Privacy Policy
Effective date: 4 June 2026
Tenkai (“we”, “us”, “our”) operates the website at https://tenkai.uk (the “Service”). This Privacy Policy explains what information we collect, how we use it, and your rights in relation to it.
1. Who we are
The Service is operated as a personal-scale project. For any privacy question you can reach us at legal@tenkai.uk.
2. Information we collect
Account information
When you create an account we collect:
- Your email address.
- A username (display name, public).
- A password hash (bcrypt; we never store your plain-text password).
- Optionally — your name and profile picture if you choose to sign in via Google, Apple, or LINE.
Study activity
To provide the Service we record:
- The words and kanji you mark as known, learn, or review.
- Your progress through quiz, exam, and practice questions.
- Your study direction (Japanese ↔ English) and chosen level (JLPT N5–N1 or CEFR A1–C2).
- Your custom decks, lists, notes, and ingested documents.
- Reading sessions and OCR images you upload — images are processed in your browser by default; Google Cloud Vision is optional and the image is ephemeral.
- Sentences, definitions, and feedback you submit (e.g. tribunal flags, custom example sentences).
Technical information
When you use the Service we automatically receive:
- Your IP address — used transiently for rate limiting and abuse detection. Not persisted to long-term storage.
- Browser type and version (User-Agent header). Kept in short-lived serverless logs.
- Your time zone (sent from your browser so streaks calculate against your local midnight).
What we do NOT collect
We do not accept payment information; we do not request access to your contacts, location, microphone, or camera (except when you explicitly choose to upload an image to OCR); we do not run third-party analytics or advertising trackers. The Service has no ads.
3. How we use your information
- Provide the Service: render your dashboard, queue your reviews, track your level, deliver password-reset emails.
- Communicate with you: send account verification, password reset, and important Service notices.
- Protect the Service: rate-limit abusive requests, detect automated traffic, comply with applicable law.
- Improve the Service: aggregated, non-identifying study statistics inform editorial decisions about content.
We do NOT sell your data. We do not share it for advertising. We do not use your individual study activity to train AI models.
4. Legal bases for processing
Where the UK GDPR applies, we process your personal data on these bases:
- Performance of contract — providing the account features you signed up for.
- Legitimate interests — protecting the Service from abuse and maintaining security.
- Consent — for any optional feature you opt into (e.g. ingesting a personal document).
- Legal obligation — retaining minimal records as required by applicable law.
5. Sub-processors and third parties
We use the following service providers to operate the Service. Each is bound by their own privacy policy:
| Provider | Purpose | Policy |
|---|---|---|
| Vercel Inc. | Web hosting and edge delivery | link |
| Neon, Inc. | Postgres database hosting | link |
| Resend, Inc. | Transactional email (password reset) | link |
| Google LLC | Sign-in with Google; YouTube Data API (optional, used by /work creator-discovery); Gemini API (optional, used to rewrite YouTube queries); Cloud Vision OCR (optional); Cloud TTS (optional) | link |
| Apple Inc. | Sign in with Apple (optional) | link |
| LINE Corporation | Sign in with LINE (optional) | link |
| Upstash, Inc. | Distributed rate limiting (optional) | link |
If you do not sign in via a third-party SSO provider, your data is not shared with them.
6. Cookies
We use only first-party cookies necessary for the Service:
- Session cookie — keeps you signed in.
- CSRF token — prevents cross-site request forgery.
- Preferences — your theme (light/dark), language toggle, and romaji-helper toggle.
We do not use cookies for advertising or third-party analytics.
7. Data retention
- Account data — retained while your account is active. Deleted within 30 days of account deletion. Backup copies may persist for up to a further 30 days.
- Anonymous sessions — not persisted to long-term storage.
- Logs — short-lived serverless logs (~24 hours); not retained beyond that.
8. Your rights
You have the right to:
- Access your data — your account page shows your study activity.
- Correct your data — edit your username, email, and preferences on /account or /settings.
- Deleteyour data — the account page has a “Delete account” action.
- Object to processing or restrict processing — contact us.
- Portability — export your decks, known-words, and review history via /settings.
- Withdraw consent — for any optional feature, by turning it off.
- Lodge a complaintwith the UK Information Commissioner's Office (ICO) at ico.org.uk.
To exercise any of these rights, email legal@tenkai.uk.
9. International transfers
The Service uses providers located in the United States (Vercel, Neon, Resend) and Japan (LINE) which may store data outside the UK / EEA. Where required, transfers are protected by Standard Contractual Clauses or equivalent safeguards.
10. Children
The Service is not directed to children under 13. If you believe a child has provided personal information to us, contact us and we will delete it.
11. Changes to this policy
We may update this policy. When we do, we'll change the “Effective date” at the top, and — for material changes — notify signed-in users via an in-app banner.
12. Contact
Privacy questions: legal@tenkai.uk.