How the KOMY Phone is built.
For everyone who wants to know exactly: which promises the KOMY Phone makes and how they are enforced in the program code and the test suite. As of 8 October 2026.
The product in three sentences
The KOMY Phone is a preconfigured, locked children’s phone with the companion Komy, plus the parents’ app on Google Play. Both are one code base in two variants; the parent variant contains no child content and is fixed to the parent role. Komy is a friend who needs the child’s help – never a tutor and never an answer machine.
Promises and how they are enforced
| Promise | Mechanism | Enforced by |
|---|---|---|
| No language model runs on the child’s phone. | Komy’s sentences, the vocabulary, 100 stories and around 1,200 name clips are stored on the phone as audio. A language model works only in our workshop, before bundling. | A manifest without audio breaks the build; tests check every situation list. |
| Offline listening is limited. | Speech recognition runs only with a fixed word list and only while a screen is visibly listening – in the routine for at most 10 seconds after each question, with the notice “Komy hört zu …” (Komy is listening). No transcript, no file, no upload. | A test ensures every word list ends with “unknown” and games know only their round’s words. |
| Every composed sentence is grammar-checked. | All combinations of sentence opening and word are exported and sent through a grammar check that writes a stamp. | An outdated stamp fails the test suite. |
| Komy is never an answer machine. | Everything Komy says is written in advance, checked by a human and stored on the phone as audio. No language model phrases anything at runtime – neither on the phone nor on our server. | A test fails as soon as anything outside the named exceptions reaches our server or calls a language model. |
| Data boundaries. | Memory book, Magic Sky and learning signals enter no sync path; from them the parents’ app shows only on how many days this week your child read aloud – never the content. No child’s name in the cloud; Android backup and device transfer carry nothing. | A test reads the source of both sync paths and the backup rules and fails as soon as a forbidden wiring appears. |
| No cloud copy of the child’s data. | The only copy outside the child’s phone is an encrypted, signed backup on the parent phone (AES-256-GCM, key only on parent phones). No server holds it or a key to it. | Tests for the envelope, the content and the handover of the backup. |
| The picture codes are bound to the device. | Komy code (parents) and child code are separate four-picture sequences, stored as a hash in the device keystore, never synced, never logged. | A test ensures no outgoing path knows the code. |
| Kiosk and locked device shell. | Komy’s world is the home screen; parent mode with automatic re-lock after 15 minutes; resetting via the settings is blocked. | Test of the allow-list. |
| Database encrypted at rest. | SQLCipher; the passphrase lives only under a key in the device keystore. | Tests for detection and migration. |
| Signed remote commands, lost mode, crypto erase. | Every command is bound to the family and exactly one device, not replayable, time-limited. Lost mode shows only a neutral screen; the erase shreds the keys first. | Tests for foreign family, foreign device, forgery, replay, expiry. |
| The child’s phone never asks for permissions. | Everything is granted in advance by the device owner; if a permission is missing, the feature quietly switches off. | Source rule for every request. |
| No image leaves the child’s phone. | Image analysis exists only in the parent variant; the child variant returns nothing. | Test: the image key is empty in the child release. |
What our server sees
There is exactly one server the child’s phone reaches: the KOMY service of Sysea, self-operated in Germany, shielded behind an access service. Since 28 September our server no longer phrases anything either. Without it Komy still speaks – only updates and a rare name are missing then. There is no fallback to a foreign provider. Every request carries a random installation ID and a device attestation – nothing about the child.
| Request | From | Content | When |
|---|---|---|---|
| Voice a rare school subject | child’s phone | only the word, e.g. “Chemie” (chemistry) | once, on Wi-Fi |
| Voice a rare name | child’s phone | only the name itself, such as the first name of the child or of a caregiver | once, as soon as the phone is online |
| Check for and download updates | child’s phone | the installed version | at night, only on Wi-Fi and while charging |
| Read a timetable or a letter to parents | only the parent phone | the downsized photo; our server passes it on to Anthropic (Claude) for analysis | when scanning |
Whatever the phone still has voiced – a rare name or a rare school subject – goes to a speech service provider as a single word, never as a sentence about the child. Outside our server the child’s phone reaches only Google Firebase (EU region, for family, appointments, safe places, remote commands), the Google Play services for location, and a weather service with the place you chose.
What we are still working on
- The backup on the parent phone is built; restoring it onto a new KOMY Phone is still being built.
- We do not store a location history – there is only the last position per phone. Safe-place and SOS alerts are deleted automatically after 30 days, commands to the phone and their replies after 90 days; “delete family” removes everything at once. A lawyer still reviews these periods before sales start.
- A safety escalation for serious situations is deliberately not built: Komy then points to a trusted adult, he does not monitor.
More than 880 automated tests run on every change. Many of them read the source code itself and fail as soon as a boundary would be crossed – long before a child could notice.