Privacy Policy

Effective 2026-07-21

This policy explains what Lock In Japanese ("we") processes on this website and in the Lock In Japanese app. If anything is unclear, email us at hello@lockinjapanese.com.

The short version

  • The app is local-first. Your exact study records and Apple's Screen Time data stay on your device. The app sends limited usage analytics, diagnostics, and the information needed to load onboarding, manage purchases, and apply a Rescue Pass.
  • The website stores an email only when you join the waitlist. It also sends limited funnel analytics and diagnostics, and uses an IP address to rate-limit waitlist submissions.
  • We do not use advertising trackers, and we do not sell data.

The website (lockinjapanese.com)

When you submit the waitlist form, we store the email address you enter in Cloudflare Workers KV, together with the language site and signup timestamp. We use it to email you once when Lock In Japanese launches. We do not pass the email to a third-party email marketing service, and there is no double opt-in. You can ask us to delete it at any time by emailing hello@lockinjapanese.com.

The waitlist endpoint uses the visitor IP address as a Cloudflare rate-limit key. The IP address is not added to the waitlist record or the funnel-analytics event.

The site sends two funnel events: waitlist_joined after a new signup and store_clicked when an App Store badge is selected. Each event contains a random event ID, event name, timestamp, app and web-platform labels, language, and source. It does not contain the waitlist email, IP address, or a persistent visitor identifier. Events go to our Cloudflare analytics endpoint and then to Amplitude's EU endpoint.

The website server is instrumented with Sentry's EU service for errors and performance monitoring when its Sentry endpoint is enabled. Performance tracing samples 5% of requests. The site does not set advertising or analytics cookies and does not embed third-party tracking pixels.

The Lock In Japanese app

Lock In Japanese works without an account and keeps its core learning and Screen Time records on your device:

  • Learning records. The exact words you study and your spaced-repetition schedule are stored locally. They are not included in the usage-analytics events sent to our endpoint, Amplitude, or Cloudflare Workers Analytics Engine.

  • Screen Time. The app uses Apple's Screen Time / Family Controls framework to seal apps behind a quiz. Your selected app, category, and website-domain tokens and your usage history stay under iOS's on-device protections. We do not receive which items you selected or how long you use them. When you apply a seal, usage analytics include only the total number of selected apps, categories, and website domains.

  • Usage analytics. The app reports events such as an onboarding step being answered, a quiz being completed, or a seal being applied. These events use counts and fixed labels. Only the reviewed categorical onboarding steps (goal, level, screen_time, commitment_level, and pledge) may include their fixed answer value. Values from every other step, including the name field and any unknown remotely supplied step, are redacted before analytics leave the app. Events use a random identifier generated for each app launch; the app has no account and does not use Apple's advertising identifier.

    Events first go to our Cloudflare endpoint and then to Amplitude's EU endpoint. Onboarding events also go to Cloudflare Workers Analytics Engine with the event name, flow, experiment and variant, screen or step, config source, platform, and timestamp. In debug builds, events can still enter the local durable queue, but that queue is not uploaded.

  • Crashes, errors, and performance. Release builds use Sentry's EU service for crashes and errors and sample 20% of performance traces. Sentry's automatic app, view-controller, and HTTP tracing is enabled. We do not attach your name or email and do not capture screenshots. Sentry is disabled in debug builds.

  • Onboarding and paywall content. On launch, the app requests onboarding and paywall configuration from a server we operate. The request includes a persistent random per-install profile ID, locale, and, when available, the device country or region setting so the device receives a consistent flow variant. It does not include your name, exact study records, SRS schedule, or Screen Time data.

  • Purchases and Adapty. Purchases are handled through Apple's App Store and managed with Adapty. Adapty processes the purchase and subscription data needed to unlock and restore access. It also receives locale, the available country or region setting, and the fixed categorical onboarding answers for goal, self-reported level, selected screen-time band, commitment level, and pledge completion. If you buy, it also records the onboarding flow and paywall variant shown. Adapty does not receive the name you typed, values from unknown onboarding steps, exact study records, your SRS schedule, or actual Apple Screen Time data. Apple's privacy terms also apply to the transaction.

  • Rescue Pass. If you receive a Rescue Pass and its trusted backend is configured for the build, the app sends that backend a new random identifier generated for the current app launch, the access level, and the grant's start and end timestamps. It sends no name, email, learning records, or Screen Time data. This lets the grant be applied server-side without putting the subscription provider's secret key in the app.

  • The name you type in onboarding. An onboarding screen after the opening introduction asks what to call you. The name is stored on your device and is not sent anywhere.

Children

Lock In Japanese is not directed at children under 13, and we do not knowingly collect data from them.

Changes

If this policy changes, we will update the effective date at the top of this page. Material changes to how we handle data will be announced on this page before they take effect.

Contact

Questions about privacy: hello@lockinjapanese.com.