Klondis Klondis

TypeThai for Android — Privacy Policy

Effective: 8 September 2026

This policy describes how the Android version of the LingoFrontier: Type Thai mobile application ("the App") handles information. It applies specifically to the Android version of TypeThai. Other Klondis products and our website are covered by the general Klondis Privacy Policy — where the two differ, this document governs the App.

Summary

The App is designed to collect as little personal information as possible. You can use the free learning features without creating a TypeThai account. A Google-backed TypeThai account enables progress synchronization between your devices and is required for purchasing, verifying, restoring, and using premium subscriptions.

The App does not show advertising, does not contain an analytics SDK, does not sell personal data, and does not share personal data for advertising or cross-context behavioural advertising.

Your preferences and learning progress are stored on your device. When you sign in with Google, TypeThai also stores learning summaries linked to your account on its Firebase backend so you can continue learning on another device. Selected learning progress may also be included in supported encrypted Android backup or device transfer.

Google Play handles subscription checkout and payment information. The App and its Firebase backend receive only the purchase and entitlement information needed to verify premium access, prevent a purchase from being claimed by another TypeThai account, restore access, and react to subscription changes.

Firebase Authentication, Cloud Firestore, Cloud Functions, Firebase Installations, and Firebase App Check with Google Play Integrity provide account, progress synchronization, entitlement, and anti-abuse services. These services process limited account and technical information described below.

1. Who we are

The data controller for personal data processed in connection with the App is:

Klondis Oy
Business ID: 3595444-5
Kukkulantie 2 A 28, 33960 Pirkkala, Finland

For privacy questions, requests, or to exercise the rights described in this policy, contact:
privacy@klondis.com

2. What the App processes

2.1 Preferences and settings

The App stores settings such as theme, voice, fonts, keyboard layout, language, and audio choices locally on your device using Android's standard app storage.

2.2 Learning progress, synchronization and Android backup

The App stores learning progress locally. When you sign in with Google, it also synchronizes completed lessons, session and mode counts, points, answer and hint totals, achievements, study dates, spaced-repetition review state, and Bubble campaign progress. A random installation identifier and contribution history prevent the same work from being counted twice.

Raw answer-event logs, response-time histories, general preferences and free-form content are not uploaded through progress synchronization. Detailed learning events remain on your device. Spaced-repetition reviews currently record successful Bubble hits.

Android backup may include the original learning database, legacy progress totals and legacy Bubble campaign file. The original database includes non-secret contribution identifiers and baselines needed to recover work without counting it twice. New account-specific databases and synchronization checkpoints, Firebase identity, App Check material, cached premium entitlement, debug state and general preferences are excluded from backup. Supported cloud backup requires encryption; eligible data can also transfer directly between Android devices. Klondis does not receive your Android backup.

2.3 Google sign-in and the TypeThai account

Progress synchronization, premium purchase and recovery features use Google Sign-In through Android Credential Manager and Firebase Authentication. When you sign in, Google and Firebase provide or create account information that may include your Google provider identifier, email address, display name, profile image URL, authentication timestamps, and a unique Firebase user ID.

Klondis uses the Firebase user ID and a one-way hash of the Google provider identifier to bind a Google Play purchase to the correct TypeThai account. The App's Firestore entitlement document does not store your name, email address, or profile image.

The App does not use email/password or email-link authentication. Your Google password is never provided to Klondis or to the App.

2.4 Google Play subscriptions and trials

Subscriptions and free trials are offered through Google Play Billing. Google processes your payment method, billing address, transaction currency, taxes, and other payment details. The App does not receive your complete payment-card or bank-account details.

The App and backend process a Google Play purchase token and subscription details such as the product, base plan, offer or trial, purchase state, acknowledgement state, expiry time, and whether renewal is enabled. The raw purchase token is used transiently to ask the Google Play Developer API to verify or acknowledge the subscription. Firestore stores a one-way SHA-256 hash of the token rather than the raw token.

Google Play sends Real-time Developer Notifications when a subscription changes. For an eligible chargeback review, the backend submits the privacy-minimal NEUTRAL response to Google's ReviewRefund API. The pending refund token and order ID are used for that request and are not retained by TypeThai.

2.5 Entitlement records in Firebase

To keep premium access accurate across devices, TypeThai stores the following limited information in Cloud Firestore:

The backend does not retain the raw purchase token, order ID, pending refund token, usage evidence, IP address, or location in these Firestore records. Signed-in users can read only their own entitlement document. Purchase-ownership and notification-processing collections are not readable or writable by the App.

2.6 App integrity and anti-abuse checks

The production App uses Firebase App Check with Google Play Integrity to protect Firestore and callable backend functions. Google Play and Firebase process app-attestation information such as the package name, app version, signing certificate, Google Play licence status for signed-in accounts on the device, device attestation material, integrity tokens, Firebase App ID, Firebase user agent, and a per-installation Firebase Installation ID.

TypeThai uses the resulting integrity decision to determine whether a request comes from the recognised Play-installed App on an eligible Android environment. We do not use Play Integrity to fingerprint or track individual users or devices, and we do not store the underlying attestation material in our Firestore account records.

2.7 Network and operational diagnostics

Firebase Authentication processes IP addresses and user-agent information for security and abuse prevention. Calls to Cloud Functions process the function name, IP address, Firebase user ID when signed in, App Check token, and technical request metadata needed to execute and secure the request. Firebase infrastructure may also generate a Firebase Installation ID and messaging token even though TypeThai does not send push notifications.

Backend logs contain operational timestamps, request status, and deliberately limited error metadata such as safe error type or HTTP status. TypeThai's backend logging is designed not to record raw purchase tokens, order IDs, Google ID tokens, App Check tokens, email addresses, Play response bodies, or user-generated learning content.

The App does not include Firebase Crashlytics, Firebase Analytics, Google Analytics, PostHog, an advertising SDK, or another third-party behavioural analytics service. Google Play may separately provide Klondis with aggregated Android vitals and purchase reports under Google's own terms.

2.8 What we do not collect

To be explicit, the App does not request or collect through Android permissions:

We do not show ads, build advertising profiles, sell personal data, share personal data with data brokers, or participate in cross-app or cross-website behavioural advertising.

3. Third parties

Google — Firebase and Google Cloud

Google provides Firebase Authentication, Cloud Firestore, Cloud Functions, Firebase Installations, App Check, Pub/Sub notification delivery, and related hosting, security, and logging infrastructure. For customer data placed in Firebase and Google Cloud, Google generally acts as our processor or service provider under its data-processing terms. Google may process separate service data as described in the Firebase Privacy and Security information and Google Privacy Policy.

Google — Google Play

Google Play distributes the App, processes subscriptions and trials, keeps payment and order history, provides subscription state through the Play Developer API and notifications, and performs Play Integrity checks. Google acts independently for Google Account, Play Store, and payment processing activities under the Google Privacy Policy and Google Play Terms.

Android backup and device transfer

If you enable Android backup, Google or your device manufacturer may back up or transfer the selected learning-progress data described in Section 2.2. Google states that Android Auto Backup data is stored in a private area associated with the user's Google Account and, on supported devices, is end-to-end encrypted using the device screen lock. Availability and handling depend on your Android version, device manufacturer, and backup settings.

4. Legal basis for processing (GDPR)

For users in the EU, EEA, and UK, we rely on the following legal bases:

TypeThai does not ask for consent to behavioural analytics because the Android App does not contain behavioural analytics or advertising SDKs.

5. Data retention

6. Your rights and choices

Depending on where you live, you may have rights to access, correct, erase, restrict, or receive a copy of personal data; object to processing based on legitimate interests; and lodge a complaint with a supervisory authority.

You can use the App without signing in for free features. If you create a Google-backed TypeThai account, you can delete it from the App's Settings after signing in with Google again. You can also initiate deletion through the TypeThai Android account-deletion page.

Account deletion does not cancel a Google Play subscription. To avoid losing the TypeThai account link while renewal remains active, the App requires you to turn off subscription renewal in Google Play before deleting the account. Cancelling renewal normally leaves premium access available until the paid period expires. You can manage the subscription at Google Play Subscriptions.

Deleting the TypeThai account deletes the Firebase Authentication user, Firestore entitlement document, purchase-ownership records linked to that user, synchronized learning progress, and the local cached entitlement. It does not delete learning progress or general settings stored on the device, Android backups, your Google Account, or Google Play's transaction records. Clear the App's storage or uninstall it to remove local data, and use your Android or Google Account backup controls to manage backups.

To request access, correction, deletion, restriction, portability, or to object, email privacy@klondis.com. We may need enough information to verify that a request relates to your TypeThai account, but we will not ask for your Google password or complete payment-card information.

You may lodge a complaint with a data protection authority. In Finland, this is the Office of the Data Protection Ombudsman (tietosuoja.fi). If you live elsewhere in the EU or EEA, you may contact your local supervisory authority.

For California residents: we do not sell personal information and do not share personal information for cross-context behavioural advertising.

7. International transfers and processing locations

Klondis is based in Finland. The TypeThai entitlement Cloud Firestore database is configured in Stockholm, Sweden (europe-north2). The separate progress database and progress-synchronization function are configured in Finland (europe-north1). The callable billing and account functions are configured in Iowa, United States (us-central1). Firebase Authentication operates from United States data centres, and other Google services may use global infrastructure.

Where personal data is transferred outside the EU/EEA, Google states that it relies on applicable safeguards such as the EU–U.S. Data Privacy Framework and contractual data-protection terms. See Google's Firebase Privacy and Security information for current details.

8. Children's privacy

The App is not directed at children under 13, and Klondis does not knowingly collect personal data from children under 13. The free learning features do not require an account. Google Account and Google Play services may apply their own age and parental-consent requirements.

If you believe a child has provided personal information to us, contact privacy@klondis.com and we will address it appropriately.

9. Security

We use technical and organisational safeguards appropriate to the limited information the App processes:

No method of storage or transmission is completely secure. If we become aware of a personal-data breach for which notification is legally required, we will notify the appropriate authority and affected individuals where reasonably possible.

10. Changes to this policy

We may update this policy as the App or the services it uses change. If we make material changes, we will update the effective date and provide notice through an appropriate channel, such as the App, the Play Store listing, or this webpage.

Previous versions of this policy are available on request.

11. Contact

Klondis Oy
Kukkulantie 2 A 28
33960 Pirkkala
Finland
Business ID: 3595444-5

Privacy questions and requests:
privacy@klondis.com


This policy is provided in English. If you have read a translated version, the English version governs in case of any conflict.