Kalima Privacy Policy
시행일: 2026년 9월 16일
This Privacy Policy explains how Kalima handles information when you use the Kalima iOS app, https://kalimaapp.com, cloud services, AI-assisted language and voice features, subscriptions, support channels, and related services. "Kalima," "we," "us," and "our" refer to Kalima's independent operator, who is the controller of personal information handled by Kalima. For privacy questions or requests, contact support@kalimaapp.com.
This Policy should be read together with the Kalima Terms of Service at https://kalimaapp.com/terms.
1. Scope
Kalima is a reading, vocabulary, and language-learning app. The app can import books and documents, extract text from scans and URLs, show public-domain books from Discovery, save vocabulary and study progress, sync eligible data to the cloud, provide subscriptions, and provide AI-assisted language and voice features.
This Policy applies to information handled through the Kalima app, website, cloud services, support, and related services. It does not replace the privacy policies of Apple, Google, Firebase, Inworld, RevenueCat, PostHog, Cloudflare, Gutendex, Project Gutenberg, websites you import from, or other third-party services.
2. Information We Collect
We collect and process information needed to provide, secure, support, and improve Kalima.
Account and authentication information
Kalima requires a real, non-anonymous account for normal app use. When you sign in, we may receive and store:
- Firebase user ID.
- Email address.
- Display name, if provided by your sign-in provider.
- Sign-in provider information, such as Apple or Google.
- Account creation and last sign-in timestamps.
- Authentication tokens needed to keep you signed in and protect cloud services.
- For Apple-linked accounts, an authorization code, verified identity token, and encrypted refresh credential used to revoke Sign in with Apple authorization during account deletion.
If you use Sign in with Apple or Google Sign-In, those providers process information under their own policies. Google Sign-In may process your Google user identifier and IP address, which may be used to estimate coarse location for fraud prevention, plus device and usage identifiers used for authentication, security, and analytics. Kalima requests no additional Google scopes and does not request or receive your Google-account phone number.
Onboarding, profile, and preferences
Kalima may store information you provide or configure in the app, including:
- Target or learning language, explanation or native language, writing script, and a temporary proficiency choice during onboarding.
- Daily reading goal, notification choice and time, active learning space, and onboarding completion state.
- Reminder settings, notification preferences, reader preferences, voice preferences, appearance settings, and recent Discovery searches.
- Reading and study activity, including calendar day, time-zone offset, reading, listening, and study duration, and words read.
Library, imported content, and reading activity
When you import or create reading material, Kalima may store:
- Book and document files.
- File metadata such as title, author, publisher, language, media type, file size, import date, cover data, and table of contents data.
- Extracted text, scans, URLs, selected text context, bookmarks, highlights (including saved excerpts), notes, and related metadata.
- Reading progress, reader location, last opened time, and whether an item is a Quick Read or library book.
- Public-domain catalog identifiers when imported from Discovery.
Kalima normalizes supported non-EPUB formats to EPUB during import so they can be opened in the reader. Imported content is primarily stored on your device. If cloud sync is available and enabled for your account, book metadata and book files may be stored in Firebase Firestore and Firebase Storage.
Vocabulary and study information
Kalima may store vocabulary and study data, including:
- Saved words, translations, lemmas, parts of speech, pronunciation, examples, and source context.
- Source book, title, chapter, language, and related reading metadata.
- Spaced-repetition scheduling data, review state, due dates, stability, difficulty, repetitions, lapses, and review history.
- Review events, ratings, timestamps, origin replica identifier, and sync state.
Camera, OCR, microphone, speech, files, and notifications
When you choose these features or grant the relevant iOS permission, Kalima may use:
- Camera access to capture images for scan import.
- Apple Vision OCR to extract text from images. Image recognition is intended to run on device, and extracted text can become a saved Quick Read.
- Microphone access and Apple Speech Recognition for pronunciation practice and transcription.
- Local notifications for reminders and weekly digests.
- Remote notifications through Firebase Cloud Messaging for account updates, including an eligible Kalima Pro trial-renewal reminder.
- The iOS document picker to access only the files you select for import. Kalima does not request general access to your Files library.
If you allow notifications in iOS and are signed in to a Kalima account, Kalima registers that installation with Firebase Cloud Messaging. Google/Firebase processes an APNs token, a Firebase Installation ID (FID), and limited device, app, language, time-zone, and operating-system information needed to address and operate delivery. Kalima associates the FID with your signed-in account, app lane, and enabled notification kinds. Notification payloads use an opaque account-binding value and do not contain your Firebase user ID, FID, product ID, price, or transaction information. Kalima does not use Firebase Messaging or these identifiers for advertising, profiling, or tracking.
Kalima는 해당 언어로 알림을 보낼 수 있도록 계정의 알림 등록 정보와 함께 앱 언어도 저장합니다. 이 값은 앱이 다시 연결될 때 갱신되며 등록 정보의 보관 및 삭제 규칙을 따릅니다.
You can control these permissions in iOS Settings. Features that require a permission may not work if that permission is denied, but Kalima does not require unrelated permissions for unrelated features.
URL imports and Discovery
When you import text from a URL, Kalima sends a request to the URL you provide and extracts readable text. The website you choose may receive information such as your IP address, device or network metadata, and the requested URL.
When you search or browse Discovery, Kalima sends your search text, selected filters, sort choice, and page request to discovery.kalimaapp.com. The endpoint's hosting infrastructure receives your IP address and request metadata for delivery and security and may retain operational logs under its configured practices. Discovery responses may include Gutendex and Project Gutenberg catalog or source information. Selecting a result may download files, covers, or metadata from Gutenberg-provided sources.
AI language, translation, and voice features
When you use AI-assisted features, Kalima may process:
- Selected words, selected text, full sentences, or sentence queues.
- Source and target language codes.
- Translation, lookup, pronunciation, or vocabulary prompts and generated responses.
- Voice ID, language, playback rate, playback mode, request intent, sentence IDs, and related request metadata.
- Authentication and App Check tokens used to protect the service.
Kalima uses Google AI through Firebase AI for reader translation, definitions, and related language assistance. When you deliberately request one of those features, the selected word or sentence, nearby context, and source and target languages are sent to Google/Firebase to produce the requested result.
Kalima uses Inworld for Kalima Pro text-to-speech. When a Pro user requests playback, Firebase mints a short-lived Inworld authorization token, but speech text, target language, selected Inworld voice and synthesis settings, generated audio, timing data, and related media travel directly between the app and Inworld. Firebase carries no speech media.
As verified on September 4, 2026, Kalima's production Firebase project uses a billing-enabled Gemini Developer API service. Under Google's current terms for paid services, Google states that it does not use prompts or responses to improve its products, although it may log them for a limited period for abuse monitoring, safety, security, or legal purposes. The applicable terms depend on the service configuration in effect when a request is made.
Inworld's current public service-specific terms state that its customer retains rights in inputs and outputs, while granting Inworld rights to use inputs to provide, maintain, develop, improve, secure, and protect its services. Kalima does not have a verified zero-data-retention commitment for the launch workspace. Provider retention and use follow each provider's current workspace settings and applicable terms, including the provider-specific conditions above.
Your subscription tier determines the read-aloud provider. Free users use Apple device text-to-speech. Kalima Pro always uses Inworld for read-aloud. Kalima Pro never falls back to Apple text-to-speech; if Inworld playback fails, Kalima surfaces the failure for retry. Requesting Google-assisted translation or definition separately sends the described text and context to Google/Firebase.
Pronunciation practice separately uses Apple Speech Recognition. Depending on language and device support, Apple may process microphone audio and return a transcript under Apple's terms and privacy policy. Kalima uses the resulting transcript to provide pronunciation feedback; this is separate from Google AI and Inworld read-aloud.
Operational Inworld usage
When a signed-in user generates Inworld speech, Kalima separately reports best-effort account-linked operational Inworld usage to Firebase for reliability and capacity operations. The report contains provider-reported and separately labelled estimated character counts, generation count, an account-scoped installation/replica identifier (AccountReplicaID), phone/tablet/other device class, OS major version, app version, and build number. The replica identifier approximates an app installation but is not guaranteed to represent one physical device. The Firebase user ID is derived from authentication. These reports do not contain reading text, audio, book IDs, voice, language, playback history, PostHog identifiers, Firebase Installation IDs, or email.
The meter counts new Inworld generation, including generated prefetches, retries, and provider-reported partial attempts. It excludes Apple text-to-speech and cached or repeated playback that performs no new generation. The figures are observational rather than billing-grade: they do not enforce a quota, block speech, change entitlement, or drive billing. Occasional loss is possible when the app terminates or remains offline.
Share Analytics controls only optional PostHog product analytics. The account-linked operational Inworld usage meter is independent of PostHog and remains active for signed-in Inworld generation whether Share Analytics is on or off.
Subscription and purchase information
Kalima uses Apple in-app purchases and RevenueCat to manage subscriptions and entitlements. We may receive:
- RevenueCat app user ID linked to your Kalima account.
- Product identifiers, entitlement status, purchase state, expiration or renewal information, restore status, and related subscription metadata.
Kalima does not receive your full payment card number from Apple.
Analytics, diagnostics, and security information
Kalima는 선택적 제품 분석에 PostHog Cloud EU를 사용합니다. 분석 공유를 켜면 로그인 상태의 활동이 Firebase 계정 ID에 연결되어 여러 기기에서의 계정 활동, 전환 및 지원 문제를 파악할 수 있습니다. 로그인 전 활동에는 무작위 익명 식별자가 사용되며, 로그인 시 현재 익명 이용 이력이 연결될 수 있습니다. 로그아웃하거나 계정을 전환하면 새로운 익명 이용 이력이 시작됩니다. 설치 단위 분석에서 업그레이드하더라도 이전 설치 이력이 계정에 자동으로 연결되지는 않습니다.
허용된 분석에는 앱 상호작용, 학습 언어, 모국어 또는 설명 언어, 앱 인터페이스 언어, 앱 버전 및 빌드, 전체 iOS 버전, 하드웨어 모델 및 기기 유형, 관측된 구독 상태가 포함됩니다. 이벤트는 활동 당시의 정보를 유지하며, 프로필에는 마지막으로 관측된 값이 표시됩니다. 이 값들은 서로 다른 기기에서 수집되었을 수 있습니다. 이벤트나 구독 관측 정보가 없다고 해서 구매가 이루어지지 않았다는 뜻은 아닙니다.
이벤트는 당사의 Cloudflare 프록시인 analytics.kalimaapp.com을 통과합니다. 무작위 수집 에포크를 통해 동의가 철회된 수집을 지속적으로 거부할 수 있습니다. Cloudflare는 프록시 운영에 필요한 네트워크 메타데이터를 받습니다. 신뢰할 수 있는 클라이언트 IP는 국가 단위의 분석만 도출하는 데 일시적으로 사용되며, 원시 IP와 더 자세한 위치 정보는 저장 전에 폐기됩니다. 이메일, 읽는 텍스트, 가져온 콘텐츠, 어휘 텍스트, 검색어, URL, 파일명, 도서 메타데이터, 거래 ID, 가격, 매출 또는 제공업체 계정의 음성 식별자는 PostHog에 전송하지 않습니다. 음성 분석에는 앱에 포함된 음성의 고정 ID가 포함될 수 있습니다.
프로필 > 개인정보 보호의 분석 공유는 PostHog 수집, 식별 및 프로필 업데이트를 제어합니다. 앱을 업데이트해도 기존 공유 설정은 유지됩니다. 끄면 기기에서 새로운 기록이 중단되고 프록시에서 현재 수집 에포크가 취소됩니다. 취소에 실패하면 수집이 비활성화된 상태에서 재시도합니다. 취소 후 다시 켜면 새로운 에포크를 사용합니다. 공유를 꺼도 이전 이벤트가 삭제되지는 않습니다. Firebase Crashlytics 진단과 계정에 연결된 운영 목적의 Inworld 사용 정보는 별도이며, 이 스위치의 제어를 받지 않습니다.
피드백 보내기는 작성 안내 문구와 계정 참조용 Firebase 계정 ID가 포함된 이메일을 기기에서 준비합니다. 분석 설치 ID, 임시 지원 코드 또는 기술 정보는 추가하지 않습니다. 작성 화면을 열거나 취소할 때 지원 참조 정보는 생성되지 않습니다. 계정 참조 정보는 지원팀이 계정과 사용 가능한 연결 분석을 찾는 데 도움이 되지만, 신원이나 권한의 증거는 아닙니다. 분석을 비활성화해도 피드백은 이용할 수 있으나, 이 경우 연결된 분석이 없을 수 있습니다.
이전 앱 버전에서는 계정과 분석 설치를 연결하는 임시 지원 참조 정보가 생성될 수 있습니다. 이 참조 정보는 90일 후 만료되며, 만료 후에는 사용할 수 없고 비동기 정리 또는 계정 삭제를 통해 제거됩니다. 과거 지원 요청에는 기존 지원 코드와 이전 설치 참조 정보가 계속 허용됩니다. 연결되지 않은 과거 분석을 항상 특정 계정에 귀속시킬 수 있는 것은 아닙니다.
Firebase Crashlytics는 자동 비정상 종료 보고서와 민감한 정보를 제거한 맞춤형 비치명적 진단 정보를 처리합니다. Firebase Messaging 서비스 진단은 별도로 유지되며, Kalima에는 Google Analytics for Firebase가 포함되어 있지 않습니다.
Kalima does not use session replay, advertising SDKs, AdMob, IDFA, App Tracking Transparency tracking, cross-app or cross-company tracking, or advertising personalization. Kalima does not send PostHog user-entered content, books, reading text, vocabulary text, URLs, or search queries.
Website information and local storage
When you visit https://kalimaapp.com, Cloudflare may process your IP address, browser and device information, requested pages, timestamps, and security or network metadata to deliver and protect the website and provide aggregate website analytics from request data. Kalima does not load a separate app-owned browser analytics SDK or tracking beacon on the website.
Kalima는 밝은 테마 또는 어두운 테마 설정과 직접 선택한 웹사이트 언어를 브라우저의 로컬 저장소에 저장합니다. 기본 홈페이지에서는 저장된 언어가 브라우저의 선호 언어보다 우선합니다. The website does not use app-owned advertising cookies, behavioral advertising trackers, or cross-site profiling. Cloudflare may set cookies that are strictly necessary when providing security or service delivery.
Support communications
If you contact us, we may process your email address, message contents, attachments, and other information you choose to provide.
3. How We Use Information
We use information to:
- Create, authenticate, secure, and manage your account.
- Provide reading, importing, OCR, vocabulary, study, sync, AI, voice, Discovery, and subscription features.
- Save your library, reading progress, vocabulary progress, goals, preferences, and reminders.
- Send optional local and remote notifications and account updates.
- Keep learning languages and daily goals available across devices for signed-in accounts, and sync eligible content for Kalima Pro accounts.
- Process purchases, restores, entitlements, and AI voice access.
- Detect, prevent, and investigate abuse, fraud, service misuse, and security issues.
- Analyze app reliability, diagnose crashes, improve performance, and understand feature usage.
- Respond to support requests and legal requests.
- Comply with legal obligations and enforce our Terms of Service.
Kalima does not use personal information to make decisions that produce legal or similarly significant effects solely through automated processing.
4. Cloud Sync and Storage
Kalima provides always-free account continuity for your learning languages and daily goals. This requires a real non-anonymous account. Kalima Pro separately provides local-first sync for eligible library, vocabulary, review, and reading data.
Account and Pro cloud data are scoped under your Firebase user ID. Pro data may include vocabulary, books, reading progress, bookmarks, highlights (including saved excerpts), notes, sync state, review events, billing state, and uploaded book files. Storage rules are intended to allow only the account owner to access their own files.
If your Kalima Pro entitlement expires, Pro sync access ends. Your former-Pro library, vocabulary, study, and reading data remains eligible for restoration for up to 12 calendar months after the authoritative entitlement expiry and may then be permanently purged. Always-free learning languages, learning-space records, and daily goals remain until you delete the account.
Signing out resets local app data on the device, but it does not delete cloud data. Account deletion is required to delete cloud account data.
5. Sharing and Service Providers
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
We share information with service providers only as needed to operate Kalima, provide features, process subscriptions, secure the service, comply with law, or protect rights and safety. Kalima remains responsible for selecting providers and for its own instructions to them and uses contractual and technical controls intended to protect information consistently with this Policy and applicable law.
These providers may include:
- Apple, for Sign in with Apple, App Store purchases, notification delivery, device permissions, Apple Speech Recognition, Apple Vision, Free-tier device text-to-speech, and iOS services.
- Google and Firebase, for authentication, Firestore, Storage, Cloud Functions, App Check, Remote Config, Cloud Messaging, Crashlytics, Google Sign-In, and Firebase AI / Google AI.
- Inworld, for Kalima Pro text-to-speech processing sent directly between the app and Inworld after Firebase mints a short-lived authorization token.
- PostHog Cloud EU: 선택적 계정 연계 제품 분석에 사용되며, 이벤트는 1년간 보관하고 계정 삭제 시 연결된 프로필과 이벤트를 자동으로 삭제합니다.
- RevenueCat, for subscription products, receipts, customer information, entitlements, restores, and billing state.
- Cloudflare, for website hosting, security, request delivery, and privacy-focused aggregate website analytics. Cloudflare may process IP address, browser, device, and request metadata under its current terms and retention practices.
- Kalima's Discovery endpoint, Gutendex, and Project Gutenberg, for public-domain catalog search, request delivery, book download, and related cover or metadata requests.
- Websites you choose to import from, when you enter a URL for extraction.
We may also disclose information if required by law, to respond to valid legal process, to protect users or the service, or in connection with a merger, acquisition, financing, or sale of assets.
6. AI Processing, Provider Use, and Your Choices
Kalima sends selected words or sentences, nearby context, and language settings to Google/Firebase when you deliberately request Google-assisted translation or definition. Free users use Apple device text-to-speech. Kalima Pro always uses Inworld for read-aloud and sends speech text, target language, selected Inworld voice and synthesis settings directly to Inworld. Kalima Pro never falls back to Apple text-to-speech; if Inworld playback fails, Kalima surfaces the failure for retry.
Kalima does not train its own AI models on your imported reading content and does not use that content for advertising. For the production Gemini service verified as billing-enabled on September 4, 2026, Google's current paid-service terms state that prompts and responses are not used to improve Google products. Google may still retain limited safety and abuse-monitoring logs under those terms.
Inworld's current public terms permit broader use of submitted inputs to provide, maintain, develop, improve, secure, and protect its services. This means provider use can be broader than Kalima's own use. Do not send sensitive, confidential, regulated, or third-party material through an AI or voice feature unless you have the right to submit it and accept the applicable provider processing.
Kalima presents these features when you deliberately request translation, definition, pronunciation, or read-aloud. The current app does not provide a separate provider-specific consent screen before text is sent to Google/Firebase or Inworld.
7. Retention and Deletion
We keep information for as long as needed to provide Kalima, maintain your account, comply with legal obligations, resolve disputes, enforce agreements, prevent abuse, and operate backups and security systems.
로컬 앱 데이터는 직접 삭제하거나, 로그아웃하거나, 계정을 삭제하거나, 앱을 제거하거나, 일반적인 정리로 삭제될 때까지 기기에 남아 있습니다. 기기 전체 설정, 최근 검색, 화면 표시 또는 리더 설정은 로그아웃 후에도 앱, iOS 또는 앱 제거를 통해 별도로 지워질 때까지 남아 있을 수 있습니다. 로그아웃하면 분석 식별자는 새로운 익명 이용 이력을 시작합니다.
On-device translation and definition results may be cached for up to 30 days in a size-limited 8 MB cache. Complete AI-voice-generated audio and relative timing offsets may be kept in a protected on-device cache limited to 512 MB and 30 days since last access. These AI caches are cleared on account exit or account change and may also be purged when the associated book is deleted or normal limits expire, subject to successful local cleanup.
For normal in-app deletion of books or vocabulary, deleted content and temporary sync-journal records generally expire after about 30 days so deletion can converge across devices. Kalima may keep content-free generation, deletion, or revocation fences for longer, including indefinitely, to prevent deleted data from reappearing, block a deleted account from being recreated by stale work, or enforce an analytics revocation. These records do not contain the deleted book text, vocabulary text, notes, or account content.
When you delete your Kalima account, local app data is removed from that device immediately and active cloud deletion becomes due seven days later. Signing in again during those seven days cancels the scheduled deletion. After the recovery period, Kalima's deletion worker disables access and retries deletion of the RevenueCat customer record, Firebase Auth account, Firestore account data (including operational Inworld usage records), Storage files under your user paths, push registrations, and reminder jobs, and requests deletion of their FIDs from Firebase. For Apple-linked accounts, it also attempts to revoke Sign in with Apple authorization and removes the encrypted revocation credential when deletion finalizes; if automatic revocation cannot be completed, Kalima may instruct you to disconnect Kalima manually in Apple settings.
Deleted Sync V1 Firestore data may remain recoverable in point-in-time recovery for up to seven days and daily backups for up to 30 days. Deleted Sync V1 Storage objects may remain recoverable under a 30-day soft-delete window. Provider logs, security records, tax or transaction records, and other records may remain longer where required or permitted by law.
Deleting your Kalima account does not cancel an Apple App Store subscription. You must cancel or manage subscriptions through Apple App Store settings or Apple's subscription management tools.
Kalima configures PostHog product-analytics events for one-year retention. Firebase Crashlytics diagnostic data is retained under the applicable Firebase configuration and provider terms. Kalima's server-side push registration expires no later than 35 days after its last refresh and is removed earlier when the installation is unregistered, becomes invalid, transfers to another account, or the account is deleted. Google retains a FID until Kalima requests deletion; Google states that data tied to a deleted FID is removed from live and backup systems within 180 days. Anonymous aggregate reports may be retained longer when they do not contain account or installation identifiers.
Account-linked Inworld usage daily totals and installation/replica metadata are retained for 13 months. Short-lived batch receipts used to prevent duplicate counting are retained for seven days. These records are deleted with the account.
계정 삭제 시 연결된 PostHog 프로필과 이벤트 이력의 삭제가 자동으로 요청되며, 해당 프로필에 연결된 익명 별칭도 포함됩니다. Kalima는 삭제된 식별자에 대한 추가 데이터 수집을 차단하고, 정리에 실패하면 재시도하며, 제공업체의 완료 여부를 확인한 후 분석 삭제가 완료된 것으로 처리합니다. 이벤트 삭제는 비동기적으로 진행되므로 접근이 차단된 후에도 대기 상태일 수 있습니다. 계정에 연결된 적이 없는 과거 이벤트에는 확인된 기존 방식의 지원 요청이 필요합니다. 대기 중인 이벤트가 삭제된 이력을 다시 생성하지 못하도록, 콘텐츠를 포함하지 않는 삭제된 분석 식별자의 키 기반 해시를 무기한 보관할 수 있습니다.
PostHog 제품 분석 이벤트는 계정 삭제 또는 적용 가능한 삭제 요청으로 더 일찍 삭제되지 않는 한 1년간 보관됩니다. 이전 버전의 지원 참조 정보는 90일 후 만료됩니다. 마지막으로 확인된 분석 프로필 속성은 프로필 삭제 시까지 프로필과 함께 보관됩니다. 계정에 연결된 분석은 제품 분석과 지원에 사용되며, 광고, 앱 간 추적 또는 개인정보 판매에 사용되지 않습니다.
웹사이트 테마 및 언어 설정은 변경하거나 사이트 데이터를 삭제할 때까지 브라우저의 로컬 저장소에 유지됩니다. Cloudflare request, security, and aggregate analytics data follows Cloudflare's applicable retention settings and terms.
8. Your Choices and Rights
Depending on your location, you may have rights to access, correct, delete, receive a portable copy of, restrict, or object to certain processing of your personal information. You may also have the right to withdraw consent where processing is based on consent, appeal certain privacy decisions, and complain to your local data-protection or privacy authority.
You can:
- Delete your account in the app.
- Sign out to reset local account data on the device without deleting cloud data.
- Delete books, Quick Reads, and vocabulary items in the app.
- Manage camera, microphone, speech recognition, and notification permissions in iOS Settings, and choose individual files through the document picker.
- Revoke notification permission in iOS Settings to stop all Kalima notifications. When you return to the app, Kalima checks that permission, cancels local reminders, and unregisters the installation from its push service. Daily Review and Weekly Digest in Profile > Notifications control those individual reminders; their selections and reminder time are preserved if permission changes. Allowing notifications again restores the selected reminders and eligible account updates. Delivery can take a short time to cease while Apple, Firebase, and Kalima process an in-flight unregistration.
- Choose a device voice while Free or an Inworld voice while subscribed to Kalima Pro; Pro read-aloud never falls back to Apple text-to-speech.
- Turn Share Analytics off in Profile Privacy to stop and revoke PostHog collection; Crashlytics remains automatic and the account-linked operational Inworld usage meter remains active.
- 브라우저의 사이트 데이터 관리 기능에서 웹사이트 테마 및 언어 설정을 삭제할 수 있습니다.
- Cancel or manage subscriptions through Apple App Store settings.
Contact support@kalimaapp.com to request access, correction, deletion, export, or other privacy assistance.
Withdrawing consent does not affect processing that was lawful before withdrawal. We may need to verify your identity before completing a request, and applicable law may allow or require us to retain certain information or decline part of a request. If we deny a request, you may contact us to appeal and may complain to the competent authority where you live.
The Kalima website does not perform app-owned cross-site tracking and Kalima does not knowingly allow other parties to collect personally identifiable information through the website about your activities over time and across unaffiliated websites or services. Because Kalima does not sell or share personal information for cross-context behavioral advertising, browser Do Not Track and Global Privacy Control signals do not change app-owned website behavior. Cloudflare's strictly necessary security and delivery processing may continue.
9. Legal Bases for EEA, UK, and Similar Regions
Where a legal basis is required, the basis depends on the purpose and information involved:
- Contract: to create and maintain your account; provide importing, reading, vocabulary, sync, AI, voice, support, and subscription features you request; and administer entitlements.
- Consent: for iOS permissions and optional processing where Kalima asks for consent and applicable law requires it. You may withdraw consent through the app, iOS settings, or by contacting us.
- Legitimate interests: to secure Kalima, prevent abuse and fraud, diagnose crashes, improve reliability, support capacity operations, understand limited pseudonymous product usage where permitted, and provide support. We consider the necessity and effect on users before relying on this basis.
- Legal obligations: to comply with applicable tax, accounting, consumer-protection, security, and valid legal-process requirements.
Providing account and feature-request data is necessary to create an account or perform the feature you request. If you do not provide it, the relevant account, sync, AI, voice, or subscription feature may not work. Optional permissions and product analytics are not required for unrelated features.
10. International Transfers
Kalima's controller and service providers may process information outside the country where you live, including in the United States, the European Economic Area, the United Kingdom, and other countries where providers or their subprocessors operate. Those countries may have different privacy laws.
Where transfer restrictions apply, a legally recognized transfer mechanism must be in place before Kalima makes the restricted transfer. Depending on the provider and route, that mechanism may include an adequacy decision, provider data-protection terms, standard contractual clauses, or supplementary technical and organizational measures. Contact support@kalimaapp.com for information about the mechanism used for a particular transfer and, where available, how to obtain a copy.
11. Security
We use reasonable technical and organizational measures designed to protect information, including Firebase security rules, account authentication, App Check, encrypted network transport, and owner-scoped cloud paths. No app, network, or storage system can be guaranteed completely secure.
You are responsible for keeping your device, Apple ID, Google account, and Kalima sign-in method secure.
12. Age Eligibility
Kalima is intended for people age 16 and older. You must also be old enough to use online services in your country. We do not knowingly collect personal information from anyone below the applicable minimum age. If you believe an underage person provided personal information to Kalima, contact us at support@kalimaapp.com.
13. Third-Party Links and Content
Kalima may let you access public-domain catalogs, imported websites, books, documents, and external services. Third-party services and content are governed by their own terms and privacy policies. We are not responsible for third-party privacy practices.
Third-party policies that may apply to related services include:
- Apple Privacy Policy: https://www.apple.com/legal/privacy/
- Google Privacy Policy: https://policies.google.com/privacy
- Firebase Privacy and Security: https://firebase.google.com/support/privacy
- Gemini API Additional Terms: https://ai.google.dev/gemini-api/terms
- Inworld Privacy Policy: https://inworld.ai/privacy
- Inworld Service-Specific Terms: https://inworld.ai/service-specific-terms
- PostHog Privacy Policy: https://posthog.com/privacy
- RevenueCat Privacy Policy: https://www.revenuecat.com/privacy/
- Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy/
- Project Gutenberg Privacy Policy: https://www.gutenberg.org/policy/privacy_policy.html
14. Changes
We may update this Privacy Policy as Kalima, its providers, or legal requirements change. We will post the updated Policy and effective date here. For material changes, we will provide additional notice in the app, by email, or through another appropriate channel before the change takes effect where required by law. You may request information about prior versions by contacting support@kalimaapp.com.
15. Contact
Kalima privacy and support contact: support@kalimaapp.com