Rekura

Privacy Policy · Effective September 6, 2026

Rekura is an app for learning English vocabulary. It is fully usable without an account: in that case all your data — cards, translations, notes, images, review history — is stored only on your device, and we have no access to it.

Who we are

The app is developed and operated by the Rekura team — an independent developer acting as the data controller for the purposes of data protection law. The developer's registered name is shown on the app's App Store and Google Play listings. Contact for privacy requests: [email protected].

What we collect and why

Account and sync (optional)

If you sign in with Google to sync your library between devices, the cloud (Supabase, servers in the EU) stores: your sign-in email address, your cards — words, translations, transcriptions, notes, examples — attached images, sets, and review history with retention metrics. This data serves one purpose: showing your library on your other devices.

Synced data is protected by authentication and row-level security: the API serves only the rows and files that belong to your account. Data is encrypted in transit. Synchronization is not end-to-end encrypted, so your data can technically be processed by our cloud infrastructure provider (Supabase) and by the developer as the service administrator.

Diagnostics (can be turned off)

The app sends crash reports (Firebase Crashlytics) and pseudonymous usage diagnostics (Firebase Analytics). These events contain no words, no translations, none of your card content, and are not linked to your account. They are, however, associated with technical identifiers (such as a Firebase app-instance ID) and may include technical information about your device and an approximate location derived from your IP address — so this data is pseudonymous rather than fully anonymous. No advertising identifier is collected. The toggle is in Settings → About; it disables both crash reports and usage diagnostics at once.

This website

The website at rekuraapp.com counts two things: that a page was opened, and that a store button was pressed. We use these counts to compare two versions of the landing page. There is no third-party analytics, no advertising or tracking script, and no analytics cookie. The single cookie the site sets holds one letter — the version of the page you were shown — so that a return visit shows you the same one.

Visitors are not identified. Instead of your IP address we store a hash of it together with your browser string and a salt that changes at midnight, so the same visitor on the next day is an unrelated value and the hash cannot be turned back into an address. Alongside it we store the page version, which of the two events it was, the host you arrived from (never the full address), and the two-letter country code reported by our hosting provider. Your IP address itself is not stored and does not leave Cloudflare. These records are deleted after 90 days.

Service providers

We do not sell personal data or share it for advertising. We disclose limited data to service providers necessary for authentication, synchronization, diagnostics, dictionary lookup, and image search:

Each provider processes this data under its own privacy policy. Word pronunciation uses the system's own voices, on the device; no text is sent anywhere for speech.

Storage, retention and deletion

Cloud data is kept for as long as the account exists and is erased when you delete it. You can delete the account right in the app (Settings → Sync → “Delete account”) — this permanently erases all cloud data, including the account itself. To delete the account without the app, see the account deletion page.

Diagnostics data is retained on Google's servers for limited periods: crash reports for around 90 days, analytics data for the period configured in Firebase (at most 14 months) — see Firebase privacy information.

On-device data can be erased in the app's settings (“Erase all data”) or by uninstalling the app. On iOS, locally stored data (your database and images) may be included in your device's system backups (iCloud or computer backups), governed by your Apple backup settings. On Android, app data is excluded from system backups.

Your rights

At any time you can export all your data to a file (Settings → “Export”), correct it in the app, delete it or the whole account, and turn diagnostics off. For any questions or requests about your data, write to [email protected] — we will respond and fulfil requests within 30 days.

Changes

If this policy changes, the new version will appear on this page with a new effective date. For material changes we will additionally announce the update in the app or on this site before it takes effect.