Baursaq ("we", "us", "our") operates the LinguaCap iOS app and the LinguaCap Chrome extension (together, the "Services"). This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our Services.
We are committed to protecting your privacy. We do not sell your personal data, we do not use it for advertising, and we do not track you across other companies' apps or websites. We do use a product-analytics service to understand how our own apps are used; this is described in section 1.8 and you can opt out.
Some practices differ between our iOS app and our Chrome extension. Where this is the case, dedicated iOS App and Chrome Extension sub-sections clearly indicate which product the information refers to.
1. Information We Collect
1.1 Account Information
When you create an account using Apple Sign-In, Google Sign-In, or an email one-time code, we collect and store on our servers:
- Email address — for account identification and communication. If you use Apple's "Hide My Email", we only ever receive the relay address;
- Full name — for personalization (optional, depending on your sign-in method);
- Profile photo URL — for display in the App (if provided by your sign-in provider);
- User ID — a unique identifier generated by our authentication system;
- Device identifier — a random ID generated by the App to link your sessions and enforce usage limits. It is not the IDFA and is not used for advertising;
- Learning profile — your native language, the language you are learning, your level, and your learning goal.
1.2 Learning Data
As you use the App we store the following learning data. It is kept on your device and, when you are signed in, also synchronised to our servers so it is available across your devices:
- Saved words — words you save with translations, transcriptions, examples, and synonyms;
- Flashcard progress — review history, scheduling state, and your flashcard settings;
- Learning statistics — daily goals, streak count, correct/wrong answer counts, number of words translated;
- Dictation results — scores and history of your dictation practice sessions.
1.3 Browsing and Watch History
- YouTube watch history — titles, video IDs, thumbnails, and last watched timestamps of YouTube videos you watch in the App;
- Web browsing history — URLs of pages visited through the App's in-app browser;
- Bookmarks — URLs and titles you save as bookmarks;
- Search queries — search terms entered in the App's search bar.
This data is stored on your device. When you are signed in, your watch history — including the video title, URL, video ID, playback position, and the associated subtitle transcript — is also synchronised to our servers so you can resume on another device. You can delete individual items or your whole account at any time (see section 7).
1.4 Subtitle and Transcript Data
When you use the subtitle feature, the App retrieves YouTube subtitle data and sends it to our servers for AI-powered punctuation correction and translation. The text is processed in real time and is not retained by us or by our AI providers for that request. Where a transcript belongs to an item in your watch history and you are signed in, a copy is stored with that history item as described in section 1.3, and is deleted when you delete the item or your account.
1.5 Subscription and Payment Information
When you subscribe to LinguaCap Pro we store:
- Subscription status — active, expired, or cancelled;
- Plan type — monthly or yearly;
- Purchase and expiry timestamps;
- Billing events received from the app store via our subscription provider, retained for accounting and dispute handling.
Payment details (card numbers, billing address) are handled entirely by Apple and are never accessible to us.
1.6 Support Messages
If you contact us through the in-app support screen, we store your message, our replies, and the platform you wrote from, so that we can answer you.
1.7 Push Notification Token
If you allow notifications, we store the push token issued by Apple (delivered to us through Firebase Cloud Messaging) so we can notify you when support replies to you. Notifications are optional and no feature is gated behind them.
1.8 Product Analytics and Session Replay
We use PostHog to understand how the App is used and to improve it. This is analytics of our own product only — the data is not linked with third-party data, not used for advertising, and not shared with data brokers.
- Product events — app opened/backgrounded/installed/updated, screens viewed, and specific in-app actions such as starting onboarding, opening the paywall, starting a subscription, or rating the app;
- Profile properties attached to your analytics profile — your user ID, email address, subscription status, and learning profile (native language, learning language, level, goal);
- Session replay — a screen recording of your interaction, captured only on the onboarding and paywall screens and never elsewhere in the App. Text inputs and images are masked by the SDK before the recording leaves your device.
You can opt out. When you opt out, the SDK stops sending events and recordings entirely. See section 7 for how.
1.9 Feature Experiments
We use Firebase Remote Config to roll out features and run A/B tests (for example, which paywall variant you see). Which variant you were assigned is recorded as a property on your analytics profile so we can compare results.
1.10 Technical Diagnostics
Like any internet service, our servers process technical data so the Services can work and stay secure:
- IP address — received with every request. We use it for abuse prevention, rate limiting, and to determine your approximate country;
- Approximate country — derived from your IP address through IPinfo. We use it only to show region-appropriate help and support information in Settings. We do not derive or store your city, coordinates, or any finer location, and we never use the device's Location Services;
- Request diagnostics — the endpoint called, HTTP status, timing, your user ID, app platform and version, and the IP address. These are kept in a short-lived in-memory buffer of the most recent requests for live debugging and are lost whenever our server restarts;
- Usage counters — per-feature daily counts used to enforce free and Pro limits.
1.11 Audio Data
The dictation feature uses text input (keyboard typing). We do not record or collect any audio data from your microphone.
1.12 Information We Do NOT Collect (iOS App)
- We do not collect the advertising identifier (IDFA) and do not run advertising SDKs;
- We do not track you across other companies' apps or websites, which is why the App never asks for App Tracking Transparency permission;
- We do not use Location Services and do not collect precise location;
- We do not access your contacts, photos, camera, or microphone;
- We do not sell personal data or share it with data brokers.
1.13 Anonymous Session
On first use, the Extension registers an anonymous session with our own backend at api.linguacap.com. This generates a random user ID (UUID) used solely for rate-limiting translation requests. Unless you sign in, no email, name, or other personally identifiable information is collected by the Extension.
1.14 Device ID
A random UUID is stored locally in Chrome storage to identify the installation and is sent to our own backend with each request. It is not shared with third parties.
1.15 Saved Words and Preferences
Words you save to the dictionary, UI language, style settings, and feature toggles are stored locally in chrome.storage.local on your device. They are not uploaded anywhere unless you link the Extension to a LinguaCap account — in that case they are synchronised to our servers and governed by the iOS App sections above.
1.16 Translation Requests
When you click a word or enable auto-translate, the selected text is sent to our own backend, which calls third-party AI and translation providers (see section 4). Only the word or subtitle line is sent for translation.
If you are signed in, the Extension additionally saves a translation history entry containing the original text, its translation, the languages involved, and the page URL and page title where you made the translation, so you can review your history in your account. If you are not signed in, no page URL or title is stored.
1.17 Information We Do NOT Collect (Chrome Extension)
- General browsing history — we only ever receive the URL of a page on which you actively translated something, and only while signed in;
- Cookies or authentication tokens from visited websites;
- Video or audio content;
- Keystrokes or form data.
2. How We Use Your Information
| Data Category | Purpose | Legal Basis |
|---|---|---|
| Account info (email, name, user ID) | Account creation, authentication, profile display, support replies | Contract performance |
| Learning profile (languages, level, goal) | Tailoring translations and lessons to your level and language pair | Contract performance |
| Saved words, flashcards & learning stats | Core functionality, progress tracking, cross-device sync | Contract performance |
| Watch history, bookmarks & transcripts | Resume playback, quick access to content, cross-device sync | Contract performance |
| Subtitle / translation text (sent for processing) | AI punctuation correction and translation | Contract performance |
| Subscription status & billing events | Feature access management, entitlement verification, accounting | Contract performance; legal obligation |
| Support messages | Answering your support requests | Contract performance |
| Push notification token | Notifying you when support replies | Consent |
| Product analytics & session replay | Understanding how the App is used, fixing usability problems, A/B testing | Consent (opt-out available) |
| IP address & request diagnostics | Security, abuse prevention, rate limiting, debugging | Legitimate interest |
| Approximate country (from IP) | Showing region-appropriate help and support information | Legitimate interest |
| Anonymous user ID — Extension | Translation request rate limiting | Legitimate interest |
3. Data Storage and Security
3.1 Local Storage
- iOS App: words, history, bookmarks, and learning stats are stored on your device using Apple's SwiftData framework and UserDefaults. Authentication tokens are stored in the iOS Keychain with
kSecAttrAccessibleAfterFirstUnlockThisDeviceOnlyprotection. - Chrome Extension: saved words, preferences, and session tokens are stored locally in
chrome.storage.local.
3.2 Server Storage
Our backend runs on our own servers, hosted with OVH in Germany (European Union). If you are signed in, the following is stored there:
- Profile information (email, name, avatar URL, learning profile);
- Subscription status, plan, expiry, and billing events;
- Saved words, flashcard progress and settings;
- Watch history and its transcripts, and translation history;
- Support messages and push notification tokens;
- Per-feature usage counters.
3.3 Security Measures
- All network communication uses HTTPS / TLS encryption;
- Every API request is authorised against your own account; endpoints only ever return your own rows;
- Refresh tokens are stored as hashes, never in plain text, and are rotated on each use;
- IP addresses used for country lookup are cached under a SHA-256 hash, not as raw addresses;
- Passwords are never collected — sign-in is delegated to Apple, Google, or a one-time email code.
4. Third-Party Services
We use the following third-party services. Each is bound by its own privacy terms and is required to protect your data to a standard equivalent to this policy. We do not authorise any of them to sell your data or use it for their own advertising.
| Service | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| Apple (Sign-In, In-App Purchase) | Authentication, payments | Apple ID token; purchase data | Apple Privacy |
| Google (Sign-In) | Authentication | Google OAuth token | Google Privacy |
| RevenueCat — App | Subscription management | User ID, entitlements, purchase events | RevenueCat Privacy |
| PostHog | Product analytics and session replay | User ID, email, subscription status, learning profile, in-app events, masked recordings of the onboarding and paywall screens | PostHog Privacy |
| Google Firebase — App | Push notifications (Cloud Messaging) and feature experiments (Remote Config) | Push token, app instance identifier | Firebase Privacy |
| IPinfo | Determining approximate country from IP | IP address | IPinfo Privacy |
| Groq | AI translation, punctuation correction | Selected text / subtitle lines | Groq Privacy |
| OpenAI | AI translation fallback | Selected text / subtitle lines | OpenAI Privacy |
| DeepSeek | AI translation fallback | Selected text / subtitle lines | DeepSeek Privacy |
| Google Translate | Basic word and line translation | Selected text | Google Privacy |
| YouTube | Video content and subtitles | Video requests | YouTube / Google Privacy |
| Resend | Sending sign-in codes and account emails | Email address | Resend Privacy |
| Stripe — web | Card payments for the web/Extension subscription | Email, subscription identifiers. Card details go directly to Stripe and never reach us | Stripe Privacy |
| Kaspi — web, Kazakhstan | Bank transfer payments | Payer name and payment amount for matching your payment | Kaspi |
| OVH | Server hosting (Germany, EU) | All server-stored data listed in section 3.2 | OVH Privacy |
AI providers are used for a single request at a time: the text you send is processed in real time to produce your translation, and we do not retain it afterwards. We send only the word, phrase, or subtitle line being translated — never your email, name, or account identifiers. How each provider handles data it receives through its API is governed by that provider's own terms, linked above.
5. Browser Extension Permissions
The Chrome Extension requests the following permissions:
- webRequest — to detect subtitle file downloads (VTT/SRT) from streaming services;
- storage — to save your preferences and dictionary locally;
- activeTab — to interact with the current tab's video player;
- alarms — to periodically check whether linking the Extension to your account has completed;
- host_permissions (
*://*/*) — required because subtitle URLs vary across streaming platforms and CDN domains; the Extension only activates its features on supported sites (YouTube, Netflix, Bilibili, Spotify, Yandex Music and other sites with VTT/SRT subtitles).
6. Data Retention
- Local data — retained on your device until you uninstall the App / Extension or clear its data;
- Account and learning data — retained as long as your account exists, then deleted as described in section 7;
- Subscription and billing records — retained after account deletion where accounting or tax law requires it;
- Support messages — retained while your account exists so we can follow up on your requests;
- Request diagnostics (IP, endpoint, status) — held only in an in-memory buffer of the most recent requests and discarded whenever our server restarts;
- IP-to-country cache — stored under a SHA-256 hash and expires automatically after 24 hours;
- Rate-limit and usage counters — expire automatically after their window (12 hours to one day);
- Analytics events and session replays — retained by PostHog according to our project's retention settings and deleted on request;
- Processed text (translations, punctuation) — not retained after real-time processing, except transcripts saved with your watch history as described in section 1.3.
7. Your Rights
You have the following rights regarding your personal data. To exercise any of them, use the App where indicated or email us at baursaqdev@gmail.com; we respond within 30 days.
- Access: You can view your profile and saved data within the App, and request a full copy from us;
- Correction: You can update your learning profile in the App and your name and email through your Apple or Google account;
- Deletion: You can delete your account and all associated data from the App's Settings screen. Deletion is permanent and removes your server-stored data within 30 days, except records we must keep for accounting purposes. For the Extension, uninstalling it removes all local data;
- Export: Contact us to request a machine-readable copy of your data;
- Opt out of analytics: You can ask us to disable product analytics and session replay for your account by emailing us, and we will opt your profile out and delete the events and recordings already collected. Opting out never limits any paid or free feature;
- Withdraw other consent: Turn off notification permission in iOS Settings to stop push notifications, or sign out and delete your account to withdraw consent entirely;
- Object or complain: If you are in the EEA or UK you may object to processing based on legitimate interest and lodge a complaint with your local data protection authority.
8. Children's Privacy
LinguaCap is not directed at children under 13 years of age (or the applicable minimum age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
9. International Data Transfers
Our own servers are located in Germany (European Union). Some of the third-party processors listed in section 4 — including PostHog, Firebase, RevenueCat, IPinfo, Groq, OpenAI, Resend, and Stripe — process data in the United States or other countries. Where such a transfer leaves the EEA or UK, it relies on the safeguards offered by that provider, such as the European Commission's Standard Contractual Clauses. You can review each provider's terms through the links in section 4.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the App or Extension. The "Last updated" date at the top reflects when this policy was last revised.
11. Contact Us
If you have questions or concerns about this Privacy Policy or your data, contact us at:
Email: baursaqdev@gmail.com
Baursaq
Astana, Kazakhstan