Privacy policy for mLearn — Language Learning Overlay
mLearn — Language Learning Overlay by Kikan
Privacy policy for mLearn — Language Learning Overlay
Canonical version: https://mlearn.kikan.net/privacy
Privacy Policy
Version 1.5 — Effective Date: 2026-07-15
Contact: adrian@kikan.net
Operator: Adrian Vlasov, Vaud, Switzerland
- Overview
mLearn is local-first software. Most of your data never leaves your device. This policy explains what happens when you use hosted cloud features at mlearn-cloud.kikan.net. - Data We Collect
2.1 Account Data (Cloud only)
Email address
Authentication tokens / session IDs (encrypted at rest)
Quota usage and transaction logs
2.2 Job Processing Data (Transient, up to 1 day)
When you use Cloud OCR or Cloud TTS, we create a minimal job record to track processing status. This includes:
OCR: Extracted text and bounding boxes (metadata only)
TTS: Source text reference
Job metadata: Processing status, timestamps, error messages
OCR images are deleted immediately after processing completes.
TTS audio files are deleted immediately after you download them.
Job metadata is retained for up to 1 day to allow status tracking, then automatically deleted.
2.3 Watch Together Session Data
Room state (playback time, pause/play status, media URL, media title, subtitle settings)
Room membership (who joined, when)
Usage segments (session start/end times)
Retention: Active room data persists while the room is open. Closed rooms, usage segments, and orphaned memberships are automatically deleted after 30 days.
2.4 Waitlist
Email address (if you signed up for the waitlist)
Retention: Deleted immediately upon notification. A 1-day safety net exists for edge cases, then purged by garbage collection.
2.5 Sync Data (Cloud only)
Flashcard text and metadata (synced via Cloudflare Durable Objects)
Application settings
2.6 Optional Website Analytics
Website analytics are disabled unless you explicitly allow them. If you opt in, we use PostHog through our first-party proxy at o.kikan.net with EU-hosted processing.
When enabled, the analytics events can include:
page views and navigation context, such as the page URL and referrer;
interaction events, including Download and GitHub link clicks and other website interactions; and
technical event context, such as browser and device information and a pseudonymous analytics identifier.
Our website integration does not send your account email or call PostHog’s identify method. We do not use these events for advertising or to build advertising profiles.
We record your analytics choice in browser storage. If you allow analytics, PostHog may use local storage and cookies to maintain the analytics session and preference. You can review or change this choice at any time using the analytics control in the website footer.
Opting out stops future analytics capture. It does not delete analytics events already collected; contact us if you wish to make a data request.
2.7 What We Do NOT Collect
The content of AI conversations (no chat logs)
Voice cloning samples (processed transiently and discarded)
OCR images after processing (deleted immediately)
Generated TTS audio after delivery (deleted immediately)
Video, audio, or subtitle files from your local media
3. How We Use Data
To authenticate you and provide cloud relay services
To process OCR and TTS jobs
To coordinate Watch Together sessions
To track quota consumption
To sync flashcards and settings across devices
To improve the website using optional analytics, when you allow it
We do NOT:
Train AI models on your data
Sell your data
Profile you for advertising
4. Data Retention & Deletion
Data Type Retention Period Automatic Deletion
Account & quota Until account deletion Manual (account deletion)
Job metadata Up to 1 day Yes (Worker GC cron)
OCR images Deleted immediately after processing Yes
TTS audio Deleted immediately after download Yes
Watch Together rooms Active session / 30 days after close Yes
Waitlist emails Deleted on notification / 1-day safety net Yes
Auth codes/tokens 5–15 minutes Yes (Worker GC cron)
Optional website analytics Managed in our PostHog project Opting out stops future collection; it does not delete events already collected
5. Third-Party Services
We use the following categories of service providers to operate the cloud backend:
Category Purpose Data Shared
Edge network / CDN Request routing, DDoS protection, flashcard sync Encrypted requests, flashcard chunks
Database / Auth User accounts, job tracking, Watch Together state Account email, job metadata, room state
AI inference LLM text generation Conversation messages (transient, not stored by us)
Audio synthesis TTS and voice cloning Text, voice sample (transient, not stored by us)
PostHog (optional) EU-hosted product analytics, routed through our first-party proxy Page views, interaction events, technical context, and pseudonymous analytics identifiers after opt-in
Specific provider names and locations may change over time. A current list is maintained at mlearn.kikan.net/infrastructure. We do not sell your data. We process it only to provide the service.
5.1 International Data Transfers
Some of our processors operate outside Switzerland. For transfers of personal data, we rely on appropriate safeguards as required by applicable data protection law, which may include Standard Contractual Clauses where applicable.
- Security
Encryption in transit (TLS 1.3)
Row Level Security (RLS) enabled on all database tables
Private Storage bucket with path-based access control
Desktop authentication tokens encrypted at rest (AES-GCM) - Your Rights
Under Swiss and EU data protection law, you have the right to:
Access your data
Correct inaccurate data
Delete your account and associated data
Object to processing
Receive a copy of your data
Contact: adrian@kikan.net
- Children's Privacy
The hosted Cloud LLM relay is available only to users who are at least 18 years old, or the age of majority in their jurisdiction if higher. We ask for that confirmation only when a user tries to access the hosted Cloud LLM relay.
Other mLearn features may be used by younger learners where a parent, guardian, school, or other authorized adult is responsible for the deployment, supervision, and any required consent. We do not knowingly collect personal data from children in a way that requires parental or school authorization without that authorization. If you believe a child provided personal data through the hosted service without the required authorization, contact us and we will delete it.
- Changes
We may update this policy. Material changes will be notified via email and/or in-app notice. Continued use after the effective date constitutes acceptance.