İçeriğe geç

Privacy Policy

Son güncelleme

Bu sayfa henüz çevrilmedi ve İngilizce gösteriliyor. Geçerli olan İngilizce sürümdür.

Effective date: August 5, 2026

Last updated: August 5, 2026


1. General Provisions

1.1. This Privacy Policy (hereinafter — the "Policy") explains how personal data of users of the Ekle service (hereinafter — the "Service") is collected, processed, stored, and protected.

1.2. The data controller is Furtaev Ilia, Individual Entrepreneur registered in the Republic of Armenia, Taxpayer Identification Number (TIN) 20354437, state registration number 286.1599034 (hereinafter — the "Controller"). Contact: support@ekle.app.

1.3. This Policy is made in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"), the UK GDPR, and applicable data protection law of the Republic of Armenia.

1.4. By using the Service, the User agrees to the processing of their personal data as described in this Policy. Where processing is based on consent, the User may withdraw consent at any time. If the User does not agree with this Policy, the User must stop using the Service.

1.5. The Controller may amend this Policy. The current version is published at https://ekle.app/privacy. The Controller notifies Users of material changes through the Service interface.

1.6. Most of the Service processes no personal data at all. Ekle is a dictionary with morphological analysis, and the entire dictionary, the grammar reference, the morphological engine's output and the pronunciation ship inside the application. Looking up a word, reading its breakdown, browsing grammar and hearing a word spoken require no account and send nothing to the Controller. Only what the User accumulates — saved words and review history — is stored on the server, and only after the User signs in.

2. Legal Bases for Processing (Article 6 GDPR)

2.1. Personal data is processed on the following legal bases:

  • performance of a contract (Art. 6(1)(b) GDPR) — processing necessary to provide the Service under the Terms of Service (account, saved words, spaced repetition, subscriptions);
  • legitimate interests of the Controller (Art. 6(1)(f) GDPR) — ensuring security, preventing fraud and abuse, and operating the Service, where such interests are not overridden by the User's rights and freedoms;
  • compliance with a legal obligation (Art. 6(1)(c) GDPR) — where retention or disclosure is required by applicable law (e.g. transaction records);
  • consent (Art. 6(1)(a) GDPR) — and only for the analytics and crash reporting described in Section 6. Consent is requested on a dedicated screen the first time the application is launched, it is not bundled with acceptance of the Terms, and it may be withdrawn at any time in Settings → Privacy → Analytics with effect for the future. Refusing has no effect whatsoever on the User's ability to use any part of the Service, paid or free.

2.2. No other processing described in this Policy relies on consent, and the Service does not operate advertising or cross-application tracking on any legal basis.

3. Purposes of Processing

3.1. The Controller processes personal data for the following purposes:

  • authentication of the User in the Service;
  • storage of the User's saved words across their devices;
  • operation of the spaced repetition schedule, streak and statistics;
  • management of subscription status and verification of purchases;
  • technical operation of the Service (monitoring, error logging, abuse prevention);
  • scheduling the User's daily study reminders on their own device.

4. Categories of Personal Data Processed

4.1. Data received on sign-in (Sign in with Apple)

The Service supports no other form of registration. There is no password, no email-and-password account, and no other identity provider.

Data categoryCompositionSource
User identifierA stable identifier issued by Apple, specific to this Service (sub)Apple
Email addressemail — may be an Apple private relay (forwarding) addressApple
NameThe name the User chooses to share at the Apple sign-in sheetApple

4.1.1. Apple provides the email address only on the first sign-in, and it may be a private relay address chosen by the User in their Apple settings. The Controller stores it, does not index it, and does not currently send email of any kind; it is retained solely so that a channel exists to reach a paying customer where necessary.

4.1.2. The name is optional, editable by the User, and used only to address them inside the application. Apple presents the name on the sign-in sheet, where the User may edit it or decline to share it, and sends it only at the first authorization. Where it is present the Controller stores it and displays it on the User's own profile screen. It is never used to identify an account, is not indexed, and is not shared with anyone. An account with no name is a normal state and is not treated differently in any way.

4.2. Saved words

Data categoryCompositionPurpose
Saved wordA reference identifying an entry in the dictionary bundled with the application, together with its part of speechThe User's personal collection

4.2.1. The Service stores references, not text. The Turkish words, glosses, examples and grammatical explanations are contained in the dictionary shipped inside the application; the server holds only what is needed to say which of them the User kept.

4.3. Learning activity data

Data categoryCompositionPurpose
Card stateDifficulty, stability, due date, repetition and lapse countsRepetition algorithm
Answer gradesGrade (again/hard/good/easy)Repetition history
Repetition timestampsTime of each review, its duration, and the calendar date in the User's own time zoneRepetition schedule, streak, statistics
Repetition parametersDesired retention, new cards per day, maximum interval, lifetime review countLearning settings

4.4. Time zone

Data categoryCompositionPurpose
Time zoneThe IANA time zone name reported by the device (for example, Europe/Istanbul)Counting the streak and the daily figures in the User's own day rather than the server's

4.4.1. The time zone is not location data. The Service requests no location permission, links no location framework, and receives no coordinates and no approximate position. A time zone name is a device setting.

4.4.2. This paragraph concerns the time zone only. Where the User has consented to analytics (Section 6), Google derives an approximate city-level location from the IP address of those requests — using no location API, and separately from anything described here. Without that consent, no location of any kind is derived from the User's use of the Service.

4.5. Subscription data

4.5.1. The Controller does not receive or store the User's bank card details (card number, expiry date, CVV/CVC code), and no payment is processed by the Controller.

4.5.2. All purchases are made through Apple (App Store In-App Purchase). The Controller receives from Apple's servers only the transaction identifier, the product identifier, the environment, the paid-through date, the price and the currency, which are required to determine whether the subscription is active. Apple's processing of payment data is governed by Apple's own privacy policy.

4.6. Technical data

4.6.1. During use of the Service, technical data is automatically processed on the server: IP address, request path, response status, and request duration. This data is used to ensure the security and operability of the Service and is deleted in accordance with the log rotation policy.

4.6.2. For requests made while signed in, the log line also records the account identifier, so this technical data is associated with the account for as long as the log is retained. Credentials, tokens, receipts and payment documents are masked before anything is written. Log records are not deleted as part of account deletion (see Section 8.2).

4.7. Session and authentication data

To maintain an active session, the Service stores refresh tokens in hashed form together with their session lineage and expiry. Session data is stored for a limited time, is automatically invalidated on expiry, and is deleted in full on sign-out or account deletion.

5. What Never Leaves the Device

5.1. The following are stored only on the User's device and are never transmitted to the Controller:

  • every word the User looks up. Searches are executed against the dictionary bundled in the application, so the Controller holds no search history of any kind. This remains true where the User has consented to analytics: Section 6.4 sets out how the application is built so that no word can reach the analytics software even in principle;
  • the gloss language and the interface language. These select which column of the bundled dictionary is displayed; the server has no field for either;
  • appearance and notification preferences;
  • study reminders. Notifications are composed and scheduled by the device itself. The Controller operates no push service and receives no push token.

6. Analytics, Crash Reporting and Cookies

6.1. The application contains analytics and crash-reporting software, and neither collects anything until the User has agreed. On first launch the application asks, on its own screen, whether the User consents. Until a positive answer is given, automatic collection is disabled at the software level and the crash reporter is not started at all. A refusal is honoured for the lifetime of the installation, and the choice can be changed at any time in Settings → Privacy → Analytics.

6.2. Where consent is given, the following are used:

SoftwareOperatorWhat it receivesPurpose
Google Analytics for FirebaseGoogle LLC (USA)A fixed, closed list of interaction events (for example: an onboarding step was shown, a word was saved, a review session finished, a subscription screen was opened, a purchase failed); an application-instance identifier; the device's vendor identifier; the IP address, from which Google derives an approximate city-level location and then discards itUnderstanding where users encounter difficulty, so the product can be improved
SentryFunctional Software, Inc., European Union data regionCrash reports and unhandled errors: stack traces, the preceding sequence of application events, device model, operating-system version, and an installation identifierDetecting and diagnosing failures

6.3. No advertising identifier (IDFA) is collected, no advertising network is present, and there is no tracking across other companies' applications or websites. The application deliberately links the variant of the analytics software that has no access to the advertising identifier, and this is verified automatically each time the application is built.

6.4. What is never sent to analytics, under any circumstances: any Turkish word, search query, dictionary entry, passage entered into the Reader, or translation the User views. The event list is fixed in the application's source code and its parameters can only be numbers, true/false values, and values from a closed predefined set — a word cannot be represented in them. This is enforced automatically and is not a matter of policy alone. Where the length of a search that returned no result is recorded, it is recorded as a number of characters, from which no word can be recovered.

6.5. The website at https://ekle.app requires no account and sets no cookies of its own.

6.6. The website includes Google Analytics 4 (operated by Google LLC) for aggregate traffic measurement. It collects pseudonymized visit data (referral source, pages, session duration, device type, approximate IP-based location) and is not linked to any Ekle account. This is a separate measurement property from the one used by the application. Google's processing is governed by policies.google.com/privacy. Users may opt out via tools.google.com/dlpage/gaoptout.

7. Recipients and Processors

7.1. To provide its functionality, the Service relies on a deliberately small number of third parties.

Services to which no personal data is disclosed: none of the Service's language functionality calls an external service. Dictionary lookup, morphological analysis, grammar content, pronunciation and phonetic transcription are all performed on the User's device against data shipped inside the application. No word, phrase or text the User enters is sent anywhere.

Recipients to which personal data is disclosed:

RecipientData disclosedPurposeCountry of processing
Apple (Sign in with Apple)Identity token issued by Apple, validated against Apple's public keysAuthenticationUSA
Apple (App Store In-App Purchase)Signed transaction dataVerification of subscription statusUSA
Hosting providerData stored and processed by the Service, as described in this PolicyOperation of the server and databaseEuropean Union
Google (Analytics for Firebase)In-application interaction events, an application-instance identifier, the device vendor identifier and the IP address — only where the User has consented (Section 6)Product usage analysisUSA
Sentry (Functional Software, Inc.)Crash reports and unhandled errors — only where the User has consented (Section 6)Fault diagnosisEuropean Union
Web analytics (Google Analytics)Pseudonymized visit data on the website only (Section 6.6)Traffic source analysisUSA

7.2. The Controller does not sell or share personal data for cross-context behavioral advertising, and does not transfer personal data to third parties for their own marketing purposes.

7.3. The Controller may disclose personal data where required by a lawful request from a competent authority.

8. Storage, Retention and Protection

8.1. Storage location

Personal data is stored on servers located within the European Union.

Where personal data is transferred to processors located outside the European Economic Area (in particular Apple, for authentication and purchase verification, in the United States), such transfers are made under appropriate safeguards within the meaning of Chapter V GDPR — in particular the European Commission's Standard Contractual Clauses.

8.2. Retention periods

Data categoryRetention periodBasis
Account data (identifier, email, time zone)Until account deletion by the UserContract performance
Saved wordsUntil the User removes the word, or deletes the accountContract performance
Cards, review history and repetition settingsUntil account deletion by the UserContract performance
Subscription recordsUntil account deletion by the UserContract performance, legal obligation
Session dataLimited period, automatic deletion on expiryContract performance
Server logsIn accordance with the log rotation policyLegitimate interest (security)

⚠️ Server logs are not deleted as part of account deletion. They are removed by rotation on their own schedule, as described in Section 4.6.

8.3. Protection measures

The Controller applies organizational and technical measures to protect personal data, including: encryption of data in transit, storage of authentication tokens in hashed form only, isolation of user data, detection and revocation of replayed session tokens, masking of credentials and payment documents in logs, and restriction of the number of persons with access to personal data.

9. Deleting Your Account

9.1. The User may delete their account at any time from Profile → Settings → Delete account in the application. Deletion is immediate and permanent, and requires no request to the Controller.

9.2. Deletion removes, in a single operation: the account record including the Apple identifier and any stored email address, every saved word, every card and the entire review history, the repetition settings, the subscription record held by the Controller, and all sign-in sessions.

9.3. Signing in again after deletion creates a new, empty account. The Controller does not restore a deleted account on the basis of a matching Apple identifier, because doing so would defeat the purpose of deletion.

9.4. Deleting the account does not cancel an active subscription. Subscriptions belong to the User's Apple ID and are managed by Apple; they are cancelled in the Apple ID subscription settings. A subscription that is still active can be restored to a new account through "Restore purchases".

9.5. Deleting the application without deleting the account leaves saved words on the server, so reinstalling and signing in restores them.

10. Your Rights (GDPR / UK GDPR)

10.1. Subject to applicable law, the User has the right:

  • of access — to obtain confirmation of, and access to, their personal data and information about the processing;
  • to rectification — to have inaccurate or incomplete personal data corrected;
  • to erasure ("right to be forgotten") — to have their personal data deleted where there is no lawful ground for continued processing;
  • to restriction of processing and to object to processing based on legitimate interests;
  • to data portability — to receive their data in a structured, commonly used, machine-readable format;
  • to lodge a complaint with a data protection supervisory authority in the User's country of residence.

10.2. To exercise these rights, the User may:

  • remove individual saved words through the Service interface;
  • delete the account entirely through Profile → Settings → Delete account, as described in Section 9;
  • contact the Controller at support@ekle.app.

10.3. The Controller responds to requests without undue delay and in any event within one (1) month of receipt. That period may be extended by up to two further months where necessary, taking into account the complexity and number of requests, with notice to the User.

11. Children's Personal Data

11.1. The Service is not intended for children below the age of digital consent applicable in their country (16 in the EEA, unless a lower age, no younger than 13, is set by national law). The Controller does not knowingly collect personal data from such children without appropriate parental consent.

11.2. If the Controller becomes aware that personal data was provided by a child in breach of this Section, the Controller will take measures to delete such data.

12. Personal Data Breach Notification

12.1. In the event of a personal data breach, the Controller will, without undue delay and where feasible within 72 hours of becoming aware of it, notify the competent supervisory authority in accordance with Article 33 GDPR, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals.

12.2. Where the breach is likely to result in a high risk to individuals, the Controller will notify affected Users without undue delay, describing the nature of the breach, the measures taken, and recommendations for Users (Article 34 GDPR).

13. Automated Processing

13.1. The Service uses a spaced repetition algorithm to generate a repetition schedule automatically from the User's own grades. This processing does not produce legal or similarly significant effects and is aimed solely at optimizing the learning process.

13.2. The Controller does not carry out automated decision-making, including profiling, that produces legal or similarly significant effects on the User within the meaning of Article 22 GDPR.

14. Contact Information

Data controller: Furtaev Ilia, Individual Entrepreneur (Republic of Armenia)

TIN: 20354437 · State registration number: 286.1599034

Email: support@ekle.app

15. Governing Law and Final Provisions

15.1. This Policy is an integral part of the Terms of Service of the Ekle service.

15.2. This Policy is governed by the law of the Republic of Armenia, without prejudice to the mandatory data protection rights available to Users under the GDPR, the UK GDPR, and other applicable local law.

15.3. All questions and requests regarding the processing of personal data should be directed to support@ekle.app.

16. California Residents (CCPA / CPRA)

16.1. The Controller does not sell or share personal information as defined by the CCPA/CPRA. California residents have the right to know, delete, and correct their personal information, and the right not to be discriminated against for exercising these rights. To exercise these rights, contact support@ekle.app.