Privacy Policy
Katasaga
Effective date: 12 September 2026
Last updated: 12 September 2026
Katasaga is committed to handling personal data transparently and responsibly. This Privacy Policy describes how personal data is collected, used, disclosed, retained, and protected when you visit katasaga.com, join the Katasaga waitlist, create a Katasaga account, or use the Katasaga web or iOS application.
This Policy is intended to provide the transparency information required under Articles 12–14 of Regulation (EU) 2016/679 (the GDPR). It should be read together with the Katasaga Terms of Service.
1. Controller identity and contact
Katasaga
KVK number: 42159778
Website: https://katasaga.com
Privacy and legal contact: dev@katasaga.com
Katasaga is operated as a Dutch sole proprietorship registered with the Netherlands Chamber of Commerce. Registered business details are available through the Dutch Business Register.
For the purposes of the GDPR, Katasaga is the controller responsible for the processing described in this Policy. Katasaga does not currently appoint a Data Protection Officer. Privacy requests may be sent to the contact address above.
2. Scope and terminology
In this Policy:
- Katasaga, we, us, and our mean the Katasaga business identified in Section 1.
- Service means the Katasaga website, waitlist, web application, iOS application, APIs, live voice features, interactive stories, flashcards, and related services.
- User, you, and your mean an individual who visits the website, joins the waitlist, creates an account, or uses the Service.
- Personal data means information relating to an identified or identifiable individual.
- Processing includes collecting, storing, using, transmitting, analyzing, and deleting personal data.
- Processor means a service provider that processes personal data on Katasaga's documented instructions.
3. Age requirement
The Service is intended for individuals aged 16 or older. Katasaga does not knowingly offer accounts to individuals under 16 and does not currently provide a parental-consent registration process.
During account registration, the User must confirm that they are at least 16 years old. Katasaga does not ordinarily require the User to provide a date of birth. If Katasaga becomes aware that an account belongs to an individual under 16, Katasaga may restrict or close the account and delete associated personal data, subject to any applicable legal retention requirement.
4. Categories and sources of personal data
Katasaga collects personal data directly from the User, automatically through interaction with the Service, and, where applicable, from payment and infrastructure providers.
4.1 Public waitlist
When a User joins the pre-launch waitlist on katasaga.com, Katasaga may process the User's email address and optional information such as language interest, story preference, how the User heard about Katasaga, campaign source, referrer URL, and any other optional waitlist fields.
Waitlist information is stored in Katasaga's waitlist system and may be transmitted to Kit (formerly ConvertKit) for email-list management and launch communications. Waitlist data is logically separate from authenticated application-account data. Joining the waitlist does not create a Katasaga application account.
4.2 Account and authentication data
When a User creates or uses an account, Katasaga processes the User's email address, authentication identifiers, account timestamps, authentication events, and password credentials managed by Supabase Auth. Katasaga does not receive or store the User's password in readable form.
Katasaga may also process onboarding information supplied by the User, including learning goals, preferred learning language, and starting-level information.
4.3 Learning, voice, and conversation data
The Service may process conversation turns, text transcripts, session metadata and summaries, scenario attempts, criteria results, generated feedback, CEFR-style placement estimates, confidence values, rationale, weak-spot categories and evidence, flashcards and review history, goals, streaks, learning-progress statistics, and story or chapter progress.
Katasaga does not intentionally record or archive raw microphone audio. During a live voice session, audio is transmitted in real time over LiveKit Cloud to the Katasaga voice agent and to Deepgram for speech-to-text processing. Audio is not written to Katasaga's database, object storage, or an audio-recording archive. The resulting text may be retained as described in Section 8.
4.4 Technical and security data
Katasaga and infrastructure providers may process information required to operate, secure, and troubleshoot the Service, including IP address, device and browser information, operating-system information, timestamps, request identifiers, authentication events, error information, connection information, and service-usage records.
Katasaga does not currently use third-party advertising or analytics products such as Google Analytics, Meta Pixel, PostHog, Mixpanel, or Sentry.
4.5 Subscription and transaction information
Katasaga does not intentionally receive or store complete payment-card numbers.
For purchases made through the iOS application, Apple processes payment through Apple's In-App Purchase infrastructure. RevenueCat may receive an application-user identifier, platform information, product identifier, purchase and renewal timestamps, expiration status, and subscription-entitlement information. Katasaga receives entitlement information required to provide paid features.
For web purchases, when available, Katasaga uses Stripe Checkout or another Stripe-hosted payment interface. Payment-card details are entered directly into Stripe's hosted interface and are not transmitted to or stored by Katasaga. Stripe may process the email address, customer identifier, subscription identifier, selected plan, transaction status, billing timestamps, fraud-prevention information, and other payment metadata required to provide the service.
4.6 Push-notification data
If push notifications are enabled, OneSignal may process a device push token, OneSignal subscriber identifier, device and application metadata, and limited targeting tags used to determine when to send reminders. Katasaga does not send conversation transcripts or raw microphone recordings to OneSignal.
Users may change notification preferences in Katasaga Settings and may disable notifications through operating-system controls. Disabling notifications stops future notifications but may not immediately delete historical delivery records retained by OneSignal under its applicable policy.
5. Purposes and legal bases
| Purpose | Categories of data | GDPR legal basis |
|---|---|---|
| Create and administer accounts | Email, authentication identifiers, onboarding data | Article 6(1)(b): performance of a contract |
| Provide language-learning features | Transcripts, progress, flashcards, story and scenario data | Article 6(1)(b): performance of a contract |
| Provide live voice conversations | Live audio, transcripts, session metadata | Article 6(1)(b): performance of a contract |
| Provide subscription features | Entitlement and transaction metadata | Article 6(1)(b) and Article 6(1)(c) |
| Operate the waitlist | Email and optional waitlist fields | Article 6(1)(a): consent |
| Send requested service communications | Email and account identifiers | Article 6(1)(b) and Article 6(1)(f) |
| Prevent abuse and protect the Service | Technical data, conversation signals, safety results | Article 6(1)(f): legitimate interests |
| Enforce usage limits and safety rules | Account, usage, session, and safety metadata | Article 6(1)(b) and Article 6(1)(f) |
| Maintain security and troubleshoot failures | Logs, identifiers, error and connection data | Article 6(1)(f): legitimate interests |
| Meet legal and accounting obligations | Transaction and account records | Article 6(1)(c): legal obligation |
Katasaga's legitimate interests include maintaining a secure and reliable service, preventing misuse, protecting users and providers, enforcing contractual limits, and investigating technical failures. Katasaga balances those interests against the User's rights and expectations.
6. AI processing and automated safety controls
Katasaga uses automated systems for conversational responses, speech-to-text, text-to-speech, scenario judging, summaries, language-learning feedback, placement estimates, and safety screening.
The safety system may classify live User turns for harmful content, sexual or NSFW content, threats or hateful content, targeted abuse, prompt injection, and attempts to manipulate scenario grading. A session may be automatically terminated based on those signals.
AI output is not verified by a human before delivery. It may be inaccurate, incomplete, biased, inappropriate, or unavailable. Katasaga's AI features are provided for language practice and are not professional, medical, legal, financial, educational-certification, crisis, or emergency services.
Katasaga does not currently make decisions producing legal or similarly significant effects solely by automated means. Automated safety decisions may limit or terminate an individual conversation or restrict access under the Terms of Service. A User may contact dev@katasaga.com regarding a moderation or access decision.
Katasaga currently has no dedicated in-app button for reporting an individual AI response. Users may end a session and contact the privacy or support address above.
7. Processors and recipients
Katasaga uses the following providers. Their role and applicable processing may change as the Service develops.
| Provider | Role | Data processed | Location / transfer context |
|---|---|---|---|
| Supabase | Database, authentication, storage, Edge Functions, and applicable Auth email delivery | Account data, transcripts, learning data, technical data, entitlement status | Primary project region selected in Germany / West Europe. Provider support and other processing locations may differ. |
| LiveKit Cloud | Real-time voice transport | Audio in transit and operational metadata | Processing and logging locations are governed by the LiveKit service configuration and applicable DPA. |
| Deepgram | Speech-to-text | Live microphone audio and transcription requests | United States; Katasaga configures applicable model-improvement opt-out controls where available. |
| Mistral AI | Conversational model, scenario judge, and safety screening | Conversation text and prompts | France / European Union, subject to applicable Mistral terms and DPA. |
| Cartesia | Text-to-speech | Text submitted to generate spoken responses | United States, subject to the API terms and privacy commitments applicable to the Katasaga account. |
| Kit | Waitlist and email automation | Waitlist email and optional waitlist fields only | United States; does not receive authenticated app conversations. |
| RevenueCat | iOS subscription and entitlement management | App-user ID, product and subscription metadata, entitlement status | United States; no full payment-card number from Katasaga. |
| Stripe | Web checkout and subscription management, when available | Email, customer and subscription identifiers, plan and payment metadata | Stripe processing locations and transfer safeguards apply. |
| OneSignal | Push notifications, if enabled | Device token, subscriber ID, device metadata, limited reminder tags | United States; no transcripts or raw audio. |
Katasaga may disclose personal data to competent authorities where legally required, professional advisers subject to confidentiality, or a successor in connection with a merger, acquisition, restructuring, or transfer of relevant assets.
Katasaga does not sell personal data.
8. Retention and deletion
Conversation transcripts and related session data are retained until deleted by the User or removed under the User's selected automatic-deletion setting. The default setting is indefinite retention. Available automatic-deletion periods are 1 week, 1 month, 3 months, and 1 year, with deletion performed by a scheduled process.
Transcript-linked data includes conversation transcripts, CEFR rationale text, weak-spot evidence text, full session summaries, session-specific skill records, and related conversation records.
The following learning records may remain after transcript-linked deletion: current CEFR-style level and confidence value, weak-spot categories and labels without evidence text, long-term goals, streaks, aggregate progress, flashcards, and flashcard-review records until the User deletes them or deletes the account.
A User may permanently delete the account through Settings. Katasaga will delete associated data from its systems, subject to limited records that must be retained for legal, accounting, security, fraud-prevention, or dispute-resolution purposes. Providers may retain limited records under their own legal or contractual retention rules.
Katasaga does not intentionally archive raw microphone audio. Live audio, generated text, and related requests may temporarily appear in provider operational, security, abuse-prevention, usage, or debugging logs according to applicable provider settings and contractual retention periods.
9. International transfers and safeguards
Katasaga's primary Supabase project region is located in Germany / West Europe. A User's location does not automatically create a regional copy of the primary database.
Some providers process personal data outside the European Economic Area, including in the United States. Where required, Katasaga relies on an applicable Data Processing Addendum, Standard Contractual Clauses, the EU–US Data Privacy Framework where applicable, or another lawful transfer mechanism. Safeguards may depend on the specific service, account, plan, and configuration.
10. Data-subject rights
Subject to the GDPR, a User may request access, rectification, erasure, restriction, portability where applicable, information about processing, or object to processing based on legitimate interests. A User may withdraw consent where consent is the legal basis.
Requests should be sent to dev@katasaga.com. Katasaga may request information reasonably necessary to verify the requester's identity and will respond within the period required by law.
A User may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
11. Security
Katasaga uses measures appropriate to the risks of processing, including authentication controls, access controls, encryption in transit, database row-level security, separation of service credentials, and provider security controls. No internet service can guarantee absolute security.
12. Cookies and similar technologies
Katasaga may use strictly necessary cookies or local storage required for authentication, security, preferences, and Service functionality. Katasaga does not currently use advertising cookies or third-party analytics tracking. If this changes, Katasaga will update this Policy and provide any notice or consent required by law.
13. Marketing and communications
Waitlist and marketing emails are sent only where permitted by applicable law and, where required, with consent. Each marketing email includes an unsubscribe mechanism. Unsubscribing stops marketing messages but does not necessarily stop essential service messages such as security, account, or transaction communications.
14. Changes to this Privacy Policy
Katasaga may update this Privacy Policy when the Service, providers, processing activities, or legal requirements change. Katasaga will publish the updated version with a new effective date and provide additional notice for material changes where required or appropriate.
15. Contact
Privacy questions and requests: dev@katasaga.com