Where your child's voice goes
We wrote the software that carries your child's calls and we run it on our own exchange in Helsinki. Here is exactly what we know, what we don't, and the parts that aren't flattering.
By Greg Chrystall
Parents ask us two questions about data, usually in the same breath: what do you know about my child, and where does the call actually go? Here are both answers, in more detail than you probably wanted β including the parts that aren't flattering.
What we don't know about your child
We collect no information about children. No birthday, no address, no school, no profile, no device identifier tied to a person. There is exactly one field in our systems that can contain anything about your child, and it is the name of the line β which exists because a parent typed it, so the phone in the hall shows something more useful than a number. Call the line "the kid" and we know nothing at all.
This isn't restraint on our part. We never built the fields.
Where a call actually goes
Barnluren is a closed network. The phone in your hall is not connected to the public telephone system, so it cannot be rung by a stranger, a scammer or an automated sales call. There is no route in.
What there is instead is our own telephone exchange, running on machines we rent in Helsinki. A call from the hall phone to grandma's app goes device β Helsinki β app. That is the entire route. No third-party voice platform, no American telecom API, no reseller arrangement with someone else's infrastructure and our logo on the front. If everyone on the call is in Europe, the call stays in Europe. If grandma answers from Bangkok, her half of the call goes to Bangkok β that's physics, not policy.
What we built, and what we bought
The firmware on the adapter, the iOS app, the Android app, the servers, the call routing: all written by us, on open source foundations β Linux, OpenWrt, Asterisk, PostgreSQL. There is no proprietary black box in the call path whose source we can't read.
That is the practical reason to own this layer. When a parent asks who can hear this call, we can answer from the code instead of from a vendor's marketing page.
Two things we didn't build. Clerk handles login and Stripe handles payments β the two areas where rolling your own is how a small company ends up in a breach headline. Both are GDPR compliant with data processing agreements in place, and both process some data outside the EU under the standard legal frameworks. What they see is the parent: an email address, a card. Neither touches a call. Neither knows that a child exists.
We would rather name them than make a blanket "nothing ever leaves the EU" claim and quietly hope nobody checks.
Encrypted, and where the seam is
Both legs of every call are encrypted in transit: SIP over TLS and SRTP from the adapter, DTLS-SRTP from the apps.
It is not end-to-end encrypted, and we are not going to imply that it is. The call is decrypted on our server in Helsinki so that it can be switched to the other party, then encrypted again on the way out. That seam exists in every system that connects a physical telephone to an app. What matters is where it sits: on hardware we control, inside the EU, at a point where we have deliberately built nothing that listens.
We don't record calls
No recordings. No transcripts. No "quality monitoring". No training data. Not stored briefly and then deleted β not created in the first place.
The single exception is a lawful order from law enforcement, which we would comply with, because that is the law. It is worth being precise about what that means in practice: there is no archive to hand over from before such an order arrives. Nobody pays us for call data either, because it does not exist and is not for sale.
Real phone numbers change one thing
We are building a plan called Barnluren Everyone, which adds a real phone number to the child's line so that people who aren't on Barnluren can reach them β a grandparent who went back to a simple phone, a friend whose family is on a landline. Parents still approve every contact, in both directions. It is in closed beta.
Inside Barnluren, nothing about the routing changes. Barnluren-to-Barnluren calls always run over our own network, even on a line that has a public number attached. The number is consulted only at the boundary: a call arriving from outside, or one going out to a number that isn't ours.
When a call does cross that boundary, it becomes an ordinary telephone call, with the ordinary properties of one. It runs over the public telephone network. It is not encrypted out there and we cannot make it so. Our carrier for those numbers is Swedish, so the route stays Nordic β but once the call is handed over it lives by the telephone system's rules, not ours.
That carrier keeps its own call records, because every telephone company is required to. That is regulation, not a Barnluren decision. Still no recordings: a call to a real number is logged for billing, not listened to.
Two consequences we would rather state than have you discover. A line with a public number is reachable in a way a closed network is not β the parent-approved contact list is what keeps that safe, and it applies in both directions. And our "this phone cannot dial 112" promise is a statement about the internal network. Emergency calling is not something Barnluren offers, and a real number does not change that. A child's phone is not a substitute for a way to reach emergency services.
The honest version of "it's all in the EU"
Three layers, three different answers.
The call itself: our software, our exchange, Helsinki. It does not leave the EU unless somebody on the call is outside it.
A call to a real telephone number: handed to a Swedish carrier at the edge, and from there it is the public telephone network, with the normal rules of one.
The account behind it: Clerk and Stripe, GDPR compliant, some processing outside the EU under the standard frameworks. Neither touches a call.
Most of this stack is ours. The layer that carries your child's voice is the one we own outright, and that is not an accident β it is the reason the answers above can be this specific.