PawlaPalabra Privacy Policy

Last updated: 1 September 2026

PawlaPalabra is a small language-learning app. This page explains, in plain language, what it stores about you, why, and how to get rid of it.

1. Who is responsible for your data

PawlaPalabra is developed and operated by Roman Neviantsev, an individual developer based in Spain, acting as the data controller under the EU General Data Protection Regulation (GDPR).

Contact: support@pawlapalabra.com

This policy covers the PawlaPalabra mobile app and its backend API at api.pawlapalabra.com.

2. What we collect

Your account. You sign in with Apple or Google. We never see or store your password. Your provider passes us, and we store:

What you create and learn. The vocabulary lists you create or follow, the translations and examples you add, any corrections you make to existing entries, and your learning progress: repetition level and next-review date per item, daily targets, current streak, counters for words learned and repeated today, and when you last practised.

Your device's time zone. The app sends its IANA time zone (for example Europe/Madrid) when it loads your profile. It exists for one reason: to decide where your day ends, so a streak and a daily goal do not reset at someone else's midnight. It is optional — if it is missing, we keep whatever we had.

Ordinary server logs. Our servers automatically record technical request data such as IP address, timestamp and the endpoint called. These keep the service running and secure, and are short-lived.

3. What we do not collect

4. Why we use it, and on what legal basis

WhatWhyGDPR legal basis
Account dataCreate and maintain your account; tell your data apart from other users'Art. 6(1)(b) — performance of a contract with you
Learning content and progressProvide the actual product: your lists, your spaced repetition, your streakArt. 6(1)(b)
Time zoneRoll your daily goal and streak over at your local midnightArt. 6(1)(b)
Server logsKeep the service available, diagnose faults, detect abuseArt. 6(1)(f) — legitimate interest in a working, secure service

We do not use your data to make automated decisions with legal or similarly significant effects, and we do not profile you for advertising.

5. Who else processes your data

The list is short deliberately. Each acts as our processor, under contract, and only on our instructions:

We do not sell your personal data, and we do not share it for advertising or for anyone else's marketing.

6. International transfers

Your data is stored and processed in the European Union. Auth0's parent company is based in the United States, so limited administrative access from outside the EEA is possible; that is covered by the European Commission's Standard Contractual Clauses together with the relevant supplementary safeguards.

7. How long we keep it

For as long as you have an account. Delete your account and we delete your account record, your lists and translations, your progress and your overrides from our live database. Deletion is immediate and cannot be undone — there is no restore. Residual copies may persist briefly in encrypted backups and in short-lived server logs before they expire on their normal cycle.

Deleting your PawlaPalabra account does not delete your Apple or Google account. To remove PawlaPalabra's access on their side, use Apple's Sign in with Apple settings or Google's Third-party apps settings.

8. Your rights

Under the GDPR you may ask us to:

Write to support@pawlapalabra.com. We answer within one month. We may need to confirm that the request comes from the account holder before acting on it.

If you think we have handled your data badly, you can complain to your national data protection authority. In Spain that is the Agencia Española de Protección de Datos (AEPD), www.aepd.es.

9. Age

PawlaPalabra is not directed to children. You must be 16 or older to create an account. We do not knowingly collect personal data from anyone under 16; if we learn that we have, we delete it. (Some EU countries set a lower threshold — Spain's is 14 — but we apply 16 everywhere.)

10. Security

All traffic between the app and our servers runs over HTTPS. The API rejects any request without a valid, unexpired token issued to you. Access to the production database is restricted to the application itself. No system is perfect, but we do not store passwords or payment details at all, which removes the two things most worth stealing.

11. If you are in the United States

We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in the California Consumer Privacy Act and comparable state laws. The rights in section 8 are available to you as well — use the same address.

12. Changes to this policy

If we change what we collect or why, we update this page and move the date at the top. Material changes will also be announced in the app.