Skip to main content

Privacy Policy

Last Updated: September 2, 2026

1. Introduction

Welcome to Phayan, a service of Zava Solutions LLC, a Wyoming limited liability company (“we,” “our,” or “us”), the controller of the personal data described here. We are committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Thai alphabet learning service (the “Service”).

By using Phayan, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Service.

2. Information We Collect

2.1 Personal Information You Provide

When you register for and use our Service, we collect:

  • Account Information: Email address, password (hashed), and display name
  • Profile Information: Optional avatar/profile picture, and the optional free-text fields on your profile (your bio and your hometown). These are yours to write and yours to leave empty; whatever you type is stored as you typed it, and is included in your data export.
  • Waitlist Email: If you join the Premium waitlist, we store the email address you provide to notify you when Premium launches
  • Feedback: If you submit feedback or bug reports through the Service, we collect the content you provide along with the page URL and your browser user agent
  • Sign-in Credentials: If you sign in with Google or Apple, we store the account identifier that provider gives us and the email address it releases. If you create a passkey, we store its public key, a credential identifier, a signature counter, and the name you give the device. Never a private key, and never your fingerprint or face, which stay on your device.
  • Your Settings: Interface language, theme, text size, the learning options you set, and your email preferences.
  • Push Notification Tokens: If you allow notifications in the iOS or Android app, we store the token the operating system issues for that installation, so we can send the reminder.

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, time spent on the Service
  • Device Information: Browser type, operating system, device identifiers
  • Cookies and Similar Technologies: Authentication tokens, preferences, GDPR region detection, and analytics data
  • IP Address: For security, fraud prevention, and GDPR region detection
  • Analytics Data: We use PostHog (product analytics) and, when configured, Google Analytics (GA4) and Google Ads conversion tracking, to collect usage statistics and measure advertising effectiveness: page views, in-app events, and identifiers associated with your browser. If you are signed in, PostHog also receives your user identifier, your email address, your plan and billing interval, and your sign-up date, so that a usage trail belongs to one account rather than one browser. Google Analytics and Google Ads are not currently configured, so neither one loads, whatever your cookie choice. If we turn them on, the tags will load for everyone, but they will store nothing and identify no one until you allow analytics cookies; until then, Google only receives a cookieless signal it uses to model traffic in aggregate. PostHog measures the visit from the start, but until you allow analytics cookies it stores nothing on your device, so what we see is that a visit happened and not who it was or that you had been here before. If you decline, or your browser sends a Global Privacy Control signal, PostHog stops there too.
  • Session Replay: When you have allowed analytics cookies, PostHog records a reconstruction of your session so we can see where the interface confuses people. Every text node and every input is masked before the recording leaves your browser, and images, video, and canvases are blocked entirely, so the replay shows shapes and clicks, not what you typed or what your profile picture looks like.
  • Advertising Data: We use Meta (Facebook) Pixel to measure advertising effectiveness, when configured. The pixel is not currently configured, so it does not load in your browser today, whatever your cookie choice or region. If we turn it on, it will load only after you allow analytics cookies (or, outside the EEA, UK, and Switzerland, unless you opt out), the same rule as PostHog. Separately, when configured, our servers send Meta a conversion event on sign-up and on purchase: a hashed version of your email address and account ID, never the address itself, plus your IP address, your browser's user agent, and any Meta click identifiers (_fbp, _fbc) your browser had already sent us. That server-side call runs independently of the cookie banner and of your analytics choice, and independently of whether the browser pixel is configured, so it can still credit a conversion when the pixel in your browser was blocked, declined, or not configured.
  • Campaign Parameters: If you arrive from an advertisement or a shared link, the campaign tags in the address (utm_source, utm_medium, utm_campaign, utm_term, utm_content) are recorded with your sign-up so we know which campaigns work.

2.3 Learning Progress Data

When you use the lessons, we collect and store:

  • Progress: Which levels and rounds you have completed, and which letters and words you have learned
  • Answers: Your drill and typing answers, including tone identification results, used to compute your tone accuracy
  • Spaced-Repetition State: The review schedule for each letter and word you are learning, including mastery status
  • Sync Metadata: A version marker on your progress tree so your devices can merge cleanly

This data is what makes the Service work: the due queue, the tone statistics, and your level unlocks all come from it. It is tied to your account and is included in your data export.

2.4 Error Monitoring Data

We use Sentry to find out when the Service breaks. Two things report to it: the app running on your device, and our own servers. They send different amounts about you.

From your browser or the app, a report carries:

  • Error messages and stack traces
  • Browser type, operating system, and device information
  • The page URL where the error occurred
  • If you are signed in, your user identifier (the account number, not your name). Your email address, your display name and your IP address are not attached. The identifier still tells us whether one person hit one bug ten times or ten people hit it once, which is the only reason to send anything about you at all
  • A replay of the seconds leading up to the error, with all text masked and all media blocked

From our servers, a report carries the error and the request that caused it, and a request always arrives with an IP address attached. That is how the internet delivers it. If you were signed in, the report also carries your user identifier, your email address, and which plan you are on. We are not going to claim a server-side report is anonymous when it is not.

Sentry runs whatever you choose about cookies. We treat knowing that the Service is broken as necessary to providing it. It is not analytics and it is not advertising, so error reporting is not behind the cookie banner. Putting it there would silence reports from exactly the people who declined, which would leave their bugs unfixed. The trade we made instead is the one above: the code on your device sends no identity. If you would rather it did not run for you at all, write to us at the address in section 15.

3. How We Use Your Information

We use the information we collect to:

  • Provide the Service: Create and manage your account, store your learning progress, and run the review queue
  • Process Payments: Handle subscription payments through Stripe on this website, and recognise the subscriptions Apple and Google sell inside the app
  • Send Emails: Two kinds. Messages you cannot switch off while you have an account, because they are the account working: your welcome message, password resets, withdrawal and refund confirmations, failed-payment notices, and warnings before we act on your account. And messages about Phayan itself: notes that bring you back when you have stopped practising, a recap of what you have learned, a thirty-day milestone, and announcements of what is new. We send the second kind only if you asked us to. You can ask, or stop, in Settings Email preferences at any time, and every message of that kind carries an unsubscribe link. We never send you another company's advertising, and we never give your email address to an advertiser.
  • Measure Our Own Emails: Our email provider tells us whether a message was delivered, opened, clicked, bounced, or reported as spam. We use this to stop mailing addresses that bounce and people who complain, and to see whether a message was worth sending.
  • Improve the Service: Analyze usage patterns, fix bugs, and develop new features
  • Security: Prevent fraud, abuse, and unauthorized access using reCAPTCHA, rate limiting, and CSRF protection
  • Analytics: Understand how our Service is used via PostHog and, when configured, Google Analytics, and measure advertising effectiveness via Meta Pixel
  • Error Monitoring: Identify and fix bugs and performance issues using Sentry
  • Legal Compliance: Comply with applicable laws and regulations

4. Information Sharing and Disclosure

4.1 Service Providers

We share information with trusted third-party service providers who assist us in operating our Service:

Payment Processing

  • Stripe: Processes all payments securely. We do not store your credit card details. (Subject to Stripe's Privacy Policy)

In-App Purchases (iOS & Android)

  • RevenueCat: Manages in-app subscriptions purchased through the Apple App Store or Google Play. Receives a pseudonymous app user ID and purchase receipt details to validate and restore your subscription. The underlying payment is handled by Apple or Google, not by Phayan. (Subject to RevenueCat's Privacy Policy)

Analytics & Advertising

  • PostHog: Product analytics that help us understand how the Service is used and improve it. Processed in the United States. (Subject to PostHog's Privacy Policy)
  • Google Analytics (GA4): Collects usage data to help us improve the Service, when configured — the tracking ID is not currently set, so this is presently inactive. (Subject to Google's Privacy Policy)
  • Google Ads: Measures advertising effectiveness and conversion tracking, when configured — the tracking ID is not currently set, so this is presently inactive. (Subject to Google's Privacy Policy)
  • Meta (Facebook) Pixel: Measures advertising effectiveness, when configured — the pixel is not currently configured, so it does not load in your browser. Separately, we also send Meta a hashed, server-side conversion event, when configured, on sign-up and purchase that runs regardless of consent choice or whether the browser pixel is configured — see section 2.2 above for detail. (Subject to Meta's Privacy Policy)

Security & Monitoring

  • Google reCAPTCHA: Protects against spam and abuse during registration, login, and password reset. (Subject to Google's Privacy Policy and Terms of Service)
  • Sentry: Monitors errors and performance. May collect error details, browser information, and anonymized session replays. (Subject to Sentry's Privacy Policy)

Authentication

Email Services

  • Resend: Delivers every email we send you, of both kinds described in section 3, and reports back whether each one was delivered, opened, clicked, bounced, or reported as spam. (Subject to Resend's Privacy Policy)

Infrastructure & Hosting

  • Cloudflare R2: Stores the two files you can upload: your profile picture, and any screenshot you attach to a feedback or support message. (Subject to Cloudflare's Privacy Policy)
  • MongoDB: The managed database that holds your account and your learning progress. (Subject to MongoDB's Privacy Policy)
  • Railway: Hosts our web application and API server. (Subject to Railway's Privacy Policy)

Lesson Audio

  • Google Cloud Text-to-Speech: Produces the spoken Thai you hear when a recording for a word has not been made yet. Our server sends Google the Thai word to be spoken and keeps the result, so the same word is never sent twice. Google is not told who asked: the request comes from our server, carries no account identifier, and does not carry your IP address. (Subject to Google's Privacy Policy)

4.2 Legal Requirements

We may disclose your information if required by law or in response to:

  • Valid legal processes (subpoenas, court orders)
  • Requests from law enforcement or government authorities
  • Protection of our rights, property, or safety
  • Prevention of fraud or security threats

4.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change.

5. We Do Not Sell Your Information

We do not sell, rent, or trade your personal information to third parties for marketing purposes. The providers listed in section 4.1 are the only third parties that receive your data, they receive only what their job needs, and they may use it only to do that job for us.

We do not use your learning progress or account data for advertising or for training AI models. Your answers, your review queue, and your account stay yours.

6. Data Security

We implement industry-standard security measures to protect your information:

  • Encryption of data in transit (HTTPS/TLS)
  • Password hashing using bcrypt
  • Secure httpOnly authentication cookies
  • CSRF protection on all state-changing requests
  • Rate limiting to prevent abuse
  • Content Security Policy (CSP), HSTS, and other security headers to protect against common web attacks

However, no method of transmission over the Internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

7. Your Rights and Choices

7.1 Access and Correction

You can access and update your account information at any time through your account settings, including your display name, avatar, and password.

7.2 Data Deletion

You can delete your account at any time through your account settings. It happens straight away and it cannot be undone.

What is deleted: your account, your learning progress and review queue, your answers and the statistics computed from them, the rounds generated for you, your passkeys, your notification tokens, your feedback submissions, your profile picture, and any waitlist entry under your address.

What survives, and why. We are telling you this rather than rounding it to “everything is deleted”, because it is not:

  • Records of emails we sent you stay, with your address replaced by the word “erased”. What is left is that a message of some kind was sent on some date, not to whom.
  • Website analytics events stay, with the link to your account cut, so they count as anonymous visits.
  • If you unsubscribed or reported one of our emails as spam, we keep your address on a do-not-mail list. That record is the instruction never to mail you again; deleting it would undo it.
  • If you ever paid us, the record of that payment stays, because a business must be able to account for money it received and to handle a refund or a chargeback afterwards. We keep it for as long as tax and accounting law requires us to keep records of a sale.

7.3 Data Portability

The Export my data button in your account settings hands you a copy of your data on the spot: your account details, your settings and email preferences, and your learning progress, as machine-readable JSON. Your browser downloads it as phayan-export.json while you wait. There is no queue and no email to watch for.

If you would rather we sent it to you, or the download will not run on your device, write to support@phayan.com from the address on the account and we will send you the same file.

7.4 Cookies

You can manage your cookie preferences through our cookie consent banner or the Cookie Preferences page. You can also control cookies through your browser settings. Note that disabling essential cookies may affect the functionality of the Service. See our Cookie Policy for more details.

If your browser or an extension sends a Global Privacy Control signal, we honour it: analytics and advertising stay off for that browser without your having to touch the banner, and the banner does not ask again. You can also set the same thing by hand on Your Privacy Choices.

8. Learning Data & Audio

Your learning data (completed rounds, drill answers, tone statistics, and the spaced-repetition queue) is stored on your account and synced between your devices when you sign in. It is never published, never shared with other learners, and never used to personalize content beyond your own review schedule.

The audio you hear in the app (letter and word recordings) is served from our content library, which combines openly licensed recordings with speech we generate. When you are the first person to reach a word we have not generated yet, our server asks Google Cloud Text-to-Speech for it and keeps the result; see section 4.1. Playing audio does not transmit anything about you beyond which file you asked for.

Your progress works offline in the browser and merges when you reconnect; the merge is per-round and keeps the highest completion state on each item.

9. International Data Transfers

Phayan is operated from the United States by the company named in section 15, so if you are outside the United States your data is transferred there. Our application runs on Railway, our database is MongoDB on a managed host, and uploaded files are on Cloudflare R2. The providers listed in section 4.1, among them Stripe, RevenueCat, PostHog, Google, Meta, Sentry, and Resend, are United States companies and process what they receive there.

If you are in the European Economic Area, the United Kingdom, or Switzerland, that is a transfer to a country your law does not treat as automatically adequate. You are entitled to know which safeguard applies to each recipient: an adequacy decision, Standard Contractual Clauses, or your explicit consent. Write to us at the address in section 15 and we will tell you, for any recipient you name.

10. Children's Privacy

Phayan is written for adults and older teenagers, and a Phayan account requires that you be old enough, where you live, to agree to the processing of your own personal data. In the European Economic Area that is 16 unless your country has set a lower age, which is never below 13, and elsewhere we require 13. The Terms say the same thing in section 2.

We do not ask your age and we do not verify it. Nothing stops a younger child from typing an email address into the sign-up form, and we would not know. What we can do is act when we are told: if you are a parent or guardian and your child has an account they were not old enough to open, write to us and we will delete the account and everything in it, as described in section 7.2, without asking you to prove anything beyond that the account is your child's. Write to support@phayan.com.

11. Region-Specific Rights

11.1 GDPR (European Economic Area, UK, Switzerland)

If you are located in the EEA, UK, or Switzerland, you have additional rights under GDPR:

  • Right to access your personal data
  • Right to rectification of inaccurate data
  • Right to erasure (“right to be forgotten”)
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent at any time
  • Right to lodge a complaint with a supervisory authority

What we rely on to process each thing:

  • Performing our contract with you: your account, your learning progress and review queue, your settings, your subscription and the emails the account itself sends you. Without these there is no Service to give you.
  • Your consent: the analytics cookie, session replay, advertising measurement, and marketing email. Marketing email goes only to people who asked for it, and we record when you asked. Withdraw at any time: on the Cookie Preferences page for the first three, and with the unsubscribe link or the switch in Settings Email preferences for the email. Withdrawing is as easy as giving it.
  • Our legitimate interests: keeping the Service working and finding out when it breaks (Sentry, section 2.4), counting how the Service is used while nothing is stored on your device, stopping spam and abuse (reCAPTCHA, rate limiting), and defending ourselves in a dispute. You can object to any of these; write to us and say which.
  • A legal obligation: keeping records of a sale for tax and accounting purposes, and answering a lawful order.

Complaining. If you think we have handled your data wrongly, tell us first; we would rather fix it. You do not have to: you can complain directly to the data protection authority of the country you live or work in, or where you think the problem happened, and its decision does not depend on ours.

For more information about your GDPR rights, see our GDPR Compliance page.

11.2 CCPA/CPRA (California)

If you are a California resident, you have rights under the California Consumer Privacy Act:

  • Right to know what personal information is collected
  • Right to know if personal information is sold or shared
  • Right to opt-out of the sale of personal information (we do not sell your information)
  • Right to deletion of personal information
  • Right to non-discrimination for exercising your rights

Opt-out preference signals. We honour Global Privacy Control. If your browser or an extension sends it, analytics and advertising stay off for that browser and we do not ask you again. We do not act on the older Do Not Track header, which browsers send inconsistently and which its own authors abandoned; use Global Privacy Control, or the button on Your Privacy Choices.

12. Data Retention

Your account, your progress, and your review queue stay for as long as you keep the account. Deleting it does what section 7.2 describes, immediately. Some things expire on their own before that:

  • Individual drill answers are deleted 90 days after they have been counted. The statistics computed from them stay, because they are your progress.
  • Notification tokens are deleted 180 days after the device last used the app.
  • Progress saved before you had an account is deleted 30 days after that browser last touched it, if it never became an account.
  • Password reset links, sign-in challenges, and upload permissions are deleted as soon as they expire: minutes to an hour, depending on the kind.

We keep everything else only while it is doing its job: giving you the Service, meeting a legal obligation, or defending a dispute that has actually arisen.

13. Third-Party Links

Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by:

  • Posting the new Privacy Policy on this page
  • Updating the “Last Updated” date

Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.

15. Contact Us

The company below decides why and how your data is processed. In the language of the GDPR, it is the controller. Write to it about anything in this policy, including any of the rights in section 11.

Company:

Zava Solutions LLC

A Wyoming limited liability company

30 N Gould St Ste N
Sheridan, WY 82801
United States

Email:

support@phayan.com