Privacy Policy for Naruhodo

Last Updated: September 2026

1. Introduction

Naruhodo ("App", "we", "us", or "our") is a Japanese-learning iOS application. This Privacy Policy explains what information we collect, how it is used, and which third parties receive it when you use the App or the website at naru-app.com.

If you do not agree with these practices, please do not use the App or the website.

2. Information Stored on Your Device

Learning data is stored locally on your device (and, if you enable it, in your personal iCloud account). We do not operate a user-account system.

3. Information We Send Off-Device

3.1 Product analytics (PostHog)

The App uses PostHog (EU cloud, eu.i.posthog.com) to understand how the App is used and to improve it. We send:

PostHog may also receive standard device and request metadata (such as IP address, device type, OS version, and language) as part of operating the SDK. See PostHog's Privacy Policy.

3.2 Subscriptions (RevenueCat and Apple)

Purchases and subscriptions are processed by Apple. We use RevenueCat to manage entitlements and subscription status. RevenueCat receives purchase receipts, product identifiers, and a pseudonymous app user ID. If you arrived via Apple Ads, we send Apple's AdServices attribution token to RevenueCat so we can see which campaigns led to trials and paid subscriptions. This does not use the advertising identifier (IDFA) and does not show an App Tracking Transparency prompt. See RevenueCat's Privacy Policy and Apple's Privacy Policy.

3.3 Advertising measurement (TikTok)

In release builds, the App initializes the TikTok Business SDK at launch. There is no in-app setting to turn this off. TikTok may receive:

We do not currently request App Tracking Transparency permission, so we do not collect or share the advertising identifier (IDFA). See TikTok's Privacy Policy.

3.4 Content delivery (Cloudflare)

Video clips and content files are downloaded from our content servers on Cloudflare. Those requests include standard HTTP data (IP address, device type, user agent). See Cloudflare's Privacy Policy.

3.5 Website (naru-app.com)

The marketing site is a Cloudflare Worker. Cloudflare sees standard request data (including IP address) to deliver the site. For tracked links (for example /r/<code>), we store only the campaign code, event kind, country code (cf-ipcountry), and user agent — not the IP address. The website does not currently load a Meta Pixel or similar browser advertising pixel.

3.6 Instagram comment-to-DM (our servers)

If you comment a campaign keyword on one of our Instagram accounts (currently Naru, Riley, or Rhea), Meta sends us a webhook. We store that event in our own database so we can send at most one private reply with a tracked App Store link and debug failures. Stored fields include:

We keep these rows to operate and audit the feature (dedupe, one DM per person per post, failure diagnosis). They are not used to advertise to you in the App. Meta also processes the same comments and DMs under Instagram's Privacy Policy; that does not replace this disclosure of what we store.

3.7 Android waitlist

If you submit the Android waitlist form on naru-app.com, we store your email, a source tag, country code (cf-ipcountry), user agent, and the time of signup in our Cloudflare R2 bucket. We use this only to notify you if an Android version becomes available.

3.8 Content-drop votes

If you vote on a content-drop poll in the App, the vote is sent to our servers. We store a device identifier in the poll's voter list so the same device cannot vote twice, plus per-option counts. This is not used for advertising.

4. Information We Do Not Collect

5. How We Use This Information

We do not sell your personal data.

6. Advertising measurement (Meta)

In release builds, the App initializes the Meta / Facebook SDK at launch. There is no in-app setting to turn this off. We do not show an App Tracking Transparency prompt, and we disable collection of the advertising identifier (IDFA). Meta's SKAdNetwork conversion-value updates are also disabled; TikTok is the only service that updates those values.

When this runs, Meta may receive:

Meta's SDK privacy manifest declares Device ID as used for tracking, linked to the user, for Third-Party Advertising, App Functionality, and Analytics, with tracking domain ep1.facebook.com. Campaign measurement is intended to use Meta Aggregated Event Measurement, not SKAdNetwork. See Meta's Privacy Policy.

7. Data Retention

8. Data Security

9. Your Privacy Rights

9.1 Access and deletion

Uninstalling the App or clearing it in iOS Settings deletes on-device App data only. iCloud backups can be removed in iOS Settings > [your name] > iCloud (the App has no in-app delete-backup control). We do not currently offer an in-app control to stop TikTok or Meta measurement, PostHog analytics, or RevenueCat. To ask us to delete data we or our processors hold (analytics, subscriptions, ads measurement, feedback, website click logs, Android waitlist email, content-drop votes), email salahedine-youssef@outlook.de. For Instagram comment-to-DM records, follow naru-app.com/data-deletion. Fulfilling a request may require us to work with those processors; this policy does not promise a timed or complete erasure of copies they retain.

9.2 Tracking and advertising

We do not show an App Tracking Transparency prompt and we do not collect IDFA. The TikTok Business SDK and the Meta / Facebook SDK run when the App launches (in release builds) and send measurement events; there is no in-app opt-out. We also send Apple Ads attribution tokens to RevenueCat. iOS Settings > Privacy & Security still controls system-level tracking and Apple Ads preferences.

9.3 Age

The App is intended for users 13 years and older. We do not knowingly collect personal data from children under 13.

10. California and European privacy rights

Depending on where you live, privacy law may give you rights to access, correct, or delete personal information, to object, or to opt out of sale or sharing. We do not sell personal information for money. TikTok and Meta measurement may count as “sharing” under some U.S. state laws. This page describes what we collect; it is not legal advice and does not claim a particular GDPR legal basis (for example legitimate interests or consent) for advertising measurement. To make a request, email salahedine-youssef@outlook.de.

11. Contact Us

Questions about this policy or our privacy practices:

Email: salahedine-youssef@outlook.de

12. Changes to This Policy

We may update this Privacy Policy. We will change the "Last Updated" date for material changes. Continued use of the App or website after changes constitutes acceptance of the updated policy.


Summary of data practices:

Data Collected Where Shared with Used for
Learning data (prefs, vocab, favorites, progress) Yes Device; optional iCloud Apple iCloud if you enable backup App features
Product events Yes PostHog (EU) PostHog Analytics
Pseudonymous app user ID Yes RevenueCat, PostHog RevenueCat, PostHog Subscriptions, analytics
Purchases / trials Yes Apple, RevenueCat; TikTok and Meta for measurement Apple, RevenueCat, TikTok, Meta Subscriptions, ads measurement
IDFV, IP, user agent (TikTok SDK) Yes, in release builds TikTok TikTok Ads measurement
IDFA No
Optional feedback + email Only if you submit it PostHog PostHog Support
Content requests (IP) Yes Cloudflare Cloudflare Content delivery
Website tracked-link clicks (code, country, user agent) Yes Our Cloudflare Worker / D1 Cloudflare as processor (IP is used to serve the request; we do not store IP in D1) Outreach measurement
Instagram commenter ID, comment text, raw webhook payload Yes, if you comment a keyword on our IG accounts Our Cloudflare D1 Stored by us; Meta also has the original comment Comment-to-DM outreach
Android waitlist email Yes, if you submit the form Our Cloudflare R2 Stored by us Notify about Android
Content-drop voter device ID Yes, if you vote Our Cloudflare R2 Stored by us One vote per device
Meta SDK device identifier, IP, user agent; install, launch, trial, purchase events Yes, in release builds Meta Meta Ads measurement

← Back to Naru · Terms of Service · Data deletion