Tilbis — Privacy Policy
Last updated: 4 October 2026
Tilbis ("the app") is a Kazakh language learning app published by Mehmet Uğur ("we", "us"). The app is available for iPhone and iPad (App Store) and for Android (Google Play); this policy covers both. It explains exactly what leaves your device, where it goes, and how long it is kept.
The app is offline-first. Every feature except the six optional online services listed in section 2 works with no network connection and sends nothing anywhere.
Our servers are outside Türkiye and Kazakhstan: the backend runs on Cloudflare's global network and the optional AI conversation practice is answered by DeepSeek (section 2.2). By opening an account or using those optional online services you accept this cross-border transfer.
What the app promises about the accuracy of its content, and how reported errors are corrected, is set out in the Terms of Use.
1. Data stored on your device only
Your learning progress — XP, streak, completed lessons, learned words, review schedule, badges, daily statistics, settings, and your chosen interface language — is stored locally on your device: in Apple's SwiftData framework on iPhone and iPad, and in the app's private storage on Android. Downloaded pronunciation audio is cached in the app's own file area.
None of this leaves your device unless you sign in for sync (section 2.1). Deleting the app deletes all of it.
To work out which kind of exercise teaches better, the app may vary the order and the form of the exercises for some words on your device. The outcome of that comparison also stays on your device only.
2. Optional online services
2.1 Account and cross-device sync (optional)
You can use the entire app without an account. If you choose to sign in — with Sign in with Apple (iPhone and iPad only), with Google (iPhone, iPad and Android), or with an email magic link — we store the following on our own backend (Cloudflare Workers, D1 database, EU/global edge):
| Stored | Why |
|---|---|
| A random user id | Identifies your account |
| Apple subject identifier, Google subject identifier, or your email address | Lets you sign in again |
| Display name and avatar choice (if you set them) | Shown in the app |
| Your learning progress snapshot | Sync between your devices |
Session records: device name (on Android, the device model name), device identifier (on iPhone and iPad Apple's identifierForVendor; on Android a random identifier the app creates for itself — never the advertising ID or the hardware ID), platform, a SHA-256 hash of the active refresh token, sign-in IP address, timestamps | Keeps you signed in and powers the "active devices" security screen so you can spot and revoke unfamiliar sign-ins |
Email magic-link tokens are stored for 15 minutes, are single-use, and are deleted after that.
If you use Sign in with Apple with "Hide My Email", we only ever see Apple's private relay address.
If you sign in with Google. Google shows you its own sign-in page and, after you approve it, hands the app a signed identity token. From that token we keep only your Google account identifier and your verified email address — no contacts, no Drive, no calendar, no profile photo, and no access to anything else in your Google account; the app asks for no Google permissions beyond your basic identity. What Google receives is the fact that you signed in to this app, plus whatever Google normally records for a sign-in; Google's own privacy policy governs that part: <https://policies.google.com/privacy>. Your Apple and Google sign-ins are separate accounts even when the email address is the same — we never merge two accounts on a matching email, because that would let anyone who can get an address verified elsewhere take over your progress. On iPhone and iPad, deleting your account also revokes the app's access on Google's side. On Android the app cannot do that for you: deleting your account removes everything we hold, and you can additionally remove the app's access at any time in your Google Account (Security → Your connections to third-party apps and services).
**We never sell this data, never use it for advertising, and never share it with third parties.**
Deletion: on iPhone, iPad and Android alike, open the Profile tab, tap the gear icon (Settings), then Account → Delete account. This removes your account and every row linked to it (progress, sessions) from our database immediately and permanently. If you cannot open the app, follow the steps on our account deletion page or write to pix_apps@proton.me. Your progress stored on the device itself stays there until you delete the app.
2.2 AI conversation practice (Premium, plus a small free daily allowance)
Premium subscribers can practise conversation with an AI tutor; without a subscription a small free daily allowance (2 messages per day) is available.
Please read this carefully — it involves a processor outside the EU/US.
- Your chat messages are sent to our backend, which forwards them to
DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.). DeepSeek is the service provider that generates the AI replies for us; its servers are located in the People's Republic of China.
- What is forwarded: the text of the current conversation (at most the last 20
messages, each capped at 500 characters) and a fixed teaching instruction. The app does not attach your name, email, account id, device id, or location.
- We do not store your chat messages. They pass through our backend in
memory and are not written to any database or log.
- DeepSeek processes the messages on its own servers under **its own privacy
policy and Chinese law**, and may retain them and use them to train its models. We have no control over that retention or use. See <https://www.deepseek.com/privacy>.
- Because of this, the app shows a consent screen before your first AI chat
and the feature stays disabled until you accept. You can decline and keep using every other part of the app. That screen also asks you not to share real names, addresses, phone numbers, passwords, or other personal details in the chat.
- To enforce your subscription and fair-use limits we verify your purchase.
On iPhone and iPad we send Apple's signed transaction receipt to Apple; on Android the app sends your Google Play purchase token to our backend, which checks it with the Google Play Developer API. We keep a **usage counter keyed to the Apple transaction id or the Google Play order id** (daily and monthly), which expires automatically (after at most 35 days). The purchase token itself is not written to storage in readable form. Without a subscription, the free daily allowance is counted per salted label derived from your IP address (the address cannot be recovered from it), kept for up to 48 hours. These counters contain no message content.
- AI output can be wrong. Every AI reply is labelled as such in the app, and you
can report any reply by long-pressing it.
Alternative — bring your own key (iPhone and iPad only). Instead of our backend you may enter your own AI provider API key. That key is stored only in your iPhone's Keychain, is sent only to that provider, and never reaches our servers.
2.3 Pronunciation audio (text-to-speech)
To play Kazakh audio the app requests an audio clip from our backend. What is sent is a Kazakh phrase that is part of the app's own course content — never anything you typed, and no account or device identifier. All Kazakh audio is generated in advance by us with Google Gemini text-to-speech and stored in our own object storage (Cloudflare R2); the app never contacts Google for this, and our backend never synthesises speech live from your request. If a clip is not yet in storage, the app is simply told it isn't available.
2.4 In-app purchases
Subscriptions and content packs are sold and processed by Apple (App Store) or Google (Google Play). We receive no card, billing, or contact information. On iPhone and iPad we send Apple's signed transaction to Apple's App Store Server API only to check that a purchase is valid. On Android the app sends the Google Play purchase token to our backend, which checks it with the Google Play Developer API and receives only the state of the purchase (product, validity, order id). We keep the transaction id or order id solely as the key of the expiring usage counters described above. Google's and Apple's own privacy policies govern what they process when you buy.
2.5 "Report a problem" form
If you use "Report a problem", the app sends: the note you write, the category you pick (translation / spelling / suggestion), the name of the screen you were on, the app version, the interface language, and a random report code created for that single report. Your IP address is not stored; we keep only a salted label derived from it so that repeated reports can be grouped, and the address cannot be recovered from it. No account, device model, operating system version, advertising ID or other device identifier is sent.
The random report code is kept on your device for up to 180 days. We store only a one-way hash of it. When the problem you reported is fixed, the app compares hashes on your device and shows a one-time thank-you; nothing is sent back to us for this.
Reports are automatically deleted from our server after 7 days. If a report turns out to be correct and a fix is being prepared, we keep only the hash of its report code until the fix is published, so the thank-you can be shown; then it is deleted too.
2.6 Course content corrections
The app periodically downloads signed course-content corrections (text, translation and audio updates) from our backend, so that errors can be fixed without waiting for an app update. Only data is downloaded — never code. The request carries no account, device identifier, app version or usage data. Whether a correction applies is decided on your device (using a random number that never leaves it). Every correction is signed by us and verified on the device before use; if verification fails, the app keeps using its built-in content.
2.7 Weekly leagues (optional)
Leagues work only with an account and only after you tap "Join league". Before you join, nothing about you is shown to anyone.
- What we store: a nickname that you pick from a fixed list (no free text),
your league level, your weekly points (worked out on our server from the increase in your total points, with a daily limit), your badges, which weekly group you are in, the list of people you chose to hide (as opaque keys, not identities), the time you joined and the version of the text you were shown, and the day on which your app last sent a device check (Apple App Attest / Google Play Integrity). The check itself is not stored. On iPhone we also keep the public key that the app created on your device for this check (it is not a device identifier); it is deleted after 180 days without use.
- What other people see: only your nickname, your weekly points, your level
badge and, if you choose one, a single badge. Your name, email, avatar, streak, country and account ID are never shown. There is no chat or messaging.
- Leaving: turn off "Show in leagues" in Settings. You leave this week's
group immediately and do not join new weeks. Your badges stay.
- Retention: weekly rows (group, points, weekly result) are kept for 8 weeks;
nickname, level and badges are kept until you delete your account.
- Legal basis: performing the feature you turned on, and your consent (the
join button; the time and the text version are recorded).
- Deleting your account deletes all league data, including your entry in other
people's hide lists.
2.8 Invitations (optional)
Invitations work only with an account. Inviting someone or entering a code is never required for any feature, and the reward cannot be bought.
- What we store: your personal invite code; for an accepted code, which
account invited which (the person who invited you never learns who you are, only counts such as "2 pending, 1 completed"), when the code was entered, how many lessons you completed after that and on which days (at most two), to check the reward condition (3 lessons over 2 days within 14 days); your reward entitlements and their status; on Android, the end date of the gift Premium; on iPhone, the App Store offer code assigned to you and whether the app reported that you redeemed it; a one-way hash (HMAC) of your device identifier, stored without your account, so that a device can be invited only once; and an hourly count of code-entry attempts.
- Device check: when you enter a code, the app may attach a device check
token (Apple DeviceCheck / Google Play Integrity). We do not store the token. When a code is accepted, Apple or Google keeps one on/off mark for your device ("an invite code was entered on this device") on their servers; we only read it to stop the same device from being invited twice, and ignore marks older than 18 months. The mark is not linked to your account or identity.
- Gift Premium: on iPhone it is a personal Apple offer code that you redeem in
the App Store; it appears in your Apple account as a free subscription that does not renew, and Apple handles it. On Android it is recorded on our server. The gift belongs to this account and is not transferred between Apple and Google accounts.
- Retention: a pending invitation expires after 14 days; a used reward
entitlement is deleted 30 days after the gift ends; code-entry counts are deleted after 2 hours; the device hash is kept for 12 months; your invite code, the invitation relationship and badges are kept until you delete your account.
- Legal basis: performing the feature you chose to use.
- Deleting your account deletes your code, your invitations and any unused
reward, including the remaining gift days. An App Store code assigned to you but not yet redeemed is cancelled; a subscription already redeemed with Apple stays with Apple.
2.9 Ауыл groups (optional)
Ауыл groups work only with an account, only after you have joined weekly leagues (2.7), and only when you create a group or enter a group code yourself. Nothing is required for any other feature.
- What we store: for each group, a name chosen from a fixed list (no free
text), a random group code and its creation and last-activity time; which accounts are members and when they joined; and, for members the organizer removed, a list of accounts that cannot rejoin. Your weekly points are the same league points (2.7); no extra personal data is collected.
- What other members see: only your nickname, your weekly points and your
badge, as in leagues. Your name, email, avatar, country and account ID are never shown, and the app shows other members only under opaque keys. There is no chat or messaging. Members may know each other in real life; the app does not show identity.
- Organizer: the person who created a group can renew the code (the old
link stops working), remove a member (who then cannot rejoin with the code) or close the group. If the organizer leaves, the role passes to the longest-standing member. A group has 2 to 12 members; one account can be in 3 groups.
- Leaving: you can leave any group at any time. Turning off "Show in leagues"
also removes you from all groups.
- Retention: a group with no points from any member for 60 days is deleted
automatically. Memberships and the removed-members list are kept until you leave, the group is closed or you delete your account. Hourly code-entry counts are deleted after 2 hours.
- Legal basis: performing the feature you chose to use.
- Deleting your account removes you from all groups, deletes your entries in
removed-members lists and transfers the organizer role if you held it; a group whose last member is deleted is deleted too.
3. Microphone and speech recognition
The pronunciation exercise asks for microphone permission (on Android, the RECORD_AUDIO permission), and only when you open that exercise. **Your recordings are never sent to our servers, and never to Google Gemini or any other provider by us.**
There are two paths, and the exercise screen always tells you which one is active:
- Kazakh recognition on your device (recommended). You can download an
offline Kazakh speech model (102 MB, Wi-Fi only, optional and removable at any time from Settings). Recognition then happens entirely inside the app, works with no internet, and no audio ever leaves your phone. The download itself fetches only the model files from our server — nothing about you is sent with it.
- Approximate matching (when the model is not installed). Audio is handled
by the speech recogniser built into your operating system, not by us. On iPhone and iPad that is Apple's Speech Recognition: on your device where the locale supports it, and by Apple's servers for locales that do not (iOS has no Kazakh recogniser; the app falls back to a related language and says so). On Android it is Android's system speech recogniser (set to Russian as the closest language, and asked to work on the device first): it is a service of your phone's speech provider — on most phones Google — so whether audio stays on the device or is processed on that provider's servers depends on your phone and its settings, and the provider's privacy policy governs that part.
In neither case is your voice sent to our servers or stored by us. Where a system recogniser is used, the policy of its provider governs that provider's part: <https://www.apple.com/legal/privacy/> and <https://policies.google.com/privacy>.
4. Analytics and tracking
None. The app contains no third-party analytics, attribution, or advertising SDKs — no Firebase, no Mixpanel, no AppsFlyer, no ad networks. We do not use the Advertising Identifier, we do not track you across apps or websites, and we do not build advertising profiles. The app's NSPrivacyTracking flag is false.
The only Google components in the app are Google Sign-In, which is there to log you in and stays inert unless you tap "Sign in with Google", and, on Android, Google Play Billing and Google Play In-App Review, which handle purchases and the rating prompt. None of them runs analytics or is connected to Google Analytics or Firebase. The Android app does not request or use the advertising ID.
The only measurement we keep is a set of anonymous counters on our own server: when the subscription screen is shown, or a purchase is started, completed or abandoned, the app sends the event name plus — at most — which screen the subscription page was opened from and which plan was selected. No user ID, device ID, advertising ID or account is attached. Nothing is stored per person: we only increment a daily total per event, so the numbers cannot be linked back to you. The exceptions are leagues, invitations and Ауыл groups (sections 2.7, 2.8 and 2.9): they are features tied to your account, not analytics.
To improve the service, your account's daily and weekly total points and the number of submissions are kept for at most 10 days under a temporary value that is not directly linked to your identity, and are stored only as range counts.
The app also works out a weekly learning summary on your device. The summary itself stays there; at most once a week, the app sends only the percentage band of that summary (for example "70-80") to the same anonymous counters, so that we can tell whether the feature is working at all. No word, score, date, user ID or device ID is attached, and the band cannot be linked back to you.
Purchase events are received anonymously from the store (Apple App Store or Google Play) and are not matched to your identity.
5. Children
The app is intended for users aged 13 and over (it is rated 12+ on the App Store) and is not directed at children. It contains no advertising and no user-to-user communication (in leagues, others see only a nickname chosen from a fixed list and weekly points). We do not knowingly collect personal data from children under 13; if you believe a child has given us any, write to pix_apps@proton.me and we will delete it. The AI tutor is constrained by safety rules that refuse harmful, sexual, violent, or illegal content, never ask for the user's name or any other personal detail, never suggest meeting, and redirect any mention of self-harm or danger to a trusted adult or a local emergency line. AI chat is gated behind the consent screen in section 2.2.
6. Retention summary
| Data | Kept for |
|---|---|
| Local progress on device | Until you delete the app |
| Account, progress snapshot, sessions | Until you delete your account |
| Magic-link token | 15 minutes, single use |
| Sign-in IP in session record | Until that session is revoked or the account is deleted |
| Chat messages | Not stored by us (see 2.2 for DeepSeek) |
| Free-TTS IP counter | Up to 48 hours |
| Purchase-quota counter (Apple transaction id or Google Play order id) | Daily / monthly window, expires automatically (at most 35 days) |
| Free AI-chat allowance counter (salted IP label) | Up to 48 hours |
| Generated pronunciation audio | Indefinitely — course content only, contains no personal data |
| Problem reports (note, category, screen, version, language, salted IP label, hash of report code) | 7 days, then deleted automatically (for confirmed reports, only the report-code hash is kept until the fix is published) |
| Random report codes on your device | Up to 180 days, or until the thank-you is shown |
| League weekly rows (group, weekly points, weekly result) | 8 weeks |
| League nickname, level, badges, hide list, join record | Until you delete your account |
| Invite code, invitation relationship, invitation badges | Until you delete your account |
| Used invitation reward (gift end date, assigned App Store code) | 30 days after the gift ends |
| Device hash for invitations (one-way, not linked to an account) | 12 months |
| Invite code entry attempt counter | 2 hours |
7. Your rights
You can, at any time and without contacting us: use the app fully without an account, sign out, revoke any individual device session, decline AI chat, and delete your account together with all associated data from Settings → Account (step by step, including for people who can no longer open the app: https://tilbis.app/delete-account).
For access, correction, deletion, objection to processing, or any other request under the GDPR, the KVKK, the Personal Data law of the Republic of Kazakhstan or comparable law, write to pix_apps@proton.me. We answer within 30 days.
8. Changes
If this policy changes materially we will update the date at the top and, where the change affects what leaves your device, surface it in the app.
9. Contact
pix_apps@proton.me