Privacy Policy

Last updated: 21.07.2026

This Privacy Policy explains how Mihail Mihaylov (“Glotsmith”, “we”, “us”, or “our”) collects, uses, shares, and protects personal data when you use the Glotsmith website and application (the “Service”). It also describes the rights you have over your personal data.

Glotsmith is available internationally, except in jurisdictions restricted by applicable law, sanctions, payment-provider requirements, or our own availability rules; it is not offered to persons located or ordinarily resident in the United Kingdom or in the province of Quebec, Canada (see our Terms & Conditions).

Wherever you are, the same protections apply. We are established in the European Union, so the EU General Data Protection Regulation (“GDPR”) governs how we handle your personal data regardless of which country you use the Service from — this Policy is built to meet it, and we do not operate a weaker standard anywhere. We additionally extend the core privacy rights found in US state privacy laws — including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”) — to our users, whether or not those laws currently apply to us.

If anything here is unclear, or you want to exercise a privacy right, contact us at privacy@glotsmith.com.

1. Who we are (data controller)

The controller responsible for your personal data is:

  • Mihail Mihaylov
  • Ul. Sv. Sv. Kiril i Metodiy 33, 6300, Haskovo, Bulgaria
  • Privacy contact: privacy@glotsmith.com

We are established in the European Union (Bulgaria). Because we have an establishment in the EU, we are not required to appoint an Article 27 EU representative. We have not appointed a Data Protection Officer; for any data protection matter, use the privacy contact above.

2. Scope and our role

This Policy applies to personal data we process as a controller through the Service. For most data we determine the purposes and means of processing and therefore act as the controller; the specialist providers listed in Section 7 act as our processors and only handle data on our instructions. Paddle acts as the Merchant of Record and the seller/reseller of our paid plans. For the payment, billing, tax, and fraud-prevention data it collects directly from you when you subscribe, Paddle is not our processor — it is a separate, independent controller that decides how that data is used for its own purposes (taking payment, invoicing, tax compliance, and fraud prevention). Its handling of that data is governed by Paddle’s own privacy notice at paddle.com/legal/privacy, and you can exercise your privacy rights over that data with Paddle directly at preferences.paddle.com.

It does not cover third-party websites or services that you may reach through links from the Service, which have their own privacy practices.

3. Personal data we collect

We collect only the data needed to run the Service. The categories are:

a) Account and profile data

  • Email address (required to create an account and sign in).
  • Display name (optional).
  • Profile picture / avatar (optional; either uploaded by you or obtained from Google if you sign in with Google).
  • If you sign in with Google: your Google account identifier, email address, name, and profile photo URL (we do not receive or store your Google password or OAuth tokens beyond what is needed to complete sign-in).
  • Account status flags and timestamps (e.g., email-verified time, account created/updated times).
  • The country your connection appears to come from. We do not ask you to tell us where you live — we read the country our network provider reports for your connection. We use it in two ways. First, when you create an account or buy a plan, we check it to confirm we are able to offer the Service to you (see Section 5) — some jurisdictions are outside the areas we serve, and payment and sanctions rules also depend on it — and for that check we do not keep it. Second, at the moment you create your account we record that country on your account, and keep it, for one purpose: to decide which email rules apply to you (marketing email needs your prior agreement in the EU/EEA, but not in some other countries — see Section 5). It is an approximate, network-derived country, not a residence you declared.
  • Whether you agreed to receive optional marketing and onboarding emails, together with the date you agreed and the version of the wording you were shown. We also keep a simple history of each time you turned those emails on or off, and where you did it (in your settings, in answer to a one-time prompt in the app, or via an unsubscribe link) — so that we can show what you agreed to and when you changed your mind, rather than only your current setting.
  • If we invited you. We sometimes create an individual signup link for a specific person. If we make one for you, we may record the email address it is issued to before you have an account — so that the link works only for you — and, once you sign up, a record that your account was created through that link. If you never sign up, that address is not an account and is used for nothing else; we delete these records once a link has been used, revoked, or expired and has been inactive for a while, and if you do sign up and later delete your account we erase the address from them (see Sections 9 and 11).

b) Authentication data

  • One-time sign-in codes (we store only a cryptographic hash of each code, never the code itself), with a short expiry.
  • A session identifier stored in a strictly necessary cookie (see Section 12).

c) Content you create or upload

  • Courses, workbooks, notes, and vocabulary you create.
  • Files you upload as study materials — PDFs, audio, video, and images.
  • Content automatically derived from your materials so the features work: extracted text from documents (OCR), transcripts generated from audio, and the vocabulary entries you save.
  • Feedback and support requests you send us — the message you write and any image or video files you attach.

Your materials and content may contain personal data if you choose to include it. Please do not upload other people’s personal data unless you have a lawful basis to do so.

Sensitive information inside your materials

The material people study is real material, so a document you upload may happen to contain sensitive information about you — health details in a medical text, religious content in a scripture you are reading, and so on. Data protection law calls this “special category” data and treats it more strictly than ordinary personal data: it may not be processed at all unless a specific condition in Article 9 GDPR is met.

Where this Article 9 condition applies to you — that is, if you are in the European Economic Area — the basis we rely on is your explicit consent (Article 9(2)(a)). Before the first study material you add to a course, we ask you to confirm that you understand your files are processed to run the features you choose — and sent to the text-recognition, transcription, or translation provider named at that point — and that this includes any sensitive information the files happen to contain. You do not have to agree: you can simply not upload such material, and the rest of the Service works without it. You can withdraw at any time by deleting the material in question or your account, which removes it from our systems as described in Section 11; withdrawal does not undo processing that already happened. Wherever you are, and whether or not this explicit-consent step is shown to you, we tell you at the point of upload which provider will receive the file.

What we do not do with it. We never ask for sensitive information, never scan your files looking for it, never use it to draw conclusions about you, and never use it for advertising or sell it. It is processed only at your direction, only to produce the output you asked for, and only for as long as you keep the material.

Other people's sensitive information is different, and your consent cannot cover it. Do not upload material containing sensitive information about someone else unless you have your own lawful basis under Articles 6 and 9 for doing so.

d) Technical and usage data

  • IP address, browser/user-agent string, and request identifiers.
  • Security and audit records of important actions (for example sign-in, sign-out, and creating, changing, sharing, or deleting your content), including the action, outcome, time, IP address, and user-agent.
  • Operational metering of feature usage (for example the number of words or characters translated or pages processed, the provider used, language codes, and an indicative cost). These records hold counts and metadata only — they never store the text, audio, images, or document content itself.
  • Error diagnostics when something goes wrong (for example the URL path, error type, and a technical stack trace). Our request logs deliberately redact credentials, cookies, and request bodies.
  • Aggregate counts of visits to our public pages — our home, pricing, FAQ, sign-in and legal pages — recorded by our own first-party, cookieless measurement. When someone opens one of our public pages, we count that page view together with a coarse label for where the visit came from (for example a search engine, a social network, or “direct”), and store only a daily total for each page-and-source combination. We set no cookie and store nothing at all on your device, and we do not keep a full referring URL.
  • So that we can tell how many people visited (and not merely how many pages were opened), we also count unique visitors for the day — again without any cookie or device identifier. To do this, we take your IP address and browser/user-agent string, combine them with a secret random value we change every day, and run the result through a one-way (irreversible) hash. Only that hash is stored, with the day and the coarse source label; your IP address and user-agent are used in memory to compute it and are never written down beside it. Because the secret changes daily, the same person hashes to a different, unconnectable value from one day to the next. While that day’s secret still exists we treat the hash as personal data — someone holding the secret could test a guessed IP address and browser string against it — and the secret is then destroyed a few days later (by default, once it is more than two days old), after which that day’s hashes can no longer be traced to anyone. The result: we can see roughly how many people visited on a given day, but we cannot recognise you, follow you from one day to the next, link a visit to your account, or track you across other websites.
  • A short, non-sensitive marketing-attribution label recorded once when you create your account, indicating where the sign-up came from (for example a referral or campaign tag from the link you followed, or “share” if you arrived from a shared workbook). The label is held only in your browser's memory while you move from the page you landed on to the sign-up form — nothing is written to your device — and it is recorded only if you go on to create an account. It is a plain label, contains no other personal data, and is used only to understand which channels bring new users.
  • Records of email delivery problems — if an email we send you bounces permanently, or you mark one as spam, we record your email address on a suppression list so that we never email that address again. This list is kept separately from your account, and it deliberately outlives it (see Sections 9 and 11).
  • Records of copyright or other legal complaints we receive about content in your account, and the action we took, so we can operate our copyright and repeat-infringer policy.

If you choose a paid plan, we process a limited set of subscription and billing data that Paddle, as Merchant of Record and seller of the plan, passes back to us: a Paddle order/customer reference, your subscription tier and status (for example active, trialing, past due, paused, canceled), the billing interval, your billing country, and related metadata. Paddle collects and handles the actual payment details (such as your card number and billing address) directly, as an independent controller (see Section 2) — we do not receive or store full card numbers on our servers.

We do not use the Service to build advertising profiles.

Do you have to provide this data? An email address is required to create an account and sign in — without it you cannot use the signed-in Service. If you choose a paid plan, payment details (collected by Paddle as Merchant of Record and independent controller) are required to subscribe. Your display name, avatar, and the materials and content you upload are optional and entirely under your control; you choose what, if anything, to add.

4. Where the data comes from

  • Directly from you — when you register, sign in, edit your profile, upload materials, or use features.
  • From Google — if you choose Google sign-in, we receive your basic Google profile (identifier, email, name, photo) under the “profile” and “email” scopes.
  • Automatically — technical, security, and usage data generated as you interact with the Service, including a marketing-attribution label taken from the link you used to reach the sign-up page (for example a referral or campaign tag, or a “share” tag when you arrive from a shared workbook).

5. How and why we use your data (legal bases)

Under the GDPR we rely on the following legal bases:

PurposeLegal basis (GDPR Art. 6)
Create and maintain your account; authenticate you; provide the workbench and the features you invoke (translation, text-to-speech, transcription, text recognition); store your courses, materials, and derived content.Performance of a contract (Art. 6(1)(b)).
Keep the Service secure, prevent and investigate abuse and fraud, maintain audit and error records, and meter feature usage so we can run the Service reliably.Our legitimate interests in operating a secure, reliable service (Art. 6(1)(f)), balanced against your rights.
Count visits to our public marketing pages using our own first-party, cookieless measurement — storing aggregate daily totals per page and per coarse traffic source, plus a daily-changing, irreversible hash used only to count how many distinct people visited that day — so we can understand which pages and channels bring visitors and improve the site. We set no cookies and store nothing on your device.Our legitimate interests in measuring and improving how our public pages perform (Art. 6(1)(f)), balanced against your rights. The impact on you is minimal: nothing is stored on your device, the results are aggregate, and the hash cannot be linked to your account or used to recognise you across days or across other websites. We treat the hash as personal data for as long as that day's secret still exists, and it is deliberately made unusable within days by destroying that secret. You may object as described in Section 10.
Understand which channels new sign-ups come from — using a single short attribution label recorded once when your account is created (for example a referral or campaign tag, or a “share” label when you arrive from a shared workbook) — so we can measure and improve how we reach new users.Our legitimate interests in understanding how people find and join the Service (Art. 6(1)(f)), balanced against your rights; you may object as described in Section 10.
Provision and support your paid subscription and keep our own accounting and tax records. Paddle, as Merchant of Record, takes payment, issues your invoice or receipt, and calculates and remits sales tax/VAT/GST; we process the limited billing data Paddle passes back to activate and support your plan.Performance of a contract (Art. 6(1)(b)) for providing your subscription; our legitimate interests in fulfilling and supporting orders (Art. 6(1)(f)); and compliance with a legal obligation (Art. 6(1)(c)) for our accounting and tax records.
Send you optional marketing and onboarding emails — a welcome and getting-started guide, an occasional tip if you have not set things up, and a note if your account goes quiet. Whichever country you are in, you can stop them at any time from your account settings or the unsubscribe link in every message.Which legal basis applies depends on your country, and we choose it from the approximate country recorded at sign-up (see Section 3). If you signed up in the EU/EEA, we rely on your consent (Art. 6(1)(a)) and send nothing until you give it — by answering the one-time prompt in the app or switching the emails on in your settings; we keep a record of the date and the wording you were shown, and you can withdraw at any time without affecting anything sent beforehand. If you signed up elsewhere (for example the United States), we rely on our legitimate interests (Art. 6(1)(f)) to send these to our own customers about our own product on an opt-out basis, and you may opt out at any time as above. Either way, they are only ever sent to people who have an account with us, never to a purchased list.
Send you the messages that are part of running your account — sign-in codes, billing and receipt information, notice that a free trial is about to end and what your account will change to, security notices, and legal or account notices we are required to give.Performance of a contract (Art. 6(1)(b)) and compliance with a legal obligation (Art. 6(1)(c)). These are not marketing and are not covered by the opt-in above: they tell you about your own account, so they continue whatever your marketing preference.
Process sensitive (special-category) information that happens to be contained in a document, image, or recording you upload — solely to produce the output you asked for, such as recognised text, a transcript, or a translation.Your explicit consent (Art. 9(2)(a)), given by the upload acknowledgment described in Section 3, alongside performance of a contract (Art. 6(1)(b)) for the underlying feature. You can withdraw it by deleting the material or your account.
Check that we are able to offer the Service to you — using the country your connection appears to come from — so that we do not open accounts or take payment in jurisdictions we do not serve or that are subject to sanctions or payment-provider restrictions.Compliance with a legal obligation (Art. 6(1)(c)) for sanctions and trade restrictions, and our legitimate interests in offering the Service only where we are able to do so lawfully (Art. 6(1)(f)). The country used for this availability check is evaluated at the moment you sign up or pay and is not stored for that purpose. (A separate, approximate country is recorded once at sign-up to decide your email rules — see Section 3 and the marketing-email row above.)

Where we rely on legitimate interests, we have considered the impact on you and limited the data to what is necessary; you may object as described in Section 10.

6. Automated decision-making

We do not carry out automated decision-making that produces legal or similarly significant effects about you. Translation, text-to-speech, transcription, and text recognition are content-processing tools that help you study; they do not make decisions about you.

7. Service providers and third parties

To provide certain features we share the minimum necessary content with specialist providers acting on our behalf. The “Status” column tells you which providers actually receive your data today: a provider marked “Not in use” is an alternative we could switch to, and receives nothing unless and until we do. If that changes, this table changes with it.

ProviderStatusData sharedPurposeLocation
Google LLC (Google Cloud)In useSelected text; audio you transcribe; images/pages for text recognitionTranslation, text-to-speech, speech-to-text, text recognition (OCR)United States
Amazon Web Services, Inc. (EC2/RDS)In useAll account, profile, content, and usage data (the hosted application and database)Cloud hosting and database for the ServiceUnited States (Northern Virginia, us-east-1)
Amazon Web Services, Inc. (S3)In useFiles you upload (materials, avatars)File storageUnited States (Northern Virginia, us-east-1)
Amazon Web Services, Inc. (Amazon SES)In useYour email address, your name, and the content of the emails we send youDelivering sign-in codes and account & optional marketing emails, and processing delivery events such as bounces and complaintsUnited States (Northern Virginia, us-east-1)
Cloudflare, Inc.In useConnection data such as IP address and request metadata passing through the networkContent delivery, DDoS protection, and reverse-proxy securityUnited States / global edge network
Zoho Corporation B.V.In useThe email address, message, and any attachments you send to our support, contact, or privacy addressesHosting our support, privacy, and contact mailboxesEuropean Union (Zoho EU data centre)
DeepL SENot in use — alternative providerThe text you select to translateTranslationEuropean Union (Germany)
Microsoft Corporation (Azure)Not in use — alternative providerDocuments/pages for text recognition; text for speechText recognition (OCR), text-to-speechEuropean Union (Netherlands)

Paddle is not listed in the table above because it is not our processor. When you buy a paid plan, Paddle (Paddle.com Market Ltd in the United Kingdom, or the Paddle entity for your country) acts as the Merchant of Record and the seller of the plan, and is an independent controller for the payment and billing data it collects directly from you at checkout — for taking payment, issuing your invoice or receipt, calculating and remitting sales tax/VAT/GST, and preventing fraud. Paddle passes back to us only a limited set of information (such as your name, email, billing country, purchase history, and a Paddle order/customer reference) so we can activate and support your subscription. For how Paddle handles the payment data it controls, and to exercise your rights against Paddle, see Paddle’s privacy notice at paddle.com/legal/privacy and its preference centre at preferences.paddle.com.

Separately from the providers above, we relay operational error alerts to a messaging channel that only we can read, so that we learn quickly when something in the Service breaks. Those alerts carry technical fault information only — the type of error, the route it happened on, a technical stack trace, and an internal reference — and are deliberately constructed to contain no identifier for you (no account reference, no email address, no IP address) and none of your content. Access tokens are removed from the route before an alert is sent.

Where several providers can perform the same feature, only the one marked “In use” above receives your content. Today that means translation, text-to-speech, transcription, and text recognition are all provided by Google Cloud, with speech-to-text processed in Google's us-central1 region; DeepL and Microsoft Azure are configured only as alternatives and receive nothing.

Our measurement of visits to our public marketing pages (described in Sections 3 and 5) is first-party and self-hosted: the aggregate page-view counts are recorded and stored on our own servers, and are not shared with any third-party analytics provider. No external analytics company receives this data.

Some text recognition can also be performed locally on our own servers (using an on-server engine) without sending your files to a third party; which path is used depends on configuration.

Text in digital PDFs (PDFs that already contain a text layer) is read directly in your browser and is not sent to any text-recognition provider. Only scanned pages and images, which have no readable text layer, are processed by a text-recognition (OCR) provider.

We may also disclose personal data to professional advisers, or to authorities, where required by law, to comply with legal process, or to protect our rights, users, or the public. If our business is involved in a merger, acquisition, or asset sale, personal data may be transferred subject to this Policy.

We do not sell your personal data, and we do not share it for cross-context behavioral advertising.

Link previews. If you share a workbook link and then post it on another service (for example a chat app or social network), that service may automatically fetch a small preview from us to show a title and description for the link. This means the workbook’s title is sent to whichever service you post the link on. We only send a short preview — the workbook’s title, a one-line description, and our logo image — never the workbook’s contents or your files. This happens because you posted the link there; those services are not acting on our behalf.

Embedded YouTube videos. A workbook can contain a YouTube video that someone added by pasting a link. We never load such a video unless you have told us we may. Until you do, opening the page — whether in the editor or through a read-only share link — sends nothing to YouTube: in place of the video you see a placeholder telling you where it is hosted and what loading it will send, with a button to load it. Until then, nothing at all is requested from Google. If you do press that button, we take it as your agreement and remember it in that browser, so from then on videos load there without asking again — and you can withdraw the agreement at any time (see below, and Section 12). The record is kept by the browser you are using, not attached to your account, so it does not follow you to another device or browser; equally, on a shared computer it is the browser’s answer rather than any one person’s.

If you do choose to load the video, your browser then fetches it directly from YouTube (Google), in YouTube’s privacy-enhanced (“no-cookie”) mode, from youtube-nocookie.com, along with YouTube’s player script from www.youtube.com (the player script is what makes timestamped annotations possible — reading the current playback position and jumping back to a saved moment). From that point YouTube (Google) receives your IP address, the browser and device information your browser sends, and the fact that the video and player were requested, and it may read or set its own cookies or similar storage on Google’s own domains — for example once playback starts. So that you are not asked again for every video, your browser remembers your choice on this device — for the rest of the page, and for your next visit. You can withdraw it whenever you like, and withdrawing is deliberately as easy as agreeing was: there is a control in Section 12 of this policy, open to anyone (you do not need an account), and it takes effect immediately — videos are once again not loaded until you ask. Clearing your browser’s site data erases the record too. We never send YouTube any account data: not your name, your email address, your workbook’s contents, or your files. In this role YouTube is not acting on our behalf and is not our processor — Google is an independent controller for the data its embedded player collects, and that data is governed by Google’s own privacy policy (policies.google.com/privacy). This is a different role from the Google Cloud row in the table above, where Google processes the content you send for translation, speech, or text recognition on our instructions. If you do not want any data to go to YouTube, simply do not load the video.

8. International data transfers

Several providers in Section 7 are located in the United States — Google LLC, Amazon Web Services, Inc. (which hosts the application, the database, our file storage, and our email delivery via Amazon SES in United States (Northern Virginia, us-east-1)), and Cloudflare, Inc. Where a provider is certified under the EU–US Data Privacy Framework, which the European Commission has recognized as providing an adequate level of protection, the transfer relies on that adequacy decision. For any transfer not covered by an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses together with any additional safeguards needed. Paddle.com Market Ltd, the Merchant of Record for our paid plans, is established in the United Kingdom, and the transfer of billing data to it relies on the European Commission’s adequacy decision for the United Kingdom under Article 45 GDPR. (That is a fact about where our payment provider is based; the Service itself is not offered to persons in the United Kingdom.) Because Paddle acts as an independent controller, any onward transfers Paddle itself makes — for example to affiliates or payment providers — are governed by Paddle’s own safeguards and are Paddle’s responsibility; see Paddle’s privacy notice at paddle.com/legal/privacy. Our measurement of visits to our public pages is first-party and self-hosted on our own servers, so it involves no third-party analytics provider and no related transfer. You can request a copy of the relevant safeguard by emailing privacy@glotsmith.com.

9. How long we keep your data

We keep personal data only as long as needed for the purposes above:

DataRetention
Account, profile, courses, materials, and derived contentUntil you delete the item or your account (see Section 11).
Feedback and support requests (message and attachments)Kept for as long as we need them to handle your request and to evidence what was asked and what we did; they are not deleted on a fixed schedule, and we review them periodically. If you delete your account, your account reference and the email address attached to the request are removed from it straight away (see Section 11), so what remains is no longer linked to you.
The approximate country recorded at sign-up, and your marketing-email consent record and historyFor as long as your account exists, and deleted with it. Both exist only to run your email preferences correctly, so once your account is gone they have nothing left to do — unlike the two records in Section 11, neither survives the deletion of your account.
Session cookieUp to 7 days, refreshed while you stay active.
Sign-in codesA few minutes, then deleted or expired.
Individual signup links we create to invite someone (see Section 3), including any email address a link is issued to and the record that an account was created through itA link that still works is kept for as long as it still works — it is a setting we are running, not a log entry. Once a link has been used up, revoked, or has expired, it and its redemption record are deleted after 90 days of no further activity. If you signed up through one, the code itself also stays on your account as the label for how the account was created, and is deleted with your account (see Section 11).
Security, audit, usage, and error records90 days, after which they are deleted automatically. This covers the usage records described above; the running counters that track your allowance for the current billing period are kept for as long as your account exists, and are deleted with it.
The daily secret used to compute the unique-visitor hash (see Section 3)Deleted a few days after the day it was used for (by default, once it is more than two days old). A new secret is generated each day, so hashes from different days are already unconnectable; deleting the secret additionally makes that day's hashes impossible to work backwards to anyone.
Unique-visitor hashes and aggregate page-view counts for our public pagesThe page-view counts are aggregate totals and are kept indefinitely. The visitor hashes are kept for up to about 400 days and then deleted; within a few days of being created they are already unusable as identifiers, because the daily secret above has been destroyed.
Subscription and auto-renewal consent records (paid plans) — the record that you agreed to a plan and its automatic renewal, including the date, plan, price, country, and the terms shown to youKept for at least three years, or one year after your subscription ends, whichever is longer, to meet automatic-renewal law requirements. This record is not covered by the 90-day security-log window above. It is included in the data you can download from your account settings.
Records of copyright and other legal complaints about content in your accountKept for as long as needed to operate our repeat-infringer policy and to establish or defend legal claims, then deleted.
Your email address on our email suppression list (if a message to you bounced permanently, or you marked one as spam)Kept indefinitely, and deliberately retained after you delete your account. Its only purpose is to stop us ever emailing that address again — deleting it would cause the very harm it prevents. It is held separately, with no link to your account.
Billing and accounting records (paid plans)As required by applicable tax and accounting law (typically up to around 10 years for invoices and accounting records).

Deletion from our active systems happens immediately when you delete an item or your account, and in any event within 30 days. Two things take a little longer, and it would be misleading not to say so. First, backups: we keep encrypted backups of the database so we can recover from a failure. A copy of deleted data can persist in a backup for up to 30 days, and no longer. Backups are not used for any other purpose and are never searched to retrieve an individual record; if we ever had to restore from one, we would re-apply any deletions made in the meantime. Second, files in our storage provider: deletion is requested immediately, and in the rare case a request does not take effect the file is left unreferenced and is removed by our storage provider's own lifecycle rules.

10. Your rights (EU/EEA)

Because we are established in the EU, the GDPR governs our processing wherever you use the Service from — so the rights below are ones we honour for everyone, not only for users in the EU/EEA. You have the right to:

  • Access — obtain a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data (“right to be forgotten”).
  • Restriction — ask us to limit processing in certain cases.
  • Portability — receive certain data in a structured, commonly used, machine-readable format.
  • Objection — object to processing based on our legitimate interests.
  • Withdraw consent — where we rely on consent, withdraw it at any time (without affecting prior processing).

You can edit your profile, download a copy of all your data (as a ZIP archive containing a machine-readable data.json plus your uploaded files), and permanently delete your account at any time from within the Service’s profile settings. To exercise any other right, email privacy@glotsmith.com; we respond within the time limits set by law (generally one month under the GDPR). You also have the right to lodge a complaint with a supervisory authority — either the authority for Bulgaria, which is the Commission for Personal Data Protection (CPDP) (2 Prof. Tsvetan Lazarov Blvd, Sofia 1592; kzld@cpdp.bg; +359 2 915 3518; www.cpdp.bg), or the one for the EU/EEA country where you live or work.

11. Deleting your account

When you delete your account, we delete your courses, workbooks, vocabulary, materials, and the files you uploaded (on a best-effort basis from file storage), and we remove your profile. Security, audit, usage, and error records are de-identified — the reference to your account is removed, so they can no longer be linked to you — and are then deleted on the schedule in Section 9. Any feedback or support request you sent is kept without your account reference (your email address is removed from it), for as long as we need it to handle and evidence that request. The record of a paid-plan purchase described in Section 9 is treated the same way: the reference to your account is removed, and what is left records that a purchase was made and on what terms, with nothing in it that points to you. If we created an individual signup link for you (Section 3), your email address is erased from that link and from the record of its use, and the link stops working; what remains records only that a link was used, with nothing in it that points to you.

Two records deliberately survive the deletion of your account, because erasing them would defeat the very purpose they exist for. Data protection law expressly allows us to keep personal data where it is needed to comply with a legal obligation, or to establish, exercise or defend legal claims.

  • Copyright complaints made about content in your account, including the email address that account used. We are required to operate a policy of terminating repeat infringers, and we could not recognise a repeat infringer if deleting an account also erased its record — anyone could simply delete and re-register to wipe the slate clean. These records are described in Sections 3 and 9.
  • Your email address on our email suppression list, if a message to you ever bounced permanently or you marked one as spam. It exists solely so that we never email that address again, so deleting it would cause precisely the harm it prevents. It is held on its own, carries no link to your (now-deleted) account, and is used for nothing else.

12. Cookies and similar technologies

There is no cookie banner on this site, and that is a deliberate design choice rather than an omission. Consent is required for storing or reading information on your device when it is not strictly necessary to provide the service you asked for. We have arranged the Service so that nothing of that kind happens: we use no advertising cookies, no cross-site tracking cookies, and no third-party analytics provider; our visitor measurement stores nothing on your device at all; the things we do keep in your browser are either essential or a memory of a setting you chose; and the one optional third-party embed that could store anything on your device — a YouTube video — is not loaded at all until you ask for it. Everything that remains is strictly necessary to provide something you asked for. Since there is nothing non-essential to consent to, there is nothing to ask you to accept.

The only cookie we set ourselves is a session cookie (named “__Host-glotsmith.sid”, or “glotsmith.sid” on a non-HTTPS deployment) that keeps you signed in. It is essential to provide the Service. You can delete cookies in your browser settings, but if you remove this one you will be signed out and unable to use the signed-in parts of the Service.

Two service providers we rely on may also set strictly necessary cookies or similar storage. Our payment provider, Paddle, does so on the billing and checkout pages when you go there to start or manage a paid subscription: its checkout runs in Paddle’s own secure frame, and that frame needs its own storage to process and secure the payment and to detect fraud. This is storage that is necessary for a transaction you explicitly asked to make, and it appears only when you visit those pages — if you never open the billing page, it never runs. Separately, our CDN and security provider, Cloudflare, may set a strictly necessary cookie on our domain to tell automated attack traffic apart from real visitors and keep the site available. It contains no name, email address, or other detail about you — though, like any identifier, it can still count as personal data — and it is not used for analytics, advertising, or profiling. Neither of these is used to profile you or to track you across other websites.

Other information kept in your browser

Beyond that cookie, the Service stores a small number of values in your browser’s local storage and session storage — “similar technologies” in the sense of this section. All of them are first-party, none of them are used to track you or shared with anyone, and each one exists either to make the Service work or to remember a choice you made. They are:

What we keep in your browserWhyHow long
Your light/dark appearance choiceSo the site renders in the theme you picked, without a flash of the wrong one while the page loads.Until you clear your browser data. (If you are signed in, this is also saved to your account.)
Which announcement banner you have dismissedSo a notice you have already closed does not keep reappearing.Until you clear your browser data.
Which usage warnings you have seen or dismissed (signed-in users)So the “you are close to your plan limit” notice is not shown to you over and over.Until you clear your browser data.
Your choice to load embedded YouTube videosSo that, having agreed once, you are not asked again — for the other videos on the page, or on your next visit. This is the record of your choice, and keeping it is what lets us avoid loading anything from Google until you ask. It is a single yes/no flag: it does not identify you, and it is never sent to us or to anyone else.Until you withdraw it (you can do so below, at any time) or clear your browser data.
A discount code from a link you followed, and which workbook to open after copying a shared oneSo a code survives the sign-in step, and so the copy you just made is the one that opens.For the current browsing session only; forgotten when you close the browser.

Finally, one third party’s technology is optional rather than necessary — and so we do not let it run unless you say so. If a workbook contains an embedded YouTube video, the video is not loaded when the page opens: you see a placeholder and must press a button to load it. (The exception is a device on which you have already agreed to load videos — there, having answered once, you are not asked again, as explained in the next paragraph.) When the video does load, your browser fetches it and the player from Google, which may read or set its own cookies or similar storage on Google’s domains (see Section 7). That is Google’s technology, not ours, it is not needed to provide the Service, and nothing reaches it unless you have chosen to load videos. That is precisely why it is behind a click and not behind a banner.

Because your answer is remembered, you can change it. Withdrawing is as easy as agreeing was: use the control immediately below, on this page — it is available to anyone, including a visitor who only ever opened a shared workbook and has no account. Withdrawal takes effect at once and applies to every video: from that moment nothing is loaded from Google again until you ask for it. You may also simply clear your browser’s site data, which erases the record along with everything else listed above.

Embedded YouTube videos

13. Your California privacy rights (CCPA/CPRA)

This section provides additional disclosures for California residents under the CCPA/CPRA, to the extent it applies to us and otherwise as a matter of good practice. It describes the categories of personal information we collect and the purposes for which we use them, and serves as our notice at collection.

Categories of personal information we collect

  • Identifiers (e.g., name, email, account/Google identifier, IP address, and — on our public pages only — a daily-changing visitor hash used solely to count how many distinct people visited that day, which cannot be linked to an account or used across days, and which we treat as personal information for as long as that day's secret exists; see Section 3).
  • Customer records (e.g., billing details for paid plans).
  • Internet or network activity (e.g., usage, audit, and error records).
  • Audio, electronic, visual, or similar information (the materials you upload and content derived from them).
  • Commercial information (e.g., the plan or features you use).

We collect this information from the sources in Section 4, for the business purposes in Section 5, and we disclose it to the categories of recipients in Section 7. We retain it as described in Section 9.

Sale and sharing

We do not sell personal information and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We have not done so in the preceding 12 months. Your uploaded materials may contain sensitive personal information (see Section 3), but we use it only to perform the feature you asked for — never to infer characteristics about you, and never for advertising — which is not a purpose that gives rise to the right to limit its use under the CCPA/CPRA. Because we do not sell or share personal information, we also do not sell or share the personal information of consumers we know to be under 16 years of age.

Your California rights

  • Right to know/access the personal information we collect, use, and disclose.
  • Right to delete personal information we have collected.
  • Right to correct inaccurate personal information.
  • Right to opt out of “sale” or “sharing” (not applicable, as we do not do either).
  • Right to limit the use of sensitive personal information (not applicable, as described above).
  • Right not to receive discriminatory treatment for exercising your rights.

To exercise these rights, use the in-app account controls or email privacy@glotsmith.com. We will verify your request using the account information we hold (for example, control of your registered email). You may use an authorized agent, who must provide proof of authorization. We do not offer financial incentives for personal information.

“Shine the Light”

California Civil Code § 1798.83 lets California residents request information about disclosures to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their own direct marketing.

14. Other US state privacy rights

Residents of other US states with comprehensive privacy laws (for example Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others as they take effect) have rights similar to those above — to access, correct, delete, and obtain a copy of their personal data, and to opt out of targeted advertising, sale, and certain profiling. We do not sell personal data, conduct targeted advertising, or carry out profiling with legal or similarly significant effects. As with our California disclosures, we honor these rights to the extent the relevant state law applies to us, and otherwise as a matter of good practice. To make a request, use the in-app account controls (edit, export, delete) or email privacy@glotsmith.com; where a law sets a deadline, we respond within 45 days of a verifiable request (extendable once where the law allows, and we will tell you if we do). If we decline your request, we will explain why. You may appeal by replying to our decision or emailing privacy@glotsmith.com with the word “Appeal”; we will respond to your appeal in writing within the time your state’s law requires. If we deny your appeal, you may submit a complaint to your state Attorney General where your state law provides for it.

14A. Your Canadian privacy rights (PIPEDA)

If you are in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) applies to our handling of your personal information, and the protections described throughout this Policy apply to you.

Consent. We collect, use, and disclose your personal information with your knowledge and consent, except where the law permits otherwise. Creating an account and using a feature is your consent to the processing needed to provide it; optional marketing emails and the processing of sensitive information inside your uploads are handled by express opt-in, as described in Sections 3 and 5. You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice — bear in mind that withdrawing consent to processing that is necessary to run the Service means we can no longer provide it to you.

Your rights. You may ask for access to the personal information we hold about you, ask us to correct it if it is inaccurate or incomplete, and ask about how it has been used and to whom it has been disclosed. Use the in-app controls (edit, export, delete) or email privacy@glotsmith.com; we respond within 30 days, and will tell you if we need an extension the law allows.

Cross-border processing. Your personal information is processed and stored outside Canada — principally in the United States and the European Union, by the providers listed in Section 7. While it is in another country, it is subject to that country’s laws and may be accessible to its courts and law-enforcement or national-security authorities. We use contractual and technical measures to protect it, as described in Sections 8 and 15.

Complaints. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca. Note that the Service is not offered to residents of Quebec (see our Terms & Conditions).

15. How we protect your data

We use technical and organizational measures appropriate to the risk, including encryption in transit (HTTPS), hashing of sign-in codes, access controls that scope your data to your account, and logging that redacts credentials and request contents. No method of transmission or storage is completely secure, but we work to protect your data and to address incidents promptly.

Our authorized administrators may access your account to provide support, to investigate abuse, fraud, or non-payment, and to operate the Service — including the ability to view the Service as your account (impersonation) and to suspend an account. Such access is limited to these purposes, relies on our legitimate interests in supporting users, operating the Service, and preventing abuse, fraud, and non-payment (Art. 6(1)(f)), and is recorded in our audit logs.

16. Children

The Service is a general-audience language-learning tool and is not directed to children. You must be at least 18 years old to use it — both to create an account and to buy a paid plan — because using the Service means entering into a contract with us, and buying a plan means entering into one with our payment provider. We do not knowingly collect personal information from anyone under 18, and we do not target the Service to them. If we learn that we have collected personal information from a minor, we will delete it and close the account. If you are a parent or guardian and believe your child has given us personal information, contact privacy@glotsmith.com and we will delete it promptly.

17. Changes to this Policy

We may update this Policy from time to time. This Policy is a notice explaining what we do with your personal data — it is not a contract, and continuing to use the Service is not how you agree to it. When we make material changes we will update the “Last updated” date and tell you, normally by email to the address on your account or by a notice within the Service, before or when the change takes effect.

Where a change means we would start doing something that legally requires your consent, we will ask you for that consent first, and we will not start until you give it. If you disagree with a change, you can object to processing we base on our legitimate interests, withdraw any consent you have given, or delete your account at any time (see Sections 10 and 11).

18. Contact us

For any question about this Policy or your personal data, contact Mihail Mihaylov at privacy@glotsmith.com or Ul. Sv. Sv. Kiril i Metodiy 33, 6300, Haskovo, Bulgaria. You can also reach us at contact@glotsmith.com for general questions and content reports; this is our single point of contact under the EU Digital Services Act.