Privacy Policy
Calmina turns two phones into a baby monitor. The sound and video from the nursery travel directly between your two phones, encrypted, and are never recorded — not on your phones, and not by us. This page lists, without exception, the small amount of data our servers do handle.
The short version. No account. No ads. No analytics or tracking SDKs. We never sell or rent data. Nursery audio and video are never stored anywhere. What our server holds is the bookkeeping needed to connect your two phones and to wake you when your baby cries.
1. Who we are
Calmina is provided by Parksoft EOOD, Aleya Vazrazhdane 110, ent. 1, fl. 2, 7000 Ruse, Bulgaria, the data controller for the processing described here. Contact: hello@calmina.app.
2. We do not have accounts
Calmina has no sign-up, no login, no email address, no password and no user profile. Two phones are paired with a temporary 6-digit code (typed or scanned as a QR code). We therefore hold no name, email address, phone number, postal address or contacts for you at any point.
3. Nursery audio and video
Live audio and video are sent over a direct, encrypted peer-to-peer connection (WebRTC, DTLS-SRTP) between the nursery phone and the parent phone. Specifically:
- Audio and video are never written to storage on either phone. The app contains no recording or playback-of-past-audio feature.
- Audio and video never pass through our servers in a readable form, and we cannot decrypt them.
- If the two phones cannot reach each other directly (some mobile and office networks), the encrypted media is bounced through a relay server (TURN) that we operate. The relay forwards encrypted packets and cannot read their contents. Nothing is retained there.
- Cry, sound and movement detection all run on the nursery phone itself. Only the fact of an event leaves the phone — never any audio.
4. What our signalling server handles
To introduce your two phones to each other and to deliver alerts, our server processes the following. This list is exhaustive.
| Data | Why | Kept for |
|---|---|---|
| Pairing code, room identifier, session resume token, and which phone is the nursery vs. the parent | To connect your two phones and let them reconnect after a dropout without re-pairing | The life of the pairing; up to 30 days after the nursery phone was last online, then deleted |
| Connection setup messages (network addresses and media-capability descriptions) | Required to negotiate the direct phone-to-phone connection | Not stored — relayed and discarded |
| Nursery phone status: charging or on battery, battery percentage, whether video is available | So the parent phone can show “Nursery phone · 47%” and warn you before the nursery phone dies | Not stored — relayed and discarded |
| Alert events: the kind of event (crying, sound, movement, low battery, monitoring stopped) plus a timestamp and an intensity number | To deliver the alert to the parent phone, including as a push notification when the app is closed | Not stored — relayed and discarded. Your alert history is kept only on your own parent phone. |
| A push notification token for the parent phone (issued by Google Firebase Cloud Messaging) | The only way to wake a locked parent phone for a cry alert | Deleted with the pairing. It is never shared with the other phone or with anyone else. |
| A one-way SHA-256 hash of your device’s Android ID | To count how many free nights you have used, so that reinstalling the app does not reset the free trial | Until you ask us to delete it. It is not shared with anyone and is not used to build a profile or for advertising. |
| Standard server logs (IP address, timestamp) generated by receiving a connection | Security, abuse prevention, and diagnosing outages | up to 30 days, then rotated automatically |
5. Crash reports
Release versions of the Android app include Firebase Crashlytics. When the app crashes, it sends Google a crash report containing the stack trace, the app version, your device model, your Android version, and a Crashlytics installation identifier. We use this only to find and fix stability bugs; it is never used for advertising or tracking. Crash reports are filtered before sending to strip identifiers such as pairing codes and tokens. Google acts as our processor for this: see the Firebase privacy documentation.
6. Diagnostics you choose to send
Settings contains a “Send diagnostics” button. Nothing is sent unless you tap it. When you do, the app uploads a technical log of the recent monitoring session (connection states, timings, error codes) to us, with pairing codes, tokens and credentials removed. It contains no audio, no video, and no images. We use it only to investigate a problem you are reporting.
7. Payments
Subscriptions are sold and processed by Google Play. Your payment details are entered into Google’s payment sheet and are never seen by, or transmitted to, Calmina. We receive only whether a valid subscription exists for the device. Google’s handling of your payment data is governed by the Google Privacy Policy.
8. Device permissions
Android will ask for these. Each is used only for the purpose given, and you can revoke any of them in system settings.
- Microphone — on the nursery phone: to hear the room, detect crying, and stream live audio to the parent phone.
- Camera — on the nursery phone: to stream live video while you are watching, and to detect movement if you turn that on. On the parent phone: only to scan the pairing QR code.
- Notifications — to deliver cry and status alerts.
- Display over other apps / full-screen alerts — so a cry alarm can wake a locked phone, like an alarm clock or an incoming call.
- Do Not Disturb access — optional, and the reason Calmina exists: it lets a critical cry alert sound through silent mode. You can switch this off in Settings.
- Nearby devices (Bluetooth) — optional, used only to hand a fresh pairing code between your two already-paired phones over a short range. Calmina does not use Bluetooth to derive your location, and requests it with Android’s “never for location” flag.
- Ignore battery optimisations — optional, so the nursery phone keeps monitoring with its screen off.
Calmina never requests location, contacts, files, photos, SMS or call logs.
9. Children
Calmina is a tool for parents and caregivers and is not directed at children. We do not knowingly collect personal data from children. Although the app is used to watch over a child, no information about that child — no audio, no video, no name, no health data — is transmitted to or stored by us. A baby’s name, if you enter one, stays on your own phone.
10. Legal basis (EEA/UK)
- Performance of a contract — pairing data, connection setup, alert delivery and the push token: without these, the app cannot do the one thing you installed it for.
- Legitimate interests — security logs, abuse prevention, crash reports and the hashed device identifier used to keep the free trial honest.
- Consent — sending a diagnostics report, which happens only when you tap the button.
11. Your rights
You can ask us to access, correct, delete, restrict or port your data, and object to processing based on legitimate interests. Because we hold no account, please tell us which data you mean when you write to us.
- Delete everything, yourself, at once: tap Unpair in the app on both phones. That deletes the pairing, the resume token and the push notification token from our server.
- Uninstalling removes the on-device data (alert history, settings, the baby’s name). Pairing and push tokens are excluded from Android backups and device-to-device transfer.
- The free-nights record is the one item that outlives uninstalling, by design. Email us at hello@calmina.app and we will delete it.
- You may lodge a complaint with your data protection authority. Ours is the Bulgarian Commission for Personal Data Protection (cpdp.bg).
12. Where data is processed
Our signalling and relay servers are located in Germany (Hetzner Online GmbH, Nuremberg) — inside the EU. Push notification delivery (Google Firebase Cloud Messaging) and crash reporting (Firebase Crashlytics) are operated by Google and may involve transfers outside the EEA under the European Commission’s Standard Contractual Clauses.
13. Security
Signalling runs over TLS (wss://); media is encrypted with DTLS-SRTP; pairing codes are short-lived; a pairing code sent over Bluetooth is encrypted with a key that only your two already-paired phones hold. No system is perfect, but we do not hold nursery audio or video, so a breach of our servers cannot expose them.
14. Changes to this policy
If we change this policy we will update the date at the top, and announce material changes in the app before they take effect.
15. Contact
Parksoft EOOD
Aleya Vazrazhdane 110, ent. 1, fl. 2
7000 Ruse, Bulgaria
EIK 206376011 · VAT BG206376011
hello@calmina.app
Calmina is not a substitute for direct adult supervision or a medical monitoring device.