Privacy Policy
Updated August 3, 2026
Privacy Policy
Your privacy is important to Wozi Pte. Ltd. This Privacy Policy explains how we collect, use, disclose, transfer, and store information when you use our iOS application and other online products and services (the Services).
We aim to collect the minimum personal information necessary to operate the Services. Where we do collect data, we do so for the purposes set out below and in accordance with applicable laws.
Controller and How to Contact Us
If you have questions about this policy or our data practices, please contact us using the details above.
Controller
Wozi Pte. Ltd. (incorporated in Singapore)
contact@wozi.app
Scope
This policy applies to the Services provided by Wozi Pte. Ltd., including our iOS application available on the Apple App Store worldwide. It does not apply to third-party websites, applications, or services that may link to or integrate with our Services. Please review their privacy policies.
Information We Collect
We do not access your location, contacts, or health data.
1) Information you provide to us
- User-generated content: Text, photos, voice recordings, and other content you create within the app. This content is stored locally on your device unless you choose to use an online feature that processes specific content.
- Communications: Content you submit through support requests, feedback forms, or other communications. When you choose in-app support, Crisp assigns a pseudonymous support/session ID and processes messages, attachments, any email address or phone number, and any photos or videos you optionally submit.
2) Information collected automatically
Device and usage information, such as device type, operating system, application version, language, pseudonymous identifiers, timestamps, and basic event logs necessary to operate the Services.
Wozi does not require sign-in. When an online feature uses the application backend, the app may create an online guest account identified by a persistent pseudonymous UUID. We do not collect a name or email address for that guest account.
Product-usage events, crash reports, and diagnostics collected through PostHog are associated with a PostHog-generated pseudonymous distinct ID. If an online guest account exists, Wozi causes that PostHog identity to become associated with or merged with the persistent pseudonymous guest UUID to help us understand app use and fix issues.
The online guest account and session are used when online functionality runs, including online pronunciation or study support. The GRDB study database remains local to your device and is not synced to Supabase.
If APNs registration succeeds, the device push token is provided to Crisp to deliver support-message notifications. This data is used for App Functionality and not for advertising or cross-app tracking.
3) Device permissions
Certain features of the app require access to device capabilities. You will be prompted before use.
- Camera: Used for taking photos within the app. Photos are stored locally on your device.
- Microphone: Used for voice input features. Voice recordings may be processed by AI providers to power certain features.
How We Use Information
We use the information we collect to:
- Provide, operate, and maintain the Services, including local app features and device-local storage.
- Process your content through AI-powered features to provide functionality within the app.
- Communicate with you about policy or service changes and security alerts.
- Improve and develop the Services through pseudonymous product analytics, diagnostics, and research.
- Maintain safety, integrity, and security.
- Comply with legal obligations and enforce our terms.
Third-Party Service Providers
We use third-party service providers to help operate the Services. These providers process data on our behalf under appropriate agreements.
- Apple (United States): Payment processing for in-app purchases.
- RevenueCat (United States): Purchase validation, restoration, and entitlement management. RevenueCat receives App Store purchase and entitlement information; technical information such as device type, operating system, app version and build, locale, storefront, network information such as IP address, and the device's vendor identifier (IDFV); and a RevenueCat-generated anonymous App User ID. In the normal guest purchase and restore flow, Wozi does not send its persistent guest UUID to RevenueCat. If an account identity path is used, Wozi also sends its pseudonymous Wozi account UUID alongside the existing RevenueCat-generated anonymous App User ID. Wozi does not send RevenueCat a name, email address, phone number, advertising identifier, or user-created content.
- PostHog (United States): Pseudonymous product analytics, crash reporting, and error tracking. PostHog receives a PostHog-generated pseudonymous distinct ID and a stable device/configuration identifier. If an online guest account exists, Wozi causes the PostHog distinct identity to become associated with or merged with the persistent pseudonymous guest UUID so we can understand app use and diagnose issues across sessions.
- Supabase: Anonymous authentication and session services when online functionality runs, including online pronunciation or study support. Supabase receives a persistent pseudonymous guest UUID and authentication and session metadata. The GRDB study database remains local to your device and is not synced to Supabase.
- Crisp: In-app customer support and support push notifications. Crisp receives a pseudonymous support/session ID, messages and attachments you submit, any email address or phone number you optionally submit, any photos or videos you optionally submit in support, and the device push token used for APNs notifications. This data is used for App Functionality and not for advertising or cross-app tracking.
- AI Providers — Google, OpenAI, and Anthropic (United States): text and user-generated content processing for app features under agreements that do not use your data for model training.
- Microsoft (United States): online text-to-speech processing for pronunciation when online pronunciation is used.
Legal Bases for Processing (EEA/UK)
Where GDPR or similar laws apply, we process personal data on the following legal bases:
- Your consent (for optional permissions and features).
- Performance of a contract (to provide the Services you request).
- Compliance with legal obligations.
- Our legitimate interests (to secure and improve the Services), balanced against your rights.
Sharing and Disclosure
We do not sell your personal information. We share information as follows:
- Service providers: to operate the Services under confidentiality and data protection obligations.
- Legal and safety: to comply with laws and protect rights, property, and safety.
- Business transfers: during merger, acquisition, reorganization, or asset sale.
- Aggregated or de-identified information that does not reasonably identify you.
Data Retention
Most app content is stored locally on your device. We retain online guest-account information, pseudonymous product analytics and diagnostics, and other personal information only as long as needed to provide the Services or meet legal obligations. RevenueCat may retain purchase and entitlement records as needed to validate or restore purchases and to meet Apple requirements or legal obligations. Supabase may retain the anonymous authentication account, its persistent pseudonymous guest UUID, and related session records only as needed for authentication, security, or legal obligations. Crisp may retain support conversation content, attachments, contact details you choose to provide, and support-notification records only as needed to provide support, secure the service, or meet legal obligations.
Security
We use technical and organizational measures designed to protect personal information, including encryption in transit and access controls. No system is completely secure.
International Transfers
Your data may be transferred to and processed in countries outside your country of residence, including the United States and Singapore. We apply safeguards as required by applicable law.
Your Rights
Depending on your location, you may have rights such as access, correction, deletion, restriction, portability, and objection. Where processing is based on consent, you can withdraw consent at any time.
The PostHog SDK stores the current distinct ID and stable device/configuration ID for analytics, and the app includes them in a privacy-request email. Separately, Wozi locally archives prior PostHog distinct IDs solely to help with an erasure or support request after an analytics reset. You can clear this prior-ID support archive in the app. For privacy or deletion requests about retained provider records, contact us at contact@wozi.app.
RevenueCat purchase and entitlement records are subject to Apple requirements and applicable legal retention. Where erasure applies, Wozi handles the RevenueCat customer-data request through an operator-managed process.
Requests to access or delete retained Supabase guest-account/session records or Crisp support records are handled by Wozi through an operator-managed process; contact contact@wozi.app. The app does not currently provide in-app deletion of the online guest account.
You may also lodge a complaint with your local data protection authority.
Children
Our Services are designed for users aged 16 and older. We do not knowingly collect personal information from children under 16 (or equivalent minimum age).
Third-Party Sites and Services
The Services may contain links to third-party sites or services. Their practices are governed by their own privacy policies.
Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the date at the top. If changes are material, we will provide additional notice as required by law.
Last modified: August 3, 2026