Skip to main content

Privacy Policy

Last updated: 7 January 2026

1. Introduction

Welcome to Kanji Rush ("we", "our", or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our Japanese kanji learning application.

2. Data Controller

The data controller for this website is:

Kanji Rush Project

Email: support@kanjirush.app

Note: Kanji Rush is currently a private educational project. For formal inquiries, please contact us via email.

3. Information We Collect

We collect minimal information necessary to provide our service:

  • Email: Email Address: Used for account authentication (Magic Link login)
  • Username: Username: Optional display name you choose
  • Progress: Learning Progress: Your study statistics, character mastery levels, and session history
  • Preferences: Preferences: Language settings and interface preferences

Legal basis (GDPR Art. 6): Contract performance (Art. 6(1)(b)) for account data; Legitimate interest (Art. 6(1)(f)) for service improvement.

4. Cookies and Analytics

We use the following technologies:

4.1 Essential Cookies

  • Authentication cookies: Required for login functionality (Supabase auth)
  • Preference cookies: Store your language and theme settings

4.2 Analytics (PostHog)

We use PostHog for privacy-friendly analytics with the following safeguards:

  • No IP storage: Your IP address is NOT stored
  • No precise location: Only country-level geo (no city, coordinates)
  • No session recording: We do not record your screen
  • Respects Do Not Track: If you enable DNT in your browser, no analytics data is collected
  • EU hosting: Data processed on PostHog EU servers

Legal basis: Legitimate interest (Art. 6(1)(f)) for understanding how users interact with our app.

Opt-out: Enable "Do Not Track" in your browser settings, or contact us.

4.3 Performance Metrics

To improve app speed and user experience, we collect anonymised performance metrics:

  • Web Vitals: Page load times (LCP, FCP, TTFB), visual stability (CLS), and interactivity (INP)
  • AI Response Times: Latency of AI-powered features (dictionary lookups, explanations)
  • Voice Recognition Timing: Speech recognition latency for voice training mode

These metrics contain no personal information and are used solely to optimise performance.

Legal basis: Legitimate interest (Art. 6(1)(f)) for service optimisation.

5. Third-Party Services

We use the following third-party services:

ServicePurposeData Location
SupabaseDatabase, authentication, file storageEU (Frankfurt)
VercelWeb hosting and CDNGlobal Edge Network
PostHogPrivacy-friendly analyticsEU
SentryError tracking and monitoringEU
UpstashRate limiting and cachingEU (Frankfurt)

6. Data We Do NOT Collect

  • Passwords (we use Magic Link authentication)
  • Payment card numbers (processed by third-party payment providers)
  • Precise location data (GPS coordinates)
  • Device identifiers (IDFA/GAID)
  • Contacts or phone numbers
  • Biometric data

7. Your Rights (GDPR)

Under GDPR, you have the following rights:

  • Right of Access (Art. 15): Request a copy of your personal data
  • Right to Rectification (Art. 16): Correct inaccurate information
  • Right to Erasure (Art. 17): Request deletion of your account and data
  • Right to Data Portability (Art. 20): Export your learning progress data
  • Right to Object (Art. 21): Object to processing based on legitimate interest
  • Right to Withdraw Consent (Art. 7): Withdraw consent at any time

To exercise these rights, please contact us. We will respond within 30 days. support@kanjirush.app

Complaint: You have the right to lodge a complaint with a supervisory authority. For Germany: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW).

8. Data Security

Your data is protected by industry-standard security measures:

  • All data encrypted in transit (HTTPS/TLS 1.3)
  • Database access protected by Row Level Security (RLS)
  • SOC2-certified infrastructure (Supabase, Vercel)
  • Passwordless authentication (Magic Link)
  • Regular security audits

9. Children's Privacy

Kanji Rush is suitable for users of all ages, including children learning Japanese. We do not knowingly collect personal information from children under 16 without parental consent. If you believe we have collected information from a child without proper consent, please contact us immediately.

Parents: You can create an account for your child and manage their data through the Settings page.

10. Data Retention

We retain your data for as long as your account is active. If you delete your account, all your personal data will be permanently removed within 30 days. Anonymised analytics data may be retained for statistical purposes.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting a notice on the app and updating the "Last updated" date above.

12. Contact Us

If you have any questions about this Privacy Policy or your data, please contact us:

© 2026 Kanji Rush. Kanji Rush. All Rights Reserved.