1. Service and choices
Local learning is available without an account. Free includes the first 30 words and first 30 kanji of each level, with unlimited repeats inside and outside the app, and 300 seconds of daily background listening. Pro unlocks the full catalog, removes the listening limit and adds manual cloud backup and restore. One backup is kept per application and account, with the source device model and upload time. Uploading replaces that backup; restoring replaces learning records on the current device. Records are not automatically transferred or merged. Display preferences stay on each device.
The app does not serve advertising or use an advertising SDK.
We do not request personalized ads or use IDFA or Android advertising ID for cross-app tracking. Analytics and crash reporting can be turned off in Settings. These controls are separate from ad privacy choices.
2. On-device data
| Category | Data | Purpose | Retention |
|---|---|---|---|
| Local learning data and account caches | Content IDs and sync scopes, Viewed status, attempts, correct answers and successful sessions, Review and saved-item status, Current sessions and answers; up to 365 recent completed sessions and lifetime completion totals, Study date, time-zone offset, active learning seconds and daily study, test, review, view and correct-answer counts, Deduplication batch UUIDs and immutable payloads, Course generation, round, day and daily review progress, Fixed free catalog IDs and per-item routine completion rounds, Legacy sync metadata retained for compatibility; unused pending commands cleared when opening the account store | Save progress, resume sessions, review mistakes, retain saved items and keep study history | Guest data stays until transferred to an account or the app is deleted. Local account learning records remain after sign-out for later sign-in. Unused legacy cloud commands are cleared when opening the store. Account deletion removes them on the requesting device; other installations retain local copies until removed. Operating-system backups may retain or restore copies under the user’s backup settings. |
| On-device learning and display settings | Study goals and JLPT level, Theme, text size and Japanese font, Voice speed, autoplay and reading aids, Recent session size and daily study and review goals for words, kanji and radicals | Remember preferences on each device | Guest settings remain until account transfer or app removal. Account settings remain after sign-out; account deletion clears the requesting installation. Operating-system backups may restore copies. |
| Analytics and crash-reporting preference | Whether analytics and crash reporting are enabled | Remember your choice between launches | Until changed or app/device secure storage is reset. |
| Handwriting practice strokes | Touch, mouse or stylus coordinates on the current practice screen | Render handwriting practice | Until the writing is cleared or the screen is closed. |
| Local sign-in session | Supabase user UUID, Access and refresh tokens, Session expiry, SecureStore chunk manifest and recovery journal | Keep optional account sign-in and refresh authentication | Until explicit sign-out or account deletion. iOS Keychain data may survive app removal and reinstallation on the same device. |
| Subscription access and daily device usage | Local date, External-answer counts across widgets, notifications, lock screen and word toll, Background playback seconds, Deduplication event UUIDs and charged units, Free/Pro status, validity and policy version, Unlimited external answers within accessible content; 300 background playback seconds per day, Current account UUID, absent for guests, Last RevenueCat response time | Enforce subscription content access and background listening allowance; share access state with native extensions | Daily counts and event receipts roll over on the next day’s first use. The current access snapshot is replaced by later decisions and removed with the app. |
| Word toll settings and action receipts | Selected app operating-system tokens or Android package names, Shared active hours, Pause-until time and disabled-for-today date, Word display snapshot and reveal, answer or emergency-pass receipt UUIDs | Show vocabulary before opening selected apps and apply answers once | Settings remain until changed or the app is removed. Action receipts are cleared after the learning ledger applies them. |
3. Data processed by services
If you use an account, Supabase processes identity, subscription access and synced learning data. RevenueCat and Apple or Google process purchases and subscription status. When enabled, Firebase processes usage analytics and crash diagnostics.
| Category | Data | Purpose and basis | Choice |
|---|---|---|---|
| Optional account identity | Email address, Supabase user UUID, Authentication-provider identifier, Authentication timestamps | Create and secure an optional account; provide purchases and manual backup and restore Perform the account and subscription services you request. | Optional |
| Legacy Synced learning progress | Content IDs and 12 sync scopes, Attempts, correct answers and successful sessions, Review status and review/reset generations, Saved items and completed-session totals, Local dates and time-zone offsets, Active learning seconds and daily study, test, review, view, answer and correct-answer counts, Deduplication batch UUIDs, payload hashes and timestamps, Course generation, round, day and daily review progress, Learning revisions and changed-scope boundaries | Retain existing pre-manual-backup records for compatibility. New app versions do not automatically upload or pull these records. Perform the Pro backup and sync service you request. | Optional |
| Legacy Synced routines, card delivery and listening | Routine name, type, content scope, goal, days, hours, surfaces and active status, Daily routine goals, progress and completion, Content IDs, display surface, prompt mode, timestamps and results, Delivery choices, permitted actions, reasons, snapshots and expiry, Listening seconds, completed clips, playback position and state, Command IDs, hashes, deduplication keys and status | Retain existing pre-manual-backup records for compatibility. New app versions do not automatically upload or pull these records. Perform the Pro routine and learning sync service you request. | Optional |
| Legacy Sync device and command identifiers | Client and server device identifiers, Sync protocol version, Last command sequence and verification hash, Registration and last-use timestamps | Retain existing pre-manual-backup records for compatibility. New app versions do not automatically upload or pull these records. Perform the Pro backup and sync service you request. | Optional |
| Registered account devices and login sessions | Random per-installation UUID and server device UUID, Device model or platform label (not a personal device name), Account UUID and authenticated session UUID, Last online verification time and revocation status | Limit signed-in account use to five registered devices and let users replace or revoke devices Provide and secure signed-in account access. Guest learning does not register a device. | Required for the selected service |
| Authentication and API security logs | Request time, IP address, User agent, Request path, Response status, Supabase user UUID | Secure authentication, investigate errors, prevent abuse and maintain service stability Service security and operation, including applicable data-protection security obligations. | Optional |
| Server subscription access for cloud backup | Supabase user UUID, Pro active status, Access expiry, RevenueCat verification time | Authorize explicit Pro cloud backup and restore requests Provide the Pro backup service requested by the user. | Optional |
| RevenueCat subscription and purchase data | App User ID based on Supabase user UUID, Store, product and base-plan identifiers, Purchase, restore, renewal, cancellation, refund and expiry status and timestamps, Transaction/order identifiers and entitlements, App, SDK, store environment and diagnostic information | Provide and verify purchases, restore access, support customers and prevent fraud Perform the subscription you request and protect payment integrity. | Optional |
| Firebase analytics and crash diagnostics | Random app installation and Crashlytics installation IDs, App sessions and semantic screen names without identifiers, Content type and aggregate study/test starts, completions, question counts, correct counts and retries, Audio type and playback success/failure, Word-toll availability, display, reveal, answer, emergency pass, suppression and technical-failure events with platform, rule version and limited reason codes, Approximate location derived from masked IP information, App/OS versions, device model, language and network type, Crash stack traces and related app/device state, Firebase SDK types and versions, Fixed operational failure codes for local learning storage initialization and synchronization; no original error messages | Measure usage, understand crashes and improve reliability Minimal usage and reliability diagnostics; no account IDs, email, learning text, answer strings or handwriting coordinates are included. Advertising identifier support is disabled. | Optional |
| Support and privacy-rights requests | Reply email, Request type and content, Identity-verification result, Resolution and timestamps | Handle access, correction, deletion, restriction and consent requests; resolve disputes Fulfil applicable privacy-rights obligations and respond to your request. | Optional |
| Server reliability diagnostics | Operation and failure-stage codes, HTTP status and request duration, Random per-request diagnostic ID, deployment environment and release version | Detect service failures and restore service availability Service reliability diagnostics exclude account identifiers, client IP addresses, request contents, authentication tokens and learning data. Sentry is contacted by our server, not the app. | Required for the selected service |
| Manual cloud learning backup | Learning progress, saved items, review status and separate in-app/outside-app rounds, Routine settings, daily progress, listening position and study-date preferences, Current session questions, answers and queue cursors; cached card text for resuming the current list, Recent sessions, lifetime counts and daily learning statistics, Stable application identifier, server-verified source device model label, server upload time, revision and payload size | Keep one manually uploaded backup per application and account and explicitly replace local learning records on restore Provide the Pro manual backup and restore requested by the user. | Optional |
4. Privacy controls
Account creation is optional; purchases, restoration and sync require sign-in. Change analytics and crash-reporting preferences in Settings.
We do not share learning content or account identifiers with advertising services.
5. Service providers and international processing
Providers may process information outside your country. The table describes their roles and processing locations; their published policies provide further detail.
| Provider | Role | Location and transfer | Retention |
|---|---|---|---|
| Supabase Pte. Ltd. | Optional account authentication, subscription access, account storage, backup, sync and security logs Optional account identity, Legacy Synced learning progress, Legacy Synced routines, card delivery and listening, Legacy Sync device and command identifiers, Registered account devices and login sessions, Authentication and API security logs, Server subscription access for cloud backup, Manual cloud learning backup | Countries where Supabase and its subprocessors operate hosting, infrastructure and support services Encrypted network transfer when using the service | Per-record retention and production-project settings |
| Google LLC (Gmail) | Support, account deletion and privacy-rights correspondence Support and privacy-rights requests | United States and other countries where Google operates servers Encrypted network transfer when using the service | 1 year after request closure |
| RevenueCat, Inc. | Store subscription verification, Pro access, purchase restoration and billing diagnostics RevenueCat subscription and purchase data | United States and other countries where RevenueCat and its subprocessors operate services Encrypted network transfer when using the service | RevenueCat retention policies, store agreements and legal obligations |
| Google LLC | App usage analytics and crash/stability diagnostics Firebase analytics and crash diagnostics | United States and other countries where Google operate services Encrypted network transfer when using the service | Analytics property retention settings and the Crashlytics 90-day policy |
| Functional Software, Inc. (Sentry) | Sanitized server error monitoring and operational alerts Server reliability diagnostics | Depends on the selected Sentry hosting region and applicable subprocessor locations Encrypted network transfer when using the service | Configured Sentry project retention; confirm before production activation |
6. Retention and deletion
| Category | Retention | Deletion |
|---|---|---|
| Local learning data and account caches | Guest data stays until transferred to an account or the app is deleted. Local account learning records remain after sign-out for later sign-in. Unused legacy cloud commands are cleared when opening the store. Account deletion removes them on the requesting device; other installations retain local copies until removed. Operating-system backups may retain or restore copies under the user’s backup settings. | Reset learning history, delete the account on this device, or remove the app. Manage operating-system backups separately. |
| On-device learning and display settings | Guest settings remain until account transfer or app removal. Account settings remain after sign-out; account deletion clears the requesting installation. Operating-system backups may restore copies. | Delete the account on this device or remove the app; manage operating-system backups separately. |
| Analytics and crash-reporting preference | Until changed or app/device secure storage is reset. | Change the setting or reset device secure storage. |
| Handwriting practice strokes | Until the writing is cleared or the screen is closed. | Removed from memory. |
| Local sign-in session | Until explicit sign-out or account deletion. iOS Keychain data may survive app removal and reinstallation on the same device. | Sign out or delete your account. On iOS, app removal alone does not guarantee Keychain deletion. |
| Subscription access and daily device usage | Daily counts and event receipts roll over on the next day’s first use. The current access snapshot is replaced by later decisions and removed with the app. | Daily rollover, replacement by a new decision, or app removal. |
| Word toll settings and action receipts | Settings remain until changed or the app is removed. Action receipts are cleared after the learning ledger applies them. | Disable the feature, deselect apps or remove the app. |
| Optional account identity | For the life of the account. Removed from live data on account deletion; pre-existing managed backups follow the configured backup retention schedule. | Authenticated account deletion or a verified support request. Apple sign-in users can also disconnect the app through Apple account settings. |
| Legacy Synced learning progress | For the life of the account. Removed from live data on deletion; pre-existing backups follow the configured backup retention schedule. | Unsaved entries without learning history or conflict-prevention markers are removed; account deletion removes all account records. |
| Legacy Synced routines, card delivery and listening | Routine settings remain until changed or the account is deleted. Routine days and dependent listening/delivery records expire after 180 days; exposure and listening records are additionally capped at 5,000 and 10,000 rows. Command receipts are capped at 180 days or 20,000 rows. Pre-existing backups follow the configured backup retention schedule. | Retention cleanup runs during routine command processing; account deletion removes live account records and dependent rows. |
| Legacy Sync device and command identifiers | Until sync identity deregistration or account deletion. Login device removal retains sync sequence history to preserve pending commands. | Deregister a device or delete the account. |
| Registered account devices and login sessions | Active registrations and device revocation records remain until account deletion. Session bindings are removed with their Supabase Auth sessions. A local receipt is cleared on denial; iOS Keychain may survive reinstall. | Revoke account access from device management; delete the account to remove server records. Revocation does not erase learning data. |
| Authentication and API security logs | According to the hosting project’s configured security-log retention schedule. | Automatic expiry; access is restricted while logs are retained, including after account deletion. |
| Server subscription access for cloud backup | For the life of the account; updated on verification and deleted with the account. | In-app account deletion or a verified support request. |
| RevenueCat subscription and purchase data | Subject to RevenueCat and store retention policies and applicable tax, dispute and security obligations. | Account deletion first requests removal of the RevenueCat customer. Store subscriptions and legally retained transactions are separate and managed through the store. |
| Firebase analytics and crash diagnostics | Analytics follows the property’s configured retention period. Crashlytics starts deletion of crash traces, minidumps and associated installation identifiers after 90 days under Google’s policy. | Turning this off stops new collection, resets the installation’s Analytics identifier and deletes unsent crash reports. Already transmitted data is not linked to an account for individual selection and follows Google’s retention and deletion processes. |
| Support and privacy-rights requests | 1 year after closure; ongoing disputes are retained separately with restricted access until resolved. | Permanently deleted after retention ends. |
| Server reliability diagnostics | Subject to the configured Supabase and Sentry project retention periods. Verify these settings before enabling production monitoring. | Automatically removed according to project retention settings; diagnostic events do not include an account identifier. |
| Manual cloud learning backup | One latest backup per application and account until replaced or the account is deleted. Failed uploads preserve the previous backup. | A successful new upload replaces the previous backup. Account deletion cascades to the backup. Managed database backups follow their retention schedule. |
Deleting an account removes live account and synced records. Existing backups may retain copies until the hosting retention schedule expires. Operating-system backups are managed separately through your device or backup provider.
7. Your rights and contact
Contact support.alan.app@gmail.com to request access, correction, deletion, restriction or withdrawal of consent. We may verify your identity before acting. You can request account deletion without reinstalling or signing in to the app. For general support, contact support.alan.app@gmail.com.
How to delete your account8. Data we do not collect
Precise location, Address books, Photos, camera and microphone access, Health information, Direct collection of payment-card numbers, bank account details or payment passwords, Sending handwriting coordinates to servers, Sending correct-answer or selected wrong-answer text to servers, An append-only history of individual learning events and completed answers, User input for AI services or model training, Third-party behavioral or cross-app tracking using IDFA or Android advertising ID, Email, Supabase user UUID, learning text, answer text or handwriting coordinates in analytics/crash payloads, IDFA, IDFV, Android advertising ID, SSAID and ad-personalization signals in Firebase Analytics
9. Operator
ALAN · Representative: 김선일
34, Nakseongdaeyeok 6-gil, Gwanak-gu, Seoul 08799, Republic of Korea · Business registration: 508-55-00902
Privacy officer: 김선일
Privacy: support.alan.app@gmail.com · Support: support.alan.app@gmail.com