Effective 30 August 2026 · applies to learnthai.app, app.learnthai.app and hebrew.learnthai.app
learnthai.app is an independent language-learning project run by its developer (“we”). This page describes every piece of data the app touches — what stays on your device, what reaches our servers, which services process it on our behalf, and how to erase all of it. Questions and requests: privacy@learnthai.app.
The short version.
· Play without an account and your progress lives only in your browser — our database holds nothing about you.
· Sign in and we store your email, your answer history, your settings and your chats with Kru, so they sync across devices.
· One cookie total — the sign-in session. Analytics is cookieless. No ads, no cross-site tracking, no data sales, no marketing email.
· Questions you ask Kru are answered by Anthropic’s Claude and sent there for that purpose.
· Delete your account any time — the link at the very bottom of ⚙️ Settings erases everything server-side, immediately.
The game is fully playable signed out. In that mode your answer history, spaced-repetition schedules and settings are stored only in your browser (IndexedDB and localStorage) and are never sent to us — a signed-out visitor leaves no row in our database. Like any website, our hosting provider (Cloudflare) handles your IP address to serve pages and keeps short-lived operational logs (errors and diagnostics), which expire automatically within days.
Signing in exists so your progress survives your browser. It adds these records, kept on Cloudflare’s D1 database:
session — set when you sign in; it is what keeps you signed
in. HttpOnly, Secure, first-party, 180-day sliding expiry. Strictly necessary.We measure how the app is used with Google Analytics 4, in cookieless mode: which task types come up, whether answers were right, which features get used — counted as events, with no identifier stored in your browser, which also means visitors who aren’t signed in are counted only approximately. What is measured is deliberately impersonal — we never send Google your email address, your practice name, anything you typed, your questions to Kru, or the text of a feedback report. When you are signed in, events carry a pseudonym (a truncated cryptographic hash of your email) so that your phone and laptop count as one learner; it is cleared the moment you sign out. Cloudflare Web Analytics additionally counts page loads in aggregate, likewise without cookies.
Kru is powered by Anthropic’s Claude models. When you ask a question, we send Anthropic the conversation, the card on screen, and how you’ve been doing on that card — that context is what makes the answer specific. Under Anthropic’s commercial API terms this data is not used to train their models. Transcripts are stored with your account and erased with it. Please don’t put personal details in questions to Kru — it never needs them.
“Report a problem” sends what you typed plus what the screen was showing (which card, which task, which audio clip) into the project’s private issue tracker on GitHub, tagged with your account ID rather than your email address. Reports become part of the project’s development records; once an account is deleted, its ID no longer maps to anyone.
| Service | Role | What it handles |
|---|---|---|
| Cloudflare | Hosting, database, aggregate analytics | All traffic; every record listed above |
| Analytics | Impersonal usage events; pseudonymous ID | |
| Resend | Sending sign-in codes | Your email address, the code email |
| Anthropic | Generating Kru’s answers | Kru questions and card context |
| GitHub | Issue tracker for feedback | Report text and card context, account ID |
These providers process data in the United States and Europe. Where EU/UK data-protection law applies, transfers rest on the providers’ certifications under the EU–U.S. Data Privacy Framework and/or standard contractual clauses.
We don’t sell or share personal data for advertising, run ad networks, or track you across other sites. The only email we send is the 6-digit sign-in code you request; there is no marketing list, and if that ever changes it will be strictly opt-in.
Sign-in code records (with their IPs) are deleted within 24 hours. Sessions expire after 180 days idle. Everything else — history, settings, transcripts, usage counters — is kept while your account exists and erased when it is deleted. Data on your own device is yours: signing out clears it, and browser controls can clear it any time.
Delete everything: the “Delete account…” link at the very bottom of ⚙️ Settings. It permanently erases your account and every server-side record, immediately, no questions asked. You can also email us to delete, access, correct, or receive a copy of your data: privacy@learnthai.app. We answer within 30 days.
If you are in the EEA or UK, these are your GDPR rights of access, rectification, erasure, restriction, portability and objection; our legal bases are performance of our terms with you (accounts, sync, Kru) and legitimate interest (security, rate limiting, impersonal analytics). You may also complain to your local supervisory authority. If you are in Israel, you have corresponding rights under the Privacy Protection Law. We honor rights requests from anywhere, wherever the law they invoke applies.
The app is not directed at children under 13, and you may not create an account under 13 (or under the higher age your country sets for consenting to online services). If we learn we hold a child’s account, we will delete it; parents can write to the address above.
When the app changes what it collects, this page changes with it, with a new effective date. Material changes will be flagged in the app itself, not slipped in quietly.