mkoma — Privacy Policy
The short version
- Your documents stay on your phone. mkoma reads, searches, edits and converts them locally. Nothing is uploaded unless you tap one of the three AI features, and then only the text you asked it to work on.
- You can use mkoma without an account. An account (an email address) only adds syncing your starred files and settings between devices.
- mkoma has no advertising and no analytics. It asks Android for four permissions: internet, network state, the camera (used only for QR and barcode scanning), and Google Play billing (needed only to offer a subscription; see "Permissions" below). If — and only if — you switch on "Help fix crashes" (off by default), it sends a short technical report when the app crashes; see below.
Permissions
- Internet — to talk to our server for sign-in, sync, the AI features and (if you opt in) crash reports. Nothing is sent without you using one of those features.
- Network state — to notice when you are offline (added by a library mkoma uses).
- Google Play billing — added by the billing library mkoma uses so that a signed-in person can buy a subscription from inside the app. Android grants it without a prompt. It does not give mkoma access to anything on your phone; until a subscription is on offer in the version you have, it is not used.
- Camera — used only by QR and barcode scanning, to read a code you point the phone at; the picture is not saved or sent. Document scanning uses Google's ML Kit Document Scanner, which runs in Google Play services and manages its own camera access. mkoma works without a camera; the permission is only asked for when you open QR scanning.
mkoma does not ask for access to your storage, contacts, location, microphone or notifications. Files you open are handed to it by the system file picker or by another app; it does not scan your phone for documents.
What stays on your device
Your library (the PDFs you open or create), the text extracted from them for search, text recognised by on-device OCR, and everything the local tools (merge, extract pages, rotate, reorder, compress, watermark, Images → PDF) produce. Read aloud uses your phone's own text-to-speech engine. None of this is sent to us.
What is sent to our server, and when
| When | What is sent | Why | Kept |
|---|---|---|---|
| First launch that needs the server | Platform (android), app version | Registers an anonymous device so you get a usage allowance | Until you delete your data or the device is purged |
| You tap Ask, Write or Translate | The prompt you typed and the document text being worked on (for Translate, the page or pages you chose) | To generate the answer. The server forwards it to an AI model provider (see below) | We do not store the prompt or document text. We store only that a run happened: task type, model name, token counts, and cost |
| You sign in | Your email address; a one-time code is emailed to you | Account and cross-device sync | Email is kept while your account exists; the code is stored only as a salted hash and expires in 10 minutes |
| You are signed in | Which files you starred (a content fingerprint and the file name), and your app settings (theme, keep-screen-awake, the "Made with mkoma" line) | Sync between your devices | Until you unstar/change them or delete your account |
| You open Notices | Which notices you have read or dismissed | So a dismissed notice stays dismissed | Until you delete your data |
We do not receive your files or their contents (except the text you send in the AI tasks above), nor your contacts, your location, your other photos, or a list of the apps on your device.
AI providers
When you use Ask, Write or Translate, the text is processed by an AI model provider we contract — currently Anthropic (Claude) and, as a fallback, Groq. Their handling of that text is governed by their own terms and privacy policies: Anthropic's privacy policy and Groq's privacy policy. Do not use these features on a document you are not willing to have processed by them.
On-device OCR
Text recognition uses Google ML Kit on your device. The recognition model may be downloaded to your phone by Google Play services; the images you scan are recognised on the device and are not sent to us.
Scanning
The camera scanner is Google's ML Kit Document Scanner, provided by Google Play services. It runs on your device and hands mkoma the finished PDF; the pages you scan are not sent to us. Google Play services may download the scanner component to your phone the first time you use it.
QR and barcode scanning
Scanning uses your camera and Google's ML Kit barcode model on your device; the camera image and what a code contains are not sent to us. The list of codes you have scanned is kept only on your phone, and you can delete entries or clear it in the app. Opening a link from a scan hands it to your browser or another app; that app's own privacy terms then apply.
Crash reports (optional, off by default)
Settings → Privacy → Help fix crashes. While it is off, mkoma sends nothing about crashes. If you turn it on, an uncaught error sends one report to our server containing: the app version, the platform (Android), the name of the error and the first line of its message, and a list of code locations (function and source-file names inside the app) where it happened. Before sending, mkoma removes file names, file paths, web addresses, email addresses, long identifiers and anything in quotes from that text, and it sends each distinct crash at most once per session and at most five per session. It never sends a document, its name, or anything you typed. The report is tied to your device or account id only so the server can limit a broken phone to 20 a day; the operator's admin view does not show that id. Reports are deleted after 90 days, are included in your data export, and are erased when you delete your account. See what is sent, and send a test report in the same place shows the exact text of a report before anything is sent. The choice is stored on this phone only and does not sync to your other devices.
Your choices and rights
- Use it without an account. Everything except cross-device sync and the daily AI allowance tied to an account works with no sign-in.
- Delete your account and data. Signed in, open Me → Delete account. This erases your sync data and notice state, clears your email and account, and anonymises (does not retain content in) usage records, per the server's deletion routine. Files on your phone stay on your phone.
- Export your data. Signed in, open Me → Export my data for a copy of what mkoma holds about your account.
- If you are in the EU/UK you have rights of access, rectification, erasure, restriction, portability and objection, and to complain to your data protection authority. Contact mkomamethod@gmail.com.
Security
Traffic to our server must use HTTPS in production. Access tokens are short-lived; one-time codes are hashed; the recipient of an email is validated so it cannot be used to inject extra recipients. No system is perfectly secure, and we cannot promise it.
Children
mkoma is not directed to children under 13.
Changes
We will update this page and its date when our practices change, and tell you in-app (Notices) about material changes.