What we hold
Yomu stores what you read, when you read it, how long each page was on screen, every word you looked up and how well you remember each one. That is a detailed picture of a person, so this page says exactly what is kept, why it is kept, and how to take it away or destroy it. It is generated from the same list the deletion works through, so it cannot quietly fall behind the database.
The short version
- Nothing is sold, shared or used to build a profile of you. There is no advertising in this product and no third-party analytics of any kind. No Google Analytics, no Sentry, no session recorder. You can check: there is no such code in the app.
- Your books are sent to this server, and the file itself is not kept. Importing a book uploads it here, because the work of turning it into a tappable Japanese text happens here, against a dictionary that is also here. What is stored afterwards is the parsed text the reader draws from; the file you chose is not saved and is still on your own disk. The text of your book is shown to nobody: not to another account, not on the public catalogue, and not to any other company. Its title is a different matter, and the person who runs this server can see it — that is set out in Who else sees it below. This bullet used to read “your books are never uploaded”, which was true when the only Yomu was the one running on its reader’s own computer. It is not true of this one, and a sentence that survives the machine it was written about is the failure this page exists to avoid.
- You can take everything, whenever you like. One link, one JSON file, with the definitions and pitch accent intact, not a list of internal numbers.
- You can delete everything, and it is actually deleted. Not deactivated, not hidden, not kept under a blank name for thirty days. The live database is emptied in one go; the last backup copy holding you ages out within 12 months, which is as fast as a copy taken before you left can possibly go.
- Statistics counted across everybody stay. They hold no identifier and cannot be unmixed. That is the one thing that survives you leaving, and it is set out below.
- You are in an experiment, and you cannot leave it. Half of all accounts are occasionally asked to recall a word cold while reading, so that “reading clears your reviews” can be checked rather than asserted. It is not a privacy question and it is not hidden in one. It has its own section, with the argument for it, below.
What you read and learn
Every learning signal, in order: each word you tapped, each review you answered and how long you took, each page you were credited for reading, each word you marked known, each card you deleted.
§4.5 makes this the only authoritative record in the product. Your schedule, your known words and every figure on your progress screen are computed from it — nothing else is stored that could disagree with it.
Deleted when you delete your account.
The words you are learning: which word, which reading, and the event that created the card.
A projection of the log, so the scheduler has something to query.
Deleted when you delete your account.
Where each of those words sits in the schedule: when it is next due, how many times you have answered it, how many times you failed it.
The scheduler's working state, rebuilt from the log at will.
Deleted when you delete your account.
Which words you know, and what established that: a review, a bulk mark-known, or an import from another app.
This is what decides which words get furigana in the reader and what your coverage of a book is.
Deleted when you delete your account.
Each sitting: when it started, and which half of the verification measurement it was in.
Reading credit is capped per sitting, and §4.3.1's measurement compares readers who are asked to recall words against readers who are not.
Deleted when you delete your account.
Each time reading a page counted as a review: which word, which sitting, and whether it was later taken back.
The audit trail behind the product's central claim. Without it, 'reading cleared this card' is unverifiable.
Deleted when you delete your account.
A nightly list of which of your cards were overdue.
Whether reading actually melts a backlog can only be measured forwards, night by night; it cannot be reconstructed later.
Deleted when you delete your account.
Which nights that collection ran, and over whom.
So that 'nobody had a backlog' and 'the job did not run' stay distinguishable. Otherwise a night the cron missed reads as a night everything was cleared.
Deleted when you delete your account.
Which scheduler settings your cards are scheduled under, and when they changed.
So a due date from a year ago can still be explained by the exact model that set it.
Deleted when you delete your account.
The scheduler settings themselves: a set of numbers, content-addressed by their own hash.
Two people fitted to identical settings share one row, which is what keeps their histories comparable.
Not about anybody. It holds no user id by design. A parameter set names the model, never the person.
Population statistics: how often a given word is recalled at its first review, across everybody, with no individual identifiable.
§6. The only feature here that gets better with more readers. It is suppressed entirely below a floor of distinct learners, so a cell can never be one person's answers.
Kept. §11 says so explicitly: already-computed k-anonymous aggregates are retained on deletion, because they hold no identifying data and cannot be unmixed. Your rows stop feeding it the moment they are erased, so the next recomputation no longer contains you.
That an account was deleted, when, and how many rows went with it.
So that 'the deletion ran' is checkable a year later, by a restore test or by you asking.
Kept. It holds no user id, no name and no address. That is deliberate, and a test asserts the whole column list. A deletion record that named the person deleted would defeat the deletion.
Which database migrations have run.
Machinery. It is a list of filenames.
Not about anybody. Filenames.
Your books
The readings you chose for particular words in a book.
To keep your corrections on your account without changing another reader's text.
Deleted when you delete your account.
The short source passages saved with cards you added while reading.
To show where you encountered a word when you review it.
Deleted when you delete your account.
Specific dictionary meanings you chose to practise as separate cards.
To preserve your chosen meaning when the dictionary changes.
Deleted when you delete your account.
Each book, subtitle track or pasted text you imported: its title, its author, its length and a fingerprint of the file.
It is your library, and the fingerprint is what stops the same file importing twice.
Deleted when you delete your account.
The text of those books, paragraph by paragraph, with every word already looked up.
The reader paginates and marks up this, not the original file. The file you imported is read once and not kept.
Deleted when you delete your account.
The title and author behind an edition, so two files of one novel are one book.
So progress survives re-importing a better copy of the same book.
Deleted when you delete your account.
The vocabulary of each of your books: which words appear in it and how often.
So 'how much of this book do you already know' is one join rather than a scan of the whole novel.
Deleted when you delete your account.
When that vocabulary summary was last computed, and against which parser.
So a summary taken during a half-finished import is detectable rather than merely wrong.
Deleted when you delete your account.
How hard each of your books is, and the counts it was worked out from: how much of the page is kanji, how long the sentences run, which kanji it uses and how far past the common words its vocabulary reaches.
Working that out reads every paragraph of the book, so the answer is kept beside the book rather than recomputed each time the shelf is drawn. It describes the text and not the reader — nothing about what you know goes into it — but it is erased with the book because it is derived from a book that is yours.
Deleted when you delete your account.
One line per book on your shelf: which book, and when you added it. Nothing about the book itself, which is stored once and shared.
A book you add from the catalogue or the news page is not copied to you any more — the text is held once and your shelf holds a reference to it. That is the row that says the book is yours to open, and removing it is what taking a book off your shelf means. Where the text is your own upload, the text goes when you do; where it is this server's, only your line goes and nobody else's reading is disturbed.
Deleted when you delete your account.
For each article on the news page, which feed it came from, its address on the web, when it was published and when this server fetched it.
News articles are the one kind of text here that somebody else owns the copyright in, so every one has to be findable by publisher and by day — that is what makes 'everything this server took from that publisher' and 'remove all of it' single statements rather than a search. The article itself is an edition in your library like any other text.
Deleted when you delete your account.
Where you are in each book, kept as a position in the text rather than a page number.
So the book reopens where you left it on a screen of a different shape.
Deleted when you delete your account.
Which database migrations have run.
Machinery. It is a list of filenames.
Not about anybody. Filenames.
Signing in
Your name, your email address, and whether you have confirmed it.
So you can sign in, and so a password reset has somewhere to go.
Deleted when you delete your account.
Each device signed in to your account: what the browser said it was, when it signed in, when it was last renewed.
So you can see them on this screen and end the ones you do not recognise.
Deleted when you delete your account.
How you sign in: a scrypt hash of your password, or the identifier Google or Apple gave us for you, and the tokens that go with it.
A password is never stored, only a hash of it that cannot be turned back into the password.
Deleted when you delete your account.
Unused password-reset and email-confirmation links.
Each works once and expires within the hour or the day; better-auth deletes the row as it is consumed.
Deleted when you delete your account.
How many sign-in attempts have come from a network address recently.
A sign-in that can be retried without limit is a password guesser. The counter is in the database so a restart does not clear it.
Kept. It is keyed on a network address and a path, never on an account, so there is no row in it that can be found by knowing who you are, and deleting an account cannot delete one. Rows fall out of their own window; nothing here has ever been joined to a person.
One row recording that the first account created on this server took over the reading history that predates accounts.
It can only happen once, and the door has to stay shut afterwards.
Kept. The fact is kept and the account id in it is cleared. Keeping the fact is what stops a second account claiming a library after the first one leaves; keeping the id would be keeping a name.
That this account is the owner of this installation, when that was granted, and why.
The first account registered on a server becomes its administrator, because on a copy with one operator the first person through the door is the person who set it up. That fact has to be stored somewhere, and it is one row naming one account.
Deleted when you delete your account.
What the server records about itself
When something in the server broke while you were using it: which screen, which HTTP status, the fault's own error message, and your account id as the last account it happened to.
So the owner finds out that a screen is failing from a dashboard rather than from you. It never holds what you sent, what you were reading, or your address, and each fault is one row with a count rather than one row per time it happened. They are deleted after thirty days.
Deleted when you delete your account.
When the server's scheduled jobs ran and whether each one succeeded.
So that a job which quietly stopped firing is visible. Without it, a night on which nothing was collected reads as a night on which everything was cleared, which is a green light manufactured by a job that did not run.
Not about anybody. It names jobs, not people. No row in it refers to an account.
Each change the owner made from the administration screens: what was done, when, and which account or job it was done to.
An administrator control with no record of its use is a control nobody can check afterwards, including the administrator. Deleting your account removes both the entries where you were the administrator and your id from any entry that was about you, while leaving the record that the action happened.
Deleted when you delete your account.
When the server last checked its own Japanese parser for mistakes, and how many it found in a sample.
So a word being read wrongly is caught by a nightly check rather than by you noticing. It records how many words were sampled and how many looked wrong — never which book they were in, and never anything about who was reading.
Not about anybody. It describes a run of a check, not a person. No row in it refers to an account, and it holds no book text.
The individual words that check flagged: the word, what the app said about it, and what a dictionary or the book's own furigana says instead.
It is the list the owner works through to fix the parser. It holds single words, the same way the library screen holds titles — no sentences, no paragraph, no edition and no account, so nothing here says which book a word came from or who was reading it.
Not about anybody. A word with no sentence, no edition and no account attached is not a fact about anybody. That is deliberate: 0014 refuses the exemption 0013 was granted, precisely so this table stays impersonal.
How long
For as long as you have an account, and no longer. Nothing above is deleted on a schedule, and that is deliberate rather than lazy: your event log is the only record of your own learning, it cannot be reconstructed, and a product that silently dropped a year-old review would be corrupting the very thing it exists to keep.
Five things do expire on their own, without you asking:
- A sign-in. Thirty days of not using Yomu ends a session, and there is a hard limit from the moment you signed in that nothing extends.
- A password-reset link, after an hour, and it works once.
- An email confirmation link, after a day.
- A sign-in attempt counter, which falls out of its own fifteen-minute window.
- A backup copy of all of it, at 12 months old. Backups are thinned as they age (everything from the last week, then one a day for three months, then one a month), and nothing of any kind is kept past 12 months. What that means for a deletion is in Taking it, and leaving below, and it is why the number is stated at all.
Who else sees it
- Nobody, for the typefaces. Until recently every page loaded three of them from
fonts.googleapis.com, which meant Google’s servers saw the address of every visitor to every page, including this one, which people read before they have agreed to anything. The files are now served from this server, so opening a page here fetches nothing from anywhere else. - An email provider. Password-reset and confirmation messages are sent through Resend, which therefore sees your email address and the text of those messages.
- Google or Apple, if sign-in through them is ever turned on. Neither is configured on this server, so no sign-in goes through either of them.
- Hetzner Online GmbH (Helsinki, Finland), which rents us the machine. Everything above (the database, your books, the backups before they leave) is on one machine rented from Hetzner Online GmbH (Helsinki, Finland). A hosting company can always reach the disk a database sits on, whatever the software does, and there is no arrangement that changes that. The GDPR's word for it is a processor: Hetzner Online GmbH (Helsinki, Finland) holds this data only because we put it on their machine, on our instructions, and may do nothing else with it. Nothing is handed to them the way an address is handed to a mail provider; they are underneath all of it. Naming them is not a formality. Every other recipient on this list can be worked out by using the product, and this one cannot.
- Wherever the backups are kept, once there is anywhere. This server keeps its backups on its own disk and sends them nowhere, which is safer for you and worse for you: nobody else holds a copy, and a disk failure would take the database and every copy of it together.
That is the complete list. There is no analytics provider, no third-party error reporter, no advertising network and no data broker, and none of the words on this page can be made true by anything other than the code.
The person who runs this server can see some of it, and here is exactly what. Whoever runs a database can read it — that is true of every product there has ever been, and a page that implied otherwise would be lying. What is worth stating is the part that is built rather than merely possible: there is one owner-only screen, and it shows your name, when you registered, how many words and books and reading events are yours, when you last had a book open, and the titles of the books on this server together with how well they parsed. It deliberately does not show the text of a book, an email address, or anything you typed — not even to the owner, and a test searches the whole screen for seeded book text and fails if a word of it appears. There is no way to sign in as you from it, and no way to delete your account from it. On a copy running on your own computer, the person that screen belongs to is you.
This server does record its own faults, and that is not a third party. When something here breaks while you are using it, the server writes down which screen failed, what the error was and your account id — so that the person who runs it finds out from a dashboard rather than from you, and so that a screen failing for one person can be told apart from a screen failing for everybody. Nothing leaves this machine, nothing you typed or were reading is in it, and each fault is one row with a count on it rather than one row every time it happens. They are deleted after thirty days — from the live database on the day they turn thirty days old, and out of the last backup holding them within 12 months, which is the same bound everything else on this page has and for the same reason. That is the whole of it, and it is listed table by table above like everything else.
Taking it, and leaving
Settings has both. The export is a single JSON file: your cards, your schedule, your known words and the complete event log (every review, every word you looked up, every page reading credited) and, for every word in it, the written forms, the reading, the meaning, the pitch accent with its source and the frequency rank with its corpus and licence. It is a vocabulary, not a history of numbers. It does not include the text of your books, which you imported from your own files, and there is no Anki .apkg yet.
Deletion is deletion. Everything marked above as deleted goes in a single database transaction, and the deletion refuses to report success while a single row that names you is still there. It checks the database’s own catalogue afterwards, so a table added in a future version is covered before anybody remembers to think about it. If anything were left, the whole thing is undone and you are told, rather than being told you are gone when you are not.
There is no grace period and no thirty-day window, on purpose: an account that can still be restored is an account that has not been deleted. Take the export first. It is offered on the confirmation screen for that reason.
Backups are the one place a deletion does not reach, and that gap is bounded. A deletion empties the live database immediately and completely. It does not, and cannot, reach into copies that were already taken. A backup is a photograph of an earlier moment, and rewriting one is not a thing a database can do. So an account deleted today is still inside the copies taken before today. What we can promise is when that stops being true: the last copy holding you ages out within 12 months, because the retention rule keeps everything from the last week, then one a day for three months, then one a month for 12 months, and then nothing. Saying “deleted everywhere, instantly” would be the easy sentence and it would not be true; saying “until it ages out” and never giving a number would be the easy evasion.
Two things about that number are worth saying plainly. It is not a shelf life somebody typed onto a page: it is the rule the pruning tool applies, imported into this page from the same module, and a test fails if the two ever disagree. And it has one exception: the tool never deletes the last backup in existence, whatever its date, because a policy that can leave a server with no backup at all is a worse failure than a copy kept too long. If backups had stopped a year ago, that single remaining copy would stay.
Statistics counted across everybody, and why there is no opt-out
One figure in this product is counted across all of its readers rather than for one of them: how often a given Japanese word is recalled at its first scheduled review, how often it lapses, how many repetitions it takes before it sticks. It is the one thing here that gets better the more people use it, and it is what will eventually let a new card start with a sensible interval instead of a guess. Only answers you gave deliberately feed it. A reading credit never does, and neither does an import.
There is no opt-out, and the reason is not that it would be inconvenient. A figure is published only when at least 50 distinct learners stand behind it; below that it is suppressed entirely rather than shown with a caveat, and the suppression is in the code that computes it, not in the screen that draws it. So no number that leaves this server can be one person’s answers, and a number that cannot be traced back to a person is not personal data. There is nothing there to opt out of, which is the same reason those figures survive your deletion, when everything else about you does not.
The honest half of that. The result identifies nobody; getting to it reads your reviews, with your account attached, because counting distinct learners is precisely what decides whether a figure may be shown at all. So the derivation runs over personal data even though what comes out of it does not. Deleting your account stops your rows feeding it: the next recomputation no longer contains you, and cells already computed stay because they hold no identifier and cannot be unmixed back into people.
The floor of 50 was not originally chosen for privacy. It was chosen because a recall rate computed from four people is not a fact anybody should act on, and one visibly wrong figure would cost more trust than the feature earns. It does both jobs, and it is worth knowing that it was set by the first argument.
One thing you are enrolled in without being asked
This is not a privacy question. It is here because answering it inside one would be the quiet way to tell you, and because you would otherwise find it out by being interrupted. Yomu’s central claim is that reading a word counts as reviewing it. Nobody knows whether that is true, including us, so the product runs an experiment on itself, and every account is in it.
What actually happens. Your account is put in one of two halves by a hash of its id: sampled, or not. It is decided the first time you start a sitting, never changes, is never chosen by you and is never accepted from your device. A client that could name its own half would be an opt-out with extra steps. If you are in the sampled half then you are sometimes asked to recall a few words cold (before a batch of reviews starts, at the end of a chapter, or as you put a book down), at most 6 in a sitting, and never in the middle of a page. The words asked are the ones reading has been carrying, paired against words you actually reviewed, because the whole point is the comparison between the two.
Why you cannot switch it off. An opt-out would not remove a random slice of readers. It would remove the readers most confident that reading alone is working for them, which is exactly the group whose self-assessment the check exists to test. What was left would be a calibration built from the people who least needed calibrating, and it would report that the mechanic works whether or not it does. The honest options were to ask nobody and claim nothing, or to ask everybody and say so on a page like this one. The rate can be turned down; the thing cannot be turned off.
What it costs you, plainly. Being quizzed is the opposite of immersive reading, and that tension is real rather than rhetorical. It is why the checks sit at pauses you had already taken, why there are never more than 6 of them in a sitting, and why the unsampled half exists at all: if being asked makes people read less, that shows up as a difference between the halves, and it is evidence about the feature rather than an argument about it. If it turns out that reading does not clear reviews, the product’s headline claim is the thing that changes.
What it stores. Which half you are in is recorded on each sitting, and your answers are ordinary events in your own history, both listed in the table above, and both deleted with your account.
Who is responsible, and how to complain
Fergus Leen runs this. Not a company and not a team: one person, who wrote the code this page describes and who holds the database it describes. In the language of the GDPR he is the data controller, which is not a title anybody awards. It follows from deciding what is collected and why, and that is what running it means. Anything about your data (a copy, a correction, a deletion, an objection to how it is used, or a complaint) goes to an address this deployment has not published, and a person reads it.
Three details are still missing from that paragraph and they are named at the bottom of this page rather than guessed at: an address to write to, which is the one gap on this list that stops you exercising any of the rights above; and a postal address, for anything that has to be served on paper; and the country this is established in, which is what decides the supervisory authority that supervises us. None of them changes how you complain, which is the next paragraph.
You may complain to your own country’s authority, wherever we are. This page used to say that how to complain followed from knowing where the controller sits. That was wrong. Article 77 of the GDPR gives you the right to complain to the supervisory authority of the country where you live, the country where you work, or the country where the thing you are complaining about happened. Whichever of those you prefer, and regardless of where we are established. So: write to the address above first, because most things are quicker to fix than to adjudicate, and if that does not satisfy you, take it to your own national authority. It is obliged to deal with your complaint and to tell you what has come of it.
And there is a court after that. If a supervisory authority does not handle your complaint, or does not tell you within three months what it is doing with it, you can take that authority to court (Article 78). You can also go to court against us directly, without complaining to anyone first (Article 79). Nothing on this page, and nothing you agreed to on the way in, asks you to give either of those up.
Sixteen
You need to be sixteen to have an account here. Sixteen is the age the GDPR takes as its default for someone deciding on their own behalf about their own data. Individual countries are allowed to set it lower, and some go to thirteen. This does not follow them down or vary by country, because one age that is right everywhere is worth more here than an age that is exactly right in one place.
Nothing asks your age and nothing checks it. There is no date-of-birth box, no estimate made from anything, and no document. That is a plain statement of what the software does rather than a policy: the requirement is real and it is unenforced, and a page that implied a check existed would be lying about the one thing on it that a parent would care about.
If we learn that an account belongs to someone under sixteen, it is deleted by the same deletion described above, which is a real one: the history, the books, the email address, all of it, in one transaction that refuses to report success while a row naming that person is still there. If you believe a child has an account here, write to the address named above.
What this page cannot yet tell you
These are real gaps, not oversights, and they are here rather than filled with something that sounds right. A stated gap can be closed; an invented promise cannot be withdrawn. This list used to have six things on it. Four are now answered above rather than quietly dropped, a fifth has shrunk to the two facts below, and the last one has not moved, because it is the price of a deliberate choice rather than something waiting on a decision.
- Where a letter would have to go. The person answerable is named above and reachable by email. What is not written down anywhere yet is a postal address, and the country this is established in. The second of those is what decides which authority supervises us. Neither is a decision anybody has to make; they are two facts nobody has supplied, and they are held as blanks in the code so that this paragraph disappears when they are filled in. Your own right to complain does not wait on them: see above.
- What happens if a backup from before your deletion is ever restored. The record kept of a deletion holds no name, no address and no id. That is deliberate, so that it cannot be used to find you. The cost of that choice is that it also cannot be used to re-apply your deletion to a restored copy, so a restore would bring the account back and somebody would have to notice. Both directions are bad; keeping an identifier for the sole purpose of deleting somebody again is the worse one, and it is named here rather than left as a surprise.
If something on this page turns out not to match what the software does, the software is the thing that is wrong, and it is a bug worth reporting.