Privacy Policy

Last updated: 10 March 2026

Effective date: 10 April 2026

Vocab Magnet is committed to protecting your privacy. This policy explains what data we collect, how we use it, and what rights you have over it.

1. What Information Do We Collect?

We only collect the minimum amount of personal data necessary to operate the service (data minimization principle).

Registered Accounts (Google & Facebook login)

  • Email address - Retrieved from your Facebook or Google OAuth login. Used to identify your account and send service-related messages. Source: Provided by the OAuth provider (Google/Facebook) when you authenticate.
  • Timezone - The timezone where the user is located (derived from your browser or device settings). Used for the functionality of features like daily streak and plotting statistic graphs.
  • Subscription status - Whether you have an active Premium subscription.
  • Billing interval - If you have an active Premium subscription, how often billing occurs (monthly, quarterly, or annually). Paddle handles all sensitive payment data - we never see your card details.
  • Paddle customer reference ID - A unique identifier assigned by our payment processor Paddle when you purchase a subscription. This is used solely to manage your subscription (e.g. cancellations, billing status). It is not a payment method and does not contain any financial data.

Guest (Anonymous) Accounts

You can use Vocab Magnet without providing any personal data by signing up as a Guest. No email address, name, or any other identifying information is collected.

  • No email or name - We never receive or store any personal identifier for Guest accounts.
  • Session-bound data - Your learning progress is tied to an anonymous session ID. When you sign out, your session is immediately invalidated. Any remaining data records are permanently purged from our database within 30 days of your last activity. This data cannot be recovered after sign-out. If you wish to export your data, you must do so before signing out (see Section 6). If you with to keep your data, you must link your account to Google or Facebook, which is possible at all times in the profile settings page.
  • To preserve your progress, you can link your Guest account to Google or Facebook at any time from your profile page. Once linked, your data is retained under the rules for registered accounts.

Learning Data

This data is collected for both permanent and guest accounts, but for Guests it is tied only to an anonymous ID.

  • Study progress - Words reviewed along with the level of difficulty marked.
  • Custom words - Any vocabulary you add yourself.
  • Settings & preferences - Your in-app configuration.

Contact Form Data

This data is only collected when you use the feedback form which is accessible from most pages. We don't attach any information about your current session.

  • Email - The email address that you list in the form. We need this information to contact you back about your inquiry.
  • Message content - Your inquiry or feedback.

Analytics Data

  • Usage analytics - Pages visited, features used, settings changed (via Umami Analytics).
  • Browser/device info - Browser type, device type, operating system (privacy-friendly, pseudonymized analytics that do not directly identify users, no IP tracking).

Provision of data: For registered accounts, your email address, timezone, and learning data are necessary to create an account and provide the core service. Without this information, we cannot offer you a linked Vocab Magnet account. Guest accounts require no directly identifying personal data - only anonymous session data is stored.

2. How Do We Use Your Data? (Legal Basis)

Under the General Data Protection Regulation (GDPR), we must have a valid legal basis for each processing activity. Below we explain the purposes and the corresponding legal bases.

To provide and improve the service

Your learning data powers Vocab Magnet's core functionality - spaced repetition, streak tracking, and personalised study sessions. This applies to both Guest and registered accounts.

Legal basis: Performance of a contract (Art. 6(1)(b) GDPR) - necessary to deliver the service you have requested.

To process payments

Paddle handles subscription billing. We only see your subscription status and a Paddle customer reference ID to manage your subscription - not your payment details or address.

Legal basis: Performance of a contract (Art. 6(1)(b) GDPR) - necessary to fulfil your paid subscription.

To respond to your inquiries

When you use our contact form, we use your email and message to help resolve your issue and contact you back. No account or session information is collected when you use the contact form.

Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) - responding to user inquiries and providing support.

To improve the application

Privacy-friendly, pseudonymized analytics that do not directly identify users (via Umami) help us understand which features are used and where to focus development.

Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) - improving our service based on aggregated, non‑personal usage data.

Automated decision‑making

We do not use automated decision‑making, including profiling, that produces legal or similarly significant effects concerning you.

We do not:

  • Sell your data to third parties.
  • Share your learning data with advertisers.
  • Use your data for targeted advertising or marketing.
  • Store any payment information.

3. Who Has Access to Your Data?

We do not sell your data to anyone. We work with the following trusted third-party providers to operate Vocab Magnet. Each has been selected for GDPR compliance.

Vercel – Hosting & Infrastructure

Vercel hosts the Vocab Magnet application and provides built‑in analytics tools. All data is encrypted in transit and at rest.

  • Provider: Vercel Inc. (US‑based).
  • Infrastructure: Vercel primarily uses Amazon Web Services (AWS) data centers.
  • Hosting location: We have configured our deployment to use servers located in Frankfurt, Germany (fra1) to keep data within the European Union. Static assets may be cached globally on Vercel's content delivery network.
  • Vercel Web Analytics & Speed Insights: These tools collect usage data (pages visited, device type, browser, country‑level location) to help us improve the app. They do not use cookies and do not track individuals across websites. Visitor identification is based on a daily‑resetting hash, not personal data. They are designed to avoid direct identification of individual users.
  • Data retention: Analytics data is retained by Vercel as described in their privacy policy; session data is discarded after 24 hours.
  • Vercel Compliance OverviewPrivacy PolicyData Processing Addendum

Supabase - Database & Authentication

Stores your account, learning progress, and custom words. All data is encrypted at rest and in transit. Also handles anonymous Guest sessions.

  • Data stored: Email, learning data, custom words, subscription status, Paddle customer reference ID (registered accounts); anonymous session data only (Guest accounts).
  • Encryption: AES-256 at rest, HTTPS in transit.
  • Location: Hosted within the European Union (EU) using Supabase-managed infrastructure.
  • Supabase Privacy Policy

Paddle - Payment Processing

Handles all subscription billing as our Merchant of Record. Paddle is PCI DSS compliant. We never see or store your payment details.

  • Data handled by Paddle: Payment method, billing address, transaction history.
  • Not shared with us: Card numbers, CVV, or full payment details. We receive only your subscription status and a Paddle customer reference ID.
  • Paddle Privacy Policy

Facebook - OAuth Authentication

Provides secure login. Facebook does not share your password with Vocab Magnet.

Google - OAuth Authentication

Provides secure login. Google does not share your password with Vocab Magnet.

  • Data accessed: Email only.
  • Not accessed: Contacts, calendar, emails, Google Drive, or passwords.
  • Google Privacy Policy

hCaptcha - Spam Protection

Protects anonymous Guest account creation from bot signups and abuse. hCaptcha processes certain technical data (such as IP address and browser information) to determine whether a request is made by a human user. We never store this data.

  • Data used: Used to determine whether a request is made by a human user. Data handling is governed by hCaptcha's privacy policy.
  • hCaptcha Privacy Policy

Formcarry - Contact Form

Transmits contact form messages securely to our support team. Formcarry stores form submissions temporarily on servers located in Frankfurt, Germany, before forwarding them to our email.

  • Data transmitted: Email and message content only.
  • Temporary storage: Formcarry may retain access and security logs for a limited period (typically up to 30 days) to ensure the integrity and security of their service, after which they are deleted.
  • Formcarry Privacy Policy

Umami - Analytics

We use Umami Cloud, a privacy-focused analytics service, to understand how visitors use our site. Umami is cookieless, does not track individuals across websites, and is designed with strong privacy protections and GDPR considerations. Analytics data is pseudonymized and designed to avoid identifying individual users.

  • Provider: Umami Software, Inc. (US-based).
  • Data tracked: Pseudonymized page view statistics, features used, device and browser type. Your identity is never recorded.
  • Server location: We have configured our Umami Cloud account to use servers located within the European Union.
  • Data retention: Under our current (free) Hobby plan, Umami Cloud automatically deletes analytics data after 180 days.
  • Umami Privacy Policy

Cookies & Tracking Technologies

Vocab Magnet does not use tracking cookies or advertising cookies.

Some infrastructure providers may use essential cookies that are required for security, authentication, and basic service functionality. These cookies are strictly necessary for the operation of the website and cannot be disabled.

Our analytics tools (Vercel Web Analytics and Umami) operate without tracking cookies and are designed to avoid identifying individual users.

Legal Disclosure

If required by law (e.g., via court order or subpoena), we may be required to disclose your data to government agencies or courts. We will notify you of such requests unless legally prohibited from doing so.

4. International Data Transfers

Vocab Magnet is based in Germany. Some of our service providers operate outside the European Union:

  • Paddle (payment processing) - based in the UK and USA. Transfers are governed by EU Standard Contractual Clauses (SCCs).
  • Supabase (database) - We have configured our Supabase project to use infrastructure located within the European Union. Supabase Inc. is a US company and may access data for support purposes. Transfers are protected by Standard Contractual Clauses.
  • Umami (analytics) - provided by Umami Software, Inc. (US-based). We have selected EU servers for data processing, and the service is designed to be GDPR-compliant with minimal pseudonymized usage data collected.

All such transfers are protected by appropriate safeguards, including the EU Standard Contractual Clauses (2021/914) approved by the European Commission, ensuring your data receives equivalent protection regardless of where it is processed.

5. Data Retention

Guest (Anonymous) accounts

When you sign out of a Guest account, your session is immediately invalidated and you can no longer access it. Any associated data records (learning progress, custom words) are permanently purged from our database within 30 days of your last activity, as part of our routine anonymous account cleanup process. This data cannot be recovered after sign-out. If you wish to export your learning data, you must do so before signing out (see Section 6). If you wish to make your learning data permanent, you must link your account to Google or Facebook, which can be done from your profile settings page.

While your registered account is active

We retain all your learning data, custom words, and account information as long as your account exists. This data is essential for the service to function.

After account deletion

When you delete your account, we initiate permanent removal of your data within 30 days. Residual copies may remain in our backups for up to 90 days, after which they are permanently erased. You may delete your account at any time from your account settings. Please note that if you have an active Premium subscription, you must cancel it before deleting your account. You can do this from your profile settings page.

Internal audit log

For security and operational integrity, we maintain an internal log of account deletion events (e.g. the date an anonymous account was cleaned up). For anonymous accounts, this log does not contain any personal data — only the timestamp and type of event. For registered accounts, it may contain the account's email address. This log is used solely for debugging and abuse prevention and is not shared with any third party.

Analytics & server logs

We use two privacy-focused analytics tools to understand how the application is used and to improve the service:

  • Vercel Web Analytics – Provides infrastructure-level metrics such as page views, browser type, and device information. Session-level analytics data is discarded after approximately 24 hours. Infrastructure and security logs may be retained for up to 30 days.
  • Umami Analytics – Used to analyze feature usage and application behavior. Umami operates without cookies and does not track users across websites. Analytics data collected through Umami Cloud is retained for up to 180 days, which corresponds to the retention period of our current plan.

Contact form submissions

When you use our contact form, the data you provide is sent to us via email through Formcarry, which acts as our data processor. Formcarry stores form submissions temporarily on servers located in Frankfurt, Germany, before forwarding them to our email. We do not store the submission data in any database. The email containing your inquiry is kept only as long as needed to respond and resolve your request, and is deleted within 90 days after the matter has been resolved, unless we are legally required to retain it. Formcarry may retain access and security logs for up to 30 days for security and debugging purposes, after which they are deleted. For more information on how Formcarry handles your data, please see their Privacy Policy.

6. Your Rights (GDPR)

As a user - particularly within the European Union - you have the following rights under the General Data Protection Regulation (GDPR):

Right to Access

You can request a copy of all data we hold about you.

Right to Rectification

You can correct or update inaccurate personal data at any time.

Right to Erasure

You can request deletion of your account and all associated data ("Right to be Forgotten"). For Guest accounts, signing out immediately invalidates your session, and all remaining data is purged within 30 days.

Right to Data Portability

You may request a copy of your User Content (learning data, custom words) at any time. We will provide your data in a commonly used, machine‑readable format within 30 days of your request. This right applies to both registered and Guest accounts - for Guests, you must request the export before signing out, as data is purged within 30 days of your last activity. If a self‑service export feature becomes available, we will notify users accordingly.

Right to Object

You can object to processing of your data, including for analytics. Since our analytics are pseudonymized and do not directly identify individuals, no directly identifying personal data is involved in that processing. For essential service data (account, learning progress), the right to object does not apply because processing is necessary for the contract. If you still wish to opt out of analytics, you can use browser extensions that block analytics scripts or contact us for assistance.

Right to Lodge a Complaint

You may lodge a complaint with your local supervisory authority. In Germany this is the data protection authority of your federal state.

To exercise any of these rights, contact us at contact@vocabmagnet.com. We will respond within 30 days as required by GDPR.

7. Security

Encryption

All data in transit uses HTTPS. Data at rest in Supabase is encrypted with AES-256 and in transit via TLS.

Row-Level Security

Supabase's Row-Level Security (RLS) policies ensure you can only access your own data, not any other user's. This applies to both registered and Guest accounts.

Authentication

We use industry-standard OAuth 2.0 via Google and Facebook. Your password is managed by Google and Facebook, we never store it. Guest accounts use anonymous sessions managed entirely by Supabase with no credentials required.

Limitations

While we implement reasonable security measures, no system is entirely immune to risk. We select reputable providers and require appropriate security measures, but breaches affecting third-party infrastructure are ultimately controlled by those providers. We will never ask for your password or sensitive information.

Breach Notification

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours, as required by law.

8. Children's Privacy

Vocab Magnet is not intended for children under 16. We do not knowingly collect personal data from children under 16. If we become aware that we have inadvertently collected such data, we will delete it immediately.

Parents or guardians who believe their child has provided personal data to us should contact us at contact@vocabmagnet.com.

9. Contact Us & Controller

If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:

Controller

João Victor Kalva Tavares
Rykestraße 24, 10405 Berlin
Germany

Country

Germany

Response Time

Typically within 5-7 business days. GDPR requests are handled within 30 days.

For payment-related inquiries, you may also contact Paddle directly at paddle.com.

10. Additional Information for California Residents

If you are a resident of California, the California Consumer Privacy Act (CCPA) provides you with additional rights regarding your personal information. This section applies only to California residents.

  • Right to Know: You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which it was collected, the business purpose for collecting it, and the categories of third parties with whom we have shared it.
  • Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions.
  • Right to Opt-Out of Sale: Vocab Magnet does not sell your personal information.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.

To exercise your CCPA rights, please contact us at contact@vocabmagnet.com. We will verify your request using the information associated with your account, or by other means if necessary. You may also designate an authorized agent to make a request on your behalf.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through an in‑app notice at least 30 days in advance. The date at the top of this policy will always show when it was last updated.