Verbs Master Irregular
Privacy Policy
This Privacy Policy describes the processing of data in connection with the Verbs Master - Irregular mobile application (the "Application"), its website (the "Website"), and communications with the Controller.
1. Controller and scope of this Policy
The controller of personal data processed in connection with the Application, the Website and correspondence is Grzegorz Kniażuk, a sole trader operating under the business name Grzegorz Kniażuk Software Development, ul. Garbarska 18A/98, 20-340 Lublin, Poland, Tax Identification Number (NIP): 9462761962, National Business Registry Number (REGON): 543548683 (the "Controller"). The Controller has not appointed a data protection officer; all personal data matters may be addressed directly to the Controller.
2. Data stored locally
The Application does not require an account or ask for a name, email address, telephone number or postal address. It does, however, store data on the user's device that is necessary for its operation and personalization: custom flashcard sets and their contents, application language, theme, selected English variety, voice, speed and volume settings, flashcard display settings, onboarding completion status, and the accepted version of the Terms and its acceptance time. This data is stored within the Application and is not directly accessible to the Controller.
3. Website and technical logs
The Website does not use analytics or advertising tools and does not create its own user profiles. Whenever a connection is made, the hosting provider Vercel may automatically process technical data necessary to display and secure the Website, in particular the IP address, request date and time, requested URL, browser type and version, operating system, device type, approximate location derived from the IP address, and diagnostic and security information. The Controller does not combine this information with data stored locally by the Application.
4. Email correspondence
When you contact the Controller, the data voluntarily included in the message is processed, in particular your email address, name or signature, message content, attachments, and technical message metadata. This data is obtained directly from the person making contact. Email for the kniazuk.dev domain is handled by Hostinger.
5. Purposes and legal bases
Website technical data is processed to deliver its content, maintain availability, diagnose issues, ensure security and prevent abuse, pursuant to Article 6(1)(f) GDPR — the Controller's legitimate interest in operating a secure Website. Correspondence data is processed to respond and communicate pursuant to Article 6(1)(f) GDPR; where a message concerns entering into or performing a contract, also pursuant to Article 6(1)(b) GDPR; and where retention or disclosure is required by law, pursuant to Article 6(1)(c) GDPR. Data may also be processed pursuant to Article 6(1)(f) GDPR to establish, exercise or defend legal claims. The Controller does not rely on consent for the processing described here.
6. Recipients and transfers outside the EEA
Recipients may include: Vercel Inc. and its subprocessors for Website hosting, content delivery and security; Hostinger group entities and their subprocessors for email services; and legal advisers, accountants, IT providers or authorized public authorities — only where necessary and lawful. The Controller does not sell personal data. Vercel is based in the United States and states that it participates in the EU–U.S. Data Privacy Framework and uses Standard Contractual Clauses or other appropriate transfer mechanisms. Hostinger states that data may also be processed outside the EEA using Standard Contractual Clauses or another basis compliant with Articles 45–49 GDPR.
7. Retention periods
The Controller does not maintain a separate Website analytics database or export logs to an external system. According to Vercel’s current documentation, runtime logs are available for the period resulting from the current service configuration, but no longer than 30 days. Independently of the period for which logs are available in the Vercel dashboard, Vercel may retain data for as long as needed to provide and secure the service or comply with legal obligations, in accordance with its documentation and privacy notice. Ordinary correspondence is retained for the time needed to resolve the matter and then for no longer than 12 months. If a message concerns a contract, legal obligation or potential claim, relevant data may be retained until the applicable limitation or legally required record-retention period expires.
8. Data subject rights
Subject to the conditions set out in the GDPR, you have the right to access, rectify, erase and restrict the processing of your data and, where applicable, the right to data portability. You may object, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR. Requests may be sent to the Controller's contact address. You also have the right to lodge a complaint with the President of the Polish Personal Data Protection Office (uodo.gov.pl). Because the processing described here is not based on consent, the right to withdraw consent does not currently apply.
9. Voluntary provision of data and automated decisions
Providing data in an email is voluntary, but without a return address or information necessary to review the matter, the Controller may be unable to respond. Technical data is transmitted automatically when opening the Website and is necessary to establish a connection and display the page. The Controller does not make decisions about users based solely on automated processing that produce legal or similarly significant effects and does not conduct profiling.
10. Speech synthesis in the Application
The Application uses only system voices available locally on the device. Text to be spoken is not sent to the Controller or to an external speech-synthesis service.
11. Data security
Local data is protected by the security mechanisms of the device and its operating system. The user is responsible for securing access to their device. The Controller applies appropriate technical and organizational measures to protect processed data against unauthorized access, loss, alteration or destruction.
12. Children's privacy
The Application is educational and may also be used by minors, but it is not designed to solicit personal data from them. It does not require an account, age or contact details, and the data described in section 2 remains on the device and is not directly accessible to the Controller. The processing described in this Policy is not based on consent, so the age threshold for a child’s consent under Article 8 GDPR is not used as a condition of access to the Application. If a minor contacts the Controller by email, the data in the message is processed in accordance with sections 4–8. A younger user who does not understand this Policy or wants to include personal data in a message should ask a parent or guardian for help. If the Controller learns that unnecessary personal data of a child has been received, it will be deleted unless continued retention is required by law or necessary for the establishment, exercise or defence of legal claims.
13. Deleting local Application data
Custom flashcard sets can be deleted directly in the Application. Voice, study, appearance and flashcard display settings can be restored to their defaults in the Application settings. Resetting settings does not delete custom flashcard sets, the application language or the record of acceptance of the Terms. All locally stored data can be removed by clearing the Application data in the operating system settings or by uninstalling it. In the current version of the Application, local data is excluded from system cloud backup and from transfers of Application data between Android devices.
14. Changes to the Privacy Policy
This Policy may be updated when Application or Website features, providers or legal requirements change. The current version is published at the permanent address linked from the Application. The last-updated date appears at the end of this document.
15. Contact
You can contact the Controller with any questions about this Privacy Policy or data protection at kontakt@kniazuk.dev.
Last updated: 23 August 2026