1. Scope and choices

This policy describes data handled by the Kulma Android app and Kulma's connected account services. You can use the learning core without creating an account. If you do not sign in, Kulma does not upload your learning progress to its account service.

2. Data stored on your device

Kulma stores your selected language route, settings, lesson and answer history, review timing, vocabulary state, scores and other learning progress in a local database. Local file backups contain the same categories of learning data when you choose to export one.

This device-only data remains on your device until you clear Kulma's app data, uninstall the app, or replace it by importing a backup. You control exported files and where you share or store them.

3. Optional online account data

If you create or use an account, Kulma handles:

  • your email address, authentication records and account identifier;
  • your display name, friend code, accepted friendships and notification preference;
  • daily course summaries, including the language route, Fluency score, words learned, current course level and date; your device timezone offset is processed to calculate the appropriate local date but is not retained in that summary;
  • friends-only weekly ranking information derived from those summaries;
  • an optional private cloud backup containing your learning database, review schedule, lesson history, answer history and settings;
  • an Expo push token and device subscription record when you enable friend notifications; and
  • limited security, delivery and rate-limit records used to operate connected features and prevent duplicate or abusive requests.

Kulma uses this information to authenticate you, restore your chosen backup, show friends and rankings, deliver opted-in progress notifications, secure the service and respond to account actions. Your accepted friends can see your display name and the course progress used in friends-only charts and rankings. Your email, private backup and push token are not shown to friends. Kulma does not sell personal data or use it for advertising.

4. Device capabilities

Kulma may use the device accelerometer for a visual parallax effect on the Home screen. Those readings are ephemeral, are not added to your profile or learning history, and are not transmitted to Kulma's online service. Lesson audio is played by the app; Kulma does not use the microphone for these features.

5. Service providers and disclosures

Kulma uses service providers only to run the app and the optional features you select:

  • Supabase provides account authentication, the protected database, cloud backups and server functions.
  • Expo Push Service routes opted-in notifications to a learner's device.
  • Google Firebase Cloud Messaging completes Android notification delivery.
  • Google Play distributes the Android app and processes store-related data under Google's own terms.

These providers process data on Kulma's behalf or under their own applicable terms. Kulma may also disclose information when legally required, to protect users or the service, or as part of a business transfer with appropriate safeguards. No third-party advertising, behavioral analytics or crash-reporting SDK was found in this release.

6. Security

Connected traffic is encrypted in transit. Supabase manages password authentication; Kulma does not store your plain-text password in its learning database. Row-level database rules restrict profiles, backups and progress to the authenticated owner and authorized friend relationships. Server-only credentials are kept outside the app and website. No security measure can guarantee absolute protection.

7. Retention and deletion

Online account data is kept while your account exists so Kulma can provide the connected features you choose. When you delete the account, Kulma permanently deletes the Auth account and its associated profile, friendships, online progress, notification subscriptions and cloud backup through database deletion rules.

Service-provider backups and limited security or operational logs may remain for a short period where technically necessary or legally permitted before being overwritten or deleted. Kulma retains data longer only where required for legal compliance, security, fraud prevention or resolving a dispute. Device-only progress and exported files are not reachable by the online deletion process; clear app data, uninstall Kulma and delete your own exported files to remove those copies.

8. Your controls and rights

You can change your display name and notification preference, export or import local progress, sign out, and permanently delete an online account from Settings. You can also start deletion without the app on the public account-deletion page. Depending on where you live, you may have rights to access, correct, delete, restrict or receive a copy of personal data, or object to certain processing.

9. Contact

For privacy questions or requests that are not handled by the account controls, contact Kulma at contact.unlock.fluency@gmail.com. Please do not send a password or exported learning backup by email.

10. Changes

Kulma may update this policy when its features or legal obligations change. The effective date at the top will be updated, and material changes will be communicated through an appropriate in-app or store notice where required.