Privacy Policy
Effective date: 30 July 2026
Last updated: 30 July 2026
1. Who we are
This Privacy Policy explains how Parlang processes personal data when you use:
- the Parlang2 mobile application, presented as “Parlang”;
- parlang.org;
- parlang.app;
- a Parlang account and its cloud features; or
- the Parlang Developer and Reviewer Program.
The data controller is:
Jiaxun Chen, operating as Parlang
Affolternstrasse 56
8050 Zürich
Switzerland
Email: info@parlang.org
In this Policy, “Parlang,” “we,” “us,” and “our” refer to that operator.
2. Summary
Parlang processes account and study data to provide comparative language learning, synchronized Books and collections, assessments, settings, and AI-assisted exercises.
Important points include:
- The native application can be used as a guest for selected features.
- Account and synchronized data are hosted using Supabase.
- The websites are hosted using Vercel.
- By default, AI-assisted learning features currently use Ollama Cloud.
- Google and Apple may process information when you choose their respective sign-in methods.
- The current release contains no advertising SDK or third-party behavioral-analytics SDK.
- We do not sell personal data or share it for cross-context behavioral advertising.
- The current mobile release does not request access to your microphone, camera, location, contacts, photos, or advertising identifier.
- Mobile pronunciation uses device text-to-speech. Parlang does not record your voice.
- Mobile study reminders are scheduled locally on your device. Parlang does not currently collect an Apple push-notification device token for those reminders.
- Personal provider API keys entered in the current mobile release are stored in the Apple Keychain on that device.
3. Personal data we process
3.1 Account and identity data
When you create or use an account, we may process:
- email address;
- username;
- optional display name;
- account and user identifiers;
- chosen application language;
- account status and plan tier;
- email-verification and password-recovery status;
- authentication-session information; and
- account creation and update timestamps.
Supabase processes passwords and authentication credentials. Parlang does not intentionally store readable passwords.
If you choose Google sign-in, we may receive information authorized through Google and Supabase, such as your Google account identifier, email address, name, profile image, and authentication metadata. We do not receive your Google password.
If you choose Sign in with Apple, Parlang may receive your Apple account identifier, name if you choose to provide it, and either your email address or an Apple private relay email address. Parlang does not receive your Apple ID password.
3.2 Study profile and personalization data
We may process information used to personalize your learning, including:
- Book and collection names;
- selected and target languages;
- current or assessed CEFR level;
- study purpose, including custom free text;
- learning habits and preferred exercise formats;
- sessions per week;
- minutes per session;
- preferred study time;
- selected dictionary fields and categories;
- active Book and language ordering;
- pronunciation voice, rate, pitch, and volume;
- AI provider and model selections;
- appearance and interface-language settings; and
- reminder preferences, selected reminder languages, and reminder times.
Do not place sensitive personal information in a custom Book name or study-purpose field.
3.3 Vocabulary, assessment, and progress data
For signed-in synchronization and study history, we may process:
- vocabulary collections and saved dictionary-entry identifiers;
- assessment and exam sessions;
- generated questions, prompts, accepted answers, and explanations;
- your submitted answers;
- whether an answer was submitted or correct;
- assessment scores and completion status;
- recommended dictionary concepts;
- summaries and study recommendations;
- incorrect-answer identifiers; and
- creation, completion, archive, Trash, and scheduled-deletion timestamps.
3.4 Dictionary searches and website activity
When you use the web dictionary, we may process:
- search text;
- selected languages and search fields;
- result-count and filter preferences;
- requested pages and URLs;
- timestamps;
- referring page;
- IP address;
- browser, operating-system, device, and language information; and
- ordinary server, security, and error logs.
Because web search text is sent as part of a request, it may appear temporarily in hosting or server logs. Do not use the dictionary search box for personal or confidential information.
Dictionary searches performed solely against the bundled mobile dictionary may remain on the device unless they are used in an account feature or cloud request.
3.5 AI-generation data
By default, Parlang’s AI-assisted learning features currently use Ollama Cloud. When you request an AI-assisted exercise, the study information described below is transmitted to Ollama Cloud for processing.
Parlang may send:
- current study level;
- study purpose;
- selected learning habits;
- study-language priority;
- display-language code;
- candidate words and phrases;
- translations;
- semantic identifiers; and
- candidate level bands.
The generated questions and model response are returned to Parlang. Your name, username, email address, account password, and submitted assessment answers are not intentionally included in the current cloze-generation request.
If a custom study purpose contains personal information, that text may nevertheless be included. You should therefore keep custom study purposes non-identifying.
We do not use your study data to train a Parlang general-purpose AI model. According to Ollama’s current Privacy Policy, Ollama processes cloud prompts and responses transiently to provide the service and does not use them to train its models. Ollama’s practices remain governed by its own policy and may change independently.
Parlang intends to replace this external cloud-processing arrangement with a Parlang-controlled local-cloud hosting architecture in a future release. Until that replacement is operational, this Policy describes Ollama Cloud as the active default provider.
Before materially changing AI processing, hosting locations, data recipients, or purposes, Parlang will update this Policy and provide any notice or consent mechanism required by law.
AI-generated content does not produce legal or similarly significant decisions about you. CEFR assessments and study recommendations are educational estimates only.
3.6 Developer and Reviewer Program data
If you apply for or participate in the Developer and Reviewer Program, we may process:
- first name and surname;
- desired username;
- email address;
- optional telephone number;
- optional organization or company;
- reason for requesting access;
- program role, membership status, invitation, and review status;
- administrator or reviewer notes;
- dictionary error reports;
- proposed corrections and replacement text;
- snapshots of the affected dictionary entry;
- approval, denial, and action history; and
- timestamps and identifiers of participants involved in a review.
Authorized administrators, developers, and reviewers may access program submissions where necessary to manage access, review corrections, and maintain an integrity audit trail.
Accepted dictionary corrections may become part of shared dictionary content. Personal contact details are not intended to be displayed as part of public dictionary entries.
3.7 Personal provider API keys
Certain account tiers may allow you to enter an API key for an external AI provider.
In the current mobile release:
- the key is stored in the Apple Keychain;
- Keychain accessibility is limited to the device after first unlock;
- the key is not displayed in full after storage; and
- the current settings flow does not upload the key to Parlang’s cloud database.
If a future version offers optional cloud synchronization of provider keys, Parlang will provide an updated notice before activating that collection.
When a personal key is used to contact its provider, that provider receives the applicable request and may process your IP address, prompt, model selection, and related metadata under its own terms and privacy policy.
3.8 Communications
When you contact us, we may process:
- your name and contact details;
- the content of your message;
- attachments you choose to provide;
- support or complaint history; and
- information needed to investigate and respond.
Please remove unnecessary passwords, API keys, or sensitive personal information before sending support material.
4. Data we do not intentionally collect
The current release does not intentionally collect:
- precise or approximate device location through location APIs;
- microphone recordings or speech-recognition data;
- photographs, camera images, or photo-library contents;
- contacts or address-book data;
- health or fitness data;
- payment-card numbers;
- government identifiers;
- advertising identifiers;
- data about other applications installed on your device; or
- data for third-party advertising or cross-service tracking.
Device, hosting, identity, AI, and network providers may independently receive technical information such as an IP address when their services are contacted.
5. How we obtain data
We obtain personal data:
- directly from you when you register, configure a Book, submit an answer, contact us, or apply to a program;
- automatically from your browser, device, and network when the Service handles a request;
- from Google when you choose Google sign-in;
- from Apple when you choose Sign in with Apple;
- from service providers that operate authentication, hosting, database, email, or AI functionality; and
- from authorized program administrators when they review an application or contribution.
6. Why we process personal data
Where the GDPR, UK GDPR, or similar law applies, we rely on the following legal bases.
| Purpose | Typical data | Legal basis |
|---|---|---|
| Create and authenticate accounts | Email, username, credentials, identity-provider data, session data | Performance of a contract |
| Provide study, dictionary, synchronization, and account features | Profile, Books, collections, settings, progress | Performance of a contract |
| Generate AI-assisted exercises | Study level, purpose, habits, languages, candidate vocabulary | Performance of a contract and, where legally required, consent |
| Provide Google or Apple sign-in | Identity and authentication data from the selected provider | Your choice and consent; performance of a contract |
| Schedule reminders | Reminder settings and local notification permission | Your consent and device settings |
| Secure and troubleshoot the Service | IP address, request logs, errors, account identifiers | Legitimate interests in security, fraud prevention, reliability, and support |
| Apply usage limits and protect provider resources | Account identifier, operation and usage metadata | Legitimate interests in service integrity and cost control |
| Personalize interface and study settings | Language, appearance, model, pronunciation, notification preferences | Performance of a contract |
| Operate the Developer and Reviewer Program | Application data, roles, reports, review records | Steps requested before participation, performance of a program agreement, and legitimate interests in editorial quality |
| Respond to messages and privacy requests | Contact and communication data | Performance of a contract, legitimate interests, or legal obligation |
| Meet legal obligations and defend claims | Relevant account, transaction, security, and communication records | Legal obligation and legitimate interests |
| Send optional marketing | Email and consent records | Consent, where required |
Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect earlier lawful processing.
Our legitimate interests do not override your rights and freedoms. You may object to relevant processing as described below.
7. Cookies and local storage
Parlang uses cookies and browser storage for authentication and functional preferences.
| Technology | Purpose | Typical duration |
|---|---|---|
| Supabase authentication cookies | Maintain and refresh a signed-in web session | Session-dependent or until expiry or sign-out |
parlang_site_language | Remember website language | Up to one year |
parlang_web_display_language | Remember web-app display language | Up to one year |
parlang_web_selected_languages | Remember selected comparison languages | Up to one year |
| Browser local storage | Remember display language, filters, search fields, result count, guest choice, and other interface preferences | Until cleared or replaced |
| Device preferences | Store application, pronunciation, AI, and notification settings | Until changed, reset, or application data is removed |
| Apple Keychain | Store mobile session tokens and optional personal provider keys | Until removed, the account is cleared, or device storage is erased |
These technologies are used for requested functionality and account security. At the effective date, Parlang does not use advertising cookies or a third-party behavioral-analytics SDK.
You may clear cookies and local storage in your browser. Doing so may sign you out or reset preferences. Browser “Do Not Track” signals do not change Parlang’s behavior because Parlang does not currently conduct cross-site behavioral tracking.
8. Analytics and service measurement
At the effective date:
- Parlang does not integrate an advertising network;
- Parlang does not integrate a third-party behavioral-analytics SDK;
- Parlang does not sell analytics profiles; and
- Parlang does not use Service activity for cross-context behavioral advertising.
We may process first-party operational events and ordinary service logs associated with an account, such as an event or operation name, limited event properties, user identifier, and timestamp. These records may be used for:
- authentication and security;
- preventing abuse;
- enforcing quotas;
- diagnosing failures;
- measuring feature reliability; and
- understanding aggregate service operation.
We will update this Policy and obtain consent where required before introducing non-essential analytics, advertising, or materially different tracking.
9. Local and cloud processing
Guest and device-local processing
Guest preferences, local dictionary use, pronunciation settings, and unsynchronized study information may be stored only on your device.
Removing the application or clearing its storage generally removes device-local data, subject to device backups and operating-system behavior.
Signed-in cloud processing
When you sign in, Parlang may synchronize profile, study, collection, assessment, settings, and progress data through Supabase.
Signing out ends the active authenticated session but does not delete your cloud account or synchronized study records. Use account deletion or a privacy request for cloud erasure.
Notifications
Study reminders are scheduled through the operating system as local calendar notifications. Notification permission can be withdrawn in device settings.
Reminder preferences may be synchronized with your account, but Parlang does not currently operate a remote promotional-push system or collect a push-notification device token for this feature.
10. When we disclose personal data
We disclose personal data only as reasonably necessary for the purposes described in this Policy.
Service providers
| Provider or category | Purpose and data involved |
|---|---|
| Supabase | Account authentication, database storage, synchronization, server functions, recovery workflows, and related technical logs |
| Vercel | Website and web-application hosting, request delivery, security, and operational logs |
| Ollama Cloud | Default AI generation using study configuration and candidate vocabulary included in a prompt |
| Authentication when you choose Google sign-in | |
| Apple | Authentication when you choose Sign in with Apple, application distribution, device Keychain, local notifications, and operating-system text-to-speech |
| Email and network providers | Delivery of verification, recovery, and support communications |
| Professional advisers | Legal, security, accounting, insurance, and compliance support where necessary |
We require service providers handling data on our behalf to use appropriate confidentiality, security, and data-protection measures through applicable contractual terms.
Authorized program participants
Developer and Reviewer Program applications and reports may be disclosed to authorized Parlang administrators, developers, and reviewers where needed for access decisions, dictionary review, and audit history.
Legal and safety disclosures
We may disclose information where reasonably necessary to:
- comply with law, court orders, or valid governmental requests;
- protect users, Parlang, providers, or the public;
- investigate fraud, abuse, security incidents, or rights violations;
- establish, exercise, or defend legal claims; or
- enforce applicable agreements.
Business transfers
If Parlang undergoes a merger, acquisition, restructuring, financing, or transfer of the Service, personal data may be disclosed subject to confidentiality and applicable law. We will provide notice if personal data becomes subject to a materially different privacy policy.
11. No sale or behavioral advertising
Parlang does not sell personal data.
Parlang does not share personal data for cross-context behavioral advertising and does not use sensitive personal information to infer characteristics about you.
If these practices change, we will update this Policy and provide any opt-out or consent mechanism required by law before the change takes effect.
12. International data transfers
Parlang is operated from Switzerland. Providers and their subprocessors may process data in Switzerland, the European Economic Area, the United States, or other countries in which they operate.
These countries may have different data-protection laws. Where required, we use or rely on safeguards such as:
- an official adequacy decision;
- the European Commission’s Standard Contractual Clauses;
- Swiss-law adaptations or safeguards recognized by the Swiss Federal Data Protection and Information Commissioner;
- applicable data-processing agreements; and
- supplementary contractual, organizational, or technical safeguards.
You may contact info@parlang.org for information about safeguards applicable to a particular transfer, subject to protection of confidential and security information.
13. Retention
We retain personal data only for as long as reasonably necessary for the relevant purpose.
Account and synchronized study data
Account, profile, Book, collection, settings, assessment, and progress data are generally retained while your account remains active.
Deleting your account initiates deletion of the authentication account and user-linked active database records. Residual copies may remain temporarily in protected backups, logs, or disaster-recovery systems until normal rotation.
Trash and archived items
Archived items remain associated with your account until they are restored, moved to Trash, permanently deleted, or the account is deleted.
When a Book or collection is moved to Trash, Parlang schedules it for permanent deletion 30 days later. The deletion state is synchronized for signed-in users so that the corresponding account data is removed from both the local application and cloud storage.
You may permanently delete an item before the 30-day period expires. For deletion of all account-associated data, use the Delete Account function or submit a privacy request to info@parlang.org.
Device-local data
Account deletion removes account-linked data handled by Parlang but may not erase independent copies remaining in device or operating-system backups. Remove application data or backups separately where desired.
Developer and Reviewer Program records
Program applications may be retained after ordinary account deletion when needed to manage prior decisions, security, access history, or legal obligations. You may separately request deletion of an application record.
Accepted Contributions and associated integrity records may be retained for as long as the corrected dictionary content remains in use. We will remove or minimize direct personal identifiers where feasible and legally required.
Logs and communications
Security, support, request, and operational logs are retained according to their sensitivity, the applicable provider’s rotation cycle, the time needed to investigate an issue, and applicable limitation or legal-retention periods.
Information needed to meet legal obligations, prevent fraud, resolve disputes, or enforce agreements may be retained until that purpose expires.
14. Security
Parlang uses technical and organizational measures designed to protect personal data, including:
- encrypted HTTPS/TLS connections;
- managed authentication rather than readable password storage;
- Apple Keychain storage for mobile sessions and personal provider keys;
- per-user database access controls and row-level security;
- authenticated server functions;
- access restrictions for administrative and reviewer tools;
- separation of public dictionary content from user-owned study data; and
- limited access to production data based on operational need.
No storage or transmission method is completely secure. You should use a strong, unique password, protect your device, revoke exposed provider keys, and notify us of suspected unauthorized access.
15. Your choices
You can:
- use selected mobile or web features as a guest;
- update your username, display name, language, and settings;
- sign out of your account;
- choose whether to use Google or Apple sign-in;
- manage or revoke Google access through your Google account;
- manage Sign in with Apple through your Apple ID settings;
- grant or deny notification permission;
- disable notifications in device settings;
- clear cookies and local storage;
- delete a personal provider key from the app;
- deactivate your account; or
- delete your account through https://parlang.org/account.
Deactivation does not erase your data. Account deletion is required for ordinary account-level erasure.
16. Your privacy rights
Depending on your location, you may have the right to:
- know whether we process your personal data;
- receive information about that processing;
- access a copy of your personal data;
- correct inaccurate or incomplete data;
- request deletion;
- restrict processing;
- receive portable data in a commonly used format;
- object to processing based on legitimate interests;
- withdraw consent;
- object to direct marketing; and
- complain to a data-protection authority.
Submit a request to info@parlang.org. Describe the account and right involved. We may request information reasonably necessary to verify identity and protect the account.
We will respond within the period required by applicable law. Rights may be limited where an exemption applies, such as protecting another person’s rights, security, legal obligations, or legal claims.
Swiss complaints
You may contact the Swiss Federal Data Protection and Information Commissioner.
EEA and UK complaints
You may complain to the data-protection authority for your habitual residence, workplace, or the place of an alleged infringement.
United States state privacy rights
Residents of jurisdictions with applicable state privacy laws may request access, correction, deletion, or portability and may appeal a refusal where local law provides that right.
Parlang does not sell personal data or share it for cross-context behavioral advertising. We will not discriminate against you for exercising an applicable privacy right.
17. Children’s privacy
Parlang accounts are intended for users aged 16 or older.
We do not knowingly collect account data from children under 16. If you believe a child under 16 created an account or provided personal information without proper authorization, contact info@parlang.org. We will investigate and delete the information where required.
Guest use by younger learners should occur only under parent, guardian, or teacher supervision and without submitting personal information.
18. Automated decisions
Parlang may automatically calculate scores, estimated CEFR levels, answer correctness, study recommendations, and content selections.
These results are designed only to assist learning. They do not determine legal rights, employment, admission, credit, insurance, or other similarly significant matters.
Developer and Reviewer Program access and content-review decisions may involve human review.
19. Changes to this Policy
We may update this Policy when data practices, features, providers, or legal requirements change.
The updated Policy will show a new “Last updated” date. We will provide additional notice—and obtain consent where required—before materially different processing begins.
20. Contact
Privacy questions and requests may be sent to:
Jiaxun Chen, operating as Parlang
Affolternstrasse 56
8050 Zürich
Switzerland
Email: info@parlang.org
Account management: https://parlang.org/account