Privacy Policy
Last updated: September 6, 2026
JLPT Vocab: Learn Japanese N5+ is developed and operated by Optimum Tech ("we", "us"). This policy explains what personal data we collect, why, and your choices. It applies to all versions of the App (Android, iOS, web) and our backend service.
1. Data we collect
Account data
When you register we collect your username, email address, a password (sent over TLS and stored as a bcrypt hash, not as plaintext), your nationality as a country code (used for national leaderboards), and your time zone (used to calculate daily streaks). With Google Sign-In we receive your Google account ID, email address and display name instead of a password; we never receive your Google password. Google may include a profile-photo URL in the identity response, but we do not save it or use it as your avatar. Your Google display name may be your real name; we do not separately ask for a legal name, phone number, postal address, date of birth or government identifier.
Profile and learning-progress data
Stored so the app works across devices: level, experience points, in-app currency balances, current and best study streaks, daily activity calendar, region/prefecture progress and quiz scores, vocabulary/grammar/sentences you marked as learned plus review timestamps, handwriting-game attempts, and cosmetic items purchased with in-app currency.
Social and community data
Your friend list, direct messages between friends (length-capped, profanity-filtered, stored temporarily and intended for the participants), chat-room and community-feed posts, and your username and score shown on public leaderboards.
Support data
If you contact support in the app, we process your username, email address and message content to respond. Conversations are stored temporarily and then deleted.
Device and technical data
A push-notification device token if you enable notifications (removed when you log out). We use IP addresses during registration and login to check an abuse blocklist. Hosting and network services may also process IP addresses and request metadata to deliver and secure the service. Application request logs record method, path and status; they do not record message bodies.
2. Third-party services
Google AdMob serves Android banner, interstitial and rewarded ads and processes device identifiers, IP addresses, and ad-interaction data. The web app may display Google AdSense ads when enabled, which may use cookies and similar identifiers. Where consent is required (EEA/UK), Google's consent form lets you choose personalised or non-personalised ads; revisit it any time via Settings → Privacy options.
Firebase Cloud Messaging delivers push notifications only. We do not use Google Analytics or Crashlytics.
Google Sign-In handles optional sign-in; we store only your account ID, email and display name.
Google Play Billing processes subscriptions and coin-pack purchases. We send purchase tokens to Google to verify purchases. We store subscription status, purchase history and a receipt prefix for subscription auditing; coin purchases use a token hash to prevent duplicate fulfillment. We do not receive your complete payment-card details.
3. How we use your data
To operate your account and sync learning progress across devices
To provide social features you choose to use (friends, chats, leaderboards)
To deliver push notifications you opted into and to verify purchases
To detect and prevent abuse (login blocklist, rate limiting, moderation, content reports)
To respond to support requests
We do not sell your personal data.
Google user data: access, use, and sharing
Google Sign-In is optional; email-and-password registration is also available. We receive a Google ID token and validate it with Google. The identity response includes your account identifier (sub), email address, email-verification status, display name and potentially a photo URL, plus token validity information. We store your Google account identifier, email and display name to create or link your JLPT Vocab account and sign you in. Your display name becomes the initial app username and can therefore appear in community features and leaderboards; you can change it in your profile.
We request basic sign-in identity only. We do not request access to Gmail, Google Drive, Calendar, contacts or other Google Workspace content. We use Google identity data only to provide account creation, account linking, authentication and the associated user-facing profile. We do not sell Google user data, use it for advertising or credit decisions, or use it to train AI or machine-learning models. We do not pass your Google identity data to advertising services.
We share the sign-in token with Google to validate it. Our hosting and infrastructure providers process data needed to operate the service; authorized operators may access account records to support users and secure the service. Other users can see information you make public through the app, such as your username and community posts, but we do not publish your Google email or account identifier. Data may also be disclosed when required by law. JLPT Vocab's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
4. Data storage, retention, and security
Databases run on our own servers (MySQL/MariaDB plus Redis for temporary data such as sessions, chats, leaderboards, and support threads — these carry automatic expiry). Passwords are bcrypt-hashed; traffic is encrypted with TLS; admin accounts are separate from user accounts.
We retain account information, including the Google account identifier, email and display name, and learning and purchase records while your account remains active so that sign-in, progress syncing and purchases continue to work. Temporary sessions, chats and support records expire according to the service retention settings; activity can extend those periods. For example, friend-message threads expire after seven days of inactivity by default.
Account deletion: you can delete your account from within the App (Settings → account deletion, re-authentication required), or — without the app installed — from our web version's Delete account page (#delete-account), where we email you a confirmation code first. Account deletion takes effect immediately: it removes your account and linked records from the active database. Temporary caches, shared messages and operational backups may remain until they expire or are rotated; deletion is not an immediate purge of every backup or message copy. Contact us for help with remaining personal content. Deleting your account does not cancel a Google Play subscription; cancel it in Google Play. You may also request deletion by emailing us.
The app stores authentication tokens, preferences and downloaded learning data on your device or in browser storage. Logging out clears account-session data; preferences or cached content may remain. Clear the app or browser site data to remove remaining local data. You can remove the Google connection in your Google Account connections settings; this does not itself delete your JLPT Vocab account or existing stored data. Use account deletion or contact us to request deletion.
5. Children's privacy
The App is a Japanese-language test-preparation product intended for teens and adults. It is not directed at children under 13, does not knowingly collect their data, and does not collect dates of birth. Contact us if you believe a child under 13 has created an account and we will delete it.
6. Your rights
Depending on where you live (e.g. EU/EEA under GDPR, UK, California under CCPA) you may have rights to access, correct, export or delete your personal data, object to processing, or withdraw consent. Delete your account and data in the app or email us; change ad-personalisation consent via Settings → Privacy options; log out to remove your push-device token. For anything else, email us and we will respond within 30 days.
7. Changes to this policy
We update this page when the policy changes and revise the date above. Material changes affecting previously collected data are announced in the App before taking effect.
8. Contact
Optimum Tech — [email protected]. You can also reach us through the in-app support form (Settings → Support).
Useful links
Request account deletion · Manage your Google connections · Google API Services User Data Policy · Google Privacy Policy