Privacy Policy

Last updated: March 24, 2026

1. Introduction

Pimochi is a language learning app. We respect your privacy and are committed to protecting your personal data. This policy explains what we collect, how we use it, and your rights.

2. Information We Collect

Account information

Your email address and password. Passwords are stored as bcrypt hashes — we never store or have access to your plain-text password.

Learning data

Articles you have read, vocabulary you have saved, quiz scores, streaks, and reading progress.

Preferences

Target languages, levels, topics, display settings, and timezone.

Usage data

Basic server logs including IP address and request timestamps, used for security and debugging purposes only.

OAuth data

If you sign in with Google, we receive your email and name from Google. We do not access your Google contacts, calendar, or any other data.

3. How We Use Your Data

  • To provide and personalize the learning experience
  • To track your progress (streaks, vocabulary review, quiz scores)
  • To generate and deliver articles tailored to your level and interests
  • To send transactional emails (password reset, email verification) — never marketing emails unless you opt in
  • To improve the service (aggregated, anonymized analytics only)

4. What We Do NOT Do

  • We do NOT sell your personal data. Ever.
  • We do NOT share your data with advertisers.
  • We do NOT use your data to train AI models.
  • We do NOT track you across other websites.
  • We do NOT use third-party analytics trackers (no Google Analytics, no Facebook Pixel).

5. Third-Party Services

  • Text-to-speech audio is generated using Microsoft Edge TTS. Text is sent to generate audio but is not linked to your account.
  • AI-generated content: Article text may be generated via OpenAI or Anthropic APIs. Your personal data is NOT sent to these services — only article prompts.
  • Google OAuth (if used for login): Subject to Google's privacy policy.

6. Data Storage & Security

  • Data is stored on servers we control.
  • Passwords are bcrypt-hashed.
  • Sessions use secure HTTP-only cookies.
  • All connections use HTTPS in production.

7. Data Retention & Deletion

  • You can delete your account at any time from Settings in the app.
  • Account deletion permanently removes all your personal data, learning history, and saved vocabulary.
  • Server logs are rotated and deleted after 30 days.

8. Children's Privacy

Pimochi is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child under 13 has provided us with personal data, please contact us and we will delete it.

9. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email or in-app notice. Continued use of Pimochi after changes constitutes acceptance of the updated policy.

10. Contact

Questions about this privacy policy? Email us at [email protected].