Privacy Policy
Kotoba (the "Service") handles users' personal information in accordance with Thailand's Personal Data Protection Act (PDPA, B.E. 2562 / 2019) and Japan's Act on the Protection of Personal Information. This Policy explains what information the Service collects and how it is used.
1. Information We Collect
- Email address: Collected to send the Magic Link / OTP code for login.
- Study history: Per-card correct/incorrect answers, review timing, and FSRS calculation results. Used to personalize the study experience and visualize progress.
- Device information: For sync, a device identifier (anonymous ID unique to the device) is regenerated and stored at each login. It does not contain any personally identifying information.
- Purchase history: Transaction information received from the payment provider when purchasing a deck. Payment details such as credit card numbers themselves are not stored by the Service.
2. Purpose of Use (PDPA §24 legal basis)
- Providing the Service (contractual performance)
- Display of study progress and personalization (consent-based processing)
- Prevention of fraudulent use and system improvement (legitimate interest)
- Compliance with laws (legal obligations)
3. Disclosure to Third Parties
The Service does not disclose users' personal information to third parties, except to the following data processors.
- Supabase Inc. — Database and authentication infrastructure (USA, Singapore region)
- Stripe, Inc. — Payment processing (USA, scheduled for adoption in the latter half of Phase 1)
These ensure appropriate data protection through Standard Contractual Clauses and other measures.
4. Retention Period
We retain personal information while the account is active, or for the period required by law. After an account deletion request, we generally delete all personal data within 30 days (full deletion from backups takes up to 90 days).
5. Your Rights (PDPA §30–§37)
Users have the following rights:
- Access and obtain copies of their personal information
- Correct inaccurate information
- Delete personal information (the "right to be forgotten")
- Restrict or object to processing
- Withdraw consent (does not affect the legality of processing prior to withdrawal)
To exercise these rights, please use "Settings" → "Delete Account" inside the app, or contact us at the address below.
6. Data Security
Communications are encrypted with TLS, and authentication credentials in the database are hashed. In addition, Row Level Security (RLS) technically prevents access to other users' data.
7. Cookies and Similar Technologies
On the web version, we use the browser's localStorage to keep you signed in. We do not use cookies for advertising purposes.
8. Children's Privacy
The Service is not intended for users under 13. If we become aware that a user is under 13, we will delete the account promptly.
9. Changes to This Policy
This Policy may be revised in response to legal amendments or changes to the Service. We will notify you of material changes inside the app or by email.
10. Contact and Data Controller
Towaidee
Email: [email protected]
Users in Thailand may also file complaints with the PDPC (Personal Data Protection Committee, Thailand).