Overview
Kotoru is designed to keep source material local when possible. This policy explains what Kotoru processes, why it is processed, and the choices available to you.
Data processed on your device
The default web capture path processes supported audio, text, photos, and documents in your browser. Local app data can include vocabulary, review history, transcripts, capture decisions, downloaded models, provider settings, and consent choices. Recorded audio is not included in account sync. Optional network providers are used only when you choose their features.
Account and sync data
If you create an account, Kotoru uses Supabase to provide authentication and store the learning snapshot you choose to sync. This can include your email address, account identifiers, vocabulary, reviews, transcripts, and capture decisions. Passwords are handled by the authentication provider and are not readable by Kotoru.
Billing data
If you purchase Pro, Stripe processes checkout and payment details, and RevenueCat manages subscription status across supported platforms. Kotoru receives identifiers, plan and entitlement status, purchase and renewal events, cancellation status, and limited transaction metadata. Kotoru does not receive your complete card number.
Product updates and leads
If you ask for product or learning updates, Kotoru stores your email address, consent time, landing page, locale, and limited referral or campaign information. This is used to send the updates you requested and understand which outreach works. Operational notifications sent to Kotoru’s private Slack channel exclude your email address. You can unsubscribe from marketing messages at any time.
Analytics and session replay
With your permission, Kotoru uses Google Analytics and PostHog to measure visits, performance, and aggregate feature interactions. PostHog may also record privacy-restricted session replay on the public site and learning app: all page text, form inputs, and element attributes are masked, while images, video, audio, canvas content, embedded frames, and marked private areas are blocked. Kotoru does not intentionally send recordings, transcripts, vocabulary, email addresses, account identifiers, authentication details, or payment details to analytics. You can decline analytics or reopen Analytics choices in the site footer or app Privacy settings. Essential security and service logs may still be processed to operate the Service.
Purposes and sharing
Data is processed to provide and secure the Service, sync your learning state, enforce usage limits, manage subscriptions, diagnose problems, understand aggregate product performance, comply with law, and communicate service-related information. Kotoru shares data only with service providers needed for those purposes, when you direct it, or when required for safety or legal compliance. Kotoru does not sell personal information.
Retention and security
Account and learning data is kept while your account is active and as reasonably needed for the purposes above. Billing records and security logs may be retained longer where required by law or legitimate operational needs. Kotoru uses reasonable technical and organizational safeguards, but no service can guarantee absolute security.
Your choices
You can use the guest experience without an account, decline optional analytics, export local learning data, delete the synced account snapshot from Settings, and cancel Pro renewal through billing management. Depending on where you live, you may also have rights to access, correct, delete, restrict, or obtain a copy of personal data.
Children and international processing
Kotoru is not directed to children under 13, or a higher minimum age where local law requires it, without appropriate consent. Service providers may process data in countries other than your own, subject to their safeguards and applicable law.
Changes and contact
We may update this policy as Kotoru changes. Material changes will be identified by a new effective date and, when appropriate, an in-product notice. Privacy requests can be sent through the support contact provided inside the Kotoru app.