Legal

Privacy policy

Last updated 1 August 2026

The short version: your words are yours. We do not sell them, we do not give them to advertisers, and we do not train AI models on them. The long version below is the information we owe you under Articles 13 and 14 GDPR, and it is written to be accurate rather than reassuring.

B1. Controller

The controller for the processing described here, within the meaning of Article 4(7) GDPR, is:

Oleksandr YaskoMindwareKolonnenstr. 810827 BerlinGermany

Email: privacy@catchword.me. Full provider details are on the Impressum page.

This policy covers the Catchword apps and this website. It applies alongside the GDPR, the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG).

B2. Data protection officer

We have not appointed a data protection officer. The thresholds in Article 37 GDPR and Section 38 BDSG are not met: this is a one-person business, and our core activity is not large-scale regular and systematic monitoring of individuals or large-scale processing of special-category data. Send data-protection questions to privacy@catchword.me and they reach the controller directly.

B3. What we collect

  • Your email address. The only identifier we ask for. There is no name, phone number or postal address field anywhere in the product.
  • The words you capture, the card generated for each one, and the context you gave — such as the title of what you were watching.
  • Your review history: which cards you saw, what you recalled, and when. The scheduling algorithm cannot work without it.
  • Your onboarding answers: your goal, your pace, your review time.
  • Subscription status: whether you have an active entitlement, which plan, and when it renews or lapses. Not your card number — we never receive it.
  • Technical data automatically sent by your browser or app when it connects: IP address, device and OS version, app version, timestamps, and error diagnostics.
  • Usage analytics, but only if you allow them — which screens you opened and which steps you finished. See B9.
  • Push notification tokens, if you turn reminders on.
  • Anything you write to us by email, and our replies.

We do not ask for special-category data under Article 9 GDPR. Please do not capture words in a note that reveals your health, beliefs, political opinions or sexuality — the field is free text and we cannot filter what you type into it.

B4. Purposes and legal bases

  • Running the service — your account, your cards, your review schedule, syncing across devices. Article 6(1)(b) GDPR, performance of the contract.
  • Signing you in — sending and checking the one-time code. Article 6(1)(b) GDPR.
  • Generating cards — sending the word and its context to our model provider. Article 6(1)(b) GDPR.
  • Taking payment and managing subscriptions — Article 6(1)(b) GDPR, and Article 6(1)(c) GDPR for the invoicing and record-keeping that tax law requires.
  • Security, abuse prevention and rate limiting — including the captcha on sign-in. Article 6(1)(f) GDPR; our legitimate interest is keeping accounts and infrastructure from being attacked or abused, which is also in your interest.
  • Diagnosing errors and keeping the service stable — Article 6(1)(f) GDPR; our legitimate interest is a working product.
  • Product analytics — Article 6(1)(a) GDPR, your consent, and Section 25(1) TDDDG for the storage and reading of information on your device. You can withdraw it at any time.
  • Push notifications — Article 6(1)(a) GDPR, the permission you grant your operating system.
  • Answering your messages — Article 6(1)(b) or 6(1)(f) GDPR depending on what you write about.
  • Meeting legal obligations and defending legal claims — Article 6(1)(c) and 6(1)(f) GDPR.

Providing your email address is necessary to have an account; without it we cannot provide the service. Everything marked as consent above is genuinely optional and the product works without it.

B5. The microphone

The microphone is only active while you are actively capturing a word — you start it, it stops on its own when you finish speaking, and it is not listening in the background at any other time. The app cannot access it at all until you grant the operating system permission, and you can revoke that in your device settings without losing your existing cards.

B6. What happens to your voice

This is the part most worth reading carefully, and the previous version of this policy overstated it.

Catchword does not record, store or transmit your audio itself, and there is no archive of you speaking anywhere in our systems. We never receive the audio. What reaches us is the transcribed text.

But the transcription is done by your device's operating system, not by us, and on current iOS and Android builds that may involve the audio being sent to Apple's or Google's servers to be recognised. That processing happens under Apple's or Google's own privacy policies, as the provider of the speech recognition on your device, and it is outside our control. If that matters to you, both platforms offer settings that keep dictation on-device, and the app works with them enabled.

We do not build a voice profile, and we do not use your voice to identify you.

B7. AI card generation

When you capture a word, we send that word and the context you gave it to OpenAI, which returns the card. We do not send your email address, and no review history goes with it.

The request is made through OpenAI's API under a data processing agreement. Content sent through that API is not used to train OpenAI's models under its API terms. OpenAI is established in the United States; see B13.

We do not use your content to train any model of our own, and we do not sell or license it as training data to anyone.

Card generation is not automated decision-making producing legal or similarly significant effects for you within the meaning of Article 22 GDPR. Nothing the model writes decides anything about you.

B8. Cookies and local storage

Storing information on your device, or reading it from there, needs your consent under Section 25(1) TDDDG unless it is strictly necessary to deliver a service you asked for.

  • Strictly necessary — your sign-in session, and the record of the choice you made on the consent banner so we do not ask again on every page. Section 25(2) no. 2 TDDDG, no consent required.
  • Analytics — set only after you press "Allow". Section 25(1) TDDDG.

We run no advertising cookies, no third-party ad trackers, no fingerprinting and no cross-site tracking pixels, on the site or in the app.

B9. Analytics

We use PostHog for product analytics and Google Analytics 4 for acquisition measurement. Neither loads, and neither sets anything on your device, until you consent on the banner. Decline and nothing is sent — events raised before you answer are held in memory and discarded, not queued for later.

Analytics events are keyed to your account identifier rather than to anything about you personally, and IP addresses are shortened by Google Analytics before storage. You can change your mind at any time by clearing this site's data in your browser, which brings the banner back, or by writing to privacy@catchword.me. Withdrawal does not affect the lawfulness of what was processed before it.

Both PostHog and Google Analytics may process data in the United States; see B13.

B10. Payments

Subscriptions run through RevenueCat, and through Apple or Google where you bought inside the app. They receive the fact of a purchase, the plan, and an identifier for your account.

We never receive your card number, and no payment credentials touch our systems. Apple and Google act as your contracting party and as their own controllers for store purchases, under their own privacy policies. We keep invoices and the underlying records for as long as tax and commercial law require.

B11. Push notifications

If you turn on review reminders, your device is issued a token by Apple Push Notification service or Firebase Cloud Messaging, and we store it so we can send the reminder. Turn notifications off in your device settings and the token stops working; we delete tokens that have become invalid.

B12. Who else receives your data

A short list, each doing one job, each bound by a data processing agreement under Article 28 GDPR where they act as our processor. None of them receives your data for their own purposes.

  • Supabase — database, authentication, and the sign-in emails. Stores your account, your words and your review history.
  • OpenAI — generates cards from the word and its context. See B7.
  • RevenueCat, and Apple and Google as the stores — subscriptions and payment.
  • Apple and Google as operating-system vendors — speech recognition (B6) and push delivery (B11), as their own controllers.
  • PostHog and Google Analytics — analytics, with your consent only. See B9.
  • hCaptcha (Intuition Machines) — distinguishes people from bots at sign-in.
  • Vercel — hosts and serves this website.

Beyond that we disclose personal data only where we are legally obliged to — a valid order from a court or authority — or where it is necessary to establish, exercise or defend legal claims. We do not sell personal data, and we do not share it with advertisers or data brokers.

B13. Transfers outside the EU and EEA

Several of the providers above are established in the United States or process data there, including OpenAI, RevenueCat, PostHog on its default US host, Google and Apple. Those transfers are covered by appropriate safeguards under Chapter V GDPR — the European Commission's Standard Contractual Clauses under Article 46(2)(c), and, where the provider is certified, the EU–US Data Privacy Framework adequacy decision under Article 45.

We should be straightforward about the residual risk: US law may give public authorities access rights that go beyond what EU law would allow, and the safeguards reduce that risk without eliminating it. You can ask us for a copy of the safeguards in place for a particular provider at privacy@catchword.me.

B14. How long we keep it

  • Account and content — until you delete them in the app, or ask us to close your account.
  • After you close your account — deleted from live systems promptly and from backups within thirty days, as backups rotate.
  • Server and security logs — up to 90 days, longer only for a specific log under investigation for a security incident.
  • Analytics — up to 14 months.
  • Invoices and accounting records — for the statutory retention periods under Section 147 AO and Section 257 HGB, currently up to ten years depending on the document. We cannot delete these on request; we can restrict their processing.
  • Correspondence — up to three years, in line with the general limitation period under Section 195 BGB.

B15. Security

Data is encrypted in transit with TLS and at rest by our infrastructure providers. Database access is restricted by row-level security so one account cannot read another's rows, administrative access is limited to the controller, and secrets are held in the hosting platform rather than in the codebase. Card generation is gated server-side on a real, entitled account, so an API key alone cannot spend it.

No system is perfectly secure, and we do not claim otherwise. Report anything you find to security@catchword.me. Where a breach is likely to result in a high risk to your rights and freedoms, we will notify you under Article 34 GDPR, and the supervisory authority under Article 33.

B16. Your rights

You have the right to:

  • access your data and get a copy of it (Article 15 GDPR);
  • correct anything inaccurate (Article 16 GDPR);
  • have it deleted (Article 17 GDPR);
  • restrict how we process it (Article 18 GDPR);
  • portability — receive it in a structured, machine-readable format, or have it sent to another provider (Article 20 GDPR);
  • object to processing based on legitimate interests (Article 21 GDPR — see the box below);
  • withdraw consent at any time, without affecting the lawfulness of processing before the withdrawal (Article 7(3) GDPR);
  • complain to a supervisory authority (Article 77 GDPR — see B17).

Write to privacy@catchword.me from the address on your account, and say in your own words what you want — access, a copy, correction, deletion. We answer within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. It is free, and you never have to quote an article number to us to exercise any of it.

Right to object — Article 21 GDPR

Where we process your personal data on the basis of our legitimate interests under Article 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation. If you object, we will stop processing that data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

Send an objection to privacy@catchword.me. No particular form is required.

B17. Complaints

You can complain to any data protection supervisory authority, in particular in the member state of your habitual residence, your place of work, or where you think an infringement happened. The authority responsible for us is:

Berliner Beauftragte für Datenschutz und InformationsfreiheitAlt-Moabit 59–6110555 BerlinGermany

datenschutz-berlin.de

We would rather hear about it first, at privacy@catchword.me — but going straight to the authority is your right and does not require you to contact us at all.

B18. Children

Catchword is not intended for children under 16, and we do not knowingly collect data from them. Article 8(1) GDPR sets the age for a child's own consent to information society services at 16 in Germany, which has not legislated a lower age.

If you believe a child under 16 has given us data, write to privacy@catchword.me and we will delete the account and its data.

B19. Changes to this policy

We update this policy when the product or the law changes. If a change materially affects how we handle your data, we will tell you in the app or by email before it takes effect, rather than quietly editing this page. The date at the top always reflects the current version.