VocaPass

Privacy Policy

Last updated: September 24, 2026

1. Scope and who we are

This Privacy Policy explains how VocaPass, operated by Temung Technologies Co., Ltd. (得夢テクノロジーズ株式会社), collects, uses, shares, and protects information in connection with the VocaPass website, account and login system, vocabulary learning features, payment and entitlement processing, and the Contact, Customer Support, and Careers forms.

2. Account information you provide

We collect information you provide to create and manage your account, including your email address, password authentication data, selected display language, learning language, and vocabulary set. We also collect information you choose to give us when you contact us, such as through Contact, Customer Support, or Careers.

3. Learning and progress data

We store information generated as you use the Service, including your learning plan terms, daily assignments, study outcomes, vocabulary scores, review-test activity, timestamps, progress records, badges, multiplayer game activity, and synchronization data needed to keep your learning continuous across sessions and devices.

4. Registration country and pricing

To show you the correct regional price and currency, VocaPass stores a registration country associated with your account. This country is derived from server-observed, coarse IP-based geolocation at the time of registration or before checkout. We do not store your raw IP address for pricing purposes, and we do not rely on browser locale, display-language settings, or self-reported location for pricing.

5. Technical and security data

We process technical information needed to operate and secure the Service, including browser and device category, operating-system category, request metadata, coarse location signals, the page or route you visited, referrer category, user-agent data, cookie and session identifiers, local-storage preferences, service-worker cache metadata, server logs, and security events.

6. Optional aggregate analytics

With your affirmative permission, we use first-party analytics to measure aggregate reliability, performance, and user-experience trends. Analytics remains off until you choose “Allow analytics,” and you may withdraw that permission at any time by opening . Refusing or withdrawing permission does not limit learning features. A browser Global Privacy Control signal is treated as a refusal.

Analytics events do not include your raw IP address, exact screen dimensions, email address, username, password, payment identifiers, authentication tokens, vocabulary or sentence content, test answers, daily assignments, full page URLs, or referrers. VocaPass does not sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or profile learners for decisions with legal or similarly significant effects.

7. Payment information

Web purchases are processed by Stripe or another approved tokenized payment provider. We store payment- and entitlement-related identifiers such as checkout, customer, payment, and charge identifiers where available, the amount and currency charged, entitlement dates and status, refund or dispute status, and provider event identifiers. We do not collect or store raw card numbers, expiration dates, CVC codes, or other sensitive payment authentication data.

8. Contact, Support, and Careers submissions

When you submit a message through Contact, Customer Support, or Careers, we collect the information you provide, which may include an optional reply email, your name or display name, your message, a selected category or role interest, your display language, page context, timestamps, your account identity if you are signed in, your approximate country or region where available, and limited request metadata needed to review and respond to your message.

9. How we use information

We use information to authenticate accounts, deliver the Service and learning continuity, provide features you choose such as display-language personalization, process payments and entitlements, evaluate and process refund requests, respond to Contact, Customer Support, and Careers submissions, prevent abuse and fraud, maintain security, debug and improve the Service, keep audit and business records, comply with legal obligations, and handle disputes.

10. Legal bases and whether data is required

Account credentials, age-band eligibility, security records, learning state, and entitlement data are required to create and operate the account you request; without them, the corresponding account or feature cannot work. Checkout and payment records are required only if you buy paid access. Contact, Support, and Careers data is required only to process the submission you choose to make. Optional aggregate analytics relies on consent. Where the law provides for these bases, service delivery relies on contract or requested pre-contract steps, security and abuse prevention rely on legitimate interests, legally required business records rely on legal obligation, and optional features rely on consent.

11. Recipients and service providers

Cloudflare provides hosting, edge security, application execution, and data infrastructure. Stripe processes web checkout and related payment operations and may act as a processor or an independent controller depending on the activity and applicable law. We may disclose the minimum necessary information to professional advisers or public authorities when legally required. VocaPass does not sell personal information or disclose it for cross-context behavioral advertising. Provider destination, contract, and transfer-mechanism details must be verified in our release register before registration or checkout is enabled in a country.

12. Cookies, local storage, sessions, and consent

Strictly necessary cookies, session identifiers, local storage, and service-worker cache storage keep you signed in, remember requested preferences, maintain learning continuity, prevent abuse, and deliver static assets. Disabling them may prevent sign-in or learning synchronization. Optional analytics remains off before consent. Your analytics choice is stored with the policy version and decision time and is as easy to withdraw as to grant.

13. Exact retention rules

Active account and learning records remain for the life of the account. After a verified deletion request, account-scoped records are deleted within 30 days; encrypted backups and the one-way restore-prevention tombstone expire within 35 days. Login sessions expire after 30 days. Support requests expire after 730 days and Careers applications after 365 days, unless a documented legal hold applies. Public form and operation receipts expire after 7 days. Short-lived security, assessment, multiplayer, and workflow records are deleted at the exact expiry timestamp stored with each record.

Purchase, entitlement, refund, reversal, dispute, accounting, and tax records are retained through July 31 seven years after the close of the fiscal year containing the relevant transaction, then deleted or irreversibly minimized, unless an active dispute or a longer mandatory legal period applies. Our fiscal year closes on July 31. Legal holds are reviewed every 90 days. Analytics stores fixed aggregate counters rather than event-level or user-level records. The versioned record-by-record schedule is record-retention-policy-v1.1.0.

14. Security safeguards

We use safeguards appropriate to a digital learning service, including tokenized payment collection through our payment processor, server-side entitlement checks, session controls, and access-controlled operational records. No online service can guarantee absolute security, and we encourage you to protect your own account credentials.

15. International processing

Cloudflare and Stripe may process information outside your country. Before registration or checkout is enabled in a market, VocaPass requires verified destination information, provider terms, contractual safeguards, and every applicable adequacy decision, standard contractual clause, certification, standard contract, assessment, notice, or separate consent. Those functions remain unavailable where the required mechanism or evidence is incomplete.

16. Children and younger learners

VocaPass is a general-audience educational service for learners who are at least 13 and meet any higher digital-consent age that applies in their registration country. We do not currently provide a guardian-consent flow, so a learner below the applicable self-consent age cannot register. Registration stores only a server-validated age-band attestation, not a full birth date. Eligible minor accounts receive only general-audience content, cannot access adult private conversation, and cannot make a direct purchase. A minor account may be updated to adult status only through the authenticated re-attestation process described by the Service.

17. Your privacy rights and request process

Depending on where you live, you may request confirmation, access, correction, a portable copy, deletion, restriction, objection, consent withdrawal, an advertising or sale/share opt-out, or review of an automated decision. You may also use an authorized agent where local law permits. Submit a request through Customer Support; the Privacy and Data Rights category is selected automatically. We provide a reference ID, verify only the information reasonably needed, respond within the applicable legal period, and explain any denial and available appeal. Requests are free unless the law expressly permits a charge.

The registration-country price is based on server-observed coarse country information. If it is wrong, ask Customer Support for human review and correction before purchase. This decision does not evaluate your behavior or learning ability.

18. Communications

We may send transactional messages related to authentication, security, payments, refunds, material service changes, and your Contact, Customer Support, or Careers requests. If we introduce marketing communications, we will request any consent required by applicable law and provide a way to opt out.

19. Changes to this policy

We post the current effective date on this page. Material changes apply prospectively, and we provide an in-service notice or another legally required notice before the change takes effect when it materially affects your rights or our use of personal information.

20. Contact and complaints

For privacy questions, rights requests, or an appeal, use the monitored Privacy and Data Rights support channel. It records the request and returns a reference ID. Any additionally required local representative will be published before the affected market is enabled.

21. Regional supplements and authority routes

Japan

Residents may exercise APPI disclosure, correction, suspension, and deletion rights and may consult Japan’s Personal Information Protection Commission.

European Union and EEA

Residents may exercise GDPR access, rectification, erasure, restriction, portability, objection, consent-withdrawal, and automated-decision rights and may complain to the supervisory authority where they live, work, or believe an infringement occurred. The European Data Protection Board lists member authorities.

United Kingdom

Residents have equivalent UK GDPR rights and may complain to the Information Commissioner’s Office.

United States and California

Applicable state rights may include know, access, correction, deletion, portability, opt-out, appeal, authorized-agent, and non-discrimination rights. VocaPass honors Global Privacy Control for applicable optional processing. California residents may consult the California Attorney General’s CCPA information.

Canada

Residents may request access and correction and withdraw consent where applicable, subject to lawful limits, and may complain to the Office of the Privacy Commissioner of Canada.

Brazil

Residents may exercise LGPD confirmation, access, correction, anonymization, blocking, deletion, portability, information, consent-withdrawal, and review rights and may petition the ANPD.

Australia

Residents may seek access and correction and complain first to VocaPass, then to the Office of the Australian Information Commissioner.

Singapore

Residents may request access and correction and withdraw consent where applicable, and may contact the Personal Data Protection Commission.

India

Rights available under provisions in force may include access to information, correction, erasure, consent withdrawal, grievance redress, and nomination. Current commencement and authority routes are rechecked before release.

Mainland China

Residents may request access, copies, correction, deletion, restriction, or explanation under the PIPL. Cross-border processing and registration remain unavailable until all required recipient disclosures, mechanisms, assessments, and separate consents are approved.

South Korea

Residents may request access, correction, deletion, suspension, and transmission where applicable and may consult the Personal Information Protection Commission. Required overseas-transfer notice or consent applies before transfer.