rilo

Privacy

The short version: we hold a short list of technical things, none of them what your child says, and none of them their name.

This policy describes what the Rilo apps and the Rilo server do with personal data. It is written to be read, not to be survived. Where it says we never, that is a description of how the software is built, and the technical page shows the database tables it follows from.

This is a careful draft, not legal advice, and it has not yet been reviewed by a lawyer. What it describes about the software is accurate; whether it satisfies every law that applies to it is a determination we have not had made yet.

Who is responsible

The controller for the data described here, in the sense of the GDPR, is:

Controller
Small Victories - BE 0793.301.929
Registered address
Mellestraat 303, 9090 Merelbeke-Melle.
Email
hello@rilotalk.com

What we hold

The full list, table by table and column by column, is on the technical page. It is generated from the same file the server runs, so the two cannot drift apart. It is short because the server is a matchmaker, not a middleman: it introduces two devices to each other and then gets out of the way.

A random account id
Generated on the device. It is not derived from your name, your phone number or anything about you, and it is the only name the server knows you by.
A public key
The public half of a keypair your device made and keeps. It is what lets the other phone be sure it is really talking to you.
No names at all
There is no name column anywhere on our server, for adults or for children. Names and faces are chosen on each phone and travel directly between the phones involved, inside a QR code or sealed so only the other phone can open it. We could not tell you what your child calls their grandmother.
A push token
The address Apple or Google uses to wake your phone for an incoming call. It is issued by them, not by us, and it changes on its own.
Guardians, and introductions in progress
That an account has a guardian. And, only while an introduction is still unfinished, the two accounts it is between. Not names: account ids. Once both phones hold the finished contact that row is deleted, so there is no list of who may call whom.
A last-active timestamp
So an account nobody has used in a long time can be swept up rather than kept forever.
An email address, briefly
Only for adults, only at sign-up, and only to check an adult is an adult. The readable copy is destroyed as soon as it is verified. What the account keeps is that address sealed to the founder’s offline key, which is legal proof of consent that no server can open. See below, including the mail provider it passes through on the way to you.
Crash reports, with no name on them
When the app crashes or freezes, it sends us where in the code it broke, the app version and the iOS or Android version. No account, no device model, no message and no name, so a report cannot be traced back to a family. That also means we cannot find yours if you ask us for it. Each report is a file on our server, deleted after 90 days.

That is everything. There is no profile, no address book, no history of who called whom, and no record of what was said.

What we never hold

These are not things we have chosen not to look at. They are things the software cannot produce:

  • What is said. Calls and messages are end-to-end encrypted between the two phones. The keys never leave the devices, so the server carries sealed traffic it cannot open.
  • Your child’s contact list. Who may call whom is decided on the phones and stays there. We can see that two account ids are linked. We cannot see that they are your child and their grandmother.
  • Location. The apps never ask for it and never send it.
  • Advertising identifiers. There is no advertising in Rilo, no analytics, and no third-party tracking code in either app.
  • Anything for sale. We do not sell, rent or share personal data with anyone for their own purposes.

The beta list this website used to have

One thing here is not part of the app at all. Until Rilo was on the App Store, this website linked to a beta list, and it no longer does. If you joined it, you gave us an email address and nothing else: no name, no phone number, and nothing about a child. We use it to say when there is something to try, and for nothing else. The list is run by Tally rather than by our server, which is why this page names them below. The basis is your consent, given by typing the address in, and one line to hello@rilotalk.com removes it. Nothing in that list is connected to a Rilo account, because there is nothing in an account to connect it to.

Why we are allowed to hold it

The legal basis is Article 6(1)(b) of the GDPR: the data is what is needed to provide the service a parent asked us for. The one exception is the beta list described above, which rests on your consent under Article 6(1)(a) and lasts exactly as long as you want it to. Nothing rests on legitimate interest in profiling, because there is no profiling.

For the subscription, the basis is the same contract; the payment itself is handled by Apple or Google, who are the merchant and hold the card details. We never see them.

Children

Rilo is built for children of roughly four to ten, and a child’s account can only exist because an adult made it. A child account is a certificate signed by a parent’s key: there is no way for a child to create one alone, and no setting a child can change to become an adult.

Because the service is provided under a contract with the parent, and every child account is created and approved by that parent on their own device, consent under Article 8 is not the basis we rely on. The parent’s approval is a cryptographic act, not a tick-box.

We keep no readable record of the address. It is verified and destroyed in the same step, and what stays with the account is that same address sealed to the founder’s offline key, which no server can open. What proves a parent agreed is the signature: a child’s account is a certificate signed by their parent’s key, which shows an adult created and approved that account without telling us who the adult is.

Who else is involved

Six other companies necessarily touch some of this. None of them receives anything about your child, and none of them is sent data for its own purposes.

Apple
Delivers call and message notifications to iPhones, and handles subscriptions bought on iOS. Apple sees a push token and the fact that a notification was sent, not its content.
Google
The same, for Android, through Firebase Cloud Messaging, and Google Play handles subscriptions bought on Android through its billing library in the app. The app also asks Google Play for an age band, which is read on the phone and never stored or sent to us. No Google or Firebase component in the app does analytics, crash reporting or advertising.
Cloudflare
Provides the relay that some calls need when two home networks refuse to talk directly. The relay forwards encrypted packets it cannot read, and is used only when a direct connection fails. Cloudflare also answers the question every call asks first: “What is my own address on the internet?” So they see that a phone is starting a call, and from where, even when the call then goes directly.
Oracle
Hosts the signalling server, in the European Union. They are our hosting provider and process nothing on their own account.
Brevo
Sends the one email this product ever sends: the code that verifies a grown-up at sign-up. Your address passes through them to reach you, which means it is in their logs for as long as their retention says, even though it is never in ours. It is the one place a Rilo address exists outside your own inbox, and we would rather name it than let the sentence above imply otherwise.
Tally
Holds the beta list this website used to link to: the addresses people typed into its form, and nothing else. It never touches the app or the server.

There is no analytics provider, no advertising network, no customer-data platform and no AI service in this list, because there are none in the product.

How long we keep it

Account records last as long as the account does. The verification email’s readable copy is destroyed the moment it has done its job. The sealed, unreadable proof described above stays with the account. Messages waiting for a phone that is switched off are stored encrypted and deleted once delivered, or after a short expiry if they are never collected. They are blobs we cannot read either way.

You can remove your account at any time from inside the app, and it takes everything attached to it; the deletion page says where that is and what is still possible when the phone is gone. We are building an automatic clear-out of families who have stopped using Rilo altogether; until it is switched on, nothing here goes on its own.

One exception to that. The database is backed up nightly, encrypted, so that a hardware failure is not the end of your family’s contacts. And a backup taken before you deleted something still contains it. Those copies are kept 30 days and then destroyed, so a deletion becomes true everywhere within a month. It is the same window we hold an undelivered message for, and we would rather name it than let the sentence above read as more absolute than it is.

Your rights

Under the GDPR you may ask us to:

  • tell you what we hold about you, and give you a copy;
  • correct it, if it is wrong;
  • delete it;
  • hand it over in a portable form;
  • stop processing it, or object to a particular use.

The app is the route for most of this: What our server knows in Settings lists every column the server has, and Delete my account below it does the erasing without asking us at all. Write to the address above for anything the app cannot do. The awkward part, said plainly: we hold no name, no email and no password, so there is usually nothing in a letter we could match to an account. Article 11 of the GDPR covers exactly this. A controller who cannot identify a person from what it holds should say so rather than guess. If the phone is gone, the deletion page sets out what is still possible.

You may also complain to the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), or to the supervisory authority where you live.

Changes

If this policy changes in a way that affects what we hold or who sees it, the apps will say so before the change takes effect, rather than quietly republishing this page.

Last updated 14 September 2026. This policy has not yet been reviewed by a lawyer.