KPulse Speak — Privacy Policy

Last updated: 1 September 2026

This policy explains what KPulse Speak collects, why, and who else touches it. It is written to be read, not to be skimmed past.


1. Who we are

KPulse Speak is an independent app built and run by an individual developer. For anything in this policy, contact:

support@kpulse.app


2. What we collect

Your account

  • Email address — to log you in and send confirmation and password-reset codes.
  • Password — stored only as a secure hash by our authentication provider. We never see it.
  • Display name — the name you choose, shown to you and to other learners.
  • Username — an automatically generated @handle so your account can be shared. You did not choose it and it does not contain your email or real name.
  • Profile photo — optional. If you upload one, it is stored in a publicly readable location, meaning anyone with the image link can view it. Don't upload anything you wouldn't put on a public profile.

Your learning progress

Your level, current lesson, lesson completions, XP, rank, Sparks, Pulse, daily streak, achievements, and a record of rewards earned.

Things other learners can see

Your display name, username, profile photo, and XP appear on leaderboards and on your public profile, and to anyone who follows you. Everything else — your email, your recordings, your conversations with Hani — is private to your account.

Your voice

When you speak in a lesson, the recording is sent to our server, passed to Google's speech recognition service, converted to text, and used to check your answer.

The recording is not saved. It exists only for the few seconds the request takes, then it is discarded. We do not keep an archive of your voice.

Your conversations with Hani

When you talk with Hani, the conversation is not recorded and no transcript is stored. The audio and text exist only in memory during the call and are dropped when it ends.

Two things survive the call: 1. A usage record — how long you talked and when, so the app can show your history and apply weekly limits. 2. Up to a few short notes — at the end of a call, an AI summarises the chat into at most two brief facts (for example, "is learning Korean for a trip to Seoul") so Hani can remember you next time. These are stored as plain text on your account, capped in number, and older ones are automatically replaced.

Photos you scan (Live Roleplay)

When you photograph a subtitle, a chat screenshot, or a scene, the image is sent to Google's Gemini AI to write a roleplay script from it.

The photo is not saved. What we keep is the generated script and a short text description of what the AI saw, so you can replay it later. You can delete any of these from your history at any time.

Notifications

If you allow notifications, we store a push token for your device, whether it's Android or iOS, and your timezone (so reminders don't arrive at 3am). Also your notification preferences.

Feedback

Anything you send through the in-app feedback form, saved against your account.

Crash reports

When the app crashes or hits an error, we receive a report through Sentry: what went wrong, where in the code, and your device model and OS version. Your account ID is attached, so we can tell whether a crash hit one person or everyone. It is not used to track what you do in the app — only errors are ever sent.

How you use the app

So that we can see where the app is confusing people, we record which steps you reach through PostHog: screens opened, lessons started and finished, and whether signing up or logging in succeeded or failed. Each event carries your account ID, or — before you have an account — a one-way scrambled form of the email you typed, which we cannot read back and which exists only so a signup that failed can be matched to the retry that worked.

What is never sent: your name, your email address itself, your password, your voice, your photos, your messages to Hani, or anything you write. We use it to fix the app, not to build a profile of you, and it is never sold or shared for advertising.

Roughly where you are

Those same PostHog events carry an approximate location — your country, and usually your city. We do not ask your device for its location and the app has no location permission; this is worked out from the internet address your phone connects to us with, which is accurate to a city at best and often only to a country. We use it for one thing: knowing which countries our learners are actually in, so we can decide what to build and where to test. It is never used to find you, and it is never sold or shared for advertising.

Subscriptions

If you subscribe to Premium, Google Play handles the payment. What reaches us is only what tells us the subscription is active — an order identifier, the plan, and its renewal or expiry date — and we store that against your account so Premium stays unlocked for as long as you have paid for. We also check it with Google to confirm the purchase is genuine before unlocking anything.

We never see or store your card details — Google does not give them to us.


3. What we do NOT collect

  • No precise or device location. We never ask your device where it is, and the app holds no location permission — the only thing we know is the rough country/city worked out from your internet address, described above
  • No contacts, photos library, or files beyond the single image you deliberately scan
  • No advertising identifiers, and no ad networks
  • No cross-app or cross-site tracking, and nothing that follows you off KPulse
  • No card or payment details. If you subscribe, Google Play takes the payment and we never see your card — see "Subscriptions" above for the little we do receive

4. Why we collect it

Only to run the app and to improve it: to log you in, teach you Korean, check your pronunciation, let Hani hold a conversation, track your progress, run leaderboards, send the notifications you asked for, apply free-tier limits, and find the places where people get stuck so we can fix them.

If you subscribe, we also use the subscription record to unlock Premium, keep it unlocked until the period you paid for ends, and confirm the purchase is genuine.

We do not sell your data. We do not share it for advertising. We do not use it to train AI models of our own.


5. Third-party services

Running the app means some data passes through these companies. Each has its own privacy policy.

Service What it handles
Supabase Database, login, and file storage — your account and progress live here
Google Cloud (Vertex AI — Gemini) Powers Hani's replies, evaluates answers, and reads scanned photos
Google Cloud Speech-to-Text Converts your speech to text
Google Cloud Text-to-Speech Generates Hani's voice
Railway Hosts the app's server
Expo Delivers push notifications
Firebase App Distribution Delivers the beta build to testers (collects your email and device model)
Cloudflare Runs our domain, and hosts this site and our support email
Resend Sends confirmation and reset emails
Sentry Receives crash and error reports, with your device model and account ID
PostHog Receives which screens and lessons you reach, with your account ID and the rough country/city your internet address suggests — never what you say, write, or scan
Google Play Takes subscription payments and tells us whether yours is active. Your card details stay with Google

Google processes your audio and images to return a result to the app. Under Google Cloud's terms, this data is not used to train Google's models.


6. How long we keep it

  • Account and progress data — until you ask us to delete it.
  • Voice recordings and scanned photos — not kept at all.
  • Hani conversations — not kept at all.
  • Hani's remembered facts — kept until replaced by newer ones, or until you ask us to clear them.
  • Subscription records — for as long as you have an account. Google Play keeps its own record of the payment, which is theirs and not ours to delete.
  • Usage and approximate-location events — kept by PostHog for up to 12 months, then deleted automatically.
  • Beta build data — deleted when the beta programme ends, unless you continue as a normal user.

7. Deleting your data

Go to Profile → Settings → Delete account. You'll be asked for your password and to type DELETE to confirm. Everything above is erased immediately and permanently — your login, profile, photo, progress, XP, streak, achievements, inbox, league standing, the facts Hani remembers, and your scanned roleplays. There is no grace period and no way to recover it.

Forgotten your password? Use "Forgot password" on the sign-in screen to get back in first — we'll email you a code.

If you'd rather keep your account but clear only the facts Hani remembers about you, email support@kpulse.app and we'll wipe those.


8. Security

Passwords are hashed by our authentication provider and never visible to us. Traffic between the app and our server is encrypted. Login tokens are held in your phone's secure storage, not in plain files.

That said, this is an early-stage app built by one person. It is not certified, audited, or covered by any compliance programme. Please do not put sensitive personal information into your conversations with Hani.


9. Age requirement

You must be at least 13 years old to use KPulse Speak. If you are under 18, please make sure a parent or guardian is happy with you using it. We do not knowingly collect data from children under 13 — if we learn we have, we'll delete it.


10. Your rights

You can ask us, at any time, to: show you what we hold about you, correct it, delete it, or export it. Email the address above and we'll respond within 30 days.


11. Changes

If this policy changes in a way that matters, we'll tell testers by email or in the app before it takes effect.