Lemmi Privacy Policy
Effective date: 2026-10-07
Lemmi is a free, ad-free app for learning English vocabulary. This policy explains what data the Lemmi mobile apps and servers process, why, and what choices you have.
1. Who is responsible
Lemmi is developed and operated by Andrii Voitenko, a private individual (not a company), resident in Ukraine. I am the controller of your personal data.
- Contact for privacy questions and requests: privacy@getlemmi.app
- Representative in the European Union (GDPR Art. 27): not appointed yet
2. The short version
- You can use Lemmi without an account. Your learning progress then stays on your device.
- With an account, your progress is stored on our servers so it syncs between devices.
- No ads. Your data is never sold, rented or used for advertising.
- Usage analytics is off unless you allow it, and you can change your choice at any time.
- You can export or delete all your data from the app at any time.
3. What data we process
3.1 Without an account
- Your learning progress, settings and preferences are stored only on your device.
- If you take the placement test, your answers are sent to our server to choose the next question and calculate your result. They are linked only to a random device identifier generated by the app, not to your name or email.
- The app downloads the word list and audio from our servers. Like any internet connection, this reveals your IP address to the servers delivering the files (see 3.5).
3.2 With an account
- Account details:
- email address;
- a password hash (argon2id) if you use email sign-in; we never store the password itself;
- or the identifier Apple or Google gives us if you sign in with them;
- a name if you choose to share it.
- Age check: the year of birth you entered during setup, used to confirm you meet the minimum age.
- Preferences: interface language, pronunciation (UK/US), time zone, daily goal, reminder settings, your analytics choice, and other settings.
- Learning data:
- the exercises you do: the word, the exercise type, whether the answer was correct, response time, and the text you typed (at most 200 characters);
- spaced-repetition review history, study sessions, streak and achievements;
- words you hide, placement test results;
- error reports you send about a word.
- Device data: a random device identifier, platform (iOS/Android), app version, and a push notification token if you allow notifications.
3.3 Crash and error reports
When the app or our servers crash, an error report is sent to Sentry. It contains technical details: the error, app version, device model and operating system version. We configure Sentry so that it does not store IP addresses and does not include your email or the answers you type.
3.4 Usage analytics: only with your consent
If you allow analytics during setup or later in Settings → Privacy, the app sends usage events to Google Firebase Analytics, for example "placement test finished" or "study session completed". Analytics also processes:
- an app-instance identifier;
- device and operating system information;
- approximate location (country or city), derived by Google from your IP address.
For signed-in users we send a pseudonymous user ID. It is derived from, but is not, your account ID. Advertising identifiers are not collected, Google signals and ad personalisation are disabled, and event data is kept for 2 months. If you do not allow analytics, none of this is sent.
3.5 Technical data
Our servers and content delivery network process IP addresses while delivering data, and to protect the service against abuse (for example, rate limiting sign-in attempts). We do not store IP addresses in our learner database. Short-lived technical logs are rotated automatically.
3.6 Account ID and donations
The app shows your account a short Account ID (Settings → Profile). It is calculated from your account ID and is not stored separately. If you quote it in a support request or in the message of a voluntary donation made on our website, we use it only to find your account, for example to recognise your support later. Donations are processed by the payment service you choose (its own privacy policy applies); we receive only what it passes on to us, such as your name, the amount and your message, and keep it for as long as the law requires for our tax records.
4. Why we process data (legal bases)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the learning service: accounts, sync between devices, placement test, study plan, progress, reminders you set up | Performance of a contract (Art. 6(1)(b)) |
| Security, abuse prevention, crash reports, fixing errors in the word content you report | Legitimate interests in a working, secure service (Art. 6(1)(f)) |
| Improving the learning algorithm and content using aggregated, de-identified statistics | Legitimate interests (Art. 6(1)(f)) |
| Usage analytics (Firebase) | Your consent (Art. 6(1)(a)), which you can withdraw at any time |
| Transactional emails (confirming your email, resetting your password) | Performance of a contract (Art. 6(1)(b)) |
We send no marketing emails.
5. Notifications
- Daily reminders are scheduled on your device and work offline. The server is not involved.
- If you allow notifications and are signed in, the server may send at most two "we miss you" messages after 3 and 7 days of inactivity.
- You can turn each type off in Settings → Reminders or in your phone's settings.
6. Who processes data on our behalf
We use the following service providers. They process data only on our instructions.
| Provider | Purpose | Location |
|---|---|---|
| Hosting Ukraine LLC (ukraine.com.ua) | Servers, database | Ukraine |
| Cloudflare, Inc. | DNS, content delivery (word list and audio), email forwarding, encrypted database backups (EU) | Global network |
| Postmark (ActiveCampaign, LLC) | Sending verification and password-reset emails | USA |
| Functional Software, Inc. (Sentry) | Crash and error reports | EU data region |
| Google LLC (Firebase Analytics) | Usage analytics, only with consent | USA |
| Expo (650 Industries, Inc.), Apple, Google | Delivering push notifications | USA |
| Apple, Google | Sign in with Apple / Google, if you choose them | USA |
Our servers and database are located in Ukraine, where we are established. Ukraine does not have an adequacy decision of the European Commission; your data there is protected by encryption in transit, access restricted to the services that need it, and encrypted backups stored in the EU. Where data is transferred to other providers outside the EU/EEA, it is protected by the European Commission's Standard Contractual Clauses or the EU–US Data Privacy Framework, as provided by each provider.
7. How long we keep data
| Data | Retention |
|---|---|
| Account, preferences, review history, progress | Until you delete your account |
| Individual exercise answers (including typed text) | 12 months, then deleted automatically |
| Placement test answers not linked to an account | Unfinished tests are deleted after 7 days, finished ones after 30 days |
| Email confirmation and password-reset links | Expire after 24 hours and 1 hour respectively |
| Database backups | 14 days |
| Crash reports | Up to 90 days |
| Analytics event data | 2 months |
When you delete your account, your data is removed from the live database immediately and disappears from backups within 14 days.
Error reports about a word that you sent are kept to improve the content, but the link to you and your comment text are removed.
8. Your rights
Depending on where you live (for example, under the GDPR), you have the right to:
- access your data and receive a copy (portability): Settings → Privacy → Export data gives you a complete JSON file;
- correct your data;
- delete your data: Settings → Privacy → Delete account, or without the app as described at
https://app.getlemmi.app/delete-account; - restrict or object to processing based on legitimate interests;
- withdraw consent for analytics at any time in Settings → Privacy. This does not affect processing that already happened.
To exercise any right, write to privacy@getlemmi.app. We answer within one month. You may also complain to a data protection authority. In the EU, this is the authority of your country of residence. In Ukraine, it is the Ukrainian Parliament Commissioner for Human Rights.
9. Children
Lemmi is intended for people aged 13 and older (16 and older in the EU/EEA). The app asks for your year of birth and does not let younger users continue. If we learn that we hold data of a younger child, we delete it. Parents or guardians can contact privacy@getlemmi.app.
10. Security
- All connections use TLS encryption.
- Passwords are stored only as argon2id hashes. Sign-in tokens are stored only as hashes.
- The public service has no access to the administration database tables. Administrator access requires two-factor authentication and is logged.
- Backups are encrypted.
No system is perfectly secure. If a breach affects your data, we will inform you and the authorities as required by law.
11. Changes to this policy
If we change this policy, we will update the date above. If the change is significant, we will also inform you in the app before it takes effect.
12. Contact
Andrii Voitenko · privacy@getlemmi.app