此法律文件目前以英文提供。导航和站点控件已本地化,方便你使用。

Kalima Privacy Policy

生效日期:2026 年 9 月 16 日

This Privacy Policy explains how Kalima handles information when you use the Kalima iOS app, https://kalimaapp.com, cloud services, AI-assisted language and voice features, subscriptions, support channels, and related services. "Kalima," "we," "us," and "our" refer to Kalima's independent operator, who is the controller of personal information handled by Kalima. For privacy questions or requests, contact support@kalimaapp.com.

This Policy should be read together with the Kalima Terms of Service at https://kalimaapp.com/terms.

1. Scope

Kalima is a reading, vocabulary, and language-learning app. The app can import books and documents, extract text from scans and URLs, show public-domain books from Discovery, save vocabulary and study progress, sync eligible data to the cloud, provide subscriptions, and provide AI-assisted language and voice features.

This Policy applies to information handled through the Kalima app, website, cloud services, support, and related services. It does not replace the privacy policies of Apple, Google, Firebase, Inworld, RevenueCat, PostHog, Cloudflare, Gutendex, Project Gutenberg, websites you import from, or other third-party services.

2. Information We Collect

We collect and process information needed to provide, secure, support, and improve Kalima.

Account and authentication information

Kalima requires a real, non-anonymous account for normal app use. When you sign in, we may receive and store:

  • Firebase user ID.
  • Email address.
  • Display name, if provided by your sign-in provider.
  • Sign-in provider information, such as Apple or Google.
  • Account creation and last sign-in timestamps.
  • Authentication tokens needed to keep you signed in and protect cloud services.
  • For Apple-linked accounts, an authorization code, verified identity token, and encrypted refresh credential used to revoke Sign in with Apple authorization during account deletion.

If you use Sign in with Apple or Google Sign-In, those providers process information under their own policies. Google Sign-In may process your Google user identifier and IP address, which may be used to estimate coarse location for fraud prevention, plus device and usage identifiers used for authentication, security, and analytics. Kalima requests no additional Google scopes and does not request or receive your Google-account phone number.

Onboarding, profile, and preferences

Kalima may store information you provide or configure in the app, including:

  • Target or learning language, explanation or native language, writing script, and a temporary proficiency choice during onboarding.
  • Daily reading goal, notification choice and time, active learning space, and onboarding completion state.
  • Reminder settings, notification preferences, reader preferences, voice preferences, appearance settings, and recent Discovery searches.
  • Reading and study activity, including calendar day, time-zone offset, reading, listening, and study duration, and words read.

Library, imported content, and reading activity

When you import or create reading material, Kalima may store:

  • Book and document files.
  • File metadata such as title, author, publisher, language, media type, file size, import date, cover data, and table of contents data.
  • Extracted text, scans, URLs, selected text context, bookmarks, highlights (including saved excerpts), notes, and related metadata.
  • Reading progress, reader location, last opened time, and whether an item is a Quick Read or library book.
  • Public-domain catalog identifiers when imported from Discovery.

Kalima normalizes supported non-EPUB formats to EPUB during import so they can be opened in the reader. Imported content is primarily stored on your device. If cloud sync is available and enabled for your account, book metadata and book files may be stored in Firebase Firestore and Firebase Storage.

Vocabulary and study information

Kalima may store vocabulary and study data, including:

  • Saved words, translations, lemmas, parts of speech, pronunciation, examples, and source context.
  • Source book, title, chapter, language, and related reading metadata.
  • Spaced-repetition scheduling data, review state, due dates, stability, difficulty, repetitions, lapses, and review history.
  • Review events, ratings, timestamps, origin replica identifier, and sync state.

Camera, OCR, microphone, speech, files, and notifications

When you choose these features or grant the relevant iOS permission, Kalima may use:

  • Camera access to capture images for scan import.
  • Apple Vision OCR to extract text from images. Image recognition is intended to run on device, and extracted text can become a saved Quick Read.
  • Microphone access and Apple Speech Recognition for pronunciation practice and transcription.
  • Local notifications for reminders and weekly digests.
  • Remote notifications through Firebase Cloud Messaging for account updates, including an eligible Kalima Pro trial-renewal reminder.
  • The iOS document picker to access only the files you select for import. Kalima does not request general access to your Files library.

If you allow notifications in iOS and are signed in to a Kalima account, Kalima registers that installation with Firebase Cloud Messaging. Google/Firebase processes an APNs token, a Firebase Installation ID (FID), and limited device, app, language, time-zone, and operating-system information needed to address and operate delivery. Kalima associates the FID with your signed-in account, app lane, and enabled notification kinds. Notification payloads use an opaque account-binding value and do not contain your Firebase user ID, FID, product ID, price, or transaction information. Kalima does not use Firebase Messaging or these identifiers for advertising, profiling, or tracking.

Kalima 还会将您的应用语言与您账户的通知注册信息一起存储,以便使用该语言发送通知。此值会在应用重新连接时更新,并遵循注册信息的保留和删除规则。

You can control these permissions in iOS Settings. Features that require a permission may not work if that permission is denied, but Kalima does not require unrelated permissions for unrelated features.

URL imports and Discovery

When you import text from a URL, Kalima sends a request to the URL you provide and extracts readable text. The website you choose may receive information such as your IP address, device or network metadata, and the requested URL.

When you search or browse Discovery, Kalima sends your search text, selected filters, sort choice, and page request to discovery.kalimaapp.com. The endpoint's hosting infrastructure receives your IP address and request metadata for delivery and security and may retain operational logs under its configured practices. Discovery responses may include Gutendex and Project Gutenberg catalog or source information. Selecting a result may download files, covers, or metadata from Gutenberg-provided sources.

AI language, translation, and voice features

When you use AI-assisted features, Kalima may process:

  • Selected words, selected text, full sentences, or sentence queues.
  • Source and target language codes.
  • Translation, lookup, pronunciation, or vocabulary prompts and generated responses.
  • Voice ID, language, playback rate, playback mode, request intent, sentence IDs, and related request metadata.
  • Authentication and App Check tokens used to protect the service.

Kalima uses Google AI through Firebase AI for reader translation, definitions, and related language assistance. When you deliberately request one of those features, the selected word or sentence, nearby context, and source and target languages are sent to Google/Firebase to produce the requested result.

Kalima uses Inworld for Kalima Pro text-to-speech. When a Pro user requests playback, Firebase mints a short-lived Inworld authorization token, but speech text, target language, selected Inworld voice and synthesis settings, generated audio, timing data, and related media travel directly between the app and Inworld. Firebase carries no speech media.

As verified on September 4, 2026, Kalima's production Firebase project uses a billing-enabled Gemini Developer API service. Under Google's current terms for paid services, Google states that it does not use prompts or responses to improve its products, although it may log them for a limited period for abuse monitoring, safety, security, or legal purposes. The applicable terms depend on the service configuration in effect when a request is made.

Inworld's current public service-specific terms state that its customer retains rights in inputs and outputs, while granting Inworld rights to use inputs to provide, maintain, develop, improve, secure, and protect its services. Kalima does not have a verified zero-data-retention commitment for the launch workspace. Provider retention and use follow each provider's current workspace settings and applicable terms, including the provider-specific conditions above.

Your subscription tier determines the read-aloud provider. Free users use Apple device text-to-speech. Kalima Pro always uses Inworld for read-aloud. Kalima Pro never falls back to Apple text-to-speech; if Inworld playback fails, Kalima surfaces the failure for retry. Requesting Google-assisted translation or definition separately sends the described text and context to Google/Firebase.

Pronunciation practice separately uses Apple Speech Recognition. Depending on language and device support, Apple may process microphone audio and return a transcript under Apple's terms and privacy policy. Kalima uses the resulting transcript to provide pronunciation feedback; this is separate from Google AI and Inworld read-aloud.

Operational Inworld usage

When a signed-in user generates Inworld speech, Kalima separately reports best-effort account-linked operational Inworld usage to Firebase for reliability and capacity operations. The report contains provider-reported and separately labelled estimated character counts, generation count, an account-scoped installation/replica identifier (AccountReplicaID), phone/tablet/other device class, OS major version, app version, and build number. The replica identifier approximates an app installation but is not guaranteed to represent one physical device. The Firebase user ID is derived from authentication. These reports do not contain reading text, audio, book IDs, voice, language, playback history, PostHog identifiers, Firebase Installation IDs, or email.

The meter counts new Inworld generation, including generated prefetches, retries, and provider-reported partial attempts. It excludes Apple text-to-speech and cached or repeated playback that performs no new generation. The figures are observational rather than billing-grade: they do not enforce a quota, block speech, change entitlement, or drive billing. Occasional loss is possible when the app terminates or remains offline.

Share Analytics controls only optional PostHog product analytics. The account-linked operational Inworld usage meter is independent of PostHog and remains active for signed-in Inworld generation whether Share Analytics is on or off.

Subscription and purchase information

Kalima uses Apple in-app purchases and RevenueCat to manage subscriptions and entitlements. We may receive:

  • RevenueCat app user ID linked to your Kalima account.
  • Product identifiers, entitlement status, purchase state, expiration or renewal information, restore status, and related subscription metadata.

Kalima does not receive your full payment card number from Apple.

Analytics, diagnostics, and security information

Kalima 使用 PostHog Cloud EU 提供可选的产品分析。开启“共享分析数据”后,登录状态下的活动会关联到您的 Firebase 账号 ID,以帮助我们了解跨设备的账号活动、转化情况和支持问题。登录前的活动使用随机匿名标识符;登录时,当前的匿名使用历程可能会与账号关联。退出登录或切换账号会开始新的匿名使用历程。从仅按安装标识进行分析的版本升级时,旧安装的历史记录不会自动关联到您的账号。

获准收集的分析数据包括应用交互、学习语言、母语或解释语言、应用界面语言、应用版本和构建版本、完整的 iOS 版本、硬件型号和设备类别,以及观测到的订阅状态。事件保留活动发生时的上下文;用户档案显示最近观测到的值,这些值可能来自不同设备。缺少事件或订阅观测记录并不能证明未发生购买。

事件通过我们的 Cloudflare 代理 analytics.kalimaapp.com 传输。随机的收集周期标识可持续拒绝已撤回同意的数据收集。Cloudflare 会接收运行代理所需的网络元数据。其可信客户端 IP 仅被临时用于生成国家级别的分析信息;原始 IP 和更详细的位置数据会在存储前丢弃。我们不会向 PostHog 发送电子邮件地址、阅读文本、导入的内容、词汇文本、搜索词、URL、文件名、图书元数据、交易 ID、价格、收入或提供商账号的语音标识符。语音分析可能包含应用内置语音的固定 ID。

“个人资料”>“隐私”中的“共享分析数据”控制 PostHog 的数据收集、身份关联和用户档案更新。更新应用时会保留现有的共享偏好。关闭此选项会停止在本地记录新数据,并在代理端撤销当前收集周期;如撤销失败,将在保持收集关闭的状态下重试。撤销后重新开启时会使用新的收集周期。关闭共享不会删除以前的事件。Firebase Crashlytics 诊断和与账号关联的运营用途 Inworld 使用数据保持独立,不受此开关控制。

“发送反馈”会在您的设备上准备一封电子邮件,其中包含填写提示,以及作为账号参考信息的 Firebase 账号 ID。邮件不会添加分析安装 ID、临时支持代码或技术背景信息。打开或取消邮件编辑界面时,不会创建支持参考记录。账号参考信息有助于支持团队找到您的账号及可用的关联分析数据,但不能作为身份或授权的证明。即使分析已关闭,反馈功能仍然可用;此时可能没有可用的关联分析数据。

旧版应用可能仍会创建临时支持参考记录,将账号与分析安装标识关联。这些参考记录在 90 天后过期,过期后无法使用,并会通过异步清理或账号删除予以移除。对于历史支持请求,我们仍接受现有的支持代码和旧安装参考信息;未关联的历史分析数据并非始终都能归属于某个账号。

Firebase Crashlytics 处理自动崩溃报告以及经过敏感信息清理的自定义非致命诊断信息。Firebase Messaging 服务诊断保持独立;Kalima 不包含 Google Analytics for Firebase。

Kalima does not use session replay, advertising SDKs, AdMob, IDFA, App Tracking Transparency tracking, cross-app or cross-company tracking, or advertising personalization. Kalima does not send PostHog user-entered content, books, reading text, vocabulary text, URLs, or search queries.

Website information and local storage

When you visit https://kalimaapp.com, Cloudflare may process your IP address, browser and device information, requested pages, timestamps, and security or network metadata to deliver and protect the website and provide aggregate website analytics from request data. Kalima does not load a separate app-owned browser analytics SDK or tracking beacon on the website.

Kalima会将您选择的浅色或深色主题以及手动选择的网站语言保存在浏览器的本地存储中。在主首页上,已保存的语言优先于浏览器的首选语言。 The website does not use app-owned advertising cookies, behavioral advertising trackers, or cross-site profiling. Cloudflare may set cookies that are strictly necessary when providing security or service delivery.

Support communications

If you contact us, we may process your email address, message contents, attachments, and other information you choose to provide.

3. How We Use Information

We use information to:

  • Create, authenticate, secure, and manage your account.
  • Provide reading, importing, OCR, vocabulary, study, sync, AI, voice, Discovery, and subscription features.
  • Save your library, reading progress, vocabulary progress, goals, preferences, and reminders.
  • Send optional local and remote notifications and account updates.
  • Keep learning languages and daily goals available across devices for signed-in accounts, and sync eligible content for Kalima Pro accounts.
  • Process purchases, restores, entitlements, and AI voice access.
  • Detect, prevent, and investigate abuse, fraud, service misuse, and security issues.
  • Analyze app reliability, diagnose crashes, improve performance, and understand feature usage.
  • Respond to support requests and legal requests.
  • Comply with legal obligations and enforce our Terms of Service.

Kalima does not use personal information to make decisions that produce legal or similarly significant effects solely through automated processing.

4. Cloud Sync and Storage

Kalima provides always-free account continuity for your learning languages and daily goals. This requires a real non-anonymous account. Kalima Pro separately provides local-first sync for eligible library, vocabulary, review, and reading data.

Account and Pro cloud data are scoped under your Firebase user ID. Pro data may include vocabulary, books, reading progress, bookmarks, highlights (including saved excerpts), notes, sync state, review events, billing state, and uploaded book files. Storage rules are intended to allow only the account owner to access their own files.

If your Kalima Pro entitlement expires, Pro sync access ends. Your former-Pro library, vocabulary, study, and reading data remains eligible for restoration for up to 12 calendar months after the authoritative entitlement expiry and may then be permanently purged. Always-free learning languages, learning-space records, and daily goals remain until you delete the account.

Signing out resets local app data on the device, but it does not delete cloud data. Account deletion is required to delete cloud account data.

5. Sharing and Service Providers

We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.

We share information with service providers only as needed to operate Kalima, provide features, process subscriptions, secure the service, comply with law, or protect rights and safety. Kalima remains responsible for selecting providers and for its own instructions to them and uses contractual and technical controls intended to protect information consistently with this Policy and applicable law.

These providers may include:

  • Apple, for Sign in with Apple, App Store purchases, notification delivery, device permissions, Apple Speech Recognition, Apple Vision, Free-tier device text-to-speech, and iOS services.
  • Google and Firebase, for authentication, Firestore, Storage, Cloud Functions, App Check, Remote Config, Cloud Messaging, Crashlytics, Google Sign-In, and Firebase AI / Google AI.
  • Inworld, for Kalima Pro text-to-speech processing sent directly between the app and Inworld after Firebase mints a short-lived authorization token.
  • PostHog Cloud EU:用于可选的账号关联产品分析,事件保留一年;账号删除时,关联的用户档案和事件会自动删除。
  • RevenueCat, for subscription products, receipts, customer information, entitlements, restores, and billing state.
  • Cloudflare, for website hosting, security, request delivery, and privacy-focused aggregate website analytics. Cloudflare may process IP address, browser, device, and request metadata under its current terms and retention practices.
  • Kalima's Discovery endpoint, Gutendex, and Project Gutenberg, for public-domain catalog search, request delivery, book download, and related cover or metadata requests.
  • Websites you choose to import from, when you enter a URL for extraction.

We may also disclose information if required by law, to respond to valid legal process, to protect users or the service, or in connection with a merger, acquisition, financing, or sale of assets.

6. AI Processing, Provider Use, and Your Choices

Kalima sends selected words or sentences, nearby context, and language settings to Google/Firebase when you deliberately request Google-assisted translation or definition. Free users use Apple device text-to-speech. Kalima Pro always uses Inworld for read-aloud and sends speech text, target language, selected Inworld voice and synthesis settings directly to Inworld. Kalima Pro never falls back to Apple text-to-speech; if Inworld playback fails, Kalima surfaces the failure for retry.

Kalima does not train its own AI models on your imported reading content and does not use that content for advertising. For the production Gemini service verified as billing-enabled on September 4, 2026, Google's current paid-service terms state that prompts and responses are not used to improve Google products. Google may still retain limited safety and abuse-monitoring logs under those terms.

Inworld's current public terms permit broader use of submitted inputs to provide, maintain, develop, improve, secure, and protect its services. This means provider use can be broader than Kalima's own use. Do not send sensitive, confidential, regulated, or third-party material through an AI or voice feature unless you have the right to submit it and accept the applicable provider processing.

Kalima presents these features when you deliberately request translation, definition, pronunciation, or read-aloud. The current app does not provide a separate provider-specific consent screen before text is sent to Google/Firebase or Inworld.

7. Retention and Deletion

We keep information for as long as needed to provide Kalima, maintain your account, comply with legal obligations, resolve disputes, enforce agreements, prevent abuse, and operate backups and security systems.

本地应用数据会保留在设备上,直至您将其删除、退出登录、删除账号、卸载应用,或由常规清理将其移除。设备级设置、最近搜索以及外观或阅读器偏好可能在退出登录后仍然保留,直至由应用、iOS 或卸载操作另行清除。退出登录后,分析标识会开始新的匿名使用历程。

On-device translation and definition results may be cached for up to 30 days in a size-limited 8 MB cache. Complete AI-voice-generated audio and relative timing offsets may be kept in a protected on-device cache limited to 512 MB and 30 days since last access. These AI caches are cleared on account exit or account change and may also be purged when the associated book is deleted or normal limits expire, subject to successful local cleanup.

For normal in-app deletion of books or vocabulary, deleted content and temporary sync-journal records generally expire after about 30 days so deletion can converge across devices. Kalima may keep content-free generation, deletion, or revocation fences for longer, including indefinitely, to prevent deleted data from reappearing, block a deleted account from being recreated by stale work, or enforce an analytics revocation. These records do not contain the deleted book text, vocabulary text, notes, or account content.

When you delete your Kalima account, local app data is removed from that device immediately and active cloud deletion becomes due seven days later. Signing in again during those seven days cancels the scheduled deletion. After the recovery period, Kalima's deletion worker disables access and retries deletion of the RevenueCat customer record, Firebase Auth account, Firestore account data (including operational Inworld usage records), Storage files under your user paths, push registrations, and reminder jobs, and requests deletion of their FIDs from Firebase. For Apple-linked accounts, it also attempts to revoke Sign in with Apple authorization and removes the encrypted revocation credential when deletion finalizes; if automatic revocation cannot be completed, Kalima may instruct you to disconnect Kalima manually in Apple settings.

Deleted Sync V1 Firestore data may remain recoverable in point-in-time recovery for up to seven days and daily backups for up to 30 days. Deleted Sync V1 Storage objects may remain recoverable under a 30-day soft-delete window. Provider logs, security records, tax or transaction records, and other records may remain longer where required or permitted by law.

Deleting your Kalima account does not cancel an Apple App Store subscription. You must cancel or manage subscriptions through Apple App Store settings or Apple's subscription management tools.

Kalima configures PostHog product-analytics events for one-year retention. Firebase Crashlytics diagnostic data is retained under the applicable Firebase configuration and provider terms. Kalima's server-side push registration expires no later than 35 days after its last refresh and is removed earlier when the installation is unregistered, becomes invalid, transfers to another account, or the account is deleted. Google retains a FID until Kalima requests deletion; Google states that data tied to a deleted FID is removed from live and backup systems within 180 days. Anonymous aggregate reports may be retained longer when they do not contain account or installation identifiers.

Account-linked Inworld usage daily totals and installation/replica metadata are retained for 13 months. Short-lived batch receipts used to prevent duplicate counting are retained for seven days. These records are deleted with the account.

删除账号时,系统会自动请求删除关联的 PostHog 用户档案及其事件历史,包括与该档案关联的匿名别名。Kalima 会阻止继续接收已删除标识对应的数据,在清理失败时重试,并在确认提供商已完成处理后才将分析数据删除视为完成。事件删除是异步进行的,因此在访问被阻止后仍可能处于待处理状态。从未与账号关联的历史事件需要经过核实的旧版支持请求才能处理。为防止队列中的事件重新创建已删除的历史记录,我们可能无限期保留已删除分析标识的带密钥哈希值,这些哈希值不包含内容。

PostHog 产品分析事件保留一年,除非通过账号删除或适用的删除请求提前删除。旧版应用的支持参考记录在 90 天后过期。最近已知的分析用户档案属性会随档案保留,直至档案删除。与账号关联的分析用于产品分析和支持,不用于广告、跨应用追踪或出售个人信息。

网站主题和语言偏好会一直保留在浏览器的本地存储中,直到您更改这些设置或清除网站数据。 Cloudflare request, security, and aggregate analytics data follows Cloudflare's applicable retention settings and terms.

8. Your Choices and Rights

Depending on your location, you may have rights to access, correct, delete, receive a portable copy of, restrict, or object to certain processing of your personal information. You may also have the right to withdraw consent where processing is based on consent, appeal certain privacy decisions, and complain to your local data-protection or privacy authority.

You can:

  • Delete your account in the app.
  • Sign out to reset local account data on the device without deleting cloud data.
  • Delete books, Quick Reads, and vocabulary items in the app.
  • Manage camera, microphone, speech recognition, and notification permissions in iOS Settings, and choose individual files through the document picker.
  • Revoke notification permission in iOS Settings to stop all Kalima notifications. When you return to the app, Kalima checks that permission, cancels local reminders, and unregisters the installation from its push service. Daily Review and Weekly Digest in Profile > Notifications control those individual reminders; their selections and reminder time are preserved if permission changes. Allowing notifications again restores the selected reminders and eligible account updates. Delivery can take a short time to cease while Apple, Firebase, and Kalima process an in-flight unregistration.
  • Choose a device voice while Free or an Inworld voice while subscribed to Kalima Pro; Pro read-aloud never falls back to Apple text-to-speech.
  • Turn Share Analytics off in Profile Privacy to stop and revoke PostHog collection; Crashlytics remains automatic and the account-linked operational Inworld usage meter remains active.
  • 您可以通过浏览器的网站数据管理功能清除网站主题和语言偏好。
  • Cancel or manage subscriptions through Apple App Store settings.

Contact support@kalimaapp.com to request access, correction, deletion, export, or other privacy assistance.

Withdrawing consent does not affect processing that was lawful before withdrawal. We may need to verify your identity before completing a request, and applicable law may allow or require us to retain certain information or decline part of a request. If we deny a request, you may contact us to appeal and may complain to the competent authority where you live.

The Kalima website does not perform app-owned cross-site tracking and Kalima does not knowingly allow other parties to collect personally identifiable information through the website about your activities over time and across unaffiliated websites or services. Because Kalima does not sell or share personal information for cross-context behavioral advertising, browser Do Not Track and Global Privacy Control signals do not change app-owned website behavior. Cloudflare's strictly necessary security and delivery processing may continue.

9. Legal Bases for EEA, UK, and Similar Regions

Where a legal basis is required, the basis depends on the purpose and information involved:

  • Contract: to create and maintain your account; provide importing, reading, vocabulary, sync, AI, voice, support, and subscription features you request; and administer entitlements.
  • Consent: for iOS permissions and optional processing where Kalima asks for consent and applicable law requires it. You may withdraw consent through the app, iOS settings, or by contacting us.
  • Legitimate interests: to secure Kalima, prevent abuse and fraud, diagnose crashes, improve reliability, support capacity operations, understand limited pseudonymous product usage where permitted, and provide support. We consider the necessity and effect on users before relying on this basis.
  • Legal obligations: to comply with applicable tax, accounting, consumer-protection, security, and valid legal-process requirements.

Providing account and feature-request data is necessary to create an account or perform the feature you request. If you do not provide it, the relevant account, sync, AI, voice, or subscription feature may not work. Optional permissions and product analytics are not required for unrelated features.

10. International Transfers

Kalima's controller and service providers may process information outside the country where you live, including in the United States, the European Economic Area, the United Kingdom, and other countries where providers or their subprocessors operate. Those countries may have different privacy laws.

Where transfer restrictions apply, a legally recognized transfer mechanism must be in place before Kalima makes the restricted transfer. Depending on the provider and route, that mechanism may include an adequacy decision, provider data-protection terms, standard contractual clauses, or supplementary technical and organizational measures. Contact support@kalimaapp.com for information about the mechanism used for a particular transfer and, where available, how to obtain a copy.

11. Security

We use reasonable technical and organizational measures designed to protect information, including Firebase security rules, account authentication, App Check, encrypted network transport, and owner-scoped cloud paths. No app, network, or storage system can be guaranteed completely secure.

You are responsible for keeping your device, Apple ID, Google account, and Kalima sign-in method secure.

12. Age Eligibility

Kalima is intended for people age 16 and older. You must also be old enough to use online services in your country. We do not knowingly collect personal information from anyone below the applicable minimum age. If you believe an underage person provided personal information to Kalima, contact us at support@kalimaapp.com.

13. Third-Party Links and Content

Kalima may let you access public-domain catalogs, imported websites, books, documents, and external services. Third-party services and content are governed by their own terms and privacy policies. We are not responsible for third-party privacy practices.

Third-party policies that may apply to related services include:

14. Changes

We may update this Privacy Policy as Kalima, its providers, or legal requirements change. We will post the updated Policy and effective date here. For material changes, we will provide additional notice in the app, by email, or through another appropriate channel before the change takes effect where required by law. You may request information about prior versions by contacting support@kalimaapp.com.

15. Contact

Kalima privacy and support contact: support@kalimaapp.com