Skip to main content

Legal

Privacy Policy

Effective 2026-07-25

Who we are

Nisatsu is a language-learning product operated by NISATSU LLC("Nisatsu", "we", "us"). This policy explains what data we collect when you use our websites (nisatsu.com and nisatsu.app) or the Nisatsu mobile app, how we use it, who we share it with, and the rights you have.

If you have questions, write to contact@nisatsu.com.

Data we collect

  • Account identifiers. Email address and/or phone number you use to sign in, a Stytch-assigned user ID, and any profile fields you edit (display name, username, bio, avatar, learning goal, interest tags).
  • Learning data. Vocabulary you add or mark, stories generated for you, read sessions, review grades, streaks, and statistics derived from these, plus, if you use the in-reader "Ask Nisatsu AI" chat, the questions you type and the answers you receive.
  • Device & technical data. IP address (derived from request headers), browser/OS user-agent, approximate region inferred from IP, push-notification tokens you register with us, and error diagnostics when something breaks.
  • Billing data. RevenueCat app user ID (equal to your internal user ID), product identifier, plan, status, and renewal/cancellation dates. We never see or store your card number; payments are processed by Stripe (web) or Apple / Google (mobile) under RevenueCat.
  • Product analytics. A fixed set of product events (e.g. story generated, word saved, onboarding completed) linked to your user ID so we can understand usage and diagnose issues.
  • Pre-launch notice signup. If you asked our coming-soon page to tell you when Nisatsu opened, we stored your email address, signup time and source, any campaign parameters on the link you used, and the delivery and unsubscribe records needed for that one requested notice. This list is separate from a Nisatsu account.

How we use it

  • To operate the service: generate stories, track vocab, run review, deliver push notifications you opted into.
  • To authenticate you securely and keep sessions valid.
  • To bill for subscriptions and enforce entitlements.
  • To debug failures and prevent abuse (rate-limiting, fraud).
  • To improve the product via aggregate/event analytics.
  • To send the one-time opening notice requested through our pre-launch page and honor its unsubscribe link.
  • If, and only if, you opt in, to email you occasional first-party updates about new languages, features, and stories.

We do not sell your personal information, show third-party ads inside the product, or profile you for advertisers. We do advertise Nisatsu on other platforms to reach new learners; where that uses advertising cookies to measure how our ads perform, they load only with your consent (see Advertising cookies below). We also do not use your data, your stories, vocabulary, reading history, or anything you write, to train AI models. Marketing email is first-party only: it comes from us, about our own product, to people who chose to receive it, and you can stop it at any time (see Marketing communications below).

Legal bases (EU/UK users)

  • Contract, to deliver the service you signed up for.
  • Legitimate interests, to keep the service safe, debug it, prevent abuse, and run product analytics; you can opt out any time in Account → Privacy.
  • Consent, for marketing email. We only send it after you actively opt in, either by requesting the one-time pre-launch opening notice, selecting the unchecked box at signup, or using the toggle in Account → Privacy. You can withdraw consent at any time.
  • Legal obligation, to retain records we must keep by law.

Who we share with

We use a small number of vetted subprocessors to run the product. A current list is maintained at /subprocessors. As of the effective date above, that list covers authentication (Stytch), subscription management (RevenueCat) and payments (Stripe / Apple / Google), AI generation (OpenAI), text-to-speech audio (Azure Speech), word- and sentence-audio caching (AWS S3 / CloudFront), database hosting (Neon Postgres), rate-limiting state, short-lived operational caches, and durable story-job delivery (Upstash Redis and QStash), product analytics (PostHog), error monitoring (Sentry), push delivery (Expo + Apple APNs / Google FCM), email delivery (Resend), and hosting (Vercel for the web app and API; Fly.io for the story-generation guardrail service, which processes your known-vocabulary list, story topic text, and recent story titles without any account identifiers).

What we send to PostHog. Product analytics events may include your internal user ID, event names, story IDs, and small operational metadata such as language or screen context. We do not send email, phone number, raw story text, or vocab prose to PostHog, and Account → Privacy opt-outs suppress non-essential PostHog events on both web/server and mobile clients.

What we send to Resend. We use Resend to deliver transactional account and legal-policy notices to accounts with an email address. If you opt in to marketing email, Resend also delivers those messages. We send the email address, the email content, and a first name when needed to address the message. For the separate one-time opening notice, we temporarily create a Resend contact, place it in the dedicated release-notice Segment, and record its opt-in to the dedicated Topic so Resend can honor provider-side unsubscribes before delivery. Resend processes this only to send our email on our behalf; it is contractually barred from using it for its own purposes, and we do not send Resend your phone number, story text, or vocab prose.

We disclose data to these providers only to the extent necessary to operate the service, under contracts that restrict their use of the data. We do not share your data with data brokers. The only information shared with advertising partners is the consent-gated ad-performance measurement described under Advertising cookies below, and it never includes your email, phone number, or anything you write.

What we send to OpenAI. When you generate a story, we send your full known-vocabulary list (up to 5,000 words), your chosen target/native languages, the titles of your recent stories (so the new story avoids repeating them), and, if you provided one, your topic prose. When you don't supply your own topic and haven't opted out of profile-based recommendations, we also send the interests and learning goal you've chosen in your profile, so the model can write something you'll care about. The topic is run through OpenAI's moderation endpoint before generation, and the generated story is moderated again before it's shown to you. When Nisatsu prepares a complete translated copy of a story, the complete story title and sentences are sent to OpenAI; the translated result is moderated before it is saved. When you press-and-drag to translate a phrase inside the reader (including phrases from stories another learner shared with you), the selected text and the source/target language pair are sent to OpenAI to produce the translation. When you tap a vocab word for details we may send the word and its meaning to OpenAI to look up its part of speech. When you request a story title in your native language, we send the title and language pair. When you use the "Ask Nisatsu AI" explain chat (a Pro feature inside the reader), the question you type, the word or phrase you asked about together with its sentence, and the recent turns of that conversation are sent to OpenAI to produce the answer; your question is run through OpenAI's moderation endpoint before it is answered, and the answer is moderated before it's shown to you. When you create or update public-facing profile fields, your display name, username, bio, and interest tags are sent to OpenAI for moderation. When you add or edit a vocab entry, manually entered vocabulary text is sent to OpenAI for moderation. For uncached free-form audio requests, the uncached text and any supplied reading are also sent to OpenAI for moderation before synthesis.

What we send to Azure Speech. When you play a single word, highlighted section, or sentence, the text being spoken and target language are sent to Azure for synthesis. Single-word MP3s may then be stored in a public S3/CloudFront cache under opaque deterministic object keys. Sentence and phrase audio may be cached the same way under keys derived from a cryptographic hash of the exact text, language, and voice; those keys are not guessable and carry no account identifiers, but because the cache is shared and keyed only by content, cached audio for a sentence can persist after the story it came from, or your account, is deleted, until the cache entry expires.

Provider handling. We do not send your name, email, phone, IP address, or internal user ID to OpenAI or Azure in any of these calls. We do not use this content to train AI models. Under OpenAI's and Azure's API terms, API data is not used to train or improve their models unless the customer opts in; Nisatsu does not opt in. OpenAI may retain customer content in API abuse-monitoring logs for up to 30 days, or longer when legally required. Nisatsu disables Responses API application storage for these calls.

Sharing with other learners

You control when stories and profile information are shown to other signed-in Nisatsu learners. Story visibility works as follows:

  • Private stories are available only to you.
  • Friends stories are available to people whose friend requests you have accepted.
  • Public stories can appear in the Community feed and can be opened by any signed-in learner, including through a shared story link. The story title and contents are visible. Learners who are not your friends do not receive your name or username as the story byline.

A profile link also requires the recipient to sign in. It can show your display name, username, avatar, and bio. It can also show your reading streak, learned-word count, and stories-read count when the corresponding sharing toggles are on. Your learning goal and interest tags are not included in the shared profile.

You can change a story's visibility, edit or remove profile fields, turn individual statistic toggles off, or rotate your profile share code so the old link stops working. Blocking another learner makes your shared profiles and stories unavailable between the two accounts. Deleting a story or your account also stops our display of that content, subject to the limited moderation and legal records described under Retention.

Advertising cookies (only with your consent)

We run ads for Nisatsu on platforms such as Google, Meta (Facebook/Instagram), and TikTok to reach new learners. To measure how those ads perform, for example, that a visit from an ad led to a sign-up, our marketing site and the app's public pages (such as the sign-in page and these legal pages) can use advertising cookies from those partners, but only if you agree. While a campaign is running, a banner asks whether we may use them. Nothing loads unless you choose Accept; Decline works with one click, and the site works exactly the same either way.

If your browser sends a Global Privacy Control signal, we treat it as a standing Decline automatically. If you accept, these partners set their own cookies and receive information about your visit (such as the pages you viewed and whether you signed up or completed a subscription purchase), never your email address, phone number, or anything you write. If you accepted before signing in, the account creation and purchase-success flows may report those two conversion events from an authenticated page; they still send no account ID or contact information and re-check your consent before sending. California residents: this is the "sharing" you may opt out of under the CCPA / CPRA, and declining the banner or sending GPC does exactly that. You can change your answer any time via "Cookie preferences" in the footer, on the marketing site and on the app's pages alike. An account-level or public Do Not Sell or Share request also visits each website in sequence so that both origins revoke their stored consent and clear visible partner cookies; you do not need to submit one request per site.

These advertising cookies are never set by default and never without your consent. Signed-in surfaces of the Nisatsu app show no advertising and never prompt for advertising cookies; while no campaign is armed (the default), the app sets only strictly-necessary cookies and no banner appears anywhere.

Separately from cookies, when you create an account we record which of our own campaigns brought you to us: the utm_ parameters carried by the link you clicked, if any. This is first-party measurement that works the same whether you accept or decline the banner: it involves no third-party cookies, is never shared with the ad platforms, and is deleted with your account.

International transfers

Our subprocessors may process data outside the country you live in (typically the United States and the European Union). Where required, transfers rely on standard contractual clauses or equivalent safeguards offered by the subprocessor.

Marketing communications

Before launch, the coming-soon page offered a separate one-time opening notice. Submitting that form asked us to send exactly that notice, not ongoing marketing. Its email includes a no-login unsubscribe link, and using the link prevents an unsent notice from being sent.

For ongoing product updates, we send marketing email only to people who ask for it. The box at signup is unchecked by default and entirely optional. Skipping it does not affect your account. If you opt in, you'll get occasional first-party email about new languages, features, and stories. We record which version of the consent wording you agreed to and when, so we can show a lawful basis for emailing you.

You can withdraw consent at any time: flip Marketing emails off in Account → Privacy (web or mobile), or use the unsubscribe link in any marketing email we send. Withdrawing is as easy as opting in and takes effect right away. Withdrawing has no effect on essential account, security, and transactional messages, which are not marketing and which we send regardless so we can operate your account.

Retention

We keep account and learning data for as long as your account is active. When you delete your account, we deactivate it right away and, after a 7-day recovery window during which signing back in restores it, permanently remove your profile, settings, vocabulary, stories, read sessions, study sessions, and friendships. A small set of records survives for billing audit, abuse prevention, regulatory compliance, and product reliability under our legitimate interests. Some records have their relational user ID nulled. Limited pseudonymous identifiers remain where billing reconciliation or abuse prevention requires them, as described below:

  • Subscription records (plan, status, store, billing period, and the internal account identifier used to reconcile with RevenueCat), for billing audit, chargeback windows, and tax records. After your account is deleted, the orphaned record is retained for up to 180 days after the underlying transaction's chargeback window closes, then eligible for hard deletion. A documented legal data-erasure request triggers an individualized retention review; we delete the row sooner when no legal obligation or overriding need requires us to keep it. If you later restore the same App Store, Play Store, or RevenueCat purchase onto a new account, the prior transaction history attached to that store-side purchase may be linked to the new account at the moment of restore.
  • Billing consent records (the EU/UK immediate-access waiver you accepted at checkout, plus its text + version + timestamp), required as durable evidence of consent under EU Consumer Rights Directive 2011/83/EU art. 16(m) and the UK Consumer Contracts Regulations 2013.
  • Age-affirmation records (the version and exact text of the unchecked minimum-age confirmation you selected during account creation, plus the timestamp), retained so we can demonstrate the affirmation that was actually presented even after the wording evolves.
  • Analytics events with your user ID nulled, for spend reconciliation, cohort analysis, and incident investigation. Identifying fields are stripped or hashed before persistence; the raw event payloads associated with billing flows are redacted to omit store-side transaction identifiers from the analytics pipeline. A scheduled job hard-deletes anonymized analytics rows after approximately 24 months from the event timestamp.
  • Privacy-request records (CCPA/GDPR DSARs you submitted), retained for 24 months under the CCPA regulations (11 CCR §7101) to demonstrate compliance with the request, with contact identifiers stored only as one-way hashes.
  • Webhook event audit + dead-letter records for billing-provider events, retained for ~30 days for dispute investigation (dead-letter records of events that failed processing are kept up to ~90 days for operator review), then purged by a scheduled job.
  • Moderation-report audit rows (reports you file against stories or profiles, and reports against your content) are kept with reporter or reported-account identity nulled, so the moderation decision trail remains intact.
  • Abuse-prevention block history, a small snapshot of who blocked whom is retained pseudonymously so re-friending after a sustained block pattern can be flagged to support.
  • Pre-launch notice records contain the email address and signup metadata described above, together with a random unsubscribe token and delivery, claim, or unsubscribe timestamps. We retain them while completing the one-time notice and for up to 24 months afterward to document consent, delivery, and opt-out handling, then delete them. A verified deletion request can remove the record earlier unless we need it briefly to resolve an in-flight delivery or meet a legal obligation.
  • OpenAI API abuse-monitoring logs may contain prompts, responses, or classifier metadata and may be retained by OpenAI for up to 30 days, unless OpenAI is legally required to retain them longer. Nisatsu disables Responses API application storage and does not opt API data into model training.
  • Email delivery logs for transactional or legal-notice email already sent to you may persist with our email provider (Resend) as delivery records (recipient address and message content) until they age out under that provider's log retention. For the one-time opening notice, we delete contacts created solely for the notice after Resend confirms the Broadcast was sent. If a contact already existed for another authorized purpose, we remove only its release-notice Segment membership and Topic opt-in. A verified deletion request can remove this release-notice contact state earlier unless a delivery is already in flight.
  • Error-monitoring events may persist with our error monitoring provider (Sentry) for up to ~90 days before they age out under that provider's default retention. The event payloads are scrubbed of free-form content at ingest, and server error-monitoring events are sent without a stable account identifier.

Backup snapshots age out within 30 days. Limited records required for legal or financial reasons (e.g. invoices, tax records) may be retained longer as permitted by law. Apart from the time-limited pre-launch notice record described above, none of the records surviving account deletion in our own systems contain your email, phone number, name, avatar, or any free-form content you authored; the provider-side residuals above (OpenAI abuse-monitoring logs, email delivery logs, and error-monitoring events) age out on their providers' schedules.

Your rights

Regardless of where you live, you can:

  • Download a portable copy of your account and learning data (Account → Privacy → Download my data). For a broader access request, use Your Privacy Choices or email us.
  • Correct your profile and settings in the app.
  • Delete your account (Account → Privacy → Delete my account). Your account is deactivated right away and permanently deleted after a 7-day recovery window; signing back in before then restores it.
  • Opt out of profile-based recommendations.
  • Turn off optional analytics/telemetry.
  • Turn off push notifications in settings or your device OS.
  • Opt out of marketing email: flip "Marketing emails" off in Account → Privacy, or use the unsubscribe link in any marketing email, including the separate one-time opening notice.

California residents may exercise CCPA/CPRA rights including "Do Not Sell or Share My Personal Information": use the toggle in Account → Privacy. EU/UK/EEA residents may also lodge a complaint with their local supervisory authority.

If GDPR applies to you, you may object under GDPR Article 21 to processing based on our legitimate interests by emailing contact@nisatsu.com. The Account → Privacy toggle disables optional analytics; an Article 21 objection can also ask us to review other legitimate-interest processing, such as security, abuse prevention, or reliability records, against your particular situation and any overriding legal grounds.

Global Privacy Control (Sec-GPC). If your browser sends a Sec-GPC: 1 header (or the equivalent Global-Privacy-Control: 1 header), we treat that as a Do Not Sell or Share signal under California CPRA (11 CCR §7025) and equivalent state laws. When you are signed in, the first request carrying that header to reach one of the surfaces wired to honor it, analytics ingestion and account reads/updates, which your browser and the app contact in normal use, automatically sets both the "Do Not Sell or Share" and analytics-opt-out flags on your account, suppresses non-essential analytics for that request, and emits an audit event so you can see when the signal landed.

To exercise any right we do not expose directly in the app, email contact@nisatsu.com. We respond within 30 days where feasible. Complex CCPA requests may take up to the 45-day statutory window (California Civil Code §1798.130(a)(2)); complex GDPR requests may take up to one month, extendable by a further two months where necessary (GDPR Art. 12(3)). If we need an extension, we will tell you within the initial window and explain why.

Children

Nisatsu is not directed to children under 13 (or under 16 in the EU / EEA where required by national law implementing GDPR Art. 8), and we do not knowingly collect data from them. Creating an account requires accepting our Terms of Service, which require you to meet the applicable age threshold; the version and exact text of the minimum-age clause in effect at that time is recorded so we can demonstrate compliance under COPPA and the ICO Children's Code.

Parents and legal guardians: if you believe a child has created a Nisatsu account, email contact@nisatsu.com with the email or phone number on the account and your relationship to the child. We will ask for one piece of identifying evidence (an email reply from the child's school district, a government-issued ID matching the account name plus a signed statement of relationship, or a court order naming you as the legal guardian). You may redact unrelated details, including ID numbers, photos, birth dates, signatures, addresses, and unrelated court information. If an identity document is needed, we arrange a secure upload method rather than asking you to email it. We delete the source evidence after verification and retain only the evidence type, outcome, dates, and operator audit record. We acknowledge within 5 business days and complete the takedown within 30 days of confirmed verification.

Security

Sessions are encrypted in transit (HTTPS), passwords are never stored (we use passwordless sign-in via Stytch), and sensitive state is kept in access-controlled databases. No system is perfectly secure; if you believe you've found a vulnerability, please follow the disclosure contacts published at /.well-known/security.txt.

Changes

We will update the effective date above when this policy changes and notify active users of material changes before they take effect.

Privacy Policy · Nisatsu