Who we are
Langvie is run by Olesia Borysova e.U. from Vienna, Austria, which is the controller for everything described on this page. One address handles every question about it.
Olesia Borysova e.U.
Langvie
Turnergasse 24/11, 1150 Vienna
Austria
support@langvie.app
What we collect and why
The rule we work to is collecting only what a flashcard schedule needs.
Langvie asks for an account before it opens, because a deck that syncs between devices has to live somewhere other than one browser. These things are kept:
- Your login. An email address and a password hash. Sign in with Google and Google returns your email address, your name and your profile picture.
- Your settings. Display name, the language you are learning, the language you read translations in, your level, your daily goal.
- Your deck. Each word you have met, its stage on a ladder that runs from one day out to a year, when it is next due, and how often you have reviewed or missed it.
- Your reviews. One row per card you rate, holding the word, whether you knew it, and the time.
- Your league place. Your display name, your profile picture if you signed in with Google, and your points for the week. The other learners in your league see these three things and nothing else.
- Your classes. If you join a class, its teacher sees your name and how much you study in it. If you teach one, your students see your name and the class name.
- Your speaking practice. The text of your conversations with the AI partner, the mistakes it noted, and your pronunciation scores. The recordings themselves are not kept.
- What you send us. Feedback, film and feature requests, and names you report on the league board, with the account that sent them so we can answer.
All of it runs your account and syncs your deck between devices, which is Article 6(1)(b) of the GDPR, performing a contract. Keeping the service up and stopping abuse rests on Article 6(1)(f), our legitimate interest in a working app. Measurement is the one thing that runs on consent, Article 6(1)(a), which is why the website asks on your first visit and the app asks on its first launch.
An email address is the only thing you have to give. There is no profiling and no automated decision making. The schedule is arithmetic on your own answers.
Analytics
Three tools measure how Langvie gets used, and not one of them runs before you allow it. The website asks on your first visit. The app asks on its first launch, and keeps the answer as a switch under Privacy in Settings.
Google Analytics counts pages on the website and screens in the app, which are one property with a stream each, so a visit that crosses from one to the other is counted once rather than twice. Microsoft Clarity records sessions in the app and builds heatmaps from them, which is how a screen that people get stuck on becomes visible. Amplitude, in its European region, records which screens you open, which words you rate and how a study session ends, together with a replay of the interface as you move through it.
A replay is a reconstruction of what was on screen and where you tapped, not a video and not your camera. None of the three is ever given your password. Amplitude is given your user id and your email address, so that a person in a chart is the same person who wrote the support mail. Google Analytics and Clarity are given neither.
All three rest on your consent, Article 6(1)(a). Decline and nothing is fetched at all: no library, no cookie, and not even the cookieless ping Google's consent mode would otherwise send before anyone had agreed to it. Withdrawing is the same switch in Settings and takes effect the moment you throw it. On the website, clearing site data asks you again. A content blocker also stops all three cleanly, and both halves are built to work when none of them loads.
Speaking and scanning
Two features send something to be processed and keep none of it. When you practice speaking, your recording goes to Google Gemini, which transcribes it and writes the reply, and to Microsoft Azure, which scores your pronunciation and reads replies aloud. When you scan a page, the photo goes to Google Gemini, which reads the words on it.
Langvie does not store the recording or the photo. Each is sent within one request and discarded when the answer comes back. What stays is listed above: the text of the conversation, your scores, and the words you chose to add. Both features run on the contract, Article 6(1)(b), and only when you press the button that starts them.
What we never collect
No advertising, no ad targeting, no third party ad cookies, no fingerprinting, no cross site tracking. It is free and has no payment step, so no card details exist. It never asks for your location or contacts. It asks for the microphone only when you practice speaking, and for the camera or your photos only when you scan a page. Google Analytics and Clarity are never given your email address.
We do not sell or rent your data, hand it to advertisers, or train machine learning models on it.
What is stored on your device
Before you answer, each half writes exactly one thing: the answer itself, held in local storage so the question comes once. There are no cookies at that point, on either half.
Accept and the cookies arrive with the tools. Google Analytics writes two, _ga and a second keyed to its property, both holding a random number that counts you as one visitor rather than five, both expiring after two years. In the app, Amplitude and Clarity add a pair each on the same principle: a number that identifies the browser, not you. Decline and none of the six is ever written.
The app writes four more things to local storage, whichever way you answered, and all four are functional.
- The session token that keeps you signed in.
- A copy of your settings and deck, stamped with the account that wrote it, so the app opens fast and works with no signal.
- Your place in a film, so a session resumes where you stopped.
- A flag recording that you have seen the welcome screen.
Signing out clears the token and the copy behind it, and clearing site data clears everything above. Your deck survives either, because the copy on the phone is a mirror of the rows in the database rather than the only version of them.
How long we keep it
Your account and everything attached to it lasts as long as the account does. Deleting it drops your rows from every table at once, because each is keyed to your user id and cascades. There is no soft delete and no archive. Supabase's routine backups may hold a copy briefly, and those expire on their own schedule.
You can delete your account yourself: open Settings, go to Account and tap Delete account. That removes the account and everything in the database at once. Amplitude keeps its own copy of your events and email address, so email us and we delete that copy too, within 30 days. If you can no longer sign in, email us and we delete the whole account for you.
Your rights
Under the GDPR you can ask for a copy of your data (Article 15), a correction (16) or deletion (17). You can also request a portable export (20), a pause on processing (18), or object to anything resting on legitimate interest (21).
Email us. There is no form, the answer comes within 30 days, and it costs nothing.
If that answer does not satisfy you, complain to the Austrian supervisory authority, the Österreichische Datenschutzbehörde, Barichgasse 40 to 42, 1030 Vienna, at dsb.gv.at. You can complain to the authority where you live instead.
How we keep it safe
Every table runs behind Postgres row level security, so a signed in user reaches only rows carrying their own user id. The database enforces that rather than the app, so a bug in the app cannot open someone else's deck.
Traffic runs over HTTPS, and Supabase stores passwords as hashes nobody can read back. The keys for OpenSubtitles, OMDb, Gemini, Azure and Resend sit in server side secrets and never reach the browser.
No system is airtight. If you find a hole, email us and we will treat it as urgent.
Changes and questions
The date at the top is the last change. Anything that alters what we collect, or who processes it, appears in the app before it takes effect.
Write to support@langvie.app for a data request, a deletion, a correction or a security report. The companion document is the terms of use.