Privacy Policy

Effective date: August 2025
Last updated: August 2025
Applies to: Say It Fluently mobile app (Android, iOS) and web app

1. Who We Are

Say It Fluently ("we", "us", "the app") is a CEFR-based language learning application built with Flutter. The app helps users learn languages through spaced repetition, adaptive quizzes, and structured exam preparation.

We are the data controller responsible for your personal data processed through the app. For any privacy-related questions or requests, you can reach us at support@vitrify.no.

2. Data We Collect

2.1 Account Information

When you create an account, we collect:

2.2 Learning Progress & Usage Data

As you use the app, we store:

2.3 Social Data

If you use the social features, we store:

2.4 Analytics Events

The app logs lightweight analytics events (such as dashboard views, button taps, calendar interactions, and leaderboard views) to a local file on your device. This data is not transmitted to any external analytics service. We do not use Firebase Analytics, Google Analytics, Amplitude, Mixpanel, or any other third-party analytics SDK.

No device identifiers collected. We do not collect device IDs, advertising IDs (IDFA/AAID), IP addresses, or location data. We do not use any advertising or tracking SDKs.

2.5 Authentication Tokens

On the web version of the app, a Supabase Auth refresh token is stored in a first-party cookie (sif_rt) so your session persists across browser restarts. This cookie is set with SameSite=Lax and the Secure flag (on HTTPS connections), and expires after 365 days. On native platforms (Android, iOS), no cookie is used.

2.6 Summary of Data Collected

Data CategoryExamplesStored LocallyStored in Cloud
AccountEmail, username, age, learning preferencesYesYes (Supabase)
ProgressVocabulary, SRS history, study plans, test scores, XP, streaks, achievementsYesYes (Supabase)
SocialFriendships, friend requests, leaderboard entriesNoYes (Supabase)
AnalyticsDashboard views, button taps, calendar interactionsYes (local file only)No
Auth tokensSupabase refresh token (web only)Cookie (web only)Managed by Supabase Auth
Device IDsNoNo
LocationNoNo

3. How We Collect Data

4. Why We Collect Data & Legal Basis

PurposeData UsedLegal Basis (GDPR)
Provide authentication and account management Email, password (hashed), OAuth identifier Contract performance (Art. 6(1)(b))
Track learning progress and personalize content Vocabulary, SRS history, study plans, test scores, XP, level Contract performance (Art. 6(1)(b))
Enable social features (friends, leaderboards) Username, XP, level, online status, friendships Contract performance (Art. 6(1)(b))
Sync data across devices Full profile data (sanitized, password excluded) Contract performance (Art. 6(1)(b))
Maintain and improve app functionality Local analytics events (not transmitted externally) Legitimate interest (Art. 6(1)(f))

5. Where Data Is Stored

5.1 Local Storage

Your profile, progress, metrics, and local analytics are stored in a file called users.json on your device. On web, this uses IndexedDB; on native platforms (Android, iOS), it uses the device's file system. This data remains on your device even when you are offline.

5.2 Cloud Storage (Supabase)

When you are signed in, your data is synced to a Supabase backend for cross-device access and social features. The following tables are used:

6. Third-Party Services

6.1 Supabase

We use Supabase for authentication, database hosting, and cloud sync. Supabase processes data on our behalf as a data processor. See the Supabase Privacy Policy.

6.2 OAuth Providers

If you sign in with a social provider, that provider processes your authentication:

We only receive your email address and a provider-specific user identifier from these services. We do not request access to your contacts, posts, friends lists, or any other data from these providers.

No advertising or tracking SDKs. We do not use any advertising networks, ad SDKs, or third-party tracking services. Your data is not sold or shared with advertisers.

7. Data Retention

8. Data Security

We take the following measures to protect your data:

9. Your Privacy Rights

9.1 GDPR (EU/EEA/UK)

If you are in the EU, EEA, or UK, you have the right to:

To exercise these rights, email us at support@vitrify.no. We will respond within one month.

9.2 CCPA/CPRA (California)

If you are a California resident, you have the right to:

9.3 Other Jurisdictions

Users in other jurisdictions may have additional rights under their local privacy laws. Contact us at support@vitrify.no for assistance.

10. How to Delete Your Data

You can delete your account and all associated data at any time:

10.1 In the App

  1. Open the app and go to your Profile screen.
  2. Tap "Delete Profile".
  3. Confirm the deletion when prompted.

This will:

This action is permanent and cannot be undone. If the cloud deletion fails (e.g., due to network issues), your local data is still removed. You will be notified to retry the cloud deletion when connectivity is restored.

10.2 By Email

You can also request account deletion by emailing support@vitrify.no from the email address associated with your account. We will process your request within 30 days.

11. Cookies & Local Storage

The web version of the app uses a single first-party cookie (sif_rt) to store a Supabase Auth refresh token for session persistence. This cookie:

The app also uses IndexedDB (web) or local file storage (native) to store your profile and progress data locally. This is essential for the app to function and is not used for tracking.

We do not use any third-party cookies, advertising cookies, or tracking pixels.

12. Children's Privacy

The app is not directed at children under 13 (or under 16 in certain EU member states). We collect age during onboarding to help verify eligibility. If we learn that we have collected personal data from a child under the applicable age without verifiable parental consent, we will delete that data promptly. If you believe a child has provided us with personal data, please contact us at support@vitrify.no.

13. International Data Transfers

Your cloud data is stored in Supabase's infrastructure. Supabase offers region selection, and your data may be processed in regions outside your country of residence. By using the app, you acknowledge that your data may be transferred to and processed in countries with different data protection laws. We rely on Standard Contractual Clauses (SCCs) where required to ensure appropriate safeguards for international transfers.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or app features. We will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Material changes will be communicated through the app or via email when feasible.

15. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

For privacy-related requests, please include the email address associated with your account so we can verify your identity.