Tokki Talk Privacy Policy

Effective date: August 24, 2026

Last updated: October 3, 2026

Policy version: 2026-10-03.1

This Privacy Policy explains how Little Oboe LLC (“Little Oboe,” “we,” “us,” or “our”), collects, uses, discloses, and retains personal information when you use the Tokki Talk mobile application, the Tokki Watch browser extension, websites, and related services that link to this policy (collectively, the “Service”).

Little Oboe is the controller of the personal information described here unless we say otherwise. Our contact details appear in Section 16.

1. The short version

  • We use account, learning, and device information to provide and secure a personalized Korean-learning service.
  • Features you choose may send text, images, audio, or transcripts to AI, speech, voice, and hosting service providers.
  • We do not sell personal information or share it for cross-context behavioral advertising, and we do not serve targeted ads.
  • We do not create voiceprints or use voice to identify you.
  • We do not use private chats, images, or voice recordings to train our own general-purpose AI models without a separate opt-in.
  • You can request access, correction, export, or deletion using the methods in Section 10.
  • The Service is for people age 13 and older and is not directed to children under 13.
  • The Service is initially offered only in the United States.

This summary does not replace the details below.

2. Information we collect

A. Account and profile information

Depending on how you sign in, we may collect:

  • display name;
  • private username and a password hash;
  • email address and name made available by Apple or Google;
  • provider-specific account identifiers for Apple or Google sign-in;
  • internal account or learner identifier;
  • account creation date, sign-in methods, session tokens, and authentication and security records;
  • your confirmation that you meet the minimum age and, if needed to enforce age-appropriate provider routing, whether you are 13–17 or 18 or older; and
  • settings, preferences, and beta-feature choices.

We do not receive your Apple or Google password. If you use password sign-in, we store a one-way password hash rather than the password itself.

B. Learning activity and inferred learning information

We collect information needed to personalize learning, such as:

  • vocabulary, expressions, grammar, sentences, and lists you save;
  • review history, answers, ratings, scheduling data, streaks, and progress;
  • lesson requests, generated lessons, playback position, and completion;
  • speaking and pronunciation attempts, corrections, and scores;
  • learner level, goals, interests, preferences, and memory items;
  • roleplay scenarios and suggested-reply interactions; and
  • inferences about familiarity, difficulty, likely knowledge, and recommended next activities.

These learning inferences are used to personalize education. We do not use them to make decisions that produce legal or similarly significant effects, such as employment, credit, insurance, housing, or healthcare decisions.

C. Messages and other content you provide

We collect content you choose to submit, which may include:

  • chat messages, prompts, assistant responses, translations, and feedback;
  • journal entries, notes, saved sentences, and list names;
  • images attached to a chat;
  • voice recordings, live voice audio, dictation audio, and resulting transcripts;
  • corrections, support messages, survey responses, and product feedback; and
  • shared-list content, invitations, and collaboration activity.

Free-form content can reveal information we did not ask for, including sensitive personal information. Please do not submit secrets, government identifiers, financial credentials, medical records, or another person's private information unless the feature clearly requires it and you have authority to do so.

D. Voice and speech information

When you choose a voice, pronunciation, or dictation feature, the app may capture and transmit microphone audio to provide speech recognition, real-time conversation, pronunciation feedback, or text-to-speech interaction. Depending on the feature and production configuration, we and our providers may process:

  • live or recorded audio;
  • transcripts and recognized Korean or English text;
  • timestamps, language, selected voice, audio quality, and connection state;
  • pronunciation or production feedback; and
  • session context needed for the tutor to respond.

We do not create a voiceprint, faceprint, or other biometric template to identify you, and we do not use voice to verify identity. If that practice ever changes, we will provide a separate notice and obtain consent required by law before the change.

The app presents recording controls when a microphone feature is active. You can stop recording in the feature and can revoke microphone permission in device Settings.

E. Device, usage, and diagnostic information

We and our service providers may collect:

  • app version, build, release channel, operating system, device type, locale, and time zone;
  • IP address and network/request metadata;
  • internal user identifier, session identifier, and pseudonymous analytics identifier;
  • app launches, screens or features used, taps, learning interactions, and feature outcomes;
  • crash, hang, CPU, disk-write, performance, and error information;
  • limited allowlisted request outcomes included in a support bundle that you choose to send; and
  • push tokens and playback state needed for notifications, widgets, or Live Activities.

Product-analytics events are designed to exclude the text of private chats, uploaded images, raw voice recordings, and transcripts. We review those event schemas when changing analytics instrumentation.

With an adult's optional product-analytics choice enabled, the app may also send sampled performance histograms and attempt counts to our first-party server. An authenticated request lets the server check current permission; the performance payload and retained aggregate rows have no stable learner, installation, or session identifier. They contain fixed operation and stage labels, broad app and device configuration, timing buckets, and counts, not learning content, chat text, images, audio, transcripts, URLs, or request bodies. The unsent app queue stays in memory and is lost when the app ends. This performance feed is separate from essential crash diagnostics and is not forwarded to PostHog.

F. Information from other people and services

We may receive:

  • account information from Apple or Google when you choose that sign-in method;
  • content and display names from people who share a study list or invitation with you;
  • subscription status and transaction information from Apple; and
  • security, delivery, and diagnostic information from our service providers.

G. Tokki Watch browser extension

Tokki Watch is an optional Chrome extension. It is separate software from the Tokki Talk app, it runs only on the video pages you grant it, and installing it is a deliberate choice. This section describes only what the extension does; it adds nothing to what the app itself collects.

Where it runs. Tokki Watch activates only on youtube.com. It does not run on any other website, and it does not run in an Incognito window.

What it reads from the page. While you watch, the extension reads Korean caption text, caption-track language labels, and the player position needed to build an in-browser timed-cue cache. It does not read or retain cookies, session data, authorization headers, content-protection state, audio, video, or unrelated player data. It does not send us a provider URL, request headers, or a raw subtitle response. You may load a subtitle file yourself for the extension's private, local transcript view; the extension does not upload it.

What is sent to us. To split a Korean line into words, look them up, and show how familiar each word already is to you, the extension sends the current caption line to our servers along with the identifier of your Tokki Talk account. Caption text sent for this purpose is processed to answer the request and is not retained as a stored transcript of what you watched. When you choose to save a word or a line, that chosen item, and only that item, is stored in your account as saved vocabulary or a saved sentence, the same as if you had saved it in the app.

If you pair a phone. Pairing is optional and requires an explicit approval on your signed-in phone. While a pairing is active, the extension sends the current caption line and a small playback summary (playing or paused, position, which service, and the video title) to a short-lived relay so your own phone can follow along and send back pause or replay commands. Relay records are held only for the active study session and expire within minutes; they are not kept as a viewing history.

Credentials. The extension never receives your Tokki Talk password, and it does not use your app's login session. It holds a separate, browser-only access credential limited to dictionary lookups, list access, and saving. You can revoke it at any time by signing out of the browser from the extension's side panel, and uninstalling the extension deletes it.

What stays on your device. Your caption display preferences, the current pairing state, and any subtitle file you load yourself stay in the extension's private storage in your browser and are not sent to us.

3. How we use information

We use personal information to:

  • create, authenticate, and secure accounts;
  • provide chat, lessons, speech, voice, review, synchronization, offline, share, widget, notification, and collaboration features;
  • personalize content, difficulty, review timing, and recommendations;
  • process text, images, and audio through AI and speech providers at your direction;
  • maintain progress across devices and restore purchased features;
  • operate, debug, monitor, and improve reliability, accessibility, safety, and user experience;
  • respond to support requests and investigate reported problems;
  • enforce usage limits and prevent abuse, fraud, or security incidents;
  • send account, service, security, and legal notices;
  • administer subscriptions;
  • comply with law and protect users, Tokki Talk, and others; and
  • create aggregated or deidentified statistics that cannot reasonably be linked back to a person.

We do not use private chats, images, or voice recordings to train our own general-purpose AI models unless you separately and affirmatively opt in. We ask for a separate, versioned choice before sending learning content you choose to use with AI or voice features to a third-party provider. You can withdraw that choice in the app; withdrawal prevents new optional AI transmissions. Users ages 13–17 may make that choice, although a particular AI or voice provider may be unavailable when its terms or our configuration do not permit use for that age range.

Human access to private content is limited to authorized personnel and contractors who need it for support, security, abuse investigation, quality review that you have enabled, or legal compliance. We do not use that access to train our own general-purpose AI models without your separate opt-in.

4. When we disclose information

We disclose personal information only as described below.

A. Service providers

We use service providers to operate the Service. The services below may receive the listed data only when the corresponding feature is enabled or you choose to use it:

CategoryProduction-capable providersInformation and purpose
Cloud hosting and infrastructureRailwayAccount, learning, content, media, request, and operational data needed to host and deliver the Service
Backup storageRailway-managed infrastructure and configured object storageDatabase replicas and recovery snapshots used to restore service data
AI and language modelsOpenAI; OpenRouter and, where selected for a request, an upstream model providerPrompts, messages, images, transcripts, lesson context, and generated output needed to answer a request, interpret an image, or create a lesson
Speech recognition and real-time voiceSoniox; LiveKitMicrophone audio, transcripts, internal learner or session identifier, tutor context, connection metadata, and generated responses needed for dictation or live voice
Text-to-speechSoniox; xAI; ElevenLabs; Apple on-device speechText, selected voice/settings, language, and request metadata needed to generate or play speech. A particular provider or voice option may be unavailable for an account's age range.
AuthenticationApple; GoogleSign-in tokens, provider identifiers, name/email where made available, and security metadata
Optional product analyticsPostHogIf you opt in and the provider is permitted for your age group: an internal or pseudonymous identifier, app/build/device information, product interactions, and feature outcomes used to understand and improve the Service. We do not intentionally send chat text, images, raw audio, or transcripts as analytics events
App distribution, push delivery, and purchasesAppleApp and device/account information; push tokens, lesson/vocabulary content, and playback data used for Live Activities; purchase, subscription, and transaction information under Apple's own terms
Support and communicationsLittle Oboe's support email and support toolsContact information, support messages, and delivery metadata

We configure providers only for the stated service purpose. Website checkout and Stripe payment processing are not part of the initial launch.

The following links provide additional information published by providers. A provider's notice explains its own practices; it does not replace this Policy, our responsibility for choosing and configuring providers, or a separate permission Tokki Talk must request before a third-party AI transmission:

  • OpenRouter: Privacy Policy, provider selection and data policies
  • OpenAI API: API data controls, business data privacy
  • Soniox: Privacy Policy, Terms of Service
  • LiveKit: Privacy Policy, Data Processing Addendum
  • xAI: Privacy Policy, Enterprise Terms, Data Processing Addendum
  • ElevenLabs: Privacy Policy, Terms of Service, API Terms, and Zero Retention Mode documentation
  • PostHog: Privacy Policy, privacy documentation

Provider terms can change and describe their own processing. We do not rely on those notices to expand the choices described in this policy. OpenRouter may route a request to an upstream provider; the provider selected for a request may have its own retention terms. Accounts that select the 13–17 age range do not send analytics to PostHog. They may use AI or voice features after making the separate AI choice, subject to provider-specific age availability.

B. Other users you select

We disclose your display name and shared content to people you invite to a shared feature. We do not disclose your private username or internal learner ID as your social identity. The feature will indicate what is shared before you send an invitation or publish content to collaborators.

C. Legal, safety, and rights protection

We may disclose information if we reasonably believe it is necessary to comply with law or valid legal process; protect the rights, safety, or property of a person; investigate fraud, abuse, or a security incident; or establish, exercise, or defend legal claims. Where lawful, we will seek to narrow a request and provide notice before disclosure.

D. Business transfers

Information may be disclosed as part of due diligence for, or transferred in, a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets. The recipient must honor this policy for information collected under it unless you receive notice and any choice required by law.

E. At your direction

We disclose information when you direct us to do so or give a separate, informed permission.

5. Sale, targeted advertising, tracking, and Global Privacy Control

We do not sell personal information for money or other valuable consideration. We do not share personal information for cross-context behavioral advertising, and we do not serve targeted advertising.

Adults who affirmatively opt in can send product analytics to PostHog and the first-party sampled performance feed described in Section 2.E to help us understand and improve the Service. You may withdraw that permission in the app; withdrawal stops new optional analytics collection, clears the in-memory performance queue, resets the PostHog analytics identity, and opts the app out. Accounts that select the 13–17 age range cannot enable product analytics. We do not use product analytics for advertising or ad measurement, and we do not currently request Apple's App Tracking Transparency authorization.

Because we do not sell or share personal information for targeted advertising, there is currently no sale/sharing activity for a Global Privacy Control signal to opt out of. If our practices change, we will update this policy, provide the required controls, and honor legally recognized universal opt-out signals.

Some browsers offer a separate “Do Not Track” signal. Because there is no generally accepted standard for responding to that signal and we do not currently conduct cross-site behavioral advertising, the Service does not respond to it separately. We do not authorize third parties to collect your activity across unrelated apps or websites through the Service for targeted advertising.

6. Legal bases for users in the EEA, UK, and similar jurisdictions

Where law requires a legal basis, we rely on:

  • Contract: to create and administer your account and provide the learning, synchronization, support, and paid features you request.
  • Legitimate interests: to secure and maintain the Service, prevent abuse, understand basic product performance, and improve reliability, after considering your rights and reasonable expectations.
  • Consent: for optional analytics where required, third-party AI sharing where required by platform rules or law, optional model improvement, marketing, and device permissions. You can withdraw consent at any time without affecting processing that was lawful before withdrawal.
  • Legal obligation: to comply with tax, accounting, consumer-protection, sanctions, law-enforcement, and other legal requirements.
  • Vital interests or legal claims: in rare situations involving safety or the establishment, exercise, or defense of legal claims.

Providing account credentials and learning content is necessary to provide the corresponding account or feature. Other fields and optional permissions are voluntary; if you do not provide them, the related feature may be unavailable.

We do not make decisions based solely on automated processing that produce legal or similarly significant effects.

7. Retention

We retain personal information only for the stated purpose, legitimate operational needs, and legal requirements. Retention depends on the feature and the data's role in an active account, a deletion request, or a legal record:

InformationRetention
Account, profile, and sign-in recordsWhile the account is active. An accepted deletion request immediately restricts ordinary account access while the deletion workflow proceeds; limited security, transaction, and legal records may be retained where necessary.
Learning progress, saved content, chats, transcripts, and collaboration dataWhile the account or content remains active, until you delete it, or until account deletion, subject to backup expiration and legal exceptions
Raw live-voice and dictation audioPending recordings on the device are removed after terminal delivery and expire after 24 hours. Where a provider must retain a request to complete it, the request remains only as long as that provider needs to provide the selected feature.
Dictation and live-voice transcriptsJob-state copies have a best-effort seven-day TTL; a transcript committed to chat is retained as chat content until that content or account is deleted
Uploaded chat imagesUntil the associated content or account is deleted, then removal from active storage through the deletion workflow.
Generated lesson mediaKept on the account until you delete the lesson or the account; deleted lesson media is then removed from active storage, subject to backup expiration and verified production configuration
Local support history and user-approved support diagnostic bundlesLocal support history is limited to seven days and 200 events. We retain an uploaded bundle only as long as needed to diagnose and respond to the request.
Routine analytics eventsUnder the retention controls of the configured PostHog project and only while an adult opt-in is active.
First-party sampled performance aggregates and random batch receiptsAvailable to ordinary reports for a rolling 90-day receipt-time window. Scheduled pruning removes aggregate rows older than 90 days and random retry-deduplication receipts older than 24 hours. Physical storage blocks or infrastructure snapshots may outlast row deletion. The unsent app queue is memory-only and does not survive app termination.
Server, security, and diagnostic logsFor security, reliability, and debugging, then deleted or deidentified under the applicable service configuration.
Purchase, tax, consent, and legal recordsFor the period required by law or reasonably necessary to establish, exercise, or defend legal rights.
BackupsIn a rolling recovery window of up to seven days, after which older recovery copies are overwritten or expire.

When retention ends, we delete or deidentify the information using reasonable measures. Deidentified information may be retained if we maintain it in deidentified form and do not attempt to reidentify it.

8. Your choices

Depending on the feature, you can:

  • update your display name, preferences, and learning settings in the app;
  • delete individual chats, lists, memories, sentences, images, or lessons where the feature offers a deletion control;
  • stop microphone use and revoke microphone, speech, camera, or notification permission in device Settings; selected photos are provided through Apple's selection-scoped photo picker rather than broad library access;
  • choose whether to send a support diagnostic bundle;
  • review or withdraw optional analytics or third-party AI permission in Settings > Privacy Choices;
  • manage an App Store subscription through Apple Account Settings;
  • leave a shared list or remove collaborators where the feature permits; and
  • initiate whole-account deletion in Settings > Account > Profile > Delete Account.

Signing out or uninstalling the app does not delete your account and does not cancel an App Store subscription. Requesting account deletion does not cancel an App Store subscription.

9. Privacy rights

Depending on where you live and subject to applicable law, you may request:

  • confirmation of whether we process your personal information;
  • access to or a copy of that information;
  • correction of inaccurate information;
  • deletion;
  • a portable copy in a commonly used format;
  • restriction of or objection to certain processing;
  • withdrawal of consent;
  • opt-out from sale, targeted advertising, or certain profiling;
  • limitation of certain uses of sensitive personal information;
  • review of a decision about your request; and
  • information about categories or specific third parties receiving your data.

We will not discriminate against you for exercising a privacy right.

10. How to exercise a privacy right

Email support@tokki.talk. Describe the right you want to exercise and the account or email involved. Where an in-app control is available for the same choice, you may use that control instead.

We may need to verify your identity and authority before completing a request. We will use information provided for verification only for that purpose. An authorized agent may submit a request where law permits, but we may require proof of authorization and direct verification with you. A parent or guardian may contact us about a child as required by law.

We may deny or limit a request where law permits, for example, if we cannot verify it, if it would affect another person's rights, or if information must be retained for security, transaction, fraud-prevention, legal, or free-expression reasons. We will explain a denial and available appeal method. To appeal, email support@tokki.talk with the subject “Privacy Appeal.”

Users in the EEA or UK may complain to the data protection authority where they live or work or where they believe an infringement occurred. You may contact us first, but you are not required to do so.

11. Account deletion

You can initiate deletion from Settings > Account > Profile > Delete Account. When we accept a request, we restrict ordinary account access, revoke active sessions, and clear local account data from the app. The deletion workflow then permanently removes active account credentials, learning data, private content, and linked media, subject to limited legal, transaction, security, and backup exceptions described in this policy. The app reports the workflow status.

Deletion does not cancel an App Store subscription; cancel it separately through Apple Account Settings. If you cannot authenticate, email support@tokki.talk. If you used Sign in with Apple, we revoke the associated authorization where a revocable Apple credential is available. Apple accounts created before that credential was stored may require the manual Apple revocation path shown in the app; you can also manage authorization in your Apple Account settings.

12. Children

The Service is for people age 13 and older and is not directed to children under 13. We do not knowingly collect personal information from a child under 13. If we learn that we did so without legally valid parental authorization, we will delete it as required by law. Contact support@tokki.talk if you believe a child under 13 has used the Service.

This statement does not override the actual design, marketing, or audience of the Service. We will not market the Service as directed to children or support under-13 accounts unless we first implement a compliant parental notice, verifiable consent, access, deletion, data-minimization, security, and retention program.

Users under the age of legal majority must have a parent or legal guardian's permission and supervision. Some regions provide additional protections for teenagers, which we will honor where applicable.

13. International availability and transfers

The Service is initially offered only in the United States. We and many service providers are based in the United States, although information may be processed in other countries where our providers operate and protections may differ.

We expect to consider international availability after launch. We will not deliberately enable another launch country until we have reviewed and, where needed, updated the applicable privacy notices, consumer terms, pricing, storefront settings, processor arrangements, and cross-border safeguards.

Before deliberately offering the Service in a jurisdiction that requires a transfer mechanism, we will implement an applicable safeguard, such as an adequacy decision, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, or another lawful mechanism. You may contact us for information about a mechanism that applies to your information.

Before deliberately offering the Service outside the United States, we will review territorial scope, processor arrangements, transfer mechanisms, and any required localized notice or representative.

14. Security

We use reasonable administrative, technical, and organizational safeguards appropriate to the nature of the information. These may include encryption in transit, access controls, credential hashing, secrets management, backups, monitoring, and incident response. No system is completely secure, and we cannot guarantee that information will never be lost, accessed, or disclosed without authorization.

You can help by protecting your credentials and devices, using a unique password, installing updates, and telling us promptly about suspected account or security problems.

15. Changes to this policy

We may update this policy prospectively to reflect changes in the Service, law, or our practices. We will update the date and version above and provide notice appropriate to the change. Before a material new use of previously collected information, especially generalized AI training, advertising, biometric identification, or disclosure to a new category of recipient, we will provide clear notice and obtain new affirmative permission where required. We will not rely only on silent posting for a materially different use.

16. Contact us

  • Privacy controller: Little Oboe LLC
  • Mailing address: 418 Broadway, Ste N, Albany, NY 12207, United States
  • Privacy and support email: support@tokki.talk
  • Public privacy notice: https://tokki.talk/privacy

For accessibility assistance with this policy or a privacy request, contact support@tokki.talk.

토끼톡(TOKKI TALK™)

The Korean companion that learns with you.

ABOUTFEATURESFAQFIELD NOTESSUPPORTTERMSPRIVACYCOMMUNITYTOKKI WATCH FOR CHROME ↗INSTAGRAM ↗TIKTOK ↗CONTACT / support@tokki.talk
Tokki Talk™ is a trademark of Little Oboe LLC© 2026 Little Oboe LLC