Privacy Policy
How Stanislav Tolmachov handles personal data in the Synaply alpha. Written to describe what the service actually does, not what a template says it might.
Edition: 2026-08-09 · In effect from: August 9, 2026
1. Who is responsible
Stanislav Tolmachov, a private individual based in Norway, is the data controller for personal data processed through synaply.me. The alpha is operated personally, without a registered company; if a company takes over later, an updated edition of this policy will say so. Write to support@tolmachov.dev for anything in this document, including requests to exercise your rights.
No school, municipality or employer decides what Synaply collects or why. Everyone in the alpha — teachers included — takes part personally and voluntarily, and this policy is addressed to each of them directly.
2. What we collect
- Account
- Name, email address, interface language and time zone. The time zone is used to decide when your day starts, so daily limits and streaks match your evening, not UTC.
- Learning data
- Words you save, your own translations and notes, review history and scheduling state, sentences you write in practice and the AI feedback on them, and daily activity counters.
- Technical data
- Sessions (browser user agent, IP address, when they started and expire) and server logs. In logs the IP address is replaced by a keyed one-way pseudonym: we can tell that requests came from the same source, but the address itself is not stored there.
- Usage events
- Records of how the app is used: which screens are opened, when a lesson or a practice round starts and ends, whether an answer was submitted, and measurements of page loading speed and responsiveness. Each record holds an event name from a fixed list, the time it happened, a browser-tab session identifier, the device cookie and — when you are signed in — your account and language-pair identifiers. They never contain free text: an event carries only a small set of predefined keys with short predefined values, so the words you type, your translations and your answers are never part of them.
- Class context
- Which class you belong to, which assignments you were given, your progress on them and any feedback a teacher writes about your work.
- Billing
- Nothing. The alpha is free, no payment provider is connected, and we hold no card details, no invoices and no payment history.
We do not use advertising trackers, we do not profile you for marketing, and we do not sell data to anyone.
3. Why we process it, and on what legal basis
- To run the service — contract, GDPR Art. 6(1)(b)
- Keeping your account, storing your vocabulary, scheduling reviews, generating and checking exercises, and showing your teacher the progress on work they assigned.
- To keep it safe — legitimate interest, Art. 6(1)(f)
- Sessions, rate limits, lockout after repeated failed sign-ins and server logs. The interest is keeping accounts from being taken over and the service from being abused; we weigh it against your privacy by pseudonymising addresses in logs.
- To keep it working — legitimate interest, Art. 6(1)(f)
- Usage events and speed measurements, so we can see where the app is slow or where people get stuck and fix it. The interest is a service that works; we weigh it against your privacy by recording no free text at all, keeping the events for a limited time and never using them to decide anything about you individually.
- To meet legal duties — Art. 6(1)(c)
- Responding to obligations the law places on us, if and when they arise.
Your data is used exclusively to provide the service and for nothing else: no marketing, no profiling, no training of AI models, no sale or sharing beyond the processors listed below. Usage events are part of running the service, not an exception to this: they are counted in aggregate to find broken and slow places in the app, they never build a profile about you, and they never change what you are shown. We do not rely on consent as a legal basis, so withdrawing consent is not the way to stop the processing — closing your account is. Accepting these documents is a record that you were informed, not a consent that carries the processing.
4. Artificial intelligence
Word explanations, generated sentences, feedback on your translations and grammar reports are produced by a large language model operated by Anthropic PBC. What we send is the material the feature needs — the word or sentence in question and the language pair — and we do not send your name, email address or any other identifier with it. Under our agreement with Anthropic, this data is not used to train their models. Avoid putting personal details into the sentences you practise on; they are processed as text.
Model output is generated text. It can be wrong, and it is not language teaching by a qualified human. No decision with a legal or similarly significant effect on you is made automatically.
5. Who else sees the data
We use these processors to run the service: Hetzner Online GmbH (DE / FI), Anthropic PBC (US), {{MAIL_PROVIDER}} ({{MAIL_PROVIDER_REGION}}). They act on our instructions and may not use the data for their own purposes.
Hosting and storage are inside the EEA. Sending text to the AI provider means a transfer to the United States; it relies on the European Commission's standard contractual clauses, reinforced by the fact that what is transferred is learning text without identifiers. Ask us at the address above for a copy of the safeguards.
If you are in a class, your teacher sees your name, your progress on assignments and the error analyses produced for your work. They do not see your personal vocabulary or what you study outside the class material.
6. How long we keep it
The alpha comes first: as the Terms of Service explain, all alpha data — including everything listed below — may be deleted or reset at any time while the test runs, and when the alpha ends. Export your data from settings if you want to keep it. Within those limits, the ordinary retention periods are:
- Account and learning data
- For as long as the account exists, and then as described under your rights below.
- Sessions
- Until they expire or you sign out; at most 30 days from sign-in.
- Read notifications
- 90 days.
- Pending invitations
- 30 days, after which they expire and are closed.
- Background job records
- 7 days after the job is published.
- Usage events
- 13 months from the event, after which they are deleted in whole monthly batches. They are included in your data export, and they are erased with your account — including events recorded on your device before you created it.
- Server logs
- No longer than the alpha itself; they are cleared together with alpha data resets.
When you leave a class, you disappear from that class's reports entirely — the teacher no longer sees your name, your address or your numbers. Your own progress stays with you.
7. Your rights
You can exercise the first two yourself, in your account settings, without asking us and without waiting.
- Access and portability
- Download everything we hold about you as a single machine-readable file. It contains your data only — not your classmates' addresses or other students' answers.
- Erasure
- Request deletion of your account and everything in it. The request takes effect after 30 days and can be cancelled during that window; you get an email confirming it, because a request may have been filed from a session you left open. Class material you authored as a teacher may survive, stripped of your name and address.
- Rectification
- Correct your name, email address, language and time zone in settings at any time.
- Restriction and objection
- Write to support@tolmachov.dev. We answer within one month, as GDPR requires, and tell you if we need longer and why.
You can also complain to a data protection authority — in Norway that is Datatilsynet (https://www.datatilsynet.no) — or to the authority where you live. You do not have to contact us first, though it is usually faster.
8. Adults only
The alpha is open to adults only: creating an account requires confirming you are at least 18, and invitations may not be passed to minors. We do not knowingly process children's data in the alpha.
If you believe an account belongs to a person under 18, write to support@tolmachov.dev: we will look into it, close the account and delete its data.
9. Cookies
Synaply sets no advertising or analytics cookies, so there is no cookie banner to click away: under the Norwegian ekomloven, storage that is strictly necessary for a service you asked for needs no consent, and every cookie below is exactly that:
- access_token, refresh_token
- Keep you signed in. They are httpOnly, so page scripts cannot read them, and they never leave the server-to-server path to our API.
- synaply_device_id
- A random identifier used to apply rate limits per device, protecting the service from abuse, and to group usage events from the same browser before you sign in. It carries no name, address or other detail about you, and it is used for nothing beyond those two purposes.
- synaply_tz
- Your time zone, so your day starts at your midnight.
- NEXT_LOCALE
- Your interface language.
- school_intent, synaply_verify_banner
- Short-lived markers so the sign-up flow and the email reminder behave sensibly.
10. Security
Traffic runs over TLS. Passwords are stored as bcrypt hashes and never in readable form. Sessions can be revoked from your settings, and changing your password signs out every device. Access to production data is limited to the operator.
If a breach puts your rights at risk we will notify the supervisory authority within 72 hours and tell you directly when the law requires it.
11. Changes
When this policy changes we publish a new edition with a new effective date and ask you to read it the next time you sign in. Earlier editions you accepted stay on record — that is part of your data, and it is included in your export.