mkoma — Privacy Policy

Operator: Xplosion Studio, Dar es Salaam, Tanzania · Contact: mkomamethod@gmail.com
Last updated: 8 October 2026

The short version

Permissions

mkoma does not ask for access to your storage, contacts, location, microphone or notifications. Files you open are handed to it by the system file picker or by another app; it does not scan your phone for documents.

What stays on your device

Your library (the PDFs you open or create), the text extracted from them for search, text recognised by on-device OCR, and everything the local tools (merge, extract pages, rotate, reorder, compress, watermark, Images → PDF) produce. Read aloud uses your phone's own text-to-speech engine. None of this is sent to us.

What is sent to our server, and when

WhenWhat is sentWhyKept
First launch that needs the serverPlatform (android), app versionRegisters an anonymous device so you get a usage allowanceUntil you delete your data or the device is purged
You tap Ask, Write or TranslateThe prompt you typed and the document text being worked on (for Translate, the page or pages you chose)To generate the answer. The server forwards it to an AI model provider (see below)We do not store the prompt or document text. We store only that a run happened: task type, model name, token counts, and cost
You sign inYour email address; a one-time code is emailed to youAccount and cross-device syncEmail is kept while your account exists; the code is stored only as a salted hash and expires in 10 minutes
You are signed inWhich files you starred (a content fingerprint and the file name), and your app settings (theme, keep-screen-awake, the "Made with mkoma" line)Sync between your devicesUntil you unstar/change them or delete your account
You open NoticesWhich notices you have read or dismissedSo a dismissed notice stays dismissedUntil you delete your data

We do not receive your files or their contents (except the text you send in the AI tasks above), nor your contacts, your location, your other photos, or a list of the apps on your device.

AI providers

When you use Ask, Write or Translate, the text is processed by an AI model provider we contract — currently Anthropic (Claude) and, as a fallback, Groq. Their handling of that text is governed by their own terms and privacy policies: Anthropic's privacy policy and Groq's privacy policy. Do not use these features on a document you are not willing to have processed by them.

On-device OCR

Text recognition uses Google ML Kit on your device. The recognition model may be downloaded to your phone by Google Play services; the images you scan are recognised on the device and are not sent to us.

Scanning

The camera scanner is Google's ML Kit Document Scanner, provided by Google Play services. It runs on your device and hands mkoma the finished PDF; the pages you scan are not sent to us. Google Play services may download the scanner component to your phone the first time you use it.

QR and barcode scanning

Scanning uses your camera and Google's ML Kit barcode model on your device; the camera image and what a code contains are not sent to us. The list of codes you have scanned is kept only on your phone, and you can delete entries or clear it in the app. Opening a link from a scan hands it to your browser or another app; that app's own privacy terms then apply.

Crash reports (optional, off by default)

Settings → Privacy → Help fix crashes. While it is off, mkoma sends nothing about crashes. If you turn it on, an uncaught error sends one report to our server containing: the app version, the platform (Android), the name of the error and the first line of its message, and a list of code locations (function and source-file names inside the app) where it happened. Before sending, mkoma removes file names, file paths, web addresses, email addresses, long identifiers and anything in quotes from that text, and it sends each distinct crash at most once per session and at most five per session. It never sends a document, its name, or anything you typed. The report is tied to your device or account id only so the server can limit a broken phone to 20 a day; the operator's admin view does not show that id. Reports are deleted after 90 days, are included in your data export, and are erased when you delete your account. See what is sent, and send a test report in the same place shows the exact text of a report before anything is sent. The choice is stored on this phone only and does not sync to your other devices.

Your choices and rights

Security

Traffic to our server must use HTTPS in production. Access tokens are short-lived; one-time codes are hashed; the recipient of an email is validated so it cannot be used to inject extra recipients. No system is perfectly secure, and we cannot promise it.

Children

mkoma is not directed to children under 13.

Changes

We will update this page and its date when our practices change, and tell you in-app (Notices) about material changes.