What Calmina can and can’t see
Putting a camera and a live microphone in your child’s room is a real decision, and “we take your privacy seriously” is not an answer. This page is the specific version: what is stored, what travels where, what the encryption does and does not protect you from, and how to check any of it yourself.
The short version. Nothing is recorded, anywhere. There is no account, so there is nothing to breach and nothing to sell. The stream is encrypted end to end between your two phones. Our server holds the small amount of bookkeeping needed to introduce them — and one anonymous code that counts your free nights.
Is anything recorded?
No. Not on our servers, and not on your phones either. Audio and video are never written to storage, and the app contains no recording feature and no way to play back the past — there is no history to enable, no clip to accidentally share, and no archive to leak. The stream is live or it does not exist.
This is a design decision with a cost: you cannot go back and listen to what happened an hour ago. We think that trade is the right way round for a device pointed at a child.
Where the sound and video actually go
Directly from the nursery phone to your phone, encrypted the whole way, using the same technology as an encrypted video call (WebRTC with DTLS-SRTP).
The honest complication, which most monitor marketing skips: a direct connection is not always possible. Some mobile and office networks will not let two devices talk to each other. When that happens the encrypted stream is bounced through a relay server we run in the EU.
The relay forwards packets it cannot read. The encryption is between your two phones, so the relay sees ciphertext and nothing else, and it retains none of it. That is a meaningfully different claim from “we never see your video” and it is the true one — we would rather say the complicated accurate thing.
What our server actually holds
The complete list, not a summary:
- Pairing data — the code, a room identifier, a resume token so a dropped connection can recover without re-pairing, and which phone is which. Deleted within 30 days of the nursery phone last being online.
- A push notification token for the parent phone. This is the only way to wake a locked phone, and it is deleted with the pairing.
- An anonymised device code — a one-way hash — used only to count how many free nights you have used so a reinstall does not reset the trial. It is shown to you in the app, and one tap writes the email that has it deleted.
- Standard server logs (IP address, timestamp), kept up to 30 days for security and diagnosing outages.
- Connection-setup messages and relay addresses, which are relayed and discarded rather than stored.
That is everything. The privacy policy states it formally, including retention periods and your rights.
There is no account
No sign-up, no email, no password, no profile. Two phones pair with a temporary six-digit code, and that is the whole identity model.
This matters more than it sounds. A service with accounts has a database of who its customers are, which is a thing that can be breached, subpoenaed, sold in an acquisition, or quietly repurposed. We do not have one. If someone compromised our servers tomorrow they would find pairing bookkeeping and a table of anonymous hashes.
Analytics, ads and trackers
None in the app. No analytics SDK, no advertising SDK, and no profile of you or your usage. The Android app carries no crash-reporting SDK either.
The one thing worth naming rather than glossing: Google is involved, because the push notification that wakes your phone is delivered by Google’s messaging service on Android, and by Apple’s on iPhone. There is no way to wake a locked phone without going through the platform. That is the entire extent of it — a message saying “something happened”, never audio, never video, never who you are.
The website you are reading sets no cookies and embeds nothing from anyone else. It does count page views and link clicks, using a cookieless tool that stores nothing on your device, does not fingerprint your browser, and cannot follow you to another site — aggregate numbers, never identities. Section 13 of the privacy policy says exactly what it does.
Who else could get in?
The pairing code is the thing to protect. While you are pairing, anyone who has the code could join the session before your second phone does — so treat it like a door key for those few seconds, and do not photograph the QR code into a group chat.
After pairing, the link is between your two phones. A fresh code can be handed between two already-paired phones over Bluetooth, encrypted with a key only those two phones hold.
How to check any of this yourself
You should not take a privacy page’s word for it, including this one. Things you can verify without any special tools:
- Check the permission list on the store page before installing anything. Calmina asks for microphone, camera, notifications and Bluetooth. It never asks for location, contacts, files, photos, SMS or call logs — and its Bluetooth request is flagged “never for location”.
- Look for an account. If a monitor made you create one, it knows who you are, and its privacy policy has to explain what it does with that. Ours does not have that section because there is nothing to put in it.
- Read the retention column. A policy that says what it keeps but not for how long has not really told you anything.
- Try to find the deletion route. If a service cannot tell you how to remove your data, that is the answer.
The formal version. Everything here is stated with retention periods, legal bases and your rights in the privacy policy.
How Calmina works · The silent-mode problem · Common questions · Pricing
Calmina is not a substitute for direct adult supervision or a medical monitoring device.