
Effective date: 23 July 2026
This summarises our privacy practices. For more information, see our full Privacy Policy below.
Madi doesn’t have user accounts, doesn’t run analytics or advertising inside the app, and doesn’t include any third-party tracking SDKs. Everything you write — essays, vocabulary, prompts, and settings — stays on your device and, if you’re signed into iCloud, syncs privately to your own iCloud account via Apple’s CloudKit. We never have access to it.
Language detection and AI writing features run entirely on-device using Apple’s own frameworks; translation may run on-device or via Apple’s own translation service, depending on your device and language pack.
We don’t operate a server for Madi at all — there’s nowhere for your writing to go except your own devices and your own iCloud account.
Read our full Privacy Policy below.
Questions? Contact me, or email me directly for any urgent privacy-related requests at privacy@myungjoon.com
Welcome to Madi’s Privacy Policy. Madi is a writing app for language learners; your writing is yours, so it stays on your device and in your own iCloud account, never on a server we control. This Policy explains what we collect (essentially nothing, since we don’t operate a backend), why, and what rights you have, while also covering the legal ground required under regulations like the GDPR (EU/UK), CCPA/CPRA (California), and PIPA (Korea). By using Madi or visiting myungjoon.com/madi, you’re agreeing to what’s laid out here. If anything in this Policy doesn’t sit right with you, please don’t hesitate to reach out.
A couple of terms come up often in this Policy, so let’s define them upfront:
Personal Data (sometimes called “PII”) is any information that could be used to identify you specifically. Data that’s been fully anonymised and can’t be traced back to you doesn’t count as such.
iCloud / CloudKit is Apple’s cloud storage and sync service. If you’re signed into iCloud, Madi uses Apple’s CloudKit framework to sync your writing across your own devices, through your own Apple ID account, governed by Apple’s own privacy policy rather than ours.
On-device processing means computation that happens entirely on your device’s hardware, without sending data to any server, ours or otherwise.
Service Providers are the outside tools we rely on to run Madi:
CloudKit, used only if you enable iCloud sync, to move your data between your own devices;
UserDefaults and SwiftData, Apple's frameworks to persist your data;
NaturalLanguage, FoundationModels, and Translation — Apple’s on-device system frameworks used to power language detection, AI writing tools, and translation, described further in Section 4; and
App Store, used to distribute the app to the public.
You or User means the natural person accessing or using Madi.
Madi is built and run by Myung Joon Kang, an independent student developer. We’re the one responsible for Madi and any data described in this Policy. There’s no company or team behind this, just us.
For anything you choose to sync via iCloud, Apple is separately responsible under its own privacy policy, available at apple.com/legal/privacy.
Using the app.
Madi doesn’t ask you to create an account, and we don’t operate a backend server that receives your data. Everything below stays on your device and, if enabled, in your own iCloud account:
Essays and vocabulary — the writing you produce, the words you flag in your Bridge Language, their translations, and your own paraphrase attempts;
Language and proficiency settings — your chosen Target Language, Bridge Language, and self-assessed difficulty level; and
App preferences — settings like whether sentence-starter suggestions (“Nudge”) are enabled and their trigger delay.
None of this is transmitted to us. It’s stored locally using Apple’s SwiftData and UserDefaults frameworks and, if iCloud is enabled on your device, synced across your own devices through your private iCloud account using Apple’s CloudKit service. That sync happens directly between your devices and Apple — we don’t have a copy and can’t access it.
Using the on-device features.
Language identification uses Apple’s on-device Natural Language framework and, if enabled, Foundation Models framework to detect which words in your writing belong to your Bridge Language. This runs entirely on your device.
Prompt generation and sentence-starter suggestions (“Nudge”) use Apple’s on-device Foundation Models framework, on supported devices with Apple Intelligence enabled, to generate the prompts and starters. This also runs on your device using Apple’s system model.
Translation uses Apple’s Translation framework to translate words you flag. This also runs on your device using downloaded languages.
Most, if not all, features are on-device. We do not have access to these.
Visiting the website.
If you visit myungjoon.com/madi, the site doesn’t collect anything that identifies you personally through general browsing. Aggregated, anonymised visit statistics may be collected the same way as described in Section 15 — this is separate from the app itself, which runs no analytics of any kind.
If you reach out to us.
If you email us directly, we’ll see whatever you choose to share (your name, email, and message) — and we’ll only use it to reply to you.
In practice, here’s how you stay in control:
iCloud sync is controlled by your device’s system settings, not by anything inside Madi. Turning off iCloud (or iCloud Drive/app sync) for Madi at the system level stops syncing; your data stays locally on that device.
Deleting your data — deleting an essay or vocabulary entry in the app removes it from your device and, on next sync, from iCloud. Deleting the app removes all locally stored data; if iCloud sync was enabled, a copy may remain in your iCloud account until it’s removed from all devices or from your iCloud storage settings directly.
AI features (Nudge, prompt generation, etc.) can be turned off at any time in Settings.
For readers in the EU or UK, here’s the legal basis under the GDPR for the very little data that reaches us at all (mainly correspondence and anonymised site analytics): our legitimate interest in keeping Madi running smoothly and responding to you (Article 6(1)(f)). Everything else — your essays, vocabulary, and settings — is processed entirely on your device and your own iCloud account under your own control, so it isn’t processing we do at all.
Whatever limited data does reach us — correspondence, or anonymised site analytics — we use it only to: keep Madi and its website running well, respond to your messages, and meet any legal obligations we’re subject to. We don’t use anything to build a profile of you or make automated decisions about you, and we have no access to your writing to use for anything in the first place.
7. The Tools We Rely On
The Service Providers listed in Section 2 support Madi’s core functionality — CloudKit for sync you control, and Apple’s on-device frameworks for language features that never leave your device. They’re not allowed to use your data for anything beyond that, and in most cases, they never receive it in a form that identifies you at all. We don’t sell, rent, or trade your data, and we never have. We’d only ever share information if the law required it, or if it were genuinely necessary to protect someone’s safety or rights.
8. How Long We Keep Things
Data you create in Madi (Section 4) stays on your device, and on iCloud if you’ve enabled sync, for as long as you keep it there — we don’t hold a copy, so retention is entirely in your hands. Site analytics, if any, are retained by our Service Provider in aggregated form consistent with their own retention practices. If you’ve emailed us, we’ll hang on to that conversation for as long as feels reasonable to keep good records.
9. Where Your Data Travels
We’re based between Korea and Canada. Because Madi doesn’t operate its own servers, the only data that travels anywhere is what you choose to sync via iCloud (governed entirely by Apple’s own infrastructure and policies) and any anonymised website analytics, which may be processed by our Service Provider in the US, the EU, or elsewhere under standard contractual clauses or equivalent safeguards.
10. Keeping Things Secure
We take reasonable steps to protect any data that does pass through our hands, such as correspondence. Data you store via iCloud is secured according to Apple’s own practices, which are outside our control.
11. Your Rights
If GDPR or UK GDPR applies to you, you have the right to ask for a copy of your data, correct it, have it deleted, restrict how it’s processed, object to processing based on legitimate interest, request it in a portable format, and complain to your local supervisory authority if you’re unhappy with how we’ve handled things. Because your writing lives only on your device and your own iCloud account, you can exercise nearly all of these rights yourself, instantly, just by editing or deleting things in the app or adjusting your iCloud settings. For anything else — like correspondence you’ve sent us — please contact us using the details in Section 18.
12. If You’re in California
If you’re a California resident, the CCPA/CPRA gives you the right to know what we collect and why, ask us to delete it, correct it if it’s wrong, opt out of any sale or sharing of it (which we don’t do), and not be treated differently for exercising these rights. Just contact us and we’ll take care of it.
13. Children’s Privacy
Madi isn’t directed at children under 13 (or the relevant age where you live), and we don’t knowingly collect personal data from kids. Since Madi doesn’t collect data on any server at all, no personal information from any user — child or adult — is transmitted to or stored by us. If we ever find out something’s slipped through by accident, we’ll delete it as soon as we can.
14. Tracking
We don’t track you across other apps or websites for advertising purposes, so we don’t ask for tracking permission through Apple’s App Tracking Transparency framework — there’s simply nothing to track. Madi includes no third-party tracking SDKs of any kind.
15. Cookies and Site Analytics
The Madi app itself runs no analytics whatsoever. The website, if you visit myungjoon.com/madi, may use cookies through our Service Providers solely to generate anonymised, aggregated analytics — referrer, pages visited, general country, OS, browser, and device type — none of which builds a personal profile of you. You can turn cookies off in your browser if you’d like, though some site features might not work as smoothly.
We’re based in Korea, so Korea’s Personal Information Protection Act (PIPA) applies to how we handle personal information, in addition to the GDPR and CCPA/CPRA protections described above. Under PIPA, you have the right to request access to, correction of, deletion of, and suspension of processing of your personal information, and to be told how any of it is used or shared. In practice, this covers the very limited data described in Section 4 — mainly aggregated site analytics and anything you’ve sent us directly by email, since your actual writing in Madi never reaches us at all. We don’t operate a separate Chief Privacy Officer function given the small scale of processing involved, but we are personally accountable for PIPA compliance and will handle any request under this section the same way we handle requests under Section 11. If you’d like to exercise a PIPA-specific right, just say so when you contact us and we’ll treat it accordingly.
As Madi grows and changes, this Policy might need updates too. Whenever that happens, we’ll update the Effective Date at the top so you can tell something’s changed.
18. Get in Touch
Questions? Contact me, or email me directly for any urgent privacy-related requests at privacy@myungjoon.com
