The short version
- Nikki is a Japanese-learning diary. What you write is the private heart of the product, and we treat it that way.
- To give you corrections and feedback, your writing is sent to a third-party AI provider. That is the single most important thing to understand about how Nikki works.
- Your journal is handled separately from everything else, by a provider whose terms forbid using it to train AI models. Lesson practice and flashcards use a cheaper provider that does allow this — so the journal is deliberately kept apart from it.
- Your journal entries and the AI feedback on them are encrypted in our database.
- Your writing is never sent to our analytics tools, and we never use it to train AI models.
- We do not sell your personal information, and we do not use it for advertising.
- You can delete your account from inside the app at any time. Everything is permanently erased 30 days later.
The rest of this page is the detailed version, written to satisfy the UK and EU General Data Protection Regulation, the California Consumer Privacy Act, and the app store requirements of Apple and Google. If anything here is unclear, email us at support@nikki-ai.app.
Who we are
Nikki AI is operated by Raymond Randall, an individual developer. For the purposes of UK and EU data protection law, Raymond Randall is the data controller for the personal data described on this page — meaning the person who decides why and how it is used, and who is answerable for it.
This policy covers the Nikki AI website at nikki-ai.app and the Nikki AI companion apps for iOS and Android. You can reach us about anything on this page at support@nikki-ai.app. We aim to respond to privacy requests within 30 days.
What we collect
Information you give us when you create an account
- Your name and email address, and a securely hashed version of your password if you sign up with one.
- If you sign in with Google or Apple, we receive your email address, your name, and (from Google) your profile picture. If you use Sign in with Apple and choose to hide your email, we only ever see Apple’s private relay address.
Information you create while using Nikki
- Journal entries, and the AI corrections, explanations, and writing suggestions generated from them.
- Flashcards you create or save, including the sentence a card came from, plus your review history.
- Lesson answers — including written answers that are sent to an AI model for grading — along with saved phrases, your progress through scenarios, and which grammar points you have met.
- Vocabulary and mistake records extracted from your entries, which contain the sentences those came from.
- Settings and preferences: your target JLPT level, tutor tone, daily goal, theme, reminder schedule, timezone, interests you tell us about, and an optional self-declared gender used to shape how the tutor addresses you. Gender is optional and defaults to “Prefer not to say.”
- Feedback and bug reports you submit, including the text you write.
Information collected automatically
- Device and app information: device type, operating system, app version, and language or locale.
- IP address, which we store against your active sign-in sessions and use for rate limiting and abuse prevention. Your IP is also recorded in the compliance record we keep when an account is deleted.
- Usage events: which screens you open and which features you use, so we can find broken flows and understand what is worth building. These events are deliberately stripped of the text you write — see How AI processing works.
- Error and crash reports, including diagnostic information about what the app was doing when something failed.
Voice
Nikki uses your microphone in two optional places, and they handle your audio differently. Both only run when you start them.
Dictating a journal entry. On the website, your recording is uploaded to OpenAI’s Whisper speech-recognition service to be transcribed, then discarded by us — we do not store the audio. In the mobile apps, your phone’s own built-in engine does the transcribing (Apple’s on iOS, Google’s on Android) and no audio reaches our servers.
Speaking practice in lessons. Your recording is never sent to us at all. Recognition is done where you are: by your phone’s built-in engine in the mobile apps, and by your browser’s on the website. What that means for the audio itself depends on the browser — Safari recognizes speech on your device, while Chrome sends the audio to Google’s servers as part of how its engine works, under Google’s privacy policy. Firefox has no speech recognition, so speaking practice is unavailable there.
Only the resulting text reaches us, and only so it can be compared against the line you were asked to say. Neither the recording nor the transcript is kept once that comparison is done.
Payment information
We never see or store your card details. Subscriptions bought on the website are handled by Stripe; subscriptions bought in the mobile apps are handled by Apple or Google through RevenueCat. We receive only the subscription status, plan, and renewal date needed to unlock paid features.
How AI processing works
This is the part of Nikki most worth understanding, because it is unavoidable: giving you feedback on your Japanese requires sending what you wrote to an AI model.
When you request feedback on a journal entry, ask for writing help, submit a written lesson answer, or look up a word in context, the relevant text — which for journal feedback is the full entry — is transmitted to a third-party AI provider, which returns the correction or explanation you see. Journal feedback is stored in our database, encrypted, so you can revisit it later.
What we promise
- We do not use your writing to train AI models.
- Your writing is never sent to our analytics tools. We record that an AI request happened, which model served it, how long it took, and what it cost — never the text of the prompt or the reply.
- We do not sell it, and we do not use it for advertising.
What we cannot promise
Once your text reaches an AI provider, it is handled under that provider’s own terms, which we do not control. Providers typically retain content sent to their API for a short period for abuse monitoring. Every provider we are able to use is listed under Who we share data with, and we will update this page before routing your content anywhere not named there.
On training, specifically. Providers differ here, so we route by sensitivity rather than treating all AI work the same.
- Your journal — entries, drafts, translations, writing ideas, and word lookups on your own sentences — goes only to providers whose terms exclude API content from training their models. Today that is OpenAI.
- Everything else — lesson answers and grading, flashcard generation, vocabulary examples, questions you type into Ask, and lookups on shared lesson dialogue — goes to DeepSeek, whose terms do permit using API inputs to improve its models. We are telling you this plainly because it is a real difference, and it is why the journal is kept separate.
If we ever changed where your journal is processed, we would tell you before the change, not after.
There is currently no way to use Nikki’s feedback, tutoring, or grading features with AI processing switched off — the features are the AI. If you would rather your writing were never sent to an AI provider, please do not use those features, and be aware that the journal-feedback and lesson-grading parts of Nikki will not be useful to you.
Why we use your data, and our legal basis
UK and EU law requires us to have a specific lawful reason for each way we use your data. Here they are.
| What we do | Why | Legal basis |
|---|---|---|
| Run your account and the learning features | To give you the service you signed up for — saving entries, generating feedback, tracking progress | Performance of our contract with you |
| Process subscription payments | To take payment and unlock paid features | Performance of our contract with you |
| Send service emails | Account verification, password resets, trial and billing notices | Performance of our contract with you |
| Send optional reminders | To nudge you to write, if you switch reminders on | Your consent, withdrawable in Settings at any time |
| Security, rate limiting, and abuse prevention | To keep accounts safe and stop automated abuse and trial farming | Our legitimate interests in protecting the service |
| Product analytics and crash reporting | To find broken flows, fix crashes, and decide what to build | Our legitimate interests in improving the service |
Where we rely on legitimate interests, we have considered whether our reasons are outweighed by your privacy — which is why analytics events exclude the text you write. You can object to processing based on legitimate interests; see Your rights.
Who we share data with
We do not sell your data. We share it only with the service providers that make Nikki work, listed here in full. Each is bound by contract to protect your data to a standard equivalent to this policy, and to use it only to provide their service to us.
| Provider | What they receive |
|---|---|
| Vercel (hosting) | All web traffic, including IP addresses in server logs |
| Prisma (database hosting) | Everything stored in your account, encrypted where noted below |
| OpenAI (AI processing) | Everything from your journal — entries, drafts, translations, writing ideas, and word lookups on your own sentences — plus web voice recordings for transcription |
| DeepSeek (AI processing) | Everything else: lesson answers and grading, flashcard generation, vocabulary examples, questions you type into Ask, and lookups on shared lesson dialogue. Never your journal. |
| Anthropic, OpenRouter (standby) | Nothing, unless a provider above is unavailable |
| PostHog (product analytics, US) | Usage events, crash reports, and session replays, linked to your account ID — never the text you write |
| Sentry (crash reporting, US) | Crash and error reports: stack traces, device and app version, and the screens you visited beforehand, linked to your account ID — never the text you write |
| Stripe (web payments) | Your email address and account ID |
| RevenueCat (mobile purchases) | Your account ID only — no name or email |
| Resend (email delivery) | Your email address and the content of service emails |
| Apple, Google (sign-in) | Authentication only — they confirm your identity to us |
| Expo (mobile app updates) | Device and app version information when checking for updates |
A note on AI providers. We deliberately split this. Your journal — the most private thing in Nikki — is handled only by providers whose terms forbid using it to train their models, and DeepSeek is not one of them. Everything else runs on DeepSeek, which costs us less and keeps Nikki affordable. This split is enforced in our code, not just by policy: a journal request that cannot reach an approved provider fails rather than falling back to one that isn’t. See Where your data goes and the note on training above.
We may also disclose data if we are legally required to, or where necessary to investigate suspected abuse, fraud, or threats to someone’s safety.
Where your data goes
Nikki is operated from, and its data is stored in, the United States. Most of the providers above process data in the United States or the European Union.
One case is worth stating plainly. DeepSeek is based in China and processes data on servers there, under laws that offer weaker protection against government access than UK or EU law; China has no UK or EU adequacy decision.
DeepSeek handles your lesson answers and grading, flashcard generation, vocabulary examples, and word lookups on shared lesson dialogue. It does not handle your journal, drafts of it, or lookups on sentences from your own entries — those go to OpenAI and cannot fall back to DeepSeek. If you would rather no part of your writing were processed in China, you can still use the journal; it is unaffected.
If you are in the UK, EU, or EEA, transfers of your data outside your region are made under the UK International Data Transfer Agreement or the European Commission’s Standard Contractual Clauses, which contractually oblige the recipient to protect your data to your home standard. You can ask us for details at support@nikki-ai.app.
How long we keep things
| Data | Kept for |
|---|---|
| Your account and everything in it | Until you delete your account. We do not expire inactive accounts. |
| A deleted account | Erased permanently 30 days after you request deletion. During those 30 days it is hidden and recoverable if you change your mind. |
| Deletion records | Kept after erasure as proof that we honoured your request. Contains your email address, IP address, and the date — nothing you wrote. |
| Sign-in sessions | Until they expire or you sign out |
| Analytics events | Up to 7 years |
| Session replays | 30 days |
| Database backups | Deleted data persists in encrypted backups until they rotate out, normally within 30 days of erasure |
How we protect your data
All traffic between your device and our servers is encrypted in transit (HTTPS). Beyond that, we apply an extra layer of encryption inside the database itself so that the most sensitive things you write are unreadable even to someone holding a copy of the database or a backup file.
Encrypted in the database (AES-256-GCM): journal entry text, AI corrections and feedback, writing suggestions and prompts, and AI tutoring session content including your practice answers.
Not covered by that extra layer, and stored as ordinary database records: flashcards, the vocabulary and mistake records extracted from your entries (which contain sentences you wrote), saved lesson phrases, lesson progress, and feedback reports. We are telling you this because a vague claim that “your data is encrypted” would be misleading.
Other measures:
- Passwords are stored as bcrypt hashes and can never be read back, by us or anyone else.
- Mobile sign-in tokens are held in your device’s secure hardware store (iOS Keychain, Android Keystore), and only as one-way hashes on our servers.
- Session replays mask all on-screen text and images before recording, so replays show layout and interaction, not what you wrote. Replay is switched off entirely in the mobile apps. Note that browser console messages are captured with web replays for debugging.
No system is perfectly secure, and we cannot guarantee absolute security. If we discover a breach affecting your personal data, we will notify you and the relevant regulator as required by law.
Your rights and how to use them
What you can do right now, inside Nikki
- Delete your account. Settings → Delete my account, on the website or in the mobile apps. Your account is hidden immediately and permanently erased after 30 days.
- Clear your data but keep your account. Settings offers a reset that removes your entries, flashcards, and progress while leaving your login intact.
- Download your writing. Export your journal entries and flashcards as spreadsheet files from Settings on the website; the mobile apps link you there from Settings → Download your writing. This is free and available on every plan.
- Correct your details and change your preferences in Settings.
- Turn reminders off at any time in Settings.
- Delete feedback you submitted from the feedback privacy page in Settings.
Your legal rights
If you are in the UK, EU, or EEA, you have the right to access your data, correct it, have it erased, restrict or object to how we use it, receive a portable copy, and withdraw consent at any time. If you are in California, you have the right to know what we collect, to delete it, to correct it, to opt out of sale or sharing, and not to be treated worse for exercising those rights. We do not sell personal information or share it for cross-context behavioural advertising, and we have not done so in the past twelve months.
The self-serve tools above cover most of these. For anything they don’t — including a complete copy of everything we hold, such as your lesson and grammar records — email support@nikki-ai.app and we will respond within 30 days, free of charge.
If you are unhappy with how we have handled your data, you can complain to your data protection authority: in the UK, the Information Commissioner’s Office; in the EU or EEA, your national supervisory authority.
Children
Nikki is not intended for children. You must be at least 13 years old to create an account, and at least 16 if you are in the European Economic Area, where 16 is the age at which you can consent to online services on your own.
We do not knowingly collect personal data from children below these ages. If you believe a child has created an account, email support@nikki-ai.app and we will delete the account and its data promptly. Parents and guardians may contact us at the same address to ask about, or request deletion of, a child’s data.
Cookies and on-device storage
We keep this deliberately minimal. We use no advertising or cross-site tracking cookies.
- Essential cookies keep you signed in and protect forms against cross-site request forgery. Nikki cannot work without these.
- Analytics cookies set by PostHog let us count visits and follow a session across pages. If you visit from the EU or UK, these load only after you accept them in the cookie banner; you can decline, and the rest of the app still works.
- Browser storage holds your display preferences — text size, theme, filters — and an anonymous identifier used before you sign in.
- Mobile app storage holds your sign-in tokens in your device’s secure store, plus offline copies of your cards and lesson progress. If you write something while offline, it stays on your device until it can be sent.
You can clear cookies and site data through your browser settings, and remove everything the app stored by deleting the app. Blocking essential cookies will stop you being able to sign in.
Changes to this policy
If we change how we handle your data, we will update this page and change the date at the top. For changes that meaningfully affect you — a new category of data, a new kind of provider, a new purpose — we will tell you in the app or by email before the change takes effect.
Questions, requests, and complaints all go to the same place: support@nikki-ai.app.