Privacy Policy
Last updated: June 17, 2026
Vocdeck ("we", "us", or "our") is operated by Felix Martinsson. This policy explains what data we collect, why, and how we protect it. We built this app to help learners — not to monetize their data.
1. Data We Collect
Vocdeck is local-first: the vocabulary catalog and the detailed record of your practice live on your device. Only a small amount of data is sent to our servers — what's needed to sign you in and carry your progress across devices.
Email address. You provide your email to sign in. We use it to send you a magic link (one-time login link) via our email provider, Resend. We do not use your email for marketing unless you explicitly opt in.
Learning activity. As you practice, the app records your responses as an append-only activity log and syncs it to our servers so your progress is backed up and available on every device you sign in on. This log is tied to your account and is only accessible to you. We do not collect or store any text you write — Vocdeck has no content-generation or note-writing feature, so there are no prompts and no uploads.
Language and learning settings. The languages you are learning, your native language, and your learning preferences are stored with your account so they follow you across devices.
Subscription status. If you subscribe, the purchase is processed by Apple and your subscription status is managed through RevenueCat. We receive only whether your subscription is active — never your payment-card details, which only Apple handles.
Diagnostics. Our server logs may include your email address and technical details about a request or error — used to verify your identity and help with support. They contain no learning content. If you opt in, the app also sends anonymized usage telemetry (e.g., which features are used) to help us improve it; this is off by default. We do not use a third-party crash-reporting or analytics service. Diagnostic data is access-controlled, retained for a limited period, and never sold or used for advertising.
2. Data We Do NOT Collect
- We do not use advertising SDKs or sell your data to advertisers.
- We do not use third-party analytics platforms (no Google Analytics, Mixpanel, etc.).
- We do not collect location data.
- We do not collect device identifiers for tracking purposes.
- We do not read your contacts, camera, microphone, or any data outside the app.
3. How We Use Your Data
- To provide the service: backing up and syncing your progress, and adapting which words you practice to your level.
- To send authentication emails: magic login links via Resend.
- To process subscriptions: verifying your subscription status via Apple and RevenueCat.
- To improve the service: if you opt in, we analyze aggregated, anonymized usage patterns (e.g., which languages are most used). We do not analyze your individual activity for this purpose.
4. Third-Party Services
We use third-party services to operate Vocdeck. These fall into the following categories:
- Subscription management — in-app purchases are handled by RevenueCat and Apple.
- Email delivery — magic login links are sent via our transactional email provider (Resend). Your email address is shared with this provider solely for authentication.
- Cloud hosting — our backend and database are hosted on servers in the United States by a managed cloud provider (Render).
5. Data Retention
Your account data (email, learning activity, settings) is retained for as long as your account is active. If you delete your account, we delete all associated data within 30 days. Anonymized, aggregated data may be retained beyond that period.
Magic link tokens expire after 15 minutes and are not retained beyond that.
6. Your Rights (GDPR)
If you are in the European Economic Area (EEA) or UK, you have rights under the GDPR:
- Access: you may request a copy of the data we hold about you.
- Rectification: you may correct inaccurate data.
- Erasure: you may delete your account and all associated data at any time via Settings → Account → Delete Account.
- Data portability: you may request an export of your data in a machine-readable format.
- Objection: you may object to processing in certain circumstances.
To exercise any of these rights, contact us at [email protected].
The legal basis for processing your data is:
- Contract performance — processing your email to authenticate you, and storing your progress so the Service works across your devices.
- Legitimate interests — maintaining the security and integrity of the service, and (where you have opted in) improving it based on aggregated usage patterns.
7. Children's Privacy
Vocdeck is intended for users aged 13 and older. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has created an account, please contact us at [email protected] and we will delete the account promptly.
8. Security
We use industry-standard security practices:
- All data in transit is encrypted via HTTPS/TLS.
- Passwords are not used — authentication is entirely via single-use email magic links.
- JWT tokens used for session authentication are short-lived and stored client-side.
- Our database is hosted on Render's managed PostgreSQL with encrypted storage.
No system is perfectly secure. If you discover a security vulnerability, please report it to [email protected].
9. International Transfers
Vocdeck's backend infrastructure is hosted in the United States (Render). If you are located in the EEA, your data is transferred to the US. We rely on Standard Contractual Clauses (SCCs) where applicable, and use service providers who maintain their own transfer mechanisms.
10. Changes to This Policy
We may update this privacy policy from time to time. When we do, we will update the "Last updated" date at the top. If changes are material, we will notify you via email. Continued use of Vocdeck after changes are published constitutes acceptance of the updated policy.
11. Contact
For privacy-related questions, data requests, or GDPR inquiries:
Email: [email protected]
Controller: Felix Martinsson, Vocdeck