Hanipi — Privacy Policy
Last updated: 4 September 2026
Hanipi (dev.lehmann.hanip) is a Korean learning app made by Simon Lehmann.
This policy describes what the app sends, where it goes, and what it keeps. It
is written from the app’s actual behaviour rather than from a template.
Contact: simon21lehmann@googlemail.com
The short version
Hanipi has no accounts, no sign-in and no analytics. It does not know who you are. Your learning progress never leaves your phone. What leaves the device is the Korean you write or say during an exercise, at the moment an exercise needs judging, and a random number that identifies the install — not you — so that a weekly allowance of those judgements can be counted against something.
The app is sold through Google Play. Play takes the payment and keeps the payment details; we never see your card, your name or your address.
What stays on your device
All of it, except as described in the next section:
- Which words, letters and grammar patterns you have seen, and how well you recall them (the scheduling data behind reviews).
- Your session history, streaks and progress.
- Any flashcards you import.
- Which of the two purchases this Google account owns, as Google Play reports it to the app.
This is held in a database in the app’s private storage. It is not backed up to any server of ours, and uninstalling the app deletes it.
What is sent off the device, and when
Some exercises need a judgement that arithmetic cannot make — whether a differently-phrased answer still means the same thing, or whether your explanation of a grammar rule is right. Only then does the app make a network request.
It is sent to a server we operate on Cloudflare Workers, which immediately forwards it to Fireworks AI, the language-model provider that produces the judgement. Depending on the exercise, the request contains:
- the Korean sentence you wrote, and the sentence that was expected
- the meaning of the sentence being practised, in your chosen app language (English or German)
- for conversation practice, the scene’s goal and the turns so far in that conversation
- for grammar checks, the rule being practised and your explanation of it in your own words
- for the read-aloud exercise, the sentences you have met and the words on your own deck, so a short passage can be composed from material you know
- when you tap a word to hear it said, that single word, which is sent on to Google Cloud Text-to-Speech to be spoken
- for a 맞춤 session — a short session about a topic you choose — the topic you typed, the words and sentence patterns you have already met and, if you switch it on, the words on your own deck, so the session can be composed from material you know. The sentences that come back are sent on to Google Cloud Text-to-Speech to be spoken, and the audio is stored on your phone with the session so you can replay it without asking again
Every one of those requests also carries an install ID. It is a random number the app invents for itself the first time it is launched — not derived from your phone, your account or anything about you — and it is the same number for every request this install makes. It exists because the AI features have a weekly allowance, and an allowance has to belong to something; this is the smallest thing it can belong to. It survives app updates and a reset of your data in settings — it is not progress, and a reset is not a way to be handed a fresh weekly allowance — and it goes from your phone with the app when you uninstall. What happens to our copy is under Your rights. You can read the number yourself in Settings → About.
Beside it the request carries a token that is identical for every install of a given build. That one identifies the app, not you: it is what keeps the server from being an open proxy for anyone who finds its address.
The request does not contain your name, email, phone number, advertising ID, IP-based location, or anything that connects the install ID to a person.
Our server does not store the text of your requests. It holds a request only for as long as it takes to forward it and return the answer, and it is written so that what you write never appears in its logs. We keep no database of your answers.
Answers are cached, so that asking the same thing twice does not cost a second call to the AI: a spoken word for 90 days, a judgement, an explanation check or a read-aloud passage for 7 days. A cached answer is filed under a one-way hash of the request and carries no install ID, so it cannot be traced back to whoever asked first — and one learner’s cached word is the same entry as everybody else’s. A 맞춤 session is not cached: it is composed for you and returned once, with its audio, and after that it lives only on your phone.
Fireworks AI processes the text in order to generate a response. Their handling of it is governed by their own privacy policy: https://fireworks.ai/privacy-policy. The text sent for speech — a single word, or the lines of a 맞춤 session — is additionally processed by Google Cloud Text-to-Speech under Google’s own terms. A spoken word comes back to the app and is kept only for as long as the app is open; a 맞춤 session’s audio is kept on your phone with the session, and goes with it when you reset your data in settings.
If the network is unavailable, or the app was built without a server configured, every one of these features falls back to an offline judgement and tells you so. The app remains fully usable offline.
What our server keeps
Three things, and nothing else:
- The install ID, with the date it was first seen.
- A weekly count, per install ID, of how many AI answers were produced for it. A number, not a history: what you practised, when, and whether you got it right are not part of it. These weekly rows are deleted automatically once they are eight weeks old.
- The Google Play purchase token for an AI Tutor subscription, if you have one. Play hands it to the app, the app hands it to us, and we keep it for one reason: so we can ask Play — now, and again at each renewal — whether the subscription is still running. It is deleted with the rest of this install’s rows (see Your rights).
There is no name, no email address and no account attached to any of it. Hanipi Complete, the one-time purchase, never reaches our server at all: the content is already on your phone, and the app asks Google Play directly what this Google account owns.
Payments
Both purchases are sold by Google Play, which is the merchant. Play takes the payment, holds the payment details, issues the receipt and handles refunds and cancellations. We never see your card number, your billing address or your name — only, for a subscription, the purchase token described above.
Speech
Exercises that ask you to say something out loud — including reading a passage
aloud — use your device’s own speech recogniser, through Android’s SpeechRecognizer. Hanipi receives only the text
of what was recognised — it never records, stores or transmits audio itself.
The recognition is performed by the system, and on most Android devices that means Google processes the audio. That processing is governed by Google’s privacy policy and your device’s settings, not by us. Microphone permission is requested the first time you tap the microphone, never at launch, and speaking exercises are optional.
What we do not do
- No analytics, telemetry, crash reporting or advertising SDKs of any kind.
- No tracking across apps or websites.
- No sale or sharing of personal data. There is none to sell.
- No profiles built about you.
Children
Hanipi is not directed at children and collects no data that would identify one.
Your rights
There is no account, so there is nothing to sign in to and no profile to export. The rows listed under What our server keeps are the only data we hold, and there are two ways to be rid of them:
- Settings → Reset all progress. Besides clearing your progress on the phone, this asks our server to delete this install’s row, the counts from past weeks and any purchase token. The current week’s count is kept until Monday, so that a reset cannot be used to refill the weekly AI allowance: the one thing here that is deliberately kept when you ask for deletion, and the only one. The number stays on the phone, so the next AI request introduces it to the server again. Your purchases are untouched: Google Play keeps those and restores them automatically.
- Uninstalling the app. Everything on the phone goes with it. On the server an install ID that will never be heard from again is left behind; its weekly counts age out after eight weeks. If you want the row itself gone, reset the data before you uninstall, or write to us.
To ask anything about this — including for a copy or a deletion by hand — write to simon21lehmann@googlemail.com and we will answer.
This website
The pages at this address are static files served by Cloudflare, which sees
your IP address and the page you request in order to deliver it and keeps its
own connection logs under Cloudflare’s terms. The site’s font is loaded from
jsDelivr (cdn.jsdelivr.net), so that request also carries your IP address.
Neither is used by us for anything. The site sets no cookies and runs no
analytics or tracking of any kind. Nothing you do on it is recorded by us.
Changes
If this policy changes in a way that affects what is sent or kept, the date at the top will change and the new version will be published here before the change ships.