Last updated: September 30, 2026
Privacy policy
Status and data controller
Kyun is an independent service operated from Spain. Contact: matt@startupfy.es. The operator’s full legal identity, tax identification number and address, and a professional review of these documents, are still pending. We explicitly acknowledge this missing information. This document is not presented as legal advice.
This document describes the system’s current technical behavior. It is not a substitute for legal advice and has not undergone a completed legal review.
What data we process and why
- Account and access. Firebase assigns an identifier even when you use the app anonymously. If you link an account, it also processes your email address and, for Google sign-in, the name and identifier provided by Google. These support sign-in and keep your progress consistent across devices.
- Learning. We store your onboarding profile, preferences, review state, daily activity and technical receipts that prevent the same answer from being applied twice. Documents are isolated under each learner’s Firebase identifier. When you answer, a function in Madrid receives the card identifier, your “I knew it” or “I didn’t know it” response, the time and time zone to calculate the FSRS schedule. It does not receive free text or the card’s Japanese content.
- Security and errors. Firebase, Resend, Sentry and the DNS provider process IP addresses or the technical metadata necessary to authenticate, deliver and protect the service. Application events sent to Sentry contain only the environment, version, error source and type, and positions in the compiled file. Identity, email, URLs, study content, messages, breadcrumbs and device context are removed before sending.
- Aggregate analytics. PostHog EU receives only page events and events for starting or completing a learning session. Fields are limited to a fixed route group, interface language, study language, learning mode, card-count range, environment, version and technical event timestamp. We do not send Firebase UIDs, email addresses, learner identifiers, card text, answers, individual progress, actual URLs, query parameters, referrers, campaigns or device data.
We do not sell data, create advertising profiles or make automated decisions with legal effects. The proposed legal bases are provision of the service for accounts and learning, and legitimate interest for security. These remain subject to the pending professional legal review.
Data stored in your browser
Firestore maintains an IndexedDB cache for offline use and multiple tabs. localStorage stores your theme, a preferences cache to prevent visual flashes, your onboarding draft, a queue of pending answers until the server acknowledges each receipt, the email address for a sign-in link until it is used, and marks or notes from the internal review tool. sessionStorage temporarily stores a notice about a failed account merge.
Your interface language preference is stored only in this browser. It is not added to your account or synced across devices. An explicit language URL takes precedence over the saved preference. Signing out retains this preference; clearing the site’s browser data removes it.
Account-related data and caches are cleared on sign-out when the browser permits it. The theme and internal review tool data remain until reset or until you clear site data. We do not use advertising cookies. PostHog runs in cookieless mode and stores no PostHog data in cookies, localStorage or sessionStorage.
Providers and locations
- Google Firebase. Static hosting, CDN, TLS, authentication, Cloud Firestore, and functions that acknowledge answers and send sign-in links. Firestore and the main functions are configured in Madrid (europe-southwest1). Firebase Authentication and Hosting operate globally as described in Firebase’s documentation.
- Cloudflare. Authoritative DNS for the domain. It does not serve Kyun’s HTML or assets, act as a proxy or CDN, or inject Cloudflare Web Analytics.
- Resend. Delivers email sign-in links. It receives the recipient’s address, message content and technical metadata necessary for delivery. Kyun does not enable open or click tracking for these emails.
- Sentry. Diagnostics for redacted technical errors, hosted in the European region configured for the project. The provider may process the connection IP address when receiving an event. Contractual verification of its retention is still pending. Tracing, session replay and breadcrumbs are disabled.
- PostHog EU. Aggregate product analytics hosted in the provider’s European region. The project is configured to discard IP addresses and uses “Cookieless server hash” mode to count without creating a persistent identifier in the browser. We do not call identify or create person profiles. Autocapture, session replay, heatmaps, dead-click tracking, surveys, conversations, tours, experiments, logs and feature flags are disabled.
Google Analytics and Cloudflare Web Analytics are not active. Firebase App Check is active and enforced in staging and production. Before sending an event, the code restricts it to the fields listed above. Any expansion of analytics requires prior documentation of its purpose, provider, retention, legal basis and, where applicable, consent.
Retention and backups
- Account and learning data are retained while the account is active or until a valid deletion request is processed.
- Firebase documents that it retains authentication IP addresses for a few weeks and removes the remaining authentication data from active systems and backups within 180 days after an Authentication user is deleted.
- Staging and production have point-in-time recovery, daily and weekly backups, and deletion protection. Two staging restores have been verified for data integrity and correct permissions.
- Actual retention of PostHog aggregate events, Sentry redacted events and providers’ operational metadata still needs confirmation in their dashboards and contracts. We do not publish retention periods we have not verified.
Export, deletion and your rights
The release candidate lets you download versioned JSON containing your profile, preferences, reviews and activity. Self-service deletion uses a privileged, durable process that can be retried. It clears Firestore before deleting the Firebase Authentication account; deletion is not simulated in the browser.
You can also request access, correction, export, erasure, objection or restriction by contacting matt@startupfy.es. We will confirm your identity and the scope of the request before acting. If you believe a request has not been handled correctly, you can contact the Spanish Data Protection Agency at aepd.es.
Children
Kyun is not intended for children under 14. If you are under 14, do not link an account or provide personal data without permission from your parent or legal guardian.
Changes to this policy
We will update this page when the system changes or before enabling a new provider. The displayed date identifies the current version.