Privacy notice
Updated October 6, 2026 · Early accessWhat we store
We store your email, display name, password hash, learning preferences, scene conversations, task evidence, feedback, saved expressions and credit records to maintain your progress. Guests also use a server session. The account cookie lasts 30 days and is not used for advertising.
Models and API keys
BYOK keys are encrypted on the server with AES-256-GCM and are never returned to the browser. Fetching models sends your key to the chosen provider to list available models. AI scenes send your current input, relevant scene facts, recent dialogue and learning summaries to that provider. Providers have their own privacy and retention policies. Guided practice uses predefined logic and does not send conversations to a model.
Voice
Voice input uses your browser’s speech recognition service, which may process audio in the cloud. It starts only after you click the microphone and grant permission. You can edit the transcript before sending. Basic read-aloud uses installed browser voices. Optional neural voice sends only the text you choose to play to OpenAI using your separately encrypted voice key. This is AI-generated speech. Audio is kept temporarily in the page for replay, not stored in our database. OpenAI applies its own processing and retention policies.
Security and infrastructure
The early service is hosted on AWS in the United States with Cloudflare providing the network entry point. These services may process IP addresses, request times and response statuses for operation and abuse prevention. Application logs do not contain keys, passwords or complete model requests. Connections use HTTPS.
Retention, export and deletion
Settings lets you export your learning data, remove model or voice keys, and permanently delete your account and related records. Deletion immediately removes data from the active database. Encrypted backups, when enabled, rotate within 14 days and are used for disaster recovery. Maintenance removes expired guest data after 30 days of inactivity. Registered account data remains until you delete it.
Your choices
Use fictional names, bookings and payments in scenes. Do not enter real identity documents, card details or other sensitive information. This version is for learners aged 18 and over. LinguaScene is operated by Kikyo, an independent developer under the Nivalune project name, at mykikyo.com. For privacy questions or data requests, contact [email protected]. Data controls are also available in account settings. We will update this notice before introducing paid features or new uses of data.
Necessary cookies and local preferences
linguascene_session is the only application identity cookie. It uses HttpOnly, SameSite=Lax and Secure on HTTPS. Interface language, appearance, learning support switches and browser voice choice are stored locally on your device. Unsent drafts are stored in the current browser tab. Contact emails are processed through Cloudflare Email Routing and the operator’s Gmail inbox; correspondence is retained as needed to handle your request, and you may ask for its deletion. We do not use advertising, marketing trackers or third-party analytics scripts.