ORANGE FOX LLC · Danki

Privacy Policy

Danki works without an account for local study. Account sign-in, purchase linking, optional paid sync, support, and voice features use only the information needed for the feature you choose.

Effective and last updated: September 17, 2026

1. Who controls your information

ORANGE FOX LLC is the controller for the Danki website, web app, and app-family processing described in this notice. Apple, Google, Paddle, and some other providers may also act as independent controllers for information they process under their own notices. To ask a privacy question or exercise a right, use the Danki support form.

2. Information and features

Local app and web learning data

Study progress, review history, bookmarks, settings, recovery data, imported mnemonics, and offline content are stored on your device or in your browser. Related Apple apps, widgets, and watch apps may share local data through an Apple App Group. Danki cannot access local-only learning data. You can use local study without an account.

Accounts and optional sync

If you sign in with Apple or Google through Clerk, Danki receives an internal account identifier and profile information supplied by that sign-in, such as name, email, profile image, provider account identifier, and session information. If you enable paid sync, Danki stores current learning state, bookmarks, study targets, compact daily activity, completed-session summaries, library-growth snapshots, device and change-ordering information, and the before-image needed to undo the newest eligible action. Local debug flags, active quiz position, themes, navigation state, and imported mnemonic text are not included in progress sync.

Purchases and access

Apple processes purchases made in the native apps. Website purchases open a RevenueCat-hosted purchase page backed by Paddle, the Merchant of Record. Paddle processes buyer identity, location, contact, billing, payment, invoice, tax, refund, and subscription-management information. RevenueCat processes Danki's internal account identifier, product and offering information, purchase evidence, and entitlement status. Danki stores linked transaction identifiers, verification timestamps, and access snapshots, but does not receive or store full payment-card details. Linking a purchase does not enable progress sync.

Support and feedback

The website support form sends the name, email address, topic, message, and CAPTCHA verification you provide to Web3Forms and hCaptcha. Native-app feedback sends the category, optional message, app version, and build number to Web3Forms and does not include your name, email, account identifier, advertising identifier, device model, operating-system version, or study data. Web-app feedback is stored directly by Danki and includes its category, message, random browser-device identifier, optional contact email, and only the current technical details you explicitly choose to include at submission. That choice is off by default. Danki does not retain a persistent route, error, performance, or sync diagnostic history in browser storage.

Voice commands

Voice commands are optional. Apple's Speech framework or browser speech recognition processes microphone audio after you grant permission. When Apple cannot recognize speech on-device, it may process audio on its servers. Danki uses the current transcript to recognize a command and does not store the audio or transcript.

Website delivery and security

Vercel processes request information such as IP address, user agent, requested path, timestamp, and security events to deliver and protect the website and sync API. Runtime-log retention depends on the hosting plan and is currently no more than 30 days. Danki does not use advertising SDKs, sell personal information, or track you across other companies' apps or websites.

4. Cookies and browser storage

Danki does not set advertising or third-party analytics cookies on its own pages. The storage below supports security, sign-in, local study, offline use, and purchases. Because Danki currently uses only strictly necessary storage or storage requested for app functionality on its own pages, it does not show a cookie-consent banner. Danki will ask for consent before introducing non-essential storage where law requires it.

TechnologyProviderPurposeDuration or criterionTreatment
Authentication cookiesClerkKeep you signed in, maintain the selected account, and protect account requests.Session-based or until the authentication session expires or you sign out.Strictly necessary; no consent banner.
Local storageDankiKeep study progress, settings, recent Undo data, the random browser-device identifier used to order offline changes, and sync adoption state.On this browser until you reset the relevant data, clear site data, or the browser removes it.Requested app functionality; no advertising or cross-site tracking.
IndexedDBDankiKeep pending offline changes, recovery snapshots, local sync state, and mnemonic stories imported from a CSV you select.On this browser until you reset or clear the relevant data, remove an imported mnemonic, or the browser removes it.Requested app and offline functionality; no advertising or cross-site tracking.
Cache StorageDankiKeep visited app assets and canonical study content available offline, including a study pack you explicitly download.Until replaced by a newer release, cleared in Settings or browser controls, or evicted by the browser.Requested app and offline functionality; no advertising or cross-site tracking.
Security storage and signalshCaptchaDistinguish people from automated abuse when the website support form is used.Determined by hCaptcha's security service and applicable retention settings.Strictly necessary for support-form security; no Danki advertising purpose.
Hosted checkout storageRevenueCat and PaddleRun checkout, prevent fraud, remember checkout preferences, and manage purchases.Determined by the provider on the hosted purchase or checkout page.Used after you choose to open the hosted purchase flow; provider consent controls apply where required.

5. Providers and other recipients

Danki shares information only with providers needed for the feature you use, with professional advisers when necessary, during a lawful business transfer, or when required to comply with law or protect rights and safety. It does not share personal information for behavioral advertising.

ProviderRoleProvider notice
AppleNative purchases, Sign in with Apple, file selection, and optional speech recognitionapple.com/legal/privacy
GoogleOptional Google account sign-inpolicies.google.com/privacy
ClerkAccount authentication and essential session cookiesclerk.com/legal/privacy
RevenueCatHosted purchase links, purchase evidence, and cross-platform entitlement reconciliationrevenuecat.com/privacy-policy
PaddleMerchant of Record for website purchases, checkout, tax, invoices, refunds, fraud prevention, and payment managementpaddle.com/legal/privacy
VercelWebsite and sync-API hosting, delivery, security, and short-lived runtime logsvercel.com/legal/privacy-notice
TursoDatabase hosting for optional account sync and related operational recordsturso.tech/privacy-policy
Web3FormsForwarding app feedback and website support submissionsweb3forms.com/privacy
hCaptchaSupport-form abuse preventionhcaptcha.com/privacy

6. International transfers

ORANGE FOX LLC is based in the United States, and the providers above may process information in the United States and other countries whose laws may differ from those where you live. Where EU, EEA, UK, or Swiss transfer rules apply, Danki relies on an available lawful transfer mechanism. Depending on the provider and transfer, that may be an adequacy decision, the EU-U.S. Data Privacy Framework and its UK or Swiss extensions, the European Commission's Standard Contractual Clauses, or the UK Addendum. Paddle acts under its own buyer privacy notice for checkout information it controls. You may contact Danki for information about the safeguard relevant to a particular transfer.

7. Retention and deletion

  • Local and browser data: remains until you reset it, remove an imported item, clear site/app data, uninstall every related app that shares it, or the operating system or browser removes it.
  • Account and sync data: remains while your account and sync service are active. If sync lapses, new cloud writes stop after any billing grace period and synced learning data remains available for export for 90 days by default before scheduled deletion. A still-paid sync subscription retains cloud data even if Pro access lapses. Account deletion removes the Clerk identity and Danki cloud records; RevenueCat customer cleanup is queued and retried separately.
  • Operational records: mutation receipts and limited conflict, recovery, and lifecycle diagnostics are retained for up to 180 days; rate-limit windows for up to 24 hours; and deletion identity tombstones for 8 days. These records are limited to operating, securing, and safely deleting the service.
  • Support and feedback: Danki retains web-app feedback for up to 365 days. Resulting support email is retained for no more than 12 months unless it is needed to finish an ongoing request or preserve a legal claim. Web3Forms' current notice says form-submission data may be retained for up to three years, or less if the applicable plan or earlier deletion provides a shorter period; its server logs are deleted on a regular basis.
  • Hosting: Vercel runtime logs are currently retained for no more than 30 days. Security records may be kept longer when necessary to investigate an incident or comply with law.
  • Purchases: Danki, Paddle, RevenueCat, and Apple may retain purchase, tax, accounting, refund, fraud-prevention, and dispute records for periods required by law or reasonably needed to establish, exercise, or defend legal claims.

8. Your privacy rights

Depending on where you live, you may ask to access, correct, delete, restrict, or receive a portable copy of your personal information; object to processing based on legitimate interests; or withdraw consent where consent is the basis. You may also appeal or complain as local law provides. Danki may need to verify your identity and may retain information when law requires it or when needed for legal claims.

Use the support form to make a request. You may also complain to the data-protection authority where you live, work, or believe an infringement occurred. EEA authorities are listed by the European Data Protection Board, and the UK authority is the Information Commissioner's Office.

You are not required to provide information for local-only study. Account and session information is required to sign in; purchase information is required to complete and link a purchase; and the fields marked required on the support form are needed to receive and answer the request. If you do not provide those details, Danki cannot provide that specific feature. Danki does not use solely automated decisions that produce legal or similarly significant effects about you.

9. Children and policy changes

Danki is a general-audience learning service and does not knowingly collect personal information from children. If you believe a child submitted personal information, contact Danki so it can be reviewed and removed. This policy may be updated when features, providers, or legal requirements change. Material changes will be identified by updating the effective date and, when appropriate, giving additional notice in the service.