Privacy Policy

This privacy policy applies to the Kotri app for mobile devices, together with any related services operated by Toluwani Ogunsanya (collectively, the "Application"). Toluwani Ogunsanya is hereby referred to as the "Service Provider".


Information Collection and Use

The Application collects information when you download and use it. This information may include information such as


Accounts and Sign in with Apple

Kotri starts with an anonymous Firebase account. Its random account identifier connects your saved words, review history, tree, streak, and purchase access to your learning account. You may connect Sign in with Apple in Settings to recover that same account on another device or after reinstalling. Kotri does not request your name or email address for this feature. Apple provides an account identifier and authentication credentials, which are used to authenticate your account through Firebase.

Connecting Apple to an existing guest account preserves its learning progress. If Apple is already connected to another Kotri account, the app asks before restoring it. Restoring does not merge the two learning histories, and progress on the guest account is not transferred. Anonymous accounts cannot be recovered through Apple unless they have been connected first.


Cookies and tracking technologies

The Application or its third-party SDKs may use cookies, SDKs, pixels, and similar technologies to support functionality, analytics, or service delivery. Where required by applicable law, the Service Provider will obtain consent before using non-essential tracking technologies.


Your Rights

You may request access to, correction of, or deletion of your personal data held by the Service Provider. To exercise these rights, or to withdraw consent where processing is based on consent, contact the Service Provider at [email protected].


Your California privacy rights (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information is collected, the right to delete personal information, the right to opt out of the sale or sharing of personal information, and the right to non-discrimination for exercising these rights. To exercise your CCPA/CPRA rights, contact the Service Provider at [email protected].

The Service Provider may use the information you provide to send important information, required notices, and, where permitted by law, marketing communications.


For a better experience while using the Application, the Service Provider may require you to provide certain personally identifiable information. The information the Service Provider requests will be retained and used as described in this privacy policy.


Third Party Access

Firebase stores your authentication and learning records. RevenueCat processes purchase and subscription information associated with your account identifier. PostHog receives app usage events and, where enabled, session recordings associated with that identifier to help diagnose problems and improve the Application. These records can be linked to your app account; they are not limited to anonymous aggregate statistics. The Service Provider may share information with service providers as described in this policy.


International Data Transfers

The Service Provider or its third-party service providers may transfer personal data to countries outside your country of residence, including outside the European Economic Area (EEA). Where applicable law requires safeguards for international transfers, the Service Provider will use appropriate mechanisms.

Data protection laws in other countries may differ from those in your jurisdiction. Where required by law, the Service Provider will apply appropriate safeguards and obtain any consent required for the transfer.


Please note that the Application utilizes third-party services that have their own Privacy Policy about handling data. Below are the links to the Privacy Policy of the third-party service providers used by the Application:


The Service Provider may disclose User Provided and Automatically Collected Information:


Opt-Out Rights

You can stop further collection of information from your mobile device by uninstalling the Application. Uninstalling will stop the Application from collecting data from your device, but it does not automatically delete information that has already been transmitted to the Service Provider or to third parties.

To request deletion of your personal data, to withdraw consent, or to exercise any of your rights, contact the Service Provider at [email protected].


Delete your account or erase guest data

In Settings, connected accounts can choose Delete account. Anonymous accounts can choose Erase guest data. After confirmation and recording the deletion request, both actions promptly remove the Firebase account and queue deletion of its saved learning data. Connected Apple accounts must authorize with Apple again so the app can revoke its Apple authorization before requesting deletion. An Apple authorization cancellation stops that request.

Once accepted, deletion continues on our servers even if you close the app. The app stops using the old account and can show deletion status using a securely stored receipt. You can start a new learning account once the Firebase account is removed, while saved learning data and associated RevenueCat and PostHog cleanup, including analytics events and recordings, remain queued separately. The app distinguishes these stages and does not describe pending cleanup as completed. The Service Provider retries failed cleanup and investigates requests that cannot be automatically verified.

Deleting the account does not cancel an App Store subscription. You can manage or cancel subscriptions through your Apple account; the app provides a Manage subscriptions link. You do not need to cancel a subscription before requesting deletion.

We retain a minimal hashed account marker to prevent deleted data from being recreated by old requests. Operational deletion records remain while cleanup is pending. After completion, they no longer contain the account identifier or PostHog person identifiers and are scheduled for removal after 90 days. You may also request help with data deletion at [email protected].


Data Retention Policy

The Service Provider retains personal data based on its necessity for the stated purposes:

You may request deletion of your personal data, subject to any legal obligation to retain it. If you want the Service Provider to delete User Provided Data submitted through the Application, please contact them at [email protected]. Please note that some User Provided Data may be required for the Application to function properly.


Children

The Application is not intended for children under 16 years of age, or such higher age as required by applicable law. The Service Provider does not knowingly solicit data from children or market the Application to them.


Where parental or guardian consent is required under applicable law, the Application is not intended for use without that consent. The Service Provider does not knowingly collect personally identifiable information from children under 16 years of age in violation of applicable law. In the event the Service Provider discovers that a child has provided personal information, the Service Provider will immediately delete this from their servers. If you are a parent or guardian and you are aware that your child has provided the Service Provider with personal information, please contact the Service Provider ([email protected]) so that they will be able to take the necessary actions.


Security

The Service Provider is concerned about safeguarding the confidentiality of your information. The Service Provider provides physical, electronic, and procedural safeguards to protect information the Service Provider processes and maintains.


Data Breach Notification

If a data breach occurs that affects your personal data, the Service Provider will notify you in accordance with applicable legal requirements, including, where required, providing information about the nature of the breach and the steps being taken to address it.


Changes

The Service Provider may update this Privacy Policy from time to time. The Service Provider will notify you of material changes by posting the updated Privacy Policy with an effective date. Where required by law, the Service Provider will seek your consent to material changes before they take effect.


Previous versions of this Privacy Policy will be maintained and made available upon request by contacting the Service Provider at [email protected].


This privacy policy is effective as of 2026-09-29


Your Consent

Where processing is based on consent, you provide that consent by affirmatively opting in to the relevant feature or action. You may withdraw consent at any time without affecting processing carried out before withdrawal. Processing based on other lawful bases is carried out as described above.


Contact Us

If you have any questions regarding privacy while using the Application, or have questions about the practices, please contact the Service Provider via email at [email protected].


This privacy policy page was generated by App Privacy Policy Generator