Privacy Policy
Last updated: 3 May 2026
1. Who is the data controller
The data controller for personal data processed through Speak·Meet·Travel (the “App”) is Norbert Czarnek, a natural person conducting business activity in Poland under the firm APQART NORBERT CZARNEK (NIP 6772275303, REGON 383714501), with registered place of business at ul. Morelowa 4A/5, 30-222 Kraków, Poland (“we”, “us”, or “our”). You can reach us at contact [at] apqart.com for any privacy-related question.
2. What we collect, and why
2.1 Account data
- Anonymous identifier. When you first launch the App, Firebase Authentication mints a stable anonymous user ID so your local progress can be saved to your device account before you choose to sign in.
- Email address — only if you create an account with email and password.
- Apple user identifier — if you sign in with Apple. Apple may also share a relay email address (e.g.
private-relay@privaterelay.appleid.com) instead of your real email if you choose “Hide My Email”. We accept relay addresses and never attempt to deanonymise them. - Display name — if you provide one.
2.2 Learning data
- Languages you are learning and the level you selected.
- Lesson progress (which lessons you completed, scores, streaks).
- App preferences (e.g. your interface language).
2.3 Subscription data
- An anonymous RevenueCat user identifier and the entitlement status that tells the App whether you have an active premium subscription. We do not receive your payment card details — Apple processes the payment and only shares the outcome with us via RevenueCat.
2.4 Diagnostics & usage
- Crash reports, error logs, and aggregate usage signals (e.g. lesson completion rate). These help us fix bugs and prioritise features.
- Device-level information such as the App version, iOS version, and device model — collected for compatibility and support.
3. Legal bases (GDPR)
- Contract (Art. 6(1)(b) GDPR) — to provide the App, your account, and any subscription you purchase.
- Legitimate interest (Art. 6(1)(f) GDPR) — for security, fraud prevention, and improving the App. We balance this against your privacy rights and you can object at any time.
- Consent (Art. 6(1)(a) GDPR) — for any optional processing such as marketing communications. You can withdraw consent at any time without affecting prior processing.
- Legal obligation (Art. 6(1)(c) GDPR) — to comply with tax, accounting, and consumer-protection law.
4. Third-party processors
We rely on a small number of vetted processors. Each is bound by a Data Processing Agreement and may only process your data on our instructions.
- Google LLC (Firebase) — Authentication, Firestore database, and crash diagnostics. Privacy info.
- Apple Inc. — Sign in with Apple, on-device and server-side speech recognition (when used), and StoreKit purchase processing. Privacy info.
- RevenueCat, Inc. — subscription receipt validation and entitlement management. Privacy info.
- ElevenLabs Inc. — text-to-speech generation for lesson audio. We send the lesson text (not your voice) to ElevenLabs and receive the audio back. Privacy info.
5. Voice and speech recognition
When you use the “Listen & Repeat” lesson, the App can record short audio clips of your voice and pass them to Apple's on-device speech recognition to compare what you said to the expected word. Where on-device recognition is unavailable on your device, Apple may transcribe the audio on its servers under Apple's Speech & Dictation policy.
- We do not upload your voice to our own servers.
- We do not retain your voice once the comparison is finished — recordings are released from memory at the end of each exercise.
- You can deny microphone access at any time in iOS Settings → Speak·Meet·Travel → Microphone, and the App will still work without speech-aware lessons.
6. International data transfers
Some of our processors (Google, Apple, RevenueCat, ElevenLabs) are based in the United States and may transfer your data outside the European Economic Area. These transfers are protected by the European Commission's Standard Contractual Clauses (or equivalent safeguards), and where available we rely on the EU–US Data Privacy Framework.
7. How long we keep your data
- Account data — for as long as you keep an account with us. When you delete your account we delete or irreversibly anonymise this data within 30 days, unless we are legally obliged to retain it.
- Learning data — kept with the account, deleted on account deletion.
- Subscription receipts — kept for as long as required by Polish accounting law (typically 5 years) so we can issue invoices and respond to chargebacks.
- Diagnostics — typically retained for up to 90 days, then aggregated or deleted.
8. Your rights
Under GDPR you have the right to:
- Access the personal data we hold about you and receive a copy (right of access & data portability).
- Correct inaccurate or incomplete data (rectification).
- Delete your data (right to erasure / “right to be forgotten”).
- Restrict or object to processing based on legitimate interests.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with the Polish Personal Data Protection Office (UODO) at uodo.gov.pl, or with your local supervisory authority if you live outside Poland.
To exercise any of these rights, write to contact [at] apqart.com. We will respond within one month.
9. Deleting your account
You can delete your account from inside the App (Settings → Account → Delete account) or by emailing us at contact [at] apqart.com. Deletion permanently removes your profile, learning history, and any device-account binding within 30 days. If you signed in with Apple, deleting your account in the App also revokes our Apple authorisation token; you can additionally manage the authorisation in iOS Settings → your Apple ID → Sign in with Apple.
10. Age requirement (18+)
Speak·Meet·Travel is intended exclusively for adults aged 18 or over. The App includes the “Meet” module, which lets adults connect with other adults around shared travel and language interests, and is not appropriate for children or teenagers. By creating an account or otherwise using the App, you represent that you are at least 18 years old.
We do not knowingly collect personal data from anyone under 18. If we discover that an account belongs to a minor, we will close that account and delete the associated personal data without delay. If you are a parent or guardian and you believe a minor has created an account or provided personal data through the App, please contact us at contact [at] apqart.com and we will delete the data promptly.
Because we operate exclusively for adults, the COPPA and GDPR provisions that protect children under 13 (or under 16 in some EU member states) do not apply to our processing in the ordinary course; the safeguards described elsewhere in this policy apply uniformly to every adult user.
11. Security
We use industry-standard safeguards: TLS encryption in transit, access controls on our cloud database, hashed credentials (Apple and Firebase manage password hashing — we never see your password), and short-lived authentication tokens. No system is perfectly secure, however, and we cannot guarantee absolute security.
12. Changes to this policy
We may update this policy to reflect product or legal changes. The “Last updated” date at the top reflects the most recent revision. If the changes are material we will notify you in the App or by email before they take effect.
13. Contact
For privacy questions, data subject requests, or to flag a concern:
contact [at] apqart.com
Norbert Czarnek
trading as APQART NORBERT CZARNEK
ul. Morelowa 4A/5, 30-222 Kraków, Poland
NIP 6772275303 · REGON 383714501