Privacy Policy - Phraseman by Knowly
Privacy Policy - Phraseman by Knowly
Last updated: July 18, 2026
This Privacy Policy explains how Maksym Babiev, an individual trader trading as "Knowly" ("Knowly", "we", "us", or "our"), collects, uses, discloses, stores, and deletes information when you use Phraseman (the "App"), related cloud features, and Knowly website pages for Phraseman. The data controller is Maksym Babiev, Ardagh, Ballymackerry, V42 P599, Ireland. Privacy contact: support.phraseman@gmail.com.
This Policy is intended to describe the App's current data practices. If a store listing, in-app notice, or consent screen gives more specific information for a particular platform or feature, that notice also applies.
1. Scope, controller, and acceptance
This Policy applies to the Phraseman mobile app, related online services, support channels, public legal pages, and cloud features operated by Knowly. The controller responsible for your personal data is Maksym Babiev, trading as Knowly, Ardagh, Ballymackerry, V42 P599, Ireland, support.phraseman@gmail.com.
By using the App, you acknowledge that your information will be processed as described in this Policy and in any applicable store or consent disclosures. If you do not want your information processed as described, do not use the App or the affected feature.
2. Age and minors
Phraseman is intended for users aged 16 and over. During onboarding we ask you to confirm that you are 16 or over. We record only that confirmation as age-consent metadata; we do not ask for or store your date or year of birth. We do not knowingly process the personal data of children under 13.
If you are a parent or guardian and believe a child has provided personal data through the App, email support.phraseman@gmail.com with subject "Parent Privacy Request". We will review the request and delete or de-identify relevant account data unless we must retain limited records for legal, safety, fraud-prevention, moderation, transaction, or security reasons.
3. Data stored on your device
The App stores learning progress, XP, streaks, achievements, flashcards, daily tasks, lesson state, settings, notification settings, cached activity/error queues, cached assets, and similar app data on your device using AsyncStorage, SecureStore where available, and related platform storage. Devices that used earlier versions may still hold legacy local state created by retired Quiz and Arena features. That state does not mean those features remain available and is removed through the ordinary local-data or account-deletion controls described below.
The App also creates or uses a Phraseman stable app identifier. It may be stored in SecureStore where available and mirrored in local storage so progress, cloud sync, purchases, referrals, moderation, fraud prevention, account recovery, and account deletion can work across app sessions. Depending on iOS Keychain, Android backup/restore, device restore, or device settings, this identifier or a backup of it may survive reinstall or device restore until you use the in-app deletion flow, clear app data, or reset relevant device storage.
4. Account, authentication, and cloud sync
The App uses Firebase Authentication. By default, Firebase may create an anonymous app session so cloud features can operate without a separate Knowly username/password.
You may optionally sign in with Google or Apple. If you do, Firebase and Knowly may process provider identifiers, Firebase Auth UID, email address if shared, display name if shared, provider type, platform, sign-in timestamps, account-linking records, and related authentication metadata. We use this to restore progress, link devices, prevent account drift, secure the service, and prevent abuse.
Cloud sync may store progress and app state in Firebase Firestore, including XP, lessons, streaks, achievements, certificates, custom flashcards, daily and weekly stats, foreground usage totals, premium status metadata, RevenueCat purchase metadata, Shards balances and ledgers, settings, language/target selections, referral state, social feature state, and other data needed to operate requested features.
5. Public, social, and historical competitive data
Some data is visible to other users when you use current public or social features. This may include nickname, avatar, frame, aura, profile card settings, XP, streak, points, rank, league or club tier, premium or club markers, friend activity, gifts, activity likes, community pack author information, seller notifications, and similar profile fields. Visibility depends on the feature: some fields may be public to app users, some visible to league or club participants, some visible to friends, some visible to community pack buyers or sellers, and some visible only to moderators/admins.
Historical records created by the retired Quiz and Arena features, such as old results or participation records, may be retained only as reasonably necessary for security, fraud or abuse prevention, dispute handling, legal compliance, backup expiry, or deletion integrity. Account deletion is designed to delete or de-identify those historical records controlled by Knowly, subject only to the limited retention grounds described in this Policy. They are not presented as currently available gameplay features.
6. User content, community packs, reports, and moderation
If you create Community Packs, submit flashcard text, translations, reports, profile names, survey answers, ratings/votes, or other user-provided content, we process the content you provide and related metadata. This may include titles, descriptions, card text and translations, normalized text used for moderation, report reasons, reporter/reported user IDs and names, author IDs, buyer/seller IDs, moderation decisions, timestamps, platform, app version, audit fields, ranking scores, vote counts, report counts, and related safety signals.
Published Community Packs and approved catalog metadata may be visible in the App. Pack cards may be visible to the author, moderators, and users who access or purchase the pack with Shards.
We may review, block, remove, hide, de-identify, retain, or disclose user content and reports when needed to operate moderation, enforce the Terms, protect users, investigate abuse, handle disputes, prevent fraud, comply with law, respond to copyright or rights complaints, or preserve service integrity.
7. Friends, gifts, referrals, invite codes, and rewards
Friend, gift, referral, invite, and reward features may process friend codes, friend relationships, friend requests, gifts sent/received, gift history, activity feed entries, activity likes, invite links, referral codes, referral owners, referral attributions, referrer/referee stable IDs, reward status, Shards ledger entries, daily or monthly limits, cooldowns, abuse checks, Google Play Install Referrer data on Android, and deep-link or manual-code source information.
We use this information to operate the feature, attribute rewards, prevent self-referrals and abuse, enforce caps and cooldowns, correct errors, and protect the App.
8. App messages, reactions, polls, and surveys
The App may show in-app messages, polls, product questions, cancellation surveys, VIP surveys, or similar prompts. If you respond, react, vote, dismiss, claim a reward, or otherwise interact, we may process response content, selected options, reaction type, vote choice, message IDs, survey IDs, timestamps, eligibility state, reward state, user or stable app IDs, and related metadata.
We use this information to operate messages and polls, prevent duplicate rewards or abuse, understand product feedback, improve the App, maintain audit records, and apply entitlements or rewards where applicable.
9. Purchases, subscriptions, RevenueCat, and Shards
Premium subscriptions, free trials, Shards purchases, and other in-app purchases are billed through the Apple App Store or Google Play. Knowly does not receive your payment card or bank details.
We use RevenueCat to verify subscriptions, entitlements, receipts, product IDs, transaction IDs, store, environment, purchase and expiry timestamps, cancellation or billing status, refund and chargeback signals, and related webhook events. RevenueCat may receive a Phraseman app user ID, Firebase/Auth ID, canonical stable ID, and attributes such as `phraseman_uid` so subscription and purchase state can be restored and matched to your account.
Shards are a virtual in-app balance. We may store Shards balances, purchases, grants, spending, refunds/reversals, pack purchases, seller credits, platform fees, reward grants, and audit logs in Firebase.
10. Analytics, diagnostics, device identifiers, and app health
We use Firebase Analytics, Firebase Crashlytics, PostHog where enabled, and our own limited app activity/error logs to operate, secure, debug, measure, and improve the App. These records may include app events, screens/features used, purchase/paywall/referral events, AI feature events, onboarding choices, notification interactions, message or survey interactions, error context, crash logs, stack traces, app version, build number, platform, OS version, device name or model, app state, user name, Firebase/Auth IDs, stable app ID, app instance identifiers, PostHog distinct IDs where enabled, and other app metadata.
These records are not described as anonymous. Some diagnostics and analytics may be linked to your app account, Firebase/Auth ID, stable app ID, app instance, or device identifiers.
We ask for your consent before collecting non-essential product analytics (such as PostHog analytics and non-essential Firebase Analytics events). If you decline, or later withdraw consent in the App, we do not collect that non-essential analytics and do not link it to your account or identifiers. We still process a limited amount of strictly necessary information, such as crash and error diagnostics, security, and fraud-prevention signals, which we rely on to keep the App working and secure. You can change your analytics choice at any time in the App settings.
The App does not use the Google Play Services Advertising ID and does not request it. We do not sell personal information, and we do not use any advertising identifier for third-party advertising or cross-context behavioral advertising unless this Policy, store disclosures, and any required consent are updated first.
11. AI features and OpenAI processing
Some Phraseman features use generative AI providers such as OpenAI to generate dialogue replies, phrase explanations, mistake explanations, weekly reviews, stats insights, and similar learning feedback.
When you use AI features, we may send the AI provider the text you enter, recent conversation history, selected scenario or mode, language level, learning target, phrase text, phrase meaning, your exercise answer and target answer, computed learning analytics such as weak words or phrases, mistake categories, progress, XP, streaks, study minutes, and related context needed to generate the requested response.
We may also keep limited AI-related logs for quotas, billing, cost control, abuse prevention, debugging, safety, and service reliability. These logs may include user IDs, feature type, model name, token counts, timestamps, request status, premium status, language, lesson or phrase identifiers, and similar metadata.
Do not submit sensitive personal data, confidential information, payment details, medical, legal, financial, immigration, employment, emergency, or safety-critical information to AI features. AI output may be inaccurate, incomplete, or unsuitable for your context.
12. Notifications and push tokens
If you enable notifications, the App may request notification permission and store notification settings, local scheduled notification IDs, Expo push tokens, native push tokens where applicable, device/platform metadata, user IDs, and related delivery metadata.
Notifications may include local reminders, phrase of the day, streak warnings, weekly/monthly recaps, XP, lesson counts, streak counts, phrase text, league rank changes, re-engagement or winback reminders, account/service notices, or similar app context. Remote notifications may be delivered through Expo's push notification service and the applicable platform push service. You can disable notifications in the App or device settings, but some service messages may still appear inside the App.
13. Text-to-speech, speech recognition, and voice features
The App uses your device's built-in text-to-speech engine through expo-speech to pronounce English phrases and example sentences. Based on the current implementation, pronunciation is generated on device and Knowly does not receive the generated text-to-speech audio.
Where speech recognition, pronunciation practice, or voice dialogue features are enabled, the App may request microphone and speech recognition permissions. Depending on the feature, speech may be processed on device or by platform speech services, and a transcript or recognized text may be used by the App. If you use an AI voice dialogue feature, the transcript or recognized text may be sent to the AI provider as described in the AI features section. Do not say sensitive personal, confidential, payment, medical, legal, financial, or emergency information in voice features.
14. Website, cookies, leads, and web purchases
The Knowly website uses local storage and session storage for essential preferences and flows, including theme choice, quiz progress, first-touch UTM attribution, lead email, cached prices, and your Meta Pixel consent choice. It also sends limited website events (page category, visit/view, store clicks, and quiz/checkout funnel events) to our Cloud Function, which stores aggregate counters. To protect that endpoint from abuse, we create a short-lived hash of the visitor IP address for rate limiting; hosting providers may also process IP addresses and request logs.
If Meta Pixel is enabled, we load it only after opt-in consent in the EU, EEA, UK, and Switzerland. You can accept, reject, or later change that choice using the "Cookie settings" link in the website footer.
If you request a quiz plan by email, we process your email address, quiz answers, UTM attribution, page, consent choice, and delivery/unsubscribe status to send the requested plan. We send follow-up product emails only when you separately opt in; you can withdraw that consent through the unsubscribe link in any such email or by contacting us.
If you use the website contact form, email support, or legal request channels, we may process your name, email address, message, topic, page URL, user-agent, forwarded IP header, support metadata, account identifiers you provide, and our replies.
For website purchases, we process your email, selected plan, gift choice, quiz/UTM attribution, order identifiers, payment status, amount, currency, activation code, and payment-provider transaction references. Card and PayPal payment credentials are collected by Stripe or PayPal, not by Knowly.
If you buy a gift certificate and choose to enter a recipient name or a sender name, we process those names solely to render the certificate email. They are stored together with the order and are not used for marketing or shared with third parties beyond our email delivery provider.
15. Email Communications and Marketing
If you provide an email address, we may send service and account emails about security, purchases, account operation, legal notices, or important service information. We send website product emails, including quiz-plan follow-ups, only where you have separately opted in. We use an email provider such as Resend. You can withdraw marketing consent at any time through the unsubscribe link in the email or by contacting support.phraseman@gmail.com; this does not affect service or account emails. We keep a suppression list so we can honour your choice.
16. Third-party services and processors
The App and related services use third-party providers, including:
- Google Firebase services such as Authentication, Firestore, Cloud Functions, Analytics, Crashlytics, App Check, and related Google Cloud infrastructure
- Google Play Services, Google Sign-In, Google Play Billing, Google Play Install Referrer, and Android platform services
- Apple Sign In, Apple App Store, Apple in-app purchase systems, and Apple platform services
- OpenAI or other AI model providers for AI dialogue, explanations, mistake feedback, reviews, insights, and related AI features
- PostHog for product analytics where enabled
- RevenueCat for subscription, purchase, entitlement, and receipt verification
- Expo / EAS / Expo Updates and Expo push notification services for app infrastructure and notification delivery
- Resend or another email provider for contact, support, and consented website email delivery
- Stripe and PayPal for website checkout and payment processing
- Meta, only where website Pixel consent is granted
- Telegram, to send payment-order notifications to authorised administrators
- App stores and payment processors for purchase, subscription, refund, tax, and compliance records
These providers process data under their own terms, privacy policies, and security programs. Data may be processed in countries other than your country of residence, subject to applicable safeguards.
17. How we use and disclose information
We use information to provide, maintain, secure, debug, personalize, and improve the App; authenticate users; sync progress; operate purchases and entitlements; manage Shards and rewards; run leaderboards, leagues, clubs, friends, gifts, referrals, community packs, surveys, notifications, moderation, AI-generated feedback, AI quotas, and AI safety controls; retain, secure, delete, or de-identify historical records from retired features; prevent fraud and abuse; respond to support and legal requests; comply with law; enforce the Terms; and protect Knowly, users, and third parties.
We disclose information to service providers and processors that help operate the App; app stores and payment processors for purchases, refunds, fraud, and compliance; other users where required by current public, social, or community features; moderators/admins for safety and support; legal, regulatory, or law-enforcement authorities where required or permitted by law; and relevant parties in connection with a merger, acquisition, financing, reorganization, asset sale, or similar transaction.
We do not sell personal information. We do not knowingly share personal information for cross-context behavioral advertising unless this Policy and applicable store disclosures are updated to describe that practice.
18. Legal bases and purposes
Depending on your location, we process information on these bases:
- Contract/performance of the App or requested service: account operation, progress sync, purchases, subscriptions, Shards, leaderboards, social features, support, AI features you request, the requested website quiz plan, and requested features
- Legitimate interests: security, fraud prevention, abuse prevention, debugging, aggregate website measurement, service reliability, moderation, management of historical feature records, AI cost control, AI safety, product improvement, legal defense, and business operations
- Consent: website marketing emails, Meta Pixel where required, optional notifications, optional microphone/speech recognition permissions, optional Google/Apple sign-in where required, consent-based analytics where required, and child/parent consent where required
- Legal obligations: tax, accounting, consumer protection, store compliance, dispute handling, copyright and rights complaints, law-enforcement requests, regulatory compliance, and sanctions/export compliance
19. Retention
We retain information only as long as reasonably needed for the purposes described in this Policy, unless a longer period is required or permitted by law.
Typical retention criteria:
- Local app data remains on your device until you delete it, use account deletion, clear app data, uninstall, or reset relevant device storage; backup/keychain behavior may vary by platform
- Active cloud progress, profile, entitlement, and feature data is retained while your account or app instance is active
- Reports, moderation records, safety records, purchase records, entitlement records, referral records, reward records, surveys, AI quota/billing/safety logs, analytics/error records, and fraud-prevention records may be retained longer where needed for safety, disputes, legal compliance, chargebacks, refunds, accounting, moderation integrity, abuse prevention, cost control, or auditability
- Website leads, consent records, contact/support messages, and payment-order records are retained only as long as needed to deliver the requested service, honour consent or unsubscribe choices, respond, prevent abuse, and keep required business, security, or legal records
- Backups and logs may persist until overwritten or deleted under normal retention cycles
We do not promise automatic deletion after a fixed inactivity period unless such a deletion job is implemented and active.
20. Account and data deletion
You can request deletion from inside the App where available, from the public deletion instructions at https://knowlyapps.com/legal/data-deletion/, or by emailing support.phraseman@gmail.com with subject "Delete My Data".
The in-app deletion flow starts an authenticated backend deletion request. The App may sign you out and clear local app data immediately while server-side deletion continues in the background. The backend deletion function is designed to delete or de-identify active account data controlled by Knowly, including the Firebase Auth user, users/{stable_id} data and subcollections, leaderboard/profile records, auth links, name/friend/referral indexes, Community Pack, report, reaction, poll-vote, survey, analytics, and error records linked to the stable ID, and local app data on the device.
If you cannot access the App, if the in-app deletion request does not complete, or if you want follow-up, contact support.phraseman@gmail.com. We may need to verify your request before acting on it.
Some records may remain when retention is required or permitted for legal compliance, payment/tax/accounting, fraud prevention, security, dispute handling, chargebacks/refunds, moderation integrity, backups, or data stored by app stores and third-party processors. Deleting the account does not automatically cancel an active App Store or Google Play subscription; you must cancel it in the store subscription settings.
21. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to processing, port your data, withdraw consent, opt out of certain processing, and complain to a data protection authority. You may lodge a complaint with the Irish Data Protection Commission or your local supervisory authority.
To exercise rights, email support.phraseman@gmail.com with subject "Privacy Request". We may need to verify your identity, request additional information, refuse or limit requests where permitted by law, and retain limited records of requests and responses.
22. US state privacy rights
California and other US state residents may request information about categories of personal information collected, sources, purposes, disclosures, and deletion/correction where applicable. We do not sell personal information. We do not knowingly share personal information for cross-context behavioral advertising unless this Policy and applicable store disclosures are updated to say so.
Categories of personal information we may collect include identifiers, app/account identifiers, commercial information, internet or electronic activity, approximate device/app information, inferences from app activity, learning progress and AI personalization signals, user-generated content, support communications, transcripts or recognized text if you use voice features, and other information you provide or generate through App features.
23. International transfers
Knowly, service providers, and app platforms may process information in countries other than your country of residence. Where required, we rely on appropriate safeguards, contractual commitments, platform terms, service-provider security measures, and other lawful transfer mechanisms.
24. Security
We use technical and organizational measures such as Firebase security rules, authenticated Cloud Functions, App Check where enabled, TLS/HTTPS, access controls, logging, abuse monitoring, and operational controls. No system is perfectly secure, and we cannot guarantee absolute security.
25. Changes
We may update this Policy from time to time. Material changes will be reflected in the "Last updated" date and may include in-app notice, website updates, consent prompts, or store disclosure updates where practicable or required. Continued use of the App after changes means you acknowledge the updated Policy where permitted by law.
26. Contact
Knowly - Phraseman
Email: support.phraseman@gmail.com
Use this contact for privacy requests, parental requests, account deletion, support, legal notices, and questions about this Policy.