Kanzen · Legal documents
Privacy policy
How Kanzen collects, uses, and protects your personal data, in compliance with the GDPR.
Last updated: 15 September 2026 · Version 1.3
1. Data controller
Tom Piguet, sole proprietor, operating under the commercial name Ikigai Studio
55 avenue du Général de Gaulle, 60150 Longueil-Annel, France
SIRET: 904 611 175 00020
GDPR contact: contact@kanzenkanji.com
2. Data we collect
2.1 Data provided by the user
| Data | Origin | Status |
|---|---|---|
| Email address | Sign-up | Required |
| Password (hashed, never stored in clear) | Email sign-up | Required if signing up by email |
| Username | Profile | Optional (auto-generated by default) |
| Hanko (avatar), banner, honorific title | Profile customization | Optional |
| Personal mnemonics | User creation | Optional |
| Friend code (8 characters, auto-generated) | System | Required (technical) |
2.2 Data generated by use
| Data | Purpose |
|---|---|
| SRS progress (kanji seen, levels, intervals, review dates) | Operation of the review engine |
| Game and progress statistics (Dōjō mini-games, strokes, streaks) | Stats display, catch-up mode |
| Duel history (results, scores, league, Glicko-2 rating) | Ranking, anti-cheat |
| Friend list, invitations sent and received | Social feature |
| Referral: who invited you, date and status of the referral (pending, converted, rewarded) | Referral program, granting rewards |
| Invitation code passed on by Google Play when you install the app from an invitation link | Automatically linking your account to the person who invited you |
| Display preferences (theme, fonts, language) | Personalization |
| Unlocked seals and torii gates | Progress system |
| Published and adopted mnemonics | Community library |
2.3 Technical data
| Data | Purpose | Retention |
|---|---|---|
| Internal user ID (UUID) | Identification | Account lifetime |
| Authentication tokens | Session maintenance | 30 days max |
| Server logs (IP address, timestamp, error codes) | Security, anti-abuse, debugging | 30 days |
| Device ID for push notifications (Expo token) | Sending review reminders | As long as the option is enabled |
| Account emails sent (recipient address, date, delivery status) | Sending password reset links and security alerts | 30 days |
2.4 Subscription data (Kanzen Plus only)
When subscribing to Kanzen Plus:
- RevenueCat customer identifier (anonymous on the publisher side);
- subscription type (monthly / yearly / lifetime);
- subscription, expiration, cancellation dates;
- subscription status (active, in trial, expired).
We do not collect any payment data. Banking or credit card details are processed exclusively by Apple or Google and are never transmitted to the publisher or its subprocessors.
2.5 Data subject to your consent
Three optional processings are offered to you the first time you launch the App, and can be changed at any time from Profile → Preferences → Privacy. As long as a switch is set to “no”, no data from the corresponding processing is sent — and no answer counts as a refusal, never as implied agreement.
| Processing | Data involved | If you decline |
|---|---|---|
| Crash reports | Error type, call stack, app version, device model and operating system, internal account identifier. Your email address and authentication tokens are redacted before sending. | No report is sent, no monitoring tool is initialised. |
| User feedback (“Send feedback”) | Category, message, originating screen, app version, operating system, language — and the screenshot you choose yourself to attach from your gallery. | The feedback form is disabled. |
| Journey measurement | A handful of named steps (onboarding progress, Plus offer displayed, purchase started or confirmed, image shared, install source, invitation code entered), timestamped and attached to your account, in our own database. | No event is recorded. |
Journey measurement is not an analytics SDK: no device identifier, no automatic screen tracking, no third-party recipient, and a closed event vocabulary (about a dozen hand-named steps).
2.6 Anonymous counting before you create an account
Before you have an account, the App adds 1 to a daily total for a few named steps: welcome screen shown, demo finished, level chosen, kanji pack confirmed, plan ready, sign-up screen shown, sign-up attempted (by email, Google or Apple).
No identifier is sent and nothing is written to your device: only totals per day and per step are kept, which cannot identify you. This counting does not happen if you have already declined journey measurement.
2.7 Data we do NOT collect
- Geolocation
- Health data
- Phone contacts
- Background access to your gallery, your files or your camera roll — only a screenshot you attach yourself to a feedback message reaches us
- Microphone, camera
- Advertising identifiers (IDFA, AAID)
- Cross-app behavioral tracking
- Advertising cookies or trackers, in any form
3. Purposes and legal bases (GDPR art. 6)
| Purpose | Legal basis |
|---|---|
| Provide the service (account, SRS, duels, mnemonics) | Performance of the contract (art. 6.1.b) |
| Multi-device cloud synchronization | Performance of the contract |
| Duel mode and league ranking | Performance of the contract |
| Community mnemonics and adoptions | Performance of the contract |
| Management of Kanzen Plus subscriptions | Performance of the contract |
| Referral program and its rewards | Performance of the contract |
| Anti-abuse, security, fraud prevention (including referral fraud) | Legitimate interest (art. 6.1.f) |
| Transactional communications (password reset, security alerts) | Performance of the contract |
| Push notifications for review reminders | Consent (art. 6.1.a) — revocable from Preferences |
| Reporting and content moderation | Legitimate interest (community safety) |
| Anonymous counting of welcome steps, before an account is created | Legitimate interest (art. 6.1.f) — no personal data kept |
| Community figures published on kanzenkanji.com (reviews, kanji learned, duels…): totals across all accounts, with no per-person data | Legitimate interest (art. 6.1.f) — anonymous aggregates, admin accounts excluded |
| Crash reports (diagnosing and fixing bugs) | Consent (art. 6.1.a) — revocable from Preferences → Privacy |
| User feedback sent from the app | Consent (art. 6.1.a) — revocable from Preferences → Privacy |
| Journey measurement (onboarding and subscription steps) | Consent (art. 6.1.a) — revocable from Preferences → Privacy |
4. Recipients and subprocessors
The publisher does not sell, rent, or share your personal data with third parties for commercial purposes. The subprocessors below intervene strictly in the execution of the service:
| Subprocessor | Role | Location | Safeguards |
|---|---|---|---|
| Supabase Inc. | Database hosting, authentication, edge functions | Ireland (EU) — AWS eu-west-1 datacentre | Supabase DPA + applicable GDPR |
| RevenueCat Inc. | Technical management of subscriptions | United States | EU Standard Contractual Clauses 2021/914 + Data Privacy Framework |
| Apple Inc. | Sign in with Apple authentication, App Store | United States | EU Standard Contractual Clauses + Data Privacy Framework |
| Google LLC | Google OAuth authentication, Google Play | United States | EU Standard Contractual Clauses + Data Privacy Framework |
| Expo (650 Industries Inc.) | Push notification delivery service | United States | EU Standard Contractual Clauses |
| Functional Software, Inc. (Sentry) | Crash report collection | European data region (Germany) — company established in the United States | Storage in the EU + EU Standard Contractual Clauses. Enabled only after your consent. |
| Resend, Inc. | Sending account emails (password reset) | European data region (Ireland) — company established in the United States | Storage in the EU + EU Standard Contractual Clauses |
| Vercel Inc. | Hosting of the kanzenkanji.com website (legal pages, app page) | United States | EU Standard Contractual Clauses + Data Privacy Framework |
No data brokers, no advertisers, no resale.
5. Transfers outside the European Union
The main hosting (database, authentication, edge functions) is located in Ireland (EU), no data leaves it as part of the ordinary operation of the App.
Crash reports, when you have accepted them, are stored by Sentry in its European data region, and account emails are sent by Resend from its European region (Ireland): this data therefore does not leave the European Union either.
Some ancillary subprocessors (RevenueCat, Apple, Google, Vercel, Expo) are established in the United States. These transfers are governed by:
- the European Commission's Standard Contractual Clauses (implementing decision 2021/914 of 4 June 2021);
- the EU–US Data Privacy Framework (adequacy decision of 10 July 2023) when the subprocessor is certified under it.
6. Retention period
| Data | Duration |
|---|---|
| Active account and all its data | As long as the account exists |
| Deleted account | Production data erased immediately (except the fingerprint below); backups purged within 30 days |
| Referred user who paid for a subscription, then deleted their account: fingerprint (SHA-256 hash) of their email address, never the address itself | 3 years, then deleted automatically. Its only use is to prevent the same email from being referred twice. |
| Public mnemonics adopted by other users | Kept anonymized (author dissociated) |
| Technical logs (IP, error codes) | 30 days |
| Detailed review history | 365 rolling days (daily purge) |
| Journey measurement events | 180 rolling days (daily purge) |
| In-app notifications | 30 days |
| Feedback sent from the app | Message and technical context kept anonymized (author dissociated); the attached screenshot is deleted |
| Crash reports | 30 days, then deleted automatically by Sentry |
| Account email sending log | 30 days |
| Billing data on the Apple / Google side | Per store terms (generally 7 to 10 years for accounting obligations) |
7. Your rights
In accordance with articles 15 to 22 of the GDPR and articles 49 and following of the amended French Data Protection Act, you have the following rights:
- Right of access: obtain a copy of all data concerning you;
- Right to rectification: modify inaccurate or incomplete data (directly from the app for most, or by request);
- Right to erasure: delete your account and your data from Profile → Preferences → Account → Delete my account, or by request to contact@kanzenkanji.com;
- Right to portability: receive your data in a structured and commonly used format (JSON);
- Right to object: object to processing based on legitimate interest, for reasons related to your particular situation;
- Right to restriction: ask for the suspension of contested processing during the investigation of a complaint;
- Right to withdraw your consent at any time, for processing based on it (push notifications, crash reports, feedback, journey measurement), from the app Preferences;
- Right to lodge a complaint with the CNIL (the French data protection authority — www.cnil.fr) if you believe your rights are not being respected;
- Right to define post-mortem directives regarding the fate of your data after your death, in accordance with article 85 of the French Data Protection Act.
To exercise these rights: contact@kanzenkanji.com
You will receive a response within a maximum of one month from receipt of your request, in accordance with article 12 of the GDPR. This deadline may be extended by two months for complex requests, with prior notice.
8. Security
Technical and organizational measures in place:
- TLS 1.2+ encryption for all client-server communication;
- passwords hashed with bcrypt (Supabase Auth);
- authentication tokens stored in the operating system's secure keychain (expo-secure-store);
- PostgreSQL Row Level Security — each user can only access their own data;
- no direct database access from the client (mandatory passage through secured functions);
- administrator access restricted to the publisher only, traceability of accesses via Supabase.
No system is infallible. In the event of a data breach likely to entail a risk to your rights and freedoms, you will be notified without undue delay, in accordance with article 34 of the GDPR, and the CNIL will be informed within 72 hours (article 33).
9. Minors
The App is open to users at least 13 years old.
We do not knowingly collect personal data concerning children under 13. If you believe a minor under 13 has provided us with personal data, please contact us immediately at contact@kanzenkanji.com: we will proceed with deletion as soon as possible.
Minor users between 13 and 15 must obtain the prior consent of their legal representatives in accordance with article 8 of the GDPR and article 45 of the French Data Protection Act.
10. Cookies and trackers
Mobile app
The mobile app uses no cookies or advertising trackers. The only local storage is technical (authentication tokens, progress cache, preferences) and necessary for operation.
The kanzenkanji.com website
The site you are reading this page on uses only strictly necessary technical cookies, exempt from prior consent under article 82 of the French Data Protection Act. They are listed one by one in the website privacy policy, which is separate from this one.
11. Modifications
This Privacy policy may be updated to reflect changes to the App or to regulations. The "Last updated" date at the top of the document indicates the current version.
Any substantial modification (new subprocessor, new purpose, new type of data collected) will be the subject of an in-app notification and, where applicable, a consent collection.
12. Contact
For any question relating to your personal data:
Data protection officer: none designated. The designation of a DPO is not required given the volume and nature of the processing carried out (article 37 GDPR).