privacy policy
effective 3 july 2026
hello. i'm the person who makes HelloHuman (shown in the app as “Hello”), an iOS app for learning languages. this policy explains, plainly, what personal data the app handles, why, who it goes to, and the choices and rights you have.
i've tried to keep this short and honest. if anything here is unclear, email me at stanislavaki@gmail.com and i'll explain.
personal data means any information that relates to you as an identifiable person — like your email address, your user id, or the words and notes tied to your account. below i list exactly what i handle, and i collect it directly from you and from your device as you use the app (plus the email that Apple or Google passes me when you sign in). i don't buy personal data about you from anyone.
using the app means providing some of this data: without account data the app can't sign you in or save your work, and specific features (camera, notifications) need your consent to function. if you'd rather not, you can simply not use those features.
who i am
HelloHuman is made and run by one individual — a sole trader, not a company. that person is the “data controller” for your personal data under the EU GDPR and the UK GDPR.
- name: Stanislav Akinfin
- address: Schmollerstr. 6, 12435 Berlin, Germany
- email: stanislavaki@gmail.com
- app: HelloHuman (bundle id world.hellohuman.app)
- website: https://www.hello-human.world
eu/uk representative (Article 27): i'm established in Germany, inside the EEA, so for EU users i serve the market directly and don't need to appoint an Article 27 representative. i don't keep a separate UK representative; if you're in the UK and have a question about this, email me at stanislavaki@gmail.com.
if you have any question about your data, or want to make a request, the email above reaches me directly.
what data i collect
i only collect what the app needs to work. here's the full list. i collect it directly from you, from your device as you use the app, and — for the sign-in email only — from Apple or Google.
account identity
- your email address, from Sign in with Apple or Google sign-in. if you use Apple's “Hide My Email,” i receive a private relay address instead of your real one — that's fine, the app works the same.
- a user id (a random UUID) that ties your data together.
your profile and preferences
- the language you're learning, your native / supporting language, your CEFR level, your notification preferences, and whether you've finished onboarding.
learning content you create
- words you save and their learning status.
- the source url or sentence a word came from, and its translation.
- example sentences.
- spaced-repetition scheduling state — review counts, ease factor, next-review dates.
- your chat history — the questions you type about a word and the AI's replies.
- AI-generated illustrations attached to your saved words.
photos and camera
- when you scan text with the camera, or use the live “look around” camera, the image is sent to an AI provider to read the words or name the objects in it. both the photo scan and the live camera feed go to the AI provider (Anthropic) for this.
- using the camera requires iOS camera permission and your consent in the app before anything is sent; you can decline, and you can stop at any time by not using those features.
- the app does not retain your photos beyond the moment of processing. the image is passed through to the AI provider to extract words or objects and is not saved on my side afterward; only the resulting words or text are kept.
push and device info
- an Apple push notification token, plus your platform, timezone, locale, and last-seen time.
- this is used only to send the daily practice reminders you opt into — nothing else.
usage metering
- for each AI request: token counts, the model name, the operation, and an estimated cost.
- this is how i enforce free daily usage limits and stop abuse. it is never used for advertising.
technical logs
- standard server logs from hosting — things like your ip address and basic request metadata — kept briefly, for security and reliability.
what i deliberately don't do
it's worth being clear about what's not here:
- no analytics or tracking SDKs. i do not run Vercel Web Analytics or Speed Insights, or any other analytics product, on the app or the website.
- no advertising, and no third-party ad trackers.
- no cross-app or cross-site tracking. because of this, the app shows no App Tracking Transparency prompt — there's nothing tracking you across other companies' apps or sites.
- no selling or sharing of your personal data for money or for cross-context behavioral advertising.
- no payments are processed in the app right now. a paid plan may come later; if it does, i'll update this policy first.
how i use your data
under the GDPR and UK GDPR i have to have a “lawful basis” for each use. GDPR has six bases in total; only four apply here (vital interests and public task do not). here's how the four map.
to give you the app you asked for — definitions, translations, practice, audio, images, spaced-repetition scheduling, and saving words — including the AI generation that happens automatically as part of these features (for example, generating a definition when you look up or save a word). lawful basis: performance of a contract (providing the service you signed up for). where AI generation isn't strictly necessary to the contract, i also rely on my legitimate interests in operating the features you're using.
to use your camera and photos, and to send you push reminders. the app asks for your explicit consent before it uses the camera or sends a photo to an AI provider, and before it sends notifications; the camera also requires iOS camera permission. lawful basis: consent. you can withdraw consent at any time — by declining when asked, by not using the camera features, or by turning off notifications in iOS settings. withdrawing consent doesn't affect anything already done before you withdrew.
to keep the service secure, prevent abuse, and enforce free usage limits. lawful basis: my legitimate interests in running a safe, reliable, sustainable app — balanced against your rights and freedoms. you can ask me for details of that balancing test (a legitimate-interests assessment) by emailing stanislavaki@gmail.com, and you have the right to object (see “your rights”).
to comply with the law where a legal duty actually arises — for example responding to a valid legal request, or keeping tax and accounting records if a paid plan launches. lawful basis: legal obligation. this applies only where such a duty genuinely applies.
who i share data with
i keep the list of recipients short, and each one only gets what it needs to do its job. most are service providers (processors) acting on my instructions — not buyers of your data. Apple and Google, for the sign-in step, act as independent controllers (see below).
- Supabase — the database, authentication, and file storage. holds your account data and your saved content.
- Vercel — hosts the website and the app's backend / api. it processes your requests and keeps short-lived logs.
- Anthropic (Claude API) — receives the text you type and the images you scan or capture with the live camera, to generate definitions, translations, hints, chat replies, and example sentences, and to read text or objects from your photos.
- ElevenLabs — receives a word's text to generate pronunciation audio.
- Pexels — receives a word as a search query, to fetch a matching stock photo.
- Apple — Sign in with Apple (for logging you in) and the Apple Push Notification service (for delivering your reminders).
- Google — Google sign-in (for logging you in).
about Apple and Google sign-in. when you sign in with Apple or Google, those companies process the authentication event as independent controllers under their own privacy policies — they are not my processors for that step. i receive back only your email (or an Apple relay address) and a user identifier.
about the AI and stock-photo providers (Anthropic, ElevenLabs, Pexels). these providers process the input you send them in order to perform the feature you asked for, under their own API terms. your inputs may be retained by them and may be used by them per those terms; what they retain, and whether they use inputs to improve their services, is governed by their terms rather than by me, and i can't guarantee otherwise. please read each provider's own privacy policy for the details:
- Anthropic — https://www.anthropic.com/legal/privacy
- Google — https://policies.google.com/privacy
- ElevenLabs — https://elevenlabs.io/privacy
- Pexels — https://www.pexels.com/privacy-policy/
- Supabase — https://supabase.com/privacy
- Vercel — https://vercel.com/legal/privacy-policy
- Apple — https://www.apple.com/legal/privacy/
most of these providers are based in the united states.
i do not disclose your personal data to any third party for that third party's own direct-marketing purposes.
international transfers
because most of my providers are in the united states, using the app means your data is transferred outside the EEA and the UK.
i am responsible for that transfer, so i rely on a lawful transfer mechanism for each US provider, incorporated into my data processing agreement with them:
- the EU Standard Contractual Clauses (SCCs) for transfers out of the EEA;
- for transfers out of the UK, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs;
- where a provider is certified under the EU–US Data Privacy Framework (and its UK extension), i may rely on that adequacy mechanism instead of, or alongside, the SCCs.
the word-as-search-query sent to Pexels, and every other US-provider transfer named above, is covered by these same safeguards. if you'd like detail on a particular provider's mechanism, email stanislavaki@gmail.com and i'll point you to it.
how long i keep your data
- your account data and saved content are kept while your account is active — i keep them until you delete your account or ask me to erase them.
- usage-metering records are kept while your account is active and are erased when you delete your account.
- server and security logs (including ip addresses) are kept only briefly — up to about 30 days — then rotate out.
- photos are not retained beyond the moment of processing (see “what data i collect”).
when you delete your account, your data is removed from the live systems straight away. backups held by my hosting providers rotate on their own schedule, so a copy may persist in encrypted backups for a short window — typically up to about 30 days — before it is overwritten. i don't keep your data longer than i need it for the purposes above or to meet a legal duty.
your rights
if you're in the EU, the UK, or a similar regime, you have the right to:
- access the personal data i hold about you,
- rectify it if it's wrong or incomplete,
- erase it (“right to be forgotten”),
- restrict how i process it,
- port it — receive the data you provided, which i process by automated means on the basis of consent or contract, in a structured, commonly used, machine-readable format,
- object to processing based on my legitimate interests — i'll stop unless i have compelling legitimate grounds that override your interests, or i need to keep processing to establish, exercise or defend legal claims (there is no direct-marketing processing here to object to),
- withdraw consent at any time (this doesn't affect anything done before you withdrew), and
- lodge a complaint with your data protection supervisory authority.
on complaints: you can complain to the supervisory authority where you live. my lead authority is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit) — https://www.datenschutz-berlin.de. in the UK it's the Information Commissioner's Office (ICO) — https://ico.org.uk. i'd appreciate the chance to sort it out with you first, but it's your right either way.
how to exercise these:
- deleting everything is built into the app. go to Profile → delete account. this permanently erases all your data (details in the next section) and removes your login. you don't have to email me or wait on me for this.
- for any other request — access, correction, a portable copy, restriction, an objection — email me at stanislavaki@gmail.com and i'll handle it.
- i may need to verify your identity before actioning an access, erasure, correction or portability request, by confirming details tied to your account, so i don't disclose your data to the wrong person.
- i'll respond within the time the law requires — generally within one month, which i can extend by up to two further months for complex or numerous requests (i'll tell you if i need to).
i won't charge you for exercising your rights, and i won't treat you differently for doing so.
what account deletion removes
when you delete your account in the app, i erase:
- all your saved words,
- your chat history,
- your preferences and profile,
- your push notification tokens,
- your usage-metering records,
and then i delete the login itself. this happens across the live systems immediately; any copy in rotating encrypted backups is overwritten within the backup window described above.
one honest note: shared, generic dictionary content — plain word entries that aren't tied to any person — isn't “your” personal data and isn't deleted. it's the same neutral reference material everyone sees, with nothing linking it to you.
california & u.s. privacy rights
if you live in California, the CCPA/CPRA gives you specific rights. this section stands on its own and broadly reflects what i offer everyone.
categories of personal information i collect, the sources, and why:
- identifiers — email address, user id, push token, ip address. sources: directly from you, from your device, and from Apple/Google sign-in. purpose: to create and secure your account and run the app.
- internet / device activity — request metadata, usage-metering data (token counts, model, operation, cost), locale, timezone, last-seen time. sources: your device as you use the app. purpose: to run features, secure the service, and enforce free usage limits.
- user content you provide — saved words, source sentences and translations, example sentences, chat messages, and images you scan (images are processed to extract text/objects and are not retained). sources: directly from you. purpose: to provide the learning features you use.
- inferences / preferences — the language you're learning, your supporting language, your CEFR level, spaced-repetition state, notification settings. sources: directly from you and from your use of the app. purpose: to personalize your learning.
i collect and use these for the business purposes described — running the app, powering its features, security, and enforcing free limits — and i don't use them for materially different, incompatible purposes without telling you first.
categories disclosed for a business purpose. i disclose identifiers and user content to my service providers so they can perform their function: Supabase (database, auth, storage), Vercel (hosting/backend), Anthropic (definitions, translations, chat, image/text reading), ElevenLabs (pronunciation audio), Pexels (stock-photo lookup), and Apple/Google (sign-in and push delivery). these are disclosures for a business purpose, not sales.
sensitive personal information (SPI). the app relies on account log-in tied to Apple or Google, and your user content could in principle contain information you choose to type. i do not seek out or use SPI to infer characteristics about you, and i only use any such information for the purposes permitted under CPRA §1798.121 (providing the service you asked for and keeping it secure). because i don't use or disclose SPI beyond those permitted purposes, the “right to limit use of sensitive personal information” does not apply here — there is nothing extra to limit.
retention. i keep each category of personal information only as long as your account is active and for the purposes above, then delete it on account deletion; logs (including ip addresses) are kept up to about 30 days. this criteria applies to SPI as well.
no sale, no sharing, no profiling. in the preceding 12 months, i have not sold or shared any personal information, and i do not sell or share it for cross-context behavioral advertising — there is no advertising here at all. because of that, no “Do Not Sell or Share My Personal Information” link is needed. i also do not use your personal information for profiling in furtherance of decisions that produce legal or similarly significant effects about you.
your California rights:
- right to know what personal information i collect, the sources, purposes, and recipients (this policy tells you; you can also ask for specifics).
- right to delete your personal information — built into the app at Profile → delete account, or by emailing me.
- right to correct inaccurate personal information.
- right to opt out of the sale or sharing of personal information — there is nothing to opt out of, because i do not sell or share it.
- right to limit use of sensitive personal information — inapplicable, as explained above.
- right to non-discrimination — i won't treat you worse for exercising any of these rights.
how to submit a request and timing. email stanislavaki@gmail.com. because HelloHuman operates exclusively online and deals with you directly, email (plus the in-app deletion control) is the designated method and no toll-free number is required. i'll confirm receipt and respond within 45 days, extendable by a further 45 days (up to 90 total) where reasonably necessary, and i'll tell you if i need the extension. i may need to verify that the request really comes from you by confirming details tied to your account.
authorized agents. you may use an authorized agent to make a request on your behalf. the agent must provide your signed written permission (or proof of a valid power of attorney), and i may still ask you to verify your own identity and confirm that you authorized the request.
no financial incentives. i don't offer any financial incentives, price or service differences, or loyalty/rewards programs in exchange for your personal information.
“Shine the Light” (Cal. Civ. Code §1798.83). i do not disclose your personal information to third parties for their own direct-marketing purposes, so there's nothing to request under this law.
automated processing
the app uses AI to generate content for you — definitions, translations, hints, example sentences, audio, and to read words or objects from your photos.
this is content generation, not decision-making about you. the AI does not make any legal or similarly significant automated decision about you — nothing here decides your eligibility for anything, profiles you, or scores you. it just helps you learn. there is therefore no automated decision-making of the kind that would trigger a right to human review under GDPR Art. 22, and no profiling for significant decisions under CPRA.
children
the app isn't directed to children.
under COPPA (US): the app is not directed to children under 13, and i do not knowingly collect personal information from children under 13. if i learn that i have, i will delete it.
under GDPR/UK GDPR (EU/UK): i don't knowingly collect personal data from anyone under 16, or the lower age of digital consent set by your country (which can be as low as 13). sign-in relies on an existing Apple or Google account, and the app has no feature intended to onboard children.
under the CCPA: since i do not sell or share personal information, no under-16 opt-in to sale/sharing is needed. i do not knowingly sell or share the personal information of anyone, including minors.
if you're a parent or guardian and you believe a child has given me their data, email me at stanislavaki@gmail.com and i'll remove it.
security
i take reasonable steps to protect your data:
- encryption in transit — everything travels over HTTPS / TLS.
- encryption at rest — your data is encrypted at rest at the database provider.
- secure token storage — your login and session tokens are kept in the device's secure keychain.
if a personal-data breach occurs that is likely to be a risk to you, i will notify the relevant supervisory authority within 72 hours of becoming aware of it where the law requires, and i will inform affected users without undue delay where the breach is likely to result in a high risk to your rights.
honest caveat: no method of storing or sending data is ever perfectly secure. i can't promise absolute security, but i do work to protect your data and to fix problems if they come up.
cookies & local storage
the app itself is not a website full of ad cookies — it doesn't use advertising cookies or third-party trackers at all.
the website at hello-human.world uses only minimal, strictly essential local storage — for example to keep you signed in or remember a basic preference. essential storage of this kind is exempt from consent, which is why there's no cookie banner. there are no advertising, analytics, or tracking cookies, and no non-essential storage. (owner to confirm this matches the deployed website before publishing.)
Do Not Track. some browsers can send a “Do Not Track” signal. because the website does no tracking and serves no advertising in the first place, it doesn't behave differently based on a DNT signal — there is nothing to turn off.
changes to this policy
i may update this policy — for example if i add a feature or a paid plan, or a provider changes. your rights described here — including the right to withdraw consent and the right to complain to a supervisory authority — remain in force across every version.
when i make a material change, i'll update the effective date at the top and, where it matters, show a notice in the app. the current version always lives at https://www.hello-human.world/legal/privacy.
contact
questions, requests, or concerns — email me at stanislavaki@gmail.com. it reaches me, the individual who runs HelloHuman, directly.
this policy is hosted at https://www.hello-human.world/legal/privacy.
© 2026 hellohuman · all rights reserved