Privacy
Last updated 23/09/2026
The short version: we keep what you need an account for, we share it with almost nobody, we never sell it, and you can delete all of it yourself in about ten seconds. The long version is below, and it is specific rather than generic — every item is something this app actually does.
Who is responsible
The person named in the legal notice decides what happens to your data and is who to contact about it. Write to avc.lleida@gmail.com and you are writing to them, not to a department.
What we store
- Your account: your email address, your name, your timezone, and — if you signed up with a password — a hash of that password, never the password itself.
- If you signed in with Google: the profile picture link Google gives us. It is stored and, as it happens, never shown anywhere in the app.
- Your settings: the levels you read at, the topics and music you chose, artists you named as favourites or asked not to hear again, how many tasks a day counts, and your light or dark preference.
- What you have done: which days you completed and when, which suggestions you were shown or skipped, and what you saved for later.
- Your vocabulary: the words you saved and the translations you wrote for them.
- Your own work: anything you wrote in an exercise, and any voice recording you made.
We do not store your payment details, because nothing here is paid for. There is no analytics, no advertising, no tracking pixel, and no profiling of any kind.
Why we are allowed to
To give you the thing you signed up for. Under the GDPR that is article 6(1)(b) — we need an account to keep your week, and we need your settings to choose what to suggest. Your email address is also used to confirm the address is yours, which is what stops somebody signing up as you.
Who else sees it
Four, and only these four:
- Mailgun receives your email address, so we can send you the message that confirms it. Nothing else is sent to them.
- Google Cloud Translation receives the German text you ask us to translate — a word from your vocabulary list, or a title. It does not receive your name, your email or anything identifying you. Where Google is unavailable we fall back to MyMemory, which receives the same text on the same terms.
- Google receives the fact that you signed in, if you chose to sign in with Google. If you signed up with a password, Google is never involved.
- The publisher of whatever you open. Every task is a link out to a newspaper, a broadcaster or YouTube, and opening one is an ordinary visit to their site — they see it as they would any visitor. For two sources the page opens inside ours in a frame, and those set their own cookies, which we can neither read nor prevent.
That is the whole list. Nobody buys this data, because it is not for sale, and nothing about you is passed to anyone for advertising.
Cookies
Two, both strictly necessary, neither used to follow you. One keeps you signed in. The other lasts ten minutes and only exists so that signing in with Google knows whether you meant to create an account or open an existing one. There is no analytics cookie, so there is no banner asking you to accept one.
How long we keep it
Until you delete it. Nothing here expires on its own — a vocabulary list you made in January is still there in December, which is the point of it. Delete your account and all of it goes at once.
One thing survives, and it is fair that you know: when text is translated we store the translation so nobody has to pay to translate the same word twice. Those rows hold the text and nothing else — no account, no name, no list, no link back to whoever asked. They cannot be traced to you, and that is why deleting your account does not remove them.
What you can do about it
The GDPR gives you these, and none of them costs anything:
- See what we hold. Most of it is already on screen; ask and we will send the rest.
- Correct it. Your name and timezone are in Settings; ask us for anything you cannot reach.
- Erase it. You do not have to ask — Settings, then Account, then Delete your account. It happens immediately and we keep no copy.
- Take it with you. Ask and we will send your data in a machine-readable file.
- Object to what we do with it, or ask us to restrict it.
- Complain. If we get this wrong, you can go to the Spanish data protection authority, the Agencia Española de Protección de Datos (aepd.es), or to the authority in the country you live in. We would much rather you told us first, at avc.lleida@gmail.com.
How it is kept
The site is served over HTTPS. Passwords are stored as bcrypt hashes and cannot be read back, by us or by anybody else. The database is not reachable from the internet, and the part of the app that holds your data is not addressable from a browser at all. Backups are taken daily and are not kept longer than a fortnight.
Age
This is not aimed at children. In Spain you must be at least 14 to consent to a service like this one handling your data. If you are younger, please do not create an account.
Changes
If this changes we will change the date at the top. Anything that genuinely affects you — a new company receiving your data, a new reason for holding it — you will be told about by email rather than left to spot it here.