Skip to main content

Privacy Policy

 

April 2025

1. Introduction

At Shapedeep we are committed to protecting your privacy as we develop our language learning app. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our app and website.

We are a new company founded by Ender Temizdemir with the mission of making language learning fun and accessible to all. We want to be fully transparent about our data practices from the very beginning and ensure that privacy is built into our app by design.

This Privacy Policy applies to information we collect when you use our mobile application and website (collectively, the “Services”). It does not apply to information collected by any third party, including through any application or content that may link to or be accessible from the Services.

Please read this Privacy Policy carefully. By accessing or using our Services, you agree to this Privacy Policy. If you do not agree with our policies and practices, do not download, register with, or use our Services. This policy may change from time to time (see Changes to This Privacy Policy). Your continued use of our Services after we make changes is deemed to be acceptance of those changes, so please check the policy periodically for updates.

Our Commitment to You

As a new company, we rely on building trust and providing an excellent user experience. Protecting your privacy is core to that mission. To that end:

  • We only collect the minimum amount of personal information necessary to provide our Services.
  • We do not sell your personal information to third parties.
  • We use strict security measures to safeguard the data we do collect.
  • We strive to be fully transparent about our data practices in this Privacy Policy.
  • We will never materially change our privacy practices to make them less protective of your information without first getting your consent.

If you have any questions about this Privacy Policy or our privacy practices, please contact us at privacy@shapedeep.com.

Our Commitment to Protecting Your Privacy at Shapedeep, protecting your privacy is fundamental to everything we do. We recognize that as a new startup, we must build trust with our users from day one. You are entrusting us with your personal information, and we do not take that responsibility lightly. We are committed to:

  • Collecting only the minimum amount of data necessary to provide you with a great language learning experience. We carefully evaluate each piece of information we request to ensure it serves a legitimate purpose.
  • Being fully transparent about what data we collect, how we use it, who we share it with, and how we keep it secure. We lay out all of these details clearly in this Privacy Policy. If our practices ever materially change, we will notify you and give you a chance to opt-out.
  • Never selling your personal information to third parties. As a bootstrapped company, we are committed to finding sustainable revenue streams that align with our values.
  • Promptly notifying you in the unlikely event of a data breach. We will be open and honest about what happened, what information was involved, and what we are doing to remediate the situation.
  • Giving you control over your data. We make it easy for you to access, correct, or delete your personal information. If you have any privacy concerns, you can always reach out to us directly at privacy@shapedeep.com.

As a new company, your trust means everything to us. We are building privacy into the core of our language learning app, not as an afterthought. Protecting your personal information will always be a top priority as we grow and evolve. Thank you for joining us on this journey as we strive to make language learning accessible to all.

2. Information We Receive and Process

2.1 Personal Information Provided During Account Registration

When you sign up for an account to use our language learning app, we collect certain personal information from you that is necessary to create and manage your account. This includes:

  • Your name
  • Your email address
  • A password that you create

We require this basic information to set up your unique user account, allow you to log in securely, and to communicate with you about your account or our services if needed.

Your email address also acts as your username to access the app. We may use this to send you important account-related messages, such as password reset emails, billing or subscription notices, or important updates to our Terms of Service or Privacy Policy. You can unsubscribe from promotional emails, but we reserve the right to contact you with critical account-related information.

Your password is hashed using industry-standard encryption before it is stored, meaning we never have access to your actual password, only a scrambled version used to verify your login attempts. We recommend you use a strong, unique password not used on any other sites.

We collect the minimum amount of personal information at signup required to establish and maintain your account. You may choose to add additional details to your account profile, such as a profile picture or biography, but these fields are optional. We’ll never require you to disclose more information than is necessary to use the core functions of the app.

The personal information you provide at registration is used only for the purposes outlined in this Privacy Policy. It is never sold to third parties or used for any undisclosed purposes. Please see the other sections of this Policy for full details on how we collect, use, disclose and protect your personal information.

If you choose to subscribe to a paid plan or make a purchase within our language learning app, we will collect certain payment information from you to process the transaction. This may include:

  • Credit/debit card details (card number, expiration date, security code)
  • Billing name and address
  • Payment amount and currency
  • Transaction date and time

We rely on trusted third-party payment processors to securely handle this sensitive financial information. Your full credit card details are never stored on our servers. Instead, the payment processor provides us with a unique token that represents your account, which we store and can use for future transactions with your permission. When you submit payment information through our app, it is encrypted using secure socket layer technology (SSL) and sent directly to our payment processor over a secure connection. The payment processor then communicates back to us whether the transaction was approved or declined based on the information provided. We collect and use this payment data, based on the legal grounds of performance of a contract and compliance with legal obligations, for the following purposes:

  • To charge you for the cost of the subscription or purchase you initiated
  • To provide you access to the paid features and content you subscribed to
  • To send you invoices, receipts, and other transaction-related communications
  • To comply with financial reporting and bookkeeping requirements
  • To prevent fraudulent transactions and unauthorized access to paid content

Your payment information is considered confidential and is never sold or shared with third parties for marketing purposes. It is only used to process payments you have authorized and to prevent fraud or abuse of our paid services. We retain information about transactions for as long as needed for tax and accounting purposes and to resolve any potential billing disputes. However, we do not retain your complete credit card number, which is held by the payment processor in compliance with strict financial industry standards. Please see the other sections of this Privacy Policy for information on your rights to access, update and delete data we hold about you. If you have any questions or concerns about the security of your payment information, please contact us at privacy@shapedeep.com.

2.2 App Usage Data and Analytics

When you use our language learning app, we collect certain information about your interactions with the app. This is known as “usage data” or “analytics data.” It helps us understand how people are using the app, identify areas for improvement, and measure the effectiveness of new features.

The usage data we collect may include:

  • Which lessons, exercises and activities you access
  • How long you spend on each screen or task
  • Your learning progress over time
  • Which app features you use most often
  • Crash reports and error logs
  • Device information like operating system and app version

This data is tied to your user account. It allows us to personalize your learning experience, such as by suggesting relevant lessons or adjusting the difficulty based on your past performance.

We use third-party analytics services, such as Google Analytics, to collect and analyze this usage data. These services use cookies and similar tracking technologies. The data they collect is aggregated and anonymized, meaning it cannot be tied back to you as an individual user. You can opt out of this tracking using the settings in the app or on your device.

We may use usage data and analytics, based on the legal ground of legitimate interest, for the following purposes:

  • To provide and maintain the core functions of the app
  • To personalize and optimize your learning experience
  • To understand and analyze trends in how the app is used
  • To measure the effectiveness of new features and identify areas for improvement
  • To diagnose technical issues and ensure the app is working properly

This data is necessary for us to operate and improve the app. Where required by law, we will obtain your consent before collecting this data.

We take steps to pseudonymize and aggregate usage data where possible. Pseudonymization means replacing personally identifying information with a pseudonym, so the data cannot be tied to a specific user without additional information. Aggregation means combining data from many users so individuals cannot be identified.

Protecting your privacy is very important to us. We will never sell your usage data to third parties or use it for any undisclosed purposes. Please see the other sections of this Privacy Policy for more details on how we protect the information we collect.

2.3 Device Information Collected

When you access our language learning app, we collect certain information about the device you are using. This may include:

  • Device type (e.g. smartphone, tablet, computer)
  • Operating system and version (e.g. iOS 15, Android 12, Windows 11)
  • Browser type and version (e.g. Chrome, Safari, Firefox)
  • Screen resolution
  • IP address
  • Mobile device identifiers (e.g. Apple IDFA, Android Advertising ID)
  • Mobile carrier

We collect this device information for a few important purposes:

  • To optimize the app experience for your specific device type and screen size
  • To diagnose technical issues and ensure the app is working properly on different devices
  • To prevent fraud and unauthorized access by detecting suspicious login attempts from unfamiliar devices
  • To analyze usage trends across different device types to inform future app development

We use this device data in aggregated and anonymized form wherever possible. This means we combine the data from many individual users so that it cannot be tied back to a specific person. We also hash device identifiers to protect your privacy.

We do not use this device data to personally identify you, build detailed user profiles, or track your activity outside of the app. We will never sell your device information to advertisers or other third parties.

The device information we collect may be stored on servers outside your country of residence, as we use third-party services and cloud platforms to process and store data. These service providers may transfer, store, and process your information in countries where their servers are located, such as the United States and other countries.

We carefully select reputable service providers that demonstrate a commitment to data protection and comply with applicable privacy laws, such as the General Data Protection Regulation (GDPR) in the European Union. These providers employ appropriate technical and organizational measures to ensure the security and confidentiality of your data.

By using our app, you acknowledge and consent to the potential transfer, storage, and processing of your information outside your country of residence.

2.4 Cookies and Similar Tracking Technologies

Our language learning app and website use cookies and similar tracking technologies to collect certain information about your device and your interactions with our services.

Cookies are small data files stored on your device when you use our app or visit our website. They allow us to recognize your device and store some information about your preferences or past actions. We use a few main types of cookies and tracking:

  • Essential cookies that are necessary for the app and website to function properly
  • Analytics cookies that help us understand how users interact with our services so we can make improvements
  • Advertising cookies that our advertising partners may use to display more relevant ads and measure their effectiveness

For a complete list of the specific cookies we use, their purposes, and your choices for managing them, please see our Cookie Policy.
You can restrict the use of cookies and tracking technologies in a few ways:

  • Use the cookie consent tools in our app and website to adjust your preferences at any time
  • Change your device settings to opt out of interest-based advertising or reset your ad identifier
  • Configure your web browser to block some or all cookies
  • Install browser extensions that block certain trackers

Please be aware that limiting cookies may impact the functionality of certain features that rely on them. However, you will still be able to use the core functions of the app.

We are committed to honoring your preferences regarding cookies and tracking to the extent required by law and technically feasible. If you have any questions, please contact us at privacy@shapedeep.com.

3. How We Use Your Information

3.1 Providing and Improving Our Language Learning Services

The main reason we collect and use your personal information is to deliver the language learning services you request and to continually enhance your experience with our app. Specifically, we use your information to:

  • Create and manage your account when you sign up for the app
  • Provide access to the language lessons, exercises, and other learning content
  • Sync your progress across devices so you can learn seamlessly on mobile or web
  • Communicate with you about your account, subscription, or learning activity
  • Provide customer support and respond to your questions or concerns

Using your information in these ways is essential for us to fulfill our contract with you when you register for an account. Collecting data on how you use the app also helps us get insights to make the learning experience better for you and all our users.

For example, if we see many users struggling with certain lessons, that signals to us that we need to improve the content or user interface. Or if we notice that reminder notifications increase learning frequency, we may expand that feature.

3.2 Communicating with You About Your Account and Our App

One of the key ways we use the personal information we collect is to communicate with you about important matters related to your account and use of our language learning app. This includes:

  • Sending you welcome emails and onboarding information when you first sign up
  • Providing you with transaction receipts, invoices, and billing-related notices
  • Notifying you about important updates to our Terms of Service or this Privacy Policy
  • Alerting you of suspicious account activity or security issues
  • Delivering announcements about new app features, content, or learning resources
  • Checking in on your language learning progress and offering study reminders
  • Requesting your feedback through occasional surveys about the app experience
  • Responding to your customer support inquiries and reported issues

We primarily communicate with you via email using the address associated with your account. Please keep your contact information up-to-date and add our sending address to your contacts to ensure you receive our messages. You can manage your email preferences or unsubscribe from certain communications in your account settings, but please note that you cannot opt out of receiving critical messages related to your account, purchases, or legal notices.

As a new company, being able to communicate with our users is essential for providing a great experience with our app and cultivating a community of passionate language learners. At the same time, we are mindful not to overload your inbox and aim to send only relevant, valuable messages. Your trust means everything to us and we will never sell or rent your contact information to third parties for their own marketing purposes.

3.3 Providing Customer Support

We are committed to providing great customer support to ensure your satisfaction. We use the personal information we collect to respond to your inquiries, troubleshoot issues, and ensure you have the best possible experience with our language learning app. Specifically, we may use your information to:

  • Access your account to investigate and resolve any reported bugs, glitches or outages
  • Respond to your emails requesting assistance
  • Process and fulfill any refund requests in accordance with our policies
  • Gather additional details from you to reproduce and fix reported app malfunctions
  • Notify you when an issue you reported has been resolved in an app update
  • Solicit your feedback on how we handled your support inquiry to improve our processes
  • Analyze support inquiries for common themes to proactively improve our app and support materials

When you contact us for support, we may ask you to confirm certain account information like your name, email address, and recent activity so we can verify it is actually you making the request. This is an important security measure to protect your account.

We will only access your personal account details to the extent needed to resolve your support inquiry. While we aim to resolve all support matters ourselves, we may need to share some of your personal information with third party service providers, like our payment processor if there is an issue with your subscription charge, or our hosting provider if there is a server outage. Where required by law, we will ask for your consent before accessing sensitive account information to resolve a support matter.

We retain support inquiry information for as long as needed to resolve your issue and for a short period afterwards in case any follow up is needed. Then the information is deleted or anonymized. We may retain non-personal information about support matters for analytics and app improvement purposes.

3.4 Conducting Research and Analytics

As a startup, understanding how users interact with our language learning app is critical for us to improve the user experience, fix issues, and develop new features that meet learners’ needs. To gain these insights, we collect and analyze certain information about your app usage. This includes:

  • Which lessons, exercises and app features you use most often
  • How long you spend on each screen or learning task
  • Your learning progress over time
  • Patterns in when you typically use the app (e.g. time of day, frequency)
  • Technical data like crash reports and error logs

We use this usage data in aggregated and anonymized form wherever possible. This means we combine the data from many users so it cannot be tied back to any one individual. We may also pseudonymize the data by replacing identifying information with a code. Some specific ways we use this aggregated, anonymized usage data include:

  • Identifying the most and least popular lessons to prioritize content improvements
  • Analyzing usage patterns of high-progress users to optimize the learning paths
  • Measuring the impact of new features on engagement and learning outcomes
  • Finding and fixing the causes behind frequently reported bugs and crashes
  • Forecasting infrastructure needs as our user base grows

We engage carefully vetted third-party analytics services, such as Google Analytics, to assist with this usage data collection and analysis. These providers are under strict contractual obligations to keep the data secure and never use it for other purposes. You can opt out of this tracking in your app settings. We are committed to only collecting and analyzing app usage data to the extent that it helps us improve our service for you. We never sell this data to advertisers or other third parties. Please see the other sections of this Privacy Policy for full details on how we protect the information we collect.

Where required by law, we will obtain your consent before collecting usage data. We are committed to only collecting and analyzing app usage data to the extent that it helps us improve our service for you. We never sell this data to advertisers or other third parties.

3.5 Marketing and Promotional Purposes

As a startup, spreading the word about our language learning app and attracting new users is critical for our growth and success. We use some of the information we collect for marketing and promotional purposes, but always with respect for your privacy choices. When we have obtained your explicit opt-in consent, and based on that consent, we may use your information to:

  • Send you newsletters, special offers, and promotional content if you have opted in to receive such communications. We use your email address to deliver this content. You can unsubscribe at any time using the link in the emails.

Based on our legitimate interest in growing and improving our offering in a privacy-preserving way, we may also use your information to:

  • Analyze the effectiveness of our marketing campaigns and make improvements. We look at metrics like open rates, clicks and conversions to understand what content resonates with our audience. This analysis is done on an aggregate level, not at an individual level.
  • Identify potential brand ambassadors and invite them to special events or programs. If you are a highly engaged user, we may reach out to you with such opportunities. Participation is always voluntary.
  • Conduct market research and user surveys to gather feedback. We may email you invitations to provide your opinion, which helps us improve. Responses are anonymized before analysis.

We will never sell your personal information to third parties for their own marketing purposes. Any promotional content we send directly will come from us. You have control over your marketing preferences and can opt out of receiving promotional communications at any time.

4. Information Sharing and Disclosure

4.1 Service Providers and Vendors That Assist in Operating the App

As a startup, we rely on carefully selected third-party service providers and vendors to help us develop, maintain, and improve our language learning app. We may share certain personal information with these providers in order for them to perform services on our behalf. However, these providers are bound by strict data processing agreements that limit their use of the information we share to only what is necessary to provide the contracted services. Some examples of the types of service providers we may share information with include:

  • Cloud hosting providers that store and serve our app data and content
  • Analytics platforms that help us understand app usage patterns and user behavior
  • Payment processors that securely handle subscription and purchase transactions
  • Email and push notification services that deliver important app communications

We only share the minimum information required for these providers to perform their designated functions. They are not permitted to use the information we share for their own independent purposes, such as marketing or user profiling. We also require that they maintain appropriate security measures to protect the confidentiality and integrity of the data we entrust to them.

Many of our service providers are located and process data in Germany or other countries outside of where our users reside. We utilize standard contractual clauses, data processing agreements, and other approved data transfer mechanisms to ensure user information remains protected when processed in other jurisdictions. We do not sell user personal information to any third parties. Any sharing of data with service providers is purely to operate and improve the app experience for our users.

4.2 Legal Obligations and Law Enforcement Requests

As a company, we are committed to complying with our legal obligations and cooperating with law enforcement when appropriate. In certain situations, we may be required to disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. Specific circumstances where we may share your information include:

  • When required by law, such as in response to valid legal process, including subpoenas, court orders, or search warrants. We carefully review all requests to ensure they satisfy legal requirements before complying.
  • To protect our rights, privacy, safety or property, and/or that of our affiliates, you or others. This includes exchanging information with other companies and organizations for fraud protection and risk reduction.
  • If we believe disclosure is necessary or appropriate to prevent physical harm or financial loss, or in connection with an investigation of suspected or actual fraudulent or illegal activity.
  • In the event we sell or transfer all or a portion of our business or assets. Should such a sale or transfer occur, we will use reasonable efforts to direct the transferee to use the personal information you have provided to us in a manner that is consistent with our Privacy Policy.

We may also share aggregated or de-identified information, which cannot reasonably be used to identify you. This falls outside the definition of personal data and is not subject to the same legal restrictions. When we are required to disclose personal information for legal reasons, we will notify you of the request unless prohibited by law or court order. We will attempt to provide notice in a timely manner so you have the opportunity to challenge the request if permitted by law. We will only disclose the specific information that is expressly requested and will take measures to validate the legitimacy of the request before responding. Any disclosures will be limited to what is legally required.

4.3 Business Transfers in the Event of a Merger, Acquisition, or Other Transaction

As a growing startup, there may come a time when we engage in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, purchase or sale of assets, or transition of service to another provider. In such transactions, user information is typically one of the business assets that are transferred. If Shapedeep is involved in any such transaction, your Personal Data may be part of the assets transferred to the acquiring party or reviewed as part of the due diligence process. Any acquirer or successor of Shapedeep may continue to use your Personal Data as set forth in this Privacy Policy.

Specifically, if our company or substantially all of our assets are acquired, or in the unlikely event that we go out of business or enter bankruptcy, user information would be one of the assets that is transferred to or acquired by a third party. You acknowledge that such transfers may occur, and that any acquirer of Shapedeep may continue to use your Personal Data as set forth in this Privacy Policy. We will notify you of any such transfer of your Personal Data, and you will have the opportunity to opt out of allowing your Personal Data to be transferred to the new entity. If you do not opt out, your Personal Data will be transferred to the acquiring entity and will be subject to their privacy policy.

Please be aware that once your Personal Data is transferred in a business transfer, it may no longer be protected by the same privacy safeguards that Shapedeep provides. We encourage you to review the privacy policies of any company that acquires Shapedeep or your Personal Data to understand how they will handle your information.

We will only transfer your Personal Data in a business transaction if it is necessary for the purposes of the legitimate interests pursued by us or by the third party acquirer, except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of your Personal Data.

4.4 Sharing with Your Consent

As a startup, our ability to share your personal information is limited to specific situations where we have obtained your express consent. We believe in being fully transparent about who we share your data with and empowering you to control your privacy preferences. Some examples of when we may share your information with your consent include:

  • When you opt-in to receive marketing communications from us or select partners. You can always unsubscribe from these messages using the link provided.
  • If you agree to be featured in a user testimonial or case study to be posted on our website or social media. We would get your approval on any content before publishing.
  • When you voluntarily participate in a survey or research project to help us improve the app. We anonymize and aggregate the results before sharing with any third parties.

In all cases, we will clearly explain what information will be shared, with whom, and for what purposes. You will have the opportunity to freely consent or decline. We will never pressure you or penalize you for not agreeing to share your data. Even when you do provide consent, you can revoke it at any time by contacting us or adjusting your privacy settings in the app. We will promptly process your request to stop sharing your information per your wishes.

Consent for sensitive information: In the unlikely event we need to share any sensitive personal information (such as health data if you request accessibility accommodations), we will always obtain your explicit, informed consent beforehand. This means you will have to take an affirmative action to opt-in, not just passively accept.

5. Data Retention

5.1 Retaining Information to Provide Services

We are committed to minimizing the personal information we collect and store to only what is strictly necessary to provide and improve our language learning services. We retain your data only for as long as needed to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required by law.

Specifically, our data retention practices are as follows:

  • Account Information: We retain your account information, such as your name, email address, and learning preferences, for as long as you maintain an active account with us. If you delete your account or request account closure, we will delete this information within 30 days, except where we need to retain it for legal purposes.
  • Learning Progress Data: We store data on your learning activities, quiz results, and progress through lessons only for the time needed to provide the personalized learning experience and track your achievements. We may retain de-identified or aggregated learning data (not tied to individual users) for a longer period for analytics and product improvement purposes.
  • Subscription and Payment Data: We retain information about your subscription plan and payment transactions for the duration of your paid service, and for a reasonable time thereafter for accounting, tax, and legal compliance needs. We securely delete payment card details once the transaction is processed.
  • Customer Support Records: If you contact our support team, we keep a record of your communication to help solve any issues you might be facing. We retain these records for 6 months, unless the issue is ongoing or there is a legal reason to keep them longer.
  • Usage Logs and Analytics Data: We collect certain information about how users interact with our app, such as crash reports and feature usage statistics. This data is typically stripped of direct identifiers and only retained in aggregated form for 6 months to help us analyze trends and improve the app experience.
  • Marketing Preferences: If you have consented to receive marketing communications from us, we will retain a record of your preferences until you opt-out or withdraw consent. We will then promptly suppress your contact information from future campaigns.

Please note that in some cases, we may need to retain certain information for longer periods to comply with legal obligations, resolve disputes, or enforce our agreements. In all cases, we apply appropriate security safeguards and limit access to this retained data.

If you have any specific questions about our data retention practices or would like to request deletion of your personal information, please contact us at privacy@shapedeep.com. As transparency is a core value for us, we are happy to discuss our data practices further.

5.2 Retention for Legal Compliance

As a company, we are committed to complying with all applicable laws and regulations related to data retention. In some cases, we may be legally required to retain certain personal information for specific time periods. Some examples of such legal obligations include:

  • Tax Laws: We are required to retain records of customer transactions, invoices, and payments for a certain number of years for tax audit and reporting purposes. This may include personal information like names, addresses, and payment details.
  • Consumer Protection Regulations: Many jurisdictions have laws that require companies to retain customer contracts, warranties, and transaction records for a defined period to protect consumer rights. We adhere to these retention periods for relevant user data.
  • Anti-Money Laundering Statutes: Financial regulations often mandate that companies retain information related to monetary transactions and suspicious activities to combat money laundering and terrorist financing. While this mostly applies to financial institutions, as a new business we maintain basic transaction records as required.
  • Litigation Holds: If we are involved in a legal dispute or receive a preservation order from a court, we may be required to retain all data relevant to the case for the duration of the proceedings, even if we would normally delete it sooner. We will inform affected users unless prohibited by law.
  • Industry-Specific Regulations: Depending on the nature of our language learning services, we may be subject to data retention requirements under education or consumer protection laws specific to our industry. We carefully monitor these sector-specific obligations.

When personal information is no longer necessary for the purposes for which it was collected and no legal retention requirements apply, we will securely delete or anonymize it in accordance with our data deletion practices.

We are committed to the principle of data minimization and strive to retain personal information only for as long as needed. We regularly review our data retention practices to ensure compliance with the latest laws and regulations.

If you have any specific questions about our legal obligations to retain your personal data, please contact us at privacy@shapedeep.com. We are happy to discuss the applicable retention periods for your information.

6. Security Measures

Limitations of Security for Information Transmitted Over the Internet

While we strive to protect your personal information through strong security measures, it’s important to understand that no method of transmission over the Internet or electronic storage is 100% secure. When you use our language learning app, your data is transmitted over the internet using secure encryption protocols. However, the internet is an inherently open and interconnected system, and there is always a risk that data could be intercepted or modified by unauthorized parties, despite our best efforts. Some specific limitations to internet security include:

  • Vulnerabilities in network infrastructure, such as routers and servers, that could allow attackers to intercept data in transit
  • Weaknesses in encryption algorithms or their implementation that could allow data to be decrypted by unauthorized parties
  • Phishing attacks or social engineering tactics that trick users into revealing their credentials or sensitive information
  • Malware or viruses on a user’s device that could capture data as it is being entered or transmitted
  • Insider threats or human error by personnel with authorized access to systems and data

As a startup, we have limited control over the wider internet infrastructure and the security practices of our users. While we implement strong security controls on our end and work with reputable service providers, we cannot guarantee the security of data during transmission. We encourage our users to take steps to protect their own devices and accounts, such as:

  • Keeping your app login credentials unique and strong
  • Enabling two-factor authentication when available
  • Only accessing the app from trusted devices and networks
  • Keeping your device software and security features up-to-date
  • Being cautious about phishing attempts or unsolicited requests for your information

If you have any reason to believe your app account has been compromised or your data has been exposed in transit, please notify us immediately at privacy@shapedeep.com. By using our app and entrusting us with your personal information, you acknowledge and accept these inherent limitations of internet security. Rest assured that we will continue to monitor for new threats and implement industry best practices to secure your data to the greatest extent possible.

7. User Rights and Choices

7.1 Accessing and Updating User Information

As a user of our language learning app, you have certain rights and choices regarding your personal information. We believe in transparency and giving you control over your data. Here’s how you can access and update your information:

Accessing Your Information:

You have the right to know what personal data we hold about you and how we use it. You can access most of your basic account information, such as your name, email address, and learning progress, directly in the app by going to your profile settings.

If you would like a more detailed copy of the personal data we have about you, including data that is not accessible in the app, you can submit a data access request to privacy@shapedeep.com. We will verify your identity and provide a copy of your data electronically within 90 days, free of charge.

Updating Your Information:

You can update account details such as your name at any time in the profile settings of the app. Keeping your data accurate and up to date ensures the best learning experience.

If you need to change information that cannot be edited directly in the app – such as the e-mail address linked to your account – please contact us at support@shapedeep.com. We will gladly assist you.

Rectifying Inaccurate Information:

If you believe any of the personal information we hold about you is inaccurate, incomplete, or outdated, you have the right to request that we correct it. You can either make the changes yourself in your profile settings or contact us at support@shapedeep.com with the details of the information you would like rectified. We will verify the accuracy of the new data you provide and update our records accordingly.

In some cases, we may need to verify the accuracy of the new information before making changes, such as requiring proof of a legal name change. We will inform you if additional verification is necessary.

Limitations on Access and Updates:

In certain circumstances, we may be unable to provide you with access to all of your personal information or make requested changes. For example, if your data access request would reveal personal information about another person, or if we are legally required to maintain certain records. In such cases, we will explain the reasons we cannot comply with your request, unless prohibited by law.

If you have any issues accessing or updating your information, or believe we have processed your personal data incorrectly, please don’t hesitate to contact us at privacy@shapedeep.com.

7.2 Deleting Accounts and Data

As a user of our language learning app, you have the right to request the deletion of your account and associated personal data at any time. We believe in data minimization and will only retain your information for as long as necessary to provide our services and meet legal obligations.

Requesting Account Deletion

To request the deletion of your account and personal data, you can:

  • Go to your account settings in the app and select the “Delete Account” option. You will be asked to confirm your request.
  • Contact us directly at privacy@shapedeep.com with your deletion request. Please provide the email address associated with your account for verification purposes.

Once we receive your verified deletion request, we will:

  • Deactivate your account and cease the collection and processing of your data within 30 days
  • Permanently delete your account and all associated personal data from our production systems within 30 days, except where we need to retain data for legal purposes
  • Notify any third-party service providers that process your data on our behalf to also delete your data, unless prohibited by law

Please note that once your account is deleted, you will lose access to all app features, progress data, and subscription benefits. Deletion is irreversible, so please ensure you truly want to close your account before confirming.

Data Stored by Third Parties

While we will delete your personal data from our systems, we cannot control how third parties with whom you’ve shared your data handle deletion requests. For example, if you connected your account to a social media platform or shared your progress on a public forum, that data may persist even after we delete your account. You will need to contact those parties separately with deletion requests.

Exceptions to Deletion

In certain circumstances, we may be unable to delete all of your personal data. For example:

  • If there is an unresolved issue with your account, such as an outstanding payment or suspected fraud
  • If we need to retain certain data to comply with legal obligations, such as maintaining records for tax purposes
  • If deleting your data would adversely affect the rights of other users, such as deleting your contributions to group discussions

In such cases, we will inform you of the specific data we need to retain and the reasons why. We will delete all other data not covered by the exception.

Inactive Accounts

If your account remains inactive for a period of 18 months, we may reach out to confirm if you still wish to maintain the account. If we don’t receive a response after multiple attempts or your account remains inactive for 6 additional months, we reserve the right to automatically delete your inactive account and associated data. We are committed to respecting your right to erasure and ensuring you have control over your personal information. If you have any questions about our deletion practices or encounter difficulty deleting your account, please contact us at privacy@shapedeep.com for assistance.

7.3 Opting Out of Marketing Communications

As a user of our language learning app, you have control over the marketing communications you receive from us. We believe in transparency and will only send you promotional messages if you have given us your explicit consent to do so.

Opting In to Marketing Communications

When you create an account with our app, you will have the option to opt-in to receive marketing communications, such as newsletters, special offers, and updates about new features. This opt-in will be a clear affirmative action, such as checking a box or toggling a switch, separate from your agreement to the general terms of service.

If you choose not to opt-in during registration, we will not send you any marketing messages. Your choice will not affect your access to the core functions of the app.

Changing Your Marketing Preferences

If you initially opted-in to marketing but later decide you no longer want to receive promotional communications from us, you can opt out at any time by:

  • Clicking the “Unsubscribe” link at the bottom of any marketing email we send. You will be immediately unsubscribed from that type of communication.
  • Going to your account settings in the app and toggling off the option to receive marketing messages.
  • Contacting us at privacy@shapedeep.com with your request to be removed from our marketing lists. Please provide the email address you want unsubscribed.

Please note that opting out of marketing communications will not affect any transactional or service-related emails we need to send you, such as password reset requests, payment confirmations, or important app updates. You will continue to receive these essential messages as long as you maintain an account with us.

Third-Party Marketing

As a new company, we do not currently share your personal information with any third parties for their direct marketing purposes. If this changes in the future, we will update this Privacy Policy and provide you with a clear opt-in choice before sharing your data for marketing by others.

Targeted Advertising

We may use some personal data, like your app usage patterns and rough location, to display more relevant ads within the app. These will be based on broad segments, not individual profiles. If you prefer not to have your data used for targeted advertising, you can opt out by:

  • Adjusting your device’s advertising identifier settings to limit ad tracking
  • Using the opt-out mechanisms provided by our ad partners, which we will list in this Policy
  • Upgrading to a paid, ad-free version of the app, if available

We do not currently respond to browser-based do-not-track signals, as there is no consistent industry standard for handling them. However, we offer the opt-out choices described above to give you control over the use of your data for advertising.

We are committed to respecting your marketing preferences and giving you clear ways to control the promotional messages you receive. If you have any issues managing your preferences or believe you have received marketing from us in error, please contact us at privacy@shapedeep.com so we can promptly resolve the issue.

8. Children’s Privacy

Minimum Age Requirements to Use the App

As a language learning app, we are committed to protecting the privacy of children and complying with laws designed to keep them safe online, such as the Children’s Online Privacy Protection Act (COPPA) in the United States and the General Data Protection Regulation (GDPR) in the European Union. Our app is intended for general audiences and not directed at children under the age of 13. We do not knowingly collect personal information from children under 13 or allow them to create accounts and use the full features of the app.

Age Verification

To comply with statutory requirements—particularly the protection of children’s privacy—we do not request an exact date of birth during registration. Instead, new users choose one of the following age groups:

  • Under 13 years
  • 13 to 17 years
  • 18 years or older

Registration under 13 years

If a user selects “Under 13 years,” the registration is automatically aborted and the account is not created.

Purpose of age data

The age group is used solely to confirm the minimum age for using our services and to activate appropriate safeguards. We do not use this information for marketing, advertising or any other profiling purposes.

Deletion of inadvertently collected data from minors

If we discover that we have stored personal data of a child under 13 years, we delete it immediately. If you believe we may have information about a child under 13, please contact privacy@shapedeep.com so that we can take the necessary steps.

Parental Rights and Choices

Parents who have consented to the collection of their child’s personal information through our app have certain rights under COPPA and GDPR, including:

  • The right to review the specific types of information collected from their child
  • The right to request deletion of that information
  • The right to revoke their consent to further collection and use of their child’s data

To exercise these rights, parents should contact us at privacy@shapedeep.com with their request. We will take steps to verify the requestor is indeed the child’s parent or legal guardian before fulfilling the request.

Protecting Teens’ Privacy

While our app is intended for general audiences, we recognize that some teenage users may also use our language learning services. We are committed to protecting the privacy of teens aged 13-17 and complying with any additional legal requirements that may apply to this age group, such as the California Consumer Privacy Act (CCPA). We will not use teens’ personal information for any materially different purposes than what is disclosed in this Privacy Policy without first obtaining their consent. We also will not knowingly share their data with third parties for direct marketing purposes. Teens have the same rights as adult users to access, update, and delete their personal information as described in the User Rights and Choices section of this Policy. If you are the parent of a teen user and have any concerns about their privacy, please contact us at privacy@shapedeep.com.

9. International Data Transfers

Principle

We process personal data primarily on servers in Frankfurt am Main (Google region europe-west3). Only Google Cloud Scheduler runs, for technical reasons, in the region us-central1 (Iowa, USA). No personally identifiable content crosses that border: the scheduler event contains only a timestamp and the name of the Pub/Sub topic that triggers our Cloud Functions in Frankfurt. All user IDs, progress data and content remain within the EU.

Services used and data categories

  • Firebase Cloud Functions (Frankfurt)
    Purpose: daily XP calculation, weekly league reset, group creation
    Data: user UID (pseudonymised), learning-statistics IDs, timestamps
    Retention: logs 30 days; resulting data are identical to the main Firestore records
  • Cloud Scheduler & Pub/Sub (Iowa)
    Purpose: calls the relevant Pub/Sub topic at defined cron times
    Data: purely technical metadata (time payload, topic name)
    Special note: no personal data; processing takes place in Frankfurt
  • Firebase Authentication & Firestore (Frankfurt)
    Purpose: sign-in, persistence of learning progress, leaderboard storage
    Data: e-mail, salted password hash, progress IDs
    Retention: until the account is deleted

Legal bases for the US component

EU-US Data Privacy Framework (DPF) – Google LLC has been certified since 17 July 2023; the European Commission adopted an adequacy decision on 10 July 2023.

Standard Contractual Clauses (SCCs) – In addition, we have concluded the EU standard clauses of 4 June 2021 with Google.

Technical and organisational safeguards

  • Transport encryption with TLS 1.3; data at rest encrypted with AES-256
  • Pseudonymisation: function calls operate only with internal UID tokens
  • Role-based access controls (RBAC) and regular IAM audits
  • Service providers are contractually bound under Art. 28 GDPR

Data-subject rights

You enjoy all rights under Art. 15-22 GDPR. For US transfers you may also appeal to the Data Protection Review Court in the United States, which offers a free complaint procedure within the DPF.

Right to object / opt-out

You may object at any time to the transfer of pseudonymised analytics and crash-diagnostics data to the USA. This concerns only voluntary telemetry (e.g. app usage duration, device type, crash reports).

Important note

  • Leaderboard and core functions remain fully available.
    Ranking is calculated in Frankfurt using Firestore data that reside in the EU.
  • Cron jobs run without a US data flow.
    The scheduler still receives a time-only signal from Iowa; because it contains no personal data, it is GDPR-compliant and not part of the opt-out.
  • Consequences of an opt-out: you will no longer receive personalised improvement tips, and crash reports are no longer linked to your session. Functionality, speed and leaderboard participation remain unaffected.

Transparency and future changes

We publish any change to the processing regions at least 30 days in advance on our privacy website. Should additional third countries become necessary, we will first obtain explicit consent under Art. 49 (1)(a) GDPR.

10. Changes to this Privacy Policy

How Users Will Be Notified About Material Changes

As our language learning app evolves, we may need to update this Privacy Policy from time to time to reflect changes in our data practices or to comply with new legal requirements. We are committed to being transparent about these changes and giving our users advance notice and choices where required.

Material Changes

A “material” change means any modification to the Privacy Policy that significantly affects your rights or the ways we use your personal data, such as:

  • Using your data for a new purpose that was not previously disclosed
  • Sharing your data with a new third-party category
  • Reducing your privacy rights or controls over your information
  • Changing how long we retain your data

When we make material changes, we will notify you in advance and give you an opportunity to review the changes before they take effect. This notice will be provided at least 30 days before the changes become effective, through one or more of the following methods:

  • Prominent notice within the app, such as a pop-up or banner
  • Email to the address associated with your account
  • Push notification, if you have them enabled for our app
  • Notice on our website homepage or privacy policy page

We will also update the “Last Updated” date at the top of this Privacy Policy to indicate when the changes were made.

Non-Material Changes

For non-material changes that do not significantly impact your rights or our data practices, we may simply post the updated Privacy Policy within the app and on our website, without additional notice. Examples of non-material changes could include:

  • Clarifying or rephrasing existing policy language
  • Reorganizing the policy sections or formatting
  • Updating our contact information

We encourage you to periodically review this Privacy Policy to stay informed about how we are protecting your data.

Your Choices

If you do not agree with any material changes to our Privacy Policy, you may have certain choices, such as:

  • Adjusting your privacy settings within the app to limit the data we collect or share
  • Requesting deletion of your account and data, where applicable
  • Stopping use of the app and any associated services

However, please note that your continued use of our app after the effective date of an updated Privacy Policy will constitute your acceptance of the changes. If you do not want to agree to a new policy, you should stop using the app and contact us to request deletion of your account before the changes take effect. We value your trust and want to ensure you understand and are comfortable with how your personal data is handled. If you have any questions or feedback about our Privacy Policy or changes to it, please don’t hesitate to contact us at privacy@shapedeep.com.