Privacy Policy
Last updated: July 18, 2026
1. Introduction
Zackly ("we", "our", or "us") is committed to protecting your privacy. This policy explains what data we collect, why we collect it, and how you can control it.
By using Zackly you agree to the practices described here. If you do not agree, please do not use the app.
2. Data Controller
The data controller is the individual developer operating Zackly.
3. Data We Collect
Account & Identity
- Device ID — generated on first launch, used as your anonymous identifier
- Username — chosen by you during onboarding
- Email address — required and verified at signup (via a one-time code); used for account verification, account recovery, and service emails
- Native language — to localise translations in games
- Learning language(s) — the language(s) you study (German, English or Spanish) and your level per language
- Account role — Free, Plus, or Premium
Learning Activity
- Game sessions — mode, level, score, answers, time taken
- Saved words — words you bookmark during practice
- Learning streak, XP, and achievements
- Daily challenge progress
- Gap map data — accuracy per level and game mode
- Word contribution requests submitted by you
Subscription & Payments
- Subscription tier and billing type (managed by RevenueCat and App Store / Google Play — we never see your card details)
- Token balance for premium AI features
- Coupon / trial redemption history
Technical & Device
- Push notification token (only if you grant permission)
- Offline game packages downloaded to your device (Premium only)
- App version, for force-update enforcement
- Approximate location — only if you open the schools map feature and grant permission; never collected in the background
- Photo library access — only when you choose to save or share an export of your learning data; we never read your photos
Analytics (only with your consent)
- Screen views and product events via PostHog (EU servers). These are pseudonymised: they are linked to your app user ID (not your name or email) so we can understand feature usage. We collect these only if you consent — you choose on first launch and analytics stay off until you do; you can withdraw anytime in Settings → Account → Usage Analytics.
Advertising (Free tier only)
- If you use the Free tier, we show ads through Google AdMob. We request non-personalized ads only — we do not build advertising profiles and do not ask for cross-app tracking permission.
- To serve and frequency-cap ads, Google processes limited device information (such as device identifiers) under its own privacy policy. Paid tiers see no ads and make no ad requests.
Crash & Stability
- Crash reports and basic device diagnostics (device model, OS version, crash stack traces) via Firebase Crashlytics, used solely to find and fix bugs.
Microphone & Speech (speaking practice only)
- When you use speaking practice, the app accesses your microphone only while you hold the speak button.
- Your voice is never sent to Zackly's servers, and we never store your audio.
- AI conversation practice is processed entirely on your device by Apple Intelligence — the conversation audio and content never leave your phone.
- Pronunciation checking uses your device's speech recognition: on-device whenever your device supports it (we require it when available); on older devices, recognition may be performed by Apple's speech service under Apple's privacy policy.
- Game audio (word and passage playback) is text-to-speech — generated on your device or delivered as pre-generated audio files. This involves no data about you.
4. How We Use Your Data
5. Data Sharing
We do not sell your data. We share it only with the processors below, all under Data Processing Agreements:
6. Data Retention
- Active account — data kept while account exists
- Inactive accounts (12 months) — analytics anonymised
- Deleted accounts — all personal data removed within 30 days
- Subscription records — kept 7 years (legal requirement)
- Push tokens — deleted when you revoke notification permission or delete your account
7. Your Rights (GDPR / CCPA)
8. Children's Privacy
Zackly is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
9. Security
- All data encrypted at rest with AWS server-side encryption
- All traffic encrypted in transit (HTTPS / TLS 1.2+)
- Device-based JWT authentication — no passwords stored
- Role-based access control on all API endpoints
- Token versioning — subscription changes immediately invalidate old sessions
10. Changes to This Policy
We may update this policy to reflect new features or legal requirements. We will update the "Last updated" date at the top. Continued use of the app after changes constitutes acceptance.
11. Contact Us
For any privacy questions or data requests:
privacy@zackly.app We respond within 7 days.