PRIVACY

Privacy Policy

Learn what information Kotomoa processes and what rights you have.

Who controls your personal information

Kotomoa publishes this policy to protect the personal information processed while providing the service and to address related concerns promptly.

This policy applies across the web service, iOS and Android apps, community, review features, JLPT Mock Tests, and paid products.

AI teacher terms

Guest conversations, memories and journals are stored only in this browser or app. When signed in, conversations, corrections, quiz attempts, user memories, learning journals and synchronization consent records are stored per account on Kotomoa servers for access across devices and deleted when the account is deleted. Guest and account records are separate; guest records are never uploaded or merged into an account. Account learning records are not retained in persistent device storage. Model and voice preferences and device consent receipts are kept separately per account on this device. Local inference does not send conversations to an external AI server, but signed-in learning records are saved to Kotomoa servers. With Gemini selected, relevant recent conversation, your input, related memories and learning materials are sent through the Kotomoa backend to Google Cloud. Speech sends only the selected response text. Do not enter sensitive information or other people’s personal data. Take care on shared devices and when deleting site data.

Scenes are Japanese roleplays in which Gemini generates and advances goals, counterpart dialogue and actions as text for the selected role and situation. Background image generation uses only fal.ai. Similar images in the shared background library are reused first; only when none is available is a visual prompt sent to fal.ai. Scene settings, goals, dialogue and progress are stored in your account, available across devices, and deleted when you delete your account. Generated backgrounds are kept in a shared server image library and reused across users in similar scenes. The shared index contains only the location, lighting and visual features, without account details or dialogue transcripts. Shared backgrounds remain after an account is deleted. Counterpart dialogue can be played as speech; generated audio is kept temporarily in screen memory only. AI progress and completion judgments may be wrong and do not make real reservations, purchases or ticket transactions.

When furigana, translation or analysis is enabled, the response text is processed by Kotomoa’s server-side morphological analyzer. Local-model reply and translation generation, and analysis of unregistered expressions, run on your device without transfers to external AI or translation providers. Signed-in conversation history is saved to your account as described in the storage notice. For Gemini-model responses, the response text is sent through the Kotomoa backend to the Google Cloud Translation API for automatic translation by Google Translate; analysis of unregistered expressions uses the corresponding Gemini model. These auxiliary requests and results are not saved to the usage database, conversations, memories or journal and are used only in the current view.

Google Cloud processes Gemini conversation, correction, speech synthesis, speech recognition, scene goal and progress text, and response translations through the Cloud Translation API as a service provider. For Gemini response translations, the required response text is sent through the Kotomoa backend to Google Translate (Cloud Translation API) for automatic translation. Local-model reply and translation generation run on your device without transfers to external AI or translation providers. However, Kotomoa’s server handles morphological and reference analysis for furigana, translation and analysis displays; signed-in conversation history is saved to your account as described in the storage notice. Required text and microphone utterances from calls using Gemini speech recognition are sent over encrypted connections when requested and may be processed internationally through global endpoints. Google's processing and retention conditions follow its service-specific terms, applicable data processing terms and data governance notices; the relevant Preview conditions apply to Gemini Preview models. Background image generation uses only fal.ai, an external AI service. A visual prompt for the scene background is sent when no reusable shared background is available. Transfers to fal.ai are also encrypted and may be processed internationally. Its processing, retention and use restrictions follow its Terms of Service, Privacy Policy, Acceptable Use Policy and data retention documentation. Use local teacher chat with speech and Gemini assistance turned off, and do not use Scenes, to avoid these external AI transfers. Inputs or outputs that violate either provider's acceptable use policy, unauthorized impersonation and deceptive use of synthetic voices are prohibited.

THIS SERVICE MAY CONTAIN TRANSLATIONS POWERED BY GOOGLE. GOOGLE DISCLAIMS ALL WARRANTIES RELATED TO THE TRANSLATIONS, EXPRESS OR IMPLIED, INCLUDING ANY WARRANTIES OF ACCURACY, RELIABILITY, AND ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT.

Google Translate · Cloud Translation API

Each Gemini conversation, correction, speech synthesis, speech recognition, scene planning and scene turn request records the account, request identifier, teacher, model, voice, processing time, status and provider-reported token counts on the server. Successful fal.ai background generation requests are counted separately. Per-request prices and estimated costs are not stored; costs are calculated at query time using administrator-defined, effective-date formulas, aggregated Gemini tokens, and successful fal.ai request counts with a fixed per-request rate. Conversation text, audio and images are not stored in the usage database. Local usage separately records a hashed device identifier and device-reported tokens and time. Offline records may be sent after reconnection. These records support usage review, cost estimation and troubleshooting, and do not automatically charge users. Any paid service will disclose prices and payment conditions and obtain separate consent.

Community auto-translation

Community auto-translation uses Google Translate (Cloud Translation API). When auto-translation is enabled and a post’s original language differs from the interface language, the required title and body text is sent through the Kotomoa backend to Google for translation and may be processed internationally. Translations are cached in the database and reused; the original is preserved. The original may be displayed when a translation is unavailable or fails. Automatic translations may contain errors, so refer to the original when accuracy matters.

Google Translate · Cloud Translation API · Read the Google translation disclaimer

Purposes of processing

  • Create and authenticate accounts, maintain sessions, manage nicknames and profiles, and prevent abuse
  • Sync review progress, run games, and provide JLPT Mock Test sessions, scoring, and results
  • Provide community posts, comments, reactions, polls, and notifications, and handle reports and disputes
  • Confirm paid-product purchases, grant and restore access, and handle refunds and transaction disputes
  • Maintain service reliability and security, analyze errors, and respond to user inquiries

Legal bases for processing

We process account, learning, community, exam, purchase, and direct-email inquiry information to the extent needed to enter into and perform the service contract you request. We process inquiry-form information only after explaining the collection and use purpose, required fields, retention period, and consequences of declining consent, and only within the scope you consent to. When a legal obligation applies, such as retaining transaction records, we process the information under that law.

We process the minimum information needed for security, abuse prevention, and dispute handling only when Kotomoa has a legitimate interest that clearly outweighs the impact on your rights.

Information processed and retention periods

Account and authentication

We process your nickname, preferred language, sign-in provider and provider account ID, and your account’s public and private IDs and status. An email address is not currently a required stored account field.

For Google sign-in on the web, we temporarily process the Google-issued ID token only during the sign-in request to verify its issuer, audience, signature, and expiration, and we store the verified Google account ID as sign-in provider information. When a new account is created, we may use the verified Google display name and profile photo as the default nickname and profile photo. You can edit your nickname and change or delete your profile photo. We do not store the original ID token or Google email address as account information.

For Sign in with Apple, we temporarily process the authorization code, ID token, and nonce issued through the Sign in with Apple pop-up on the web or Android, or through the system authentication screen on iOS or iPadOS, only during the sign-in request. We store the verified Apple account ID as sign-in provider information. We do not store the original authorization code, ID token, nonce, or Apple email address as account information.

When you delete your account, we delete its authentication methods, sessions, profile, avatar, review progress, and original nickname. To preserve referential integrity for posts, transactions, and exam results, we retain an account record containing the withdrawal status and time, a randomized public ID, and an internal replacement nickname until the service ends. Public screens display the author as “Deleted user.”

Sign-in sessions

We process a hash of the session token; whether the session is for the web or app; and the authentication, last-use, expiration, and revocation times. A session remains active for up to 30 days after its last use and up to 90 days after its initial authentication.

We revoke a session earlier if you sign out or delete your account, or if revocation is required for security.

Community

We process post and comment content, nicknames, attachment information, reactions, bookmarks, polls, notifications, and creation and modification times. For anonymous posts, we also process a device UUID, password hash, audit fingerprint hash, IP address, and User-Agent.

We delete the original IP address and User-Agent from anonymous audit data 90 days after creation. We retain the fingerprint hash with its related records to verify post ownership and prevent abuse. Upload drafts expire after 24 hours and are deleted by the cleanup process.

Posts and comments may remain public until their author deletes them or they are removed under the operating policy. After account deletion, we may preserve the surrounding discussion and replies while changing the author display to “Deleted user.”

Review and games

For signed-in accounts, we store review folders, items, and modification times with the account. Review progress and game state for signed-out users may be stored only in the user’s browser or app storage.

We delete account review progress when the account is deleted. Information stored on a device may remain until the user clears browser or app data.

JLPT Mock Tests

We process the account, exam and content versions, exam flow, selected-answer indexes, overall and section scores, elapsed time, and submission time. We do not duplicate the question text, correct answers, or explanations in the account results table.

We retain submitted results and the minimum answer record as immutable records until the service ends so we can preserve result integrity and provide history. After account deletion, we block user access but retain the connection between the result record and the deleted account.

Purchases and access rights

We process the product, payment provider, transaction ID, status, purchase time, private account-linking ID, and access status. For Play Store purchase tokens, we store only an encrypted value and a hash. Kotomoa does not store raw payment details such as card numbers.

A purchase-intent record is valid for seven days. We retain transaction and access records until the service ends to confirm payments, issue refunds, restore rights, and prevent abuse, or longer when a statutory retention period below applies. We deactivate access rights when an account is deleted.

Inquiry form submissions

We store your name, reply email address, inquiry type, subject, message, privacy collection-and-use consent status, and consent time in Kotomoa’s PostgreSQL database. As a rule, we delete the record three years after the inquiry is closed or answered.

If a dispute is ongoing or another legal retention basis applies, we keep only the necessary information separately until that basis ends. The inquiry database does not store the original IP address or User-Agent.

Direct email inquiries

Gmail processes the email address, inquiry content, attachments, and reply history. As a rule, we delete them three years after the final reply. If a dispute is ongoing or a legal retention basis applies, we keep only the necessary information separately until that basis ends.

Do not send passwords, authentication tokens, full card numbers, or unnecessary sensitive information.

We retain the following records for the specified periods under applicable laws, including South Korea’s Act on the Consumer Protection in Electronic Commerce. When a legal obligation takes priority, we retain only the required scope after a deletion request and do not use it for another purpose.

Display and advertising records

6 months

Contract and withdrawal records

5 years

Payment and supply records

5 years

Consumer complaint and dispute records

3 years

Public community content and sensitive information

Community posts and comments, attachments, and nicknames are public information that anyone can view. Kotomoa currently does not offer private posts.

Do not post sensitive information such as health, beliefs, or political views; unique identifiers such as a resident registration number; contact or financial information; or another person’s personal information. Do not enter information you do not want made public. After posting, you can delete it yourself or request its removal at moonlab.app@gmail.com.

Sharing and direct processing by external providers

Kotomoa does not sell personal information or routinely provide it to third parties. We may provide information within the scope separately disclosed or consented to when you give separate consent or when permitted by law.

Paddle, the App Store, and Google Play collect purchaser and payment-method information directly on their own screens and handle transactions, receipts, and refunds. When you open a screen where Google or Apple sign-in, Google AdSense, YouTube, or X content is active, that provider may directly process your IP address, browser and device information, cookies and advertising IDs, and usage information.

Google, Apple, Paddle, X Privacy Policy describe how each provider processes information.

Google sign-in on the web runs through a Google Identity Services pop-up only when you choose it. Sign in with Apple runs through a pop-up on the web and Android, and through the operating system’s authentication screen on iOS and iPadOS.

Processing service providers

The arrangement below applies only to inquiries that a user sends directly to the public email address. It does not apply to information submitted through the inquiry form and stored in Kotomoa’s PostgreSQL database.

Processor

Google LLC (Gmail)

Processing services

Receive, store, and answer inquiry emails, and perform spam and security processing

Information and period

Sender email address, inquiry body, attachments, and reply history / three years after the final reply or until the statutory retention basis ends

International transfers

When you use the features below, the necessary information is sent over an encrypted network to providers outside South Korea. You may refuse the transfer by not using the feature, but the related direct-email inquiry, payment confirmation, or purchase-restoration feature will then be unavailable.

Google LLC / United States

If you choose Google sign-in on the web, your browser connects to the Google sign-in pop-up. Google may process your IP address, browser and device information, Google-domain cookies, and selected account information for account selection, authentication, and security. When authentication is complete, Google provides an ID token to the browser. Kotomoa verifies it on its own server and does not store the original token.

When you send an inquiry email, the sender address, body, attachments, and reply history are transferred to Gmail and processed for inquiry handling and security for three years after the final reply.

When you confirm or restore a Google Play purchase, the product and package IDs and purchase token are transferred. Purchase records may be retained while the Google account remains active, and records needed for payment, tax, accounting, or security may be retained for the applicable legal or operational period. Additional processing may occur in countries where Google operates global infrastructure.

Recipient contact and privacy policy · Retention information

Apple Inc. / United States

If you choose Sign in with Apple, Apple may process your IP address, browser and device information, Apple-domain cookies or device account information for account selection, authentication, and security. After authentication, the authorization code, ID token, and nonce are sent to Kotomoa’s server for verification. We do not store their original values as account information.

When you confirm or restore an App Store purchase, the product, app, and transaction IDs and proof of purchase are transferred. Purchase and download records may be retained while the Apple account remains active, and financial reporting records may be retained for at least 10 years in most regions.

Recipient contact · App Store processing and retention

Paddle.com Market Limited / United Kingdom

When you start a web payment or confirm a transaction, the product ID and randomized purchase-intent ID are transferred to provide the checkout, confirm transactions and refunds, and prevent fraudulent transactions. Paddle collects purchaser and payment-method information directly. Some transaction records are retained for five years to meet legal obligations.

Recipient privacy request contact · Privacy Policy

Google uses global infrastructure to provide its services, and Paddle may use affiliates and processors outside South Korea. The notices above describe additional processing locations and periods. If a provider’s processing locations or retention policy changes, we will review the change and update this policy.

Cookies and device storage

Web sign-in uses an HttpOnly session cookie. Theme, sidebar, signed-out review progress, and some game and exam state may be stored in localStorage or sessionStorage. The app stores authentication tokens in the operating system’s secure storage.

You can delete cookies and stored data in your browser settings. Blocking the essential session cookie prevents sign-in, and clearing device storage may remove unsynced state. On the web, Google may use separate cookies or identifiers on its own domains when the Google sign-in pop-up or advertising is active.

Third-party advertising providers, including Google, may use cookies to serve ads based on your previous visits to Kotomoa or other websites. Google’s use of advertising cookies enables Google and its partners to serve ads based on visits to Kotomoa and other sites.

You can turn off personalized ads from Google in Google Ad Settings. If a non-Google third-party advertiser or network is enabled and offers an opt-out, you can opt out of personalized advertising cookies on that provider’s site or through YourAdChoices for some third parties.

Deletion procedures and methods

When the purpose and statutory retention period end, we promptly delete personal information in a way that makes recovery difficult. We delete database records or remove their links, and remove files from storage and cleanup queues. Records that must remain for legal requirements or transaction or result integrity are separated or access-restricted so they are not used for another purpose.

We do not treat hashing, encryption, or replacement with a randomized ID alone as completed deletion. While information can still be linked with other data to identify a person, we protect it as personal information and delete it together when the retention basis ends.

Rights of users and legal representatives

You can view, correct, or delete your information and delete your account through account settings and the relevant content screens. Send requests to access, correct, delete, or suspend processing; withdraw consent; or handle posts after account deletion to moonlab.app@gmail.com.

Kotomoa may request the minimum information needed to verify that the requester is the individual concerned or an authorized representative. If another person’s rights or a legal restriction limits the request, we will explain why.

Kotomoa is not designed for children under 14 and does not collect age as required account information. If a legal representative learns that a child’s information has been processed, they may request deletion or other action through the same email address.

Security measures

We store hashes or encrypted values instead of raw session credentials, passwords, and proof of purchase, and use HttpOnly cookies for web authentication. Google ID tokens and Apple authorization codes, ID tokens, and nonces are used only for verification requests and are not recorded in URLs, browser storage, initial screen data, or logs. We apply access controls, input validation, transport protection, and boundaries for logs and file storage.

Privacy contact

Responsible entity

Kotomoa

Send inquiries, complaints, or requests to exercise privacy rights to the contact address above.

Remedies for privacy violations

If you are not satisfied with Kotomoa’s response or need separate counseling or dispute mediation, you may use the Personal Information Portal, Privacy Infringement Report Center or Personal Information Dispute Mediation Committee.

Changes to this policy

If applicable laws, the service, or the information we process changes, we will announce the changes and effective date in the service before they take effect.

Effective date

This policy takes effect on August 24, 2026.

Menu

Language
Display theme

Sign In

Sign in to continue.