Privacy Policy (Kikis)

Effective Date: [YYYY-MM-DD β€” fill in the actual deployment date] Version: 1.0

Kikis ("we", "us", "our") takes your privacy seriously. This policy explains what data we collect, why, and how we handle it. We comply with applicable laws including GDPR (EU), CCPA (California), and South Korea's Personal Information Protection Act (PIPA).


1. Data We Collect and Why

1.1 At Sign-Up

DataSourcePurpose
Email addressGoogle/Apple Sign-In or direct entryAccount identification, password reset
Name or display nameOAuth provider metadataProfile display
Profile picture (optional)User uploadProfile display
Learning language / native languageUser selectionPersonalized content

Apple Sign-In note: If you choose "Hide My Email", Apple provides us with a relay address. We never see your actual Apple ID email.

1.2 During Use

DataPurpose
Search queries (text)AI translation and kiki generation; cache
Saved kikis (expressions, patterns, sentences)Your vault content; learning progress
Learning history (last reviewed, success rate)SM-2 spaced-repetition algorithm
Device info (iOS/Android, OS version, app version)Compatibility, crash diagnostics
FCM push tokenNotification delivery (if you opt in)
Subscription stateSubscription management

1.3 Optional (only when you actively use)

DataPurposeStorage
Voice input (STT)Pronunciation evaluation, voice searchProcessed and discarded; not stored
Camera/photo (OCR)Extract text from imagesProcessed and discarded
Connect posts / commentsCommunity featureUntil you delete

2. Third-Party Service Providers

Kikis uses these external services to function. Each has its own privacy policy.

ServiceProviderData SharedLocation
Authentication, DB, serverless functionsSupabase Inc. (USA)Full account & contentUSA (us-east)
Push notificationsFirebase Cloud Messaging / Google LLCFCM token onlyUSA
Google Sign-InGoogle LLCOAuth credentialsUSA
Apple Sign-InApple Inc.OAuth credentialsUSA
AI translation / kiki generationGoogle Gemini (Google LLC)Search text (PII-stripped)USA / EU
Speech-to-textGoogle Cloud SpeechVoice data (discarded after processing)USA
Pronunciation evaluationMicrosoft Azure SpeechVoice data (discarded after processing)User's region
Subscription managementRevenueCat Inc.Anonymous user ID, subscription stateUSA
App analytics (optional)None β€” no third-party analytics in the current betaβ€”β€”

Each provider's privacy policy:


3. Data Retention

DataRetention
Account info, vaults, kikis, learning historyUntil account deletion (or earlier upon user request)
Connect posts / commentsUntil user deletion
Payment & subscription history5 years (commercial law requirement in some jurisdictions)
Voice / image inputDiscarded immediately after processing
Push tokensUntil user uninstalls or token invalidates
Backup data30 days after account deletion (in case of re-signup) β†’ auto-purged

4. Your Rights

You can exercise these rights anytime:

  1. Access β€” view your profile in the app's "Profile Settings"
  2. Correction β€” edit your profile in "Profile Edit"
  3. Deletion (account closure) β€” in-app "Delete Account" or email support@my-kiki.app (or actual operational email)
  4. Restrict processing β€” email request
  5. Data portability β€” request a JSON export of your vault
  6. Withdraw consent β€” uninstall the app and request data deletion

We respond within 7 days.

EU/UK users have additional GDPR rights including the right to lodge a complaint with your local supervisory authority.

California residents have additional CCPA rights including the right to know what categories of personal information we collect and the right to opt out of "sale" (we do not sell your data).


5. Children Under 14

Kikis is intended for users 14 and older. We do not knowingly collect data from children under 14. If we discover a user is under 14, their account is deleted immediately. Children in jurisdictions where the legal age is higher (e.g. 16 under GDPR without parental consent) should obtain such consent.


6. Cookies and Tracking

Mobile app does not use cookies. We also do not use:


7. Security


8. Changes to This Policy

If this policy changes materially we will notify you via in-app notice and/or email. For substantial changes affecting your rights, we may re-prompt for consent.


9. Contact Us

For privacy questions or requests:

Data Protection Officer:


10. International Data Transfers

Your data may be transferred to, processed in, and stored in the United States and other countries where our service providers operate. By using Kikis you consent to this transfer. For EU/UK users, we rely on the relevant Standard Contractual Clauses or equivalent safeguards.


Last Updated: [YYYY-MM-DD]

For the Korean version see privacy-policy-template-ko.md. In case of conflict between the two versions, the Korean version governs for Korean users; the English version governs for all others.