This Privacy Policy explains how the provider of the CatchLingo mobile application ("CatchLingo", "we", "us") collects, uses, stores, shares, and protects your personal information when you use the CatchLingo app (the "Service"). It also explains the rights and choices you have.
We built CatchLingo with a "data-minimization" approach: we collect only what is needed to recognize objects in your photos and help you learn new words, and we delete your photos shortly after each recognition is complete.
1. The short version
- What you give us: your email address (to sign in), the photos you choose to recognize, and your language preferences.
- Photos are short-lived: we delete the photos you upload, together with the recognition results, within minutes after each task finishes. We do not keep your photos, and we never use them to train AI models.
- We do not sell your data, and the app does not include advertising SDKs that track you across other apps.
- No device tracking IDs: we do not collect IDFA, IDFV, Android advertising ID, precise location, or your contacts.
- Analytics are region-aware: anonymous usage analytics are off by default for users in GDPR regions (EU/EEA/UK/CH) and can be switched off anywhere.
- You are in control: export your data or delete your account at any time in Settings → Data & Privacy.
2. Information we collect
2.1 Information you provide
- Account information. When you sign up with email, we collect your email address and a password (stored only as a one-way hash). When you use "Sign in with Google" or "Sign in with Apple", we receive only the limited profile data the provider shares — typically your name, email address, and profile-photo URL. We store only a stable, provider-assigned account identifier from Google/Apple, not your Google/Apple passwords or access tokens.
- Photos. The pictures you take or pick from your library so we can recognize objects in them. This is the core of the Service.
- Learning preferences. The languages you are learning (native and target), the text-to-speech voice you select, and your preferred recognition quality.
2.2 Information generated when you use the Service
- Recognition results (object names, related words, categories), task and status records, your credits and subscription entitlement, and which in-app notifications you have read.
- Your time zone and a coarse region tag (whether you are in a GDPR region or not), which we use only to choose where to store your data.
2.3 Information collected automatically (and what we deliberately avoid)
- Your IP address and device type are used only transiently, in memory, to determine your region (so we can route storage correctly) and to show you the right system prompts. They are not saved in our database.
- What we do not collect: precise location, IDFA, IDFV, Android ID or advertising IDs, phone number, address book/contacts, date of birth, or gender. The app does not request permission for any of these.
2.4 Information from third parties
- Purchase data from Apple App Store, Google Play, and RevenueCat (our subscription-management provider) — limited to what is needed to confirm and manage your subscription. We never see or store your card numbers or full payment details; payments are processed by Apple/Google.
- Anonymous usage and crash data via Firebase, described in Section 4.
3. How we use your information
We use your information to:
- Provide the Service: recognize objects in your photos, generate vocabulary and pronunciation, and save the cards you create.
- Manage your account and subscription: sign you in, verify your email, reset your password, and apply your credits and subscription.
- Communicate with you: send verification, security, and account-deletion-confirmation emails.
- Improve and stabilize the Service: diagnose crashes and analyze aggregated, anonymous usage (only where enabled — see Section 4).
- Meet legal obligations and protect against abuse and fraud.
Legal bases (for users in the EU/UK/EEA): we process your data based on (a) performance of the contract with you to provide the Service, (b) your consent where we ask for it, (c) our legitimate interests in operating, securing, and improving the Service, and (d) compliance with our legal obligations.
What we do not do: we do not sell or rent your personal data, we do not use your photos to train AI models, and we do not share your data for cross-app advertising.
4. Analytics, crash reporting, and advertising
- Firebase Analytics (Google Analytics for Firebase). Used to understand, in aggregate, how the app is used (for example, which screens are viewed and which features are used). It is disabled by default for everyone, and is turned on only for users outside GDPR regions. It collects anonymous usage events and basic device attributes (app version, OS version, device model, language). It does not collect your photos, your email, your precise location, or any advertising identifier — advertising-ID collection is switched off and the related permissions are removed.
- Firebase Crashlytics. Active for all users. When the app crashes, it sends a crash report so we can fix the bug. This includes the crash stack trace, device model, OS/app version, and a couple of custom keys indicating your selected languages. It does not collect advertising identifiers.
- No advertising or cross-app tracking. The app does not include any advertising SDK, and we have removed the permissions and signals that would allow advertising identifiers to be collected. You will not see an App Tracking Transparency prompt, because we do not track you.
- Your choice: at any time, go to Settings → Data & Privacy → "Clear ad/analytics data" to reset the anonymous identifier linked to your device and switch off analytics collection.
5. How we share information, and the SDKs we use
We share data only with providers that help us operate the Service, and only as described below. We do not sell your data.
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Alibaba Cloud — international platform (DashScope / Qianwen) | AI image recognition | Your photo (or a link to it) and your selected languages, for recognition only | Outside mainland China |
| Alibaba Cloud — international platform (image segmentation) | Cutting out the object in your photo (only when this mode is used) | Your photo (or a link to it) | Outside mainland China |
| Microsoft Azure (Text-to-Speech) | Pronouncing the recognized words | Only the recognized word or phrase (text), not your photo | United States |
| Cloudflare R2 | Storing your photos and generated cards | The image files, in private storage | EU (GDPR users) or US (default) |
| Cloudflare | Network security and delivery (CDN/WAF) | Traffic as needed to deliver the Service | Global |
| RevenueCat | Managing subscriptions and purchases | An internal user identifier (not your email) and purchase/subscription status | United States |
| Resend | Sending transactional emails | Your email address and a verification link | United States |
| Apple Sign-In / Google Sign-In | Signing you in | Only the data the provider returns to us | United States / Global |
| Firebase (Analytics & Crashlytics) | Usage analytics and crash reports | As described in Section 4 | United States |
We have configured our AI and text-to-speech providers to opt out of using your content for model training and to disable request/response logging wherever the provider offers that option.
6. International data transfers and where your data is stored
Because we use specialized AI and infrastructure providers in different countries, your data may be processed outside the country where you live:
- Your photos are processed for AI recognition by Alibaba Cloud's international platform, which is operated by an Alibaba Cloud entity outside mainland China, and then stored in Cloudflare R2 (in the EU if you are in a GDPR region, otherwise in the United States).
- Recognized words/text may be sent to Microsoft Azure (US) for pronunciation.
- Your email is sent to Resend (US) for transactional emails.
- An internal user identifier and purchase data are sent to RevenueCat (US).
- Your account, task, credit, and subscription records are stored on our infrastructure hosted in the United States.
We do not offer the Service to users in mainland China, and your personal data is not processed or stored in mainland China.
For users in the EU/UK/EEA, transfers of personal data outside those regions (for example, to the United States) take place under appropriate safeguards (such as standard contractual clauses) and, where required, on the basis of your consent. You can ask for a copy of the safeguards we rely on using the contact details in Section 12.
7. How long we keep your data
- Photos and recognition results: the original photo and the cut-out image are deleted as soon as a task finishes (success or failure), and the recognized text (words, translations) is cleared shortly after — typically within a few minutes. As a safety net, any remaining objects are removed by our storage lifecycle within about one day.
- Account data: kept while your account is active, and deleted within 30 days after you delete your account (see Section 8).
- Anonymized records: we may keep aggregated or anonymized records (for example, anonymized credit/accounting logs) for as long as needed for accounting or as required by law. These can no longer be linked back to you.
- Analytics and crash data: governed by Firebase's retention, and reset when you use "Clear ad/analytics data".
8. Your rights and choices
Depending on where you live, you may have the right to:
- Access and export your data — use Settings → Data & Privacy → "Export my data" to download a copy.
- Correct inaccurate information.
- Delete your data and your account — use Settings → Data & Privacy → "Delete my account". Your account is deactivated immediately and permanently deleted within 30 days, including your photos stored in the cloud. (If you change your mind during the 30-day window, contact us — see Section 12 — and we will try to help.)
- Withdraw consent for analytics — use Settings → Data & Privacy → "Clear ad/analytics data". Withdrawing consent will not affect processing that is based on another legal ground, such as providing the Service you requested.
- Object to or restrict certain processing, and exercise data portability.
To exercise any of these rights, use the in-app options above or email us at the address in Section 12. We will respond within the time required by your local law (usually within 30 days; in some cases we may need a short, explained extension).
A note on automated decisions: we use AI to recognize objects in your photos, but we do not use it to profile you or to make decisions that legally or significantly affect you.
9. Children's privacy
CatchLingo is not directed to children under 13 (or the age of digital consent in your country, which may be higher, for example 16 in parts of Europe), and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.
10. Security
We protect your data with measures including TLS/HTTPS encryption in transit, hashed passwords, private cloud storage accessed only through short-lived signed links, removal of photo metadata (EXIF) on your device before upload, least-privilege access for our staff and service accounts, and avoiding third-party analytics/monitoring trackers on our servers. Your sign-in credentials are stored locally on your device. No method of transmission or storage is completely secure, but we work to protect your data, and we will notify you and the relevant authorities as required by law if a data breach occurs.
11. Changes to this policy
We may update this Privacy Policy. When we make material changes, we will show you a notice in the app and ask you to agree again where appropriate. The "last updated" date and version at the top always reflect the current version. Continuing to use the Service after a change means you accept the updated policy, to the extent permitted by law.
12. Contact us
If you have questions about this Privacy Policy or want to exercise your rights, contact our data-protection contact at:
Email: yanfenhe01@gmail.com
We aim to reply within 30 days.
This is a human-readable summary and does not replace any rights granted to you by applicable law. If anything here conflicts with mandatory local law, the local law applies.