KopiAI Privacy Policy

Last Updated: August 31, 2026
Effective Date: August 31, 2026
Contact: cdlcdl9527@gmail.com
Privacy Policy Terms of Service
This web page mirrors the in-app privacy policy used by the current KopiAI Android release.

Last Updated: August 31, 2026

Effective Date: August 31, 2026

Applicable App: KopiAI

Applicable App Versions: All versions

Data Controller: KopiAI Developer

Privacy Contact: cdlcdl9527@gmail.com

1. Introduction and Scope

This Privacy Policy explains how KopiAI ("App") collects, uses, shares, stores, and deletes data.

This policy applies to processing through:

This policy does not apply to third-party products/services not controlled by us.

2. Data We Process

We follow data minimization and process only data needed for core features, security, abuse prevention, diagnostics, analytics, ads, and legal compliance.

2.1 Data You Create in App (Primarily Local)

Recovery copies stay in app-private, non-backed-up storage. Recoverable generation is available for 10 minutes, and temporary recovery records are removed after 24 hours, on normal completion/abandonment where applicable, when you clear local data, or when you uninstall the App. Interrupted tasks are not automatically resubmitted.

2.2 Account, Device, and Technical Data

2.3 Sensitive Permissions and Data Boundaries

Current Android permissions requested by the App:

Important boundaries:

2.4 Purchases

Google Play Billing processes payment and transaction data. We do not store full payment card details.

2.5 Ads, Analytics, and Diagnostics

Depending on app behavior/SDK behavior and your settings, data may be processed for:

3. Purposes of Processing

We process data to:

4. Backend Processing and Retention

When network features are used, requests are processed by our backend (Cloudflare Worker).

4.1 Backend Data Categories

4.2 Backend Purposes

4.3 Typical Retention (Operational Stores)

Retention is TTL-based and limited to necessary periods, for example:

Account, quota, reward, verified subscription, and purchase-binding state may be kept while needed to provide the account-backed features, prevent abuse, or meet legal obligations, and is covered by the deletion process in Section 5.

Retention may be adjusted for security/operations. If law requires longer retention, legal requirements prevail.

5. In-App and Server-Side Data Deletion

The in-app "Delete account" control submits an authenticated server deletion request before erasing data from your device.

When the server confirms completion, the App deletes:

If the server cannot confirm completion, local data remains on the device so you can retry. This prevents the App from destroying the credentials needed to finish the server request.

Deletion does not reset security or fraud-prevention protections. Security, risk, rate-limit, and abuse-prevention records may be retained for as long as reasonably necessary. A short-lived retry record may be retained for up to 24 hours so a repeated request can remove data recreated after a lost response. A deletion audit record may be retained for up to 90 days. Longer retention applies where required by law.

For privacy rights requests or linkable records that cannot be handled automatically:

We process valid email requests within 30 calendar days (or faster if required by local law) and confirm completion by email. If some data must be retained by law, security, or fraud-prevention obligations, we restrict processing to those purposes and explain the reason where required.

6. Third-Party Services, SDKs, and Sharing

We do not sell personal data for money.

Under Google Play policy, developers remain responsible for third-party SDK behavior inside the app. We perform due diligence and require integrated third parties to comply with applicable policies.

Third-party services used:

1. Google ML Kit

2. Google AdMob

3. Google Play Billing / Google Play Services

4. Firebase Analytics

5. Firebase Crashlytics

6. Cloudflare

7. AI model providers configured by backend

8. Device speech-recognition service

We may disclose data when required by law, legal process, or to protect rights/safety/security.

7. Advertising and Sensitive Category Restrictions

For ads and ad personalization:

8. Sale/Share Statement

9. User Rights and Response Time

Depending on your jurisdiction, you may have rights such as access, correction, deletion, portability, objection/restriction, and complaint.

How to exercise rights:

Response time:

10. Pseudonymous App Account and Recovery

KopiAI may create a pseudonymous app account when you first use an account-backed translation feature or restore a purchase. The account does not require an email address, username, or password. It links translation quota, rewards, device access, and verified subscription state across devices.

Your recovery code is the credential used to recover this account after reinstalling or changing devices. Keep it secure. The App stores it in encrypted app-private storage on your device, and the backend stores a keyed verifier rather than the raw recovery secret. Section 5 explains the in-app account deletion process and additional privacy request options.

11. Children and Age Thresholds

The App is not directed to children.

We do not knowingly collect personal data from children under 13, or under a higher minimum age where required by local law. If such data is identified, we will take steps to delete it.

12. Security Measures

We use reasonable technical and organizational safeguards, including:

No method is 100% secure, but we continuously improve safeguards.

13. Business Transfer

If a merger, acquisition, reorganization, bankruptcy, or asset transfer occurs:

14. Cross-Border Processing

Data may be processed outside your country through global cloud/service providers. We apply safeguards required by applicable law.

15. Regional Compliance (Southeast Asia)

For users in Southeast Asia (including Singapore, Indonesia, Thailand, Malaysia, and Vietnam), we process data in accordance with applicable local privacy/data protection requirements, including rights handling and lawful transfer obligations.

16. Tracking Technologies

The app and integrated SDKs may use identifiers and similar technologies (for example Android advertising identifiers and SDK telemetry mechanisms) for ads, analytics, diagnostics, security, and anti-fraud.

You can manage ad personalization and reset advertising identifiers in device Google Ads settings.

17. In-App Prominent Disclosure and Consent

Where required by Google Play policy, we provide in-app prominent disclosure and obtain affirmative user action before collecting/processing personal and sensitive data outside reasonable user expectation.

18. Policy Accessibility and Language

19. Changes to This Policy

We may update this policy when features, providers, legal requirements, or processing practices change.

For material changes, we provide prominent notice where required.

20. Contact

Privacy requests and complaints:

The English version is the authoritative version. No login is required to view this page.