alma — Privacy Policy

Translation. Alma is a Hebrew-language service and the Hebrew policy at privacy.html is the governing version, mirrored in-app under Settings → מדיניות פרטיות. This English text is provided for review convenience; in case of any discrepancy, the Hebrew version governs.

Last updated: 25 August 2026

alma is an educational app primarily designed for children ages 6–8, used under a parent or guardian account. Advanced curriculum for grades 4–6 is also available when selected by the family. This policy describes the active Version 1 (“V1”) product: lessons, learning progress, the Alma AI tutor, child-to-Alma voice features, camera activities, friends, structured duels, and optional notifications. The peer knowledge shop is not active in V1 and cannot be enabled remotely.

Release-verification notice. The source code identifies the processors and app-controlled retention described below. The operator’s complete legal identity, executed child-data processor terms, provider account-level retention settings, cloud log/backup retention, and the final App Store archive privacy report still require product/legal verification before this policy is approved for a production Kids Category release. Alma does not claim Zero Data Retention (“ZDR”) merely because an API request uses store=false.

1. Who operates Alma

Alma is operated by Siata AI, a registered Israeli sole proprietorship (עוסק מורשה), of 12 HaShiryonaim Street, Ashkelon, Israel. Siata AI is the controller of the personal information described in this policy. Privacy questions and requests may be sent to dbusbib@gmail.com.

2. Information Alma handles

Alma does not use advertising SDKs and does not request precise location, the device address book, or the photo library. It does not collect payment-card information. V1 contains no child-to-child text chat, peer voice messages, photo/video sharing, public posting, study groups, or peer knowledge shop.

3. Why Alma uses information

Alma does not sell personal information, share it with data brokers, use it for behavioral advertising, or track children across apps and websites owned by other companies.

4. AI tutor and parental consent

The Alma AI tutor is disabled for a child unless a parent grants the current, versioned AI consent in the parent area. The backend checks that consent before moderation, model calls, tool calls, stored-chat access, output delivery and persistence. If consent cannot be verified, the request is denied.

With consent, OpenAI may receive the child’s message, up to 12 recent messages needed for context, subject and lesson information, grade, grammatical gender, interests, learning progress, recent mistakes, placement answers, and tool input or output required to answer. Alma does not intentionally include the child’s name, parent email, Firebase UID, family ID or device token in the model prompt.

Child-facing OpenAI Responses and Chat Completions requests are configured with store=false, and child-agent tracing is disabled. Local deterministic safety rules and provider moderation are also applied. These code controls do not prove account-level ZDR or a specific provider abuse-log retention period; those facts depend on Alma’s OpenAI account and executed terms and must be confirmed before release.

5. Voice, transcription and text-to-speech

Voice features require a separate current parent consent. Microphone permission is requested only when the child starts a read-aloud activity.

Browser speech dictation is disabled in V1 because its processor and retention can depend on the browser or operating system. Provider-side retention for OpenAI transcription and Google Cloud Text-to-Speech must be confirmed from the applicable account settings and contracts.

6. Camera and handwriting

The camera is used only after a contextual choice to scan a parent-presented joining QR code or to show a live educational camera activity. The app does not take, store or upload camera photos or video frames.

In supported handwriting exercises, a server-authenticated child identity already bound to one family child profile may send on-screen stroke coordinates to the Alma backend; the request cannot select another child profile. The canvas is limited to 64–512 pixels per dimension, each request is limited to 4,096 finite in-bounds points, and a Firestore rate limit fails closed. A bundled deterministic server-side digit model processes the strokes in memory and returns a digit and confidence; the strokes are not stored and are not sent to an external AI provider.

7. Parent-directed account-link and reset sharing

A verified parent can create a six-digit account-link or password-reset code that expires after 15 minutes. Firestore stores the SHA-256 digest as the linkCodes document identifier, together with the owner/child/creator, type, expiry and use metadata; it does not store the raw code. Redemption claims that record transactionally for one child UID before family binding, so another UID cannot consume the same code in a race.

The app opens the operating-system share chooser or Web Share only after the parent chooses to share. The parent selects the recipient or app. Alma does not contact Meta or WhatsApp directly, include their SDK, use a wa.me URL, or preselect a social destination. If Web Share is unavailable, the browser copies the message to the local clipboard. A destination selected by the parent receives and handles the shared text under that destination’s own practices.

Successful redemption issues a narrow setup capability for only the permitted credential or PIN action. Its raw token is represented on the server only by a SHA-256 digest, is bound to the child identity, family, child and scope, expires after 20 minutes, and is consumed per scope. The web client keeps it in memory; a native client uses device-only Secure Store to cross the setup screens. Completed or skipped setup and account-data cleanup clear the client value; after 20 minutes the server rejects it even if an interrupted native flow has not yet cleared it.

8. Friends, blocks and structured duels

There is no public or global child directory and no friend search by username or handle. A verified parent can create a hashed, one-time invitation code for their child; the code expires after 15 minutes. Another child may redeem that code to create a friend request, but only the receiving child’s parent can approve or reject the relationship. Children see only the peer nickname/avatar fields required for an approved feature. Parents can remove or block relationships, and a block prevents friend and matchmaking interactions.

Direct duels require an approved friend relationship. Random matchmaking is server-selected and shares only the minimum peer display and game state needed to play. Duels support fixed actions such as invite, accept/decline, answer, score and result. They do not provide arbitrary messages, URLs, audio, images or video. The peer knowledge shop’s production route redirects home, its implementation is outside the production route tree, and immutable client/server V1 capability maps prevent a remote flag from enabling it.

9. Notifications

Alma does not ask for notification permission on a clean launch. A parent must enable notifications for a child in the parent controls before the app can request operating-system permission and register a token. Expo receives the token and a generic payload, then routes it through Apple Push Notification service (APNs) on iOS or Firebase Cloud Messaging (FCM) on Android.

Lock-screen text is generic, for example that a new duel invitation exists. It does not contain a child’s name, grade, join code, question, answer, score or internal identifier. Turning notifications off removes the child’s server token mappings and clears local scheduled notifications on the current device.

10. Service providers

ProcessorData and purposeApp-controlled retention
Google Firebase / Google CloudAuthentication, Firestore data, hosting, Cloud Run processing/logs, text-to-speech text/audio, and Firebase App Check verification.Active data and TTL periods below; cloud logs, backups, Google TTS retention, App Check registration and production enforcement require deployment/account confirmation.
OpenAIParent-approved tutor text/context, content moderation, and parent-approved read-aloud audio/transcription.App requests use the privacy controls described above; account-level retention and child-data terms require confirmation. No ZDR claim is made.
ExpoPush token, generic notification payload, and delivery ticket.Alma deletes stored token mappings on opt-out/deletion; Expo queue/log retention requires contractual confirmation.
Apple APNs / Google FCMDevice routing token and generic notification payload needed for delivery.Governed by the applicable platform service; confirm production credentials and terms before release.
Firebase App Check platform providersreCAPTCHA Enterprise on web, App Attest with DeviceCheck fallback on iOS, and Play Integrity on Android evaluate app/device integrity and anti-abuse signals. Alma does not intentionally include child profile, lesson or message content in attestation requests.Provider registration, hostname/signing restrictions, production enforcement, device signals and the final archive privacy report require verification.
Parent-selected share destinationThe operating system/browser and only the recipient or app selected by the parent receive the account-link/reset text.Alma does not choose or contact a social service directly. Clipboard and recipient retention are controlled by the selected platform/destination.

11. Retention

Firestore TTL deletion is asynchronous. Before release, Alma must verify that every described TTL policy is active in the production project and backfill or delete historical records that lack a native expiration field. This specifically includes old linkCodes documents whose raw code was used as the document ID or whose expiration was stored as a string, old setup grants, and inactive peer-shop/group/chat/voice records. Alma must also set and document bounded production retention for Cloud Logging, backups and provider-side logs.

12. Parent choices and deletion

A verified parent can view and edit a child profile, manage friendships and blocks, and grant or withdraw AI, voice and notification consent separately. Withdrawing AI consent blocks new provider processing and deletes the child’s stored tutor chats and generated day recaps from the active database. Withdrawing voice consent blocks new recording, transcription and external text-to-speech requests. Withdrawing notification consent removes the child’s push-token mappings.

A parent can delete an individual child profile or the owner account inside the app. The server-authoritative, retryable deletion process covers Firebase Auth identities; current and legacy profiles; progress, answers, attempts and sessions; account-link/reset records and setup grants; friendships, requests and blocks; duel and matchmaking data; reports; push tokens; device credentials; stored tutor content; and identified legacy group/voice/shop records. After the server confirms deletion, the app clears Alma AsyncStorage, local web storage, child resume tokens, setup grants, cached push tokens and notifications. A secondary parent deleting only their own account does not delete the family owner’s children.

To request access, a copy, correction or deletion, email dbusbib@gmail.com. We may need to verify that the requester is authorized for the family.

13. Security

Alma uses encrypted network transport, Firebase authentication, server-side child/family authorization, parent gates for sensitive controls, bounded inputs and fail-closed rate limits on sensitive code and handwriting flows. Release clients are designed to use Firebase App Check through reCAPTCHA Enterprise, App Attest/DeviceCheck and Play Integrity for the Alma backend, but production provider registration, signing/hostname restrictions and enforcement must be verified before release. Firebase Storage client access is denied in V1. No security measure is perfect; please report a suspected privacy or security issue to the contact above.

14. International processing and legal rights

Google, OpenAI, Expo and Apple may process data outside the child’s country. The production operator must confirm the contracting entities, processing locations, transfer mechanism, age band and jurisdiction-specific parent-consent process before release. Parents may have rights to access, correct, restrict, object to or delete personal data depending on applicable law.

15. Changes and contact

Material changes will update the date above and, when a provider/data practice changes, will invalidate the old versioned consent so a parent can review the new disclosure.

Privacy questions or requests: dbusbib@gmail.com.