Privacy Policy
Effective date :
This text is in English. The English version is the one that applies.
Who we are
Langie (langie.app and the Langie apps) is run by Vladimir Gelunov, an individual developer based in Brazil. In this policy "we" means Vladimir Gelunov. We decide how your data is used, so we are the data controller.
Questions about your data: [email protected].
What we collect
Account. Your name, e-mail address and password. We store the password only as a one-way hash (bcrypt), never in plain text. We also store when you confirmed your e-mail and when you created the account.
Sign-in with Google or Apple. If you sign in with Google, Google gives us your name, e-mail address and profile picture. If you sign in with Apple in the mobile app, Apple gives us your e-mail address and, if you share it, your name. We do not get your Google or Apple password.
Using Langie without an account. You can study without signing up. We then keep your progress under a random device ID stored in a cookie. When you later sign in, that progress moves into your account.
Learning data:
- the languages you study, your level, the script you read in and your progress on the map;
- the review schedule for each word you study, your XP, streaks and achievements;
- your settings, such as interface language, new words per day and form of address, and your time zone;
- words you add yourself;
- your answers: the question, the expected answer, what you typed or said and whether it was right. We read these answers to find and fix wrong cards.
Reports. When you report a card or a sentence, we store the reason, your comment, the card and the cards you saw just before it.
Your voice. When you answer with the microphone, the audio goes to Microsoft Azure Speech to turn it into text. We do not store the audio. The text is graded like a typed answer.
Payments. The plan, amount, currency, status and dates of each purchase, the Polar customer and checkout IDs and the e-mail you enter at checkout. We never see or store your card details.
Reminders. If you turn on streak reminders, we store the push subscription your browser gives us (an address and keys for sending notifications) and your time zone.
Technical data:
- your IP address and a device ID. The device ID is a random value in a cookie. If cookies are blocked, it is a hash of browser headers such as user agent and language. We use both to apply the free plan limits, to link a purchase to a device and to stop abuse;
- server logs with the pages requested (without query strings) and errors;
- error reports: when something breaks, we get the error, the page, your browser and device type. On a sample of visits and on visits with an error we also get a replay of the page. The replay hides all text and form input;
- the version of the Android app, if you use it.
Where you came from. If you open Langie from a link with a campaign tag (utm_source and similar), we remember that tag for 90 days and save it with your account when you sign up. We also count visits per campaign per day, without any personal data.
How we use it and why we may
- To run Langie for you: your account, your cards, your progress, your purchases and the e-mails you ask for. This is needed to provide the service you signed up for (contract).
- To keep Langie safe and working: free plan limits, rate limits, bot checks, error reports and logs. This is our legitimate interest in a working, abuse-free service.
- To improve lessons: reading answers and reports to fix wrong cards. This is our legitimate interest in correct content.
- Streak reminders and the microphone: only when you turn them on (consent). You can turn them off at any time.
- Payment records: we keep them because tax and accounting law requires it (legal obligation).
We do not show ads. We do not sell your data. We do not use your data to train AI models.
Who else processes your data
We use these services to run Langie. Each gets only what it needs for its job:
- Hetzner (Germany) — hosts the server where the app, the database (PostgreSQL) and the cache (Redis) run. All data above is stored there.
- Cloudflare — delivers the site, provides HTTPS and protects it from attacks. It sees every request, including your IP address. Cloudflare Turnstile checks that a human is asking before we send a password-reset or confirmation e-mail.
- Google — Sign-in with Google (name, e-mail, profile picture).
- Apple — Sign in with Apple in the mobile app (e-mail, and name if you share it).
- Polar (polar.sh) — sells and charges for paid plans, with Stripe as its card processor. Polar gets your payment details and the e-mail you give at checkout, under its own privacy policy.
- Microsoft Azure Speech — reads card text aloud and turns your voice answers into text.
- Translation — our own translation service passes words and sentences, including words you add and interface text, to machine translation providers: DeepL, Google Cloud Translation, Yandex Cloud Translate, MyMemory, Microsoft Azure Translator and OpenAI. It does not send your name, e-mail or account ID.
- AI models — to write example sentences and short word explanations we send words and sentences to AI models: Google Gemini and Anthropic Claude, reached directly or through OpenRouter. We do not send your name, e-mail or account ID.
- Mailgun — sends e-mail confirmation and password-reset messages. It gets your e-mail address and the message.
- Sentry — collects error reports and page replays (see Technical data).
- Pexels — card photos load straight from Pexels servers, so Pexels sees your IP address and browser.
- flagcdn.com — flag pictures load from it, so it sees your IP address and browser.
- Push services of your browser (for example Google, Mozilla or Apple) — deliver streak reminders if you turned them on.
Some of these providers are outside your country, including in the United States. Where the law requires it, the transfer relies on the safeguards those providers offer, such as the EU Standard Contractual Clauses.
Cookies and storage on your device
We use only cookies and storage that Langie needs to work or to remember your choices. There are no advertising or cross-site tracking cookies.
- next-auth.session-token and related Auth.js cookies — keep you signed in for up to 30 days and protect sign-in forms.
- __lang_did — your device ID, signed and hidden from page scripts, kept for 2 years.
- interface_language, theme, sourceLang, targetLang, displayScript and targetLevel — your language, level and look.
- lastAuthMethod — which sign-in method you used last on this device.
- acquisition — the campaign tag you arrived with, for 90 days.
- stepDownSnooze — that you declined the offer to switch to an easier level.
- Local storage, session storage and IndexedDB — your settings, study progress and the lesson in progress, plus answers given offline until they can be sent.
- The offline cache of the app — recent pages and card audio, so you can study without a connection.
Cloudflare and Sentry may set their own short-lived cookies or storage for security and to group an error report with its replay.
How long we keep it
- Account and learning data: as long as your account exists.
- Your answers: 90 days, then deleted automatically.
- Sign-in sessions: 30 days.
- E-mail confirmation and password-reset links: until used or expired.
- Guest progress: until it moves into an account or you ask us to delete it.
- Payment records: as long as tax and accounting law requires, even after you delete your account. The link to your account is removed.
- Reports you sent: kept to fix content. The link to your account is removed when you delete it.
- IP address and device ID used for the free plan limit: kept to apply that limit.
- Error reports: deleted automatically at the end of the retention period of our Sentry plan.
Deleting your account
To delete your account, e-mail [email protected] from the address on the account. We delete it within one month. This removes your profile, cards, progress, words you added, achievements, sessions and reminder subscriptions. Answers, reports and payment records stay without a link to you, as described above.
You can also remove a language course in Settings, remove words you added and turn off reminders at any time.
Your rights
Depending on where you live (for example under the EU GDPR or the Brazilian LGPD), you have the right to:
- get a copy of your data (access);
- correct wrong data. You can change your name in your profile yourself;
- have your data deleted;
- get your data in a machine-readable format (portability);
- object to or limit how we use it;
- withdraw consent you gave, such as for reminders.
To use any of these rights, e-mail [email protected]. We answer within one month. You can also complain to your data protection authority.
Children
Langie is for people aged 13 or older. If you are younger, do not create an account. Where the law of your country sets a higher age for consenting to online services on your own, you need a parent's or guardian's permission to use Langie until you reach that age. If you believe a child gave us personal data, write to [email protected] and we will delete it.
Security
All traffic uses HTTPS. Passwords are hashed. Session and device cookies are signed and hidden from page scripts. Access to the server and to provider keys is limited to us. No system is perfectly secure, but we work to protect your data.
Changes to this policy
When we change this policy, we update the date at the top. If a change affects you in an important way, we tell you in the app or by e-mail before it applies.
Contact
Vladimir Gelunov, Brazil. E-mail: [email protected].