Effective date: 2026-04-13
Last updated: 2026-09-12
Noku is operated by Arman Aralbayev in Almaty, Kazakhstan ("we", "us"). Contact: t3ch1ee@gmail.com.
Noku stores your library and learning activity on your device. Online features can send information off the device even if you have not signed in with Google or Apple. Noku uses an anonymous Firebase identity for authenticated service requests, quotas, and abuse prevention. Anonymous authentication is different from named account sign-in.
Staying signed out does not make online features local-only. To avoid sending content for AI processing, leave Settings → Privacy → Share with AI disabled. Opening an external URL or requesting an online import still involves the relevant online service.
Your app-private storage can contain imported text, PDFs, EPUBs and other supported files; source URLs and metadata; highlights and bookmarks; notes and tutor conversations; interview recordings, transcripts and feedback; quizzes, flashcards and review history; and generated summaries, content categories and search embeddings.
Noku records reading position, reading sessions, section time, reading interactions and study results to support resuming, review scheduling and personalized recommendations. Some interactions or their effects, such as returning to a section, can help identify material to revisit. Reading time and exposure are not proof of understanding. Mastery and recommendation values are estimates derived from available activity and assessments, not measurements of intelligence or guarantees of learning outcomes.
Reading-action rows keep non-text metadata for lifetime counts. The selected excerpt and stored AI response in those rows are redacted after 90 days on app startup; a data export also enforces this redaction before it is generated. Other local records persist until removed through the app or its local storage is cleared. Device backups, exported files and copies you share have their own retention. Uninstalling Noku does not delete existing server records, provider records or exported copies.
With AI sharing enabled, relevant feature inputs travel through Noku's proxy to the provider used for that feature. This can occur without a named account or Premium sync.
| Feature | Service | Information processed |
|---|---|---|
| Summaries, quizzes, answer evaluation, categorization and other text assistance | Anthropic or OpenAI, depending on the configured model | Relevant source text, instructions, answers and context selected for the feature |
| AI tutor | Anthropic or OpenAI | Your message, relevant prior turns and source context |
| Interview questions and feedback | Anthropic or OpenAI | Relevant source text, questions, answers and assessment context |
| Voice transcription | OpenAI | Recorded audio sent for transcription |
| Voice playback | OpenAI | Text to synthesize as speech |
| Semantic search embeddings | OpenAI | Content chunks or search text requiring embeddings |
Tutor history is excluded from library sync, but relevant conversation turns are sent when you use the online tutor. Interview audio is excluded from library sync, but it leaves the device when you request transcription.
Revoking AI sharing stops new consent-controlled AI work. It does not recall requests already received by a provider or delete earlier results and provider records. Retention is described in Section 5. Noku does not use your learning content to train its own models. Provider training and retention controls are distinct; see their policies and Section 4.
| Source | Service contacted | Information involved |
|---|---|---|
| Web pages and feeds | The requested website/feed host, directly or through Noku's import service | Requested URL and ordinary network request metadata |
| Web-page extraction with AI sharing enabled | Jina AI Reader | Source URL and the page content fetched for extraction |
| YouTube | TranscriptAPI and Google's YouTube Data API through Noku's proxy | Video ID and requested transcript language; transcript and video metadata are returned |
| Podcasts requiring transcription | AssemblyAI through Noku's proxy | Audio URL and the audio fetched from it; resulting transcript and episode metadata |
| Connected import services, such as Readwise | The service you connect | Authorization information and content requested from that service |
YouTube and podcast provider imports require current in-app permission. Without that permission, article imports use direct source extraction instead of Jina AI Reader.
A source may record the requests made to it under its own policy. A URL can itself reveal what you are reading or listening to; do not import private links you are not authorized to share with the services needed to process them.
Podcast job state, episode metadata and completed transcripts can be stored temporarily in Noku's processing service so the app can retrieve a completed import later. That processing storage is separate from Premium library sync and from AssemblyAI's records.
Library sync requires a named signed-in account and an active Premium entitlement. It copies supported records to our service so another device can restore them:
Tutor conversation history, recorded interview audio, device-local paths and local search embeddings are excluded from library sync. Their use by an online feature is a separate flow described above. Learning data is linked to your account when synchronized.
The current attachment transport uses private Cloudflare R2 storage, including large extracted-text objects. The service also contains cleanup support for earlier Supabase attachment storage. Supabase/PostgreSQL and PowerSync provide the structured sync data and synchronization service. Cloudflare Workers handles API requests and processing; Cloudflare storage also holds temporary podcast jobs and related operational state.
Sync stops when the required entitlement is no longer active. Existing server data is not automatically deleted solely because a subscription lapses. We do not promise that all processing or storage occurs exclusively in the European Union; see Section 4.
If you submit a report, we receive the generated excerpt, reason, optional comment and source category shown in its preview, together with your Firebase UID and request ID. The report does not automatically include the source file, raw prompt or full conversation. It enters a private developer review queue. A submission acknowledgment means it was queued, not that a person has already reviewed or acted on it.
Firebase Authentication processes account identifiers and sign-in information. Noku does not receive your Google or Apple password. Anonymous identities can also be used for service authorization and quota enforcement.
Firebase Analytics and Crashlytics process installation identifiers, device/app version, locale, usage events, performance information and crash diagnostics. Firebase Analytics derives approximate location from IP addresses. We aim to avoid including source content in diagnostics; diagnostics should not be treated as anonymous merely because they omit your name. See Firebase privacy information.
RevenueCat processes subscription identifiers, entitlement status and associated app-user identifiers. Apple or Google processes the store purchase. Noku does not receive your payment-card details. See RevenueCat's privacy policy and your store's privacy information.
We use this information to provide the features you request, resume learning between sessions/devices, personalize learning and review, operate subscriptions, investigate reports and failures, and protect the service from abuse. We do not sell your learning content or use it for third-party advertising.
Use the AI-sharing control to manage AI processing, disconnect optional source services when no longer needed, and use account export/deletion controls or contact us to exercise your data rights. AI consent is not consent to every unrelated data use. Depending on your location, processing may rely on your consent, performance of the service contract, legitimate interests in security/reliability, or legal obligations. Mandatory local rules can impose additional requirements; an in-app toggle alone does not establish compliance with every jurisdiction's transfer or localization rules.
Noku's operator is in Kazakhstan. Our service providers operate internationally, including in the United States and Europe, and may use subprocessors in other countries. A provider's headquarters, a database region or a storage location hint does not establish where every copy, support operation or subprocessor processes information.
OpenAI and Anthropic API processing is subject to their commercial data-use terms and account controls. Do not assume these terms describe AssemblyAI or other providers. Following the September 12, 2026 service update, new podcast jobs use AssemblyAI's EU endpoint, which AssemblyAI excludes from model training. Earlier jobs can remain associated with its US endpoint and earlier account terms; this change does not retroactively remove provider records. AssemblyAI's model-training controls are separate from production retention. Where applicable, international transfers require appropriate safeguards and agreements; contact us for information about the safeguards applicable to your request.
Settings → Account → Delete account starts deletion of the named account's active Noku service data, private attachments and sign-in identity, together with local cleanup. Failures can require retrying. This is not a guarantee that all provider logs, backups, exports or copies on offline devices disappear instantly.
An offline device can retain its local copy until it runs Noku online and receives a confirmed account-deletion signal. Timing depends on connectivity, authentication and background execution; there is no guaranteed minutes-long deadline. A device that never reconnects can retain its copy. Protect lost devices using the operating system's device management and erase controls where available.
For data associated with anonymous use, provider processing, reports, exports or other questions not resolved by an in-app control, contact us. Provide enough information to identify the request; do not email private source files unless needed and agreed.
App-private files and the database use operating-system access controls. This version does not add a separate application-level database encryption layer. Keep a device screen lock enabled. Online service traffic uses HTTPS/TLS; certificate pinning is not a universal guarantee covering every provider or SDK connection. Synced data and private objects use account-scoped authorization. No security measure can guarantee protection in every case.
Noku is intended for people aged 13 or older. The current app does not independently verify a user's age, so a store age rating or account-provider eligibility rule must not be described as age assurance. Noku is not intended to collect information from children under 13. Contact us if you believe a child's information has been collected. Availability and consent requirements may differ by region.
Depending on applicable law, you may request access, correction, deletion, portability, restriction or objection to processing and withdraw consent. Use Export my data or Delete account where available, or contact t3ch1ee@gmail.com. You may also have a right to complain to your local data protection authority. California residents can request information about collection and deletion and applicable sale/sharing opt-outs; Noku does not sell learning content or share it for cross-context advertising.
We will update this policy when practices change and provide any notice or renewed consent required by applicable law. The date above identifies this revision.
Contact: t3ch1ee@gmail.com, or Settings → Help & Support.