This policy explains what data YabLab collects, why, and what happens to it. YabLab — the web application, browser extension, and desktop application, together the “Service” — is operated by Yevhenii Zapov, an individual entrepreneur registered in Georgia (“we”, “us”).
The short version: we collect what’s needed to run a language-learning product, we don’t sell it or use it for advertising, and you can delete your account or ask us to exercise any of your privacy rights.
1. Who we are
The Service is operated by Yevhenii Zapov, an individual entrepreneur registered in Georgia, located at Police Street I Dead End N5, Floor 2, N4a, Samgori District, Tbilisi, Georgia. Identification number 306443202. For anything privacy-related, write to yevheniizapov@gmail.com.
2. What data we collect
2.1 Things you give us
- Account data — your email address and, if you register with a password, a securely hashed version of it. If you sign in with Google, we get your email and basic profile information instead (see 2.3).
- Age group — at sign-up we ask for your month and year of birth to check you are 16 or older, but we store only the resulting age group (16–17 or 18+), never the date itself. We also record which version of the Terms and this policy you accepted, and when.
- Learning preferences — your native language, the languages you’re learning, and your goals and settings.
- Learning content — vocabulary, terms, sets, study sessions, review results, and progress data you create, save, or import (for example, from Anki).
- Text you send to language features — the words and phrases you select for translation, subtitle excerpts you interact with, text you type in fields where the writing checker is active, page text you explicitly ask the extension to adapt to your level, and anything you submit to AI-assisted learning features.
- Billing data — if you buy a subscription, the payment itself is handled by Paddle (see section 5). We receive your subscription status, plan, and transaction metadata — never your full card number.
- Support and feedback — if you contact us or send a bug report through the Service, we keep the message and any files you attach.
2.2 Things collected automatically
- Technical data — browser type and version, operating system, device type, language preference, and approximate location derived from your IP address.
- Usage data — limited feature interactions, app platform, runtime session timestamps, and acquisition parameters we need to understand and improve the Service. Product analytics runs only after you allow it in the analytics choice shown on our sites, and you can decline with one click. Before sign-in, product-analytics identifiers, session state, and acquisition parameters are kept only in the current JavaScript runtime; after sign-in, events are linked to your account identifier so your history stays consistent across devices. A short-lived journey identifier may travel from the landing page to sign-up in the URL and may be associated with your account if you register. We remove query strings and fragments from page and referrer URLs before analytics is sent, and we don’t send selected text, text-field contents, or page contents in product-analytics events.
- Error and performance data — app version, platform, stack traces, and technical context needed to diagnose failures. Before browser errors are sent, we remove URL query strings and fragments, cookies, authentication headers, and other sensitive request headers.
- Cookies and local storage — authentication tokens, locale preference, and short-lived state the Service needs to function. These functional storage mechanisms are separate from product analytics.
2.3 Things from third parties
If you sign in with Google, we receive your email address and the basic profile data allowed by the permissions you grant.
3. Why we process your data (legal bases)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and operating your account | Contract |
| Providing language-learning features | Contract |
| Processing subscriptions and payments | Contract |
| Sending account, security, and service emails | Contract / Legitimate interest |
| Handling support requests and feedback | Contract / Legitimate interest |
| Securing, maintaining, and improving the Service | Legitimate interest |
| Complying with legal obligations | Legal obligation |
| Product analytics | Consent |
| Optional product communications | Consent |
You can withdraw consent at any time; this doesn’t affect processing that happened before you withdrew it.
4. How long we keep your data
- Account and learning content — kept while your account is active. When account deletion completes, your account record, learning content, preferences, statistics, stored files, and related data are removed from our active databases and object storage. Any renewable Paddle subscription is scheduled to stop before its next billing period. If Paddle or cloud storage is temporarily unavailable, deletion remains pending and can be retried instead of silently leaving files or an active renewal behind. You can also delete individual items whenever you want.
- Support and feedback — kept in an access-controlled support system as long as needed to resolve your request, plus a reasonable period for reference.
- Authentication tokens — access tokens expire after 24 hours; refresh tokens and the sign-in session after 60 days; email-verification and account-recovery tokens live between 15 minutes and 24 hours.
- Billing records — Paddle retains transaction records as required by tax and accounting law; we keep the subscription metadata described in 2.1 while your account exists.
- Analytics, error reports, and operational logs — kept for limited periods configured with the relevant provider and only as long as needed to understand, debug, and secure the Service. Account-linked analytics may require a separate erasure request until vendor deletion is fully automated; write to us and we will handle it under the applicable legal deadline.
- Backups — database backups are managed by our database provider (MongoDB Atlas) and retained according to its backup configuration; residual copies are overwritten on a rolling basis.
5. Who we share data with
We do not sell your personal data. We share it only with service providers and other recipients that we need to run the Service:
- Cloud hosting, compute, and email — Amazon Web Services (EC2 for application hosting, Amazon SES for transactional email such as sign-up confirmation, password reset, and security alerts).
- Database — MongoDB Atlas (managed by MongoDB, Inc.); a Redis cache may hold short-lived operational state.
- Object storage — Google Cloud Platform (Cloud Storage) for files such as images attached to your learning content.
- Authentication — Google, if you choose to sign in with Google.
- Payments — Paddle.com, our merchant of record. Paddle collects and processes your payment details under its own privacy policy; we never see your card number.
- Product analytics — PostHog, Inc. We send limited product events to its EU ingestion endpoint. PostHog receives the runtime or account identifier used for the event and the minimized properties described in section 2.2; it does not receive advertising profiles from us.
- Error monitoring — Functional Software, Inc. (Sentry). Sentry receives minimized crash and diagnostic data described in section 2.2. We disable default PII collection and sanitize browser URLs, cookies, and authentication headers before sending.
- AI and language-model processing — when you use translation, dictionary lookup, writing check, page adaptation, or other AI-assisted features, the text you submitted is sent to third-party AI and language-model providers for processing. We avoid attaching your name, email, or account identifiers to these requests where avoidable. Linguistic processing of subtitles runs on our own servers.
- Support and feedback — feedback messages and attachments are stored in an access-controlled support system hosted by GitHub, Inc. They are not publicly accessible; access is limited to the operator, and to service-provider personnel where necessary to operate, secure, or maintain the service, or where disclosure is required by law.
Where a provider acts as our processor, our agreement limits it to processing data to provide the contracted service. Providers such as Paddle and Google may also act as independent controllers for parts of their payment or authentication services under their own privacy notices.
6. International transfers
Some providers are located outside your country, including in the United States. Where required, transfers rely on the European Commission’s Standard Contractual Clauses or other safeguards listed in GDPR Chapter V.
7. Your rights
Georgia’s personal-data law applies to processing carried out by us in Georgia. Depending on where you live and how the Service is offered to you, the GDPR, UK GDPR, or other local privacy laws may apply as well. These laws may give you the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data deleted (“right to be forgotten”);
- restrict or object to certain processing;
- receive a portable copy of your data;
- withdraw any consent you’ve given;
- complain to your local data-protection authority.
Write to yevheniizapov@gmail.com to exercise any of these rights. Requests governed by Georgian law are generally handled within 10 working days, subject to a justified extension where the law permits one; GDPR requests are normally handled within one month. You may also complain to the State Audit Office of Georgia or to the data-protection authority where you live.
8. Security
We protect your data with encryption in transit (HTTPS/TLS), encryption at rest where our infrastructure supports it, role-based access controls, and regular security reviews. No system is perfectly secure; if we discover a breach affecting your data, we will notify you and the relevant authorities as the law requires.
9. Children
The Service is for users aged 16 and older, and we don’t knowingly collect data from anyone younger. Sign-up includes an age check, accounts that fail it are deleted, and paid subscriptions are limited to users aged 18 or older. If you believe someone under 16 has given us data, contact yevheniizapov@gmail.com and we’ll delete it.
10. Browser extension and desktop application
The extension and desktop app don’t collect your browsing history or send the URLs or contents of pages you visit to product analytics. They do send the limited feature-use and error data described in section 2.2. Here is exactly what each user-facing language feature touches:
- Click-to-translate — processes only the text you select, and only when you select it.
- YouTube subtitles — processes the subtitles of videos you watch with the feature enabled, so it can show the paired translation.
- Word highlighting — scans the text of pages you visit locally in your browser to highlight words from your saved vocabulary. Page text is not sent to our servers for this; you can turn highlighting off per site.
- Writing check — when active in a text field, the text you type there is sent to our backend and AI sub-processors (section 5) to generate corrections. It processes only the field you’re writing in, and YabLab’s own pages are excluded.
- Page adaptation — when you explicitly invoke it (context menu or keyboard shortcut), the readable text of the current page is sent for processing so it can be rewritten at your level. It never runs on its own.
Text sent for processing by these features goes to our backend and to the AI sub-processors described in section 5. Authentication tokens are stored locally by the extension solely to keep you signed in and to sync your data with your account.
11. Changes to this policy
We may update this policy from time to time. For material changes we’ll notify you by email or in the app. The “Last updated” date at the top reflects the most recent revision.
12. Contact
Yevhenii Zapov (Individual Entrepreneur) Police Street I Dead End N5, Floor 2, N4a, Samgori District Tbilisi, Georgia Email: yevheniizapov@gmail.com