Privacy Policy
How we collect, use, and protect your personal data (GDPR)
Last updated: 2026-06-14
1. Data Controller
The controller responsible for your personal data is:
- Name: [Egyéni vállalkozó / company name]
- Registered address: [Irányítószám, Település, Utca, Házszám]
- Tax number: [00000000-0-00]
- Email: [[email protected]]
We are a small operation (under 250 employees) and are not required to appoint a Data Protection Officer; the contact above handles all privacy requests.
2. What We Collect and Why
| Data | Examples | Legal basis |
|---|---|---|
| Account | Email, name, password hash | Contract — Art. 6(1)(b) |
| Learning | Exercise results, accuracy, response times, practice & Vocab Match sessions | Contract / legitimate interest — Art. 6(1)(b),(f) |
| Vocabulary | Words you save and their mastery status | Contract — Art. 6(1)(b) |
| Preferences | Theme, language, tutor style, learning goals | Contract — Art. 6(1)(b) |
| Analytics | Anonymous, aggregated page/feature usage | Consent — Art. 6(1)(a) |
AI conversations (tutor, role-play, debate) are processed to generate a reply and are not stored against your account. We keep an anonymized, fragmented log of AI calls for quality tuning that is deliberately not linked to you.
We do not sell your data or use it for advertising.
3. Processors & International Transfers
- OpenAI — generates AI exercises, lessons and conversations. Hosted in the USA; transfers are covered by Standard Contractual Clauses. See OpenAI's data-processing addendum.
- Resend — sends transactional email (verification, password reset, account deletion).
- Hosting & database — the application server and PostgreSQL database that store your account.
- Product-usage analytics are first-party — when you consent, anonymous, aggregated usage (which pages you visit, where you click, scroll depth, time on page) is stored in our own database and never shared with any third-party analytics provider.
Organizations may configure their own AI provider key; in that case AI requests use their key under their agreement.
4. Retention
We keep your personal data while your account is active. When you delete your account, all personal data is erased immediately (see Section 6). Anonymized analytics and the non-personal AI quality log have their own short retention and contain no identifier.
5. Cookies
We use essential storage to keep you signed in and remember your preferences. Optional analytics run only after you choose “Accept all” in the consent banner; you can change this any time in Settings → Privacy.
6. Your Rights
- Access & portability (Art. 15, 20) — export all your data as JSON from Settings.
- Erasure (Art. 17) — permanently delete your account and data from Settings.
- Rectification (Art. 16) — edit your profile in Settings.
- Objection / consent withdrawal (Art. 21, 7) — turn analytics off any time.
To exercise any right you can also email the controller above. You may lodge a complaint with the Hungarian authority (NAIH).
7. Changes
We may update this policy; material changes will be announced in-app. Continued use after an update means you accept the revised policy.