Glossy — Privacy Policy & Terms of Service
Privacy Policy
1. Introduction
This Privacy Policy explains how Glossy (“we”, “us”, “our”) collects, uses, stores, and shares information when you use the Glossy mobile application (“the App”).
By using the App, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the App.
2. Who we are
Glossy is a flashcard and vocabulary learning app with optional AI-powered features and a paid subscription (“Glossy Pro”).
Data controller: LingoQuestLearn
Contact for privacy requests: tomas.krauk@gmail.com
3. Information we collect
3.1 Information stored on your device (local)
Most of your data stays on your device and is not uploaded to our servers unless you use AI features (see below). This includes:
- Flashcard lists and folders you create
- Study progress, excluded cards, and training settings
- AI Coach conversations and goals
- App preferences (e.g. dark mode, hidden library items)
- A randomly generated anonymous user ID used to identify your device for subscriptions and AI requests
We do not require you to create an account with an email address or password.
3.2 Information sent to our servers (AI features)
When you use AI features (list generator, AI editor, AI Coach), the App sends data to our backend API hosted on Vercel so we can process your request. This may include:
- Your anonymous user ID
- Text you enter (prompts, instructions, vocabulary, coach messages)
- Existing card content (terms and definitions) when editing or generating lists
- Images you optionally attach in the AI generator (processed for text extraction / context)
- Technical data such as IP address and request timestamps (used for rate limiting and abuse prevention)
We do not intentionally collect your name, email, or phone number through the App itself.
3.3 Subscription and payment data
Payments are processed by Apple App Store or Google Play Store. We do not receive or store your full payment card details.
We use RevenueCat to manage subscriptions and verify whether you have an active Glossy Pro entitlement. RevenueCat receives:
- Your anonymous app user ID
- Purchase and subscription status
- Information provided by the app store (e.g. transaction identifiers)
For more information, see RevenueCat’s Privacy Policy.
3.4 AI processing by third-party providers
To power AI features, our servers forward relevant content to third-party AI providers, currently including:
- Google (Gemini API)
- OpenAI
These providers process your submitted content solely to generate responses for your request. Their use of data is governed by their own policies:
We instruct AI providers through our prompts to return structured vocabulary data. Do not submit highly sensitive personal data (e.g. government IDs, health records, financial account numbers) through AI features.
3.5 Caching and rate limiting
We use Upstash Redis to cache subscription status and enforce usage limits. Cached data may include your anonymous user ID and a premium/non-premium flag for a short period (minutes).
4. How we use your information
We use collected information to:
- Provide core App functionality (flashcards, study modes, library)
- Process AI generation and editing requests
- Verify subscription status and deliver Glossy Pro features
- Prevent abuse, fraud, and excessive API usage
- Improve reliability and security of the service
We do not sell your personal data to third parties.
5. Legal bases (EEA/UK users)
If you are in the European Economic Area or United Kingdom, we process data based on:
- Contract — to provide the App and subscription features you request
- Legitimate interests — security, rate limiting, and service improvement
- Consent — where required for optional AI features that send your content to third-party AI providers
You may withdraw consent for AI features by not using them. Local study features do not require sending data to AI providers.
6. Data retention
- On-device data remains until you delete it or uninstall the App.
- Server-side logs and rate-limit data are kept for a limited period necessary for operations and security (typically days to weeks unless required longer by law).
- RevenueCat subscription records are retained according to RevenueCat’s policies and applicable tax/accounting requirements.
7. Data sharing
We share data only with:
- Service providers listed above (hosting, AI, subscriptions, caching)
- App stores (Apple, Google) for purchases
- Authorities when required by law or to protect rights and safety
We do not share your data with advertisers.
8. International transfers
Our service providers may process data in countries outside your own, including the United States. Where required, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms.
9. Your rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Request correction or deletion
- Object to or restrict certain processing
- Data portability
- Withdraw consent (where processing is consent-based)
- Lodge a complaint with your local data protection authority
Because most content is stored locally, you can delete your lists and uninstall the App to remove on-device data. For requests related to server-side data, contact us at tomas.krauk@gmail.com.
10. Children’s privacy
The App is not directed at children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will take steps to delete it.
11. Security
We use reasonable technical measures (HTTPS, API keys, rate limiting, server-side subscription checks). No method of transmission or storage is 100% secure.
12. Changes to this Privacy Policy
We may update this policy from time to time. We will post the new version with an updated “Last updated” date. Continued use of the App after changes means you accept the updated policy.
13. Contact
Questions about privacy: tomas.krauk@gmail.com