Privacy
What Viky keeps about you, where it goes, and for how long. This describes the current test version and is updated before anyone outside the team uses Viky.
What Viky never receives
- The name you give your account: it stays in your device's passkey manager (iCloud Keychain, Google Password Manager, 1Password) as a label. Viky has no copy.
- Your Duolingo password: you sign in to Duolingo inside Reclaim's verification page, never on Viky.
- Your card number or identity documents: card purchases and sales happen on Mercuryo, which runs its own identity checks under its own privacy policy.
What Viky keeps, and where
- Your account's public identifier. Created on your device from your passkey. Kept in our database with each gift you fund or receive, and visible on the Monad network, a public ledger.
- If you fund a gift: the gift terms (amount, goal, daily target, duration) and the recipient's email or phone number as a one-way fingerprint only. The fingerprint is what the database and the public program hold; the plain email or number is never stored.
- If you receive a gift: your Duolingo username, profile id and display name (as read at each attested reading, including the short code you add to it once), kept in the database with each reading; a keyed pseudonym of that profile id, which is what the public program sees; your total XP as read, and the attested proof of the reading (produced with Reclaim), kept as the record of each day.
- Every visit: a session cookie (__Host-viky-session, 12 hours, signed, holds your account identifier) and a request counter keyed by the IP of your connection, held in memory for a few minutes to slow down abuse. No analytics scripts, no advertising, no tracking cookies.
- On your device: the technical id of your passkey, so the next sign-in can use it directly.
Who processes it
- Vercel hosts the application (Paris region) and keeps standard request logs.
- Neon hosts the database (Frankfurt, Germany).
- Reclaim Protocol runs the verification of your Duolingo progress; its attestation service sees your Duolingo session in the way its protocol describes, and Viky receives only the proof.
- Duolingo answers a public profile lookup for the username you enter.
- Mercuryo handles card purchases and sales, with its own account and identity checks.
- Kuru provides the exchange used to convert between currencies; it sees your account identifier and the amount.
- The Monad network is public and permanent: account identifiers, gift terms, the contact fingerprint, the identity pseudonym, every check-in and every amount moved can be read by anyone and cannot be erased.
How long
- A verification session that is never completed is deleted after 24 hours.
- Completed verifications and gift records are kept as long as the gift exists and afterwards as its record, until you ask for their deletion.
- The session cookie expires after 12 hours; request counters after a few minutes.
- What is on the public ledger stays there.
Your rights
You can ask what Viky holds about you, have it corrected, or have the database records deleted (the public ledger cannot be changed). Write to the contact given on the legal notice.