JapanilyPrivacy

Privacy policy

This policy explains what Japanily collects, why it is needed, and the choices available to students, teachers and schools.

Last updated 4 October 2026

Information we collect

Temporary guest quizzes are separate from account-based live games. They store an owning teacher and source set, a bounded question snapshot, generated Daruma labels, hashed invitation/session tokens, admission/removal state, answers and temporary scores. No learner name or email is requested and no learner Auth account, account link, permanent assessment, XP or reward is created. A secure HTTP-only first-party cookie reconnects the browser to its guest session for at most one hour; it is restricted to the guest API and cleared when leaving or when the app detects the session has ended. A momentary cookie probe checks whether cookies work before joining.

We collect account details such as email address, role, display name, avatar, year level and learning pathway. The service also stores class membership, teacher-created study content, assignments, answer and completion results, live-game participation and scores, and earned XP, petals, abilities and cosmetics.

Optional Japanese reading practice stores words or phrases you explicitly save, their source sentences, your reading hints and personal notes, chosen word states, explicitly approved cards, and self-rated review history and due dates. These records are private to your account in the app: teachers cannot browse another learner’s personal vocabulary. They do not create grades, XP or proficiency claims. Do not include personal information about other people in your notes.

Your teacher can set a school-approved class alias for your current roster, evidence and newly generated reports. You can see your own alias and export it with your account data. It does not change your account name, sign-in or live-game display name. The latest alias and update time are stored until cleared or the membership, class or account is deleted; archived classes retain it. Previously downloaded reports do not change.

Teachers may record dated observations, draft rubric judgements, support used and next steps. An explicitly authorised teacher colleague may review the scoped observation, learner label and class name, not the whole roster or attempt history. Teacher-prepared family reports require review before download; Japanily does not automatically email them or create a public sharing link. Downloaded copies are outside the service and need school-approved handling.

Public reader polls store a random visitor token and vote choice; public questions or ideas also store the chosen age band, submission text and moderation state. The browser remembers its token and poll selections in local storage until cleared; this is separate from account sign-out. Do not include identifying or sensitive information in submissions. Only aggregate poll results are public, and submitting an idea does not publish it.

Optional voice practice records and replays in the current browser tab without uploading the learner recording. Professionally reviewed model recordings are a separate media workflow; browser speech is not a professional recording. The optional school connection check sends two read-only requests without account credentials and keeps its results only on the page; ordinary provider request logs still apply.

Our hosting and database providers may process technical information needed for security and operation, such as IP address, device or browser details, request logs and authentication events. Japanily does not request precise location, advertising identifiers, student contacts or payment data.

How we use information

Information is used to authenticate users, deliver teacher-directed learning, show progress, run live classroom games, prevent abuse, troubleshoot faults and keep the service secure. We do not sell personal information and do not use student information for targeted advertising.

Schools and children

A school or teacher introducing Japanily must have authority to do so and provide any notices or consent required by its policies and applicable law. Student accounts are private by default: there is no public profile directory, direct messaging or unmoderated public posting. Teachers can see information for their own classes, with explicitly authorised observation review as described above.

Service providers and location

Japanily uses Supabase for authentication and application data, Netlify for hosting and delivery, and GitHub for source-code operations. These providers may process data in Australia or other countries under their own contractual safeguards. A school should complete its own privacy and vendor review before rollout.

Retention, access and deletion

Guest access expires one hour after the teacher creates the room. Ending the room deletes its guest sessions, answers and scores immediately; deleting the owning teacher or source set also cascades them. Leaving or teacher removal revokes that guest’s access but preserves the temporary room record until room deletion. An hourly cleanup removes up to 100 expired rooms per run, with additional cleanup when teachers create rooms; failures or service outages can delay physical deletion, but do not extend access. Guests are not linked to account exports. Share guest invitations only with the intended class and use Leave guest session before handing over a shared device.

Personal reading notes and card history are stored with your account in Supabase, not as an offline browser copy. They are included in your account export. You can permanently remove individual words and their cards/history, or remove a card and its history; deleting the account also deletes these records. Unpublishing or ageing out a source preserves your notes, but permanently deleting its source reading also deletes the linked personal words and cards. Known and Ignored pause cards without deleting them.

Assignment games can keep a short-lived recovery checkpoint and an unsent submission in session storage in the current tab. These contain student and assignment identifiers and vocabulary responses, not passwords or recordings. Checkpoints are ignored after four hours and cleared on successful save or replay. Sign-out clears these records in open tabs with JavaScript when they receive its signal or next become active; closing a tab normally clears session storage. Save work first, then sign out and close all tabs before sharing a device.

Sign-in offers shared-device browser-session cookies or personal-device cookies kept for up to 30 days after use. Existing sessions without a saved preference should be updated in Your account. Browser session restore may keep session cookies: shared mode is not an automatic sign-out timer. A non-identifying device preference and sign-out signal coordinate this browser; the signal expires after 30 days and a short sign-out result cookie after one minute. Signing out clears the device preference. It does not clear downloaded files, history, saved browser passwords, public bookmarks or your Google/Microsoft session. If JavaScript or browser storage is blocked, follow your school’s browser-data clearing instructions.

We retain account and learning records while the account or relevant school use remains active, then delete or de-identify them when no longer required. Signed-in users can download a machine-readable copy from Account and request deletion there. We aim to action verified deletion requests within 30 days, unless a school or legal retention duty requires a different response.

Security and contact

We use access controls, row-level database security, encrypted transport, restricted administrative access and operational checks. No online service can promise absolute security. Report a privacy concern or request correction at puttosensei@gmail.com.

The school-readiness page separates implemented controls from missing approvals. These public notices still need qualified school/privacy review before a production rollout.