← Back to Support

Privacy Policy

Last Updated: January 2025

🔒Introduction

VocaBuddy ("we," "our," "us," or "the Company") is committed to protecting your privacy and ensuring transparency in how we collect, use, and safeguard your information. This Privacy Policy explains our practices regarding your personal data when you use our mobile application ("the App").

By using VocaBuddy, you agree to the collection and use of information in accordance with this Privacy Policy.

🛡️ Our Privacy Promise

We prioritize your privacy above all else. We never sell your data, never display ads, and use industry-leading encryption to keep your information secure.

📊Information We Collect

1. Personal Information

When you use VocaBuddy, we collect the following personal information:

  • Apple ID Information: When you sign in with Apple, we receive your unique Apple ID identifier and, if you choose to share it, your email address.
  • User Profile Data: Your language preferences, learning level (beginner, intermediate, advanced), interests, and learning goals.
  • Learning Data: Words you save, definitions, example sentences, learning progress, quiz results, game scores, and usage statistics.
  • Subscription Information: Your subscription tier (Free, Plus, or Premium), payment status, and subscription period.

2. Automatically Collected Information

  • Usage Data: App features you interact with, session duration, frequency of use, and interaction patterns.
  • Device Information: Device type and model, iOS version, app version, device language, and timezone.
  • Performance Data: Crash reports, error logs, and performance metrics to improve app stability.

3. AI-Generated Content

Content generated by our AI services (powered by OpenAI GPT) including word definitions, examples, stories, and recommendations. This content is created based on your vocabulary selections and learning preferences.

Important: We do NOT collect your precise location, contacts, photos, camera access, microphone recordings, or any other sensitive device permissions.

⚙️How We Use Your Information

We use your information for the following purposes:

  • Provide Core Services: Enable vocabulary learning, progress tracking, and game features.
  • AI Personalization: Generate personalized word definitions, example sentences, stories, and recommendations using OpenAI's GPT API.
  • Data Synchronization: Sync your learning data across all your Apple devices via iCloud.
  • Subscription Management: Process and manage your subscription purchases through Apple's StoreKit framework.
  • Service Communications: Send important updates, security alerts, and customer support responses.
  • Product Improvement: Analyze anonymized usage patterns to improve features, fix bugs, and enhance user experience.
  • Legal Compliance: Comply with applicable laws, regulations, and legal processes.

🤖 AI Content Generation

When you request AI-powered features (word enrichment, story generation, recommendations), we send your vocabulary selections and learning preferences to OpenAI's API. OpenAI processes this data to generate personalized content. We have a data processing agreement with OpenAI that requires them to comply with our privacy standards.

☁️Data Storage and Security

Where Your Data is Stored

iCloud Storage

Your learning data is stored in your private iCloud account using Apple's CloudKit framework. Only you can access this data through your Apple ID.

Encryption

All data is encrypted in transit using TLS 1.3+ and at rest using AES-256 encryption.

Access Control

Access to your data requires Apple ID authentication. We cannot access your iCloud data.

Data Residency

Data location follows Apple's iCloud data residency policies based on your Apple ID region.

Security Measures

  • Encryption: End-to-end encryption for data transmission and storage.
  • Apple Sign-In: Secure authentication through Apple's Sign in with Apple service.
  • No Third-Party Tracking: We do not use tracking SDKs, analytics that identify you personally, or advertising networks.
  • Regular Audits: Security reviews and updates to protect against emerging threats.
  • Data Minimization: We collect only the data necessary to provide our services.

Data Breach Notification: In the unlikely event of a data breach affecting your personal information, we will notify you within 72 hours via email and in-app notification, and report to relevant authorities as required by law.

🔗Third-Party Services

Services We Use

What We Do NOT Do

We absolutely do NOT:

  • Share your personal information with advertisers or marketing companies
  • Use tracking cookies or fingerprinting technologies
  • Sell, rent, or trade your data to third parties
  • Display advertisements within the app
  • Use your data for purposes other than providing our services

⚖️Your Rights and Choices

Under GDPR (European Union)

If you are located in the European Economic Area (EEA), UK, or Switzerland, you have the following rights:

  • Right to Access: Request a copy of all personal data we hold about you.
  • Right to Rectification: Correct inaccurate or incomplete personal data.
  • Right to Erasure: Request deletion of your personal data ("right to be forgotten").
  • Right to Restriction: Limit how we process your personal data.
  • Right to Data Portability: Receive your data in a structured, machine-readable format.
  • Right to Object: Object to processing of your personal data.
  • Right to Withdraw Consent: Withdraw consent at any time without affecting lawfulness of prior processing.
  • Right to Lodge a Complaint: File a complaint with your local data protection authority.

Under CCPA/CPRA (California)

If you are a California resident, you have the following rights:

  • Right to Know: Request disclosure of personal information collected, sources, purposes, and third parties with whom it's shared.
  • Right to Delete: Request deletion of personal information we've collected.
  • Right to Opt-Out: Opt-out of the sale of personal information (Note: We do NOT sell personal information).
  • Right to Non-Discrimination: Not be discriminated against for exercising your privacy rights.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Limit: Limit the use and disclosure of sensitive personal information.

How to Exercise Your Rights

📧 Email Request

Contact us at menesahin99@gmail.com with your request.

📱 In-App Settings

Navigate to Profile → Account Settings → Privacy Rights to manage your preferences.

⏱️ Response Time

We respond to all verified requests within 30 days (or as required by applicable law).

✅ Verification

We may request additional information to verify your identity before processing requests.

🗑️Account and Data Deletion

You can permanently delete your VocaBuddy account and all associated data at any time directly from within the app.

How to Delete Your Account

  1. Open the VocaBuddy app on your device
  2. Navigate to Profile → Account Settings
  3. Scroll down to the "Danger Zone" section
  4. Tap "Delete Account"
  5. Read the warning and confirm your decision
  6. Enter your password or use Face ID/Touch ID to confirm

What Gets Deleted

When you delete your account, the following data is permanently removed from all your devices:

  • All saved words, definitions, and example sentences
  • All AI-generated stories and personalized content
  • All game session records, scores, and achievements
  • Learning progress, statistics, and streaks
  • All user preferences and settings
  • Your user profile and account information
  • Subscription history (billing records retained as required by law)

⚠️ Important Notes

  • Irreversible: Account deletion is permanent and cannot be undone. Your data cannot be recovered.
  • All Devices: Data will be permanently deleted from all your devices via iCloud sync.
  • Subscription: Active subscriptions must be canceled separately in App Store settings to prevent future charges.
  • No Refunds: No refunds will be issued for remaining subscription time.
  • Legal Retention: Some data may be retained for legal compliance (e.g., payment records for tax purposes) as required by law.

Alternative Options

If you don't want to permanently delete your account, consider these alternatives:

  • Sign Out: Simply sign out to stop using the app temporarily while keeping your data.
  • Disable iCloud Sync: Turn off iCloud sync in settings to keep data local only.
  • Cancel Subscription: Downgrade to the free tier while keeping your account and data.
  • Export Data: Export your vocabulary list before making any changes.

👶Children's Privacy (COPPA Compliance)

VocaBuddy is rated 4+ and suitable for users of all ages. However, we take children's privacy seriously and comply with the Children's Online Privacy Protection Act (COPPA).

  • Age Requirement: Users under 13 require parental consent to create an account.
  • No Targeted Advertising: We never display advertisements or targeted marketing to children.
  • Parental Controls: Parents can review and delete their child's account at any time.
  • Limited Data Collection: We collect only the minimum data necessary to provide educational services.
  • No Third-Party Sharing: We never share children's personal information with third parties for marketing purposes.

If you believe we have collected information from a child under 13 without proper consent, please contact us immediately at menesahin99@gmail.com.

🌍International Data Transfers

Your personal data is stored in your iCloud account, which follows Apple's data residency policies based on your Apple ID country/region settings.

Data Transfer Mechanisms

  • EU-US Data Privacy Framework: We comply with applicable frameworks for cross-border data transfers.
  • Standard Contractual Clauses: We use EU-approved Standard Contractual Clauses (SCCs) for data transfers.
  • Adequate Protection: We ensure adequate safeguards are in place for international data transfers.

OpenAI Data Processing

When using AI features, your vocabulary selections may be processed by OpenAI's servers located in the United States. This processing is necessary to provide AI-powered definitions, examples, and stories. OpenAI is certified under the EU-US Data Privacy Framework and maintains GDPR compliance.

📜Data Retention

We retain your personal data only as long as necessary to provide our services and comply with legal obligations.

Retention Periods

  • Active Accounts: Data retained while your account is active and for the duration of your subscription.
  • Inactive Accounts: Accounts inactive for 24 months may be flagged for deletion (with prior notice).
  • Deleted Accounts: Most data deleted immediately; some records retained for legal compliance (e.g., payment records for 7 years for tax purposes).
  • Usage Analytics: Anonymized usage data may be retained indefinitely for product improvement.
  • Support Communications: Customer support emails retained for 3 years.

🍪Cookies and Tracking

VocaBuddy does not use cookies, tracking pixels, or any similar tracking technologies within the mobile app.

Our website (this support page) may use minimal functional cookies to:

  • Remember your language preference
  • Maintain secure sessions
  • Prevent fraud and abuse

We do NOT use advertising cookies, analytics cookies, or third-party tracking cookies.

📱Your California Privacy Rights (Shine the Light)

California Civil Code Section 1798.83 permits California residents to request information about disclosure of personal information to third parties for direct marketing purposes.

VocaBuddy does NOT share personal information with third parties for their direct marketing purposes.

🔄Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

How We Notify You

  • Material Changes: We will notify you via email (if provided) and prominent in-app notification at least 30 days before changes take effect.
  • Minor Changes: Non-material changes will be posted with an updated "Last Updated" date.
  • Continued Use: Your continued use of VocaBuddy after changes take effect constitutes acceptance of the updated Privacy Policy.
  • Version History: Previous versions available upon request.

📞Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

⏱️ Response Time

We typically respond within 24-48 hours

📍 Data Protection Officer

For GDPR inquiries: menesahin99@gmail.com

🌐 More Information

Visit our Support Center

🛡️ Commitment to Privacy

VocaBuddy is committed to protecting your privacy and maintaining the highest standards of data protection. We continuously review and update our practices to ensure compliance with global privacy regulations and to exceed user expectations.

⚖️Legal Compliance

This Privacy Policy complies with:

  • General Data Protection Regulation (GDPR) - EU
  • California Consumer Privacy Act (CCPA/CPRA)
  • Children's Online Privacy Protection Act (COPPA)
  • Apple App Store Review Guidelines
  • ePrivacy Directive
  • UK Data Protection Act 2018
  • Australian Privacy Principles (APP)
  • Personal Information Protection and Electronic Documents Act (PIPEDA) - Canada