Privacy policy
Moguru is an app that turns Japanese text you read into flashcards. This policy explains what information the app collects, why, who helps us process it, how long we keep it, and how you can delete it. We've tried to write it plainly. We only collect what the app needs to work and to help us improve it.
1. Summary
- You can use Moguru without giving us your name or email. The app creates an anonymous account for you automatically.
- When you capture a photo or paste text, it goes to our server so an AI model can pick out vocabulary. Your photo and text are deleted as soon as your cards are made. Only one short sentence per card is kept. We never store pages.
- Your decks, cards and review history are stored on your device and backed up to our database so they survive a reinstall.
- We don't sell your data, and we don't show ads.
- You can permanently delete your account and server data at any time in Settings → Delete account.
2. Information we collect
a. Account identifiers
- Anonymous user ID. When you first use the app we create an anonymous account with a random identifier. It isn't linked to your name, email or phone number.
- Google account (if you choose to sign in with Google). [Applies once Google sign-in launches.] If you sign in with Google, we receive your Google account's email address, name and a Google account identifier so we can link your data to that account and restore it on another device. We don't receive your Google password.
b. Content you capture
- Photos you take with the camera or choose from your gallery, and text you paste. We use these only to generate a vocabulary deck (section 3). Before upload, the app resizes and compresses photos on your device. Text is limited to 4,000 characters and images to 4 MB.
- We only ask for camera access when you choose to take a photo. We only access the photos you pick from your gallery.
c. Your study data
- Decks and cards: the deck title (which you can rename, for example to the book you're reading), and for each card the word, its reading, an English meaning (which you can edit), and one short sentence from your source text that the word appeared in, trimmed to about 60 characters around the word. This is the only part of your original text we keep. We don't keep the order of sentences or where they appeared on the page, so saved sentences can't be put back together into the original text. When you delete a card (or remove a word before saving a deck), its sentence is deleted too.
- Words you add yourself: if you add a word by typing it or tapping it, we store it as a card like any other. If you include the sentence it came from, we keep only about 60 characters of it around the word, and we use it once to write a meaning for that context.
- Full page view (temporary): right after a scan you can open the whole page to tap words. For pasted text, the page stays on your device. For a photo, the photo is sent to our server once more to be transcribed and the text is sent back to your device. Neither the photo nor the page text is stored: the text exists only on your screen until you save the deck or leave it.
- AI study extras: if you ask for an explanation of a card's sentence, or when example sentences are written for your cards, we store them with the card. Example sentences are newly written by the AI; they don't come from your source.
- Review history: for each review, the card, the rating you gave (Again/Hard/Good/Easy), the card's learning stage, the date and the time. This powers scheduling, streaks, badges and stats.
- Learning settings: your chosen JLPT level, new cards per day, and daily reminder time (if you set one).
- Usage counters: how many captures you've made each week (for the free-tier limit), plus the AI processing cost and token counts for each generation. We use these for billing limits and cost control.
d. Product analytics
If analytics is enabled in the build you're using, the app sends a small set of usage events to our analytics provider (PostHog). They're linked to your anonymous user ID:
onboarding completed (with your level and daily goal), capture started, deck generated (card count, processing time, cost), deck saved, capture failed/empty/limit reached, review session completed (cards reviewed, duration), badge earned, and, once subscriptions launch, paywall viewed, trial started and purchase completed (plan and price).
Each event also includes your device's operating system and the app version. Events never contain your photos, your text or the words on your cards. We ask the analytics provider not to derive your location from your IP address. You can turn analytics off at any time in Settings → Share anonymous usage data.
e. Purchases [applies once subscriptions launch]
If you subscribe, Google Play processes the payment. We and our subscription provider (RevenueCat) receive the purchase details: product, price, dates, subscription status, and a purchase token tied to your user ID. We never receive your card number or other payment details.
f. What stays only on your device
Your appearance setting (light/dark), earned-badge dates, and a local copy of your decks, cards and review history are kept on your device. Daily reminders are local notifications scheduled on your phone. We don't use push-notification servers, and we don't collect a push token.
We don't collect your contacts, precise location, microphone, SMS, or advertising ID.
3. How we use information
| Purpose | Information used |
|---|---|
| Generate flashcards from a capture | Photo or text, your JLPT level, and a list of words already in your decks (so they aren't repeated) |
| Store, sync and restore your decks and review progress | Account ID, study data |
| Schedule reviews, streaks, badges and stats | Review history (processed on your device) |
| Enforce the free weekly capture limit | Usage counters, subscription status |
| Understand which features work and fix problems | Analytics events, processing cost/latency logs |
| Provide subscriptions | Purchase records [once launched] |
| Respond to your requests | Your email, if you contact us |
We don't use your data for advertising, and we don't sell or rent it to anyone.
4. How AI is used
To pick vocabulary, our server sends your photo or text, your JLPT level and up to 500 of the words already in your decks to Anthropic's Claude API. The model returns suggested words, short in-context meanings, the sentences they came from, and a deck title. Readings don't come from the AI. Every word is looked up in the JMdict dictionary, and words that aren't found are dropped. When you ask for an explanation, translation or example sentences, we send only the card's word, meaning and its one stored sentence (or the single sentence you tapped), never a page.
Anthropic processes this data as our service provider under its commercial terms. Under those terms, Anthropic does not use API inputs or outputs to train its models. Anthropic may keep API inputs and outputs for a limited period for safety and abuse monitoring, as described in its commercial terms, after which they are deleted. AI output can be wrong, so check meanings before relying on them. You can edit any meaning in the app.
5. Service providers (processors)
We use these companies to run Moguru. They process data only on our instructions and only to provide their service to us.
| Provider | What it does | Data it handles | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage and server functions | Account ID (and Google email/name if you sign in), study data, usage counters; photos and text briefly during processing | United States (US East) |
| Anthropic | AI model that picks vocabulary | Photo or text, JLPT level, list of known words | United States |
| PostHog | Product analytics (only if enabled) | Analytics events, anonymous user ID, OS, app version, IP address | United States (us.i.posthog.com) |
| Google (Google Sign-In) [once launched] | Sign-in | Google account email, name, account ID | Global |
| Google Play and RevenueCat [once launched] | Payments and subscription management | Purchase records, user ID | Global / United States |
If you're outside the United States, your information will be transferred to and processed in the United States. [If you serve EEA/UK users, name your transfer mechanism here, such as the Standard Contractual Clauses in each provider's data processing agreement.]
6. How long we keep it
| Data | Retention |
|---|---|
| Captured photos | Deleted from storage as soon as generation finishes, whether it succeeded or failed (usually within a minute) |
| Pasted text | Cleared from our database as soon as generation finishes, whether it succeeded or failed |
| The source sentence for each card (about 60 characters at most) | Kept with the card; deleted when you delete the card, deck or account |
| Explanations and example sentences | Kept with the card; deleted with it |
| Decks, cards, settings | Until you delete them or your account |
| Review history (ratings and dates only) | Until you delete your account. Deleting a deck doesn't remove past review records, so your streaks and stats stay intact. |
| Capture records (type, status, timestamps; no content), usage counters, AI cost logs | Until you delete your account |
| Analytics events | Up to [ANALYTICS RETENTION, e.g. 12 months] in PostHog |
| Purchase records [once launched] | As long as required for tax and accounting law, even after account deletion |
When you delete a card, it's marked deleted and hidden, and the server copy stays marked deleted until you delete your account. When you delete a deck, the deck and its cards are removed from our database.
7. Your choices and rights
- Delete your account: Open Settings → Delete account in the app. This permanently deletes your account and all associated server data: profile, captures, decks, cards, review history, usage counters, AI cost logs, and any capture image still in storage. The app also erases its local copy on your device. It can't be undone.
- Delete without the app: If you've uninstalled the app, request deletion at https://moguru.app/delete-account or email help@gruuw.com with your user ID or Google account email. We'll process it within [30] days.
- Analytics data: Deleting your account doesn't automatically remove past analytics events from PostHog. Email us and we'll delete them.
- Notifications and camera: You can turn reminders off in Settings, and revoke camera or notification permission in your phone's settings at any time.
- Access and correction: You can see and edit your study data in the app. Email us if you want a copy of your data.
Depending on where you live (for example the EEA, UK or California), you may have rights to access, correct, delete, restrict or object to processing, and to data portability. You can also complain to your local data protection authority. Email help@gruuw.com to exercise any of these rights. We don't sell or "share" personal information for cross-context behavioural advertising as defined by California law.
[If relying on GDPR: our legal bases are performance of a contract (providing the app), legitimate interests (analytics, security, cost control), and consent where required.]
8. Security
All data sent between the app and our servers is encrypted in transit using HTTPS/TLS. Our database uses row-level security, so each account can only read its own rows. Captured images sit in a private storage bucket that only our server functions can access. No system is perfectly secure, but we work to protect your information.
9. Children
Moguru is not directed at children under 13 (or the minimum age in your country), and we don't knowingly collect personal information from them. If you believe a child has given us information, contact help@gruuw.com and we'll delete it.
10. Changes
If we change this policy, we'll update the effective date above. If a change is significant, such as a new category of data or a new processor, we'll also let you know in the app before it takes effect.
11. Contact
Gruuw Pte Ltd [POSTAL ADDRESS (required for some regions)] Email: help@gruuw.com
*Moguru uses the JMdict dictionary from the Electronic Dictionary Research and Development Group (EDRDG), under the Creative Commons Attribution-ShareAlike 4.0 International licence.*