Privacy Policy for Vokki
Last updated: July 30, 2026
1. Introduction
Vokki (hereinafter — the "App") is a mobile application for learning German. We respect your privacy and strive to protect your personal data. This Privacy Policy explains what data we collect, how we use it, and how we store it.
2. What data we collect
- Learning progress — stories read, words learned, training results.
- App settings — interface language, theme, daily goal.
- Anonymous usage analytics — screen views, feature usage, session duration. No personal data is included.
If you use AI features:
- Voice input — microphone audio while a speaking call is running. Processed live, not stored as a recording. Pronunciation practice recordings are different: the audio file stays on your device, and only metadata (which story and sentence, and the length of the recording) is synced to our server.
- Conversation transcripts — the text of what you and the AI tutor said, stored on our server.
- Learner memory — a short profile of your recurring mistakes and topics you mentioned.
- Text you submit — call topics and target words, texts and YouTube links you import, words and sentences you ask us to explain or translate.
If you sign in with Apple or Google:
- Email address (for account identification).
- Name and profile photo (if provided by the auth provider).
Without signing in, all data is stored locally on the device only.
3. How we use your data
Collected data is used exclusively for:
- Ensuring the app works and preserving your progress.
- Improving the quality of the app.
4. Data storage
Without an account, all data is stored locally on the device.
If you sign in, your learning progress is synced with our server (Supabase, hosted in Germany). This allows you to restore progress on another device.
Data created by AI features — speaking-call transcripts, your learner-memory profile, imported texts and generated lessons, your ✦ Funken balance and history — is stored on the same server and linked to your account.
You can delete your account at any time through settings. Deletion removes your account, your learning progress, your speaking-call transcripts, your learner-memory profile and your imported content. It takes effect immediately and cannot be undone. Data already stored locally on your device is removed when you uninstall the app.
5. AI features and voice data
Vokki uses AI to power spoken practice, explanations and content you import. Here is exactly what happens.
Speaking practice with the AI tutor
- While a call is running, audio from your microphone is streamed live to our AI provider (OpenAI, US) so the tutor can hear you and answer in real time. We do not record or store the audio.
- Your speech is converted to text. The text of the conversation (yours and the tutor's) is stored on our server so you can read the summary after the call.
- What we send to start a call: the topic and target words you typed, your German level, the scenario, and a short "learner memory" profile.
Learner memory
- After a call, AI extracts a short profile from the transcript: grammar topics you keep missing and a few facts you mentioned about yourself. It is used to make later calls feel like a continuation. It is stored on our server, tied to your account, and never shared with other users.
Text you send to AI
- Word, form and phrase explanations, reply suggestions, the post-call summary, and lessons or stories generated from your material are produced by AI from the text involved.
- The topic and target words you type to start a speaking practice call are automatically screened for prohibited content before the call starts. Flagged text may be blocked.
Your control
- Speaking practice is optional — if you never start a call, no audio and no transcript is ever created.
- Transcripts and learner memory are deleted when you delete your account.
- We do not sell your data and we do not use your conversations to train AI models. Our AI providers process content sent through their APIs on our behalf and state that it is not used to train their models.
- Some providers process data in the United States. Those transfers are covered by the EU Standard Contractual Clauses.
6. Third-party services
- Apple Sign In / Google Sign In — for authentication (only by your choice).
- Supabase (self-hosted) — for cloud sync of authorized users' progress. Server is located in Germany.
- OpenAI (US) — powers speaking practice and AI explanations. Receives your microphone audio during a call, the conversation transcript, the topic and target words you type, your level, your learner-memory profile, and text you submit for explanation or generation. Also screens the topic and target words you type to start a speaking practice call for prohibited content. See "AI features and voice data" section.
- ElevenLabs (US) — text-to-speech for content you import or generate. Receives the German text and its translation in order to synthesise audio.
- DeepL (EU) — translation. Receives the word or sentence you tap, sentences from a speaking-call transcript when you ask for their translation, and the full text of materials you import.
- Supadata — fetches the subtitles of YouTube videos you import. Receives the video link you submit.
- YouTube Data API (Google) — reads titles and video lists for links and playlists you import. Receives the link you submit.
- Wiktionary (Wikimedia) — dictionary lookups. Receives the single word being looked up.
- PostHog (EU) — for anonymous product analytics (screen views, feature usage). Analytics is always active and cannot be disabled. Data is stored on servers in the EU (Frankfurt). No personal data is collected.
- Sentry (EU) — for crash and error reports. See "Crash reporting and diagnostics" section.
- RevenueCat (US) — for subscription management. See "Subscriptions and payments" section.
- Cloudflare R2 (CDN) — for streaming and downloading audio materials. No personal data is transmitted.
- Firebase Cloud Messaging — for delivering push notifications (only if enabled by you).
App stores (App Store, Google Play) may collect anonymous analytics according to their own policies.
7. Push notifications
If you enable push notifications, we collect:
- Device token (Firebase Cloud Messaging) — to deliver notifications to your device.
- Timezone — to send reminders at appropriate local times.
- Notification preferences — which types of reminders you enabled.
We use this data exclusively to send learning reminders and streak alerts. Google Firebase Cloud Messaging is used as a transport layer only.
All notification data is deleted when you delete your account.
8. Crash reporting and diagnostics
To improve app stability we use Sentry to collect crash and error reports:
- Error type, stack trace, and app version.
- Device model, OS version, and interface language.
- Anonymous session identifier (no email or name).
We do not send the contents of your dictionaries, notes, learning progress, or personal data to Sentry. Data is processed by Sentry GmbH (EU, Germany) and stored for no more than 90 days.
Reports help us quickly find and fix errors you may have encountered in the app.
9. Subscriptions and payments
Vokki offers a paid Pro subscription and one-time ✦ Funken top-ups. Payments are processed by the App Store (Apple) or Google Play — we do not receive or store your bank card data.
For subscription management we use RevenueCat (US). RevenueCat receives:
- Anonymous app user identifier.
- Purchase identifier and product (Pro subscription or ✦ Funken top-up; ✦ top-ups are one-time purchases).
- Subscription status (active, cancelled, expired).
This data is needed to unlock paid features across all your devices and to restore purchases. Email and name are not transmitted to RevenueCat.
You can cancel your subscription at any time via App Store or Google Play settings. After the paid period ends, access to paid features is revoked, but all your learning data is preserved.
10. Your rights
You have the right to:
- Know what data is stored.
- Delete your data — delete your account through settings, or uninstall the app to remove local data. Account deletion also removes your learning progress, speaking-call transcripts, learner-memory profile and imported content.
- Ask us for a copy of the data stored for you.
- Contact us with any privacy-related questions.
11. Contact
For privacy-related questions, contact us at: support@vokki.me