Back to Mitsuki

Privacy Policy — Mitsuki

Effective date: 2026/07/23

Products covered

This policy covers both Mitsuki products: the Mitsuki app (iOS/macOS) and the Mitsuki browser extension (Chrome, Edge, Brave). They share one account and one Mitsuki Cloud backend. Where their data handling differs, this is called out under each section below — anything not marked "extension only" or "app only" applies to both. A short note on the mitsukiapp.me website itself is included at the end of section 2.

Products
Mitsuki app (iOS/macOS) · Mitsuki browser extension
Developer / data controller
BAOUAB Youssef
Contact
ybaouab2@gmail.com

1) Summary

2) Information Mitsuki processes

A. Account information

B. Content you create

C. Clipboard data (app only, optional feature)

If you enable Clipboard Prefill, Mitsuki reads the current clipboard while the app is active to prefill a lookup when it appears to contain Japanese text. It is off by default, processed on-device, and never uploaded unless you choose to save a card that includes it.

D. Purchases

Mitsuki Pro can be purchased in two places. In the app, payment is handled entirely by Apple; we never receive your payment details. In the extension, payment is handled by Stripe on Stripe-hosted checkout and billing pages; your card details go to Stripe, never to us. In both cases we record your subscription status against your account (and, for Stripe, a customer reference used to open your billing portal).

E. Page detection data (extension only)

To show you which show and episode you're on, the extension reads the current tab's page title, URL, and page-authored metadata (e.g. the schema.org/OpenGraph tags sites publish), plus — on sites you've set up or that have built-in support, such as Netflix — a small number of on-page text elements like the visible show title. Its content script is present on pages you visit (that's what lets detection work without broad host permissions), but it only records an entry when the page matches a site you've set up, a built-in or remembered site, or actually has a video playing. Entries go into a local "watch log" in your browser's extension storage — they are not sent to Mitsuki Cloud and we never see your browsing. Two optional flows use watch-log data: fetching show artwork sends the show title (not the URL) to our TMDB proxy (see section 4), and saving a word puts that page's details on the card (see F).

F. Cards captured from a page (extension only)

When you save a word while watching, the resulting card includes the subtitle line, the page URL and page title, the show/episode title, and — when media capture is on — a snapshot of the current video frame and a short audio clip of that line sliced from the video. All of it is stored locally and, if you're signed in, uploaded to Mitsuki Cloud as your card and its media attachments, exactly like cards created in the app. Subtitle files you load (uploaded or found via subtitle search) are cached locally so dual subtitles keep working without re-fetching them.

G. Diagnostics and presence (app only)

H. Website (mitsukiapp.me)

3) How your data is used

We do not use your data for advertising profiling or cross-app tracking.

4) AI processing & sub-processors

On-device AI (app)

Lighter AI tools use Apple's on-device models. The text you submit is processed locally and is not sent off your device.

Cloud AI (app)

For full study-session generation, custom-deck generation, and as a fallback on devices without on-device AI, the text you submit is sent to Mitsuki's AI service (a Supabase Edge Function operated by the developer), which forwards it to OpenAI to generate the result. OpenAI processes the request to return a response. We store only a per-day count of requests for quota enforcement — not the content of your prompts.

Optional AI in the extension (off unless you configure it)

The extension's subtitle-analysis feature (and an AI-assisted subtitle-filename parser) only work if you paste your own Google AI Studio (Gemini) API key into the extension's settings. When you use them, the subtitle text or filename — plus the show title and your configured study preferences — is sent directly from your browser to Google using your key. Nothing passes through Mitsuki's servers, and we never see your key: it is stored only in your browser's extension storage. If you don't add a key, the extension makes no AI requests at all.

Sub-processors (services we operate through)

Extension-only third-party services (each contacted only when you use that feature)

If you configure a self-hosted service under Settings — a personal Lingarr or Subliminal server, or your own subtitle-catalog server — the extension talks directly to the address you entered. With a personal catalog server configured, subtitle files (with show/episode metadata) and a backup of your saved-word lists are uploaded to your server. That's your own infrastructure — we never see that traffic and it isn't covered by the list above.

5) Data sharing & transfers

6) Storage, security, and retention

On-device (app)

Preferences, deck profiles, search history, and cached data are stored locally. Remove them by deleting items in-app or uninstalling the app.

In your browser (extension only)

Settings, the watch log, the subtitle cache and library, saved words pending sync, your session tokens, and any API keys you added are stored in your browser's local extension storage (chrome.storage and IndexedDB) — sandboxed to the extension, not accessible to the sites you visit or to other extensions. Uninstalling the extension removes all of it. Signing out does not clear local data by itself; it only stops cloud sync.

In Mitsuki Cloud

Your account data is protected by per-user row-level access rules so only your account can read it. Card media (frames, audio) is stored in per-user storage areas and served to your devices via short-lived signed URLs. Crash reports are write-only for clients: no app or extension can read them back. Data persists until you delete it in-app or request account deletion.

Retention

7) Your choices and controls

8) Children's privacy

Mitsuki is not directed to children under 13, and we do not knowingly collect personal information from children.

9) Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in the app or legal requirements. We will update the Effective date above and, where appropriate, note material changes in-app or in release notes.

10) Contact

For any privacy questions or requests, contact: ybaouab2@gmail.com