Koko · Privacy
Privacy Policy
Last updated: August 11, 2026
Koko is built to teach Amharic and Afaan Oromo while collecting as little information as practical. Most learning data stays on your device.
At a glance: Koko does not sell personal information, show third-party ads, or track you across other companies’ apps and websites.
1. Scope
This policy explains how Koko (“Koko,” “we,” or “us”) handles information when you use the Koko iOS app, visit hellokoko.app, or contact support. It also explains the choices available to you.
2. Information stored on your device
Koko stores the following locally so the app can work and personalize your learning:
- Your selected language, optional display name, learning motivation, daily goal, and app preferences.
- Lesson progress, scores, streaks, vocabulary review status, reading progress, and words you add through Word Scan.
- Practice Chat continuity as a short semantic state: the scenario step, completed intents, vocabulary identifiers, an unresolved correction category, and turn count. Visible chat turns are kept in memory while the chat is open and are not saved as a transcript.
- A random local learner identifier used to keep device-local records separated and consistent.
Koko’s launch version does not sync lesson progress between devices or browsers. In the iOS app, deleting Koko removes its SwiftData and preference records, subject to normal Apple device backups. On the web, using Reset Progress or clearing this site’s browser storage removes local learning records.
3. Information processed when you use online features
Practice Chat
When you send a practice message, Koko processes the text you submit, up to eight recent turns, the selected language and scenario, a semantic continuity state, lesson-unlock information, and identifiers for verified words you collected. This information is used to moderate the request and generate a language-practice response.
Koko’s backend keeps an anonymous session identifier, message count, usage-limit events, semantic continuity state, and limited operational metadata. It does not store the visible chat transcript. A response cache may store generated practice output and a one-way request signature for a limited period; it does not store your readable message.
Word Scan
When you choose or capture a photo, Koko prepares bounded images on your device. On iOS, foreground masking identifies a noticeable subject; on the web, Koko creates a center crop. Koko then sends that subject image and a smaller context image for safety moderation and object identification. Koko’s backend does not save either image. It retains an anonymous usage claim, quota information, and any feedback reason you choose so it can enforce monthly limits and refund unsuccessful scans.
Koko first checks its human-reviewed vocabulary collection. When a recognized everyday concept is missing, Koko may generate and cache a clearly labeled AI translation. This shared cache can contain the target language, generic concept identifier and English label, translated word, transliteration, model version, aggregate cache-use counts, and aggregate feedback counts. It does not contain a user ID, photo, prompt, request ID, or link to a scan claim. A wrong-word or wrong-language report flags the cached translation so Koko will stop serving it until it is replaced or reviewed.
Lesson feedback and support
If you report a lesson issue, Koko may receive the language, unit, lesson, exercise, feedback category, and details you type. If you email support, we receive the information you choose to provide, such as your email address and message.
Optional product research
After you have completed learning activity, Koko may show an optional one-tap question about why you are learning or how you found Koko. Before you answer, Koko explains that your selected response and basic onboarding milestones will be shared with a random service identifier. Koko does not include your name, email, lesson answers, photos, chat text, or free-text response.
If you answer, Koko creates or reuses an unlinked anonymous Supabase session and stores one constrained product-interaction record. If you decline, the locally recorded onboarding milestones are not uploaded for product research. Product-research records are deleted after 30 days and are not used for advertising or cross-app tracking.
Anonymous product analytics
Koko uses PostHog to understand whether onboarding, lessons, review, reading, Practice Chat, and Word Scan are working as intended. Koko sends curated event names with limited properties such as app version, language choice, fixed lesson or scenario identifier, completion status, coarse count or timing range, and categorized failure stage. PostHog uses a random analytics identifier so events from one installation can be understood together. Koko does not identify you to PostHog.
Analytics never include your name, email, lesson answers, typed chat text, translations, native-language words, recognized objects, photos, image metadata, or written feedback. Session replay, screen capture, automatic element tracking, surveys, advertising profiles, and cross-app tracking are disabled. Anonymous analytics are enabled by default; you can stop new analytics at any time with Share Anonymous Analytics in Koko Settings.
Website and service logs
Our hosting and infrastructure providers may process basic technical information such as IP address, request time, browser or device type, and error or security logs to deliver and protect the service.
Crash and performance diagnostics
Koko may send privacy-filtered crash and performance diagnostics to Sentry so we can investigate reliability problems. These diagnostics are not linked to your identity and are not used for tracking. Koko disables screenshots, session replay, view-hierarchy capture, default personal information, request bodies, and learner content. Diagnostic records are retained for up to 30 days.
4. AI-assisted features
Practice Chat and Word Scan use OpenAI through Koko’s server-side services. Koko links these terms and this policy from the app’s start experience and Settings. Practice text is sent only when you submit it in Practice Chat, and an image is sent only when you choose a subject in Word Scan. If you do not want this processing, do not use those two tools; lessons, audio, progress, reading, and review remain available.
Koko sends OpenAI requests with application storage disabled. OpenAI states that API inputs and outputs are not used to train its models by default. OpenAI may retain API content in abuse-monitoring logs for up to 30 days unless a different retention control or legal requirement applies. Moderation requests are handled under OpenAI’s applicable API data controls.
Leaving Practice Chat or Word Scan stops new content from being sent. This does not undo processing that already occurred for a request you submitted.
5. Service providers
We use providers that process information only to support Koko:
- Supabase for backend hosting, anonymous authentication, database functions, usage limits, feedback, and optional product research you choose to share.
- OpenAI for safety moderation, guided practice responses, and object identification.
- Cloudflare for website delivery and related security and request logging.
- Sentry for redacted crash and performance diagnostics retained for up to 30 days.
- PostHog for anonymous, curated product analytics. Session replay, automatic interaction capture, surveys, and identity profiles are disabled.
- Apple for app distribution, device permissions, backups, and speech-recognition services you choose to use.
We require service providers to protect information consistently with their agreements with us and applicable law. Their processing may occur in the United States or other countries where they operate.
6. Camera, photos, microphone, and speech
Koko requests camera or photo-picker access only when you choose Word Scan. It requests microphone and speech-recognition access only when you choose voice input for Practice Chat. You can deny or revoke these permissions in iOS Settings. On the web, your browser controls camera and photo access. You can keep using text and offline learning features instead.
7. How we use information
- Deliver lessons, practice, review, reading, and progress tools.
- Generate and moderate the online features you request.
- Apply feature limits and prevent abuse or security incidents.
- Investigate feedback, reliability problems, and support requests.
- Measure feature adoption, onboarding completion, lesson completion, and categorized reliability trends using anonymous analytics.
- Understand onboarding and learning needs when you choose to answer an optional product-research question.
- Comply with law and protect Koko, learners, and third parties.
8. Tracking, advertising, and sale
Koko does not use third-party advertising SDKs, does not sell or rent personal information, and does not use information to track you across other companies’ apps or websites for advertising.
9. Retention and deletion
On iOS, Delete Account & All Data in Settings removes device-local learning data, preferences, saved continuity, and Koko’s unlinked online-service identity and associated server records. Removing Koko also removes device-local data but may not delete server records. Privacy-safe AI request diagnostics and Sentry crash or performance diagnostics, as well as optional onboarding product- research records, are kept for up to 30 days. Anonymous product analytics may be retained to compare feature and release trends and are deleted or aggregated when no longer reasonably needed. Anonymous backend session, quota, moderation, security, and feedback records are otherwise kept only as long as reasonably needed to provide the relevant feature, enforce limits, resolve disputes, protect the service, and meet legal obligations. Provider retention periods may also apply as described above.
To request access to or deletion of information held by Koko, email [email protected] . Because Koko’s online launch features use a pseudonymous identifier rather than an account profile, we may need limited information from your app to locate the correct record and may be unable to connect an anonymous record to you without that identifier.
10. Security
We use reasonable administrative and technical safeguards, including encrypted network transport, access controls, scoped authorization, input limits, and moderation. No storage or transmission system is completely secure, so we cannot guarantee absolute security.
11. Children
Koko is a general-audience education app and is not directed to children under 13 or offered in the App Store Kids Category. We do not knowingly collect personal information from a child who cannot lawfully consent without a parent or guardian. Contact us if you believe a child provided personal information without appropriate permission.
12. Your privacy choices
- Choose whether to use Practice Chat or Word Scan.
- Skip optional product-research questions without losing access.
- Manage camera, photo, microphone, and speech permissions in iOS or your browser.
- Use Delete Account & All Data in iOS Settings to remove local and associated server data.
- Delete browser-local data by clearing site storage.
- Contact us about access, correction, objection, or deletion.
Depending on where you live, you may have additional rights under privacy law. We will respond to verified requests as required by applicable law.
13. Changes to this policy
We may update this policy as Koko changes. We will post the revised policy here, update the date above, and provide additional notice when required.