Priority of Documents
In case of any discrepancy between this document and its translations, the English version shall prevail. Additionally, the terms of Apple App Store and Google Play Store, and applicable regional legislation shall take precedence over this document where applicable.
1. Introduction
This Privacy Policy explains how AtoC.ai collects, uses, stores, and protects your personal data. It applies to all users regardless of location and incorporates requirements under GDPR (EU/EEA/UK), CCPA/CPRA (California, USA), LGPD (Brazil), KVKK (Türkiye), Russian Federal Law 152-FZ, Kazakhstan Law 94-V, and India DPDP Act 2023.
AtoC.ai is a draft product. Some features described here are not yet implemented and are clearly marked as planned. They will be activated only with appropriate legal basis, consent, and policy updates.
2. Data Controller
Maksim Golitsyn (individual), Mersin, Türkiye. Full address available upon request via contact support.
For GDPR purposes, the controller acts as its own representative for EU/EEA users. GDPR requests can be sent to contact support.
3. Personal Data Processed
We process personal data in the categories below. Some categories are used only after you activate a specific feature or give consent.
- Identity & contact: email address, display name, username, profile photo, birth month and year (not full date of birth), phone number if added, and social-login data from Google/Apple.
- Account content: password (hashed), settings, language pairs, subscription status, achievements.
- Learning data: vocabulary progress, grammar completion, FSRS state, XP, streaks, training history, answers, leaderboard rankings.
- User-generated content (planned): vocabulary/grammar prompts, custom sets and exercises. We apply automated content filtering to block prohibited content; we do not guarantee 100% effectiveness. Users are responsible for their prompts.
- Voice data (planned): voice recordings processed solely for pronunciation feedback. Recordings are deleted after the result is returned; metadata is retained only as needed for service improvement.
- AI tutor data (planned): dialogue transcripts and audio messages sent to AI vendors to generate responses.
- Device & usage data: device type, OS version, app interactions, push token, IP address (hashed, retained no more than 30 days), advertising ID (consent-controlled), crash logs, diagnostics.
- Communication data: feedback submissions, support requests, email correspondence.
- Payment data: transaction identifiers, subscription status, plan type (processed by Apple, Google, or RevenueCat; we do not store full payment card data).
- TTS audio: synthesised audio generated by Google Cloud TTS or Amazon Polly and stored in Cloudflare R2. This is not your voice.
- Cookie & analytics data: cookies, SDK analytics events, attribution data.
4. Purposes of Processing
| Purpose | Data Categories | Legal Basis | Retention |
|---|---|---|---|
| Provide app functionality | Identity, account content, learning data | Performance of contract | Until account deletion + 30 days |
| Process subscriptions & payments | Identity, payment data | Performance of contract / Legal obligation | 7 years for tax/accounting |
| Send transactional notifications | Identity, device data | Legitimate interest | Until account deletion |
| Send marketing communications | Identity | Consent | 3 years after last communication |
| App operation & security | Usage data, diagnostics | Legitimate interest | Up to 1 year |
| Analytics & product improvement | Usage, learning, diagnostics | Consent (third-party SDKs) / Legitimate interest | Up to 3 years |
| Advertising | Advertising ID, usage data | Consent (EU/EEA) / Legitimate interest | Up to 3 years |
| AI tutor & voice features | AI tutor data, voice recordings | Consent | Voice deleted after processing; AI data until account deletion |
| Internal records & legal claims | All categories as required | Legitimate interest / Legal obligation | Up to 10 years after contract end |
| Comply with legal requests | All categories as required | Legal obligation | As required by law |
5. Third-Party SDKs & Subprocessors
Current subprocessors and SDKs active in the app or its backend:
| Provider / SDK | Data Processed | Purpose | Status |
|---|---|---|---|
| Netcup | All service data | Cloud hosting (Germany) | Current |
| Selectel | Personal data of Russian users | 152-FZ data localization | Current |
| Cloudflare | HTTP metadata, audio/avatar files, cached content | CDN, Workers, R2 storage | Current |
| Google Cloud TTS / Amazon Polly | Text strings | Text-to-speech synthesis | Current |
| Firebase Analytics | Usage events, device info | Product analytics (consent) | Current |
| Firebase Crashlytics | Crash logs, device info | Crash reporting | Always active |
| AppsFlyer | Install referrer, advertising ID | Attribution | Always active |
| Amplitude | Usage events, user properties | Product analytics (consent) | Current |
| Mixpanel | Usage events, user properties | Product analytics (consent) | Current |
| Sentry | Error logs, device info | Error monitoring | Current |
| RevenueCat | Transaction IDs, subscription status | Subscription management | Current |
| Google Mobile Ads (AdMob) | Advertising ID, usage data | Advertising (consent) | Current |
| Firebase Cloud Messaging | Push token | Push notifications | Current |
Planned subprocessors (not yet active):
| Provider / SDK | Data Processed | Purpose | Status |
|---|---|---|---|
| Cloudflare D1 / KV | Cached learning data | Edge database / key-value store | Planned |
| AI providers (OpenAI, Google, etc.) | Prompts, dialogue transcripts, audio | AI tutor, content generation | Planned |
| Speech recognition providers | Voice recordings | Pronunciation feedback | Planned |
All subprocessors are contractually bound to process data only on our behalf and in compliance with applicable data protection laws. Third-party analytics SDKs (Amplitude, Mixpanel, Firebase Analytics) are active only after user consent; EU/EEA requires explicit consent. Crashlytics and AppsFlyer are always active for error monitoring and attribution.
6. Cross-Border Transfers & Regional Servers
Your data may be stored and processed in jurisdictions other than your own. Our primary infrastructure is in Germany (Netcup) and Russia (Selectel for Russian users). We are planning regional servers in the Middle East, India, and Asia where data-localization laws require it. Personal data remains in primary databases; Cloudflare edge locations process only cached training content and HTTP metadata.
- EU/EEA/UK users: data is processed within the EU or transferred under Standard Contractual Clauses (SCCs).
- Russian users: personal data is initially collected and stored in Russia (Selectel) under 152-FZ; cross-border transfer to Germany is under Russia's adequate-protection list.
- Turkish users: transfer to Germany is based on explicit consent under KVKK Art. 9 or other permitted grounds.
- Brazilian users: transfer under LGPD adequacy decisions or SCCs.
- Kazakhstan users: transfer under 94-V safeguards.
- Indian users: transfer under India DPDP Act 2023 requirements; explicit consent for sensitive data.
7. Security Measures
- Encryption: TLS 1.3 in transit; AES-256 at rest.
- Access control: RBAC, least-privilege, MFA for staff.
- Monitoring: intrusion detection, vulnerability scanning, incident response.
- Backups: encrypted, geographically redundant, restricted access.
- Data minimisation: collect only what is necessary; pseudonymise where possible.
8. Your Rights
Depending on your jurisdiction, you may have the following rights:
| Jurisdiction | Rights |
|---|---|
| GDPR (EU/EEA/UK) | Access, rectification, erasure, restriction, portability, object, withdraw consent, lodge complaint with DPA/ICO. |
| CCPA/CPRA (California) | Know, delete, opt-out of sale/share, correct, limit use of sensitive data, non-discrimination. |
| LGPD (Brazil) | Confirmation, access, correction, anonymisation/blocking/deletion, portability, revoke consent, object, complain to ANPD. |
| KVKK (Türkiye) | Learn processing, request info/correction/deletion/anonymisation, object, claim damages, complain to KVKK. |
| 152-FZ (Russia) | Access, clarify/block/destroy inaccurate/unlawful data, withdraw consent, complain to Roskomnadzor. |
| 94-V (Kazakhstan) | Access, correct, delete, be informed, object to direct marketing. |
| DPDP Act 2023 (India) | Access, correction, erasure, grievance redressal, nominate another person; parental consent for children under 18. |
To exercise your rights, contact us at contact support. We will respond within 30 days, or sooner where required by law.
9. Cookies & Tracking
We use cookies and similar technologies to operate the service, analyze usage, and deliver relevant advertising. For details and consent controls, see our Cookie Policy.
10. AI-Generated Content & Planned Features
Current: Grammar cards and exercises in the AtoC.ai catalog may be generated by AI (marked as isAIGenerated). Content may be published before teacher/moderator review; priority display is given to teacher-verified material. AI-generated content may contain errors and does not replace professional instruction.
Planned: The following features are on the roadmap and will be activated only with appropriate legal basis, consent, and policy updates:
- Voice pronunciation check: voice recordings processed solely for pronunciation feedback; recordings deleted after the result is returned.
- AI tutor: conversational AI for language practice; dialogue history processed to provide responses.
- User-generated vocabulary & grammar: users may generate custom sets and exercises from prompts. Automated filtering is applied but not guaranteed to be 100% effective.
- Mascots & Command Competition: team-based language challenges where hints are earned through activity and skill — not gambling, no loot boxes, no real-money prizes.
- Any language from any language: expansion of target languages beyond English and Turkish.
- Regional servers: Middle East, India, and Asia for data localization where required by law.
- 300+ Cloudflare edge PoPs: low-latency training worldwide via edge caching and compute; personal data remains in primary databases.
11. Children’s Privacy
AtoC.ai is not intended for children under 13. We do not knowingly collect personal data from children under 13. If you believe we have collected data from a child under 13, contact us immediately.
Users under 16 receive high-privacy defaults: non-personalized ads and disabled third-party analytics. Where required by law, verifiable parental consent is required before processing personal data of children.
12. Data Protection Officer
We are not currently required to appoint a Data Protection Officer under GDPR Article 37. If this changes, we will update this policy accordingly.
13. Contact
For privacy-related inquiries, data subject requests, or complaints, please contact our privacy team at contact support.
14. Changes to This Policy
We may update this Privacy Policy from time to time. The updated version will be indicated by a revised date. Material changes will be communicated through the app or by email. Continued use of the service after changes constitutes acceptance of the revised policy.