Effective date: July 30, 2026 · Last updated: July 30, 2026
1.1. This Privacy Policy (hereinafter — the "Policy") explains how personal data of users of the Linglass service (hereinafter — the "Service") is collected, processed, stored, and protected.
1.2. The data controller is Furtaev Ilia, Individual Entrepreneur registered in the Republic of Armenia, Taxpayer Identification Number (TIN) 20354437, state registration number 286.1599034 (hereinafter — the "Controller"). Contact: [email protected].
1.3. This Policy is made in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"), the UK GDPR, and applicable data protection law of the Republic of Armenia.
1.4. By using the Service, the User agrees to the processing of their personal data as described in this Policy. Where processing is based on consent, the User may withdraw consent at any time. If the User does not agree with this Policy, the User must stop using the Service.
1.5. The Controller may amend this Policy. The current version is published at https://linglass.app/privacy. The Controller notifies Users of material changes by email or through the Service interface.
2.1. Personal data is processed on the following legal bases:
3.1. The Controller processes personal data for the following purposes:
| Data category | Composition | Required |
|---|---|---|
| Email address | Required | |
| Name | First name, last name | Optional |
| Password | Stored in encrypted form | Required (for email registration) |
| Data category | Composition | Source |
|---|---|---|
| User identifier | Hashed identifier in the provider's system | Google, Apple |
| Email address | Google, Apple | |
| Name | First name, last name | Google, Apple |
| Avatar URL | Link to profile image | Google, Apple |
Apple Sign In may provide a private relay (forwarding) email address instead of the User's real email, according to the User's Apple settings. The name is provided only on the first sign-in.
| Data category | Composition | Purpose |
|---|---|---|
| Saved words | Word, language, normalized form | Personal dictionary |
| Translations | Translation, target language | Contextual translation |
| Transcription (IPA) | Phonetic transcription of the word | Pronunciation |
| Context sentence | The sentence in which the word appeared | Learning context |
| Source metadata | Platform, video URL, video identifier, timestamp | Source attribution |
| Video frame screenshot | Image (JPEG) | Visual context |
| Audio clip | Audio fragment from the video | Audio context |
| Data category | Composition | Purpose |
|---|---|---|
| Card state | Difficulty, stability, retrievability, interval | Repetition algorithm |
| Answer grades | Grade (again/hard/good/easy) | Repetition history |
| Repetition dates and times | Timestamps | Repetition schedule |
| Repetition parameters | Desired retention, new cards per day, max interval | Learning settings |
| Usage statistics | Aggregated data on Service feature usage | Subscription limit management |
The Controller does not receive or store the User's bank card details (card number, expiry date, CVV/CVC code). Card data is entered by the User on the secure page of a PCI DSS–certified payment provider and is not stored by the Controller.
Depending on the platform, payments are processed by:
Data on each transaction (date, amount, currency, payment status) is stored to provide the User with a payment history and to comply with legal requirements. Apple's and Google's processing of payment data is governed by their respective privacy policies.
During use of the Service, technical data is automatically processed: IP address, browser type, and server request information. This data is used to ensure the security and operability of the Service, is not stored in association with the User's account, and is deleted in accordance with the log rotation policy.
To ensure account security and maintain an active session, the Service processes session data (encrypted authentication tokens, email confirmation codes). Session data is stored for a limited time and is automatically deleted upon expiration.
5.1. The Service uses strictly necessary cookies for authentication and session management. Without these cookies, the Service cannot be used. The Service does not use advertising cookies.
5.2. To analyze traffic sources and improve the Service, we use Google Analytics 4 (operated by Google LLC), which sets its own cookies and collects pseudonymized visit data (referral source, pages, session duration, device type, approximate IP-based location) on the basis of the User's consent where required. Google's processing is governed by policies.google.com/privacy. Users may opt out via tools.google.com/dlpage/gaoptout.
5.3. The User may manage cookies through browser settings. Disabling strictly necessary cookies may prevent use of the Service.
5.4. Marketing attribution. When the User first arrives at the Service from an external source, the Service stores a first-touch attribution cookie (linglass_attribution) containing UTM parameters from the URL and the host of the referring page (no full URL, no query string). On registration, this cookie is stored alongside the User account to analyze marketing channel effectiveness. The data is not transferred to any third party. The cookie is cleared after successful registration.
5.5. Mobile applications. In the mobile applications, the Controller uses Firebase Analytics (Google LLC) for aggregated usage analytics and Sentry for crash and error diagnostics. Analytics and diagnostic data in the mobile applications are collected only after the User grants consent on the in-app consent screen; nothing is sent before consent, and the User may decline.
6.1. To provide its functionality, the Service relies on third-party processors and services. The following describes the categories of recipients and the data disclosed to them.
Services to which no personal data is disclosed: the Service sends pseudonymized requests (individual words, language pairs, contextual sentences with no link to the user) to third-party machine translation and text-to-speech services. These requests do not contain User identifiers.
Recipients to which personal data is disclosed:
| Recipient | Data disclosed | Purpose | Country of processing |
|---|---|---|---|
| Authentication services (OAuth providers) | OAuth token or authorization code | Authentication via third-party account | USA |
| Cloud storage service | Media files (screenshots, audio clips) linked to the account | Media file storage | European Union |
| Polar Software Inc. (merchant of record) | Email, payment data (without card number), billing country | Card payment processing on the web, tax handling, billing documents | USA |
| Robokassa (payment aggregator) | Payment data (without card number) | Historical one-time card payments on the web | Russia |
| Apple (App Store In-App Purchase) | Transaction identifier, subscription status | Payment processing (iOS) | USA |
| Google (Google Play Billing) | Transaction identifier, subscription status | Payment processing (Android) | USA |
| Web analytics (Google Analytics) | Pseudonymized visit data, referral source, technical parameters | Traffic source and marketing analysis | USA |
| Mobile analytics (Firebase, Google LLC) | Aggregated usage events, app instance identifier | Usage analytics (mobile apps) | USA |
| Crash & error diagnostics (Sentry) | Crash reports, device and diagnostic data | Stability and error monitoring | USA |
6.2. The Controller does not sell or share personal data for cross-context behavioral advertising, and does not transfer personal data to third parties for their own marketing purposes.
6.3. The Controller may disclose personal data where required by a lawful request from a competent authority.
7.1. Personal data is stored on servers located within the European Union (see Section 8). Where personal data is transferred to processors located outside the European Economic Area (for example, authentication, analytics, and diagnostics providers and card payment processing via Polar in the United States, and historical card payment processing via Robokassa in Russia), such transfers are made under appropriate safeguards within the meaning of Chapter V GDPR — in particular the European Commission's Standard Contractual Clauses — or, where applicable, on the basis of the User's explicit consent.
Personal data is stored on servers located within the European Union. Media files (screenshots, audio clips) are stored in cloud storage within the European Union. Access to media files is provided via signed URLs with a limited validity period (1 hour).
| Data category | Retention period | Basis |
|---|---|---|
| Account data | Until account deletion by the User | Contract performance |
| Learning data (dictionary, cards) | Until deletion of the record by the User | Contract performance |
| Media files (screenshots, audio) | Until deletion of the corresponding record by the User | Contract performance |
| Session data | Limited period, automatic deletion | Contract performance |
| Server logs | In accordance with the log rotation policy | Legitimate interest (security) |
The Controller applies organizational and technical measures to protect personal data, including: encryption of data during storage and transmission, isolation of user data, protection against unauthorized access, restriction of the number of persons with access to personal data, and regular security reviews.
9.1. Subject to applicable law, the User has the right:
9.2. To exercise these rights, the User may:
9.3. The Controller responds to requests without undue delay and in any event within one (1) month of receipt. That period may be extended by up to two further months where necessary, taking into account the complexity and number of requests, with notice to the User.
10.1. The Service is not intended for children below the age of digital consent applicable in their country (16 in the EEA, unless a lower age, no younger than 13, is set by national law). The Controller does not knowingly collect personal data from such children without appropriate parental consent.
10.2. If the Controller becomes aware that personal data was provided by a child in breach of this Section, the Controller will take measures to delete such data.
11.1. In the event of a personal data breach, the Controller will, without undue delay and where feasible within 72 hours of becoming aware of it, notify the competent supervisory authority in accordance with Article 33 GDPR, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals.
11.2. Where the breach is likely to result in a high risk to individuals, the Controller will notify affected Users without undue delay, describing the nature of the breach, the measures taken, and recommendations for Users (Article 34 GDPR).
12.1. The Service uses a spaced repetition algorithm to automatically generate a repetition schedule based on the User's grades. This processing does not produce legal or similarly significant effects and is aimed solely at optimizing the learning process.
12.2. The Controller does not carry out automated decision-making, including profiling, that produces legal or similarly significant effects on the User within the meaning of Article 22 GDPR.
Data controller: Furtaev Ilia, Individual Entrepreneur (Republic of Armenia)
TIN: 20354437 · State registration number: 286.1599034
Email: [email protected]
14.1. This Policy is an integral part of the Terms of Service of the Linglass service.
14.2. This Policy is governed by the law of the Republic of Armenia, without prejudice to the mandatory data protection rights available to Users under the GDPR, the UK GDPR, and other applicable local law.
14.3. All questions and requests regarding the processing of personal data should be directed to [email protected].
15.1. The Controller does not sell or share personal information as defined by the CCPA/CPRA. California residents have the right to know, delete, and correct their personal information, and the right not to be discriminated against for exercising these rights. To exercise these rights, contact [email protected].