Privacy Policy
Last updated: May 22, 2026 · Effective date: May 22, 2026
Plain-language summary. We are IMPERT Konrad Bejger, a Polish business, and we are the controller of your personal data. We collect only what we need to run the Poliglotter language-learning service: your account email, your learning preferences, your activity inside the app, and (if you pay) the information our payment processor needs. We do not sell your data. We do not show third-party advertising inside the product. You can access, correct, export, or delete your data at any time by contacting us at contact@poliglotter.com.
1. Who we are
The controller of your personal data within the meaning of Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") is:
IMPERT Konrad Bejger
Magellana 6/64, 80-288 Gdańsk, Poland
NIP (Tax ID): 8781795948
Email: contact@poliglotter.com
We have not appointed a Data Protection Officer because we are not legally required to do so. You can reach the person responsible for privacy at IMPERT Konrad Bejger at the address above.
2. Scope of this policy
This policy applies to personal data we process in connection with:
- the Poliglotter browser extension for Chrome, Edge, Firefox and Safari (the "Extension");
- the Poliglotter mobile applications for iOS and Android (the "Mobile App");
- the Poliglotter website at https://www.poliglotter.com (the "Website");
- any related support, billing and communication channels we operate.
The Extension, Mobile App, Website and related services are referred to together as the "Service".
3. Data we collect
We collect only the data we need to provide the Service. We never ask for, and we do not want to receive, more personal data than is described below.
3.1 Data you give us
- Account data – email address and a password that we store only in hashed form. If you sign in with a third-party identity provider (for example Google or Apple), we receive the identifier and email address that provider shares with us, in accordance with the consents you grant in their consent screen.
- Profile and preferences – the languages you study, your declared level, learning pace, notification settings, and any other settings you adjust.
- Communications – the content of emails, support tickets and bug reports you send us, including any screenshots or shake-to-report submissions you choose to share.
3.2 Data the Service generates
- Learning activity – the phrases you see, your difficulty feedback, your streak, your test scores and other progress signals. We use this to personalise the experience and to compute statistics shown back to you.
- Technical data – the kind of device and browser you use, app version, language settings, operating system, and crash diagnostics. We use this to diagnose problems and to keep the Service reliable.
- Logs – limited server-side logs of requests to our backend (timestamp, endpoint, status code, anonymised request identifier). These help us detect abuse and debug incidents.
3.3 Data we receive from third parties
- Payment data – when you subscribe, our payment processor (Stripe, or the Apple App Store / Google Play store when you purchase through them) tells us whether the payment succeeded, the subscription tier, the renewal date and a token that identifies the transaction. We never receive or store your full card number, CVV, or bank credentials.
- Authentication data – when you sign in with a third-party identity provider, we receive the identifiers described in section 3.1.
3.4 What we do not collect
- We do not collect your contacts, photo library, calendar, microphone audio, or location.
- We do not read or store the content of the web pages or videos you watch with the Extension on our servers. The Extension processes that content locally in your browser only to inject learning phrases (see section 12).
- We do not buy personal data from data brokers and we do not enrich your profile with data from external sources.
4. Why we use your data
| Purpose | What this means in practice |
|---|---|
| Run the Service | Create your account, sign you in, sync your progress across devices, deliver learning phrases tailored to your level. |
| Personalise learning | Pick which phrases to show you next based on your prior feedback, level and pace. |
| Billing | Process subscription payments, manage renewals and refunds, send invoices, comply with tax-record obligations. |
| Support | Answer your questions, investigate and fix bugs you report. |
| Safety and abuse prevention | Detect and block fraud, automated account creation, scraping, and other misuse. |
| Service improvement | Analyse aggregated, mostly anonymous usage signals to understand which features work and where the Service can be improved. |
| Marketing communications | If you opt in, send you product updates and learning tips. You can opt out at any time using the unsubscribe link in any such message. |
| Legal obligations | Retain records required by tax, accounting and consumer-protection law and respond to lawful requests from authorities. |
5. Legal bases (GDPR)
We process your personal data on the following legal bases under Article 6 GDPR:
- Performance of a contract (Art. 6(1)(b) GDPR) – to create and run your account, deliver the Service you signed up for, and process your subscription.
- Legal obligation (Art. 6(1)(c) GDPR) – to retain invoices and tax records (Polish accounting law: 5 years after the end of the tax year), and to respond to verified requests from competent authorities.
- Legitimate interests (Art. 6(1)(f) GDPR) – to keep the Service safe and reliable, to prevent abuse, to defend ourselves against legal claims, and to understand at an aggregate level how the Service is used. You may object to this processing at any time (see section 10).
- Consent (Art. 6(1)(a) GDPR) – for optional cookies, analytics and marketing communications. You can withdraw your consent at any time without affecting processing carried out before withdrawal.
6. Who we share data with
We share personal data only with carefully selected processors that help us run the Service, and only to the extent each of them needs to perform its task. Each processor is bound by a written data processing agreement that complies with Article 28 GDPR.
| Recipient | Role | Location |
|---|---|---|
| Google Ireland Limited / Google LLC (Firebase, Google Cloud) | Authentication, database, hosting, crash reporting. | EU / United States (under EU Standard Contractual Clauses and the EU–US Data Privacy Framework). |
| Stripe Payments Europe, Limited | Subscription payment processing (Website). | EU / United States. |
| Apple Distribution International Limited | In-app subscription billing on iOS. | EU / United States. |
| Google Ireland Limited | In-app subscription billing on Android. | EU / United States. |
| Email delivery providers | Sending transactional and (if opted in) marketing emails. | EU / United States. |
| Tax advisor / accounting firm | Bookkeeping and tax filings, on a need-to-know basis. | Poland. |
We will share personal data with public authorities only when we are legally required to do so and only after we have verified the request. We will not disclose personal data in response to informal requests.
We do not sell your personal data, and we do not share it with third-party advertising networks for behavioural advertising.
7. International transfers
Some of our processors store or process data outside the European Economic Area, principally in the United States. When that happens, the transfer is protected by one or more of the following safeguards required by Chapter V GDPR:
- the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914);
- the EU–US Data Privacy Framework, where the recipient is self-certified;
- additional technical measures (encryption in transit and at rest, access controls, pseudonymisation where feasible).
You may request a copy of the safeguards we rely on by emailing contact@poliglotter.com.
8. Retention
| Category | How long we keep it |
|---|---|
| Account data and learning activity | For as long as your account is active. If you delete your account, we delete or anonymise this data within 30 days, except where law requires longer retention. |
| Billing records and invoices | 5 years after the end of the tax year in which the transaction took place, as required by Polish accounting and tax law. |
| Support communications | Up to 3 years from the last contact, then deleted. |
| Server logs | Up to 90 days, then deleted or aggregated to non-personal statistics. |
| Marketing opt-in records | Until you opt out, plus a reasonable period to prove that the opt-in was given. |
9. Security
We use industry-standard technical and organisational measures to protect personal data, including TLS for data in transit, encryption at rest for sensitive fields, hashing of passwords with a modern algorithm, role-based access controls, infrastructure isolation, and routine review of access logs. Despite our efforts no method of internet transmission or electronic storage is 100% secure, so we cannot guarantee absolute security. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and, where required, notify you without undue delay.
10. Your rights
Subject to applicable law, you have the following rights regarding your personal data:
- Access (Art. 15 GDPR) – obtain a copy of the personal data we hold about you.
- Rectification (Art. 16 GDPR) – correct inaccurate or incomplete data.
- Erasure / "right to be forgotten" (Art. 17 GDPR) – delete data we no longer need, unless we must keep it by law.
- Restriction of processing (Art. 18 GDPR).
- Data portability (Art. 20 GDPR) – receive your data in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible.
- Objection (Art. 21 GDPR) – object to processing based on legitimate interests; we will stop unless we can show compelling overriding grounds.
- Withdrawal of consent (Art. 7(3) GDPR) – for processing that is based on your consent, at any time and without affecting processing done before withdrawal.
- No automated individual decisions (Art. 22 GDPR) – not be subject to a decision based solely on automated processing that produces legal effects or similarly significant effects on you. We do not make such decisions (see section 15).
To exercise any of these rights, write to contact@poliglotter.com from the email address linked to your account. We will respond within 30 days and, where the request is complex, may extend that period by up to two months while informing you of the extension and its reasons. We do not charge a fee for handling requests unless they are manifestly unfounded or excessive.
11. Cookies and similar technologies
On the Website we use:
- Strictly necessary cookies / storage – needed to remember your session, your language and your theme. These do not require consent.
- Analytics and marketing cookies – only set after you give explicit consent through our cookie banner. You can change your choice at any time from the banner.
The Extension and the Mobile App use local storage on your device to remember preferences and offline state. They do not set tracking cookies.
12. The browser extension
The Extension reads the content of the page you are looking at solely to detect text into which it can inject Poliglotter learning phrases. That content is processed locally inside your browser. We do not transmit the content of the pages you read to our servers, we do not store it, and we do not share it with any third party. The Extension requests the minimum browser permissions required to perform that task. Page content never leaves your device through Poliglotter.
To the extent the Extension is distributed through the Chrome Web Store, the Microsoft Add-ons store, Firefox Add-ons or the Apple App Store, we comply with the developer programme policies of each store, including the disclosures they require about data handling.
13. The mobile app
The Mobile App processes the same categories of data as the Extension and the Website, but it does not read the content of other apps you use. Crash and performance diagnostics are collected via Firebase Crashlytics; they identify the app version, the device model and the line of code where the crash occurred, but not your account email or learning content. On iOS and Android we declare the categories of data we collect in the privacy nutrition label / Data Safety section of the App Store and Google Play, in line with Apple App Store Review Guideline 5.1 and the Google Play Data Safety policy.
14. Children
The Service is not directed at children under 16. We do not knowingly collect personal data from anyone under 16 without verifiable parental consent. If you believe a child has provided us with personal data without that consent, please email us at contact@poliglotter.com and we will delete it promptly.
15. Automated decisions and profiling
We use rule-based and statistical algorithms to recommend which phrases to study and to estimate your difficulty level, so that the Service feels personal. These decisions do not have legal effects on you and do not similarly significantly affect you within the meaning of Article 22 GDPR. You can always override our recommendations from within the product, and you can request that a human re-examine any decision the Service has made by emailing us.
16. Changes to this policy
We may update this Privacy Policy from time to time, for example to reflect changes in the law or in the Service. When the change is significant, we will tell you in advance — by email to your account address, by a banner inside the product, or by both — at least 30 days before the change takes effect, so that you have time to review it and, if you disagree, to delete your account. The "Last updated" date at the top of this page always shows when this version came into force.
17. Complaints
If you believe that we have processed your personal data in breach of the law, please contact us first at contact@poliglotter.com — we will do our best to resolve the issue. You also have the right at any time to lodge a complaint with a supervisory authority. In Poland this is:
President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych)
ul. Stawki 2, 00-193 Warsaw, Poland
uodo.gov.pl
If you live in another EU/EEA country, you can also lodge a complaint with the supervisory authority of your habitual residence, place of work, or the place where the alleged infringement took place.
18. Contact
For any privacy question, please contact:
IMPERT Konrad Bejger
Magellana 6/64, 80-288 Gdańsk, Poland
NIP: 8781795948
contact@poliglotter.com