Kotobaia privacy policy
Updated September 11, 2026
This policy describes how Kotobaia, an app from Sunimori, handles data for learning, accounts, social features, purchases and optional AI and speech features. Kotobaia does not sell personal data or use it for advertising across apps or websites.
1. Account information and Google sign-in
When you choose Google sign-in, Google and our authentication provider Supabase provide the account identifier, email address and basic profile information made available by Google, such as your name and profile image. We use this information to create or identify your Kotobaia account, display your profile, sync your data and associate purchases with the correct account. Kotobaia does not receive your Google password. Basic sign-in does not request access to Gmail messages, Google Drive files, contacts or calendars.
Google account information is processed through Supabase for authentication, account storage and synchronization, and through Cloudflare where needed for authenticated service requests. It is not sold, used for targeted advertising, or supplied as training data for general-purpose AI models. Using an optional AI feature may send the text you choose to enter and relevant learning context to the selected provider, as described below.
2. Learning, profile and purchase data
Vocabulary collections, quizzes, reviews, learning statistics, word lists and settings are stored on your device and, when signed in, synchronized to your Supabase account. Guests may choose iCloud key-value synchronization. A randomly generated device identifier helps prevent duplicate synchronization and is not used for advertising. When you use friends, rankings or sharing, your nickname, region, results and the learning information you choose to share may be visible to the relevant users. Apple-signed transaction identifiers, products, expiration and refund status are associated with your account to deliver and restore purchases and prevent duplicate claims. Apple handles payment card information; Kotobaia does not receive it.
3. Optional AI and cloud processing
AI features process your input, necessary conversation history and relevant learning context when you use them. Processing follows the execution mode and provider selected in the app. In Smart Balance mode, supported lightweight tasks can use Apple Foundation Models on the device; tasks that need cloud processing may use the selected provider through our Cloudflare service, or Apple Private Cloud Compute where supported. Device-only Apple and Apple PCC modes restrict processing to Apple. Cloud mode uses the selected external provider. The Mac app can also connect to an LM Studio server you configure; whether data leaves your device depends on its address.
4. Speech and audio
Speech recognition for conversation and interpretation prefers on-device processing. The cloud recognition mode for interpretation, and conversation on devices without supported on-device recognition, use Apple speech recognition. Pronunciation assessment sends microphone audio through Cloudflare to Microsoft Azure Speech; cloud interpretation sends audio to Google Gemini. Voice conversation sends recognized text and speech-synthesis requests rather than the recording. Japanese male-voice synthesis sends the text to Amazon Polly. Kotobaia does not retain audio content on its servers; short-lived usage counters support service limits and abuse prevention.
5. Service providers
- Apple — Device AI, Private Cloud Compute and speech services
- Supabase — Authentication, database and synchronization
- Cloudflare — Service proxy, usage control, content delivery and security logs
- Microsoft Azure — Pronunciation assessment and speech synthesis
- Amazon Polly — Japanese male-voice synthesis
- Google Gemini — Optional text AI and live speech
- OpenAI — Text AI when selected by the user
- Anthropic — Text AI when selected by the user
Providers may retain limited logs for security, abuse prevention and service delivery according to their API terms.
6. Retention and deletion
Device data remains until you delete it, uninstall the app or the system removes it. You can delete your account from the account page in Kotobaia; this removes the Supabase account and its associated learning, ranking and social data. Private caches of AI replies and pronunciation results expire after 24 hours. Purchase, refund, usage and redemption ledgers support correct balances and prevent duplicate delivery. Contact us with questions about retained records or deletion. Deleting a Kotobaia account does not cancel an Apple subscription.
7. Your choices
You can sign out, delete your Kotobaia account, revoke microphone and speech permissions, and choose supported device-only processing modes. You can also remove Kotobaia access from the third-party connections section of your Google Account. Disconnecting Google prevents future access through that connection; it does not by itself delete data already stored in your Kotobaia account. Use in-app account deletion or contact us for help.
8. Contact
For privacy or account questions, contact dev@sunimori.com. Please do not include passwords, authentication tokens or private recordings.