AtoC.ai

Privacy Policy

Draft — Last updated: June 23, 2026

Priority of Documents

In case of any discrepancy between this document and its translations, the English version shall prevail. Additionally, the terms of Apple App Store and Google Play Store, and applicable regional legislation shall take precedence over this document where applicable.

1. Introduction

This Privacy Policy explains how AtoC.ai collects, uses, stores, and protects your personal data. It applies to all users regardless of location and incorporates requirements under GDPR (EU/EEA/UK), CCPA/CPRA (California, USA), LGPD (Brazil), KVKK (Türkiye), Russian Federal Law 152-FZ, Kazakhstan Law 94-V, and India DPDP Act 2023.

AtoC.ai is a draft product. Some features described here are not yet implemented and are clearly marked as planned. They will be activated only with appropriate legal basis, consent, and policy updates.

2. Data Controller

Maksim Golitsyn (individual), Mersin, Türkiye. Full address available upon request via contact support.

For GDPR purposes, the controller acts as its own representative for EU/EEA users. GDPR requests can be sent to contact support.

3. Personal Data Processed

We process personal data in the categories below. Some categories are used only after you activate a specific feature or give consent.

  • Identity & contact: email address, display name, username, profile photo, birth month and year (not full date of birth), phone number if added, and social-login data from Google/Apple.
  • Account content: password (hashed), settings, language pairs, subscription status, achievements.
  • Learning data: vocabulary progress, grammar completion, FSRS state, XP, streaks, training history, answers, leaderboard rankings.
  • User-generated content (planned): vocabulary/grammar prompts, custom sets and exercises. We apply automated content filtering to block prohibited content; we do not guarantee 100% effectiveness. Users are responsible for their prompts.
  • Voice data (planned): voice recordings processed solely for pronunciation feedback. Recordings are deleted after the result is returned; metadata is retained only as needed for service improvement.
  • AI tutor data (planned): dialogue transcripts and audio messages sent to AI vendors to generate responses.
  • Device & usage data: device type, OS version, app interactions, push token, IP address (hashed, retained no more than 30 days), advertising ID (consent-controlled), crash logs, diagnostics.
  • Communication data: feedback submissions, support requests, email correspondence.
  • Payment data: transaction identifiers, subscription status, plan type (processed by Apple, Google, or RevenueCat; we do not store full payment card data).
  • TTS audio: synthesised audio generated by Google Cloud TTS or Amazon Polly and stored in Cloudflare R2. This is not your voice.
  • Cookie & analytics data: cookies, SDK analytics events, attribution data.

4. Purposes of Processing

Purpose Data Categories Legal Basis Retention
Provide app functionality Identity, account content, learning data Performance of contract Until account deletion + 30 days
Process subscriptions & payments Identity, payment data Performance of contract / Legal obligation 7 years for tax/accounting
Send transactional notifications Identity, device data Legitimate interest Until account deletion
Send marketing communications Identity Consent 3 years after last communication
App operation & security Usage data, diagnostics Legitimate interest Up to 1 year
Analytics & product improvement Usage, learning, diagnostics Consent (third-party SDKs) / Legitimate interest Up to 3 years
Advertising Advertising ID, usage data Consent (EU/EEA) / Legitimate interest Up to 3 years
AI tutor & voice features AI tutor data, voice recordings Consent Voice deleted after processing; AI data until account deletion
Internal records & legal claims All categories as required Legitimate interest / Legal obligation Up to 10 years after contract end
Comply with legal requests All categories as required Legal obligation As required by law

5. Third-Party SDKs & Subprocessors

Current subprocessors and SDKs active in the app or its backend:

Provider / SDK Data Processed Purpose Status
NetcupAll service dataCloud hosting (Germany)Current
SelectelPersonal data of Russian users152-FZ data localizationCurrent
CloudflareHTTP metadata, audio/avatar files, cached contentCDN, Workers, R2 storageCurrent
Google Cloud TTS / Amazon PollyText stringsText-to-speech synthesisCurrent
Firebase AnalyticsUsage events, device infoProduct analytics (consent)Current
Firebase CrashlyticsCrash logs, device infoCrash reportingAlways active
AppsFlyerInstall referrer, advertising IDAttributionAlways active
AmplitudeUsage events, user propertiesProduct analytics (consent)Current
MixpanelUsage events, user propertiesProduct analytics (consent)Current
SentryError logs, device infoError monitoringCurrent
RevenueCatTransaction IDs, subscription statusSubscription managementCurrent
Google Mobile Ads (AdMob)Advertising ID, usage dataAdvertising (consent)Current
Firebase Cloud MessagingPush tokenPush notificationsCurrent

Planned subprocessors (not yet active):

Provider / SDK Data Processed Purpose Status
Cloudflare D1 / KVCached learning dataEdge database / key-value storePlanned
AI providers (OpenAI, Google, etc.)Prompts, dialogue transcripts, audioAI tutor, content generationPlanned
Speech recognition providersVoice recordingsPronunciation feedbackPlanned

All subprocessors are contractually bound to process data only on our behalf and in compliance with applicable data protection laws. Third-party analytics SDKs (Amplitude, Mixpanel, Firebase Analytics) are active only after user consent; EU/EEA requires explicit consent. Crashlytics and AppsFlyer are always active for error monitoring and attribution.

6. Cross-Border Transfers & Regional Servers

Your data may be stored and processed in jurisdictions other than your own. Our primary infrastructure is in Germany (Netcup) and Russia (Selectel for Russian users). We are planning regional servers in the Middle East, India, and Asia where data-localization laws require it. Personal data remains in primary databases; Cloudflare edge locations process only cached training content and HTTP metadata.

  • EU/EEA/UK users: data is processed within the EU or transferred under Standard Contractual Clauses (SCCs).
  • Russian users: personal data is initially collected and stored in Russia (Selectel) under 152-FZ; cross-border transfer to Germany is under Russia's adequate-protection list.
  • Turkish users: transfer to Germany is based on explicit consent under KVKK Art. 9 or other permitted grounds.
  • Brazilian users: transfer under LGPD adequacy decisions or SCCs.
  • Kazakhstan users: transfer under 94-V safeguards.
  • Indian users: transfer under India DPDP Act 2023 requirements; explicit consent for sensitive data.

7. Security Measures

  • Encryption: TLS 1.3 in transit; AES-256 at rest.
  • Access control: RBAC, least-privilege, MFA for staff.
  • Monitoring: intrusion detection, vulnerability scanning, incident response.
  • Backups: encrypted, geographically redundant, restricted access.
  • Data minimisation: collect only what is necessary; pseudonymise where possible.

8. Your Rights

Depending on your jurisdiction, you may have the following rights:

Jurisdiction Rights
GDPR (EU/EEA/UK)Access, rectification, erasure, restriction, portability, object, withdraw consent, lodge complaint with DPA/ICO.
CCPA/CPRA (California)Know, delete, opt-out of sale/share, correct, limit use of sensitive data, non-discrimination.
LGPD (Brazil)Confirmation, access, correction, anonymisation/blocking/deletion, portability, revoke consent, object, complain to ANPD.
KVKK (Türkiye)Learn processing, request info/correction/deletion/anonymisation, object, claim damages, complain to KVKK.
152-FZ (Russia)Access, clarify/block/destroy inaccurate/unlawful data, withdraw consent, complain to Roskomnadzor.
94-V (Kazakhstan)Access, correct, delete, be informed, object to direct marketing.
DPDP Act 2023 (India)Access, correction, erasure, grievance redressal, nominate another person; parental consent for children under 18.

To exercise your rights, contact us at contact support. We will respond within 30 days, or sooner where required by law.

9. Cookies & Tracking

We use cookies and similar technologies to operate the service, analyze usage, and deliver relevant advertising. For details and consent controls, see our Cookie Policy.

10. AI-Generated Content & Planned Features

Current: Grammar cards and exercises in the AtoC.ai catalog may be generated by AI (marked as isAIGenerated). Content may be published before teacher/moderator review; priority display is given to teacher-verified material. AI-generated content may contain errors and does not replace professional instruction.

Planned: The following features are on the roadmap and will be activated only with appropriate legal basis, consent, and policy updates:

  • Voice pronunciation check: voice recordings processed solely for pronunciation feedback; recordings deleted after the result is returned.
  • AI tutor: conversational AI for language practice; dialogue history processed to provide responses.
  • User-generated vocabulary & grammar: users may generate custom sets and exercises from prompts. Automated filtering is applied but not guaranteed to be 100% effective.
  • Mascots & Command Competition: team-based language challenges where hints are earned through activity and skill — not gambling, no loot boxes, no real-money prizes.
  • Any language from any language: expansion of target languages beyond English and Turkish.
  • Regional servers: Middle East, India, and Asia for data localization where required by law.
  • 300+ Cloudflare edge PoPs: low-latency training worldwide via edge caching and compute; personal data remains in primary databases.

11. Children’s Privacy

AtoC.ai is not intended for children under 13. We do not knowingly collect personal data from children under 13. If you believe we have collected data from a child under 13, contact us immediately.

Users under 16 receive high-privacy defaults: non-personalized ads and disabled third-party analytics. Where required by law, verifiable parental consent is required before processing personal data of children.

12. Data Protection Officer

We are not currently required to appoint a Data Protection Officer under GDPR Article 37. If this changes, we will update this policy accordingly.

13. Contact

For privacy-related inquiries, data subject requests, or complaints, please contact our privacy team at contact support.

14. Changes to This Policy

We may update this Privacy Policy from time to time. The updated version will be indicated by a revised date. Material changes will be communicated through the app or by email. Continued use of the service after changes constitutes acceptance of the revised policy.