Privacy Policy

Last Updated: July 31, 2026

1. Introduction

JamKham (จำคำ) ("we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Thai language learning platform.

This policy is designed to comply with the EU and UK General Data Protection Regulation (GDPR), Thailand's Personal Data Protection Act B.E. 2562 (2019) (PDPA), and other applicable data protection laws.

Important Notice

We do NOT sell your personal data to third parties. Your learning data and personal information are used solely to provide and improve our language learning service.

Beta Program Notice

JamKham is currently in beta. During the beta period, we collect additional data to help improve the Service:

  • Detailed usage analytics to understand user behavior and learning patterns
  • Feedback submissions including context about where and when you encountered issues
  • Error reports and technical diagnostics to identify and fix bugs
  • Pseudonymized session recordings may be used for user experience research, including on our public demo and sign-up pages before you have an account

This enhanced data collection helps us build a better product. We disable this analytics and session recording for visitors we detect as located in the EEA or the UK (see Section 2.1). For other users it is not a condition of accepting our Terms of Use. Once you have an account you can opt out at any time in your settings; before you sign up, we honor the Global Privacy Control and Do Not Track signals your browser sends. See the Product Analytics & Session Recording section for details. All beta-specific data practices will be reviewed and updated when we transition to general availability.

2. Data Controller

The data controller responsible for your personal data is:

Twin Palms Advisors Co., Ltd. (operating JamKham / จำคำ)

Registered office: 52/9 หมู่ที่ 2 ต.วิชิต อ.เมืองภูเก็ต จ.ภูเก็ต 83000, Thailand

Privacy contact: privacy@jamkham.com

Twin Palms Advisors Co., Ltd. is established in Thailand and is the controller for your account and learning data. Paddle (our merchant of record for sales outside Thailand) acts as an independent controller for payment and transaction data, as described in Section 6.1. Where you purchase directly from Twin Palms within Thailand (paying in Thai baht), Twin Palms is also the controller for your payment and billing data for that purchase. Tembusu Ventures LLC (a Delaware limited liability company, USA) acts as our data processor — processing personal data on our behalf and under our instructions to provide hosting, support, and marketing services, and to administer sales outside Thailand as described in Section 6.1. If you have questions about how we handle your data, please contact us using the information in Section 15.

2.1 EEA and UK Users

The Service is operated from Thailand and is intended for users outside the European Economic Area (EEA) and the United Kingdom. We do not target or market the Service to residents of the EEA or the UK, and our users represent that they are located outside, and will not use the Service from within, those regions (see our Terms of Use). We disable session recording, behavioural product analytics, and any use of your data for our own product and model development — whether collected in your browser or on our servers — for users we detect (by IP address) as located in those regions. For such users we process personal data only as necessary to provide the Service they have requested and to meet our legal obligations. On that basis, we do not target or actively offer the Service to, and do not monitor the behaviour of, individuals in the EEA or the UK, and we have not appointed representatives under Article 27 of the EU or UK GDPR.

Whether data-protection law applies depends on where you are actually located, not on this statement alone. If it turns out that the EU or UK GDPR applies to our processing of your personal data, the rights and protections described in this policy still apply to you, and we will appoint EU and UK representatives and update this section. IP-based location detection is not perfect; if you are in the EEA or the UK and believe we hold your personal data, please contact privacy@jamkham.com.

2.2 Thai PDPA

As a company established in Thailand, Twin Palms Advisors Co., Ltd. also processes personal data in accordance with Thailand's Personal Data Protection Act B.E. 2562 (2019) (PDPA). The lawful bases, data-subject rights, and contact routes described in this policy apply under the PDPA as well as the GDPR; where a right exists under one framework but not the other, we will honor the higher standard. PDPA-related requests can be sent to privacy@jamkham.com.

3. Information We Collect

3.1 Account Information

When you create an account, we collect:

  • Email address (used for login and communications)
  • Password (stored in encrypted form) - if using email/password registration
  • Display name or username (optional)
  • Profile preferences and settings

3.1.1 Social Login (LINE and other providers)

If you register or log in using a social authentication provider, we collect information from that provider:

  • LINE Login: Display name, profile picture URL, email address (if provided by LINE), and unique LINE user identifier
  • Google (if enabled): Email address, name, profile picture URL, and unique Google identifier

We use this information to create your account, authenticate your identity, and personalize your experience. We do NOT receive or store your social provider password.

3.2 Learning Data

To provide our language learning service, we collect:

  • PDF documents you upload for vocabulary extraction
  • Flashcard review history and performance scores
  • Learning progress, statistics, and achievements
  • Study session data (time spent, cards reviewed, accuracy)
  • Vocabulary items and custom notes you create
  • Learning preferences (training modes, difficulty settings)

3.3 Payment Information

When you subscribe to a paid plan:

  • For purchases outside Thailand, payment and billing information is collected and controlled by Paddle, our merchant of record, as an independent data controller; for direct purchases within Thailand, Twin Palms is the controller for that data (see Section 6.1)
  • We store only limited payment metadata (subscription tier, billing cycle, transaction IDs)
  • We do NOT collect or store your full credit card numbers or banking details

3.4 Technical Data

We automatically collect certain technical information:

  • IP address and device information
  • Browser type and version
  • Operating system
  • Referring website URLs
  • Pages visited and time spent on pages
  • Error logs and diagnostic data

3.5 Communications

If you contact us for support:

  • Email correspondence and support tickets
  • Feedback and survey responses

4. How We Use Your Information

We use your personal data for the following purposes:

4.1 Service Provision

  • Create and manage your account
  • Process PDF uploads and extract vocabulary using AI/LLM
  • Provide flashcard training and spaced repetition scheduling
  • Generate audio pronunciations for Thai vocabulary
  • Track your learning progress and provide analytics
  • Sync your data across devices

4.2 Service Improvement and Model Development

  • Analyze aggregated usage patterns to improve features
  • Identify and fix technical issues
  • Develop new learning modes and features
  • Optimize AI/LLM vocabulary extraction accuracy
  • Develop, train, fine-tune, and improve our own models, algorithms, and learning systems

We may use short text excerpts derived from the content you provide (for example, individual extracted vocabulary items and brief example phrases), together with the outputs generated for you and aggregated data about how the Service is used, to operate, analyze, and improve our products and to develop, train, fine-tune, and improve our own models, algorithms, and learning systems. We do not train our models on your raw uploaded documents. Where this information identifies you, we use it for these purposes in de-identified or aggregated form. This is separate from the third-party AI providers described in Section 6.2, who do not use your content to train their models. We do not use the data of users we detect as located in the EEA or the UK for this model-development and product-improvement activity (see Section 2.1). For other users, this activity is not a condition of using the Service, and you may opt out or object at any time by contacting privacy@jamkham.com. We do not use special-category data of identifiable individuals for model training without a separate lawful basis.

4.3 Communications

  • Send account verification and password reset emails
  • Provide customer support
  • Send important service updates and security notifications
  • Send optional learning reminders (if you opt in)
  • Notify you of subscription status and billing

4.4 Payment Processing

  • Process purchases and subscription payments through Paddle, our merchant of record
  • Manage subscription status, billing cycles, and access entitlements
  • Coordinate with Paddle on refunds and payment disputes

4.5 Security and Fraud Prevention

  • Detect and prevent fraudulent account creation
  • Monitor for suspicious login attempts
  • Enforce rate limits and prevent abuse
  • Use CAPTCHA (Cloudflare Turnstile) to prevent bots

6. Data Sharing and Third Parties

We Do NOT Sell Your Data

JamKham does not sell, rent, or trade your personal data to third parties for marketing purposes.

We share your data only with trusted third-party service providers necessary to operate our Service:

6.1 Payment Processing (Paddle, Merchant of Record)

For sales outside Thailand, purchases are made through Paddle, our merchant of record (Paddle.com Inc. for buyers in the US, Paddle.com (Canada) Ltd. for buyers in Canada, and Paddle.com Market Ltd. for buyers elsewhere). Paddle collects and processes your payment and billing data as an independent data controller — it is not our processor, and it decides how it uses buyer data for payment, tax, fraud prevention, and legal compliance. Paddle may use its own downstream processors for these purposes.

  • Data Paddle collects: name, email, billing address, payment method details, and transaction data
  • Data we receive back from Paddle: subscription tier, billing cycle, transaction IDs, and country/tax region — not your full card or banking details
  • Paddle privacy policy: paddle.com/legal/privacy
  • Paddle GDPR information: paddle.com/legal/gdpr

For sales outside Thailand, our reseller chain runs from Paddle to Tembusu Ventures LLC (a Delaware limited liability company, USA) to Twin Palms Advisors Co., Ltd.: Paddle faces you as merchant of record, Tembusu acts as Paddle's authorised reseller and contracts with Twin Palms, and Twin Palms licenses the Read Thai course to you. In this chain Tembusu processes the transaction and billing data it receives from Paddle (such as your country/tax region, transaction IDs, and subscription details) on our behalf and under our instructions to administer these sales; it does not receive your full payment card or banking details.

If you purchase directly from Twin Palms within Thailand (paying in Thai baht), Twin Palms collects and processes your payment and billing data as the controller for that purchase, and neither Paddle nor Tembusu is involved.

6.2 AI/LLM Vocabulary Extraction

  • OpenAI: Processes PDF text to extract Thai vocabulary
  • Anthropic (Claude): Alternative AI provider for vocabulary extraction
  • Data shared: Text content from uploaded PDFs
  • Note: We do NOT share personally identifiable account information with LLM providers
  • No training by providers: We use these providers under their business/API terms, which do not permit them to use your content to train or improve their models. (This is separate from our own use of inputs and outputs to improve our products and models, described in Section 4.2.)
  • Privacy policies: OpenAI Privacy, Anthropic Privacy

6.3 Audio Generation

  • Google Cloud Text-to-Speech: Generates Thai audio pronunciations
  • Data shared: Thai vocabulary words and phrases
  • Privacy policy: https://cloud.google.com/privacy

6.4 Email Delivery

6.5 Security and Bot Protection

6.6 Social Authentication Providers

If you choose to register or log in using a social authentication provider:

  • LINE Corporation: Provides social login authentication via LINE Login
  • Data shared: We receive your LINE display name, profile picture URL, email address (if you grant permission), and a unique identifier
  • Note: We do NOT receive or have access to your LINE password, contacts, or chat messages
  • Privacy policy: https://line.me/en/terms/policy/

6.7 Hosting, Infrastructure and Operational Support

  • Cloud hosting providers (e.g., Railway, AWS) for data storage and service delivery
  • These providers have access to data only as necessary to maintain infrastructure
  • Tembusu Ventures LLC (a Delaware limited liability company, USA): provides hosting support, technical and customer support, and marketing services for the Service as our data processor, acting on our behalf and under our instructions
  • Data shared with Tembusu: account, usage, and contact data as needed to provide these support and marketing services

6.8 Error Monitoring and Performance

  • Sentry: Monitors application errors and performance to improve service reliability
  • Data shared: Error logs, browser/device information, page URLs, IP addresses (pseudonymized)
  • Note: We configure Sentry to minimize personal data collection and scrub sensitive information
  • Privacy policy: https://sentry.io/privacy/
  • Sentry is GDPR compliant and offers EU data residency

6.9 Product Analytics and Session Recording

  • PostHog: Product analytics and pseudonymized session recording, to understand usage and improve the Service. Both run inside the authenticated app and on our public demo and sign-up pages, for visitors we detect as outside the EEA and the UK. On the public pages the recording is tied to an anonymous identifier rather than to you; if you then create an account, that pre-signup recording is linked to the account, so the demo and sign-up steps you took are visible to us alongside your later activity.
  • Data shared: Pseudonymized user identifier, pages and features used, learning-session events, device/browser information, and session recordings. What you type into form fields — including your email address and password — is masked and never captured, everywhere we record. Inside the signed-in app the on-screen text is masked as well, so a recording shows the layout and what you clicked but not the words on the page. On the public demo and sign-up pages the on-screen text is recorded, so that we can see which step or error message stopped a visitor; where those pages display an email address back to you, that address is masked.
  • We disable this processing for users we detect as located in the EEA or the UK (see Section 2.1); for other users, see the "Product Analytics & Session Recording" section below
  • Privacy policy: https://posthog.com/privacy

6.10 Legal Disclosures

We may disclose your data if required by law, court order, or government regulation, or if necessary to:

  • Comply with legal obligations
  • Protect our rights, property, or safety
  • Prevent fraud or illegal activities
  • Enforce our Terms of Use

7. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence, including the United States and other jurisdictions where our service providers operate.

Your account and learning data are processed by Twin Palms Advisors Co., Ltd. in Thailand. Thailand does not currently benefit from a European Commission adequacy decision, so transfers of personal data from the EEA and the UK to Thailand are made under appropriate safeguards.

For transfers from the EEA and the UK to countries without an adequacy decision (including Thailand), we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, together with the UK International Data Transfer Addendum for UK transfers
  • Data Processing Agreements with GDPR-compliant service providers
  • The EU–US Data Privacy Framework (and its UK and Swiss extensions) where a US provider is certified under it
  • Supplementary technical and organizational measures where needed to protect the transferred data

You may request a copy of the relevant transfer safeguards by contacting privacy@jamkham.com.

8. Data Retention

We retain your personal data only as long as necessary to provide the Service and fulfill the purposes described in this policy:

  • Active accounts: Data is retained while your account is active
  • Deleted accounts: Most data is deleted within 30 days of account deletion
  • Backup retention: Backup copies may be retained for up to 90 days for disaster recovery
  • Legal obligations: Some data (e.g., payment records) may be retained longer to comply with tax and legal requirements (typically 7 years)
  • Aggregated data: Anonymous, aggregated statistics may be retained indefinitely for research and improvement

9. Your Rights (GDPR Articles 15-22)

Under GDPR and other data protection laws, you have the following rights:

9.1 Right of Access (Art. 15)

You can request a copy of the personal data we hold about you.

9.2 Right to Rectification (Art. 16)

You can request correction of inaccurate or incomplete data. You can update most information directly in your account settings.

9.3 Right to Erasure / "Right to be Forgotten" (Art. 17)

You can request deletion of your personal data. You can delete your account directly through account settings, or contact us for assistance.

9.4 Right to Data Portability (Art. 20)

You can request a copy of your data in a machine-readable format to transfer to another service.

9.5 Right to Object (Art. 21)

You can object to processing based on legitimate interests — including our use of your data for product and model development described in Section 4.2 — or to processing for direct marketing purposes. To object, contact us at privacy@jamkham.com.

9.6 Right to Restrict Processing (Art. 18)

You can request limitation of processing in certain circumstances (e.g., while we verify data accuracy).

9.7 Right to Withdraw Consent

Where processing is based on consent, you can withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.

9.8 Right to Lodge a Complaint

You can file a complaint with your local data protection authority if you believe we have violated your privacy rights.

How to Exercise Your Rights

To exercise any of these rights, please contact us at privacy@jamkham.com

We will respond to your request within 30 days as required by GDPR.

10. Cookies and Tracking

We use cookies and similar tracking technologies to provide and improve our Service:

Essential Cookies

  • Session cookies: Keep you logged in during your session
  • CSRF protection: Prevent cross-site request forgery attacks
  • Security cookies: Detect fraudulent login attempts

These cookies are necessary for the Service to function and cannot be disabled.

Analytics and Performance

We use PostHog for product analytics and session recording, and Sentry for error monitoring, both inside the authenticated app and on our public demo and sign-up pages. We do not run product analytics or session recording for visitors we detect as located in the EEA or the UK (see Section 2.1). See the "Product Analytics & Session Recording" section below for full details.

Third-Party Cookies

  • Cloudflare Turnstile: May set cookies for CAPTCHA verification
  • Paddle: May set cookies during checkout and payment processing
  • LINE Login: May set cookies during the OAuth authentication flow when you choose to log in with LINE
  • Google Sign-In (if enabled): May set cookies during the OAuth authentication flow

Product Analytics & Session Recording

To improve the app and understand where learners get stuck, we use PostHog and Sentry to record how the app is used — after you sign in, and, for visitors we detect as outside the EEA and the UK, on our public demo and sign-up pages before an account exists. This includes pages visited, features used, learning-session outcomes, and error reports. We also capture pseudonymized session recordings of that activity. What you type into form fields, including your email address and password, is masked and is never recorded, on every page we record. Inside the signed-in app we also mask the on-screen text, so a recording shows the layout and your clicks but not the words on the page. On the public demo and sign-up pages we do record the on-screen text — that is how we see which step or error message stopped someone — except where those pages display an email address back to you, which stays masked. We do not record activity on our public marketing site.

We disable this analytics and session recording entirely for visitors we detect (by IP address) as located in the EEA or the UK (see Section 2.1), and on the public pages we also honor the Global Privacy Control and Do Not Track signals your browser sends. A recording made before you signed up is linked to your account if you go on to create one. For other users, you can opt out at any time through your settings or by contacting privacy@jamkham.com. Internal staff accounts are excluded from product analytics.

11. Data Security

We implement industry-standard security measures to protect your data:

Technical Safeguards

  • Encryption: All data transmitted over HTTPS/TLS encryption
  • Password security: Passwords are hashed using bcrypt or similar algorithms
  • Database security: Access controls and encrypted connections
  • File storage: Uploaded PDFs stored with access controls

Operational Safeguards

  • Access controls: Limited employee access on a need-to-know basis
  • Login protection: Rate limiting, CAPTCHA, and account lockouts after failed attempts
  • Monitoring: Security event logging and intrusion detection
  • Regular updates: Security patches and vulnerability scanning

While we strive to protect your data, no method of transmission or storage is 100% secure. Please use a strong, unique password and enable any available security features.

12. Data Breach Notification

In the event of a security breach that affects your personal data, we are committed to transparency and timely notification as required by GDPR and other applicable laws.

12.1 Our Commitments

If we become aware of a data breach that poses a risk to your rights and freedoms, we will:

  • Notify affected users within 72 hours of becoming aware of the breach, as required by GDPR Article 33
  • Contact relevant data protection authorities within 72 hours where required by law
  • Provide clear information about the nature of the breach, the data affected, and the likely consequences
  • Recommend protective actions you can take to mitigate potential harm

12.2 Notification Contents

Our breach notification will include:

  • A description of the nature of the personal data breach
  • The categories and approximate number of individuals affected
  • The categories and approximate number of personal data records affected
  • The name and contact details of our data protection contact
  • A description of the likely consequences of the breach
  • A description of the measures taken or proposed to address the breach

12.3 How We Notify You

We will notify you through:

  • Direct email to your registered email address
  • A prominent notice within the Service upon login
  • Our website and social media channels (for widespread breaches)

Reporting a Security Issue

If you discover a potential security vulnerability in JamKham, please report it responsibly to security@jamkham.com. We appreciate your help in keeping our users safe.

13. Children's Privacy

Our Service is not intended for children under 13 years of age. We do not knowingly collect personal data from children under 13.

For users in the EEA or the UK, children under 16 require parental or guardian consent to use the Service. The Service is not directed to those regions (see Section 2.1).

If you believe we have inadvertently collected data from a child, please contact us immediately at privacy@jamkham.com and we will delete it promptly.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements.

We will notify you of material changes by:

  • Posting the updated policy on our website
  • Sending an email to your registered email address
  • Displaying a prominent notice within the Service

Material changes will take effect 30 days after notice. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

The "Last Updated" date at the top of this policy indicates when it was last revised.

15. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:

Data Protection Contact

Twin Palms Advisors Co., Ltd. (operating JamKham / จำคำ)

Registered office: 52/9 หมู่ที่ 2 ต.วิชิต อ.เมืองภูเก็ต จ.ภูเก็ต 83000, Thailand

Privacy Inquiries: privacy@jamkham.com

General Support: support@jamkham.com

EU/UK representatives: see Section 2.1

Website: https://jamkham.com

We will respond to your inquiry within 30 days as required by GDPR.

GDPR & PDPA Compliance

This Privacy Policy is designed to comply with the EU and UK General Data Protection Regulation (GDPR), Thailand's Personal Data Protection Act (PDPA), and other applicable data protection laws. If you have concerns about how we handle your data, you have the right to lodge a complaint with your local data protection authority (for Thailand, the Personal Data Protection Committee).