Priority of Documents
In case of any discrepancy between this document and its translations, the English version shall prevail. This page is intended for Google Play Data Safety and Apple App Privacy disclosures.
1. Data Collected (Current)
- Email address — for account registration and communication.
- Display name and username — for profile and leaderboard.
- Profile photo — user-uploaded avatar.
- Birth month and year — for age validation (not full date of birth).
- Certificate name — the name you provide for issuing completion certificates. Collection is strictly voluntary; you may skip it and certificates will be issued without a personalised name. Stored encrypted (AES-256 at rest), never shared with third parties, used solely to render the name on your certificate.
- Learning progress — vocabulary progress, grammar completion, XP, streaks, training history, achievements.
- Device information — device type, OS version, push tokens, hashed IP address.
- Subscription status — plan type and transaction identifiers (processed by Apple, Google, RevenueCat).
- TTS audio — synthesised audio generated by Google Cloud TTS or Amazon Polly, stored in Cloudflare R2. This is not user voice.
- Analytics data — Firebase Analytics, Crashlytics, AppsFlyer, Amplitude, and Mixpanel collect usage events, device info, and crash logs. These SDKs are active only after user consent (EU/EEA requires explicit consent; other regions may be enabled by default with opt-out option).
- Advertising data — AdMob advertising ID, only after explicit consent (EU/EEA). Disabled by default for Russian users.
2. Data Not Collected
- Full date of birth — only month and year are collected.
- Payment card data — processed by Apple, Google, or RevenueCat; we do not store card numbers.
- Biometric data — no facial recognition, fingerprint, or voice biometric identification.
- Health data — not collected.
- Location data — not collected. IP address is hashed and used only for security.
3. Data Encryption
- In transit: TLS 1.3
- At rest: AES-256
- Backups: Encrypted, geographically redundant
4. Data Used for Tracking
For the purposes of Google Play and Apple App Store disclosures, the following data may be used for tracking across third-party apps and websites:
- Advertising ID — used by Google AdMob for ad personalization (only after consent; disabled by default for Russian users).
- Device ID / device info — used by AppsFlyer for install attribution; by Firebase Analytics, Amplitude, and Mixpanel for analytics (only after consent).
Third-party analytics SDKs are active only after user consent (EU/EEA requires explicit consent; other regions may be enabled by default with opt-out option). Crashlytics and AppsFlyer attribution are always active for error monitoring and install attribution.
5. Third-Party SDKs (Current)
| SDK / Provider | Data Collected | Purpose | Consent |
|---|---|---|---|
| Netcup | All service data | Hosting (Germany) | Contract |
| Selectel | Personal data of Russian users | 152-FZ localization | Legal obligation |
| Cloudflare | HTTP metadata, cached files, audio/avatars | CDN, Workers, R2 | Legitimate interest |
| Google Cloud TTS / Amazon Polly | Text strings | Text-to-speech | Contract |
| Firebase Cloud Messaging | Push token, device type | Push notifications | Contract |
| Google AdMob | Advertising ID, device info | Advertising | Consent |
| Sentry | Crash logs, device info | Error monitoring | Legitimate interest |
| RevenueCat | Transaction IDs, subscription status | Subscriptions | Contract |
| Firebase Analytics | Usage events, device info | Product analytics | Consent |
| Firebase Crashlytics | Crash logs, device info | Crash reporting | Always active |
| AppsFlyer | Install referrer, advertising ID | Attribution | Always active |
| Amplitude | Usage events, user properties | Product analytics | Consent |
| Mixpanel | Usage events, user properties | Product analytics | Consent |
6. Third-Party SDKs (Planned — Not Yet Active)
| SDK / Provider | Data Collected | Purpose | Status |
|---|---|---|---|
| Cloudflare D1 / KV | Cached learning data | Edge database / key-value store | Planned |
None of these planned SDKs are included in the current app version. They will be added only with appropriate consent and policy updates.
7. Regional Servers
Primary infrastructure is in Germany (Netcup) and Russia (Selectel for Russian users). We are planning regional servers in the Middle East, India, and Asia where data-localization laws require it. Personal data remains in primary databases; edge locations process only cached training content and HTTP metadata.
8. Data Deletion
Users can request account deletion in the app settings. Account data is deleted within 30 days. Learning data is retained for 90 days for analytical purposes, then permanently erased. Payment records are retained for 7 years for tax compliance.
AI-Generated Content
The app contains educational content generated by artificial intelligence (grammar exercises, grammar rules, word details for system words). AI-generated content is labeled with an "AI" badge. Content may contain errors; use the in-app report button to flag mistakes. No personal data is shared with third-party AI providers for content generation; generation happens on our backend. User interactions with AI-generated content are used solely for learning progress and content quality improvement.
9. Contact
For data safety questions, please use the in-app support channel or contact contact support.