Privacy Policy
Last updated: October 2026 (draft)
This policy explains what personal data Linguomate collects, why, and what rights you have under the EU General Data Protection Regulation (GDPR).
1. Controller
The controller is [operator legal name], [registered address]. Contact for all privacy matters: mivan@metawords.xyz.
2. Data we collect
- Account data: email address, password (stored hashed), name and profile settings.
- Content you enter: clients, projects, tasks, deadlines, notes and time entries.
- Billing data: subscription status and Stripe customer identifiers. Card details go directly to Stripe and are never stored by us.
- Notification data: deadline reminders generated for your tasks. Reminder emails contain your email address and the titles of the tasks concerned, which are passed to our email provider.
- Usage data: a short list of in-app events (for example "task created") and the days you were active, kept in our own database for up to 400 days. They contain no client, project or task names, no text and no amounts. The operator can see your account email and these counts, never your content.
- Exit survey: if you answer the optional one-question survey after your trial ends or when you cancel, we store your chosen reason and any comment you write. Please do not include personal or confidential details in the comment.
- Website analytics: on our public pages (not inside the signed-in app) we use Vercel Web Analytics, which works without cookies and does not store anything on your device. It counts page views and a few button clicks, and records the country, device type and the site you came from. When you create an account we also store where you came from (for example "reddit.com") and, if the link you used carried one, the campaign name (the utm_campaign parameter) with your profile, so we can see which channels bring new users.
- Time tracker connection (optional): if you connect Toggl Track or Clockify, we store your API token encrypted (it gives full access to your account in that tracker) and import your time entries, including their descriptions, tags and project names. You can disconnect at any time; the token is then deleted and you can choose to remove the imported entries too.
- Browser extension (optional): if you connect the LinguoMate browser extension, we store a session for it: the browser name, when it was connected and last used, and hashed access tokens (the tokens themselves are never stored). Through it the extension can read your open tasks and deadlines and start or stop your timer. You can disconnect every browser in Settings; changing your password disconnects them as well.
- Adding tasks from a purchase-order page (optional, with the browser extension): when you click it on a page, the extension reads only the fields its recipe points to and sends just those extracted values (for example client, quantities, deadline) to us as a draft. We never receive the page, its HTML or its text. A draft is deleted after one hour or once used, and nothing becomes a task until you review and save it. Extraction recipes are private to your account and hold labels and rules, never values from the pages.
- Technical data: essential cookies used to keep you signed in. Our hosting and database providers (Vercel, Supabase) automatically log requests, including IP addresses, for security and operation; the application itself does not store IP addresses.
3. Why we use it
- To provide the service you signed up for (contract, Art. 6(1)(b) GDPR).
- To process payments and meet accounting obligations (contract and legal obligation).
- To keep the service secure and prevent abuse (legitimate interest).
4. Who processes your data
We use the following processors, bound by data processing agreements:
- Supabase — database, authentication and file/data hosting
- Stripe — subscription billing and payment processing
- Resend — sending transactional emails (confirmation, deadline reminders)
- Vercel — application hosting
- Toggl Track and Clockify — only if you connect your own account: we start and stop timers there and import your time entries (see section 2)
Some of these providers may process data outside the EU/EEA, in which case transfers rely on safeguards such as Standard Contractual Clauses. We do not sell your data.
5. How long we keep it
Account and content data are kept while your account exists and deleted after you ask us to close it. Billing records are kept as long as accounting law requires. You can ask us to delete your data at any time by emailing mivan@metawords.xyz.
6. Your rights
You have the right to access, correct, delete and port your data, to restrict or object to processing, and to withdraw consent. To exercise them, email mivan@metawords.xyz.
You may also lodge a complaint with your national data protection authority.
7. Cookies
We only use essential cookies needed to sign you in. We do not use advertising or tracking cookies.
8. Changes
We will update this page when our processing changes and note the date above.