAI to understand the request and create a spoken response.
1. Privacy by design
Talking Robot is operated by Kenzi.ai and is designed for children and families. We aim to collect the minimum information needed to run the game, protect the service, calculate battery use, and improve reliability.
The app does not ask a child to create an account or provide a name, email address, phone number, home address, school, contacts, precise location, or profile photo. It does not include public profiles or a social feed. Supported iOS and Android versions offer optional, user-initiated rewarded videos through Google AdMob, as explained below.
2. Information the app processes
The service processes limited device and operational information, including:
- A random device/installation identifier and protected authentication token. The installation identifier is stored as a one-way hash on our server.
- Platform, app version, language/locale, a two-letter country code inferred at the network edge, timestamps, and last activity time. We do not use this country code as precise location.
- Battery balance, battery transactions, purchase validation records, store transaction identifiers, product and price details, and related anti-fraud information.
- For an optional rewarded video: an installation-linked reward session, a single-use verification token, ad unit and transaction identifiers, completion or failure status, timestamps, awarded battery, and any estimated ad revenue and currency reported by the ad provider. These records verify rewards, enforce limits, prevent duplicates, and support accounting; they do not contain voice recordings or conversation text.
- An encrypted push-notification token and delivery status only when a grown-up chooses to enable notifications.
- Technical interaction metrics such as audio duration, token counts, reply length, success/failure status, and diagnostic correlation identifiers.
- Standard security logs, which may include IP address, user agent, request time, route, and response status, for security, abuse prevention, and reliability.
- On our public website, Google Analytics may process page views, link interactions, referrer, browser and device type, approximate region, and pseudonymous analytics identifiers.
3. Voice recordings and AI processing
The microphone activates only when the child or parent starts a talk interaction and the device grants microphone permission. The recorded clip is transmitted securely to the Talking Robot API and then to OpenAI’s API services to convert speech to text, generate a child-aware reply, and create the robot’s spoken audio.
Kenzi does not save the microphone recording to its database, local server files, or cloud object storage. We process it in memory for the request and discard it from our systems after the request completes. We also do not store the full transcript or robot reply in our persistent interaction database.
OpenAI processes submitted data as our AI service provider. OpenAI states that API data is not used to train its models by default. Under OpenAI’s current API data controls, some reply and speech request data may be retained for up to 30 days in abuse-monitoring logs. Kenzi has not opted in to model training. Families should not say names, addresses, contact details, or other sensitive personal information to the robot.
4. Short-term conversation memory
To make a short exchange feel like a conversation, up to two recent child-and-robot turns may be held in volatile server memory for up to 15 minutes. This memory is linked to an installation and conversation identifier, is not written to the conversation database, and disappears when it expires or the service restarts.
5. Why we use information
We use the limited information described above to:
- Register and recognize an app installation without creating a child account.
- Understand a voice request and return an AI-generated spoken response.
- Apply child-safety checks to incoming and outgoing content.
- Maintain battery balances, validate purchases, prevent duplicate charges, and investigate fraud.
- Verify optional ad rewards, enforce the displayed daily allowance, reconcile ad earnings, and investigate failed or duplicate rewards. Test ads and manual support grants are kept separate from real sales and ad earnings.
- Protect the API, diagnose errors, monitor availability, and improve product performance.
- Understand how visitors use our public website and which app download links they choose.
- Meet legal obligations and respond to valid requests from authorities where required.
6. When information is shared
We do not sell children’s personal information or use it for behavioral advertising. Information is processed by providers needed for the selected feature: OpenAI for speech and AI replies; Google Firebase Cloud Messaging for optional notifications; Google AdMob for optional rewarded videos, ad measurement, and fraud prevention; Bunny CDN for a static greeting and public-website files; our hosting and security providers; Apple or Google for store purchases; and Google Analytics on the public website. We may also disclose information when required by law.
The mobile app does not include Firebase Analytics or Google Analytics. The advertising SDK does perform ad-related measurement and diagnostics when its optional feature is used; this is different from website analytics. Firebase Cloud Messaging receives an app installation token and technical delivery information after a grown-up opts in and may process limited performance diagnostics. Notification data is not used by us for advertising profiles.
Providers process information under the terms and privacy commitments applicable to their services. Google describes its advertising processing in the links in the next section. We may also disclose information to protect a child, user, Kenzi, or the public from a credible safety or security threat, where legally permitted.
7. Optional rewarded ads on iOS and Android
Rewarded ads are an optional way to add battery credit in supported app versions. Selecting “Watch a video” starts the video flow after any required privacy choices; newer versions do not require the two-second grown-up hold for this option. Parents should supervise children’s use of ads. We do not start an ad on app launch or during a conversation, and declining the offer leaves free building and mini games available. Purchases and parent-controlled settings retain their grown-up checks.
Google’s User Messaging Platform may check whether privacy choices are required when a supported iOS version opens. This check does not start an ad. Any required privacy form is presented before requesting an ad, and a “Privacy choices” button is available in the app’s settings or charging area when Google requires it so those choices can be reviewed. A button tap or grown-up hold does not replace consent required by law.
We request non-personalized ads and apply the general-audience (G) ad-content limit. We disable publisher first-party personalization, do not request App Tracking Transparency permission, and remove the Android advertising-ID permission. Age-treatment settings vary by platform and app version; a G content rating controls ad content and does not itself identify a user’s age. We do not provide AdMob with names, email addresses, microphone audio, transcripts, purchase receipts, or our persistent support device ID. Reward verification uses a random, single-use token rather than a child profile.
Non-personalized does not mean no data is processed. Google’s Mobile Ads SDK can receive the device’s IP address and approximate region, app/device technical identifiers and characteristics, ad impressions, taps and video interactions, and crash or performance diagnostics. Google uses this information for ad delivery, measurement, security, and fraud prevention. Privacy settings limit personalization but do not remove all network and diagnostic data processing.
Kenzi stores reward and accounting records on its service infrastructure. Google and its advertising-service providers may process data on servers in multiple countries under Google’s published policies. Their retention periods depend on the data and purpose; we do not claim their processing stops instantly when a video closes. Parents can decline videos and contact us about installation-linked records. Deleting Kenzi records does not automatically delete records independently held by Google.
8. Retention and security
Voice recordings are not retained by Kenzi. Temporary conversation memory expires as described above. Device, battery, purchase, rewarded-ad verification, security, and technical records are kept only as long as reasonably needed to operate the service, meet financial or legal obligations, resolve disputes, and prevent abuse, after which they are deleted or anonymized where practical. See our data-deletion page for request steps and limited retention periods.
We use transport encryption, protected credentials, access controls, rate limiting, hashed identifiers, and other safeguards appropriate to the information. No online service can promise absolute security, so we continually review and improve these controls.
9. Parents’ choices and rights
A parent or guardian can decline voice processing in the app or deny or revoke microphone permission in the device settings; offline building and reactions can still be used. Notifications are optional and can be disabled in device settings. Removing the app may remove local preferences, but some server-side battery and transaction records may remain where needed for purchase restoration, fraud prevention, or legal compliance.
Rewarded videos are optional: choose a battery pack, return to free play, or close the charging area instead. No advertising consent or tracking permission is required to use the free activities. To report an inappropriate ad, contact us with the approximate time, platform, and advertiser if visible; do not include a child’s personal details.
Depending on where the family lives, a parent may have rights to request access, correction, deletion, restriction, or a copy of personal information. Because there is no account, we may request limited information needed to verify the relevant installation and the requesting adult’s authority.
10. Website analytics and cookies
The public website uses Google Analytics to understand visits, page performance, and app-store link activity. Google Analytics runs on heytalkingrobot.com only and is not included in the iOS or Android app. On the website, it may use cookies or similar browser storage and receive technical information such as an IP-derived approximate region, device/browser details, referrer, pages viewed, and interaction timestamps.
We use this information in aggregate to improve the website and app-discovery experience, not to create child advertising profiles. Visitors can limit cookies through browser settings or use Google’s available analytics opt-out controls. Website analytics and the mobile app’s optional rewarded-ad feature are separate services.
11. International processing and policy changes
Our providers may process data in countries other than the family’s country. We use appropriate contractual and technical measures where required. We may update this policy as the product, providers, or law changes; the current date will always appear at the top of this page.
Privacy question or parent request?
A parent or guardian can contact [email protected] about Talking Robot privacy, consent, or installation-linked data.
This information is written in plain language for families and is not a substitute for professional legal advice.
