Koto / Information
Koto Privacy Policy
Effective 21 September 2026
Koto is operated by Matthew Evan. For privacy questions or requests, contact [email protected].
This policy explains how Koto handles information when you learn, save content, ask questions, and use voice features. During the beta, feature availability can vary by build. The online processing described below applies when you use an enabled online feature; viewing a local demo is not the same as using live AI.
Visiting this website
This website is hosted by Cloudflare. Delivering and protecting the site involves processing connection and request information, such as IP address, requested page, browser information, and request time. Hosting and security records follow the service provider's retention settings. See Cloudflare's Privacy Policy.
We have not added advertising trackers, embedded third-party media, or a contact form to this website. Support email links open your email application; you choose whether to send a message. Visiting a page does not submit your phone's learning library or start an AI or speech request.
Your learning library
Koto's invited beta is intended for adults aged 18 or older. This audience restriction is separate from Apple's content-based App Store age rating. If you believe a child has submitted personal information to Koto, please contact support.
Koto stores saved expressions, notes, conversation history, and learning progress on your device. This lets you revisit existing content without an internet connection. The library is not a general cloud-sync service, and Koto's server backups do not back up your phone's library. Deleting the app or losing access to the device may result in loss of local content.
The Koto widget can read a limited learning snapshot shared locally with the app. Items marked private are excluded from that widget snapshot. This marking is not a guarantee that text will never leave your phone: using an online feature with that text, such as asking about it or requesting cloud pronunciation, sends the information needed for that request.
Questions, translations, and AI conversations
When you submit an online request, Koto sends your text, relevant recent conversation and learning context, language preferences, and any image you choose to submit through Koto's backend to OpenAI. This supports translations, explanations, roleplay, and conversational replies. A pseudonymous safety identifier may accompany requests to help prevent misuse; it is not a claim that the request is anonymous.
Image input is optional. If you choose a photo or file for an online question, its contents are processed with the accompanying request so Koto can respond to what you selected. Koto does not silently upload your photo library. iOS permission controls which photos or files you can choose, and you should remove names, faces, documents, or other sensitive details that are not needed for the question.
For enabled personalized online features, Koto's backend can store a limited learner profile and learning context to make later replies more relevant. This is separate from, and not a complete backup of, your device's Memory library.
Please avoid submitting confidential information or personal information about someone else unless you have a reason and permission to share it. AI output may contain errors, including translation and tone errors.
OpenAI states that API data is not used to train its models unless the customer opts in. Its standard abuse-monitoring retention may include prompts and replies for up to 30 days, with exceptions described in its documentation. Koto requests that responses not be stored as retrievable response history, but this does not mean zero provider retention. See OpenAI's API data controls.
Listening and pronunciation
For cloud voice playback, Koto sends the text to be spoken, its language, and the selected playback mode through its backend to Google Cloud Text-to-Speech, using Chirp 3 HD. An explicit Kana reading may be spoken instead of the Kanji shown on screen. This speech-generation request sends text, not a recording from your microphone.
Generated cloud audio is held temporarily in memory for playback, not saved as a permanent offline audio library. When device voice playback is available as a fallback, that playback uses the device's speech system and may sound different.
Google states that Cloud Text-to-Speech does not log customer synthesis text or audio. This is specific to that service; it does not mean Koto has no usage records or that Google Cloud has no infrastructure logs. See Google's Cloud Text-to-Speech data-logging explanation.
Microphone and speech recognition
Speaking into Koto uses Apple's speech-recognition framework after you grant microphone and speech-recognition permission. Audio is processed for transcription and may be sent to Apple; recognition is not guaranteed to happen entirely on your device. The current Koto recognition flow does not save an audio recording. Recognized text may be kept in your conversation and sent for an AI reply when you use an online speaking feature.
You can manage these permissions in iOS Settings. Denying microphone access does not prevent you from typing or viewing saved content. Apple describes the processing of third-party speech recognition in Siri, Dictation & Privacy.
Operating and protecting the service
Enabled account-based services use account identifiers and session information to control access. The backend records usage and technical information such as request identifiers, error categories, request counts, text or token quantities, and estimated service costs. These records help enforce beta limits, prevent abuse, investigate failures, and reconcile provider charges.
Application diagnostic logging is designed to exclude message bodies, microphone recordings, and credentials. Operational records can still include pseudonymous account identifiers, request identifiers, feature and error categories, quantities, timings, and cost estimates. Hosting providers may separately process connection metadata, such as IP addresses, and infrastructure, security, and audit logs. Koto uses Google Cloud for its backend and server-side storage.
Koto's current app does not include advertising networks or cross-app advertising tracking. Provider credentials are kept on the backend, not distributed in the app. Access controls and encrypted network connections help protect information, but no service can guarantee absolute security.
Subscriptions and payment
Koto does not currently offer a live paid subscription and does not currently collect subscription payment or purchase-history data. A possible Koto Plus offer is still being designed. If a paid offer is activated later, Koto will update this policy and the in-app disclosure to explain the purchase, entitlement, and allowance records actually processed. Apple would process App Store payment details under Apple's own terms; Koto would not receive your full card details.
Support messages
If you email support, we receive your email address, your message, and any attachments through Gmail. Matthew Evan and Koto team members handling support may read this correspondence to answer your request and investigate the issue you report. Send only what is needed, and redact private conversations and other people's details. Never send passwords, verification codes, API keys, or private signing keys.
How long information is kept
Different kinds of information have different retention periods:
- Device library: kept locally until you delete it or the device/app data is removed. Koto does not erase saved learning content just because you are inactive.
- Backend learner context: kept to support enabled personalized services; deletion is handled separately from deleting an item on your phone.
- Application diagnostics: subject to a seven-day retention policy. This does not cover every infrastructure or audit log, or older copies created before the current log-routing configuration.
- Settled individual request and cost details: eligible for scheduled cleanup 30 days after confirmation or settlement. Unresolved charges and in-flight operations are held until they can be safely reconciled.
- Server database backups: daily backups are retained for seven days. Copies can remain in a backup until it expires; these backups do not contain a backup of your device-only notes and chats.
Cleanup runs periodically, so becoming eligible for deletion does not mean removal at that exact moment. Security records that prevent deleted accounts from being restored, unresolved operations, account-level usage totals, and non-learner-specific aggregate totals have separate lifecycles. Infrastructure and audit logs are governed by their own retention settings. Support correspondence is kept as needed to handle the request and meet applicable recordkeeping obligations.
Service providers have their own processing and retention rules. Deleting local content does not automatically erase information already sent to a provider.
Your choices and privacy requests
Online AI and cloud voices are optional. In enabled account-based builds, Koto asks for permission on this device and for your online account before sending content to OpenAI or Google Cloud Text-to-Speech. Koto stores your account's latest decision, policy version, opaque revision, and update time, linked through a pseudonymous account identifier. You can check, allow, or withdraw account permission in Settings → Online processing. A material disclosure change requires a fresh choice. Saved content, notes, review, Kana, and available on-device pronunciation remain usable without online permission.
Withdrawing device permission stops new online requests here and stops current playback. Confirmed account withdrawal prevents subsequent online dispatch across devices. If account withdrawal cannot be confirmed, this device stays off; reconnect and check account status. Withdrawal cannot recall information already transmitted, guarantee cancellation of dispatched provider work, or itself delete retained data. The latest account decision remains with account records until account deletion; backup copies may remain until their retention period ends. Local demo content stays separate from your personal learning data.
For questions about information held by Koto, or to request access, correction, or deletion, email [email protected]. We may need to verify your connection to the information before acting. Do not send identity documents unless specifically requested through an appropriate process. The rights available to you depend on applicable law.
Deleting a local item, uninstalling the app, and deleting server-held account information are different actions. In an account-enabled build while signed in, request deletion through Settings → Online account → Delete online account. Koto does not present the request as complete until the server confirms it; pending backups and unresolved operations remain subject to the retention rules above. If that control is unavailable, or you cannot recover access needed to finish a pending deletion, contact support. We cannot promise to recover a library deleted from your device.
International processing
Koto's configured backend is in Singapore. OpenAI, Google, Apple, and the email and hosting services involved may process information in other countries. Koto does not promise that all processing or storage remains in Singapore or in your country of residence.
Updates and contact
We will update this policy when Koto's data practices change and identify the effective date of the updated version. For help with the app, see Koto Support. The current Koto Terms also explain the service boundary. For privacy matters, contact Matthew Evan at [email protected].