Privacy Policy
Last updated: September 3, 2026
PolyglotGym ("we", "us") operates the language-learning platform at polyglotgym.com and the PolyglotGym apps for Android, Wear OS, iPhone, Apple Watch, and Mac. This policy explains what data we collect, why, where it goes, and what choices you have. Questions and requests: [email protected].
What we collect
- Account data. Email address and a hashed password when you register, plus your chosen interface and study languages. If you continue with Google instead, Google confirms your email address to us and passes along the name and profile picture on your Google account, which become your display name and avatar until you change them. We do not receive your Google password, and signing in this way tells Google that you use PolyglotGym.
- Learning activity. Exercise results, course progress, points, streaks, achievements, vocabulary reviews, and similar gamification data. We use this to run the product: track your progress, schedule reviews, and award achievements.
- How you use the product.Which cards you open, how long a card takes, when you skip one, and how many answers in a row went wrong, so the trainer can offer help before you give up. While you are signed in we also log which pages you visited, which is what lets us retrace an account's steps when you write to us about something going wrong. These records stay with us and go nowhere else. The card-level signals are pruned after about 30 days; the page-visit history and your actual progress stay as long as your account does.
- Voice recordings. When you speak to the trainer or record a spoken answer, the clip is uploaded to our server and passed to OpenAI to be turned into text. Only the text comes back, and that text is what gets checked and, in a chat, stored. We do not keep the audio, we do not use it for advertising, and we do not train any model on it.
- AI feature inputs. If you use AI features (the AI mentor chat, conversation practice, writing feedback), the text, photos, and voice messages you submit are sent to our AI model providers to generate a response and are counted against your usage credits: text messages are processed by DeepSeek, while photos and voice messages are processed by OpenAI. Voice messages are transcribed to text and the audio is not retained. Photos you send to the mentor are kept only for the few minutes needed to process them.
- AI mentor conversations.Your chats with the AI mentor (messages and the mentor's replies) are stored so you can resume them and so the mentor can personalize its teaching from your learning profile (your languages, level, goals, and practice results). We may review conversations internally to improve quality and safety. Conversations are automatically deleted 12 months after their last activity; AI usage metrics (token counts, costs, no message content) are kept for service accounting. If you ask the trainer a question without an account, nothing you typed is stored at all: only the token count and a per-IP counter that keeps the free questions free.
- Payment records. Purchases (premium membership, dialect courses) are processed by Stripe. We never see or store your card number; we store the purchase record (what was bought, when, for how much).
- Problem reports. If you tell the trainer something is broken, we save what you said in your own words along with the card you were on, so we can reproduce and fix it.
- Technical logs. IP addresses and request metadata in server logs, used for security, rate limiting, and abuse prevention. Log retention is short and capped, and the rate-limit counters keyed on your IP address sit in a cache that expires within 48 hours.
Identifiers the website sends
- A visitor token.The first time you open the site, your browser generates a random id and keeps it in local storage. It travels with the anonymous "someone looked for this language" beacon that tells us which courses to build next, and it decides which side of an A/B test you see. If you later create an account, it is sent once at signup so the version of the site you had been using does not change under you. It is a random string and says nothing about you.
- Browser push details.If you switch on browser reminders, we store the push address your browser's own push service issues, the two keys that go with it, and your browser's user-agent string. Delivering the reminder means going through that push service, which is run by your browser vendor.
- Which client you are on.Every request carries a header saying "web" and the build version, so our own reporting can tell the site apart from the phone apps.
Identifiers the Android app sends
- A push registration. To deliver study reminders the app registers with us and sends: the Firebase Cloud Messaging token, the Android ID (the per-app, per-device id Android provides) as the device identifier, plus the platform, your app version, your Android version, and the device model and code name. Right afterwards it sends your time zone, so a reminder arrives at the hour you picked and not in the middle of your night. The registration is sent when you sign in, when the app starts while you are signed in, and whenever Firebase rotates the token. Signing out deletes it from our side.
- An install id.A random id generated the first time the app runs and kept in the app's own storage. Like the website's visitor token it picks your A/B group, and it is sent once as the signup id if you register from the app. Android's system backup copies app preferences, including this id, into your Google account; your login tokens are deliberately excluded from that backup.
- Crash reports. Release builds of the Android app send crashes and handled errors to Firebase Crashlytics, which is run by Google, together with the installation id the Firebase library creates for itself. We read them to fix crashes and nothing else.
- Because reminders travel over Firebase Cloud Messaging, Google necessarily handles the delivery of the notification itself.
Identifiers the iPhone, Apple Watch, and Mac apps send
- A push registration.The same idea as on Android: the APNs device token Apple issues, an identifier for the device, the platform, your app version, your iOS version, the device model, and then your time zone. On iPhone the device identifier is Apple's identifier for vendor, which is shared only among our own apps and is reset when you delete them. On Mac it is a random id the app generates for itself, and the device name it reports is the name you gave your Mac, which may contain your own name.
- An install id.A random id stored in the app's preferences, used for A/B assignment and sent once as the signup id if you register from the app. Deleting the app removes it.
- Nothing else.The Apple apps contain no analytics library and no crash-reporting library. They talk to polyglotgym.com and to Apple's push service, and to nowhere else.
Cookies and analytics
- Essential cookies keep you signed in and remember your language preferences. These are required for the site to work.
- Google Analytics 4 tells us which pages people actually use. It is loaded with Google Consent Mode configured so that analytics storage is on and every advertising signal is off: no advertising storage, no ad user data, no ad personalization. In plain terms, GA4 sets its own first-party cookie to recognize a returning browser and reports pages visited and an approximate region worked out from your IP address, and it receives nothing it could use to advertise to you. It does not show us your IP address, and it does not run on our admin pages. If you would rather it did not run at all, the Google Analytics opt-out browser add-on blocks it.
- Microsoft Clarity gives us heatmaps and session replays: where people click, how far they scroll, and how a page behaved while they were on it. It is how we find the button nobody can see and the step where everyone gives up. Clarity sets its own cookies and is run by Microsoft. We use it to understand pages, never to look up an individual, and it does not run on our admin pages. Any browser setting or extension that blocks trackers stops both Clarity and GA4.
We do not currently show a cookie banner, and neither tag is used for advertising.
Service providers
We share data only with the processors needed to run the service:
- Stripe - payment processing.
- Resend - delivery of our email: verification, password resets, study reminders, and the daily digest. Receives your email address and the message we send you.
- ElevenLabs and OpenAI - text-to-speech generation of course audio (course text only, no personal data).
- DeepSeek - processing of text messages you send to AI features to generate responses, under our API agreement as a processor.
- OpenAI - processing of photos and voice messages you submit to AI features, including turning a voice clip into text, under our API agreement as a processor.
- Google- site analytics (GA4); sign-in, if you choose "continue with Google"; on Android, notification delivery through Firebase Cloud Messaging and crash reporting through Crashlytics.
- Microsoft - Clarity heatmaps and session replay on the website.
- Apple - notification delivery to iPhone, Apple Watch, and Mac through the Apple Push Notification service.
- Hetzner - hosting and audio storage; servers are located in the EU.
We do not sell personal data and we do not show third-party advertising.
What we do not collect
- No advertising identifiers.The Android app never reads the Android advertising ID and does not even ask for the permission to do so. The Apple apps never read Apple's advertising identifier, which is why they never show you the "allow tracking?" prompt: there is nothing to ask about.
- No ad networks, no attribution or marketing SDKs. None of the usual advertising, attribution, or third-party product-analytics libraries are built into either app.
- No tracking across other companies' apps and sites. Nothing we collect is shared with advertisers or data brokers, and none of our identifiers can follow you outside PolyglotGym.
- No location, contacts, calendar, or health data. The apps ask only for what a language gym needs: notifications, the microphone when you speak, and the camera when you photograph something for the trainer. Photos you pick from your library are handed to us one at a time by the system picker; we have no access to the library itself.
- No card numbers. Payment details go to Stripe and never reach our servers.
How long we keep things
- Your account, your progress, and your page-visit history for as long as your account exists.
- Card-level signals (how long a card took, skips, runs of wrong answers) about 30 days.
- Trainer conversations 12 months after their last activity, then deleted automatically.
- Voice clips and photos are not stored: the clip becomes a transcript, the photo is held only for the minutes it takes to answer.
- Rate-limit and free-question counters expire within 48 hours.
- Push registrations are deleted when you sign out of the app, and with your account if you delete it.
ChatGPT app and public discovery tools
PolyglotGym exposes public, read-only discovery tools (for example via our ChatGPT app and the public MCP endpoint at /mcp). These tools only return links to public course, grammar, vocabulary, and word-list pages. They cannot access accounts, learner progress, or any private data. Requests to these endpoints are rate-limited and logged (IP-derived client key, tool name, timing) for abuse prevention only.
Your rights
You can access, correct, export, or delete your data. You can export your data directly from your profile, and delete your account from Profile → Settings → Delete account or by writing to us; see how account deletion works. Deleting removes your personal data from our active systems, including your push registrations and your trainer conversations (records we must keep for legal reasons, such as payment records, are retained in anonymized form). To exercise any of these rights, email [email protected]. If you are in the EU/EEA, you also have the right to lodge a complaint with your local supervisory authority.
Children
PolyglotGym is not directed at children under 16. We do not knowingly collect personal data from children.
Changes
We will update this page when our practices change and adjust the date above. Material changes will be announced in the product.
See also our Terms of Service.