プライバシーポリシー
二つのアプリと、このウェブサイト。三つのポリシーを、一つのページに。
このページは英語のみで提供しています。英語版が正式なものです。
Toku Reader for iPhone and iPad
Last updated: September 8, 2026
Toku Reader (“the App”) is a Japanese and Chinese reading assistant developed by Darren Nah. This policy explains what data the App collects, why, and how it is handled.
On-Device Processing
The core function of Toku Reader is to help you read Japanese and Chinese text. All text analysis — including tokenization, readings, definitions, and dictionary lookups — is performed entirely on your device. The texts you paste, import, or read in the App are never sent to any server, except the single sentence you choose to send when you ask for an AI explanation (see “AI explanations” below).
This applies to all content surfaces in the App:
- Text Reader — Pasted or imported text (plain text, PDF, EPUB, SRT files) is processed and stored locally on your device.
- Web Reader — The in-app browser lets you read web pages with reading aids. Web pages are fetched directly by Apple’s WebKit framework (the same engine used by Safari), and text analysis happens on-device. Browser conveniences — browsing history, open tabs, per-site reading-aid preferences — are stored only on your device, are never transmitted anywhere, are excluded from device backups, and can be cleared at any time (History > Clear). The App developer cannot see your browsing activity.
- Watch (YouTube) — The Watch tab plays YouTube videos through YouTube’s official embedded player and shows their subtitles as tappable text. When you search for videos or play one, your search terms and video requests go directly to YouTube (Google); the developer never sees them. Google’s Privacy Policy applies to that traffic. Subtitle text and your recent-video list are cached locally on your device; all language analysis of subtitles happens on-device. The App developer receives none of this data.
- OCR Reader — When you use the camera or select a photo for text recognition, images are processed entirely on your device, either by Apple’s built-in Vision framework or by Google ML Kit’s Japanese and Chinese text recognizers (see “Third-Party SDKs” below). Both ML Kit text-recognition models are bundled in the app, so no network download is needed for them. Images are not uploaded, stored, or transmitted.
- Dictionary — Lookups use bundled offline databases: JMdict (Japanese), CC-CEDICT (Simplified/Traditional Chinese), MoEDict (Taiwan Traditional Chinese), JMnedict (Japanese names), KANJIDIC2 (kanji data), Tatoeba (example sentences), and pitch accent data. No network requests are made for dictionary lookups.
- Handwriting Input — When you use the handwriting canvas to draw a character, recognition runs on-device via Google ML Kit’s Digital Ink Recognition. Unlike ML Kit’s text-recognition models, the Digital Ink models are downloaded from Google (about 20 MB per language) and then cached on your device — after that, recognition runs fully offline. The download starts automatically over Wi-Fi in the background after you finish setup; it does not wait for you to open the handwriting canvas. See “Third-Party SDKs” below.
- Share Extension — When you share text or URLs from other apps into Toku Reader, the shared content is processed and stored locally on your device.
- Word Review & SRS — Saved words, review history, and spaced-repetition scheduling data are stored locally on your device.
- Text-to-Speech — Read-along audio is generated on-device using Apple’s built-in speech synthesis. No audio data is transmitted.
- Anki Import / Export — Imported .apkg files are parsed in memory on-device and are not retained after import. Exports are written to a file location you choose; nothing is transmitted.
Podcasts and Speech Models
The Listen tab is the one reading surface that has to reach the open internet, because podcasts live there. What it does, and who sees what:
- Shows and episodes — Feeds, episode audio, artwork, and any transcript a publisher provides are fetched directly from that publisher and from Apple’s podcast content network. They do not pass through the developer’s servers.
- Searching for a show — Your search words are sent to Apple’s podcast directory and to PodcastIndex.org, which are the two catalogues the App searches. They go to those services, not to the developer.
- Transcribing an episode — When a publisher provides no transcript, the App makes its own, on your device. To do that it downloads a speech-recognition model of about 600 MB from Hugging Face. The download starts automatically over Wi-Fi, in the background, after you finish setup. The audio itself is never uploaded; transcription happens entirely on the phone.
- Your own audio and video files — When you open an audio or video file from your own device through the Files picker, the App reads it where it sits and writes the transcript on your phone (or uses a subtitle file you picked with it). The App keeps only a pointer to the file, never a copy. The file, the audio and the transcript are never uploaded and never leave your device. Removing a file from the App’s list never touches the file itself.
- Shadowing practice — Repeating a line back uses the microphone. The recording is compared with the line on your device and stays on your device. No audio is transmitted.
What We Collect
The App sends the developer three kinds of data by default, and one more only if you turn on AI explanations. None of the three include the text you read.
- Crash and freeze reports— on by default, and switched off in Settings (“Share anonymous crash & performance reports”). If the App crashes or stops responding, the report carries: your device model, iOS version, the App version and build number, where in the code it stopped, and the anonymous device identifier described below. It never carries your texts, your saved words, or anything you typed.
- First-two-days setup counters — sent only by new installs, during the first two days, and switched off in Settings. Eight yes-or-no facts about getting started — for example whether setup was finished, whether a word was tapped, and whether the App was opened again on the second day — plus how many seconds passed before the first tap, the anonymous device identifier, and the App version. No content of any kind is included.
- Feedback reports you choose to send — when you report a wrong reading or definition, or send feedback about the App, the report carries: the word you tapped, the passage you were reading exactly as it appeared on screen, the dictionary form and word class the App chose for that word, which reader you were in, the version of the analysis engine, the language, your note, and the App version.
The anonymous device identifieris a random UUID generated on first launch and stored in your device’s Keychain. It exists to group reports that came from the same device; it cannot identify you personally, and it is tied to no name, email, or account. Because it lives in the Keychain it may survive reinstalling the App. It accompanies crash reports, setup counters, feedback reports, and — from version 5.5.0 — AI explanation requests. On the server it is never stored in its original form: it is kept only as a one-way hash, used to count explanations against your monthly allowance.
Optional External Integrations
The following integrations are off by default and only activate when you explicitly opt in. Each is independent — you can use the App without any of them.
AI explanations (optional, off until you turn it on; version 5.5.0 and later)
From version 5.5.0 the App can explain whya word or a sentence means what it means. This is off until you turn it on. When you have turned it on and you tap the AI button, the App sends the following to the developer’s server, which forwards it to an AI provider: the sentence you asked about, the sentence before it, the App’s own word-by-word breakdown of it, the dictionary meanings the App found, the question being asked, and the language you read answers in.
The provider is either Anthropic (Claude) or Google (Gemini). Both are named here because the developer may switch between them without shipping a new version of the App. Each retains what it receives under its own API terms — see Anthropic’s privacy policy and the Gemini API terms.
No name, email, or account is sent. The anonymous device identifier is sent so that explanations can be counted against your allowance — or, if you are a subscriber, the signed App Store receipt instead — and the server stores it only as a one-way hash. The answer, once it has passed the App’s own correctness checks, is kept on the server under a fingerprint of the sentence, so that the next reader who asks about the same sentence gets the same answer instantly.
Reading, dictionary lookups, and listening never use this. You can turn it off again at any time in Settings.
Sign in with Apple (optional)
If you sign in with Apple, the name and email Apple shares (both of which you can hide) are stored only in your device’s Keychain and are never sent to the developer. If you later delete your account, the App sends a single one-time authorization code from Apple to the developer’s server for one purpose only: to tell Apple to revoke the sign-in token. The code is used once and nothing from it is stored.
WaniKani (optional)
If you connect a WaniKani account, the App acts as a client of wanikani.com’s public API (api.wanikani.com). This requires:
- Your WaniKani Personal Access Token (PAT), which you generate on wanikani.com and paste into the App. The PAT is stored in the iOS Keychain on your device. It is only transmitted to
api.wanikani.comover HTTPS, never to the App developer’s servers. - Your WaniKani subjects, assignments, review statistics, and study materials are fetched from
api.wanikani.comand cached locally so reviews and lessons work offline. - When you submit a review grade, the result is sent to
api.wanikani.comto update your SRS progress on WaniKani’s servers. The App does NOT send this data anywhere else.
Disconnect at any time in Settings — the PAT is deleted from the Keychain and cached WaniKani data is cleared. The App does not read, log, or transmit your WaniKani data except to and from api.wanikani.com. WaniKani’s own privacy policy applies to data it holds on its servers.
Premium Subscription (optional)
The monthly Premium subscription is processed entirely through Apple’s StoreKit. Payment information is handled by Apple — the App never sees or stores your payment method, Apple ID, or billing details. The App records your current tier (free or Premium) and a count of the word lookups you have made today in your device’s iOS Keychain. From version 5.5.0 it also keeps, in its ordinary local settings, a running count of the explanations you have asked for this month, and the signed receipt Apple issues for your subscription is sent with an explanation request so the server can confirm that you are a subscriber.
What We Do NOT Collect
- No names or email addresses are ever transmitted to the developer. If you optionally use Sign in with Apple, the name and email Apple shares (which you can hide) are stored only in your device’s Keychain and never sent to us; the WaniKani PAT likewise stays on your device and is only sent to wanikani.com
- No location data
- No third-party analytics or advertising SDKs. The developer receives only the crash reports and setup counters described under “What We Collect” above, both of which you can switch off in Settings
- No advertising identifiers
- No browsing history or web activity is ever transmitted to the developer (your local history stays on your device, under your control)
- No photos or camera images
- No payment information (handled entirely by Apple)
- The Japanese and Chinese texts you read in the App are processed entirely on your device and are never sent to any server, apart from a sentence you choose to send for an AI explanation
- Nothing the App keeps in your iCloud account — your library, saved words, decks, reading position, podcast favorites — is visible to the developer. It is in your account, not ours (see “iCloud Sync” below)
Device Permissions
The App may request the following permissions, all of which are optional:
- Camera — Used only for the OCR Reader to photograph printed text. Images are processed on-device and never leave your device.
- Photo Library — Used only for the OCR Reader to select images for text recognition. The App uses Apple’s privacy-preserving photo picker, which only gives the App access to photos you explicitly select.
- Notifications — Optional. If you connect WaniKani, the App can schedule a local notification when reviews become available. Notifications are scheduled on-device by iOS; no data is transmitted to enable them.
Third-Party SDKs
The App integrates one third-party SDK family: Google ML Kit. The specific ML Kit modules used, how they behave, and how to avoid them are listed below.
- Text Recognition (Japanese and Chinese) — one of the two OCR engines the App can use. Both models are bundled inside the App, so nothing is downloaded for them. Recognition runs fully on-device.
- Digital Ink Recognition (handwriting in the Dictionary tab). Recognition runs on-device, but the models come from Google — about 20 MB per language.
- Translation — what the “Show English” option uses. Translation runs on-device, but the models come from Google — about 30 MB per language.
- ML Kit’s default SDK telemetry. Google ML Kit generates a pseudonymous instance identifier and may send basic SDK diagnostics to Google on first use. This is Google’s default SDK behavior and is not specific to this App. See Google ML Kit’s terms and Google’s Privacy Policy.
When the handwriting and translation models are downloaded:automatically, from Google, over Wi-Fi, in the background, after you finish setup. They do not wait until you open the handwriting canvas or ask for English. (If a download did not succeed, Settings offers a retry that is allowed to use cellular data.) Once a model is on your device, that feature works offline from then on.
Can you avoid Google ML Kit? Not entirely: the modules above are part of the App, and the handwriting and translation models download after setup as described. You can avoid usingthem — the OCR Reader can run on Apple’s own Vision framework instead, and you need never open the handwriting canvas or turn on “Show English.” Everything else — text reader, web reader, dictionary text search, SRS reviews, WaniKani, paste-based reading — never touches ML Kit at all.
No advertising SDKs and no third-party analytics SDKs are integrated. Crash reports go to the developer’s own server, not to a third-party crash-reporting service, and can be switched off in Settings.
What Happens at Launch
On each app launch, Toku Reader fetches the latest set of approved dictionary corrections (reading/definition fixes the developer has curated from anonymous user feedback) from the same Supabase server the feedback reports go to. This is a read-only download of correction entries — no personal data is sent from your device in this request, and the App does not upload or identify you during the fetch. If the network is unavailable, the App continues using the previously cached corrections bundled with the app.
In the same way, the App fetches its own configuration and its bundled story texts from the developer’s storage at launch, so that both can be corrected without waiting for an App Store update. These requests carry no personal data either.
iCloud Sync (Your Own iPhones and iPads)
Toku Reader can keep your reading in step across your own Apple devices. Your saved texts and books, your saved words and their review progress, your decks, and where you had got to in each text are stored in your own iCloud account— on Apple’s servers, under your Apple ID, in what Apple calls a private database. That means exactly what it sounds like: it belongs to you, not to us. The App developer cannot read it, cannot list it, and could not produce it if asked to.
Your podcast favorites, your collections, and the shows and channels you follow travel the same way, using iCloud key-value storage — a small, simple version of the same thing, also inside your own iCloud account.
- Nothing new is sent to the developer.This feature does not add anything to what is described under “What We Collect” above. Your texts still never reach our servers.
- It covers your iPhones and iPads— the devices signed in to the same Apple account. Toku Reader for Android does not sync, and cannot: iCloud is Apple’s.
- Your settings do not sync. Reading aids, text size, and your other preferences are set on each device separately.
- You can turn it off.In the App, go to Settings and switch off “Sync with iCloud”. Nothing further is sent to iCloud after that.
- You can delete what is already there.On your iPhone or iPad, open the iOS Settings app, tap your name at the very top, then iCloud → Manage Account Storage (called “Manage Storage” on some versions of iOS) → Toku Reader. Deleting it there removes the App’s iCloud data from your account. Because this is your account and not ours, this is something only you can do — the developer has no way to reach it.
Apple’s handling of data in your iCloud account is governed by Apple’s Privacy Policy, not by this one.
How Data Is Stored
The data that leaves your device for the App developer’s servers — crash reports, setup counters, feedback reports, and (from version 5.5.0) AI explanation requests — is stored in a Supabase database hosted in the United States (AWS us-east-2, Ohio). Data is transmitted over HTTPS. Row Level Security (RLS) is enabled on all database tables.
WaniKani data (if you opt in) is held by WaniKani on its own servers under WaniKani’s privacy policy. Apple holds subscription and payment data under Apple’s privacy policy. The App developer has no access to either.
Data Retention
Feedback reports, crash reports, and setup counters are retained indefinitely, to fix what is wrong and to see whether the App is getting easier to start using. A checked AI explanation is kept under a fingerprint of the sentence it explains, so that the same question does not have to be asked twice. You may request deletion at any time (see below).
Your Rights
What you can ask for depends on where you live. The four cases below cover most readers; if yours is not listed, write to the address at the foot of this policy and the same requests will be honored.
Under GDPR (European Union)
If you are in the EU/EEA, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Request portability of your data
- Object to processing of your data
Legal basis for processing: legitimate interest in improving the App’s accuracy based on voluntary user feedback.
Under APPI (Japan)
If you are in Japan, you have the right to request disclosure, correction, or deletion of your personal information under the Act on the Protection of Personal Information. Data is stored in the United States; transfers rely on the developer’s data-processing agreement with Supabase, which includes standard contractual clauses.
Under PIPL (China)
If you are in China, you have the right to access, copy, correct, and request deletion of your personal information under the Personal Information Protection Law. The App processes all reading content locally on your device. Only the data described under “What We Collect” is transferred to servers in the United States.
Under CCPA (California, USA)
If you are a California resident, you have the right to know what personal information is collected and to request its deletion. The App does not sell personal information.
Children’s Privacy (COPPA)
The App is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has submitted data through the App, please contact us for removal.
Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated date.
Contact
The data controller for this website and the Toku Reader apps is Darren Nah, an individual developer in New York, NY, USA.
For any privacy-related request — access, deletion, or a question — please write to:
If you are in the EU or UK and are unhappy with how your data is handled, you may complain to your local supervisory authority (in the UK, the Information Commissioner’s Office).
Privacy Policy — Toku Reader for Android
Version 2.2 · Last updated: September 6, 2026
Toku Reader ("the App") is a Japanese and Chinese reading assistant developed by Darren Nah. There is no account, and nothing you read, listen to, record or save is sent anywhere — with one exception you switch on yourself: AI explanations. If you turn that on, the single sentence you ask about is sent to be explained, and nothing else. That one feature is described in full under AI explanations. The App contains no advertising SDK, no crash-reporting SDK, and no analytics SDK of the developer's.
It does contain two Google SDKs — ML Kit and Google Play Billing — and those report their own diagnostics to Google. That is described in full under Google's SDKs, because a policy that said "nothing leaves your phone" while a Google library reported to Google would be false.
This policy covers the Android app (package
com.darren.tokureader). The iOS app is a separate product, built on
a different set of components, with its own
privacy
policy. Where the two differ, this page governs Android. Notably, the iOS app
has a feedback-and-corrections feature that sends data to a server;
the Android app has no such feature. The Android app does reach
one server of the developer's, but only for AI
explanations, and only after you turn that feature on.
What the developer collects
Nothing at all, unless you turn on AI explanations. There is no sign-up, no login and no user account. Your texts, saved words, review history, recordings, browsing history and downloads exist only on your phone, and the App contacts no server of the developer's while that switch is off.
If you do turn AI explanations on, the sentences you explicitly ask about — and nothing else — reach a small server the developer runs, along with a random per-install number used to count your monthly allowance. It is still no name, no email and no account. Exactly what is sent, what is kept and how to have it deleted is set out under AI explanations.
Almost everything the App does for you happens on your device
- Reading — text you paste, share, import or scan is analysed on-device: word boundaries, readings (furigana / pinyin), and dictionary meanings. It is stored only on your phone.
- Dictionaries — the Japanese and Chinese dictionaries ship inside the App (they are most of its download size). Tapping a word to see what it means makes no network request, and the App reads perfectly well in airplane mode. Asking for an AI explanation of a word or sentence is the one tap that does leave the phone, and only if you have switched that feature on.
- Saved words and review — your saved words, review history and scheduling live in a database on your phone.
- Reading text in photos — the Japanese and Chinese text recognition models are bundled inside the App. Photos are read on-device and are never uploaded or stored by the App. The App has no camera permission at all: you pick an existing image through Android's own picker, which hands the App only the file you chose.
- Transcribing podcasts — when a show publishes no transcript, the App writes one on your phone using a speech model that runs locally; the audio is not uploaded to anyone. The model itself is downloaded once — see Where the App connects.
- Your own audio and video files — When you open an audio or video file from your own device through the Files picker, the App reads it where it sits and writes the transcript on your phone (or uses a subtitle file you picked with it). The App keeps only a pointer to the file, never a copy. The file, the audio and the transcript are never uploaded and never leave your device. Removing a file from the App’s list never touches the file itself.
- Shadowing recordings — recordings you make stay in the App's private cache on your phone. They are not uploaded, and they are not sent to any speech-recognition service.
- Browsing history in the Web tab — the addresses you visit are written to a file inside the App's private storage so the "continue reading" shelf works. That file never leaves your phone.
- Text-to-speech — spoken readings use the text-to-speech engine already installed on your Android device.
- Crash reports — if the App closes unexpectedly, it writes the technical details to a file on your phone and offers to share it the next time you open the App. Nothing is sent unless you tap Send and choose where it goes. You can dismiss it and the file is deleted. (Separately, Google Play collects crash and not-responding data for every app installed from Play — that is a Play platform behaviour, described under Google's SDKs.)
Where the App connects, and why
The App reaches the network only to do something you asked for. This list is meant to be exhaustive. With one exception — AI explanations, the last entry below — every request goes to that third party directly: it does not pass through, and is not logged by, any server of the developer's.
- Podcast feeds and episodes — the App fetches a show's RSS feed and downloads or streams episodes from the show's own host. The list of shows is bundled in the App, so browsing the directory itself contacts no one. Be aware that podcast audio links routinely redirect through the publisher's own measurement services before reaching the audio file; those services see a normal media request (including your IP address and app user agent), exactly as they would from any podcast app.
- Podcast artwork — cover images are loaded from the publisher's image host or a podcast-directory CDN.
- Speech model download — the offline transcription
models are downloaded once: the recognizer (roughly 240 MB) from
Hugging Face (
huggingface.co) and a small voice-activity file (under 2 MB) from GitHub (github.com) — the standard public hosts for these models. A larger optional model chosen in Settings › Transcripts & Storage (up to roughly 1.6 GB) also comes from Hugging Face. Each host sees a normal file download. After that, transcription is fully offline. If you never transcribe anything, this never happens. - Web Reader — the in-app browser loads the pages you navigate to using Android System WebView (the same engine as Chrome). The App does not collect, log or transmit your browsing history, the addresses you visit, or page contents — the one exception being a single sentence you deliberately ask about with AI explanations switched on, which is sent without the page address. Sites you visit see you as they would in any browser, and their own privacy policies and cookies apply to them.
- YouTube captions — if you open a YouTube video to read along with its captions, the App requests that video's caption data from YouTube. YouTube sees a normal request for that video.
- Google's on-device model downloads — two optional features fetch a model from Google the first time you use them, then work offline afterwards: handwriting input in the Dictionary tab (about 20 MB per language, and the App shows you the size and asks before downloading) and Show English gloss translation on transcripts (about 30 MB per language pair, downloaded silently on first use over whatever connection you are on). If you never use those features, nothing is downloaded.
- Google Play Billing — if you buy a subscription, the purchase is handled entirely by Google Play. The App asks Google Play for the price and for your existing purchases, and it never sees or handles your payment details.
- WaniKani — only if you connect it; see below.
- Google's SDK diagnostics — see below.
- AI explanations — the one destination that is the developer's own. If, and only if, you switch this feature on and tap to ask about a sentence, that sentence goes to a small server the developer runs on Supabase in the United States, which passes it to the AI provider. This never happens with the switch off. See AI explanations for everything that is sent, everything that is kept, and how to have it deleted.
Two of these happen during first-run setup if you accept the offer to prepare offline listening: the speech model download and a first episode download. Both are optional and are described on screen before they start.
AI explanations (optional)
This is the only part of the App that sends anything to the developer, and it is switched off until you switch it on. If you never switch it on, nothing in this section ever happens to you.
With it on, a word card gains a small sparkles button, and a sentence gains the rows Why this meaning? and What is this sentence doing?. Tapping one asks an AI to pick, out of the meanings the App has already worked out on your phone, the one that fits this particular sentence — and to say why in a sentence or two. The first time you tap, the App shows you what will be sent and asks; you can say no, and you can turn the feature off again whenever you like in Settings.
One small automatic request comes with this feature: once every few hours the App fetches a short settings file from the developer's server that says whether AI explanations are switched on at all (the developer's off switch). That fetch carries no data about you — it is a plain download of a public file, like fetching a podcast list — and it happens whether or not you have turned explanations on.
Where the request goes
It travels over HTTPS to a small server the developer runs on Supabase, hosted in the United States. That server passes the sentence to the AI provider — today Claude, made by Anthropic. The developer may change provider (Google's Gemini, for example) without changing what is sent; if that happens, this page will be updated to name the new one. Your phone never talks to the AI provider directly.
What is sent
- The sentence you tapped. If you asked about the whole sentence, also the sentence immediately before it, so the answer fits the context.
- The App's own breakdown of that sentence — for each word, how it is written, how it is read, what kind of word it is, and its dictionary form.
- The candidate meanings, alternative readings and grammar patterns the App's built-in dictionaries already found for that sentence. That is the list the AI chooses from; it is not asked to invent anything.
- Which question you asked, and whether it is your first or second try.
- Which part of the App you asked from — pasted or imported text, a web page, a podcast, or a video. The web address is not sent, only the word "web".
- The language you want the answer in, and a version number for the App's dictionary analysis.
- A random number the App made up when you installed it. It is not your name, your email, or any Google or Android account — it exists only to count how many explanations this installation has used this month. The server stores it only as a one-way scramble (a SHA-256 hash), so the stored counter cannot be turned back into the number your phone holds.
- If you subscribe, a proof of purchase from Google Play, so that the larger allowance applies to you. It carries no payment details of any kind.
Never sent: your name or your email address (the App has neither, and there is no account), the addresses of pages you visit, your saved words, your review history, any audio or recording, any photo, and any sentence you did not tap. The rest of whatever you are reading stays on your phone.
What is kept, and for how long
- A counter — the scrambled number above, with how many explanations it has used this calendar month, so the free allowance can be applied.
- The checked answer, filed under a scramble of the sentence rather than under you. That way a sentence is explained once and the next person who asks the same thing gets the stored answer instead of a new one.
- One line per request: the scrambled number, what was asked, which version of the App's dictionaries produced the breakdown, and how long the answer took. It is there to spot the feature breaking and to stop the costs running away.
Being straight with you: no deletion schedule has been set yet. Those rows are kept indefinitely today. A retention period will be chosen and this page will then say what it is. Until then, "indefinitely" is the honest answer — writing "30 days" here because it reads better would be a promise the server does not keep.
Asking for it to be deleted
Email tokureader@gmail.com and ask. The App cannot show you your random number today, so a request is actioned by month: tell us roughly when you used the feature, and the counters and request lines for that period are deleted. The stored answers are filed under the sentence rather than under you, so they hold nothing that points back to you. If a future version of the App shows you that number, this page will say so and deletion will become exact.
The short version
- Reading, tapping words, listening, saving and review never need the internet. This is the only part that does.
- Everything sent is encrypted in transit (HTTPS).
- It is never used for advertising, is never sold or rented to anyone, and is not linked to your identity — the developer has no identity for you to link it to.
- Free: 5 explanations per calendar month, which start again when the month does. Toku Unlimited: unlimited within fair use.
- Turning the switch off in Settings stops all of it.
Google's SDKs — ML Kit and Play Billing
The App uses Google ML Kit for on-device text recognition (reading photos), handwriting recognition, and gloss translation; and Google Play Billing for subscriptions. The recognition and translation themselves run on your device — your photos, your handwriting and your transcripts are not sent to Google for processing.
However, these are Google SDKs and they report to Google about themselves. Per Google's own ML Kit data disclosure, ML Kit collects and transmits to Google:
- device information (manufacturer, model, OS version and build) and available ML hardware accelerators;
- the App's package name and version;
- performance metrics such as latency, and API configuration such as image format and resolution;
- event types such as feature initialisation, model download, detection and resource release;
- a per-installation identifier, which Google states is not intended to identify you or your device uniquely;
- for translation, the source and destination languages configured; for handwriting, the language configured.
Google states this is used for diagnostics and usage analytics, is encrypted in transit, and is not transferred by ML Kit to third parties. It is Google's behaviour, not something the App requests, and the developer never receives any of it. The Google Play Billing library likewise communicates with Google Play and includes Google's own logging transport.
Because these SDKs transmit that information off your device, Google Play's rules require the App to declare it in the Play Store listing's Data safety section, and it is declared there.
If you would rather avoid ML Kit entirely, do not use photo text recognition, the handwriting canvas, or Show English. Everything else — reading, dictionary search, podcasts, transcripts, saved words and review — works without it.
One clarification, because a curious reader may notice it: the Google Play Billing library carries a Google location library as an internal dependency. The App requests no location permission of any kind, asks for no location, and receives none. You can confirm this on the App's Play listing permissions.
Optional: connecting WaniKani
The App can optionally connect to WaniKani, a third-party Japanese study service, so your WaniKani lessons and reviews appear alongside your saved words. This is off unless you set it up, and the App is fully usable without it.
- You generate a read/write Personal Access Token on wanikani.com and paste it into the App. It is stored in encrypted, hardware-backed storage on your device (Android Keystore).
- The token is sent only to
api.wanikani.com, over HTTPS. It is never sent to the developer. - The connection reads your WaniKani data and writes to your WaniKani account: when you answer a review in the App, the App submits that answer to WaniKani, which advances your WaniKani progress exactly as answering on their site would.
- What WaniKani does with those requests is governed by WaniKani's own privacy policy.
- You can disconnect at any time, which deletes the stored token.
Permissions, and what each one is for
This is the complete list in the App as shipped, including the permissions added by the libraries it uses. Only the microphone produces a prompt; the rest are granted at install with no prompt because Android classes them as non-sensitive.
| Permission | Why it is there |
|---|---|
MicrophoneRECORD_AUDIO |
Used only by shadowing practice, where you record yourself repeating a sentence to compare with the speaker. The App does not touch the microphone until you tap Record yourself; opening the practice screen does not activate it. Recordings stay in the App's private cache, are not uploaded, and are not sent to any speech-recognition service. Declining is fine — the rest of shadowing still works, and the App says so. |
InternetINTERNET |
Everything under "Where the App connects". |
Network stateACCESS_NETWORK_STATE |
So a failed page load can say "you're offline" instead of a generic error, and so downloads can wait for a suitable connection. |
Foreground service (media playback)FOREGROUND_SERVICE,
FOREGROUND_SERVICE_MEDIA_PLAYBACK |
So podcast audio keeps playing when the screen turns off, with the usual lock-screen and notification-shade controls. |
Show notificationsPOST_NOTIFICATIONS |
Asked for at the moment you press play or start a transcript, never at launch. It lets the App show the playback controls and a progress bar while an episode is transcribed. It is used for nothing else. |
Background workFOREGROUND_SERVICE_DATA_SYNC |
So a transcript keeps being built when you look away from the App. Nothing plays and nothing is sent; the work ends on its own when the episode is done. |
Keep awakeWAKE_LOCK |
Added by the media and background-work libraries so playback and a long download are not cut off mid-way by the device sleeping. |
Run at start-upRECEIVE_BOOT_COMPLETED |
Added by Android's background-work library (which arrives with Google's handwriting recognition) so unfinished work can resume after a restart. The App schedules no work at boot on its own. |
Billingcom.android.vending.BILLING |
Added by Google Play Billing so the App can offer a subscription through Google Play. |
An internal signature permissioncom.darren.tokureader.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION |
Added by an Android library. It lets only this App's own components talk to each other; no other app can use it, and it grants no access to anything of yours. |
The App does not request your camera, location, contacts, call logs, messages, calendar, or your photo library as a whole. When you pick a photo or a video, Android's own picker hands the App only the one file you chose.
Notifications
The App asks permission to show notifications so it can display playback controls and a progress bar while it transcribes an episode. It sends no other notifications.
Ratings and feedback
The App may, after you have finished a few review sessions or episodes, ask whether you would like to rate it. The rating card is Google Play's own — it is shown by the Play Store app, not by Toku Reader, and the App is never told whether it appeared or what you chose. The App only keeps a local count of finished sessions and the date it last asked, so that it does not ask again for months.
"Send feedback" and the crash-report bar open your mail app with a draft addressed to the developer. The draft carries the App version, your Android version and phone model, and nothing else; nothing is sent unless you press send in your mail app. The Community sheet contains ordinary web links to the developer's website and social channels; opening one is the same as typing the address into a browser, and is governed by that site's own policy.
Children
The App is a language-learning tool for a general audience. It is not directed to children, and it does not knowingly collect personal details from anyone of any age — it asks for none, because there is no account. The only thing it ever sends is a sentence a reader deliberately asks about with AI explanations switched on, and that feature is off until someone turns it on; if a child has been given the phone, leaving that switch off means nothing is sent at all. Note also that the App includes a web browser, so a young user could reach general web content through it; supervision is advised for children.
Data retention and deletion
On your phone. Almost everything the App knows about you is on your phone and nowhere else. Uninstalling the App, or using Android's Clear storage, removes it. Downloaded episodes, transcripts and speech models can also be cleared individually in Settings › Transcripts & Storage. Disconnecting WaniKani deletes the stored token.
On the developer's server. If you have used AI explanations, there is now something to delete: a scrambled per-installation number with a monthly count, and one line per request. No retention period has been set yet, so those are kept indefinitely today — and this page will be updated when a period is chosen. To have them removed, email tokureader@gmail.com; because the App cannot show you your number, deletion is done by the month or months you name. Stored answers are filed under the sentence rather than under you and carry nothing that points back to you. If you have never turned the feature on, the server holds nothing about you at all.
Data held by WaniKani, by podcast publishers, by Google, by the AI provider, or by websites you visited is governed by their own policies and their own deletion processes.
Your rights
Privacy laws including the GDPR (EU/EEA), the UK GDPR, the APPI (Japan) and the CCPA/CPRA (California) give you rights over personal data a company holds about you — access, correction, deletion, portability, and objection to processing. The developer holds no name, email or account for any Android user, because there is no account to hold. The only thing held is the AI-explanations material described above; write to the contact address below for access or deletion of it, saying roughly when you used the feature, and it will be actioned. If you believe anything else is held, use the same address and it will be investigated.
The App does not sell or rent personal information, does not use your data for advertising, and does not track you across apps or websites. Sending a sentence to the AI provider so it can be explained back to you is the only sharing that happens, it happens because you asked for it, and it is used for nothing else.
Changes to this policy
If the App ever begins collecting anything, or adds a network destination not listed above, this page will be updated before that version ships, the version number and date above will change, and the Play Store Data safety declaration will be updated to match.
That promise is being kept right now: version 2.2 was written for the AI explanations feature before the version containing it went to the Play Store, and the Data safety declaration was re-answered in the same breath.
Contact
Darren Nah
tokureader@gmail.com
This website (tokureader.com)
Last updated: September 11, 2026
This site exists to describe Toku Reader. It has no advertising and no tracking cookies. It loads no fonts, scripts, or media from anyone else’s server — everything you see is served from this domain.
Visitor Counts
The public pages of this site count page views, so the developer can see which pages people actually read. This is Vercel Web Analytics, run by the same company that hosts the site, and it is the least invasive kind: it sets no cookie and stores nothing in your browser. For each page view it records the time, the page address, the referring site if you arrived from one, a filtered version of any query string, and — worked out from the request — the country you are in, your browser and its version, your operating system, and your device type. It does not record your name, your email, or anything you type.
Your IP address is not stored. It is used only at the moment of the request, together with your browser’s user-agent string, to compute a one-way hash that distinguishes one visitor from another; that hash is discarded and regenerated every 24 hours. So a visit cannot be tied back to you, cannot be followed from one day to the next, and cannot be joined up with your activity on any other site or app. The script is served from this domain (/_vercel/insights/) and its measurements are sent there, not to a third-party tracker. A content blocker will stop it, and the site works exactly the same if it does. None of this runs on the developer-only pages described below.
What Is Stored in Your Browser
Two things, both of them your own choices and both kept only in your browser’s local storage on this device: whether you prefer the light or dark theme, and whether you have dismissed an announcement. A third mark lasts only for the browser tab: that you have seen the front page once, so it does not replay its opening. None of it is sent anywhere or identifies you, and clearing your browser data removes them.
Hosting and Server Logs
The site is hosted by Vercel Inc. (United States), which keeps the standard server logs any web host keeps: the IP address a request came from, the kind of browser it came from, which page was requested, and when. These exist to run the site and to protect it from abuse.
The Developer’s Own Pages
Two areas, /login and /admin, exist only for the developer. They are not part of what the site offers you. An email address entered on the sign-in page is sent to Supabase Inc. (United States) so that a one-time sign-in link can be emailed; signing in successfully sets one strictly necessary authentication cookie. No cookie is set on any public page of this site. If you entered an address there by mistake, email the address below and it will be deleted.
Legal Basis and Transfers (EU/UK)
Server logs, abuse protection, and the visitor counts described above rest on legitimate interest — knowing which pages are read, without identifying who read them. Because the counting stores nothing on your device and sets no cookie, it does not require a consent banner. The sign-in step rests on performance of the service you requested by asking to sign in. Vercel and Supabase both process this data in the United States under their standard data-processing agreements, which include the EU standard contractual clauses.
Contact
The data controller for this website is Darren Nah, an individual developer in New York, NY, USA.