Last Updated: April 20, 2025
1. Introduction
Welcome to EverGrasp, a learning web application ("Service"). This Privacy Policy explains how Daniel Mikula, operating as a sole trader under Czech law ("we," "us," "our"), collects, uses, processes, and protects your personal data when you use our Service.
We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR).
By creating an account and using the Service, you acknowledge that you have read and understood this Privacy Policy. This policy should be read in conjunction with our Terms of Use.
2. Data Controller
The data controller responsible for the processing of your personal data is:
Daniel Mikula
Registered Address: Osadní 869/32, 170 00 Prague 7, Czechia
IČO (Identification Number): 04949421
Contact Email: info@evergrasp.com
3. What Personal Data We Collect and Why
We collect different types of information for various purposes to provide and improve our Service to you.
-
Account Information:
-
Data: Email address, password hash, account creation date.
-
Purpose: To create and manage your user account, allow you to log in, secure your account, and communicate important service-related information.
-
Legal Basis (GDPR Art. 6(1)(b)): Processing is necessary for the performance of a contract (our Terms of Use) with you.
-
User Preferences & Learning Data:
-
Data: Language learning preferences, learning data (e.g., vocabulary items marked as learned, review schedules, progress metrics).
-
Purpose: To personalize your learning experience and provide the core functionality of the language learning service.
-
Legal Basis (GDPR Art. 6(1)(b)): Processing is necessary for the performance of a contract with you.
-
User-Generated Content:
-
Data: Vocabulary, example sentences, or other text you voluntarily submit to the Service for your personal learning.
-
Purpose: To allow you to personalize your learning materials. We also process this data using third-party AI services (see Section 7) to provide features like translation and pronunciation generation for your benefit. This content is not visible to other users but may be accessed by administrators for service maintenance and support.
-
Legal Basis (GDPR Art. 6(1)(b)): Processing is necessary for the performance of a contract with you (providing the features you use).
-
Technical & Security Data (Transient):
-
Data: IP address, accessed endpoints (pages/API routes visited).
-
Purpose: To protect the Service against abuse, ensure security, perform rate limiting, and diagnose technical problems. This data is stored temporarily and is automatically deleted no more than 45 days after it is collected.
-
Legal Basis (GDPR Art. 6(1)(f)): Processing is necessary for our legitimate interests in maintaining the security and integrity of our Service. We have balanced this interest against your rights and freedoms.
-
Usage Information (via Cookies & Local Storage):
-
Data: We store your login session identifier in a cookie. We store your user interface preferences (e.g., dark/light mode) in your browser's local storage.
-
Purpose: To keep you logged in across sessions and to remember your interface preferences for a better user experience.
-
Legal Basis (GDPR Art. 6(1)(a)): Your consent, obtained via our cookie consent mechanism.
4. How We Use Your Data
We use the collected data for the following purposes:
-
To provide and maintain our Service.
-
To manage your account and facilitate login.
-
To personalize your learning experience based on your preferences and progress.
-
To enable features using third-party AI services.
-
To monitor the usage of our Service for security, abuse prevention, and technical troubleshooting.
-
To communicate with you, potentially including service updates or responding to your inquiries (using your provided email).
5. Cookies and Local Storage
We use cookies and browser local storage to enhance your experience.
-
Cookies: We use a persistent cookie solely to manage your login session, allowing you to stay logged in.
-
Local Storage: We use browser local storage to remember your user interface preferences.
You can typically manage cookies and local storage through your browser settings. Please note that disabling the essential login cookie will prevent you from logging into the Service.
6. Data Security
We implement appropriate technical and organizational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These include measures like hashing passwords and securing our hosting environment. However, please be aware that no method of transmission over the Internet or method of electronic storage is 100% secure.
7. Third-Party Services and Data Processors
We use third-party services ("Data Processors") to provide certain functionalities. We only share data necessary for them to perform their services and require them to uphold the confidentiality and security of your data.
-
OpenAI, L.L.C.: Used for generating translations, generating audio or other language-related features. To enable these features, we send only the relevant text (e.g., the expression to be translated) to OpenAI for processing. No personal identifiers like your email address are included in this request.
-
Google Cloud Platform (Google LLC / Google Cloud EMEA Ltd): Used for generating translations, generating audio or other language-related features. To enable this feature, we send only the relevant text (e.g., the expression to be translated) to Google Cloud for processing. No personal identifiers like your email address are included in this request.
-
Hosting Provider: Hetzner Online GmbH located in Germany. Provides the infrastructure for the Service, including storing your data securely.
8. International Data Transfers
Some of our Data Processors (OpenAI, Google Cloud) may be based outside the European Union / European Economic Area (EEA), primarily in the United States. When your personal data (specifically, the text content submitted for AI features) is transferred outside the EEA, we ensure appropriate safeguards are in place to protect your data in accordance with GDPR requirements.
These safeguards currently include:
-
Reliance on Standard Contractual Clauses (SCCs) approved by the European Commission and/or the provider's certification under the EU-US Data Privacy Framework (DPF).
We recommend you review the privacy policies of OpenAI and Google Cloud for more information on their data handling practices.
9. Data Retention
We retain your personal data associated with your account for as long as your account remains active.
If you choose to delete your account via the Service's settings page, all your personal data associated with that account will be permanently deleted from our primary databases within a reasonable timeframe, subject to any technical limitations or legally required retention periods.
10. Your Data Protection Rights (GDPR)
Under GDPR, you have the following rights regarding your personal data:
-
Right of Access: You can request copies of your personal data.
-
Right to Rectification: You can request correction of inaccurate data or completion of incomplete data.
-
Right to Erasure ('Right to be Forgotten'): You can request the deletion of your personal data under certain conditions (e.g., it's no longer necessary for the purpose it was collected).
-
Right to Restriction of Processing: You can request the limitation of how we process your data under certain conditions.
-
Right to Data Portability: You can request your data be transferred to you or another controller in a structured, commonly used, machine-readable format (where processing is based on consent or contract and automated).
-
Right to Object: You can object to processing based on legitimate interests.
-
Right to Withdraw Consent: Where processing is based on consent (like for non-essential cookies/local storage), you can withdraw your consent at any time.
11. How to Exercise Your Rights
-
Account Deletion: You can exercise your right to erasure by deleting your account directly through the settings page within the EverGrasp application. This is the fastest way to have your data removed.
-
Other Rights: To exercise your rights of access, rectification, restriction, portability, or objection, or if you have issues with account deletion, please contact us at: info@evergrasp.com. We will respond to your request in accordance with applicable law. We may need to verify your identity before processing your request.
12. Children's Privacy
Our Service is not intended for use by individuals under the age of 16 (or the applicable minimum age required for data processing consent in their jurisdiction, whichever is higher). We do not knowingly collect personal data from children under this age limit. Use of the Service by individuals under this age limit is prohibited.
If we learn that we have inadvertently collected personal data from a child under the required age limit, we will take steps to delete that information as quickly as possible. If you are a parent or guardian and discover that your child under the required age limit has created an account or otherwise provided personal data to us, please contact us immediately so we can take appropriate action, including deleting the child's personal data.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We may also inform you via email or through the Service. We encourage you to review this Privacy Policy periodically for any changes.
14. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Daniel Mikula
Contact Email: info@evergrasp.com
Registered Address: Osadní 869/32, 170 00 Prague 7, Czechia
15. Supervisory Authority
If you are located in the European Economic Area and believe our processing of your personal data infringes GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement. The supervisory authority in Czechia is:
Úřad pro ochranu osobních údajů (The Office for Personal Data Protection)
Pplk. Sochora 27
170 00 Praha 7
Czechia
Website: www.uoou.cz