Dieses Rechtsdokument wird derzeit auf Englisch bereitgestellt. Navigation und Website-Steuerung sind zu Ihrer Bequemlichkeit lokalisiert.

Kalima Privacy Policy

Gültig ab: 16. September 2026

This Privacy Policy explains how Kalima handles information when you use the Kalima iOS app, https://kalimaapp.com, cloud services, AI-assisted language and voice features, subscriptions, support channels, and related services. "Kalima," "we," "us," and "our" refer to Kalima's independent operator, who is the controller of personal information handled by Kalima. For privacy questions or requests, contact support@kalimaapp.com.

This Policy should be read together with the Kalima Terms of Service at https://kalimaapp.com/terms.

1. Scope

Kalima is a reading, vocabulary, and language-learning app. The app can import books and documents, extract text from scans and URLs, show public-domain books from Discovery, save vocabulary and study progress, sync eligible data to the cloud, provide subscriptions, and provide AI-assisted language and voice features.

This Policy applies to information handled through the Kalima app, website, cloud services, support, and related services. It does not replace the privacy policies of Apple, Google, Firebase, Inworld, RevenueCat, PostHog, Cloudflare, Gutendex, Project Gutenberg, websites you import from, or other third-party services.

2. Information We Collect

We collect and process information needed to provide, secure, support, and improve Kalima.

Account and authentication information

Kalima requires a real, non-anonymous account for normal app use. When you sign in, we may receive and store:

  • Firebase user ID.
  • Email address.
  • Display name, if provided by your sign-in provider.
  • Sign-in provider information, such as Apple or Google.
  • Account creation and last sign-in timestamps.
  • Authentication tokens needed to keep you signed in and protect cloud services.
  • For Apple-linked accounts, an authorization code, verified identity token, and encrypted refresh credential used to revoke Sign in with Apple authorization during account deletion.

If you use Sign in with Apple or Google Sign-In, those providers process information under their own policies. Google Sign-In may process your Google user identifier and IP address, which may be used to estimate coarse location for fraud prevention, plus device and usage identifiers used for authentication, security, and analytics. Kalima requests no additional Google scopes and does not request or receive your Google-account phone number.

Onboarding, profile, and preferences

Kalima may store information you provide or configure in the app, including:

  • Target or learning language, explanation or native language, writing script, and a temporary proficiency choice during onboarding.
  • Daily reading goal, notification choice and time, active learning space, and onboarding completion state.
  • Reminder settings, notification preferences, reader preferences, voice preferences, appearance settings, and recent Discovery searches.
  • Reading and study activity, including calendar day, time-zone offset, reading, listening, and study duration, and words read.

Library, imported content, and reading activity

When you import or create reading material, Kalima may store:

  • Book and document files.
  • File metadata such as title, author, publisher, language, media type, file size, import date, cover data, and table of contents data.
  • Extracted text, scans, URLs, selected text context, bookmarks, highlights (including saved excerpts), notes, and related metadata.
  • Reading progress, reader location, last opened time, and whether an item is a Quick Read or library book.
  • Public-domain catalog identifiers when imported from Discovery.

Kalima normalizes supported non-EPUB formats to EPUB during import so they can be opened in the reader. Imported content is primarily stored on your device. If cloud sync is available and enabled for your account, book metadata and book files may be stored in Firebase Firestore and Firebase Storage.

Vocabulary and study information

Kalima may store vocabulary and study data, including:

  • Saved words, translations, lemmas, parts of speech, pronunciation, examples, and source context.
  • Source book, title, chapter, language, and related reading metadata.
  • Spaced-repetition scheduling data, review state, due dates, stability, difficulty, repetitions, lapses, and review history.
  • Review events, ratings, timestamps, origin replica identifier, and sync state.

Camera, OCR, microphone, speech, files, and notifications

When you choose these features or grant the relevant iOS permission, Kalima may use:

  • Camera access to capture images for scan import.
  • Apple Vision OCR to extract text from images. Image recognition is intended to run on device, and extracted text can become a saved Quick Read.
  • Microphone access and Apple Speech Recognition for pronunciation practice and transcription.
  • Local notifications for reminders and weekly digests.
  • Remote notifications through Firebase Cloud Messaging for account updates, including an eligible Kalima Pro trial-renewal reminder.
  • The iOS document picker to access only the files you select for import. Kalima does not request general access to your Files library.

If you allow notifications in iOS and are signed in to a Kalima account, Kalima registers that installation with Firebase Cloud Messaging. Google/Firebase processes an APNs token, a Firebase Installation ID (FID), and limited device, app, language, time-zone, and operating-system information needed to address and operate delivery. Kalima associates the FID with your signed-in account, app lane, and enabled notification kinds. Notification payloads use an opaque account-binding value and do not contain your Firebase user ID, FID, product ID, price, or transaction information. Kalima does not use Firebase Messaging or these identifiers for advertising, profiling, or tracking.

Kalima speichert auch deine App-Sprache zusammen mit der Benachrichtigungsregistrierung deines Kontos, um dir Benachrichtigungen in dieser Sprache zu senden. Dieser Wert wird aktualisiert, wenn sich die App erneut verbindet, und unterliegt den Aufbewahrungs- und Löschregeln der Registrierung.

You can control these permissions in iOS Settings. Features that require a permission may not work if that permission is denied, but Kalima does not require unrelated permissions for unrelated features.

URL imports and Discovery

When you import text from a URL, Kalima sends a request to the URL you provide and extracts readable text. The website you choose may receive information such as your IP address, device or network metadata, and the requested URL.

When you search or browse Discovery, Kalima sends your search text, selected filters, sort choice, and page request to discovery.kalimaapp.com. The endpoint's hosting infrastructure receives your IP address and request metadata for delivery and security and may retain operational logs under its configured practices. Discovery responses may include Gutendex and Project Gutenberg catalog or source information. Selecting a result may download files, covers, or metadata from Gutenberg-provided sources.

AI language, translation, and voice features

When you use AI-assisted features, Kalima may process:

  • Selected words, selected text, full sentences, or sentence queues.
  • Source and target language codes.
  • Translation, lookup, pronunciation, or vocabulary prompts and generated responses.
  • Voice ID, language, playback rate, playback mode, request intent, sentence IDs, and related request metadata.
  • Authentication and App Check tokens used to protect the service.

Kalima uses Google AI through Firebase AI for reader translation, definitions, and related language assistance. When you deliberately request one of those features, the selected word or sentence, nearby context, and source and target languages are sent to Google/Firebase to produce the requested result.

Kalima uses Inworld for Kalima Pro text-to-speech. When a Pro user requests playback, Firebase mints a short-lived Inworld authorization token, but speech text, target language, selected Inworld voice and synthesis settings, generated audio, timing data, and related media travel directly between the app and Inworld. Firebase carries no speech media.

As verified on September 4, 2026, Kalima's production Firebase project uses a billing-enabled Gemini Developer API service. Under Google's current terms for paid services, Google states that it does not use prompts or responses to improve its products, although it may log them for a limited period for abuse monitoring, safety, security, or legal purposes. The applicable terms depend on the service configuration in effect when a request is made.

Inworld's current public service-specific terms state that its customer retains rights in inputs and outputs, while granting Inworld rights to use inputs to provide, maintain, develop, improve, secure, and protect its services. Kalima does not have a verified zero-data-retention commitment for the launch workspace. Provider retention and use follow each provider's current workspace settings and applicable terms, including the provider-specific conditions above.

Your subscription tier determines the read-aloud provider. Free users use Apple device text-to-speech. Kalima Pro always uses Inworld for read-aloud. Kalima Pro never falls back to Apple text-to-speech; if Inworld playback fails, Kalima surfaces the failure for retry. Requesting Google-assisted translation or definition separately sends the described text and context to Google/Firebase.

Pronunciation practice separately uses Apple Speech Recognition. Depending on language and device support, Apple may process microphone audio and return a transcript under Apple's terms and privacy policy. Kalima uses the resulting transcript to provide pronunciation feedback; this is separate from Google AI and Inworld read-aloud.

Operational Inworld usage

When a signed-in user generates Inworld speech, Kalima separately reports best-effort account-linked operational Inworld usage to Firebase for reliability and capacity operations. The report contains provider-reported and separately labelled estimated character counts, generation count, an account-scoped installation/replica identifier (AccountReplicaID), phone/tablet/other device class, OS major version, app version, and build number. The replica identifier approximates an app installation but is not guaranteed to represent one physical device. The Firebase user ID is derived from authentication. These reports do not contain reading text, audio, book IDs, voice, language, playback history, PostHog identifiers, Firebase Installation IDs, or email.

The meter counts new Inworld generation, including generated prefetches, retries, and provider-reported partial attempts. It excludes Apple text-to-speech and cached or repeated playback that performs no new generation. The figures are observational rather than billing-grade: they do not enforce a quota, block speech, change entitlement, or drive billing. Occasional loss is possible when the app terminates or remains offline.

Share Analytics controls only optional PostHog product analytics. The account-linked operational Inworld usage meter is independent of PostHog and remains active for signed-in Inworld generation whether Share Analytics is on or off.

Subscription and purchase information

Kalima uses Apple in-app purchases and RevenueCat to manage subscriptions and entitlements. We may receive:

  • RevenueCat app user ID linked to your Kalima account.
  • Product identifiers, entitlement status, purchase state, expiration or renewal information, restore status, and related subscription metadata.

Kalima does not receive your full payment card number from Apple.

Analytics, diagnostics, and security information

Kalima verwendet PostHog Cloud EU für optionale Produktanalysen. Wenn das Teilen von Analysedaten aktiviert ist, werden Aktivitäten angemeldeter Nutzer mit ihrer Firebase-Konto-ID verknüpft. Dadurch können wir Kontoaktivitäten, Conversions und Supportprobleme geräteübergreifend nachvollziehen. Vor der Anmeldung wird ein zufälliger anonymer Bezeichner verwendet; der aktuelle anonyme Nutzungsverlauf kann bei der Anmeldung verknüpft werden. Durch Abmelden oder einen Kontowechsel beginnt ein neuer anonymer Nutzungsverlauf. Beim Aktualisieren von rein installationsbezogenen Analysen wird der bisherige Installationsverlauf nicht automatisch mit deinem Konto verknüpft.

Zulässige Analysedaten umfassen App-Interaktionen, Lernsprache, Mutter- oder Erklärungssprache, Sprache der App-Oberfläche, App-Version und Build, vollständige iOS-Version, Hardwaremodell und Gerätekategorie sowie den beobachteten Abonnementstatus. Ereignisse behalten den Kontext zum Zeitpunkt der Aktivität; Profile zeigen die zuletzt beobachteten Werte, die von verschiedenen Geräten stammen können. Fehlende Ereignisse oder Abonnementbeobachtungen beweisen nicht, dass kein Kauf stattgefunden hat.

Ereignisse durchlaufen analytics.kalimaapp.com, unseren Cloudflare-Proxy. Ein zufälliger Bezeichner für den Erfassungszeitraum ermöglicht es, widerrufene Datenerfassung dauerhaft zurückzuweisen. Cloudflare erhält die für den Proxybetrieb benötigten Netzwerkmetadaten. Die vertrauenswürdige Client-IP wird vorübergehend verwendet, um Analysedaten ausschließlich auf Länderebene abzuleiten; die unverarbeitete IP-Adresse und genauere Standortdaten werden vor der Speicherung verworfen. Wir senden PostHog weder E-Mail-Adressen, Lesetexte, importierte Inhalte, Vokabeltexte, Suchanfragen, URLs, Dateinamen, Buchmetadaten, Transaktions-IDs, Preise, Umsätze noch Stimmenkennungen aus Anbieterkonten. Sprachanalysen können eine stabile ID einer mitgelieferten Stimme enthalten.

Das Teilen von Analysedaten unter Profil > Datenschutz steuert die Erfassung, Identifizierung und Profilaktualisierungen in PostHog. Deine bestehende Einstellung bleibt bei einem App-Update erhalten. Beim Ausschalten wird die Erfassung neuer Daten lokal gestoppt und der aktuelle Erfassungszeitraum am Proxy widerrufen. Schlägt der Widerruf fehl, wird er erneut versucht, während die Erfassung ausgeschaltet bleibt. Beim erneuten Einschalten nach einem Widerruf wird ein neuer Zeitraum verwendet. Das Ausschalten löscht keine früheren Ereignisse. Firebase-Crashlytics-Diagnosen und die kontoverknüpfte betriebliche Inworld-Nutzung bleiben getrennt und werden nicht durch diesen Schalter gesteuert.

Feedback senden bereitet auf deinem Gerät eine E-Mail mit einer Aufforderung zum Verfassen deiner Nachricht und deiner Firebase-Konto-ID als Kontoreferenz vor. Es werden weder eine Analyse-Installations-ID noch ein temporärer Supportcode oder technische Kontextdaten hinzugefügt. Beim Öffnen oder Abbrechen des E-Mail-Entwurfs wird keine Supportreferenz erstellt. Die Kontoreferenz hilft dem Support, dein Konto und verfügbare verknüpfte Analysedaten zu finden, ist aber kein Identitäts- oder Berechtigungsnachweis. Feedback funktioniert auch bei ausgeschalteten Analysen; verknüpfte Analysedaten sind dann möglicherweise nicht verfügbar.

Ältere App-Versionen können weiterhin temporäre Supportreferenzen erstellen, die ein Konto mit einer Analyseinstallation verknüpfen. Diese Referenzen laufen nach 90 Tagen ab, können danach nicht mehr verwendet werden und werden durch asynchrone Bereinigung oder Kontolöschung entfernt. Bestehende Supportcodes und ältere Installationsreferenzen werden für historische Supportanfragen weiterhin akzeptiert; nicht verknüpfte historische Analysedaten lassen sich nicht immer einem Konto zuordnen.

Firebase Crashlytics verarbeitet automatische Absturzberichte und bereinigte benutzerdefinierte Diagnosen nicht schwerwiegender Fehler. Die Dienstdiagnosen von Firebase Messaging bleiben davon getrennt; Kalima enthält kein Google Analytics for Firebase.

Kalima does not use session replay, advertising SDKs, AdMob, IDFA, App Tracking Transparency tracking, cross-app or cross-company tracking, or advertising personalization. Kalima does not send PostHog user-entered content, books, reading text, vocabulary text, URLs, or search queries.

Website information and local storage

When you visit https://kalimaapp.com, Cloudflare may process your IP address, browser and device information, requested pages, timestamps, and security or network metadata to deliver and protect the website and provide aggregate website analytics from request data. Kalima does not load a separate app-owned browser analytics SDK or tracking beacon on the website.

Kalima speichert Ihre Auswahl des hellen oder dunklen Designs und die manuell gewählte Website-Sprache im lokalen Speicher Ihres Browsers. Auf der Hauptstartseite hat die gespeicherte Sprache Vorrang vor den bevorzugten Sprachen Ihres Browsers. The website does not use app-owned advertising cookies, behavioral advertising trackers, or cross-site profiling. Cloudflare may set cookies that are strictly necessary when providing security or service delivery.

Support communications

If you contact us, we may process your email address, message contents, attachments, and other information you choose to provide.

3. How We Use Information

We use information to:

  • Create, authenticate, secure, and manage your account.
  • Provide reading, importing, OCR, vocabulary, study, sync, AI, voice, Discovery, and subscription features.
  • Save your library, reading progress, vocabulary progress, goals, preferences, and reminders.
  • Send optional local and remote notifications and account updates.
  • Keep learning languages and daily goals available across devices for signed-in accounts, and sync eligible content for Kalima Pro accounts.
  • Process purchases, restores, entitlements, and AI voice access.
  • Detect, prevent, and investigate abuse, fraud, service misuse, and security issues.
  • Analyze app reliability, diagnose crashes, improve performance, and understand feature usage.
  • Respond to support requests and legal requests.
  • Comply with legal obligations and enforce our Terms of Service.

Kalima does not use personal information to make decisions that produce legal or similarly significant effects solely through automated processing.

4. Cloud Sync and Storage

Kalima provides always-free account continuity for your learning languages and daily goals. This requires a real non-anonymous account. Kalima Pro separately provides local-first sync for eligible library, vocabulary, review, and reading data.

Account and Pro cloud data are scoped under your Firebase user ID. Pro data may include vocabulary, books, reading progress, bookmarks, highlights (including saved excerpts), notes, sync state, review events, billing state, and uploaded book files. Storage rules are intended to allow only the account owner to access their own files.

If your Kalima Pro entitlement expires, Pro sync access ends. Your former-Pro library, vocabulary, study, and reading data remains eligible for restoration for up to 12 calendar months after the authoritative entitlement expiry and may then be permanently purged. Always-free learning languages, learning-space records, and daily goals remain until you delete the account.

Signing out resets local app data on the device, but it does not delete cloud data. Account deletion is required to delete cloud account data.

5. Sharing and Service Providers

We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.

We share information with service providers only as needed to operate Kalima, provide features, process subscriptions, secure the service, comply with law, or protect rights and safety. Kalima remains responsible for selecting providers and for its own instructions to them and uses contractual and technical controls intended to protect information consistently with this Policy and applicable law.

These providers may include:

  • Apple, for Sign in with Apple, App Store purchases, notification delivery, device permissions, Apple Speech Recognition, Apple Vision, Free-tier device text-to-speech, and iOS services.
  • Google and Firebase, for authentication, Firestore, Storage, Cloud Functions, App Check, Remote Config, Cloud Messaging, Crashlytics, Google Sign-In, and Firebase AI / Google AI.
  • Inworld, for Kalima Pro text-to-speech processing sent directly between the app and Inworld after Firebase mints a short-lived authorization token.
  • PostHog Cloud EU für optionale kontoverknüpfte Produktanalysen, mit einjähriger Ereignisaufbewahrung und automatischer Löschung verknüpfter Profile und Ereignisse bei Kontolöschung.
  • RevenueCat, for subscription products, receipts, customer information, entitlements, restores, and billing state.
  • Cloudflare, for website hosting, security, request delivery, and privacy-focused aggregate website analytics. Cloudflare may process IP address, browser, device, and request metadata under its current terms and retention practices.
  • Kalima's Discovery endpoint, Gutendex, and Project Gutenberg, for public-domain catalog search, request delivery, book download, and related cover or metadata requests.
  • Websites you choose to import from, when you enter a URL for extraction.

We may also disclose information if required by law, to respond to valid legal process, to protect users or the service, or in connection with a merger, acquisition, financing, or sale of assets.

6. AI Processing, Provider Use, and Your Choices

Kalima sends selected words or sentences, nearby context, and language settings to Google/Firebase when you deliberately request Google-assisted translation or definition. Free users use Apple device text-to-speech. Kalima Pro always uses Inworld for read-aloud and sends speech text, target language, selected Inworld voice and synthesis settings directly to Inworld. Kalima Pro never falls back to Apple text-to-speech; if Inworld playback fails, Kalima surfaces the failure for retry.

Kalima does not train its own AI models on your imported reading content and does not use that content for advertising. For the production Gemini service verified as billing-enabled on September 4, 2026, Google's current paid-service terms state that prompts and responses are not used to improve Google products. Google may still retain limited safety and abuse-monitoring logs under those terms.

Inworld's current public terms permit broader use of submitted inputs to provide, maintain, develop, improve, secure, and protect its services. This means provider use can be broader than Kalima's own use. Do not send sensitive, confidential, regulated, or third-party material through an AI or voice feature unless you have the right to submit it and accept the applicable provider processing.

Kalima presents these features when you deliberately request translation, definition, pronunciation, or read-aloud. The current app does not provide a separate provider-specific consent screen before text is sent to Google/Firebase or Inworld.

7. Retention and Deletion

We keep information for as long as needed to provide Kalima, maintain your account, comply with legal obligations, resolve disputes, enforce agreements, prevent abuse, and operate backups and security systems.

Lokale App-Daten bleiben auf deinem Gerät, bis du sie löschst, dich abmeldest, dein Konto löschst, die App deinstallierst oder die reguläre Bereinigung sie entfernt. Geräteweite Einstellungen, letzte Suchanfragen und Darstellungs- oder Leseeinstellungen können nach dem Abmelden erhalten bleiben, bis sie separat durch die App, iOS oder die Deinstallation gelöscht werden. Beim Abmelden beginnt für die Analyseidentität ein neuer anonymer Nutzungsverlauf.

On-device translation and definition results may be cached for up to 30 days in a size-limited 8 MB cache. Complete AI-voice-generated audio and relative timing offsets may be kept in a protected on-device cache limited to 512 MB and 30 days since last access. These AI caches are cleared on account exit or account change and may also be purged when the associated book is deleted or normal limits expire, subject to successful local cleanup.

For normal in-app deletion of books or vocabulary, deleted content and temporary sync-journal records generally expire after about 30 days so deletion can converge across devices. Kalima may keep content-free generation, deletion, or revocation fences for longer, including indefinitely, to prevent deleted data from reappearing, block a deleted account from being recreated by stale work, or enforce an analytics revocation. These records do not contain the deleted book text, vocabulary text, notes, or account content.

When you delete your Kalima account, local app data is removed from that device immediately and active cloud deletion becomes due seven days later. Signing in again during those seven days cancels the scheduled deletion. After the recovery period, Kalima's deletion worker disables access and retries deletion of the RevenueCat customer record, Firebase Auth account, Firestore account data (including operational Inworld usage records), Storage files under your user paths, push registrations, and reminder jobs, and requests deletion of their FIDs from Firebase. For Apple-linked accounts, it also attempts to revoke Sign in with Apple authorization and removes the encrypted revocation credential when deletion finalizes; if automatic revocation cannot be completed, Kalima may instruct you to disconnect Kalima manually in Apple settings.

Deleted Sync V1 Firestore data may remain recoverable in point-in-time recovery for up to seven days and daily backups for up to 30 days. Deleted Sync V1 Storage objects may remain recoverable under a 30-day soft-delete window. Provider logs, security records, tax or transaction records, and other records may remain longer where required or permitted by law.

Deleting your Kalima account does not cancel an Apple App Store subscription. You must cancel or manage subscriptions through Apple App Store settings or Apple's subscription management tools.

Kalima configures PostHog product-analytics events for one-year retention. Firebase Crashlytics diagnostic data is retained under the applicable Firebase configuration and provider terms. Kalima's server-side push registration expires no later than 35 days after its last refresh and is removed earlier when the installation is unregistered, becomes invalid, transfers to another account, or the account is deleted. Google retains a FID until Kalima requests deletion; Google states that data tied to a deleted FID is removed from live and backup systems within 180 days. Anonymous aggregate reports may be retained longer when they do not contain account or installation identifiers.

Account-linked Inworld usage daily totals and installation/replica metadata are retained for 13 months. Short-lived batch receipts used to prevent duplicate counting are retained for seven days. These records are deleted with the account.

Beim Löschen eines Kontos wird automatisch die Entfernung des verknüpften PostHog-Profils und seines Ereignisverlaufs angefordert, einschließlich der mit diesem Profil verknüpften anonymen Aliasse. Kalima blockiert die weitere Datenaufnahme für gelöschte Identitäten, wiederholt fehlgeschlagene Bereinigungen und prüft den Abschluss beim Anbieter, bevor die Analyselöschung als abgeschlossen gilt. Das Löschen von Ereignissen erfolgt asynchron und kann nach der Zugriffssperre noch ausstehen. Historische Ereignisse, die nie mit dem Konto verknüpft waren, erfordern eine verifizierte Supportanfrage über das Altsystem. Inhaltsfreie, schlüsselbasierte Hashwerte gelöschter Analyseidentitäten können unbegrenzt gespeichert werden, damit Ereignisse in der Warteschlange den gelöschten Verlauf nicht erneut erzeugen.

PostHog-Produktanalyseereignisse werden ein Jahr lang aufbewahrt, sofern sie nicht zuvor durch Kontolöschung oder eine entsprechende Löschanfrage entfernt werden. Supportreferenzen aus älteren Versionen laufen nach 90 Tagen ab. Die zuletzt bekannten Eigenschaften des Analyseprofils bleiben bis zur Löschung beim Profil gespeichert. Kontoverknüpfte Analysedaten dienen der Produktanalyse und dem Support, nicht der Werbung, appübergreifendem Tracking oder dem Verkauf personenbezogener Daten.

Ihre Einstellungen für Design und Website-Sprache bleiben im lokalen Browserspeicher, bis Sie sie ändern oder die Website-Daten löschen. Cloudflare request, security, and aggregate analytics data follows Cloudflare's applicable retention settings and terms.

8. Your Choices and Rights

Depending on your location, you may have rights to access, correct, delete, receive a portable copy of, restrict, or object to certain processing of your personal information. You may also have the right to withdraw consent where processing is based on consent, appeal certain privacy decisions, and complain to your local data-protection or privacy authority.

You can:

  • Delete your account in the app.
  • Sign out to reset local account data on the device without deleting cloud data.
  • Delete books, Quick Reads, and vocabulary items in the app.
  • Manage camera, microphone, speech recognition, and notification permissions in iOS Settings, and choose individual files through the document picker.
  • Revoke notification permission in iOS Settings to stop all Kalima notifications. When you return to the app, Kalima checks that permission, cancels local reminders, and unregisters the installation from its push service. Daily Review and Weekly Digest in Profile > Notifications control those individual reminders; their selections and reminder time are preserved if permission changes. Allowing notifications again restores the selected reminders and eligible account updates. Delivery can take a short time to cease while Apple, Firebase, and Kalima process an in-flight unregistration.
  • Choose a device voice while Free or an Inworld voice while subscribed to Kalima Pro; Pro read-aloud never falls back to Apple text-to-speech.
  • Turn Share Analytics off in Profile Privacy to stop and revoke PostHog collection; Crashlytics remains automatic and the account-linked operational Inworld usage meter remains active.
  • Löschen Sie die Einstellungen für Design und Website-Sprache über die Website-Datenverwaltung Ihres Browsers.
  • Cancel or manage subscriptions through Apple App Store settings.

Contact support@kalimaapp.com to request access, correction, deletion, export, or other privacy assistance.

Withdrawing consent does not affect processing that was lawful before withdrawal. We may need to verify your identity before completing a request, and applicable law may allow or require us to retain certain information or decline part of a request. If we deny a request, you may contact us to appeal and may complain to the competent authority where you live.

The Kalima website does not perform app-owned cross-site tracking and Kalima does not knowingly allow other parties to collect personally identifiable information through the website about your activities over time and across unaffiliated websites or services. Because Kalima does not sell or share personal information for cross-context behavioral advertising, browser Do Not Track and Global Privacy Control signals do not change app-owned website behavior. Cloudflare's strictly necessary security and delivery processing may continue.

9. Legal Bases for EEA, UK, and Similar Regions

Where a legal basis is required, the basis depends on the purpose and information involved:

  • Contract: to create and maintain your account; provide importing, reading, vocabulary, sync, AI, voice, support, and subscription features you request; and administer entitlements.
  • Consent: for iOS permissions and optional processing where Kalima asks for consent and applicable law requires it. You may withdraw consent through the app, iOS settings, or by contacting us.
  • Legitimate interests: to secure Kalima, prevent abuse and fraud, diagnose crashes, improve reliability, support capacity operations, understand limited pseudonymous product usage where permitted, and provide support. We consider the necessity and effect on users before relying on this basis.
  • Legal obligations: to comply with applicable tax, accounting, consumer-protection, security, and valid legal-process requirements.

Providing account and feature-request data is necessary to create an account or perform the feature you request. If you do not provide it, the relevant account, sync, AI, voice, or subscription feature may not work. Optional permissions and product analytics are not required for unrelated features.

10. International Transfers

Kalima's controller and service providers may process information outside the country where you live, including in the United States, the European Economic Area, the United Kingdom, and other countries where providers or their subprocessors operate. Those countries may have different privacy laws.

Where transfer restrictions apply, a legally recognized transfer mechanism must be in place before Kalima makes the restricted transfer. Depending on the provider and route, that mechanism may include an adequacy decision, provider data-protection terms, standard contractual clauses, or supplementary technical and organizational measures. Contact support@kalimaapp.com for information about the mechanism used for a particular transfer and, where available, how to obtain a copy.

11. Security

We use reasonable technical and organizational measures designed to protect information, including Firebase security rules, account authentication, App Check, encrypted network transport, and owner-scoped cloud paths. No app, network, or storage system can be guaranteed completely secure.

You are responsible for keeping your device, Apple ID, Google account, and Kalima sign-in method secure.

12. Age Eligibility

Kalima is intended for people age 16 and older. You must also be old enough to use online services in your country. We do not knowingly collect personal information from anyone below the applicable minimum age. If you believe an underage person provided personal information to Kalima, contact us at support@kalimaapp.com.

13. Third-Party Links and Content

Kalima may let you access public-domain catalogs, imported websites, books, documents, and external services. Third-party services and content are governed by their own terms and privacy policies. We are not responsible for third-party privacy practices.

Third-party policies that may apply to related services include:

14. Changes

We may update this Privacy Policy as Kalima, its providers, or legal requirements change. We will post the updated Policy and effective date here. For material changes, we will provide additional notice in the app, by email, or through another appropriate channel before the change takes effect where required by law. You may request information about prior versions by contacting support@kalimaapp.com.

15. Contact

Kalima privacy and support contact: support@kalimaapp.com