AtoC.ai

Data Safety

Draft — Last updated: June 23, 2026

Priority of Documents

In case of any discrepancy between this document and its translations, the English version shall prevail. This page is intended for Google Play Data Safety and Apple App Privacy disclosures.

1. Data Collected (Current)

  • Email address — for account registration and communication.
  • Display name and username — for profile and leaderboard.
  • Profile photo — user-uploaded avatar.
  • Birth month and year — for age validation (not full date of birth).
  • Learning progress — vocabulary progress, grammar completion, XP, streaks, training history, achievements.
  • Device information — device type, OS version, push tokens, hashed IP address.
  • Subscription status — plan type and transaction identifiers (processed by Apple, Google, RevenueCat).
  • TTS audio — synthesised audio generated by Google Cloud TTS or Amazon Polly, stored in Cloudflare R2. This is not user voice.
  • Analytics data — Firebase Analytics, Crashlytics, AppsFlyer, Amplitude, and Mixpanel collect usage events, device info, and crash logs. These SDKs are active only after user consent (EU/EEA requires explicit consent; other regions may be enabled by default with opt-out option).
  • Advertising data — AdMob advertising ID, only after explicit consent (EU/EEA). Disabled by default for Russian users.

2. Data Collected (Planned — Not Yet Active)

  • Voice recordings — for pronunciation check only; deleted after feedback is generated. Not used for biometric identification.
  • AI tutor dialogue history — for conversational language practice.
  • User-generated vocabulary/grammar prompts — for custom content creation.

3. Data Not Collected

  • Full date of birth — only month and year are collected.
  • Payment card data — processed by Apple, Google, or RevenueCat; we do not store card numbers.
  • Biometric data — no facial recognition, fingerprint, or voice biometric identification.
  • Health data — not collected.
  • Location data — not collected. IP address is hashed and used only for security.

4. Data Encryption

  • In transit: TLS 1.3
  • At rest: AES-256
  • Backups: Encrypted, geographically redundant

5. Data Used for Tracking

For the purposes of Google Play and Apple App Store disclosures, the following data may be used for tracking across third-party apps and websites:

  • Advertising ID — used by Google AdMob for ad personalization (only after consent; disabled by default for Russian users).
  • Device ID / device info — used by AppsFlyer for install attribution; by Firebase Analytics, Amplitude, and Mixpanel for analytics (only after consent).

Third-party analytics SDKs are active only after user consent (EU/EEA requires explicit consent; other regions may be enabled by default with opt-out option). Crashlytics and AppsFlyer attribution are always active for error monitoring and install attribution.

6. Third-Party SDKs (Current)

SDK / Provider Data Collected Purpose Consent
NetcupAll service dataHosting (Germany)Contract
SelectelPersonal data of Russian users152-FZ localizationLegal obligation
CloudflareHTTP metadata, cached files, audio/avatarsCDN, Workers, R2Legitimate interest
Google Cloud TTS / Amazon PollyText stringsText-to-speechContract
Firebase Cloud MessagingPush token, device typePush notificationsContract
Google AdMobAdvertising ID, device infoAdvertisingConsent
SentryCrash logs, device infoError monitoringLegitimate interest
RevenueCatTransaction IDs, subscription statusSubscriptionsContract
Firebase AnalyticsUsage events, device infoProduct analyticsConsent
Firebase CrashlyticsCrash logs, device infoCrash reportingAlways active
AppsFlyerInstall referrer, advertising IDAttributionAlways active
AmplitudeUsage events, user propertiesProduct analyticsConsent
MixpanelUsage events, user propertiesProduct analyticsConsent

7. Third-Party SDKs (Planned — Not Yet Active)

SDK / Provider Data Collected Purpose Status
Cloudflare D1 / KVCached learning dataEdge database / key-value storePlanned
AI providers (OpenAI, Google, etc.)Prompts, dialogue transcripts, audioAI tutor, content generationPlanned
Speech recognition providersVoice recordingsPronunciation feedbackPlanned

None of these planned SDKs are included in the current app version. They will be added only with appropriate consent and policy updates.

8. Regional Servers

Primary infrastructure is in Germany (Netcup) and Russia (Selectel for Russian users). We are planning regional servers in the Middle East, India, and Asia where data-localization laws require it. Personal data remains in primary databases; edge locations process only cached training content and HTTP metadata.

9. Data Deletion

Users can request account deletion in the app settings. Account data is deleted within 30 days. Learning data is retained for 90 days for analytical purposes, then permanently erased. Payment records are retained for 7 years for tax compliance. Voice recordings, when the feature is active, are deleted immediately after pronunciation feedback is generated.

10. Contact

For data safety questions, please use the in-app support channel or contact contact support.