Privacy Policy
Last updated: 24.08.2025
1. Who We Are
WordWise AI ("WordWise AI", "we", "our") provides the WordWise AI mobile application and the website at wordwise-ai.com. For the purposes of applicable data protection laws (including GDPR/UK GDPR), WordWise AI is the data controller of personal data processed in connection with the app and website.
If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at privacy@wordwise-ai.com.
2. Scope of this Policy
This Privacy Policy explains how we collect, use, and protect personal data when you use:
- The WordWise AI mobile app (iOS), and
- The wordwise-ai.com website and related pages.
This Policy does not apply to third-party websites or services that may be linked from our properties.
3. Key Definitions (Plain English)
- Personal data: Information that identifies, relates to, or could reasonably be linked with an individual (e.g., email address).
- Processing: Any operation performed on personal data (such as storing, using, or deleting).
- Controller: The entity that determines the purposes and means of processing personal data (here, WordWise AI).
- Anonymized data: Data that cannot reasonably be linked back to an individual.
- Aggregated data: Information combined from multiple users in a way that does not identify any individual.
4. What Data We Collect
4.1 Account Data
- Email address and basic profile settings you provide when you create or manage an account.
- Authentication information necessary to operate your account and keep it secure.
4.2 App Content You Add
- Vocabulary sets, translations, flashcards, generated texts, titles, labels, and any notes you create within the app.
- This content is used to provide core learning functionality you request.
4.3 Usage & Device Data — Not Collected
- We do not collect app feature interaction telemetry.
- We do not collect device identifiers, advertising IDs, or precise location data for the app or website.
4.4 Support Communications
- Information you choose to send us by email (including attachments) when you request support or provide feedback, which we use to respond and maintain a record of the request.
4.5 Payment & Subscription Data
- Purchases and subscriptions are handled by the Apple App Store. We receive non-card details such as subscription status or receipt metadata needed to activate and manage your premium access. We do not collect or store payment card numbers.
4.6 Cookies (Website)
- The website may use essential and functional cookies necessary to operate the site and remember preferences.
- We do not use advertising cookies.
5. How We Use Your Data (Purposes)
We process personal data only to operate and support the app and website, including:
- Creating and managing your account.
- Delivering core learning features you request.
- Providing customer support and communicating about service-related matters.
- Maintaining service reliability, security, and fraud prevention.
- Complying with legal obligations.
Optional analytics used specifically for AI-Powered Learning Insights are described in Section 7 and require your explicit consent.
5.1 Legal Bases (GDPR/UK GDPR)
- Contractual necessity: To provide the app and its core functionality.
- Consent: For the optional AI-Powered Learning Insights feature (Section 7).
- Legal obligation: Where processing is required by applicable law.
6. Sharing & Disclosure
- We do not sell or share your personal data for advertising.
- If we engage in a business transfer (e.g., merger, acquisition), we will ensure appropriate safeguards and notify you where required.
7. AI-Powered Learning Insights (Optional Feature; Consent-Based)
7.1 Overview
AI-Powered Learning Insights is an optional feature that analyzes anonymized learning activity to generate personalized study recommendations and weekly insights. The feature is off by default and is not required to use the app. It is activated only after you give explicit consent.
7.2 Data Collection and Processing
7.2.1 Learning Activity Data
To power this feature (after you consent), the system derives learning activity data from your in-app use, such as:
- Flashcard practice: Session duration, practice frequency, interaction patterns.
- Vocabulary management: Word additions and status changes (e.g., in-progress → mastered).
- AI text generation: Creation frequency, context preferences, word coverage metrics.
- Text-to-speech usage: Pronunciation practice frequency, language preferences.
- Study sessions: Session timing and duration.
- Set management: Set creation and organization patterns.
This data is processed solely for generating insights and is not used for advertising or cross-service tracking.
7.2.2 Data Anonymization Process
Before any external AI processing, we apply a comprehensive anonymization workflow:
- Removal of personal identifiers (e.g., email addresses, user IDs).
- Session-based anonymization using temporary, non-traceable identifiers.
- Categorical transformation of raw events into non-identifying categories (e.g., "moderate engagement," "evening preference").
- Aggregation of individual events into patterns and trends that cannot be traced to a specific person.
7.2.3 Categories of Anonymized Data
Only categorical patterns are used, such as:
- Study frequency patterns (daily, weekly, sporadic).
- Session duration preferences (short, medium, long).
- Learning content preferences (flashcards, AI texts, mixed).
- Performance trends (improving, stable, declining).
- Consistency levels (high, medium, low).
- Activity variety scores (narrow, balanced, diverse).
7.3 Third-Party AI Processing
We use a third-party AI service as our processor to generate learning recommendations. Only anonymized, categorical patterns are sent; no personal data or raw app content is transmitted. The provider processes data under contractual safeguards consistent with applicable data protection laws.
7.4 Consent and Control
7.4.1 Explicit Consent Required
AI-Powered Learning Insights is enabled only after you provide clear, affirmative consent within the app.
7.4.2 Consent Information Provided
Before enabling the feature, the app explains:
- What anonymized learning activity patterns are used.
- How anonymization and aggregation work.
- The purpose of generating insights.
- Retention and deletion processes.
- How to withdraw consent.
7.4.3 Withdrawal of Consent
You can withdraw consent at any time by disabling the feature in the app or by emailing us. Upon withdrawal, we immediately stop processing and delete existing insights as described in Section 7.5.
7.5 Data Retention and Deletion
7.5.1 Retention Periods
- AI-generated insights: Retained for 30 days after generation and then automatically deleted.
- Anonymized learning patterns: Processed temporarily for insight generation and not permanently stored.
- Consent records: Retained as required for compliance until consent is withdrawn.
7.5.2 Immediate Deletion
We promptly delete AI insights data when you:
- Withdraw consent via the app or by email.
- Delete your account.
- Request deletion by contacting us.
7.6 Data Security
7.6.1 Technical Safeguards
- Encryption in transit for all data transmissions.
- Access controls to restrict who can handle anonymized data.
- Security monitoring and periodic assessments of the insights pipeline.
7.6.2 Data Minimization
We limit processing to what is necessary, and we do not transmit personal identifiers or raw app content for this feature.
7.7 Your Rights Under GDPR
You may exercise the following rights with respect to AI-Powered Learning Insights:
- Access to information about processing.
- Rectification of inaccurate personal data related to the feature.
- Erasure (right to be forgotten).
- Data portability (where technically feasible).
- Objection to processing for this optional feature.
See Section 10 for how to submit requests.
7.8 International Data Transfers
Anonymized data used for AI insights may be processed in jurisdictions outside your own. We implement safeguards such as anonymization and appropriate contractual protections to help ensure an adequate level of data protection.
7.9 Changes to AI Insights Privacy Practices
If we materially change the AI insights feature or its privacy practices, we will notify you in-app and by email where appropriate. Continued use after notice constitutes acceptance of the changes where permissible by law.
7.10 Contact Information
For questions or requests about AI-Powered Learning Insights, email privacy@wordwise-ai.com.
7.11 Compliance and Auditing
We maintain internal controls and audit trails documenting:
- Anonymization processes.
- Insight generation activities.
- Data deletion operations.
- Consent grant and withdrawal events.
8. Data Retention (Non-AI-Insights)
- Account data: Retained while your account is active and for a reasonable period thereafter to comply with legal obligations and resolve disputes. Deleted upon verified account deletion request, subject to lawful retention requirements.
- App content you add (e.g., vocabulary sets, translations, flashcards, generated texts): Retained while your account is active and deleted upon account deletion or your request, subject to lawful retention requirements and routine backup cycles.
- Support communications: Retained as long as necessary to respond to your inquiry and maintain appropriate records, then deleted or archived in accordance with legal obligations.
- Usage & device data: Not collected (see Section 4.3).
9. Your Privacy Rights
Depending on where you live, you may have rights over your personal data. We respect and enable these rights as described below.
9.1 EEA/UK (GDPR/UK GDPR)
If you are in the EEA or UK, you have the right to:
- Access your personal data and obtain a copy.
- Rectify inaccurate or incomplete personal data.
- Erase your personal data where applicable ("right to be forgotten").
- Restrict processing in certain circumstances.
- Port your data to another service where technically feasible.
- Object to processing based on legitimate interests, where applicable.
- Withdraw consent at any time for processing that relies on consent (e.g., AI-Powered Learning Insights).
You also have the right to lodge a complaint with your local Supervisory Authority.
9.2 California (CCPA/CPRA) (if applicable)
If you are a California resident, subject to the CCPA/CPRA you may have the right to:
- Know/Access the categories and specific pieces of personal information we have collected about you.
- Delete personal information, subject to statutory exceptions.
- Correct inaccurate personal information.
- Limit the use/disclosure of sensitive personal information (if applicable).
- Opt out of "selling" or "sharing" personal information for cross-context behavioral advertising.
We do not sell or share personal information for advertising.
10. Exercising Your Rights
You can exercise your privacy rights or submit questions by emailing privacy@wordwise-ai.com.
To protect your account and data, we may need to verify your identity before acting on your request (for example, by confirming control of your account email). We aim to respond within 30 days of receiving a verifiable request. If additional time is needed, we will notify you of the reason and extension period. Requests are handled free of charge unless they are excessive or unfounded as defined by law.
11. Children's Privacy
Our services are not directed to children and are intended for individuals who meet the applicable age of digital consent in their jurisdiction (e.g., 13 or 16). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact privacy@wordwise-ai.com so we can take appropriate action, including deletion where required.
12. Security
We use organizational and technical safeguards to help protect personal data:
- Encryption in transit for data exchanged between the app/website and our services.
- Access controls and least-privilege practices for personnel and systems.
- Authentication and session protections to help prevent unauthorized access.
- Data minimization and limited retention in line with Section 8.
- Monitoring, vulnerability management, and regular reviews of security posture.
- Incident response procedures designed to detect, investigate, and notify where required by law.
- Confidentiality obligations for personnel and service providers handling personal data.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe your account or data has been compromised, contact privacy@wordwise-ai.com immediately.
13. International Data Transfers
We may store and process personal data in countries other than your own, including within and outside the EEA/UK and the United States. When we transfer personal data internationally, we implement appropriate safeguards to protect it, such as:
- Use of Standard Contractual Clauses (SCCs) or other legally recognized transfer mechanisms.
- Anonymization and minimization practices to limit identifiable data where possible.
14. Cookies & Similar Technologies (Website)
Our website may use essential and functional cookies to operate the site and remember your preferences. We do not use advertising cookies.
You can control or delete cookies through your browser settings. Disabling certain cookies may affect site functionality. If we introduce additional cookie types in the future (e.g., optional analytics), we will update this Policy and provide appropriate choices.
15. Mobile App Permissions
- Notifications: With your permission, the app may send notifications to remind you about study sessions, progress, and service updates. You can enable or disable notifications at any time in your device settings.
16. Data Storage Location & Hosting
We use reputable hosting and infrastructure providers that may operate in multiple regions. Personal data may be stored and processed in data centers located within or outside your country of residence. We apply access controls, encryption in transit, backups, and other measures to help protect data, as described in Section 12.
17. Changes to this Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email before the new terms take effect. The "Last updated" date at the top of the Policy will reflect the most recent changes.
18. Account Deletion
You can delete your account at any time in the app Settings by selecting Delete account and confirming your choice. Deletion is permanent and cannot be undone.
What is deleted
- Account data (e.g., your email and profile settings).
- App content you added (e.g., vocabulary sets, translations, flashcards, generated texts).
- AI-Powered Learning Insights data (if enabled), as described in Section 7.5.2 (immediate deletion upon account deletion).
What may be retained
- Limited records we are legally required to keep (e.g., proof of your request, compliance or fraud-prevention logs).
- App Store purchase information retained by Apple; we do not store payment card numbers.
19. Fair Use & Abuse Prevention
To protect service reliability and user safety, we enforce a Fair Use policy. You agree not to misuse the app or website. Unfair or abusive use includes, without limitation:
- Automated or scripted access; attempts to circumvent limits or quotas.
- Bulk account creation, account sharing, or reselling access.
- Scraping, reverse engineering, or interfering with normal operation.
- Uploading, generating, or distributing illegal, harmful, or harassing content.
- Activities that degrade performance or threaten security and integrity.
Enforcement actions.
We may take proportionate actions at our discretion, which can include warnings, rate-limiting, feature restrictions, temporary suspension, or account termination. Where feasible, we will notify you by email; in urgent cases (e.g., security threats), actions may occur without prior notice.
Appeals. If you believe a mistake was made, contact us. We will review and, where appropriate, restore access.
Data used for enforcement.
For abuse prevention and security, we may process limited security signals (e.g., authentication events and request volume) necessary to detect and investigate misuse. We do not collect feature-interaction telemetry, device identifiers, or advertising IDs. Enforcement-related data is retained only as needed per Section 8 and is not used for advertising.
Legal basis. We rely on legitimate interests (service security and reliability), contractual necessity (providing the service), and legal obligations where applicable.
20. Contact Us
For questions about this Privacy Policy or to exercise your privacy rights, email privacy@wordwise-ai.com.