Privacy policy
Last updated: 22 July 2026
This policy describes what personal data the Greenlight app (“the app”) processes and why. It is written in line with Regulation (EU) 2016/679 (GDPR).
1. Data controller
The data controller is Dariusz Biel. For any data-protection matter, contact [email protected].
2. What we process
For the app to work, we process the following categories of data:
- Account data: your email address and password. We never store the password in clear text — only a cryptographic hash of it (bcrypt).
- Learning profile: your chosen level (A2, B1, B2), comfort threshold, learning goal, favourite genres, daily time goal and time zone (default Europe/Warsaw). This drives vocabulary selection and statistics.
- Personal dictionary and progress: the words you know or are learning together with their spaced-repetition state, your watched-episode history, flashcard sessions and cached episode analyses (Gap Check).
- Requests and votes: the titles you request for the library and your votes on community suggestions.
- Subscription status: whether you have an active Pro plan. The subscription is billed by the App Store — we do not receive or store your card details.
3. Subtitles are processed ephemerally
When we analyse an episode, the subtitle file is processed in memory and immediately discarded. We do not store its contents in the database. What remains is a SHA-256 digest (so we can recognise a file we have already analysed) and a set of numeric counts. Not a single line of dialogue is stored. The example sentences shown on flashcards are written for the app — they are not quotes from the analysed subtitles.
4. Purposes and legal bases
- Providing the service (running your account, syncing your dictionary and progress, analysing episodes) — Art. 6(1)(b) GDPR (performance of a contract).
- Billing the Pro subscription — Art. 6(1)(b) GDPR. The payment itself is handled by Apple under its own terms.
- Security and abuse prevention (e.g. rate-limiting login attempts) — Art. 6(1)(f) GDPR (legitimate interest).
5. Sessions and security
To keep you signed in we use tokens (a JWT and rotating refresh tokens). The database stores only their digests — never the tokens themselves. On the device, tokens are held in the system Keychain. Changing your password or signing out of all devices invalidates every active session. A password-reset link is single-use and expires after 15 minutes.
6. Analytics and tracking
The app contains no third-party analytics or advertising package and does not track you across apps. This website uses no cookies and no analytics — see the Cookie policy.
7. Recipients
Data is processed by the controller and by a hosting-infrastructure provider acting on the controller's behalf. Subscription status is verified against the purchase receipt issued by Apple. We do not sell data and do not share it for marketing.
8. Transfers outside the EEA
We do not transfer your data outside the European Economic Area.
9. Retention
Account and progress data are kept for as long as you have an account. After you delete your account, the data is deleted, except for information we must retain for a period required by law (e.g. billing records related to a subscription).
10. Your rights
You have the right to access, rectify, erase, restrict and port your data, and to object to processing. You can delete your account from within the app or by writing to [email protected]. You also have the right to lodge a complaint with the Polish data-protection authority (UODO).
11. No profiling
We do not make decisions about you based solely on automated processing that would produce legal or similarly significant effects. Vocabulary selection serves only to personalise your learning.
12. Changes
We will announce material changes in the app or on this page. The date at the top of the document shows the last update.