Privacy Policy for VociApp
Back to main pageVociApp ("the App") is developed and published by Dominik Schmitt ("we", "us", or "our"). This Privacy Policy explains what data VociApp processes, how it is used, when it is transmitted off your device, and how you can contact us or request deletion.
Summary
- VociApp is local-first: core learning data is stored on your device unless you use account sync or AI features.
- An account is optional, but required for account sync and quota-bound AI features.
- We do not sell your personal data.
- We do not use third-party advertising SDKs.
- We do not track you across apps or websites.
- App Store privacy disclosures for VociApp are limited to account, purchase, learning, usage, and diagnostic data categories that support the app.
- AI requests may send selected learning content, answers, prompts, or OCR text to Supabase Edge Functions and OpenAI for processing.
- Camera/photo access is used only for user-initiated scan/import features. Original images are not collected by us in the normal OCR flow.
- Admin tooling is restricted to authorized administrators and is used for support, security, entitlement, and content operations.
App Store Privacy Disclosure Categories
For App Store privacy disclosures, VociApp may collect and link the following data to your account or identity when you sign in, sync, purchase, use AI features, or contact support:
- Contact Information: email address.
- Identifiers: user ID or account ID.
- Purchases: purchase history, subscription status, product tier, and entitlement status.
- User Content: vocabulary decks, cards, examples, notes, imported/OCR text, prompts, answers, and other learning content you create or submit.
- Usage Data: product interaction and other usage data such as learning progress, review activity, feature usage, quotas, and timestamps.
- Diagnostics: other diagnostic data such as backend errors, operational logs, request metadata, and support diagnostics when needed for reliability, abuse prevention, cost control, or support.
VociApp does not use these data types for tracking across apps or websites, advertising, or data brokerage. We do not collect payment card numbers, precise location, contacts, browsing history, advertising data, or device advertising identifiers.
Data We Process Locally on Your Device
VociApp may store the following information locally in the app database or app storage:
- vocabulary decks and cards
- front/back card text, examples, notes, imported vocabulary, and language metadata
- verb metadata and verb forms
- study settings, selected deck, study mode, daily learning settings, and app preferences
- review logs, answer ratings, learning state, due dates, intervals, and mastery progress
- sync cursor state and local account-scope state
- temporary import, OCR, and AI enrichment results shown to you in the app
Purpose: to provide vocabulary training, spaced repetition, imports, deck management, progress tracking, and app session restoration.
Account and Authentication Data
If you create or sign into an account, VociApp uses Supabase Auth. Account-related data may include:
- email address
- authentication user ID
- session tokens managed by Supabase Auth
- profile status such as active, suspended, or banned
- admin role information if you are an authorized administrator
Purpose: authentication, account management, security, sync eligibility, support, and admin access control.
Optional Sync Data
When you are signed in and sync is eligible, VociApp may transmit account-scoped learning data to Supabase so that it can be restored or shared across your signed-in devices. This may include:
- decks, cards, examples, notes, language metadata, and template/subscription deck relationships
- review logs, learning progress, mastered status, intervals, due dates, and user statistics
- verb metadata, verb forms, and related review logs
- settings needed to restore app behavior, including selected deck and study settings
- sync status metadata and timestamps
Guest-local data does not sync unless you choose to claim it into your signed-in account.
AI Features and AI Quota Data
VociApp includes optional AI-assisted features. Depending on the feature you use, selected content may be sent to Supabase Edge Functions and OpenAI for processing. This may include:
- card text, example sentences, language pair, and answer text for explanations or answer feedback
- terms or verbs for detection, analysis, conjugation, and enrichment
- OCR text or imported vocabulary text for extraction and import assistance
- AI request metadata such as endpoint, user ID, quota category, token or cost estimates, status, timestamps, and errors
Purpose: to provide AI explanations, study help, answer feedback, vocabulary extraction, context generation, import enrichment, quota enforcement, fraud prevention, cost control, and operational diagnostics.
AI request content and usage metadata are treated as app functionality, user content, usage data, or diagnostic data depending on context. They are not used by VociApp for advertising or cross-app tracking.
AI output may be inaccurate, incomplete, or inappropriate. Do not rely on AI output as the sole authoritative source for exams, professional translation, legal, medical, financial, or safety-critical decisions.
For more detail, read AI & Data Safety.
Camera, Photos, OCR, and Imported Files
VociApp may request camera or photo access when you choose to scan or import learning material. The app uses on-device OCR to recognize text and help create vocabulary cards. Images are selected or captured by you. In the normal scan/import flow, the original image is processed locally and is not uploaded to our backend.
Recognized text, imported file contents, and import results may be stored locally as part of decks/cards if you choose to save them. If you use AI-assisted extraction or enrichment, recognized text or selected content may be sent to AI processing as described above. VociApp does not use camera or photo access for background tracking or advertising.
Admin Console and Support Operations
Authorized administrators may access an admin interface for support and operational purposes. Admin functionality may include:
- viewing account status, role, email, and support snapshots
- updating account status or role where permitted
- reviewing and adjusting AI entitlements and usage resets
- managing decks, cards, templates, subscriber decks, and soft deletion
- reviewing platform, usage, and cost summaries
- recording admin audit logs for accountability
Purpose: support, abuse prevention, security, billing/entitlement support, content maintenance, and service reliability.
Support Communications
If you contact us by email, we process the information you include, such as your email address, device details, app version, screenshots, and problem description.
Purpose: to respond to support requests, investigate bugs, handle privacy requests, and improve reliability.
Purchases and Subscriptions
VociApp may offer optional paid tiers such as Plus or Pro AI. If paid tiers are sold in the App Store or Google Play, purchases, subscriptions, renewal, cancellation, refunds, and payment methods are handled by the relevant platform. We do not receive your full payment card details from Apple or Google.
VociApp may process purchase history and entitlement data such as store, product ID, tier, subscription status, transaction identifiers, hashed purchase tokens, subscription expiration, quota limits, and usage counters to validate purchases and decide which features are available to your account.
Data We Do Not Sell or Use for Tracking
- We do not sell personal data.
- We do not use third-party advertising SDKs.
- We do not use your learning data for cross-app or cross-site tracking.
- We do not use your camera or photos for advertising.
Third-Party Service Providers
VociApp may use the following service providers:
- Supabase for authentication, database sync, Edge Functions, and storage of account-scoped backend data.
- OpenAI for optional AI processing when you use AI-assisted features.
- Apple and Google for app distribution, platform billing, subscription management, crash/reporting infrastructure they provide at the platform level, and store operations.
- Google ML Kit OCR libraries for on-device OCR language support in scan/import flows.
- Your email provider and our email provider if you contact support.
These providers process data under their own terms and privacy policies as applicable.
Security
We use reasonable technical and organizational measures for the nature of the app, including local app sandboxing, Supabase authentication, database access controls, service-role-only backend operations for sensitive RPCs, and HTTPS/TLS transport for network requests. No method of storage or transmission can be guaranteed to be completely secure.
Retention
- Local app data remains on your device until you delete it in the app, reset local data where available, or uninstall the app.
- Synced account data remains in Supabase until you delete it, request deletion, or we remove it under our retention, support, security, or legal processes.
- AI usage logs and admin audit logs may be retained for security, cost control, abuse prevention, support, and legal compliance.
- Support emails are retained for as long as reasonably needed to handle the request and related follow-up.
- Some data may be retained where required for security, fraud prevention, billing, dispute resolution, legal compliance, or legitimate backup processes.
Deletion and Privacy Choices
You can delete local data by deleting the app or using in-app reset/delete features where available. Signed-in users can initiate account deletion directly in the app from Account > Delete account. If you cannot access the app, use Account Deletion for the external deletion instructions.
If you have an active App Store or Google Play subscription, account deletion does not automatically cancel the platform subscription. Manage subscriptions in your Apple ID or Google Play account settings.
Your Rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, objection to certain processing, withdrawal of consent, or review of certain automated decisions. Contact us at vociapp.support@gmail.com. We will review and respond in accordance with applicable law.
For account deletion, use the in-app Account > Delete account flow when possible. If you cannot access the app, use the dedicated Account Deletion page so the request is easy to identify and process.
Regional Privacy Notes
If you are in the European Economic Area, United Kingdom, or Switzerland, the legal bases for processing may include performance of the app service you request, your consent for optional features, legitimate interests such as security and abuse prevention, and legal obligations. You may also have the right to lodge a complaint with your local data protection authority.
If you are in California or another US state with privacy rights, you may have rights to know, access, correct, delete, or obtain a copy of certain personal information, and to opt out of sale or sharing where applicable. VociApp does not sell personal data and does not use personal data for cross-context behavioral advertising.
If you are in Brazil or another jurisdiction with similar privacy rights, you may have rights to confirm processing, access, correct, anonymize, delete, or port certain personal data, subject to applicable exceptions.
Children and Minors
VociApp is intended for general language learning and is not directed to children or the Kids category. If you are below the age required to consent to digital services in your country, use VociApp only with permission and supervision from a parent or legal guardian. Do not submit personal data about children into decks, OCR imports, support emails, or AI prompts.
If you believe a child has provided personal information without appropriate permission, contact us so we can review and take appropriate action.
International Processing
VociApp may be offered worldwide. Service providers such as Supabase, OpenAI, Apple, Google, and email providers may process data in countries outside your own. Where required, we rely on appropriate legal mechanisms and service provider commitments for international data transfers.
Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date on this page.
Contact
Dominik Schmitt
Email: vociapp.support@gmail.com