This policy explains what data ThaiHabit handles, why it is used and which services receive it.
Information We Collect
Local Learning Data: The app stores learning progress, streaks, review history and preferences locally on your device.
Optional Speech Recordings: If you start an online pronunciation exercise and separately allow Speech and pronunciation coaching, the recording and practiced Thai reference text are sent to our speech backend and Microsoft Azure Speech to transcribe or provide automated practice estimates. These estimates are coaching signals, not correctness judgments. Hugging Face ASR may be used server-side as a transcription fallback or optional comparison. These exercises are optional and require an internet connection.
Anonymous AI Identity and Quotas: The app may create a Supabase anonymous user id to enforce daily AI usage limits, restore Premium AI access and keep server-side quota records.
Optional Account Identity: If you choose email, Google, or Sign in with Apple, Supabase stores the account email and linked provider identity needed to authenticate you and restore your account. Apple may provide a private relay email address.
Optional Learning Profile Sync: Your selected Thai level, focus goal, polite ending and optional preferred name may be synced to Supabase so online conversations and phrase tools can use those choices across app sessions.
Generated Reference Audio: In releases where learner-derived online synthesis is available, requesting it and separately allowing Online reference audio sends the exact Thai prompt through a Supabase Edge Function to ElevenLabs. The initial review-safe release disables online synthesis for learner-entered, imported, custom, or AI-derived text and uses device speech instead, so that text is not placed in a shared permanent audio cache.
Optional Word-import Images: If you choose a screenshot or take a photo for word import and separately allow Vocabulary image import, that image and text extracted from it may be processed by the app backend and OpenAI, OpenRouter, or Hugging Face to extract and structure Thai words. This only happens when you start that import.
Optional Clipboard and File Imports: When you explicitly paste clipboard text or select a TXT, CSV, JSON, Anki, screenshot, or photo import, the app reads that selected content. Imported text is sent to OpenAI, OpenRouter, or Hugging Face only after you separately allow Vocabulary text import and request an online cleanup or check; standard text and Anki parsing can stay on device. ThaiHabit disables Hugging Face Dataset row search that would place learner text in URL query parameters.
AI Conversations: After you separately allow the applicable AI Conversation or Phrase Builder purpose, conversation messages or phrase instructions, custom goals, recent context and selected learning-profile context are sent through Supabase to OpenAI or OpenRouter. Allowing one purpose does not unlock the other. Synced conversation threads and bounded response-cache entries may be stored in Supabase. If you separately allow Online Thai language analysis, a typed Thai answer or lookup text and, for answer comparison, the expected answer and accepted alternatives may be sent through our backend to Hugging Face. Automatic wrong-answer feedback and live lookup remain local when this separate purpose has not been allowed.
Support and Feedback Requests: If you contact support, confirm an error report, or send feedback in the app, the request is linked to your current app or account identity. Your message, optional email address, app version, platform and basic diagnostics are stored in Supabase and delivered to support through Resend so we can respond and fix issues.
Optional Leaderboard: If you link a permanent account, accept the current version of the Community Rules and join the leaderboard, other participating learners can receive your curated alias, opaque public profile identifier, weekly and all-time rank and client-attested consistency-point totals and consistency-award count. The app may request one fixed 20-point award for an eligible completed practice day; the server limits awards to one per eligible local day and one per account UTC day, but does not independently verify the underlying practice. Your email, sign-in identifier, exact award time, private XP, level, streak, achievements, lessons, answers, report history and reporter identity are not public. A report stores its category, optional short explanation and a report-time alias, profile, visibility, moderation and accepted-rules snapshot for private human review. Participation is optional; you can leave, report a profile, block another participant or separately delete your leaderboard data in the app.
Network and Crash Diagnostics: Our backend and hosting providers process network information for security, abuse prevention and rate limiting. Supabase stores hashed network subjects for bounded rate-limit records. When Sentry is enabled, it receives crash and app/device diagnostics with default personal data, tracing, profiles, request data and user identity disabled in app code.
Learning Progress: The app stores your learning progress, including:
- Characters you have studied
- Review history and performance
- Learning streaks and statistics
- App preferences and settings
How We Use Your Data
We use local and optional online data solely to:
- Track your learning progress
- Use your selected level and goals to suggest relevant Thai activities
- Remember your preferences and settings
- Assess pronunciation when you choose to record
- Provide cached AI reference audio and daily quotas
- Validate Premium access and restore purchases
- Respond to support or feedback requests you submit
- Improve your learning experience
Data Storage and Security
Local Storage: Core learning progress, streaks, review history and preferences are stored on your device using the device's built-in storage mechanisms.
Limited Cloud Sync: If you sign in with email, Google, or Apple, eligible learning progress, preferences, custom word sets, their words and durable custom-vocabulary operation receipts are encrypted in transit and can synchronize to a Supabase account snapshot. Device-bound credentials, purchase caches, analytics identifiers, temporary import drafts and temporary media caches are excluded. Without account sign-in, core progress and custom vocabulary remain local-first.
Data Control: You can reset local learning progress, delete local app data, leave the public leaderboard, separately delete leaderboard data, or permanently delete a linked account and app-controlled cloud data from Profile. Leaving hides your public profile immediately without changing private learning. Separate leaderboard deletion removes the profile, score, awards, alias history, Community Rules acceptances and your blocks, while submitted reports are detached and may remain under the safety-retention policy below. Support remains available for applicable records outside those direct paths.
Third-Party Services
We do not show ads or use third-party behavioral advertising SDKs. On iOS, RevenueCat may collect Apple Search Ads attribution data to measure installs and subscription events. When AppsFlyer attribution is enabled, AppsFlyer may receive install, deep-link and privacy-filtered subscription-funnel event data. When product analytics is enabled, PostHog may receive privacy-filtered funnel events and allowlisted campaign labels, but not raw audio, transcripts, names, emails, support messages, raw URLs, or raw click ids. The app uses RevenueCat for purchase-status verification and Premium access; Supabase for identity, account snapshots, support, conversation sync, quotas, leaderboard operation and moderation, Edge Functions and storage; Resend for support notification emails; OpenAI or OpenRouter for separately permitted imports, phrases and conversations; Microsoft Azure Speech for separately permitted transcription and pronunciation feedback; Hugging Face for separately permitted Thai text understanding, image reading, answer comparison and speech recognition; ElevenLabs for separately permitted generated Thai audio where that feature is enabled; Apple, Google, Mozilla, or another browser-selected push service for opted-in reminders; and Sentry for restricted crash diagnostics when enabled.
Children's Privacy
Our app is designed for language learning and is not directed specifically to children under 13. Accounts are optional. Separately permitted online pronunciation exercises send speech audio for processing, releases with learner-derived online reference audio may send prompt text after separate permission and word import may process a screenshot or photo you select after its own permission, so younger users should use online features with parental guidance.
Data Retention
Local app data remains on your device until you delete it, sign out of a linked account, delete that account, or uninstall the app. Account snapshots and other app-controlled account records are retained while the account is active and are removed through in-app account deletion, subject to bounded operational and legally required records. For the optional leaderboard, pending or claimed reports remain until human resolution; resolved or dismissed reports are scheduled for deletion after 365 days. Separate leaderboard deletion detaches your identity from submitted reports but retains their immutable report-time snapshots until that boundary. A current hidden or suspended moderation restriction may remain until full account deletion so feature deletion cannot evade a safety action. Account-linked award fences expire after 72 hours and report-intake counters after 48 hours. Scheduled Supabase cleanup removes those expired controls plus stale AI response caches, archived conversations, resolved support requests, old webhook payloads, other rate-limit records, quota usage and stale generated-audio metadata according to configured retention windows. Store purchase history and provider security records follow Apple, Google, RevenueCat, hosting and AI/speech provider retention rules.
Your Rights
You can control local app data directly in the app, export linked-account data, separately delete optional leaderboard data and permanently delete a linked account from Profile. For applicable records outside those direct paths, contact us for access or deletion help:
- View your learning progress within the app
- Reset all learning data at any time
- Delete all app data through the app settings
- Delete the app to remove local device data
- Delete leaderboard data or a linked account and app-controlled cloud data in Profile, or contact contact@julianschubert.dev about applicable records outside those direct paths
App Data Deletion
You can delete all your app data at any time through the app's menu. This will:
- Remove all learning progress
- Clear all app preferences and settings
- Clear the local Supabase session and detach the local RevenueCat identity where possible
- Reset the app to its initial state
This action requires confirmation and cannot be undone. It resets local app state; it does not remove App Store or Google Play purchase history or provider records. If you joined the public leaderboard, use Delete leaderboard data to remove that feature's profile graph without deleting private learning or your ThaiHabit account. If you have a linked account, use Delete account in Profile to remove the Supabase Auth account, app-controlled cloud data and RevenueCat customer record. Apple-linked deletion reauthorizes with Apple and revokes the Apple authorization first. Records required for law, fraud prevention, security, or store purchase restoration may remain with the applicable provider; contact support for records outside the direct account path.
Subscription Services
Premium subscriptions are purchased through Apple’s App Store or Google Play. RevenueCat helps verify purchase status and provide Premium access. When you make a purchase:
- Purchase information is processed by Apple’s App Store or Google Play
- RevenueCat verifies purchase status and provides Premium access
- We do not store your payment information
- Subscription status is stored locally on your device and mirrored to Supabase for AI entitlement limits
RevenueCat's privacy policy can be found at: https://www.revenuecat.com/privacy
Speech Processing
After separate Speech and pronunciation coaching permission, online pronunciation exercises send recorded audio and the practiced Thai reference text to our backend, which forwards them to Microsoft Azure Speech for transcription or pronunciation assessment and may forward audio to Hugging Face for ASR fallback or optional comparison. Our backend processes audio in memory for the request and does not store uploaded recordings. In releases where learner-derived online synthesis is enabled, separate Online reference audio permission allows the exact Thai prompt to be sent to ElevenLabs through our Supabase Edge Function. The initial review-safe release instead uses device speech for learner-entered, imported, custom, or AI-derived text and does not create shared permanent provider audio for it.
Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at:
contact@julianschubert.devData Protection Rights
You have control over local learning data and direct export and deletion paths for linked-account and optional leaderboard data through the app's built-in features. For questions about retained safety records, optional speech processing, subscription-related data, or provider-held records outside those paths, contact us at the address above.
Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be reflected in the app with a new "Last updated" date. We encourage you to review this policy periodically.
Your Consent
Using ThaiHabit is not blanket permission to share personal data with third-party AI. Before the first transfer for each optional tool, an in-app consent dialog identifies the exact data, purpose and possible providers: OpenAI, OpenRouter, Hugging Face, Microsoft Azure Speech or ElevenLabs. Allow AI processing grants only the named purpose; permission for an image import does not unlock conversations, speech, reference audio, answer comparison, live language analysis or another import type. Not now cancels that transfer and keeps the content on your device. You can review or withdraw each permission at any time in Data and privacy; after withdrawal, ThaiHabit asks again before a new transfer for that purpose.
Website learning and download analytics
The website records visits to its landing pages, interactions with the sample lesson and store buttons, and selected learning or plan options. A short browser-tab session connects these actions with a broad source category, such as Google, ChatGPT, an email campaign or an unknown referral, and the language of the first landing page visited. The session uses sessionStorage and expires after 30 minutes without a recorded event; if storage is unavailable, it lasts only within the current page. We do not create a persistent visitor identifier or include raw referrer URLs, search terms, campaign text, email addresses, newsletter tokens or click identifiers in these event records.
Cloudflare processes these website events for aggregate reporting. The Analytics Engine dataset retains events for three months; operational logs may also record these events. The reports help us understand which visits lead to trying a Thai word or opening a store. They do not establish a person's identity or prove an app installation. This website measurement is separate from app analytics and newsletter subscription records. For questions about website data, contact contact@julianschubert.dev.