Privacy Policy - Phraseman by Knowly
Privacy Policy - Phraseman by Knowly
Last updated: September 1, 2026
This Privacy Policy explains how Maksym Babiev, an individual trader trading as "Knowly" ("Knowly", "we", "us", or "our"), collects, uses, discloses, stores, and deletes information when you use Phraseman (the "App"), related cloud features, and Knowly website pages for Phraseman. The data controller is Maksym Babiev, Ardagh, Ballymackerry, V42 P599, Ireland. Privacy contact: support.phraseman@gmail.com.
This Policy is intended to describe the App's current data practices. If a store listing, in-app notice, or consent screen gives more specific information for a particular platform or feature, that notice also applies.
MAX voice privacy summary
MAX voice calls stream microphone audio to the AI provider only while the call is active. Knowly does not record or retain the call audio. A transient text transcript is processed to create the post-call review and short learning notes; the full transcript is not retained by Knowly after finalization. The durable review and selected MAX learning notes remain linked to your account until you delete individual notes, clear all MAX memory in the App, or delete the account. Withdrawing MAX voice consent blocks new voice processing but does not silently delete existing learning notes; those remain under your separate memory controls.
1. Scope, controller, and acceptance
This Policy applies to the Phraseman mobile app, related online services, support channels, public legal pages, and cloud features operated by Knowly. The controller responsible for your personal data is Maksym Babiev, trading as Knowly, Ardagh, Ballymackerry, V42 P599, Ireland, support.phraseman@gmail.com.
By using the App, you acknowledge that your information will be processed as described in this Policy and in any applicable store or consent disclosures. If you do not want your information processed as described, do not use the App or the affected feature.
2. Age and minors
Phraseman is intended for users aged 16 and over. During onboarding we ask you to confirm that you are 16 or over. We record only that confirmation as age-consent metadata; we do not ask for or store your date or year of birth. We do not knowingly process the personal data of children under 13.
If you are a parent or guardian and believe a child has provided personal data through the App, email support.phraseman@gmail.com with subject "Parent Privacy Request". We will review the request and delete or de-identify relevant account data unless we must retain limited records for legal, safety, fraud-prevention, moderation, transaction, or security reasons.
3. Data stored on your device
The App stores learning progress, XP, streaks, achievements, flashcards, daily tasks, lesson state, settings, notification settings, cached activity/error queues, cached assets, and similar app data on your device using AsyncStorage, SecureStore where available, and related platform storage. Devices that used earlier versions may still hold legacy local state created by features that have since been retired or rebuilt (such as the old Quiz mode or earlier versions of competitive modes). That state does not mean those features remain available in that form and is removed through the ordinary local-data or account-deletion controls described below.
The App also creates or uses a Phraseman stable app identifier. It may be stored in SecureStore where available and mirrored in local storage so progress, cloud sync, purchases, referrals, moderation, fraud prevention, account recovery, and account deletion can work across app sessions. Depending on iOS Keychain, Android backup/restore, device restore, or device settings, this identifier or a backup of it may survive reinstall or device restore until you use the in-app deletion flow, clear app data, or reset relevant device storage.
4. Account, authentication, and cloud sync
The App uses Firebase Authentication. By default, Firebase may create an anonymous app session so cloud features can operate without a separate Knowly username/password.
You may optionally sign in with Google or Apple. If you do, Firebase and Knowly may process provider identifiers, Firebase Auth UID, email address if shared, display name if shared, provider type, platform, sign-in timestamps, account-linking records, and related authentication metadata. We use this to restore progress, link devices, prevent account drift, secure the service, and prevent abuse.
Cloud sync may store progress and app state in Firebase Firestore, including XP, lessons, streaks, achievements, certificates, custom flashcards, daily and weekly stats, foreground usage totals, premium status metadata, RevenueCat purchase metadata, Shards, Runes, and Energy balances and ledgers, Arena and tournament progress, season-pass progress, settings, language/target selections, referral state, social feature state, and other data needed to operate requested features.
5. Public, social, and historical competitive data
Some data is visible to other users when you use current public or social features. This may include nickname, avatar, frame, aura, profile card settings, XP, streak, points, rank, league or club tier, Arena star rank and match results, tournament scores and placements, season progress, premium or club markers, friend activity, gifts, activity likes, community pack author information, seller notifications, and similar profile fields. Visibility depends on the feature: some fields may be public to app users, some visible to league or club participants, some visible to friends, some visible to community pack buyers or sellers, and some visible only to moderators/admins.
When you use the Together feature with friends, those friends may see whether you studied today, how many days you both studied on the same day, the resulting friendship level and progress, and contributions to the shared weekly friends chest. Friends may also send or receive nudge and gift-availability signals through this feature.
In Arena matches and friend duels, your opponent and match participants may see your nickname, avatar, rank, and in-match progress and results. Opponents may be other users or computer-controlled practice opponents.
Historical records created by retired features (such as the old Quiz mode or earlier versions of competitive modes), including old results or participation records, may be retained only as reasonably necessary for security, fraud or abuse prevention, dispute handling, legal compliance, backup expiry, or deletion integrity. Account deletion is designed to delete or de-identify those historical records controlled by Knowly, subject only to the limited retention grounds described in this Policy. Those historical records are not presented as currently available gameplay features.
6. User content, community packs, reports, and moderation
If you create Community Packs, submit flashcard text, translations, reports, profile names, survey answers, ratings/votes, or other user-provided content, we process the content you provide and related metadata. This may include titles, descriptions, card text and translations, normalized text used for moderation, report reasons, reporter/reported user IDs and names, author IDs, buyer/seller IDs, moderation decisions, timestamps, platform, app version, audit fields, ranking scores, vote counts, report counts, and related safety signals.
Published Community Packs and approved catalog metadata may be visible in the App. Pack cards may be visible to the author, moderators, and users who access or purchase the pack with Shards.
If you comment on a Community Pack you have added, we store your comment text, your author ID and display name, the pack ID, timestamps, reaction counts, and pin status. Comments are visible to other users who have added the same pack, remain attached to the pack, and are not private messages. The pack's author can pin one comment and hide a comment from the pack's comment list for other viewers; a hidden comment is not deleted and may still be reviewed if reported. You can delete your own comment at any time, and any user can report a specific comment (separately from reporting the whole pack) using the same report categories described above. If someone comments on a Community Pack you authored, we send you an in-app notification containing a short excerpt of the comment so you can review it.
A Community Pack's author can edit the pack's title, description, and cards after it is published. Edited content replaces the previous version immediately and does not go through a separate moderation review before becoming visible to other users; we keep the previous version and edit metadata for audit and abuse-investigation purposes.
We may review, block, remove, hide, de-identify, retain, or disclose user content, comments, and reports when needed to operate moderation, enforce the Terms, protect users, investigate abuse, handle disputes, prevent fraud, comply with law, respond to copyright or rights complaints, or preserve service integrity.
7. Friends, gifts, referrals, invite codes, and rewards
Friend, gift, referral, invite, and reward features may process friend codes, friend relationships, friend requests, gifts sent/received, gift history, activity feed entries, activity likes, invite links, referral codes, referral owners, referral attributions, referrer/referee stable IDs, reward status, reward roulette spins and outcomes, Shards ledger entries, daily or monthly limits, cooldowns, abuse checks, Google Play Install Referrer data on Android, and deep-link or manual-code source information.
We use this information to operate the feature, attribute rewards, prevent self-referrals and abuse, enforce caps and cooldowns, correct errors, and protect the App.
8. App messages, reactions, polls, and surveys
The App may show in-app messages, polls, product questions, cancellation surveys, VIP surveys, or similar prompts. If you respond, react, vote, dismiss, claim a reward, or otherwise interact, we may process response content, selected options, reaction type, vote choice, message IDs, survey IDs, timestamps, eligibility state, reward state, user or stable app IDs, and related metadata.
We use this information to operate messages and polls, prevent duplicate rewards or abuse, understand product feedback, improve the App, maintain audit records, and apply entitlements or rewards where applicable.
9. Purchases, subscriptions, RevenueCat, and Shards
Premium subscriptions, free trials, Shards purchases, and other in-app purchases are billed through the Apple App Store or Google Play. Knowly does not receive your payment card or bank details.
We use RevenueCat to verify subscriptions, entitlements, receipts, product IDs, transaction IDs, store, environment, purchase and expiry timestamps, cancellation or billing status, refund and chargeback signals, and related webhook events. RevenueCat may receive a Phraseman app user ID, Firebase/Auth ID, canonical stable ID, and attributes such as `phraseman_uid` so subscription and purchase state can be restored and matched to your account.
Shards are a virtual in-app balance. We may store Shards balances, purchases, grants, spending, refunds/reversals, pack purchases, seller credits, platform fees, reward grants, and audit logs in Firebase.
10. Analytics, diagnostics, device identifiers, and app health
We use Firebase Analytics, Firebase Crashlytics, PostHog where enabled, and our own limited app activity/error logs to operate, secure, debug, measure, and improve the App. These records may include app events, screens/features used, purchase/paywall/referral events, AI feature events, onboarding choices, notification interactions, message or survey interactions, error context, crash logs, stack traces, app version, build number, platform, OS version, device name or model, app state, user name, Firebase/Auth IDs, stable app ID, app instance identifiers, PostHog distinct IDs where enabled, and other app metadata.
These records are not described as anonymous. Some diagnostics and analytics may be linked to your app account, Firebase/Auth ID, stable app ID, app instance, or device identifiers.
We ask for your consent before collecting non-essential product analytics (such as PostHog analytics and non-essential Firebase Analytics events). If you decline, or later withdraw consent in the App, we do not collect that non-essential analytics and do not link it to your account or identifiers. We still process a limited amount of strictly necessary information, such as crash and error diagnostics, security, and fraud-prevention signals, which we rely on to keep the App working and secure. You can change your analytics choice at any time in the App settings.
The App does not use the Google Play Services Advertising ID and does not request it. We do not sell personal information, and we do not use any advertising identifier for third-party advertising or cross-context behavioral advertising unless this Policy, store disclosures, and any required consent are updated first.
11. AI features and OpenAI processing
Some Phraseman features use generative AI providers such as OpenAI to generate dialogue replies, phrase explanations, mistake explanations, weekly reviews, stats insights, and similar learning feedback.
When you use AI features, we may send the AI provider the text you enter, recent conversation history, selected scenario or mode, language level, learning target, phrase text, phrase meaning, your exercise answer and target answer, computed learning analytics such as weak words or phrases, mistake categories, progress, XP, streaks, study minutes, and related context needed to generate the requested response.
We may also keep limited AI-related logs for quotas, billing, cost control, abuse prevention, debugging, safety, and service reliability. These logs may include user IDs, feature type, model name, token counts, timestamps, request status, premium status, language, lesson or phrase identifiers, and similar metadata.
When you rate a lesson, vocabulary session, dialogue, or Arena match and write a comment in the rating card, that comment text may be sent to an AI provider (such as OpenAI) so we can group recurring topics across many reviews and see what to fix first. This happens without a separate in-app checkbox: your use of the rating card is optional, and submitting it is what indicates your agreement. Ratings and comments are optional — you can always skip the card, and every screen works exactly the same if you do. Please do not include personal data in your comment; email addresses and phone numbers are stripped before the text is grouped.
Do not submit sensitive personal data, confidential information, payment details, medical, legal, financial, immigration, employment, emergency, or safety-critical information to AI features. AI output may be inaccurate, incomplete, or unsuitable for your context.
Mistake-explanation features in lessons (the inline mistake breakdown and the simplified 'explain simpler' view) require your explicit, separate opt-in before they are used for the first time, and you can withdraw that consent at any time in the App's privacy settings. If you do not opt in, or if you withdraw consent, these two features are not shown and the associated text is not sent to the AI provider; the rest of the lesson (including the correct answer) continues to work normally.
AI dialogs (scenario practice conversations and the free-form companion chat) also require your explicit, separate opt-in before you can open them for the first time, and you can withdraw that consent at any time in the App's privacy settings. If you do not opt in, or if you withdraw consent, these screens do not open and your messages are not sent to the AI provider.
AI voice lessons and calls (the "MAX" voice tutor and voice role-play calls) stream your microphone audio in real time to the AI provider (OpenAI) over an encrypted connection so that it can recognise your speech and answer with a synthetic voice; the AI provider also produces a text transcript of what you and the tutor said. Knowly does not record or store the audio of these calls. To let the AI tutor remember your progress between lessons, after a lesson we store short teacher notes derived from the transcript: your name and personal facts you chose to tell the tutor (for example your city, job, hobbies or plans), recurring language mistakes worth practising, the phrases the tutor asked you to practise next time, the topic promised for the next lesson, your language-preference request (for example "speak more English with me"), and the number and date of lessons. These notes are stored in your account, are used only to personalise your lessons and the post-lesson review, are never shown to other users, and are deleted together with your account. You can ask us to delete them separately at any time by emailing support.phraseman@gmail.com. Please do not tell the AI tutor sensitive personal data (health, finances, legal matters, identifiers or passwords).
12. Notifications and push tokens
If you enable notifications, the App may request notification permission and store notification settings, local scheduled notification IDs, Expo push tokens, native push tokens where applicable, device/platform metadata, user IDs, and related delivery metadata.
Notifications may include local reminders, phrase of the day, streak warnings, weekly/monthly recaps, XP, lesson counts, streak counts, phrase text, league rank changes, re-engagement or winback reminders, account/service notices, or similar app context. Remote notifications may be delivered through Expo's push notification service and the applicable platform push service. You can disable notifications in the App or device settings, but some service messages may still appear inside the App.
13. Text-to-speech, speech recognition, and voice features
The App uses your device's built-in text-to-speech engine through expo-speech to pronounce English phrases and example sentences. Based on the current implementation, pronunciation is generated on device and Knowly does not receive the generated text-to-speech audio.
Where speech recognition, pronunciation practice, or voice dialogue features are enabled, the App may request microphone and speech recognition permissions. Depending on the feature, speech may be processed on device or by platform speech services, and a transcript or recognized text may be used by the App. If you use an AI voice dialogue feature, the transcript or recognized text may be sent to the AI provider as described in the AI features section. Do not say sensitive personal, confidential, payment, medical, legal, financial, or emergency information in voice features.
For real-time AI voice lessons and calls, the App establishes a direct encrypted media connection from your device to the AI provider (OpenAI): your live microphone audio and the tutor's synthetic voice travel over that connection while the call is active. Knowly's servers issue a short-lived access token for the call, keep the call's duration, quota, billing and usage counters, and receive the transcript for the post-call review and the tutor's memory notes described in the AI features section; Knowly does not receive or store the raw call audio.
Some of the libraries that power these voice features are general-purpose media and animation libraries that also support video capture and motion sensors. Because of this, on some platforms the operating system may list camera or motion permissions for the App. The App does not take photos, record video, open the camera, or read motion and fitness sensors, and it never asks you for those permissions; the only sensor input the App captures is microphone audio for the voice features described above.
14. Website, cookies, leads, and web purchases
The Knowly website uses local storage and session storage for essential preferences and flows, including theme choice, first-touch UTM attribution, cached prices, and your Meta Pixel consent choice. It also sends limited website events (page category, visit/view, store clicks, and checkout funnel events) to our Cloud Function, which stores aggregate counters. To protect that endpoint from abuse, we create a short-lived hash of the visitor IP address for rate limiting; hosting providers may also process IP addresses and request logs.
If Meta Pixel is enabled, we load it only after opt-in consent in the EU, EEA, UK, and Switzerland. You can accept, reject, or later change that choice using the "Cookie settings" link in the website footer.
If you use the website contact form, email support, or legal request channels, we may process your name, email address, message, topic, page URL, user-agent, forwarded IP header, support metadata, account identifiers you provide, and our replies. To respond faster, support messages may be triaged and answered with AI assistance: the text of your message and related support context may be shared with our AI provider (OpenAI) to classify the request and draft a reply, and routine replies may be sent automatically. You can ask for human review in your reply at any time.
For website purchases, we process your email, selected access option, gift choice, UTM attribution, order identifiers, payment status, amount, currency, activation code, and payment-provider transaction references. Card and PayPal payment credentials are collected by Stripe or PayPal, not by Knowly.
15. Email Communications and Marketing
If you provide an email address, we may send service and account emails about security, purchases, account operation, legal notices, or important service information. We send website product emails only where you have separately opted in. We use an email provider such as Resend. You can withdraw marketing consent at any time through the unsubscribe link in the email or by contacting support.phraseman@gmail.com; this does not affect service or account emails. We keep a suppression list so we can honour your choice.
16. Third-party services and processors
The App and related services use third-party providers, including:
- Google Firebase services such as Authentication, Firestore, Cloud Functions, Cloud Storage, Analytics, Crashlytics, and related Google Cloud infrastructure
- Google Play Services, Google Sign-In, Google Play Billing, Google Play Install Referrer, and Android platform services
- Apple Sign In, Apple App Store, Apple in-app purchase systems, and Apple platform services
- OpenAI or other AI model providers for AI dialogue, explanations, mistake feedback, reviews, insights, real-time voice lessons, AI-assisted support replies, and related AI features
- YouTube API Services and embedded YouTube players for the in-app video catalog; when you view or play videos, YouTube/Google processes data under the Google Privacy Policy (https://policies.google.com/privacy)
- PostHog for product analytics where enabled
- RevenueCat for subscription, purchase, entitlement, and receipt verification
- Expo / EAS / Expo Updates and Expo push notification services for app infrastructure and notification delivery
- Resend or another email provider, and Gmail (Google) for the support mailbox, for contact, support, and consented website email delivery
- Stripe and PayPal for website checkout and payment processing
- Meta, only where website Pixel consent is granted
- Telegram, to send payment-order and aggregated operational notifications to authorised administrators
- App stores and payment processors for purchase, subscription, refund, tax, and compliance records
These providers process data under their own terms, privacy policies, and security programs. Data may be processed in countries other than your country of residence, subject to applicable safeguards.
17. How we use and disclose information
We use information to provide, maintain, secure, debug, personalize, and improve the App; authenticate users; sync progress; operate purchases and entitlements; manage Shards and rewards; run leaderboards, leagues, clubs, friends, gifts, referrals, community packs, surveys, notifications, moderation, AI-generated feedback, AI quotas, and AI safety controls; retain, secure, delete, or de-identify historical records from retired features; prevent fraud and abuse; respond to support and legal requests; comply with law; enforce the Terms; and protect Knowly, users, and third parties.
We disclose information to service providers and processors that help operate the App; app stores and payment processors for purchases, refunds, fraud, and compliance; other users where required by current public, social, or community features; moderators/admins for safety and support; legal, regulatory, or law-enforcement authorities where required or permitted by law; and relevant parties in connection with a merger, acquisition, financing, reorganization, asset sale, or similar transaction.
We do not sell personal information. We do not knowingly share personal information for cross-context behavioral advertising unless this Policy and applicable store disclosures are updated to describe that practice.
18. Legal bases and purposes
Depending on your location, we process information on these bases:
- Contract/performance of the App or requested service: account operation, progress sync, purchases, subscriptions, Shards, leaderboards, social features, support, AI features you request, and requested features
- Legitimate interests: security, fraud prevention, abuse prevention, debugging, aggregate website measurement, service reliability, moderation, management of historical feature records, AI cost control, AI safety, product improvement, legal defense, and business operations
- Consent: AI-based mistake-explanation features in lessons, AI dialogs, website marketing emails, Meta Pixel where required, optional notifications, optional microphone/speech recognition permissions, optional Google/Apple sign-in where required, consent-based analytics where required, and child/parent consent where required
- Legal obligations: tax, accounting, consumer protection, store compliance, dispute handling, copyright and rights complaints, law-enforcement requests, regulatory compliance, and sanctions/export compliance
19. Retention
We retain information only as long as reasonably needed for the purposes described in this Policy, unless a longer period is required or permitted by law.
Typical retention criteria:
- Local app data remains on your device until you delete it, use account deletion, clear app data, uninstall, or reset relevant device storage; backup/keychain behavior may vary by platform
- Active cloud progress, profile, entitlement, and feature data is retained while your account or app instance is active
- Reports, moderation records, safety records, purchase records, entitlement records, referral records, reward records, surveys, AI quota/billing/safety logs, analytics/error records, and fraud-prevention records may be retained longer where needed for safety, disputes, legal compliance, chargebacks, refunds, accounting, moderation integrity, abuse prevention, cost control, or auditability
- Website leads, consent records, contact/support messages, and payment-order records are retained only as long as needed to deliver the requested service, honour consent or unsubscribe choices, respond, prevent abuse, and keep required business, security, or legal records
- An account you asked us to delete is retained for a 14-day grace period before irreversible deletion, so that an accidental deletion can be undone; during that period the account cannot be used and the data is not processed for any other purpose
- Backups and logs may persist until overwritten or deleted under normal retention cycles
We do not promise automatic deletion after a fixed inactivity period unless such a deletion job is implemented and active.
20. Account and data deletion
You can request deletion from inside the App where available, from the public deletion instructions at https://knowlyapps.com/legal/data-deletion/, or by emailing support.phraseman@gmail.com with subject "Delete My Data".
The in-app deletion flow starts an authenticated backend deletion request. The App signs you out and clears local app data on that device immediately. Server-side deletion is then scheduled after a 14-day grace period, so that an accidental deletion can still be undone: if you sign in again during those 14 days, the App offers to restore the account, and accepting cancels the deletion and returns your data in full. Once the 14 days elapse, deletion runs and becomes irreversible. The backend deletion function is designed to delete or de-identify active account data controlled by Knowly, including the Firebase Auth user, users/{stable_id} data and subcollections, leaderboard/profile records, auth links, name/friend/referral indexes, Community Pack, report, reaction, poll-vote, survey, analytics, and error records linked to the stable ID, and local app data on the device.
If you cannot access the App, if the in-app deletion request does not complete, or if you want follow-up, contact support.phraseman@gmail.com. We may need to verify your request before acting on it.
Some records may remain when retention is required or permitted for legal compliance, payment/tax/accounting, fraud prevention, security, dispute handling, chargebacks/refunds, moderation integrity, backups, or data stored by app stores and third-party processors. Deleting the account does not automatically cancel an active App Store or Google Play subscription; you must cancel it in the store subscription settings.
21. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to processing, port your data, withdraw consent, opt out of certain processing, and complain to a data protection authority. You may lodge a complaint with the Irish Data Protection Commission or your local supervisory authority.
To exercise rights, email support.phraseman@gmail.com with subject "Privacy Request". We may need to verify your identity, request additional information, refuse or limit requests where permitted by law, and retain limited records of requests and responses.
22. US state privacy rights
California and other US state residents may request information about categories of personal information collected, sources, purposes, disclosures, and deletion/correction where applicable. We do not sell personal information. We do not knowingly share personal information for cross-context behavioral advertising unless this Policy and applicable store disclosures are updated to say so.
Categories of personal information we may collect include identifiers, app/account identifiers, commercial information, internet or electronic activity, approximate device/app information, inferences from app activity, learning progress and AI personalization signals, user-generated content, support communications, transcripts or recognized text if you use voice features, and other information you provide or generate through App features.
23. International transfers
Knowly, service providers, and app platforms may process information in countries other than your country of residence. Where required, we rely on appropriate safeguards, contractual commitments, platform terms, service-provider security measures, and other lawful transfer mechanisms.
24. Security
We use technical and organizational measures such as Firebase security rules, authenticated Cloud Functions, TLS/HTTPS, access controls, logging, abuse monitoring, and operational controls. No system is perfectly secure, and we cannot guarantee absolute security.
25. Changes
We may update this Policy from time to time. Material changes will be reflected in the "Last updated" date and may include in-app notice, website updates, consent prompts, or store disclosure updates where practicable or required. Continued use of the App after changes means you acknowledge the updated Policy where permitted by law.
26. Contact
Knowly - Phraseman
Email: support.phraseman@gmail.com
Use this contact for privacy requests, parental requests, account deletion, support, legal notices, and questions about this Policy.