Privacy Policy
Gangkar · Last updated: July 13, 2026
This policy explains what information Gangkar collects, how we use it, and the choices you have. It applies to the Gangkar iOS app, Android app, and web app. By using Gangkar, you agree to the practices described here.
Who we are
Gangkar is an educational app for learning to read, write, and speak Tibetan: the script, vocabulary, pronunciation, and sentence structure. We are the data controller for the information described in this policy. For any question about your data, contact support@gangkar.app.
Using Gangkar without an account
You do not need an account to learn. The lessons, script reference, practice, and progress tracking all work without signing in, and in that case your progress is stored only on your device. You need an account only to use the social features (the leaderboard and friends). When you continue as a guest, we create an anonymous account and generate a display name for you so you can appear on the leaderboard; a guest account holds no email or other contact information.
Information we collect
Account and profile. When you sign in, we use Firebase Authentication, and depending on the method you choose we may process:
- Your email address, if you sign in with an email link, Google, or Apple. If you use Sign in with Apple and choose to hide your email, we receive only Apple's private relay address.
- Your Firebase user ID.
- Profile details you set, such as username, display name, and avatar color.
- Learning stats synced to your profile, such as XP, streak, and words known.
Learning progress. If you are signed in, we sync your practice progress and session history to your account so it follows you across devices. To keep your progress complete and recoverable, this backup includes the app's saved state from your device. Progress is also kept locally on your device so the app works offline and loads quickly.
Social features. If you use the leaderboard or friends, we store the data needed to run them: friend requests and connections between accounts, and "pokes" (a simple, fixed nudge you can send a friend). Your display name, username, avatar color, and weekly XP are visible to other signed-in users on the leaderboard and in search. You can hide yourself from the leaderboard at any time in the app. There is no messaging or free-text chat between users.
Contributions you submit. If you choose to contribute a word or a pronunciation, we store what you submit, which may include Tibetan and English text, notes, and an audio recording of your voice, along with your user ID if you are signed in. Contributions go to a private review queue and are not shown to other users; a reviewed contribution may later be added to the app's word bank. If you send feedback or a bug report, we store your message and, for bug reports, technical details about your device and a copy of the app's current saved state, which helps us reproduce the problem.
Microphone. Some lessons let you record yourself to compare your pronunciation. These practice recordings are processed on your device only. Audio is uploaded to our storage only in one case: if you deliberately submit a pronunciation as a contribution, as described above.
Notifications. If you allow notifications, we send practice reminders and, when you use social features, alerts such as a friend's poke. To deliver push notifications we store a device notification token on your profile. You can turn notifications off at any time in your device settings.
Analytics. We use PostHog to understand how the app is used in aggregate, such as which lessons are opened and which features are used. It is configured to be privacy-friendly: it runs without cookies or any persistent identifier stored on your device, and events are not linked to your account, user ID, or email. We do not use this data for advertising and do not share it with data brokers. Gangkar does not use Apple's advertising identifier and does not show the App Tracking Transparency prompt, because it does not track you.
Diagnostic and crash data. When something goes wrong, we record a diagnostic event with the error message, stack trace, app version, device and browser user agent, the in-app screen you were on, and your Firebase user ID if you are signed in. This helps us find and fix bugs. We remove the user ID from these events after 90 days, so older logs are no longer linked to you, and they are deleted if you delete your account.
Technical data. As with most online services, the providers listed below receive standard technical information when you use the app, such as IP address, device and browser type, and timestamps, as needed to operate and secure the service.
How we use information
- Provide the learning experience and sync your progress across devices when you are signed in
- Authenticate you and maintain your account
- Run the social features you choose to use
- Handle contributions and feedback you send us
- Send notifications you have allowed
- Measure aggregate usage to improve the app
- Diagnose crashes and bugs, and protect against abuse and keep the service secure
Our legal basis (for users in the EU/UK)
If you are in the European Economic Area, the United Kingdom, or a place with similar data-protection law, we process your information on these bases: performance of a contract (to run your account and sync your progress when you sign in), your consent (for optional features you choose to use, such as social features), and our legitimate interests (to diagnose crashes, keep the service secure, and understand aggregate usage so we can improve the app). Where we rely on consent, you can withdraw it at any time by stopping use of that feature or deleting your account.
Where data is processed
We use Google Firebase (Authentication, Cloud Firestore, Cloud Storage, and Cloud Messaging) to run accounts, store synced data and contributed audio, and deliver push notifications. Firebase operates under Google's terms and privacy policies, and data may be processed in the United States and other countries where Google operates infrastructure. Our own server functions, which send notifications and route feedback, run on Vercel. We use PostHog for cookieless, anonymous analytics, hosted on its European Union infrastructure. Where data about people in the EEA or UK is processed outside those regions, we rely on our providers' standard data-transfer safeguards.
Third-party services
- Google Firebase: authentication, database, file storage, messaging, and infrastructure (Google Privacy Policy)
- Apple: Sign in with Apple (Apple Privacy Policy)
- PostHog: cookieless, anonymous product analytics, EU-hosted (PostHog Privacy Policy)
- Vercel: hosting for our notification and feedback functions (Vercel Privacy Policy)
- Givebutter: processes voluntary donations if you choose to give; we do not receive or store your payment details (Givebutter Privacy Policy)
- Google Fonts: fonts are loaded from Google, so Google may log the request, including your IP address
Retention and deletion
We keep account and profile information for as long as your account exists and as needed to provide the service. You can delete your account directly in the app: open the Social tab, tap your profile avatar, then choose Delete account. Deleting your account removes your profile, synced learning progress, friend connections, and diagnostic logs. Anything you contributed to the community, such as words or feedback, is kept but is unlinked from you so it is no longer associated with your account. You can also request deletion by emailing support@gangkar.app, and we will process the request within 7 days. Data stored only on your device is removed when you delete the app.
Your rights
Depending on where you live (for example the EU, the UK, or California), you have rights over your personal information. These include the right to:
- Access the personal data we hold about you
- Correct data that is wrong or out of date (you can edit most profile fields directly in the app)
- Delete your data (see Retention and deletion above · you can do this yourself in the app)
- Export a copy of your data in a portable format
- Object to or restrict certain processing, such as our use of diagnostic data
- Withdraw consent for optional features at any time
To exercise any of these, email support@gangkar.app from the address on your account and we will respond within 30 days. We will not charge you or treat you differently for exercising these rights.
If you are in the EU or UK and believe we have handled your data improperly, you also have the right to lodge a complaint with your local data-protection authority, though we hope you will contact us first so we can put things right.
Children
The app is intended for learners of all ages who use it with appropriate consent. If you believe we have collected personal information from a child without proper consent, contact us and we will take steps to delete it.
Changes
We may update this policy from time to time. The “Last updated” date at the top will change when we do. Continued use of the app after changes means you accept the updated policy.
See also: Terms of Service · Support