1. Scope and controller
This policy applies to the Vokai Android application, its vocabulary-learning API, and this website. Vokai is operated by DoubleStick UG (haftungsbeschränkt), Germany, which is the controller for Vokai's processing of personal information.
Vokai is a daily vocabulary app with optional advertising and an optional third-party offerwall. The current release is intended for adults aged 18 and older.
Current reward status: eligible coins can optionally be redeemed for third-party digital gift cards inside the app, subject to the minimum balance, verification, holds, and limits described in the Terms of Use. Coins are not cash, cannot be purchased, and cannot be sold or transferred to other users. Redemption requires a verified email address; if you never use redemption, Vokai does not ask for an email address.
2. Data we process
Account and server learning records
Vokai creates a pseudonymous API account rather than asking for a name, phone number, or account email. The Cloudflare Worker and D1 database may store the account identifier, selected native and learning languages, goal and difficulty choices, session dates, quiz facts, responses and response times, earned points, streak and review state, offer credits, and technical anti-abuse records.
The API issues an authentication credential for account operations. The app stores that credential in the operating system's encrypted SecureStore, not in ordinary app preferences. Vokai uses separate provider-specific aliases for supported advertising and offer callbacks instead of sending the raw API account identifier to those providers.
Learning and preference data kept locally
Detailed recent lesson history, mastery state, missed-card review, quests, XP, streaks, points, display name, avatar, theme, audio settings, analytics choice, notification settings, and similar learning preferences are stored locally on your device. Some progress fields are also sent to the API so the service can validate sessions and preserve server-authoritative totals.
The Android word-of-day widget stores a small upcoming-word set locally. Reminder and word-of-day notifications are scheduled locally after you enable them; Vokai does not operate a remote push-notification profile for these reminders.
Advertising and consent information
Google AdMob may automatically process and share IP address (which may estimate general location), device and app information, device or account identifiers where available, consent signals, product interactions such as app launches, taps, and video views, ad impressions, reward verification data, and SDK diagnostics such as app launch time, hang rate, and energy usage for advertising, analytics, and fraud prevention. Google User Messaging Platform (UMP) is used where required. Vokai's ad-request path fails closed: if UMP errors or does not confirm that ads may be requested, Vokai does not request ads.
Optional Offers
Tapjoy is contacted only when you explicitly open the in-app offerwall labeled "Offers." Opening it is optional and is not required to learn. Tapjoy receives a provider-specific alias, not the raw Vokai API account identifier, and may process device and app information, IP-derived general location, locale, advertising identifiers where permitted, page views, taps, other offerwall actions, other app-performance data, and offer-view or completion events for analytics, fraud prevention and security, personalization, and advertising. Tapjoy sends server-to-server completion callbacks so Vokai can credit non-cashable points.
If you voluntarily submit a Tapjoy offerwall customer-support ticket, Tapjoy requires an email address for correspondence and receives the messages exchanged with support. Tapjoy may also record a CPA purchase conversion if an offer requires a purchase. Each advertised offer is controlled by its advertiser and may ask for additional information under that advertiser's own terms. Vokai does not receive payment-card or banking details from those offers.
Release control: Vokai will not publish a Tapjoy-enabled production build until the app supplies the required regional privacy choices to Tapjoy before connection and provides an effective withdrawal or opt-out path. A production build without those controls must keep Offers unavailable.
Optional gift-card redemption (cashout)
If you choose to redeem eligible coins for a digital gift card, Vokai collects and processes additional data that is never requested otherwise: the email address you provide for redemption, an email-verification code exchange, the redemption request itself (brand, amount, timestamps, and status), a server-side ledger of earned, spent, reserved, and redeemed value, and technical anti-abuse records such as rate-limit counters and an install-binding entry that limits how many accounts may redeem from one app installation.
Two processors are used only for this feature. Resend delivers the verification email to the address you enter. Reloadly issues the gift card and receives the delivery email address, the card brand and value, and order metadata needed to fulfil and audit the order. The gift card itself is a product of its issuing brand and is governed by that issuer's own terms. Vokai does not collect payment-card or banking details for redemption.
Redemption data is used to verify eligibility, deliver the card, prevent duplicate or fraudulent payouts, satisfy bookkeeping and tax obligations, and handle disputes. Requests may be checked against velocity, device, and account-integrity signals before fulfilment.
Optional analytics and attribution
PostHog and Tenjin are optional and begin only after you opt in to analytics. The choice is off by default for migrated accounts and is revocable at any time in Profile. PostHog may receive coarse app events such as onboarding completion, feature use, and ad or offer availability. Tenjin may receive install, app-open, device, advertising-identifier, and campaign-attribution information. When you revoke consent, Vokai opts out and resets the provider profile where the SDK supports it; no new Vokai analytics events are sent while the choice is off.
Crash diagnostics
The current release includes the Sentry software library but has no Vokai Sentry project endpoint configured, and automatic native initialization is disabled. It therefore does not send crash reports to Sentry. If a future version enables crash reporting, this policy will be updated before that version is distributed.
Website data
This static website contains no analytics or advertising scripts and sets no application cookies. The hosting provider may process standard delivery logs, such as IP address, requested path, browser information, and timestamp, for security and reliable delivery.
3. How data is used
- Provide vocabulary lessons, audio, quizzes, review, streaks, quests, points, and progress.
- Authenticate account operations and keep the app and API in sync.
- Schedule optional local notifications and update the optional Android widget.
- Show consented advertising, verify rewarded-ad completion, and prevent duplicate rewards.
- Open and personalize the Tapjoy offerwall at your explicit request, support offer-related requests, prevent abuse, and credit completed offers.
- Verify a redemption email address, fulfil gift-card redemptions, maintain the redemption ledger, and prevent duplicate or fraudulent payouts.
- Measure app use and acquisition only after analytics opt-in.
- Diagnose crashes using scrubbed reports when Sentry is configured.
- Detect abuse, secure the service, meet legal duties, and process deletion requests.
Where applicable, Vokai relies on performance of the service you request, legitimate interests in security and service integrity, compliance with law, and consent for optional analytics, attribution, advertising, or device permissions.
4. Service providers and disclosure
Vokai does not sell personal information. Data is disclosed only as needed to operate the requested feature, protect the service, comply with law, or complete a business transfer subject to appropriate safeguards.
| Provider | Role and activation | Typical data |
|---|---|---|
| Cloudflare | Hosts the static site, Worker API, and D1 learning database. | API account and progress records; delivery and security logs. |
| Google AdMob / UMP | Consent management and ads; requests fail closed when permission is unavailable. | Consent signal, IP-derived general location, device/app identifiers, product and ad interactions, SDK diagnostics, and provider alias for reward verification. |
| Tapjoy | Only after you explicitly open Offers; support details only if you submit a ticket. | Provider-specific alias, device/app data, IP-derived general location, identifiers, page views, taps, other offerwall actions and performance data, offer events, optional support email and messages, and CPA purchase conversions. |
| Reloadly | Issues digital gift cards only when you request a redemption. | Delivery email address, gift-card brand and value, order identifiers and status. |
| Resend | Sends the email-verification message only when you start a redemption. | Email address and verification message content. |
| PostHog | Optional product analytics only after opt-in. | App events and coarse feature properties. |
| Tenjin | Optional install attribution only after opt-in. | Install/open, device, campaign, and advertising-identifier data where permitted. |
| Sentry | Library present but runtime crash reporting disabled in the current release; no Vokai project endpoint. | No crash data transmitted. |
5. Your choices and rights
- Analytics and attribution: use the Analytics switch in Profile. PostHog and Tenjin remain off until opt-in and stop after revocation.
- Advertising: use Google's consent or privacy-options screen when available, and manage the Android advertising identifier in device settings. If Vokai cannot establish permission to request ads, ads remain off.
- Offers: a Tapjoy-enabled public version must present the applicable offer privacy choice before connecting and provide a withdrawal or opt-out path. Until those controls are available, Offers remains unavailable in production. Do not submit an offerwall support ticket if you do not want Tapjoy to receive your email address and support messages.
- Gift-card redemption: redemption is optional. Vokai asks for an email address only when you start a redemption; declining simply leaves redemption unused. A verified redemption email can be reviewed before each request, and deleting the account removes the live address from the account record.
- Notifications: decline the permission request, turn reminders off in Vokai, or revoke notification permission in Android settings.
- Local widget: remove the Vokai widget from your home screen. Deleting Vokai data also clears its local widget data.
- Access, correction, portability, objection, restriction, and deletion: contact support. The available right depends on your location and whether Vokai can verify the pseudonymous account without collecting excessive new data.
- Withdraw consent: you may withdraw consent at any time without affecting processing that was lawful before withdrawal. Use the Analytics switch for PostHog and Tenjin, Google's privacy-options screen for AdMob, the dedicated Offers control in any future Tapjoy-enabled public version, or contact support.
- Lodge a complaint: you may complain to the data-protection authority where you live or work, where an alleged infringement occurred, or to the Berlin Commissioner for Data Protection and Freedom of Information.
6. Retention and deletion
Local learning state remains on the device until you delete it, clear app storage, or uninstall. Server learning records remain while the pseudonymous account is active and for only as long as needed for the purposes above, security, dispute handling, and legal obligations. Provider retention is governed by each provider's service rules.
In-app deletion sends an authenticated deletion request, then clears the SecureStore credential, local learning state, install identifier, notification state, widget data, analytics identity, Tenjin profile, and Tapjoy binding after the server confirms deletion. Vokai deletes the live account and associated progress.
For retry and replay safety, the deletion system may keep a brief unlinkable idempotency receipt that confirms a request was already completed. Where gift-card redemptions occurred, Vokai retains the minimum redemption and ledger records required for bookkeeping, tax, fraud prevention, and dispute handling for the legally required period. Those limited records are stripped of live account credentials and are not used to restore the account.
See the account deletion page for the in-app route, support-assisted verification, and timing.
7. Security and international processing
Vokai uses transport encryption, authenticated API requests, SecureStore for the credential, provider-specific aliases, disabled crash reporting, and access controls appropriate to a small production service. No system can guarantee absolute security.
Providers may process information outside Germany or the European Economic Area. When required, Vokai uses provider contracts, consent, or another permitted transfer mechanism. Contact support for questions about a specific transfer.
8. Age and children
Vokai is intended only for people aged 18 or older and is not directed to children. Do not use Vokai if you are under 18. Contact us if you believe a child has provided information so we can investigate and delete it where appropriate.
9. Changes and contact
Vokai may update this policy as the service, providers, or law changes. The effective date above will change, and material changes may also be presented in the app before they take effect.
Controller: DoubleStick UG (haftungsbeschränkt)
Address: Urbanstr. 182, 10961 Berlin, Germany
Privacy and support: support@doublestick.ai
Phone: +49 176 55374207
Account deletion: https://vokai-legal.pages.dev/delete-account/
Company details: Impressum