ORANGE FOX LLC · Danki
Privacy Policy
Danki works without an account for local study. Account sign-in, purchase linking, optional paid sync, support, and voice features use only the information needed for the feature you choose.
Effective and last updated: September 17, 2026
1. Who controls your information
ORANGE FOX LLC is the controller for the Danki website, web app, and app-family processing described in this notice. Apple, Google, Paddle, and some other providers may also act as independent controllers for information they process under their own notices. To ask a privacy question or exercise a right, use the Danki support form.
2. Information and features
Local app and web learning data
Study progress, review history, bookmarks, settings, recovery data, imported mnemonics, and offline content are stored on your device or in your browser. Related Apple apps, widgets, and watch apps may share local data through an Apple App Group. Danki cannot access local-only learning data. You can use local study without an account.
Accounts and optional sync
If you sign in with Apple or Google through Clerk, Danki receives an internal account identifier and profile information supplied by that sign-in, such as name, email, profile image, provider account identifier, and session information. If you enable paid sync, Danki stores current learning state, bookmarks, study targets, compact daily activity, completed-session summaries, library-growth snapshots, device and change-ordering information, and the before-image needed to undo the newest eligible action. Local debug flags, active quiz position, themes, navigation state, and imported mnemonic text are not included in progress sync.
Purchases and access
Apple processes purchases made in the native apps. Website purchases open a RevenueCat-hosted purchase page backed by Paddle, the Merchant of Record. Paddle processes buyer identity, location, contact, billing, payment, invoice, tax, refund, and subscription-management information. RevenueCat processes Danki's internal account identifier, product and offering information, purchase evidence, and entitlement status. Danki stores linked transaction identifiers, verification timestamps, and access snapshots, but does not receive or store full payment-card details. Linking a purchase does not enable progress sync.
Support and feedback
The website support form sends the name, email address, topic, message, and CAPTCHA verification you provide to Web3Forms and hCaptcha. Native-app feedback sends the category, optional message, app version, and build number to Web3Forms and does not include your name, email, account identifier, advertising identifier, device model, operating-system version, or study data. Web-app feedback is stored directly by Danki and includes its category, message, random browser-device identifier, optional contact email, and only the current technical details you explicitly choose to include at submission. That choice is off by default. Danki does not retain a persistent route, error, performance, or sync diagnostic history in browser storage.
Voice commands
Voice commands are optional. Apple's Speech framework or browser speech recognition processes microphone audio after you grant permission. When Apple cannot recognize speech on-device, it may process audio on its servers. Danki uses the current transcript to recognize a command and does not store the audio or transcript.
Website delivery and security
Vercel processes request information such as IP address, user agent, requested path, timestamp, and security events to deliver and protect the website and sync API. Runtime-log retention depends on the hosting plan and is currently no more than 30 days. Danki does not use advertising SDKs, sell personal information, or track you across other companies' apps or websites.
3. Purposes and legal bases
The legal basis depends on the feature and your location. Danki does not rely on consent for processing that is necessary to provide a service you request. Where it does rely on consent, you may withdraw it without affecting earlier lawful processing.
| Purpose | Information | GDPR / UK GDPR basis |
|---|---|---|
| Provide local study, an account, optional sync, purchase linking, and paid access | Information you choose to store locally; account and session identifiers; synced learning state; purchase and entitlement records | Performance of a contract or steps you request before entering one |
| Answer support and feedback requests | Name and email when supplied, topic, message, app version/build, and optional current technical details | Performance of a contract or steps you request; legitimate interests in support and product quality |
| Protect accounts, forms, infrastructure, and payments | Session, request, network, device, anti-abuse, and security-event information | Legitimate interests in security, fraud prevention, reliability, and protecting users |
| Keep required business and transaction records | Purchase, refund, tax, accounting, dispute, and compliance records | Legal obligations and legitimate interests in establishing, exercising, or defending legal claims |
| Use optional microphone or speech-recognition features | Microphone audio and the current command transcript | Your permission or consent and the feature you request; you can withdraw device permission at any time |
4. Cookies and browser storage
Danki does not set advertising or third-party analytics cookies on its own pages. The storage below supports security, sign-in, local study, offline use, and purchases. Because Danki currently uses only strictly necessary storage or storage requested for app functionality on its own pages, it does not show a cookie-consent banner. Danki will ask for consent before introducing non-essential storage where law requires it.
| Technology | Provider | Purpose | Duration or criterion | Treatment |
|---|---|---|---|---|
| Authentication cookies | Clerk | Keep you signed in, maintain the selected account, and protect account requests. | Session-based or until the authentication session expires or you sign out. | Strictly necessary; no consent banner. |
| Local storage | Danki | Keep study progress, settings, recent Undo data, the random browser-device identifier used to order offline changes, and sync adoption state. | On this browser until you reset the relevant data, clear site data, or the browser removes it. | Requested app functionality; no advertising or cross-site tracking. |
| IndexedDB | Danki | Keep pending offline changes, recovery snapshots, local sync state, and mnemonic stories imported from a CSV you select. | On this browser until you reset or clear the relevant data, remove an imported mnemonic, or the browser removes it. | Requested app and offline functionality; no advertising or cross-site tracking. |
| Cache Storage | Danki | Keep visited app assets and canonical study content available offline, including a study pack you explicitly download. | Until replaced by a newer release, cleared in Settings or browser controls, or evicted by the browser. | Requested app and offline functionality; no advertising or cross-site tracking. |
| Security storage and signals | hCaptcha | Distinguish people from automated abuse when the website support form is used. | Determined by hCaptcha's security service and applicable retention settings. | Strictly necessary for support-form security; no Danki advertising purpose. |
| Hosted checkout storage | RevenueCat and Paddle | Run checkout, prevent fraud, remember checkout preferences, and manage purchases. | Determined by the provider on the hosted purchase or checkout page. | Used after you choose to open the hosted purchase flow; provider consent controls apply where required. |
5. Providers and other recipients
Danki shares information only with providers needed for the feature you use, with professional advisers when necessary, during a lawful business transfer, or when required to comply with law or protect rights and safety. It does not share personal information for behavioral advertising.
| Provider | Role | Provider notice |
|---|---|---|
| Apple | Native purchases, Sign in with Apple, file selection, and optional speech recognition | apple.com/legal/privacy |
| Optional Google account sign-in | policies.google.com/privacy | |
| Clerk | Account authentication and essential session cookies | clerk.com/legal/privacy |
| RevenueCat | Hosted purchase links, purchase evidence, and cross-platform entitlement reconciliation | revenuecat.com/privacy-policy |
| Paddle | Merchant of Record for website purchases, checkout, tax, invoices, refunds, fraud prevention, and payment management | paddle.com/legal/privacy |
| Vercel | Website and sync-API hosting, delivery, security, and short-lived runtime logs | vercel.com/legal/privacy-notice |
| Turso | Database hosting for optional account sync and related operational records | turso.tech/privacy-policy |
| Web3Forms | Forwarding app feedback and website support submissions | web3forms.com/privacy |
| hCaptcha | Support-form abuse prevention | hcaptcha.com/privacy |
6. International transfers
ORANGE FOX LLC is based in the United States, and the providers above may process information in the United States and other countries whose laws may differ from those where you live. Where EU, EEA, UK, or Swiss transfer rules apply, Danki relies on an available lawful transfer mechanism. Depending on the provider and transfer, that may be an adequacy decision, the EU-U.S. Data Privacy Framework and its UK or Swiss extensions, the European Commission's Standard Contractual Clauses, or the UK Addendum. Paddle acts under its own buyer privacy notice for checkout information it controls. You may contact Danki for information about the safeguard relevant to a particular transfer.
7. Retention and deletion
- Local and browser data: remains until you reset it, remove an imported item, clear site/app data, uninstall every related app that shares it, or the operating system or browser removes it.
- Account and sync data: remains while your account and sync service are active. If sync lapses, new cloud writes stop after any billing grace period and synced learning data remains available for export for 90 days by default before scheduled deletion. A still-paid sync subscription retains cloud data even if Pro access lapses. Account deletion removes the Clerk identity and Danki cloud records; RevenueCat customer cleanup is queued and retried separately.
- Operational records: mutation receipts and limited conflict, recovery, and lifecycle diagnostics are retained for up to 180 days; rate-limit windows for up to 24 hours; and deletion identity tombstones for 8 days. These records are limited to operating, securing, and safely deleting the service.
- Support and feedback: Danki retains web-app feedback for up to 365 days. Resulting support email is retained for no more than 12 months unless it is needed to finish an ongoing request or preserve a legal claim. Web3Forms' current notice says form-submission data may be retained for up to three years, or less if the applicable plan or earlier deletion provides a shorter period; its server logs are deleted on a regular basis.
- Hosting: Vercel runtime logs are currently retained for no more than 30 days. Security records may be kept longer when necessary to investigate an incident or comply with law.
- Purchases: Danki, Paddle, RevenueCat, and Apple may retain purchase, tax, accounting, refund, fraud-prevention, and dispute records for periods required by law or reasonably needed to establish, exercise, or defend legal claims.
8. Your privacy rights
Depending on where you live, you may ask to access, correct, delete, restrict, or receive a portable copy of your personal information; object to processing based on legitimate interests; or withdraw consent where consent is the basis. You may also appeal or complain as local law provides. Danki may need to verify your identity and may retain information when law requires it or when needed for legal claims.
Use the support form to make a request. You may also complain to the data-protection authority where you live, work, or believe an infringement occurred. EEA authorities are listed by the European Data Protection Board, and the UK authority is the Information Commissioner's Office.
You are not required to provide information for local-only study. Account and session information is required to sign in; purchase information is required to complete and link a purchase; and the fields marked required on the support form are needed to receive and answer the request. If you do not provide those details, Danki cannot provide that specific feature. Danki does not use solely automated decisions that produce legal or similarly significant effects about you.
9. Children and policy changes
Danki is a general-audience learning service and does not knowingly collect personal information from children. If you believe a child submitted personal information, contact Danki so it can be reviewed and removed. This policy may be updated when features, providers, or legal requirements change. Material changes will be identified by updating the effective date and, when appropriate, giving additional notice in the service.