Tilbis

Tilbis — Privacy Policy

Last updated: 4 October 2026


Tilbis ("the app") is a Kazakh language learning app published by Mehmet Uğur ("we", "us"). The app is available for iPhone and iPad (App Store) and for Android (Google Play); this policy covers both. It explains exactly what leaves your device, where it goes, and how long it is kept.

The app is offline-first. Every feature except the six optional online services listed in section 2 works with no network connection and sends nothing anywhere.

Our servers are outside Türkiye and Kazakhstan: the backend runs on Cloudflare's global network and the optional AI conversation practice is answered by DeepSeek (section 2.2). By opening an account or using those optional online services you accept this cross-border transfer.

What the app promises about the accuracy of its content, and how reported errors are corrected, is set out in the Terms of Use.

1. Data stored on your device only

Your learning progress — XP, streak, completed lessons, learned words, review schedule, badges, daily statistics, settings, and your chosen interface language — is stored locally on your device: in Apple's SwiftData framework on iPhone and iPad, and in the app's private storage on Android. Downloaded pronunciation audio is cached in the app's own file area.

None of this leaves your device unless you sign in for sync (section 2.1). Deleting the app deletes all of it.

To work out which kind of exercise teaches better, the app may vary the order and the form of the exercises for some words on your device. The outcome of that comparison also stays on your device only.

2. Optional online services

2.1 Account and cross-device sync (optional)

You can use the entire app without an account. If you choose to sign in — with Sign in with Apple (iPhone and iPad only), with Google (iPhone, iPad and Android), or with an email magic link — we store the following on our own backend (Cloudflare Workers, D1 database, EU/global edge):

StoredWhy
A random user idIdentifies your account
Apple subject identifier, Google subject identifier, or your email addressLets you sign in again
Display name and avatar choice (if you set them)Shown in the app
Your learning progress snapshotSync between your devices
Session records: device name (on Android, the device model name), device identifier (on iPhone and iPad Apple's identifierForVendor; on Android a random identifier the app creates for itself — never the advertising ID or the hardware ID), platform, a SHA-256 hash of the active refresh token, sign-in IP address, timestampsKeeps you signed in and powers the "active devices" security screen so you can spot and revoke unfamiliar sign-ins

Email magic-link tokens are stored for 15 minutes, are single-use, and are deleted after that.

If you use Sign in with Apple with "Hide My Email", we only ever see Apple's private relay address.

If you sign in with Google. Google shows you its own sign-in page and, after you approve it, hands the app a signed identity token. From that token we keep only your Google account identifier and your verified email address — no contacts, no Drive, no calendar, no profile photo, and no access to anything else in your Google account; the app asks for no Google permissions beyond your basic identity. What Google receives is the fact that you signed in to this app, plus whatever Google normally records for a sign-in; Google's own privacy policy governs that part: <https://policies.google.com/privacy>. Your Apple and Google sign-ins are separate accounts even when the email address is the same — we never merge two accounts on a matching email, because that would let anyone who can get an address verified elsewhere take over your progress. On iPhone and iPad, deleting your account also revokes the app's access on Google's side. On Android the app cannot do that for you: deleting your account removes everything we hold, and you can additionally remove the app's access at any time in your Google Account (Security → Your connections to third-party apps and services).

**We never sell this data, never use it for advertising, and never share it with third parties.**

Deletion: on iPhone, iPad and Android alike, open the Profile tab, tap the gear icon (Settings), then Account → Delete account. This removes your account and every row linked to it (progress, sessions) from our database immediately and permanently. If you cannot open the app, follow the steps on our account deletion page or write to pix_apps@proton.me. Your progress stored on the device itself stays there until you delete the app.

2.2 AI conversation practice (Premium, plus a small free daily allowance)

Premium subscribers can practise conversation with an AI tutor; without a subscription a small free daily allowance (2 messages per day) is available.

Please read this carefully — it involves a processor outside the EU/US.

DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.). DeepSeek is the service provider that generates the AI replies for us; its servers are located in the People's Republic of China.

messages, each capped at 500 characters) and a fixed teaching instruction. The app does not attach your name, email, account id, device id, or location.

memory and are not written to any database or log.

policy and Chinese law**, and may retain them and use them to train its models. We have no control over that retention or use. See <https://www.deepseek.com/privacy>.

and the feature stays disabled until you accept. You can decline and keep using every other part of the app. That screen also asks you not to share real names, addresses, phone numbers, passwords, or other personal details in the chat.

On iPhone and iPad we send Apple's signed transaction receipt to Apple; on Android the app sends your Google Play purchase token to our backend, which checks it with the Google Play Developer API. We keep a **usage counter keyed to the Apple transaction id or the Google Play order id** (daily and monthly), which expires automatically (after at most 35 days). The purchase token itself is not written to storage in readable form. Without a subscription, the free daily allowance is counted per salted label derived from your IP address (the address cannot be recovered from it), kept for up to 48 hours. These counters contain no message content.

can report any reply by long-pressing it.

Alternative — bring your own key (iPhone and iPad only). Instead of our backend you may enter your own AI provider API key. That key is stored only in your iPhone's Keychain, is sent only to that provider, and never reaches our servers.

2.3 Pronunciation audio (text-to-speech)

To play Kazakh audio the app requests an audio clip from our backend. What is sent is a Kazakh phrase that is part of the app's own course content — never anything you typed, and no account or device identifier. All Kazakh audio is generated in advance by us with Google Gemini text-to-speech and stored in our own object storage (Cloudflare R2); the app never contacts Google for this, and our backend never synthesises speech live from your request. If a clip is not yet in storage, the app is simply told it isn't available.

2.4 In-app purchases

Subscriptions and content packs are sold and processed by Apple (App Store) or Google (Google Play). We receive no card, billing, or contact information. On iPhone and iPad we send Apple's signed transaction to Apple's App Store Server API only to check that a purchase is valid. On Android the app sends the Google Play purchase token to our backend, which checks it with the Google Play Developer API and receives only the state of the purchase (product, validity, order id). We keep the transaction id or order id solely as the key of the expiring usage counters described above. Google's and Apple's own privacy policies govern what they process when you buy.

2.5 "Report a problem" form

If you use "Report a problem", the app sends: the note you write, the category you pick (translation / spelling / suggestion), the name of the screen you were on, the app version, the interface language, and a random report code created for that single report. Your IP address is not stored; we keep only a salted label derived from it so that repeated reports can be grouped, and the address cannot be recovered from it. No account, device model, operating system version, advertising ID or other device identifier is sent.

The random report code is kept on your device for up to 180 days. We store only a one-way hash of it. When the problem you reported is fixed, the app compares hashes on your device and shows a one-time thank-you; nothing is sent back to us for this.

Reports are automatically deleted from our server after 7 days. If a report turns out to be correct and a fix is being prepared, we keep only the hash of its report code until the fix is published, so the thank-you can be shown; then it is deleted too.

2.6 Course content corrections

The app periodically downloads signed course-content corrections (text, translation and audio updates) from our backend, so that errors can be fixed without waiting for an app update. Only data is downloaded — never code. The request carries no account, device identifier, app version or usage data. Whether a correction applies is decided on your device (using a random number that never leaves it). Every correction is signed by us and verified on the device before use; if verification fails, the app keeps using its built-in content.

2.7 Weekly leagues (optional)

Leagues work only with an account and only after you tap "Join league". Before you join, nothing about you is shown to anyone.

your league level, your weekly points (worked out on our server from the increase in your total points, with a daily limit), your badges, which weekly group you are in, the list of people you chose to hide (as opaque keys, not identities), the time you joined and the version of the text you were shown, and the day on which your app last sent a device check (Apple App Attest / Google Play Integrity). The check itself is not stored. On iPhone we also keep the public key that the app created on your device for this check (it is not a device identifier); it is deleted after 180 days without use.

badge and, if you choose one, a single badge. Your name, email, avatar, streak, country and account ID are never shown. There is no chat or messaging.

group immediately and do not join new weeks. Your badges stay.

nickname, level and badges are kept until you delete your account.

join button; the time and the text version are recorded).

people's hide lists.

2.8 Invitations (optional)

Invitations work only with an account. Inviting someone or entering a code is never required for any feature, and the reward cannot be bought.

account invited which (the person who invited you never learns who you are, only counts such as "2 pending, 1 completed"), when the code was entered, how many lessons you completed after that and on which days (at most two), to check the reward condition (3 lessons over 2 days within 14 days); your reward entitlements and their status; on Android, the end date of the gift Premium; on iPhone, the App Store offer code assigned to you and whether the app reported that you redeemed it; a one-way hash (HMAC) of your device identifier, stored without your account, so that a device can be invited only once; and an hourly count of code-entry attempts.

token (Apple DeviceCheck / Google Play Integrity). We do not store the token. When a code is accepted, Apple or Google keeps one on/off mark for your device ("an invite code was entered on this device") on their servers; we only read it to stop the same device from being invited twice, and ignore marks older than 18 months. The mark is not linked to your account or identity.

the App Store; it appears in your Apple account as a free subscription that does not renew, and Apple handles it. On Android it is recorded on our server. The gift belongs to this account and is not transferred between Apple and Google accounts.

entitlement is deleted 30 days after the gift ends; code-entry counts are deleted after 2 hours; the device hash is kept for 12 months; your invite code, the invitation relationship and badges are kept until you delete your account.

reward, including the remaining gift days. An App Store code assigned to you but not yet redeemed is cancelled; a subscription already redeemed with Apple stays with Apple.

2.9 Ауыл groups (optional)

Ауыл groups work only with an account, only after you have joined weekly leagues (2.7), and only when you create a group or enter a group code yourself. Nothing is required for any other feature.

text), a random group code and its creation and last-activity time; which accounts are members and when they joined; and, for members the organizer removed, a list of accounts that cannot rejoin. Your weekly points are the same league points (2.7); no extra personal data is collected.

badge, as in leagues. Your name, email, avatar, country and account ID are never shown, and the app shows other members only under opaque keys. There is no chat or messaging. Members may know each other in real life; the app does not show identity.

link stops working), remove a member (who then cannot rejoin with the code) or close the group. If the organizer leaves, the role passes to the longest-standing member. A group has 2 to 12 members; one account can be in 3 groups.

also removes you from all groups.

automatically. Memberships and the removed-members list are kept until you leave, the group is closed or you delete your account. Hourly code-entry counts are deleted after 2 hours.

removed-members lists and transfers the organizer role if you held it; a group whose last member is deleted is deleted too.

3. Microphone and speech recognition

The pronunciation exercise asks for microphone permission (on Android, the RECORD_AUDIO permission), and only when you open that exercise. **Your recordings are never sent to our servers, and never to Google Gemini or any other provider by us.**

There are two paths, and the exercise screen always tells you which one is active:

offline Kazakh speech model (102 MB, Wi-Fi only, optional and removable at any time from Settings). Recognition then happens entirely inside the app, works with no internet, and no audio ever leaves your phone. The download itself fetches only the model files from our server — nothing about you is sent with it.

by the speech recogniser built into your operating system, not by us. On iPhone and iPad that is Apple's Speech Recognition: on your device where the locale supports it, and by Apple's servers for locales that do not (iOS has no Kazakh recogniser; the app falls back to a related language and says so). On Android it is Android's system speech recogniser (set to Russian as the closest language, and asked to work on the device first): it is a service of your phone's speech provider — on most phones Google — so whether audio stays on the device or is processed on that provider's servers depends on your phone and its settings, and the provider's privacy policy governs that part.

In neither case is your voice sent to our servers or stored by us. Where a system recogniser is used, the policy of its provider governs that provider's part: <https://www.apple.com/legal/privacy/> and <https://policies.google.com/privacy>.

4. Analytics and tracking

None. The app contains no third-party analytics, attribution, or advertising SDKs — no Firebase, no Mixpanel, no AppsFlyer, no ad networks. We do not use the Advertising Identifier, we do not track you across apps or websites, and we do not build advertising profiles. The app's NSPrivacyTracking flag is false.

The only Google components in the app are Google Sign-In, which is there to log you in and stays inert unless you tap "Sign in with Google", and, on Android, Google Play Billing and Google Play In-App Review, which handle purchases and the rating prompt. None of them runs analytics or is connected to Google Analytics or Firebase. The Android app does not request or use the advertising ID.

The only measurement we keep is a set of anonymous counters on our own server: when the subscription screen is shown, or a purchase is started, completed or abandoned, the app sends the event name plus — at most — which screen the subscription page was opened from and which plan was selected. No user ID, device ID, advertising ID or account is attached. Nothing is stored per person: we only increment a daily total per event, so the numbers cannot be linked back to you. The exceptions are leagues, invitations and Ауыл groups (sections 2.7, 2.8 and 2.9): they are features tied to your account, not analytics.

To improve the service, your account's daily and weekly total points and the number of submissions are kept for at most 10 days under a temporary value that is not directly linked to your identity, and are stored only as range counts.

The app also works out a weekly learning summary on your device. The summary itself stays there; at most once a week, the app sends only the percentage band of that summary (for example "70-80") to the same anonymous counters, so that we can tell whether the feature is working at all. No word, score, date, user ID or device ID is attached, and the band cannot be linked back to you.

Purchase events are received anonymously from the store (Apple App Store or Google Play) and are not matched to your identity.

5. Children

The app is intended for users aged 13 and over (it is rated 12+ on the App Store) and is not directed at children. It contains no advertising and no user-to-user communication (in leagues, others see only a nickname chosen from a fixed list and weekly points). We do not knowingly collect personal data from children under 13; if you believe a child has given us any, write to pix_apps@proton.me and we will delete it. The AI tutor is constrained by safety rules that refuse harmful, sexual, violent, or illegal content, never ask for the user's name or any other personal detail, never suggest meeting, and redirect any mention of self-harm or danger to a trusted adult or a local emergency line. AI chat is gated behind the consent screen in section 2.2.

6. Retention summary

DataKept for
Local progress on deviceUntil you delete the app
Account, progress snapshot, sessionsUntil you delete your account
Magic-link token15 minutes, single use
Sign-in IP in session recordUntil that session is revoked or the account is deleted
Chat messagesNot stored by us (see 2.2 for DeepSeek)
Free-TTS IP counterUp to 48 hours
Purchase-quota counter (Apple transaction id or Google Play order id)Daily / monthly window, expires automatically (at most 35 days)
Free AI-chat allowance counter (salted IP label)Up to 48 hours
Generated pronunciation audioIndefinitely — course content only, contains no personal data
Problem reports (note, category, screen, version, language, salted IP label, hash of report code)7 days, then deleted automatically (for confirmed reports, only the report-code hash is kept until the fix is published)
Random report codes on your deviceUp to 180 days, or until the thank-you is shown
League weekly rows (group, weekly points, weekly result)8 weeks
League nickname, level, badges, hide list, join recordUntil you delete your account
Invite code, invitation relationship, invitation badgesUntil you delete your account
Used invitation reward (gift end date, assigned App Store code)30 days after the gift ends
Device hash for invitations (one-way, not linked to an account)12 months
Invite code entry attempt counter2 hours

7. Your rights

You can, at any time and without contacting us: use the app fully without an account, sign out, revoke any individual device session, decline AI chat, and delete your account together with all associated data from Settings → Account (step by step, including for people who can no longer open the app: https://tilbis.app/delete-account).

For access, correction, deletion, objection to processing, or any other request under the GDPR, the KVKK, the Personal Data law of the Republic of Kazakhstan or comparable law, write to pix_apps@proton.me. We answer within 30 days.

8. Changes

If this policy changes materially we will update the date at the top and, where the change affects what leaves your device, surface it in the app.

9. Contact

pix_apps@proton.me