Privacy Policy
Last updated: July 27, 2026
The short version
- Everything you do in Kamby is stored in our own database. We do not sell your data.
- No ads, no ad identifiers, no third-party analytics or crash-reporting SDKs. The usage data we collect is ours alone and is used to make the course better.
- You can delete your account from inside the app. It takes your progress, your events and your account with it, straight away.
- No cookies on kamby.app, and no payments anywhere — Kamby is a free beta.
- Questions? Requests? Send an e-mail to: support@kamby.app.
1. Who we are
Kamby is a mobile app for learning the Khmer language. It is free while in beta: there are no payments, no subscriptions and no advertising.
The controller of your personal data is:
- Raphael Saing, ‘micro-entreprise’ from France
- 1 rue Marguerin, 75014 Paris
- SIREN 988 355 111
- Email: support@kamby.app
This policy is governed by French law.
2. What we collect, and why
Account
You sign in with Sign in with Apple or with an email magic link / one-time code, or with an email & password.
- With Sign in with Apple, we may receive the name you choose to share through Apple on your first sign-in. We keep it as your display name.
- With email sign-in, we store your email address.
- Your profile holds your display name (optional), your app language (English or French) and the dates your account was created and updated.
Linking an email address or an Apple ID is what lets your progress survive a lost phone or a reinstall.
Guest accounts. The first time you open the app, we create an anonymous account for you automatically — no email, no name, just a random identifier — so your progress is saved before you decide whether to sign up. You can link an email address or an Apple ID later and keep everything. A guest account that stays inactive for 90 days is deleted, along with its data.
Learning progress
Your progress with the lesson curriculum, your memory strength for each word, your stats (streaks, activity, timezone).
Usage and diagnostics
We record some in-app events — session starts, errors, sign-in steps. Each event carries your user ID, a session ID that rotates (a new one on every cold start, and after 30 minutes in the background — it is not a device identifier), and the app version. We also collect your device model (a hardware model identifier such as “iPhone14,7”), your OS version, your app interface language (English or French only) and your time-zone offset.
We receive crash and performance diagnostics through Apple’s MetricKit, reduced before they reach us to: the type of crash or hang, a numeric code, and a short technical fingerprint (the app binary name and its hash).
Some structural facts about this:
- There is no free text in an event. The shape of every event is a fixed list of fields.
- The app stores no IP address and no user agent.
- There are no advertising identifiers and no persistent device identifier.
- Events are deleted with your account.
- Raw events are kept for 12 months, then reduced to anonymous aggregate statistics.
We use all of this to improve the course and the app and to diagnose bugs. Nothing else. We do not share this data to third parties.
Feedback reports
When you use “report a problem” in a lesson, you write us a message (required), and we attach a text record of what was on screen: the exercise content shown, the answer you chose, the app version and build, and your app language.
Dictation and the microphone. The report sheet lets you speak instead of typing. The audio is transcribed and then immediately discarded — we never collect it and we never upload it. Recognition runs on your device when your device supports it; otherwise the audio is processed by Apple’s speech-recognition servers, and Apple’s privacy terms apply to that processing. Only the resulting text is saved, as your feedback message. Using the microphone is optional and requires your permission.
Your reports are kept while your account exists. If you delete your account, the report is de-identified: the text and the screen context stay, the link to your account is removed. We keep them because they document fixes we made to the course.
Notifications
If you decide to turn notifications on, we store a push token — a random routing identifier issued by Apple or Google — together with your platform and language, so we can send you reminders such as a streak reminder. Delivery goes through Google Firebase Cloud Messaging. The token is deleted with your account, and turning notifications off in your device settings stops delivery.
Emails we send
We send sign-in emails (magic link or one-time code) and essential account emails, through Resend, our email delivery provider, in your app language (EN/FR).
Website (kamby.app)
kamby.app is a presentation site. No cookies, no analytics scripts, no forms. It is hosted on Cloudflare, which keeps standard short-lived server logs to run and protect the service.
Support
If you email support@kamby.app, we receive whatever you put in your message and use it to answer you.
3. What we never do
- We never sell personal data.
- No advertising, no ad SDKs, no advertising identifiers.
- No third-party analytics or crash-reporting SDKs. Our analytics are ours, in our own database.
- No cross-app tracking.
- No profiling for marketing.
4. Where your data lives
Your data is hosted in the United States. Our providers are bound by data-processing agreements that incorporate the EU Standard Contractual Clauses (SCCs), which is the safeguard we rely on for those transfers. You can ask us for a copy of these safeguards at support@kamby.app.
5. Who helps us run Kamby
| Provider | What they do for us | Where |
|---|---|---|
| Supabase (on Amazon Web Services) | Database, authentication, file storage — where app data lives | USA (us-east-1) |
| Resend | Sending sign-in and account emails | USA |
| Cloudflare | Hosting our website and our internal admin console | Global edge, US company |
| Google (Firebase Cloud Messaging) | Delivering push notifications, only if you enable them | USA |
| Apple | Sign in with Apple; optional speech-to-text for dictated feedback; app distribution | USA |
6. How long we keep things
| Data | Kept |
|---|---|
| Account, profile, learning progress | Until you delete your account |
| Guest accounts | Deleted after 90 days of inactivity |
| Usage events | 12 months, then only anonymous statistics |
| Crash diagnostics | Same as usage events — they live in the same records |
| Feedback reports | While your account exists; de-identified after account deletion |
| Push token | Until you disable notifications or delete your account |
| Sign-in emails | Not retained by us beyond delivery |
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- rectify data that is inaccurate or incomplete;
- erase your data;
- portability — receive your data in a portable format;
- restrict how we process your data;
- object to processing we base on legitimate interest — including our usage analytics and diagnostics;
- withdraw consent at any time, where we rely on consent (notifications), without affecting what happened before.
Automated decisions. We make no automated decisions about you that produce legal effects or similarly significantly affect you, and we do not profile you for marketing.
Deleting your account. In the app, go to Settings → Delete account. This deletes your account and all data associated with it, immediately — with the one exception described above: feedback reports stay, de-identified. You can also email support@kamby.app and we will do it for you.
Exercising the other rights. Email support@kamby.app. We answer within one month.
8. Children
Kamby is not directed at children. You must be at least 13 to use it. In France, users under 15 need a parent or guardian’s permission. If we learn that an account belongs to someone under 13, we will delete it.
9. Changes to this policy
When this policy changes, we post the updated version here and change the date at the top. If a change is material, we will flag it in the app.
10. Contact
Write to us at support@kamby.app — for privacy requests or questions about this policy.