Deep In

Privacy Policy

Effective: 4 July 2026 · Last updated: 4 July 2026

This Policy covers the Deep In mobile app (iOS and Android).

1. Who controls your data

The data controller is DEEP IN EDPK, a company registered in Bulgaria. EIK: 208772397. Registered address: bul. Slivnitsa 188B, office 17, Oborishte district, 1202 Sofia, Bulgaria. Privacy contact: [email protected].

2. What data we process

2.1 Account & authentication. Email; account and session identifiers. You can sign in with a one-time code sent to your email, or with Apple or Google — we never store passwords. When you sign in with Apple or Google we receive a stable identifier for your account with them and, if you allow it, your email address. Apple’s “Hide My Email” gives us a relay address (@privaterelay.appleid.com) instead of your real one.

2.1.1 Anonymous start. You can use the app for the first 24 hours without registering. During that time we create a temporary account tied to an anonymised device fingerprint. The fingerprint cannot identify you personally — it exists only to stop one device from creating unlimited free accounts. Legal basis: our legitimate interest in preventing abuse (GDPR Art. 6(1)(f)).

2.2 Profile & settings. Name (optional), avatar, native language, learning language, proficiency, motivation, daily goal, notification and player preferences, activity streaks.

2.3 Learning content. Saved words and translations, history and progress, bookmarks, videos you add by URL, AI-tutor conversations.

2.4 Voice. During a spoken AI conversation your audio is streamed in real time to OpenAI. We store session duration (in seconds, for plan limits) and the text transcript in your chat history; we keep no persistent raw-audio archive on our servers.

2.5 Subscription. Status and tier (deep/master) and a technical purchaser identifier are provided by RevenueCat via the Apple App Store and Google Play. We never receive or store your payment card details.

2.6 Technical data & notifications. Push-notification token (with your consent), cookieless usage analytics, error/crash logs (may include a technical user identifier for diagnostics).

3. Purposes and legal bases (GDPR Art. 6)

PurposeBasis
Account, sign-in, running the app, vocabulary, progress, translations, AI tutor, voice, transcription, subscriptionContract — Art. 6(1)(b)
Security, abuse prevention, rate-limiting, diagnosticsLegitimate interest — Art. 6(1)(f)
Push notifications, cookieless analyticsConsent — Art. 6(1)(a)
Abuse prevention (device fingerprint for the anonymous start)Legitimate interest — Art. 6(1)(f)

Where consent is the basis, you can withdraw it at any time without affecting the lawfulness of prior processing.

4. Who we share data with (processors)

We do not sell your data. We use trusted providers that act on our instructions under data processing agreements (DPAs):

5. International transfers

Some processors are located outside the European Economic Area, including in the United States (Anthropic, OpenAI, Google, RevenueCat, Cloudflare, Resend). For those transfers we rely on the Standard Contractual Clauses (SCCs) approved by the European Commission and/or adequacy decisions and Data Privacy Framework certification where applicable. Sentry processes data in the EU. Convex processing may occur, among other places, in the United States.

6. How long we keep data

7. Your rights (GDPR)

You have the right to access (Art. 15), rectification (16), erasure (17), restriction of processing (18), data portability (20), objection (21), and to withdraw consent.

8. Age and children

Deep In is intended for people aged 16 and over. The app asks your age on first launch; anyone who answers under 16 is not granted access. Sixteen is the default digital-consent age under GDPR Art. 8, so no separate parental consent is required to use the app.

We do not knowingly collect data from anyone under 16. If you believe a child has provided us data, email [email protected] and we will delete it.

Because 16- and 17-year-olds may use the app, we follow the UK Age Appropriate Design Code: the app carries no advertising, does no profiling for advertising purposes, requests no location access, and ships its privacy settings at their most protective defaults.

9. Analytics and cookies

In the app we use cookieless analytics (Umami) and Cloudflare; we do not use advertising trackers, Meta/TikTok pixels, or Google Analytics in the app. Push notifications are enabled only with your consent.

10. Security

Data is transmitted over encrypted connections (HTTPS/TLS). System access is restricted. No method is 100% secure, but we apply technical and organizational measures proportionate to the risk. In the event of a breach that risks your rights, we will notify you and the relevant authority as required by law.

11. Notice for U.S. users (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect, to request its deletion or correction, and not to be discriminated against for exercising these rights. We do not sell or "share" your personal information as those terms are used under the CCPA/CPRA. Requests — [email protected].

12. Changes to this Policy

We may update this Policy. We will notify you of material changes in the app or by email and update the date at the top.

13. Contact

Privacy questions — [email protected].