AtoC.ai

Data Safety

Draft — Last updated: August 2, 2026

Priority of Documents

In case of any discrepancy between this document and its translations, the English version shall prevail. This page is intended for Google Play Data Safety and Apple App Privacy disclosures.

1. Data Collected (Current)

  • Email address — for account registration and communication.
  • Display name and username — for profile and leaderboard.
  • Profile photo — user-uploaded avatar.
  • Birth month and year — for age validation (not full date of birth).
  • Certificate name — the name you provide for issuing completion certificates. Collection is strictly voluntary; you may skip it and certificates will be issued without a personalised name. Stored encrypted (AES-256 at rest), never shared with third parties, used solely to render the name on your certificate.
  • Learning progress — vocabulary progress, grammar completion, XP, streaks, training history, achievements.
  • Device information — device type, OS version, push tokens, hashed IP address.
  • Subscription status — plan type and transaction identifiers (processed by Apple, Google, RevenueCat).
  • TTS audio — synthesised audio generated by Google Cloud TTS or Amazon Polly, stored in Cloudflare R2. This is not user voice.
  • Analytics data — Firebase Analytics, Crashlytics, AppsFlyer, Amplitude, and Mixpanel collect usage events, device info, and crash logs. These SDKs are active only after user consent (EU/EEA requires explicit consent; other regions may be enabled by default with opt-out option).
  • Advertising data — AdMob advertising ID, only after explicit consent (EU/EEA). Disabled by default for Russian users.

2. Data Not Collected

  • Full date of birth — only month and year are collected.
  • Payment card data — processed by Apple, Google, or RevenueCat; we do not store card numbers.
  • Biometric data — no facial recognition, fingerprint, or voice biometric identification.
  • Health data — not collected.
  • Location data — not collected. IP address is hashed and used only for security.

3. Data Encryption

  • In transit: TLS 1.3
  • At rest: AES-256
  • Backups: Encrypted, geographically redundant

4. Data Used for Tracking

For the purposes of Google Play and Apple App Store disclosures, the following data may be used for tracking across third-party apps and websites:

  • Advertising ID — used by Google AdMob for ad personalization (only after consent; disabled by default for Russian users).
  • Device ID / device info — used by AppsFlyer for install attribution; by Firebase Analytics, Amplitude, and Mixpanel for analytics (only after consent).

Third-party analytics SDKs are active only after user consent (EU/EEA requires explicit consent; other regions may be enabled by default with opt-out option). Crashlytics and AppsFlyer attribution are always active for error monitoring and install attribution.

5. Third-Party SDKs (Current)

SDK / Provider Data Collected Purpose Consent
NetcupAll service dataHosting (Germany)Contract
SelectelPersonal data of Russian users152-FZ localizationLegal obligation
CloudflareHTTP metadata, cached files, audio/avatarsCDN, Workers, R2Legitimate interest
Google Cloud TTS / Amazon PollyText stringsText-to-speechContract
Firebase Cloud MessagingPush token, device typePush notificationsContract
Google AdMobAdvertising ID, device infoAdvertisingConsent
SentryCrash logs, device infoError monitoringLegitimate interest
RevenueCatTransaction IDs, subscription statusSubscriptionsContract
Firebase AnalyticsUsage events, device infoProduct analyticsConsent
Firebase CrashlyticsCrash logs, device infoCrash reportingAlways active
AppsFlyerInstall referrer, advertising IDAttributionAlways active
AmplitudeUsage events, user propertiesProduct analyticsConsent
MixpanelUsage events, user propertiesProduct analyticsConsent

6. Third-Party SDKs (Planned — Not Yet Active)

SDK / Provider Data Collected Purpose Status
Cloudflare D1 / KVCached learning dataEdge database / key-value storePlanned

None of these planned SDKs are included in the current app version. They will be added only with appropriate consent and policy updates.

7. Regional Servers

Primary infrastructure is in Germany (Netcup) and Russia (Selectel for Russian users). We are planning regional servers in the Middle East, India, and Asia where data-localization laws require it. Personal data remains in primary databases; edge locations process only cached training content and HTTP metadata.

8. Data Deletion

Users can request account deletion in the app settings. Account data is deleted within 30 days. Learning data is retained for 90 days for analytical purposes, then permanently erased. Payment records are retained for 7 years for tax compliance.

AI-Generated Content

The app contains educational content generated by artificial intelligence (grammar exercises, grammar rules, word details for system words). AI-generated content is labeled with an "AI" badge. Content may contain errors; use the in-app report button to flag mistakes. No personal data is shared with third-party AI providers for content generation; generation happens on our backend. User interactions with AI-generated content are used solely for learning progress and content quality improvement.

9. Contact

For data safety questions, please use the in-app support channel or contact contact support.