Priority of Documents
In case of any discrepancy between this document and its translations, the English version shall prevail. This page is intended for Google Play Data Safety and Apple App Privacy disclosures.
1. Data Collected (Current)
- Email address — for account registration and communication.
- Display name and username — for profile and leaderboard.
- Profile photo — user-uploaded avatar.
- Birth month and year — for age validation (not full date of birth).
- Learning progress — vocabulary progress, grammar completion, XP, streaks, training history, achievements.
- Device information — device type, OS version, push tokens, hashed IP address.
- Subscription status — plan type and transaction identifiers (processed by Apple, Google, RevenueCat).
- TTS audio — synthesised audio generated by Google Cloud TTS or Amazon Polly, stored in Cloudflare R2. This is not user voice.
- Analytics data — Firebase Analytics, Crashlytics, AppsFlyer, Amplitude, and Mixpanel collect usage events, device info, and crash logs. These SDKs are active only after user consent (EU/EEA requires explicit consent; other regions may be enabled by default with opt-out option).
- Advertising data — AdMob advertising ID, only after explicit consent (EU/EEA). Disabled by default for Russian users.
2. Data Collected (Planned — Not Yet Active)
- Voice recordings — for pronunciation check only; deleted after feedback is generated. Not used for biometric identification.
- AI tutor dialogue history — for conversational language practice.
- User-generated vocabulary/grammar prompts — for custom content creation.
3. Data Not Collected
- Full date of birth — only month and year are collected.
- Payment card data — processed by Apple, Google, or RevenueCat; we do not store card numbers.
- Biometric data — no facial recognition, fingerprint, or voice biometric identification.
- Health data — not collected.
- Location data — not collected. IP address is hashed and used only for security.
4. Data Encryption
- In transit: TLS 1.3
- At rest: AES-256
- Backups: Encrypted, geographically redundant
5. Data Used for Tracking
For the purposes of Google Play and Apple App Store disclosures, the following data may be used for tracking across third-party apps and websites:
- Advertising ID — used by Google AdMob for ad personalization (only after consent; disabled by default for Russian users).
- Device ID / device info — used by AppsFlyer for install attribution; by Firebase Analytics, Amplitude, and Mixpanel for analytics (only after consent).
Third-party analytics SDKs are active only after user consent (EU/EEA requires explicit consent; other regions may be enabled by default with opt-out option). Crashlytics and AppsFlyer attribution are always active for error monitoring and install attribution.
6. Third-Party SDKs (Current)
| SDK / Provider | Data Collected | Purpose | Consent |
|---|---|---|---|
| Netcup | All service data | Hosting (Germany) | Contract |
| Selectel | Personal data of Russian users | 152-FZ localization | Legal obligation |
| Cloudflare | HTTP metadata, cached files, audio/avatars | CDN, Workers, R2 | Legitimate interest |
| Google Cloud TTS / Amazon Polly | Text strings | Text-to-speech | Contract |
| Firebase Cloud Messaging | Push token, device type | Push notifications | Contract |
| Google AdMob | Advertising ID, device info | Advertising | Consent |
| Sentry | Crash logs, device info | Error monitoring | Legitimate interest |
| RevenueCat | Transaction IDs, subscription status | Subscriptions | Contract |
| Firebase Analytics | Usage events, device info | Product analytics | Consent |
| Firebase Crashlytics | Crash logs, device info | Crash reporting | Always active |
| AppsFlyer | Install referrer, advertising ID | Attribution | Always active |
| Amplitude | Usage events, user properties | Product analytics | Consent |
| Mixpanel | Usage events, user properties | Product analytics | Consent |
7. Third-Party SDKs (Planned — Not Yet Active)
| SDK / Provider | Data Collected | Purpose | Status |
|---|---|---|---|
| Cloudflare D1 / KV | Cached learning data | Edge database / key-value store | Planned |
| AI providers (OpenAI, Google, etc.) | Prompts, dialogue transcripts, audio | AI tutor, content generation | Planned |
| Speech recognition providers | Voice recordings | Pronunciation feedback | Planned |
None of these planned SDKs are included in the current app version. They will be added only with appropriate consent and policy updates.
8. Regional Servers
Primary infrastructure is in Germany (Netcup) and Russia (Selectel for Russian users). We are planning regional servers in the Middle East, India, and Asia where data-localization laws require it. Personal data remains in primary databases; edge locations process only cached training content and HTTP metadata.
9. Data Deletion
Users can request account deletion in the app settings. Account data is deleted within 30 days. Learning data is retained for 90 days for analytical purposes, then permanently erased. Payment records are retained for 7 years for tax compliance. Voice recordings, when the feature is active, are deleted immediately after pronunciation feedback is generated.
10. Contact
For data safety questions, please use the in-app support channel or contact contact support.