Legal
Privacy Policy
Last updated 2026-06-04.
This policy explains what personal data Vladimir Shirokun ("we") processes when you use Pepelen, why, and the rights you have. We are the data controller. Contact: privacy@pepelen.com.
Data we process
- Account data — your email address, an optional display name, and a hashed password (we never store your password in plain text). Used to provide and secure your account. Legal basis: performance of a contract.
- Learning data — the cards, decks, lessons, courses, attempts and progress you create or study. Used to provide the service. Legal basis: performance of a contract.
- Technical data — minimal request metadata (e.g. IP address) used for security and rate limiting. Legal basis: legitimate interest in protecting the service.
- Usage analytics — to improve the product we record first-party, server-side events about how the app is used: pages viewed (route paths), lessons started and finished, exercise results, card reviews, placement submissions, video votes, use of the AI tutor and card generator, and search activity. We store coarse signals only — never your search text or AI questions — linked to your account when you are signed in. Legal basis: legitimate interest in improving the service. The operator can disable analytics entirely, and we honour your browser's Do-Not-Track / Global Privacy Control signal.
Processors and third parties
- AI features (optional). If you use the AI tutor or AI card generator, the text you submit (your question or topic and the current exercise) is sent to OpenAI to generate a response. OpenAI processes it as our sub-processor; API inputs are not used to train their models by default. Don't submit sensitive personal data to these features.
- Embedded videos. Lessons may embed YouTube videos in privacy-enhanced mode (
youtube-nocookie.com). When you play a video, Google may receive data per its own policy. - Email. Verification and password-reset emails are delivered via our SMTP provider.
Cookies
We use a single strictly-necessary cookie (pepelen_session) to keep you signed in. We use no advertising or cross-site tracking cookies; the usage analytics described above are recorded server-side, not via cookies. Embedded videos may set third-party cookies only once you play them.
Retention
We keep your account and learning data until you delete your account, after which it is erased — including your analytics events and placement results. Usage-analytics events are additionally deleted automatically after a retention period. Security logs are kept only as long as needed for that purpose.
Your rights
You can access and export your data and delete your account(right to erasure) at any time from Settings. You may also request rectification or restriction, and lodge a complaint with your supervisory authority. To exercise any right, contact privacy@pepelen.com.
Children
Pepelen is not directed to children under 16. You must be at least 16 years old to create an account.
See also our Terms of Service and contact details.