learnthai.app Open the app

Privacy Policy

Effective 31 August 2026 · applies to learnthai.app, app.learnthai.app and hebrew.learnthai.app

learnthai.app is an independent language-learning project run by Itai Bar Sinai (“we”). This page describes every piece of data the app touches — what stays on your device, what reaches our servers, which services process it on our behalf, and how to erase all of it. Questions and requests: privacy@learnthai.app.

The short version.

· Play without an account and your progress lives only in your browser — our database holds nothing about you.

· Sign in and we store your email, your answer history, your settings and your chats with Kru, so they sync across devices.

· One cookie total — the sign-in session. Analytics is cookieless. No ads, no cross-site tracking, no data sales, no third-party marketing.

· Questions you ask Kru are answered by Anthropic’s Claude and sent there for that purpose.

· If you pay for a plan, Paddle takes the payment and we never see your card.

· Delete your account any time — the link at the very bottom of ⚙️ Settings erases everything server-side, immediately.

Playing without an account

The game is fully playable signed out. In that mode your answer history, spaced-repetition schedules and settings are stored only in your browser (IndexedDB and localStorage) and are never sent to us — a signed-out visitor leaves no row in our database. Like any website, our hosting provider (Cloudflare) handles your IP address to serve pages and keeps short-lived operational logs (errors and diagnostics), which expire automatically within days.

What we store when you sign in

Signing in exists so your progress survives your browser. It adds these records, kept on Cloudflare’s D1 database:

Cookies and local storage

Analytics

We measure how the app is used with Google Analytics 4, in cookieless mode: which task types come up, whether answers were right, which features get used — counted as events, with no identifier stored in your browser, which also means visitors who aren’t signed in are counted only approximately. What is measured is deliberately impersonal — we never send Google your email address, your practice name, anything you typed, your questions to Kru, or the text of a feedback report. When you are signed in, events carry a pseudonym (a truncated cryptographic hash of your email) so that your phone and laptop count as one learner; it is cleared the moment you sign out. Cloudflare Web Analytics additionally counts page loads in aggregate, likewise without cookies.

Kru, the AI teacher

Kru is powered by Anthropic’s Claude models. When you ask a question, we send Anthropic the conversation, the card on screen, and how you’ve been doing on that card — that context is what makes the answer specific. Under Anthropic’s commercial API terms this data is not used to train their models. Transcripts are stored with your account and erased with it. Please don’t put personal details in questions to Kru — it never needs them.

Feedback reports

“Report a problem” sends what you typed plus what the screen was showing (which card, which task, which audio clip) into the project’s private issue tracker on GitHub, tagged with your account ID rather than your email address. Reports become part of the project’s development records; once an account is deleted, its ID no longer maps to anyone.

Paying for a plan

We never see your card. Paddle.com is the Merchant of Record for every purchase: the checkout is theirs, the card number goes to them and never reaches us, and they hold the billing address and tax details a receipt legally needs. What comes back to us is only what unlocks the plan — your email address, which plan it is, and when it runs out. Refunds are processed by Paddle too. Their privacy policy covers their side of the payment. Playing on the free plan involves none of this.

Services that process data for us

ServiceRoleWhat it handles
CloudflareHosting, database, aggregate analyticsAll traffic; every record listed above
GoogleAnalyticsImpersonal usage events; pseudonymous ID
ResendSending sign-in codes and product updatesYour email address; the update list
AnthropicGenerating Kru’s answersKru questions and card context
PaddleSelling and billing paid plans, as Merchant of RecordYour email address, payment and billing details — held by Paddle, not by us
GitHubIssue tracker for feedbackReport text and card context, account ID

These providers process data in the United States and Europe. Where EU/UK data-protection law applies, transfers rest on the providers’ certifications under the EU–U.S. Data Privacy Framework and/or standard contractual clauses.

Email

We send two kinds of email. Sign-in codes — the 6-digit code you request to log in. Product updates — occasional notes about the app: signing in adds you to those, as the sign-in form says at the moment you give the address, and you can leave at any time — every update carries a one-click unsubscribe, and there is a switch under ⚙️ Settings → Account. The update list lives with Resend, our email provider; deleting your account removes you from it along with everything else. We never share the list, and we never send third-party marketing.

What we never do

We don’t sell or share personal data for advertising, run ad networks, or track you across other sites.

Retention

Sign-in code records (with their IPs) are deleted within 24 hours. Sessions expire after 180 days idle. Everything else — history, settings, transcripts, usage counters — is kept while your account exists and erased when it is deleted. Data on your own device is yours: signing out clears it, and browser controls can clear it any time.

Your rights and choices

Delete everything: the “Delete account…” link at the very bottom of ⚙️ Settings. It permanently erases your account and every server-side record, immediately, no questions asked. You can also email us to delete, access, correct, or receive a copy of your data: privacy@learnthai.app. We answer within 30 days.

If you are in the EEA or UK, these are your GDPR rights of access, rectification, erasure, restriction, portability and objection; our legal bases are performance of our terms with you (accounts, sync, Kru) and legitimate interest (security, rate limiting, impersonal analytics). You may also complain to your local supervisory authority. If you are in Israel, you have corresponding rights under the Privacy Protection Law. We honor rights requests from anywhere, wherever the law they invoke applies.

Children

The app is not directed at children under 13, and you may not create an account under 13 (or under the higher age your country sets for consenting to online services). If we learn we hold a child’s account, we will delete it; parents can write to the address above.

Changes to this policy

When the app changes what it collects, this page changes with it, with a new effective date. Material changes will be flagged in the app itself, not slipped in quietly.