Effective date: 13 June 2026. Data controller: Yuriy Anochshenko, an individual, based in Astana, Kazakhstan. Contact: hello@vocabu.io.
1. What We Collect
- Account data: email, password (hashed), display name ("what should we call you"), age range, interface language.
- Learning data: your goal description (free text and tags), language pair and region, level estimates, words and your interaction history with them (exercise results, timings, schedules), sprints, idioms, stories read, settings. Please do not include sensitive personal details (health, beliefs, etc.) in your goal description — the service does not need them. Goal text is processed as provided.
- Support contact (optional): one email address of a person you choose to be notified about your progress. You must inform that person; every message to them includes a one-click unsubscribe.
- Payment data: handled by Paddle (Merchant of Record). We never see your card details; we receive subscription status only.
- Technical data: basic logs and analytics necessary to run and improve the service (device type, approximate region, usage events). We do not sell personal data and do not show advertising.
2. How We Use It
To provide the service (generate your vocabulary, schedule reviews, send learning notifications you agreed to); to maintain security and prevent abuse; to improve the product using aggregated, de-identified statistics; to communicate service matters. Legal bases (EU/EEA users): contract performance, legitimate interest, consent where required (e.g., push notifications, support-contact messages).
3. AI Processing
Your goal text and learning context are processed by AI to generate study content. Our AI provider is Anthropic (Claude API). Inputs are sent for generation purposes only; we do not use your personal data to train AI models.
4. Service Providers (Subprocessors)
We use a small set of reputable service providers, each receiving only the data needed for its function: a cloud database and authentication provider, an application hosting provider, a transactional email provider, and a scheduled-tasks service (facilities located in the EU/US). Two providers we name directly: Paddle (payments, acting as Merchant of Record — you see Paddle at checkout and on receipts) and Anthropic (AI content generation — see Section 3). Data may be processed outside your country; we rely on providers' standard contractual safeguards. A full, current list of subprocessors is available on request at hello@vocabu.io.
5. Notifications
Email and (if you allow) push notifications support your learning schedule (e.g., a review ~25 minutes after a session, a daily reminder). You control them in Settings and in your device/browser permissions. The optional support-contact emails are sent only if you added a contact, and stop immediately on their unsubscribe or your removal of the contact.
6. Retention, Archiving and Deletion
Learning progress is archived, not silently deleted, so you can pause and return without losing your history. You can delete your account in Settings → Account → Delete account: this permanently removes your personal data within 30 days, except minimal records we must keep for legal/accounting reasons. Aggregated statistics that no longer identify you may be retained.
7. Your Rights
Depending on your location (including GDPR for EU/EEA users), you have the right to access, correct, export, restrict, object to processing of, and delete your personal data, and to withdraw consent. Write to hello@vocabu.io; we respond within 30 days. EU/EEA users may also lodge a complaint with their supervisory authority.
8. Children
Vocabu is not available to children under 13, and we do not knowingly collect their data. Users aged 13–17 have informal-register content disabled. If you believe a child under 13 has created an account, contact hello@vocabu.io and we will delete it.
9. Cookies and Local Storage
We use strictly necessary cookies/storage for sign-in and preferences, and minimal analytics. No third-party advertising cookies. [If an analytics tool is added, it will be listed here with an opt-out.]
10. Security and Incidents
We protect your data with industry-standard measures: encrypted connections (TLS), encrypted storage, hashed passwords, row-level access isolation (each account sees only its own data), and least-privilege access to infrastructure. No system is perfectly secure; if a data breach occurs that is likely to affect your rights, we will notify the competent authority within the legally required timeframe (72 hours under GDPR) and inform affected users without undue delay, describing what happened and what we are doing about it.
11. Changes
We will announce material changes in-app or by email at least 14 days in advance. Upon incorporation of the operating company, the data controller will change to that company without reducing your rights.