Legal
Privacy Policy
Kilemat is a website and an Android app for learning to read Arabic. They share one account and one database. This describes what is collected, why, who processes it, and what you can ask for.
Last updated 2026-08-31 · version 2026-08-31.2 · English is the authoritative version of this document.
Who is responsible
The controller for the processing described here is the Kilemat operator identified in the legal notice. That page is the canonical source for the operator's identity and postal address.
Privacy requests go to Data protection contact not yet published (set LEGAL_PRIVACY_CONTACT). General enquiries can use the contact form, which does not require an account.
What Kilemat stores
Every category below corresponds to something in the database, and nothing is listed that does not exist.
Your account
Name, email address, whether that address is verified, a password hash if you set one, an avatar choice, and your role. If you sign in with Google or Apple, the identifier that provider gives us and the email address in their token. Failed sign-in counts and a temporary lock, so an account cannot be brute-forced.
Security
If you turn on two-factor authentication, the secret your authenticator app was set up with. Verification and password-reset codes, which expire. A timestamp of when your existing sign-ins were last invalidated, and a record of each mobile sign-in so it can be withdrawn.
Learning
Which lessons you have practised and your best score on each, which stories and conversations you have opened and read, words you have saved and their review schedule, comprehension questions you have got wrong, your daily plan, experience points, and reading preferences: dialect, translation language and vowelling.
Activity and streaks
One row per study session, holding the local calendar day, the seconds spent and what was being studied. The streak is derived from those days on the server rather than being reported by your device.
Social features
Friend requests and friendships, your profile visibility setting and whether you appear on leaderboards, accounts you have blocked, and reports you file about other accounts. A report holds who filed it, who it is about, a reason, optional free text, and its review status.
New accounts are visible to friends only and are out of the public leaderboard by default. You can change both at any time.
Subscriptions
Whether you have premium access, which product, and when it expires. Kilemat never sees or stores a card number: payments are handled by the app store you bought from, or by Stripe through RevenueCat for a purchase made on the website.
Technical information
Ordinary server logs kept by our hosting provider, and IP addresses held briefly for rate limiting so that sign-in, registration and the contact form cannot be attacked automatically.
Why, and on what basis
- Providing the service you asked for — your account, your progress, your saved words, your subscription. Performance of a contract.
- Keeping accounts secure — password hashing, two-factor, rate limiting, session revocation, blocks and reports. Legitimate interests, and a legal obligation where security of processing is required.
- Social features and leaderboards — only to the extent your visibility settings allow. Performance of a contract for the features you switch on.
- Advertising in the app — consent, gathered through Google's consent form before any ad is requested. Declining does not restrict the learning content.
- Meeting legal and accounting obligations — records of purchases, held by the payment providers named below.
Kilemat does not sell personal information and runs no advertising or analytics on the website.
Who processes it
Each of these is a service Kilemat actually uses. Several are outside the EEA, and international transfers are covered under Transfers.
- Vercel — hosting for the website and the API. Sees every request.
- The PostgreSQL database provider — where everything above is stored. Named in the legal notice once the operator confirms it.
- Upstash — Redis, used for rate-limit counters keyed by IP address or email address.
- Resend — sends verification, password-reset and contact emails. Sees the recipient address and the message.
- Google reCAPTCHA — protects sign-in and registration on the website from automated abuse. Google receives information about the browser making the request.
- Google sign-in and Sign in with Apple — only if you choose them. We receive an identifier and, on the first authorization, an email address.
- RevenueCat — the record of what you are entitled to, on every platform. Receives your Kilemat account identifier.
- Stripe — takes the payment for a subscription bought on the website, through RevenueCat.
- Google Play billing — takes the payment for a subscription bought in the Android app.
- Google AdMob — serves ads in the Android app, and only after the consent form allows it. Uses device and advertising identifiers.
How long it is kept
Account and learning data is kept until you delete your account. Verification and reset codes expire within hours. Rate-limit counters expire within minutes. Reports are kept while they are open and for a period afterwards so that a pattern of behaviour can be recognised, and they are removed when either account involved is deleted.
Records of purchases are held by the payment providers for as long as their own accounting obligations require, which is typically several years, and is outside Kilemat's control.
Your rights
You can ask for a copy of your data, ask for it to be corrected, ask for it to be deleted, object to processing based on legitimate interests, ask for processing to be restricted, and ask for your data in a portable form. Where processing is based on consent, you can withdraw it without affecting what was done before.
You can delete your account yourself from Settings on the website or in the app. If you cannot sign in, use the deletion request page, which does not require an account.
Deleting an account removes your Kilemat data. It does not cancel a subscription: see the subscription and cancellation page.
If you are in the EEA or the UK you can complain to your data protection authority.
Transfers outside the EEA
Several of the processors above are established in the United States. Transfers rely on the safeguards those providers offer, typically standard contractual clauses or an adequacy decision. The exact safeguard for each processor is part of the review this document still needs, and is not something that can be asserted from the code.
Children
Kilemat has not set a minimum age, and this section will change when it does. It contains a category of children's stories, which adult learners use because the language is simple, and it is not currently offered as a service directed at children. Nothing in the app is configured as child-directed advertising, and no age is collected.
If you believe a child has created an account, write to Data protection contact not yet published (set LEGAL_PRIVACY_CONTACT) and it will be removed.
Security
Passwords are hashed. Two-factor authentication is available. Changing or resetting a password withdraws every existing sign-in, on the website and on the phone. Requests from the app carry a token that can be revoked. None of this makes a system perfectly secure, and no operator can promise that it does.
Changes
The date and version at the top of this page change when the document does. A change that materially affects you will be announced in the product rather than only here.