Privacy policy · July 24, 2026

Simple practice. Minimal data.

KanaDaruma works without an account. Core learning progress stays on the device. Anonymous analytics and purchase verification use the providers described below; handwriting-photo scoring is optional.

1. Summary

KanaDaruma does not require an account. Character lessons, vocabulary lessons, bundled audio, progress, and reviews work locally. The app uses PostHog for anonymous product analytics, AppsFlyer for install attribution and aggregate funnel measurement, RevenueCat for purchase and entitlement handling, and Google/Firebase for optional handwriting-photo scoring and service-abuse protection. Advertising identifiers and AppsFlyer partner sharing are disabled. These services are not used for advertising or cross-app tracking.

2. Handwriting photo scoring

Scoring starts only after you take or choose a photo and tap Reveal my score. KanaDaruma sends a sanitized version of the selected image, expected Japanese answers, and the current curriculum context to a Google AI model through Firebase AI Logic. The response is used to show a friendly practice score and feedback. The score is not calligraphy certification and is not used for advertising.

Online requests also contain technical service data needed to deliver and protect the request, such as the Firebase app identifier, platform and SDK information, IP address, user agent, and—on signed releases—an App Check token derived from Apple App Attest/DeviceCheck or Google Play Integrity.

3. Photo minimization and lifecycle

  • The picker is configured not to request full photo metadata.
  • The selected image is reduced to a bounded size when the platform supports it.
  • Before analysis, KanaDaruma decodes the image in memory, bakes visible orientation into the pixels, removes EXIF, GPS, ICC, and text metadata, then re-encodes it as JPEG.
  • The photo and its path are not added to learning history.
  • The app makes a best-effort deletion of its session cache copy after a successful score, replacement, retake, or leaving the flow.
  • If scoring fails, the session copy remains temporarily available so you can retry.
  • On Android, interrupted picker recovery can keep the chapter, prompt identifiers, phase, launch time, and returned cache path for up to 24 hours. Expired recovery data and its cache copy are removed on the next recovery check.
  • A photo selected from your system photo library is not deleted; KanaDaruma deletes only a session-scoped app or picker copy when the platform permits it.

Operating-system picker copies and provider-side request processing are controlled by their respective providers and cannot be directly deleted by KanaDaruma.

4. Learning progress stored on your device

KanaDaruma stores item attempts and skill strength for recognition, listening, recall, and handwriting; completed or skipped placement; review due dates; active lesson checkpoints; onboarding completion; and your selected pace, goal, and word-context interest. This supports offline lessons and adaptive review. A completed writing grade can update local handwriting evidence, but the photo and detailed cloud response are not stored in learning history.

The current app has no account synchronization or server-side learning profile.

5. Anonymous product analytics

KanaDaruma configures PostHog when the app launches. Because there is no account, KanaDaruma does not call PostHog's identify API or send a name, email address, account ID, or advertising identifier. PostHog uses a pseudorandom app-scoped identifier for an installation.

The app sends route and screen views. The SDK also sends app-lifecycle events and a small, fixed set of product events for onboarding, learning-session, Situation, and paywall funnel steps. These events contain only coarse state such as session type, Guided or Challenge mode, free or linked access, resume state, paywall source, and selected billing period. They do not contain lesson answers, exact correctness, item or Situation identifiers, health-related context, reminder schedules or taps, handwriting pixels, or scoring feedback.

Session replay is explicitly disabled, so PostHog does not receive screen recordings or screenshots. Project-wide IP anonymization is enabled, and console capture, performance capture, and heatmaps are disabled. Data is sent to the project's configured PostHog Cloud US endpoint and retained according to the project's settings and PostHog's terms. PostHog is not used for advertising, sale of data, or cross-app tracking.

6. Install attribution and funnel measurement

KanaDaruma configures AppsFlyer in release builds to measure app installs and the same non-revenue onboarding, learning, Situation, and paywall funnel steps. AppsFlyer receives an app-scoped installation identifier, fixed event names and coarse properties, and device, app, timestamp, locale, and network context needed to deliver and attribute those events.

KanaDaruma disables advertising-identifier collection, removes Android's advertising-ID permission, does not request Apple's App Tracking Transparency permission, and initially blocks event sharing with all integrated advertising partners. The app does not send names, email addresses, account IDs, learner-entered text, answers, item or Situation identifiers, exact learning performance, photos, or purchase value through the AppsFlyer client SDK.

The app-scoped AppsFlyer identifier is passed to RevenueCat so RevenueCat can deliver subscription lifecycle events if its AppsFlyer dashboard integration is enabled. RevenueCat is the sole AppsFlyer source for those revenue events, preventing duplicate purchase reporting. Enabling a specific advertising partner or broader data sharing requires a new privacy and store-disclosure review.

7. Purchases and subscriptions

KanaDaruma uses RevenueCat to load product offers, verify and restore purchases, and decide whether Premium features are available. The app does not pass an account ID, so RevenueCat creates a pseudorandom anonymous App User ID. KanaDaruma does not send RevenueCat a name, email address, account profile, or advertising identifier.

RevenueCat processes the anonymous ID, device and app context, store receipt or purchase token, purchase and subscription history, product and entitlement state, and related transaction timestamps. This supports purchases, restores, entitlement checks, customer support, and aggregate purchase and subscription analytics. Apple or Google remains the payment processor; KanaDaruma and RevenueCat do not receive your payment-card number from the app store.

8. Optional learning reminders

Learning reminders are off by default. If you turn them on in Learning reminders, KanaDaruma asks for the operating system's notification permission and schedules a small number of local notifications on your device. Your selected days and time, pause state, coarse reminder category, and recent scheduling and tap history remain in app-local storage. Notification bodies are generic and do not contain Japanese answers or detailed learning history.

KanaDaruma does not register a remote push token, upload your reminder schedule, or send reminder preferences, payloads, or tap history as analytics events. Turning reminders off cancels pending KanaDaruma notifications. Your operating system's Focus, notification summary, delivery, and settings continue to apply.

9. Permissions

Camera

Requested only when you choose Take photo.

Photo library

Used only when you choose Choose from photos. On supported system pickers, you select the individual image shared with the app.

Notifications

Requested only after you explicitly enable Learning reminders. The app remains fully usable if you decline.

Declining these permissions does not prevent character, vocabulary, listening, review, or tracing lessons.

10. Service providers and retention

KanaDaruma uses Firebase AI Logic for optional photo analysis and Firebase App Check to reduce abuse. Firebase AI Logic usage is governed by the applicable Google Cloud Platform, Generative AI, and Gemini API terms. Google/Firebase controls provider-side request, diagnostic, and security-log retention.

Firebase states that App Check does not retain attestation material. A successful App Check token is valid for its configured time-to-live, which Firebase caps at seven days. Tokens used with replay protection can be stored for up to 30 days; other App Check tokens are not retained by Firebase services. Attestation material sent to Apple or Google is subject to those providers’ terms.

PostHog controls provider-side analytics processing and retention under the KanaDaruma project settings and its terms. AppsFlyer controls provider-side attribution processing and retention under the KanaDaruma app settings and its terms. RevenueCat and the app stores retain purchase, receipt, subscription, and entitlement records under their service, support, accounting, fraud-prevention, and legal requirements. Processing can occur outside your country.

Official provider information: Firebase AI Logic data governance, Firebase privacy and security, Firebase App Check, PostHog privacy, PostHog privacy documentation, AppsFlyer privacy, RevenueCat privacy, and RevenueCat anonymous identifiers.

11. Your choices and data removal

  • Do not open the writing-photo flow if you do not want online photo processing.
  • Leave the scoring flow to trigger best-effort removal of its session copy.
  • Remove camera, photo-library, or notification permission in device Settings at any time.
  • Turn off Learning reminders to cancel pending KanaDaruma notifications.
  • Uninstall KanaDaruma to remove locally stored progress, reminder records, SDK identifiers, and app cache.

Uninstalling does not automatically erase provider-side analytics, attribution, or purchase records. Because KanaDaruma has no account or server-side learning profile, it cannot retrieve a profile by email. For privacy requests or a question about specific processing, contact the developer with the approximate date, device platform, and app version. Provider-side requests are subject to PostHog, AppsFlyer, RevenueCat, Google/Firebase, and app-store retention rules and legal obligations. Do not send an original handwriting photo unless specifically requested and you choose to do so.

12. Contact

For privacy requests, support, or questions about this policy, email bill@jocoding.net. You can also visit the KanaDaruma support page.

This policy may be updated when the app’s data handling or service providers change. The current effective date appears at the top of this page.