← Piko Polyglot

Privacy Policy for Piko Polyglot

Last Updated: August 8, 2026

Українською: короткий зміст нижче після англійського тексту. For Google Play / App Store the authoritative version is English.

1. Introduction

Welcome to Piko Polyglot ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our mobile application available on Android (Google Play) and iOS (App Store) (the "App").

Piko Polyglot is an English-learning application with sentence-building exercises, optional challenge lessons, and vocabulary flashcards. The user interface is available in Ukrainian and English (and may include other UI languages). The App is operated by Pavlo Makarenko, individual developer, located in Austin, Texas, United States.

This App is designed for a mixed audience of children, teens, and adults. We use an age screen at first launch and apply different data-handling rules depending on the age category selected.

2. Information We Collect

A. Information You Provide

We may collect the following information when you use the App:

  • Email address if you sign in with Google or Apple, for account authentication and cloud sync.
  • Display name or nickname, for profile identification and app features.
  • User ID (Supabase UUID), for account identification and synchronization.
  • Learning progress for core and thematic lessons, including scores, stars, attempts, session state, difficulty level, and streaks.
  • Challenge-lesson progress when that feature is available, including attempt results and related scores or stars.
  • Vocabulary / flashcard activity, including which catalog decks you open or add, spaced-repetition (SRS) card state, and "continue" / last-opened markers used to resume study.
  • User-created vocabulary content you choose to add (for example custom decks, terms, meanings, and example sentences). This content is stored for your account only and is not published to other users. Free-tier custom decks may be stored only on your device until a premium sync entitlement is available.
  • App preferences, including UI language, theme, and exercise source language.
  • Self-declared age category on device only: Child, Teen, or Adult. We do not collect a date of birth.
  • Optional issue report text if you choose to report a problem with App-provided lesson, theory, or vocabulary content.
  • Subscription and purchase status for paid plans (currently Ad-free / no_ads).

B. Information Collected Automatically

We may automatically collect or process:

  • Device and advertising identifiers through Google AdMob.
  • Authentication tokens stored securely on your device.
  • Local profile, progress, and (where applicable) free-tier custom vocabulary data stored in MMKV on your device for guest use and on-device storage.

C. Information We Do Not Collect

We do not collect phone numbers, physical addresses, exact dates of birth, GPS location, photos, camera or microphone data, contacts, SMS, health data, or social profile data from Facebook or Twitter. We do not collect payment card numbers or bank account details — billing for Ad-free and other paid plans is handled by Google Play or the App Store; we receive subscription and entitlement status (for example via RevenueCat), not your full payment credentials.

3. How We Use Information

We use information to provide app functionality (lessons, challenge practice, and flashcards), authenticate users, sync learning progress and eligible vocabulary data between devices, show advertisements, process Ad-free and other subscriptions, review optional content-issue reports, comply with legal obligations, and improve the App.

For GDPR purposes, our legal bases are contract necessity, legitimate interests, and legal obligations, depending on the processing activity.

Account linking

If you sign in with Google, Sign in with Apple, or (when enabled) email magic link using the same verified email address, Supabase Auth treats these as one account with one user ID and one cloud progress record. Different email addresses remain separate accounts.

User-created vocabulary (private)

Custom flashcard decks and cards you create are treated as private learning materials for your account. We do not show that content in a public catalog or to other accounts. If we later add optional sharing of user-created content, we will update this Privacy Policy and applicable store disclosures before enabling that feature.

4. Advertising

We display advertisements in the App through Google AdMob.

  • Banner and interstitial ads may be shown on the free tier.
  • Rewarded ads may be added later.
  • Ad personalization depends on age category and consent settings.
  • Child users do not receive behavioral targeting.
  • You may remove ads by subscribing to the Ad-free plan ("Без реклами" / no_ads entitlement) through the store.

We do not sell your personal data to advertisers.

5. Analytics and Tracking

We do not use Google Analytics, Firebase Analytics, Mixpanel, or Amplitude. We use RevenueCat for subscription-related event handling and entitlement verification (including Ad-free). When crash reporting is enabled for a release build, we may use Sentry to receive technical crash and error diagnostics (device/app version, stack traces) so we can keep the App stable. We do not use browser cookies because the App is a mobile application; authentication sessions are handled through the Supabase SDK.

6. Sharing Information

We do not sell your personal data. We do not share personal information for cross-context behavioral advertising. We work with third-party service providers only as needed to operate the App.

These providers may include:

  • Supabase for authentication, profile storage, and cloud sync.
  • Google for OAuth sign-in and AdMob.
  • Apple for Sign in with Apple.
  • RevenueCat for subscription verification and entitlements.
  • Sentry for optional crash and error diagnostics in release builds.
  • Vercel for hosting public pages such as this Privacy Policy and the account deletion page.
  • Expo / EAS for app build, deployment, and over-the-air JavaScript updates.

Each provider receives only the data needed for its function.

7. International Transfers

Your information may be stored and processed in the region used by our Supabase project. Data may be transferred to cloud providers located in the United States or other countries where our service providers operate. Where required, we rely on appropriate contractual safeguards for such transfers.

8. Data Retention

We keep personal data only as long as needed for the purposes described in this policy.

  • Cloud account data — including lesson and challenge progress, flashcard SRS state, library membership, and synced custom vocabulary — is retained while your account is active and is deleted when you delete your account.
  • Local device data (including guest progress and free-tier custom vocabulary stored only on device) remains on your device until you delete the profile, delete the account, or reinstall the App.
  • Age category is stored locally only and is not uploaded to our servers.
  • Optional content-issue reports may be retained as needed to investigate and fix App content problems.
  • Subscription-related records are retained as needed for billing, entitlement, fraud prevention, and legal compliance.

9. Children's Privacy

Piko Polyglot is a mixed-audience app. We comply with COPPA and handle child users with extra restrictions.

Age Screen

At first launch, users choose an age category: Child, Teen, or Adult. We do not collect a date of birth. The selected age category is stored locally on the device only.

Child Users

If a user selects the Child category, we limit data collection to what is necessary for the App's core functionality.

For child users, the following may be processed only if needed for that user's use of the App:

  • Google AdMob — device or advertising identifiers, for child-directed ads without behavioral targeting.
  • Google OAuth — email address and display name, if the child signs in.
  • Apple Sign in with Apple — email address and display name, if the child signs in on iOS.
  • Supabase — User ID, display name, learning progress (lessons, challenge practice, and flashcards), and any synced private custom vocabulary, if the child uses a cloud account.
  • RevenueCat — subscription status, if subscription features are used.

We do not collect a child's date of birth, GPS location, contacts, photos, or sensitive personal information.

Child users are not shown personalized ads. Non-personalized child-directed ads are considered necessary for providing the free tier of the App. Parents may contact us to request ad-free access or account deletion.

Parental Rights

Parents and guardians may request access to, correction of, or deletion of their child's personal information. A parent may consent to our collection and use of a child's personal information without consenting to disclosure to third parties, unless that disclosure is necessary for the service requested.

To exercise these rights, contact us at piko.polyglot@gmail.com.

Child Data Retention

  • Age category is kept only on the device and can be cleared by deleting the profile, deleting the account, or reinstalling the App.
  • Cloud progress and account data are retained only while the account exists and are deleted when the account is deleted.
  • Advertising identifiers are handled by Google AdMob according to Google's policies.
  • We do not keep marketing profiles or behavioral profiles for child users.

Verifiable Parental Consent

At this time, we use self-declared age selection rather than a verifiable parental consent flow. If a parent believes a child has provided personal information, the parent may contact us to request access or deletion.

10. Your Rights

A. GDPR Rights

If you are in the EEA, UK, or another region with similar rights, you may request access, correction, deletion, portability, and withdrawal of consent. You may also sign out, delete your account, or change your age category in the App.

B. CCPA / CPRA Rights

If you are a California resident, you may request to know, delete, or correct personal information, and you may opt out of sale or sharing of personal information.

We do not sell your personal information and we do not share it for cross-context behavioral advertising. If you still want to submit an opt-out request, email piko.polyglot@gmail.com with the subject line CCPA Opt-Out Request. We will confirm the action taken within 15 business days of receiving a verified request.

11. Security

We use reasonable administrative and technical safeguards designed to protect your information. However, no method of transmission or storage is completely secure.

12. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last Updated" date at the top shows when the policy was last revised. Continued use of the App after changes means you accept the updated policy.

13. Contact Us

This App is operated by an individual developer.

No phone number or postal address is provided. Contact is by email only.

14. Store Disclosures

For Google Play and Apple App Store disclosures, the App may report data transmitted to us or our service providers, such as:

  • email address,
  • display name,
  • user ID,
  • app activity such as lesson, challenge, and flashcard learning progress,
  • user-generated text you enter for private custom vocabulary (not shared with other users),
  • device or advertising identifiers, and
  • purchase history for Ad-free and other paid plans.

Self-declared age category (Child, Teen, or Adult) is stored on your device only and is not transmitted to our servers. AdMob age-related settings are applied on the device based on that local choice.

Custom vocabulary you create is private to your account and is not accessible to other users. If we later enable optional sharing of user-created content, we will update this Privacy Policy before that feature goes live.

15. Exclusions

This policy does not cover a separate web app product, email magic links, Stripe, PayPal, Facebook login, Facebook fan pages, Google Analytics, or AppLovin as a standalone SDK.

Короткий зміст (українською)

  • Мобільний застосунок Android / iOS; оператор — Pavlo Makarenko, Austin, Texas, United States.
  • Вхід: Google / Apple (адреса email лише як ідентифікатор акаунта та для sync). Один email = один акаунт.
  • Дані навчання: уроки, challenge, флешкарти (SRS). Власні колоди/слова — приватні для акаунта, не публікуються іншим користувачам.
  • Реклама: Google AdMob; для дітей — без behavioural targeting. Підписка «Без реклами» прибирає рекламу.
  • Вікова категорія — лише на пристрої; COPPA.
  • Видалення акаунта: Профіль → Налаштування або /delete-account; разом з акаунтом видаляється й синхронізований прогрес / власні флешкарти в хмарі.
  • Контакт: piko.polyglot@gmail.com