How we collect, use, and protect your information
At KanaMastery, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at kanamastery.com or use our services.
Data Controller: KanaMastery is the data controller responsible for your personal data. We are based in Portugal and operate under the General Data Protection Regulation (GDPR) and Portuguese data protection laws.
By using KanaMastery, you agree to the collection and use of information in accordance with this policy. We will not use or share your information with anyone except as described in this Privacy Policy.
Effective Date: December 5, 2024
Last Updated: December 5, 2024
We collect several types of information for various purposes to provide and improve our service to you:
We collect this information when you voluntarily provide it (account creation, profile updates) or automatically when you use our Service (analytics, logs).
Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:
Processing necessary to provide you with our Service, including account management, learning progress tracking, subscription management, and customer support.
Processing for analytics to improve our Service, fraud prevention, security measures (rate limiting, CSRF protection), and maintaining leaderboards. We balance our interests against your rights and freedoms.
Processing based on your explicit consent, including marketing emails and making your profile public on leaderboards. You can withdraw consent at any time.
Processing required to comply with legal obligations, such as maintaining financial records for tax purposes and responding to lawful requests from authorities.
We use the information we collect for the following purposes:
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy:
Your data is retained for the duration of your account. You may request deletion at any time.
Upon account deletion, we immediately delete or anonymize your personal data. However, we retain anonymized purchase records for up to 7 years to comply with tax and financial regulations in Portugal/EU.
Usage analytics collected via Google Analytics are aggregated and anonymized. We do not retain individual-level analytics data beyond what Google Analytics provides (typically 26 months for standard retention).
Security-related logs (authentication attempts, rate limiting) are retained for 90 days for security monitoring and fraud prevention.
Records of transactional emails sent are retained by our email provider (Postmark) for 45 days.
We use the following third-party services to operate KanaMastery. These providers only have access to your personal information to perform specific tasks on our behalf and are obligated to protect your data:
Purpose: Authentication (email/password, Google OAuth) and database (Firestore) for storing user data.
Data Shared: Account information, learning progress, preferences.
Purpose: Website analytics to understand usage patterns and improve the Service.
Data Shared: Anonymized usage data, page views, device information, IP address (anonymized).
Purpose: Secure payment processing for subscriptions and purchases.
Data Shared: Email address, name, purchase details. Credit card information is sent directly to Stripe and never touches our servers.
Purpose: Transactional email delivery (verification, password reset, payment confirmations, etc.).
Data Shared: Email address, name, email content.
Purpose: Profile image uploads and storage.
Data Shared: Profile images you choose to upload.
Purpose: Website hosting and infrastructure.
Data Shared: Standard web server logs (IP address, browser info, pages accessed).
We do not sell your personal information to any third parties for advertising or marketing purposes.
KanaMastery is operated from Portugal (EU). However, some of our third-party service providers process data in the United States and other countries outside the European Economic Area (EEA).
When we transfer your data outside the EEA, we ensure appropriate safeguards are in place:
You can request more information about the safeguards we use for international transfers by contacting us.
Under the General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:
How to Exercise Your Rights: You can exercise most of these rights directly through your account settings (update profile, delete account, change marketing preferences) or by contacting us at [email protected].
We will respond to your request within 30 days. We may ask you to verify your identity before processing your request.
If you believe we have not handled your data correctly, you have the right to lodge a complaint with your local data protection authority. For Portugal, this is the Comissão Nacional de Proteção de Dados (CNPD):
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
Categories of Personal Information Collected: Identifiers (email, name), account information, commercial information (purchase history), internet activity (usage data), and inferences (learning progress).
How to Submit a Request: Email us at [email protected] with the subject line "California Privacy Request." We will verify your identity and respond within 45 days.
Do Not Sell My Personal Information: KanaMastery does not sell personal information as defined by the CCPA/CPRA.
KanaMastery features leaderboards that can publicly display user rankings, usernames, and scores.
Opt-In Required: Your profile is private by default. To appear on public leaderboards, you must explicitly enable the "Public Profile" setting in your account preferences.
What's Displayed: If you opt into public leaderboards, the following information may be visible:
Opting Out: You can disable your public profile at any time through your account settings. Your data will be removed from public leaderboards, though this may take a few minutes to propagate.
Privacy Recommendation: We recommend using a pseudonym rather than your real name if you wish to participate in leaderboards while maintaining privacy.
We use cookies and similar tracking technologies to operate and improve our Service. Cookies are small text files stored on your device.
These cookies are necessary for the Service to function:
These cookies remember your preferences:
Google Analytics cookies help us understand how you use the Service:
Managing Cookies: You can control cookies through your browser settings. Note that disabling essential cookies may prevent you from using certain features of the Service.
Opting Out of Analytics: You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.
Learn more about how Google uses data: https://policies.google.com/technologies/partner-sites
Our Service may contain links to other websites that are not operated by us, including affiliate links to Japanese learning resources and products.
If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit.
We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.
Security Measures Include:
While we strive to use commercially acceptable means to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
Reporting Security Issues: If you discover a security vulnerability, please report it responsibly to [email protected].
Our Service is not intended for use by children under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personally identifiable information from children under 16.
If you are a parent or guardian and you are aware that your child has provided us with personal information without your consent, please contact us at [email protected]. If we discover that a child under 16 has provided us with personal information, we will delete this information from our servers promptly.
For Users Aged 16-18: If you are between 16 and 18 years old, we recommend reviewing this Privacy Policy with a parent or guardian.
We may update our Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
Notification of Changes: If we make material changes to this Privacy Policy, we will notify you by:
Material changes include modifications to how we collect, use, or share your personal data, or changes that affect your rights.
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after any changes indicates your acceptance of the updated policy.
If you have any questions about this Privacy Policy, your personal data, or wish to exercise your privacy rights, please contact us:
Email: [email protected]
Website: kanamastery.com
Response Time: We aim to respond to all privacy-related inquiries within 30 days. For urgent matters or to report security issues, please indicate this in your email subject line.
For EU/EEA Residents: If you are not satisfied with our response, you have the right to lodge a complaint with the Portuguese CNPD or your local supervisory authority.