This Privacy Policy explains how the provider of the CatchLingo mobile application ("CatchLingo", "we", "us") collects, uses, stores, and protects your information when you use the CatchLingo app (the "Service"), and the choices you have.
We designed CatchLingo to be privacy-friendly: we collect only what is needed to recognize objects in the photos you take in the app or select from your photo library and help you learn new words, and we delete your photos as soon as each recognition is complete. We never sell your data, and we never use your photos to train AI models.
1. Information we collect
1.1 Information you provide
- Account information. When you sign up with email, we collect your email address. When you use "Sign in with Google" or "Sign in with Apple", we receive only the data you allow the provider to share with us — this always includes your email address, and may also include your profile nickname and profile photo.
- Photos. When you use the app to recognize an object, the photo you took in the app or selected from your photo library is sent to our servers and kept there only long enough to run recognition, and it is deleted immediately afterwards. We do not keep or retain your photos on our servers.
- Please do not upload sensitive information. Please do not use the app to upload sensitive information about yourself, such as health data, genetic data, biometric data, data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or data concerning sexual orientation.
1.2 Information generated when you use the Service
- A minimal record of your activity. We keep only what is needed to run the Service and your account: that a recognition task took place (such as its status and time), and the recognition usage credits you used. What you recognized is kept only long enough to deliver your result, and is not kept afterwards.
- Your time zone and a broad region indication (for example, whether you are in a GDPR region), which we use to apply the correct privacy settings and meet local legal requirements. All of your data is stored in the United States regardless of your region.
1.3 What we collect automatically — and what we don't
- To apply the right privacy controls, we determine your broad region once when the app starts. We do not store your IP address.
- What we do not collect: we do not collect precise location, phone number, address book/contacts, date of birth, or gender, and we do not collect any advertising identifier (IDFA, IDFV, or the Android advertising ID).
1.4 Information from third parties
- Purchase information from the Apple App Store and Google Play, limited to what is needed to confirm and manage your subscription.
- Usage analytics and crash data, as described in Section 3.
2. How we use your information
We use your information to:
- Provide the Service: recognize objects in the photos you take in the app or select from your photo library, generate the word along with related information (such as associated words and example usage) and pronunciation, and save the Lingo stickers you create (your Lingo stickers are stored on your device, not on our servers).
- Manage your account: sign you in, verify your email, reset your password, and apply your in-app recognition usage credits and your subscription.
- Communicate with you: send verification, security, and account-related emails.
- Keep the Service stable and improve it: diagnose and fix bugs and crashes (see Section 3), and — where you have agreed — understand how features are used.
- Billing and fair use. We apply your credits, keep the records needed for billing and accounting, and detect and prevent abuse, fraud, or other fair-use violations. These records reflect only your usage (such as the recognition usage credits you used) — not what you recognized.
- Meet our legal obligations.
What we do not do: we do not sell or rent your personal data, and we do not use your photos to train AI models.
3. Analytics, crash reporting, and advertising
- Usage data. We collect data about how the app is used, to understand and improve it. This may include events and basic device attributes (such as app version, OS version, device model, and language). It does not collect your photos, your email, or your precise location. We follow GDPR: in regions covered by GDPR (EU/EEA/UK/CH), we ask for your explicit consent before collecting any usage data that is linked to you — until you agree, whatever we collect is anonymous and not linked to your account. In other regions, usage-data collection begins once you accept these terms and this policy. Wherever you are, you can change your choice or withdraw your agreement at any time in Settings.
- Crash reporting. When something goes wrong, we receive a crash report so we can fix it — this is always on, because it is what keeps the app stable for everyone. A crash report contains only the technical details needed to diagnose the problem (such as the error, device model, and system/app version). We follow GDPR: in regions covered by GDPR (EU/EEA/UK/CH), we ask for your explicit consent before linking a crash report to your account — until you agree, whatever we collect is anonymous and not linked to your account. In other regions, linking begins once you accept these terms and this policy. Wherever you are, you can change your choice or withdraw your agreement at any time in Settings. Crash reports never include your photos or your email.
- Your choice: at any time, go to Settings → Data & Privacy → "Clear ad/analytics data" to turn off usage-data collection.
4. Third-party providers we rely on
To recognize objects in the photos you take in the app or select from your photo library, we send that photo to our AI recognition provider (Alibaba Qwen). It processes your photo solely to produce the recognition result — it does not save your photo or use it to train its models. To understand and improve the app, we use an analytics provider (Google Firebase) as our data processor, handling only the data described in Section 3 on our behalf. These providers act on our behalf to provide the Service; we do not share your data with them for any other reason, and all of this processing runs in United States data centers.
We do not sell your personal information.
When we may disclose your data. We may disclose your information when we believe we are legally required to do so (for example, by law, legal process, or a government request); to protect our rights, property, or safety, or to investigate or prevent fraud, abuse, or violations of our Terms; or in connection with a merger, acquisition, sale of assets, or similar business transaction, in which case we will require the recipient to handle your data consistently with this policy. These are standard protections, and we still do not sell your personal information.
5. Where your data is stored
All processing and storage of your data takes place in the United States. Our servers and database, and the AI services that recognize objects in your photos and generate pronunciation, all run in United States data centers.
If you use CatchLingo from outside the United States — for example, from the EU/UK/EEA — your information is transferred to and processed in the United States as described in this policy. By registering an account, signing in, or otherwise using the Service, you authorize this transfer and processing. Where required by law, such transfers also rely on appropriate safeguards, such as standard contractual clauses. You can withdraw this authorization at any time by deleting your account (see Section 7), and you can ask for a copy of the safeguards we rely on using the contact details in Section 11.
6. How long we keep your data
- Photos: deleted immediately after recognition is complete. We do not keep or retain your photos; any leftover is removed very shortly afterwards as a safety net.
- What you recognized: kept only long enough to deliver your result to you, then wiped within a very short time of the task completing.
- Account data (your email address, profile nickname, and profile photo): kept while your account is active, and deleted within 30 days after you delete your account (see Section 7).
- Billing and usage records: retained for as long as needed for billing, accounting, and to prevent abuse, as permitted or required by law. They reflect only your usage (such as the recognition usage credits you used) — not what you recognized.
- Crash and usage data: kept only as long as needed to improve stability — crash reports are automatically deleted within 90 days, and usage data within 2 months.
- De-identified statistics: aggregate statistics that cannot be linked to any person may be kept without a time limit, because they no longer identify anyone.
7. Your rights and choices
You have rights over your data. Regardless of where you live, you can:
- Access and export your data — use Settings → Data & Privacy → "Export my data" to download a copy.
- Correct inaccurate information.
- Delete your data and your account — use Settings → Data & Privacy → "Delete my account". Your account is deactivated immediately and permanently deleted within 30 days, along with any data still associated with your account. (If you change your mind during the 30-day window, contact us — see Section 11 — and we will try to help.) Deleting your account is also how you withdraw your authorization for U.S.-based processing (see Section 5).
- Turn off usage-data collection — use Settings → Data & Privacy → "Clear ad/analytics data". This also withdraws any agreement you have given to linking data with your account. Withdrawing consent will not affect processing based on another legal ground, such as providing the Service you requested.
- Object to or restrict certain processing, and exercise data portability.
European Union / UK / EEA (GDPR). Our legal bases for processing your personal data are: performing the contract to provide you the Service; your consent — for example, when you grant a device permission such as camera access, or when you agree to account-linked usage data; our legitimate interests in operating, securing, and improving the Service (such as diagnosing and fixing crashes); and compliance with our legal obligations. You can withdraw your consent at any time as described above, and you also have the right to lodge a complaint with your local data-protection authority.
California residents (CCPA). We do not "sell" or "share" your personal information as those terms are defined under California law. You have the right to request that we tell you what personal information we collect, to ask us to delete it, and to opt out of any "sale" or "sharing" — and because we do not sell or share your personal information, there is nothing you need to opt out of. To exercise these rights, use the in-app options above or email us (Section 11).
8. Children's privacy
CatchLingo is not designated for children and is not addressed to anyone under the age of 13 (or a higher age where local law requires). We do not knowingly collect personally identifiable information from children under 13. If we discover that a child under 13 has provided us with personal information, we immediately delete it from our servers. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us (Section 11) so that we can take the necessary action.
9. Security
We protect your data with industry-standard safeguards, including TLS/HTTPS encryption in transit, hashed passwords, private cloud storage accessed only through short-lived signed links, automatic removal of photo metadata (EXIF) on your device before upload, and strictly limited access for our staff and systems. Your sign-in credentials are stored locally on your device. We regularly review and improve these practices to keep your data safe.
10. Changes to this policy
We may update this Privacy Policy. When we make material changes, we will show you a notice in the app and ask you to agree again where appropriate. The "last updated" date and version at the top always reflect the current version. Continuing to use the Service after a change means you accept the updated policy, to the extent permitted by law.
11. Contact us
If you have questions about this Privacy Policy or want to exercise your rights, contact our data-protection contact at:
Email: support@hesheme.xyz
We aim to reply within 90 days.
This is a human-readable summary and does not replace any rights granted to you by applicable law. If anything here conflicts with mandatory local law, the local law applies.