Last updated: 28 August 2026

This Privacy Policy explains what data BrioVocab collects, why we collect it, who we share it with, how long we keep it, and how you can access or delete it.

1. Who we are

BrioVocab is operated by Vasilii Pintov.

For users in the European Economic Area and the United Kingdom, we act as the data controller for the data described below. Email is the fastest way to reach us about any privacy matter.

2. What this policy covers

This policy applies to the BrioVocab website (briovocab.com), the web app (app.briovocab.com), the BrioVocab mobile apps for Android and iOS, the Telegram mini app, and the VK mini app. We refer to all of these together as the Service.

3. What data we collect

3.1 Data you provide

  • Account data. Your name or nickname, and any other details you enter in your profile.
  • Contact details. Your email address and phone number, if you choose to provide them.
  • Voice recordings. When you use a speaking exercise or a voice message, the app records audio through your device microphone. See section 4.
  • Images. Photos or images you choose to send to the AI assistant, for example to ask what an object is called in French.
  • Messages. The text you write to the AI assistant, and the AI's replies.
  • Support correspondence. Whatever you send us when you contact support.

3.2 Data collected automatically

  • Installation and device identifier. A unique identifier assigned to your installation of the app. We use it to link your learning progress and subscription to your device when you are not signed in, and to keep the Service working correctly across sessions.
  • Marketing attribution and product analytics. When you arrive through a campaign link or install the app through an app-store campaign, we may collect standard UTM parameters, the store install-referrer value, VK launch and advertising parameters, the app surface, and events showing that onboarding or paywall screens were displayed or completed. For a paywall view on a monetized non-iOS surface, we record whether it followed an intentional action, a free-version limit, or exhausted credits, together with the IP address. The iOS App Store version does not display paywalls, so it generates no paywall-view events. Onboarding events may be recorded before you sign in and are linked to an onboarding-session or installation identifier. When you follow one of our short campaign links to an app-store page (a link under briovocab.com/go/), we record the campaign name, the target store, the time of the click and the IP address, and then send you to the store. We do not fingerprint your device and we do not attempt to match that click to a later installation.
  • Install sign-in code. If you use the "install the Android app" banner in the web app or in the Telegram or VK mini app, we generate a single-use code, pass it to the store you choose (Google Play or RuStore) together with the app link, and read it back once when the installed app first starts, so the app opens on your existing account instead of creating a new one. The code is a random value that carries no personal data, expires after 7 days, and stops working after the first use.
  • Referral links. If you arrive through a referral link published by a teacher or partner, we record which link brought you and when, so that we can give you the free subscription month the link promises and pay the teacher in in-app credits when a student they brought pays for a subscription for the first time. The code can reach us as a web address you open, as a Telegram bot start parameter, or as an app-store install-referrer value; in the last case it is read once on the first launch of the installed app. Teachers see only counts for each of their links — how many students arrived, how many of them subscribed, and the credits earned. They never learn who you are, and they never see your email, your learning activity or what you paid. When you open a teacher's link, that teacher's first and last name is shown to you on the landing page.
  • Account identifiers. Identifiers from the sign-in systems you use (web app, Telegram, VK). When you open the Telegram or VK mini app, we use the identifier and basic profile details supplied by that platform to create or open your BrioVocab account automatically.
  • Push notification identifiers. If you enable notifications, we process the app's device identifier, Firebase Cloud Messaging registration token, platform and app store so we can deliver service notifications such as Word of the Day.
  • Learning activity. Which words you have studied, your answers, your review schedule, your progress, your proficiency level (including a CEFR level selected during onboarding or estimated by an assessment), and your settings.
  • Subscription and payment status. Your plan, access status, and payment and refund history. Card numbers are handled by the payment provider or by the app store; we never receive or store them.
  • Technical data. IP address, app and OS version, language, and server logs of errors and technical events.

3.3 What we do not collect

  • We do not use third-party advertising or cross-app tracking SDKs. Each Android build uses its store's install-referrer component — RuStore's Install Referrer SDK, or Google's Play Install Referrer library — only to retrieve the campaign referrer and the install sign-in code supplied by that store; product analytics are sent from our server rather than by a third-party analytics SDK embedded in the app.
  • We do not collect your contacts, calendar, precise location, photo library (beyond images you deliberately send), SMS, or call logs.
  • We do not ask for special categories of data such as health, biometric identification, religion or political opinions, and you should not send them to us.
  • We do not sell your personal data, and we do not share it for advertising or cross-app tracking.

4. Microphone and voice recordings

BrioVocab requests the microphone permission (RECORD_AUDIO on Android, NSMicrophoneUsageDescription on iOS) for one purpose: to let you speak French and get feedback on what you said.

  • The microphone is activated only when you deliberately start a recording, for example by pressing and holding a record button. The app does not listen in the background and does not record when you have not started a recording.
  • Your recording is sent to our servers and to an external AI provider so that your speech can be transcribed and assessed. See section 6.
  • Recordings are stored on our servers, linked to your account or installation identifier, and are kept until you delete them or delete your account. We keep them so that you can replay your own attempts and so the Service can track your pronunciation progress over time.
  • You can withdraw the microphone permission at any time in your device settings. The rest of the Service continues to work without it; only the speaking exercises become unavailable.

Under the GDPR, we rely on the legal bases listed below. If you are not in the EEA or the UK, the purposes still describe what we do.

What we doWhyLegal basis (GDPR)
Create your account and give you access to BrioVocabTo provide the Service you asked forPerformance of a contract (Art. 6(1)(b))
Store your learning progress and schedule your reviewsTo make the Service work as describedPerformance of a contract (Art. 6(1)(b))
Process voice recordings, images and messages through AITo deliver the AI features you actively invokePerformance of a contract (Art. 6(1)(b)); consent for microphone access at the device level (Art. 6(1)(a))
Use an installation or device identifierTo link your progress and subscription to your installation, and to keep the Service secure and functionalLegitimate interests (Art. 6(1)(f))
Measure acquisition campaigns, onboarding and paywall effectivenessTo understand which campaign links, app-store referrals, onboarding flows and paid-access prompts are effectiveLegitimate interests (Art. 6(1)(f))
Handle payments, trials, refunds and support requestsTo run the paid Service and answer youPerformance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for accounting records
Keep logs, prevent abuse and fix errorsTo keep the Service secure and reliableLegitimate interests (Art. 6(1)(f))
Send you service notifications about your accountTo tell you things you need to know as a userPerformance of a contract (Art. 6(1)(b))
Comply with applicable lawTo meet our legal dutiesLegal obligation (Art. 6(1)(c))

6. Sending your data to AI providers

BrioVocab's learning features are built on artificial intelligence. To make them work, we send the content you submit to third-party AI providers acting as our processors.

  • Who they are: OpenAI (OpenAI, L.L.C., USA) — generates the assistant's replies, recognises text on images, and transcribes and assesses your speech; ElevenLabs (ElevenLabs Inc., USA) — synthesises the audio you hear in speaking practice.
  • Your consent: before your content is sent to an AI provider for the first time, the app shows a consent dialog describing what is shared, with whom and why. AI features work only after you agree. You can withdraw this consent at any time in the app settings; the rest of the Service keeps working without the AI features. We store your consent together with the version of the consent text, and ask again if the text materially changes.
  • What is sent: your voice recordings, the images you send to the assistant, the text of your messages, and the minimum context needed to produce a useful answer (for example, the word you are practising or your target level).
  • What is not sent: your name, email address, phone number, or payment details. We do not send your contact details to AI providers.
  • What they do with it: they process the request, return a result to us, and act only on our instructions under their contracts with us. We do not permit them to use your content for their own purposes.
  • Where: these providers operate outside your country and outside the EEA, including in the United States. See section 8.

We may change AI providers as the Service evolves. Any provider we use is bound by a data processing agreement that limits them to processing your content for the purpose of answering your request.

7. Who else we share data with

We share personal data only with the following categories of recipients, and only as far as necessary:

  • AI providers — they receive only the content of your requests, as described in section 6.
  • Hosting and infrastructure providers — to run our servers and store data.
  • Push notification provider (Google Firebase Cloud Messaging) — receives the registration token and message payload needed to deliver notifications to Android and iOS devices, including the RuStore Android app.
  • Analytics provider (PostHog) — receives server-side product events and associated attribution and technical fields, including IP address for paywall-view events and campaign-link clicks, to help us measure acquisition and improve onboarding and paid-access prompts.
  • Payment providers and app stores (Google and payment processors) — to process subscriptions, trials and refunds on supported non-iOS surfaces. The iOS App Store version has no purchases and sends no purchase or subscription data to Apple.
  • Communication platforms (Telegram, VK) — where you use BrioVocab as a mini app inside their platform, and their own privacy policies also apply to your use of their platform.
  • Authorities — where we are legally obliged to disclose data, or where disclosure is necessary to establish, exercise or defend legal claims.

Teachers and partners are not on this list. If you arrived through a teacher's referral link, that teacher is shown counts for their own link and nothing else. We do not disclose your identity, your contact details, your learning activity or your payment details to them.

We do not sell personal data and we do not share it with data brokers.

8. International transfers

The providers we rely on operate in several countries, including the United States. If you are in the EEA or the UK, this means some data may be processed outside the EEA/UK, in countries that have not received an adequacy decision from the European Commission and that may not provide the same level of protection as your home country.

AI providers do not receive your personal details. As described in section 6, they receive only the content of the request you submit — a voice recording, an image, or the text of a message — together with the minimum learning context needed to answer it; never your name, contact details, account data or payment information.

Where a processor handles data on our behalf, we put a data processing agreement in place and use appropriate safeguards, such as the European Commission's Standard Contractual Clauses, where those are available to us. Where they are not, transfers that are necessary to deliver the Service you asked for are made on the basis of Article 49(1)(b) of the GDPR (performance of a contract with you). You can ask us for details at vasily@briovocab.com.

9. How long we keep data

  • Account data, learning progress, voice recordings, images and AI messages — until you delete them or delete your account (see section 10).
  • Payment and accounting records — for as long as tax and accounting law requires us to keep them, even after you delete your account.
  • Referral attribution — the record of which teacher's link brought you, until you delete your account.
  • Technical and analytics event logs — normally for a short period, and then deleted or anonymised.
  • Backups — deleted content is removed from backups on our normal backup rotation, and is not used for ordinary operations in the meantime.

10. Deleting your data and your account

You can delete your account directly in the app, in the app settings. Deleting your account deletes your profile, your learning progress, your voice recordings, your images and your AI messages. It also removes the record of which teacher's referral link brought you, and, if you published referral links yourself, switches them off. Credits already paid to a teacher stay in that teacher's own account, without any reference to you.

You can also request deletion by emailing vasily@briovocab.com with the subject "Account deletion". We will action the request within 30 days.

Some data is kept after deletion where the law requires it — in particular records of payments and refunds, which we must retain for tax and accounting purposes. Retained data is isolated and used only for that purpose.

11. Your rights

Depending on where you live, you have the right to:

  • Access the personal data we hold about you, and get a copy of it.
  • Rectify data that is inaccurate or incomplete.
  • Erase your data ("right to be forgotten").
  • Restrict or object to processing based on our legitimate interests.
  • Portability — receive your data in a machine-readable format and have it transferred to another controller.
  • Withdraw consent at any time, without affecting processing that already took place. Withdrawing microphone permission in your device settings, or turning off AI data sharing in the app settings, are two ways to do this.
  • Complain to a supervisory authority. In France, this is the CNIL (cnil.fr). You can also complain to the authority in your country of residence.

To exercise any of these rights, email vasily@briovocab.com. We respond within 30 days. We may ask you for information to confirm that the request comes from you.

12. Children

BrioVocab is not directed at children under 13, and we do not knowingly collect personal data from them. In the EEA, if you are under the age of digital consent in your country (between 13 and 16 depending on the country), you may use BrioVocab only with the consent of a parent or guardian. If you believe a child has provided us with personal data, contact us and we will delete it.

13. Security

We use reasonable technical and organisational measures to protect your data against unauthorised access, alteration, disclosure and loss. Data is encrypted in transit. Access to personal data is limited to those who need it to operate the Service. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

14. Changes to this policy

We may update this policy. When we do, we change the "Last updated" date at the top and publish the new version on this page. If a change materially affects how we use your data, we will tell you in the app or by email before it takes effect.

15. Contact

For any question about this policy, your data, or a deletion request: