Privacy Policy
This Privacy Policy explains what personal data the 12levels mobile application (the "Service") collects and how it is processed.
1. Data Controller
The data controller is Iuvenalii Khlopkov (PE), an individual entrepreneur registered in the Republic of Armenia, tax identification number 20279853, registered office: 26A Movses Khorenatsi str., apt. 201, Yerevan 0010, Armenia.
Contact for data protection inquiries:
Email: [email protected]
Website: https://12levels.app
2. Categories of Data Processed
2.1 Identification data
- Email address — for registration and account recovery (only if you choose email sign-in)
- Name — for interface personalization (only if you sign in with Apple/Google or provide it during email registration)
- Internal user identifier (User ID) — to link progress to your account
- Anonymous device identifier (UUID) — a random UUID generated on first app launch and stored in your device's Keychain. Used as your stable identity for purchases and progress recovery before you sign in with Apple/Google/Email. See Section 2.5 for details.
2.2 Learning data
- Word learning progress — which words are being learned and their current learning stage
- Answer results — correct/incorrect answers used to schedule review intervals via a spaced-repetition algorithm
- Reading sessions — which learning texts you have opened, your position within them, and your overall progress
- Free-text answers — phrases you type during knowledge-check exercises; in this release they are evaluated locally or by the 12levels backend and are not sent to a third-party AI provider
- Feedback text — optional text you deliberately submit through the feedback form; it is sent to Sentry as the single support processor and is not copied to product analytics or messaging services
- Calibration results — your detected language level (CEFR scale) and identified gaps
2.3 Technical and product-usage data
- Crash reports — crash data via Apple MetricKit (anonymous, aggregated) and via Sentry. Sentry crash reports are linked to your internal User ID (UUID) for debugging; they never include your email or name.
- Performance metrics — performance data (launch time, memory, slow operations) via Apple MetricKit and Sentry, the latter linked to your internal User ID (UUID).
- Diagnostic breadcrumbs — a short trail of recent in-app actions before a crash (taps, screen navigation, network requests without their contents), collected by Sentry to reproduce bugs.
- App and iOS version — for compatibility
- Product analytics — typed events such as app lifecycle, screen category, feature use, learning-session counts and accuracy, reading progress, subscription-funnel state, interface language, level, app version, iOS version, device model and a random device-level identifier. PostHog receives the internal User ID after account provisioning or sign-in, so these analytics are treated as linked to your account/device. We do not send email, name, raw answers, searched text, book titles or word text to PostHog.
2.4 Payment and subscription data
The Service does not receive credit card numbers, bank details, or any other payment instrument data. All payments for the "12levels Pro" subscription and Lifetime purchase are processed by Apple through the App Store In-App Purchase system.
For purchases made inside the Service, we process the following purchase-related data:
- Signed Apple transaction receipt (JWS) — cryptographically signed by Apple, contains the transaction identifier, product identifier (Monthly / Yearly / Lifetime), purchase date, expiration date (for subscriptions), and Apple's environment (sandbox or production). Verified server-side using Apple's public certificate chain to confirm the purchase is genuine and untampered.
- App Account Token (
appAccountToken) — a UUID that matches your internal User ID (see Section 2.1). The token is sent to Apple at purchase time so that subsequent Apple-to-server notifications (renewals, refunds, cancellations) can be matched back to your account. Before you sign in with Apple/Google/Email, this UUID is the anonymous device identifier described in Section 2.5 and contains no link to your real identity beyond what Apple already processes as the payment processor (your Apple ID). After sign-in, the same UUID is associated with your authenticated account so that purchases made before and after sign-in remain on the same record. - Entitlement status — derived state on our servers: which "Pro" plan is active for your account, when it expires, whether auto-renewal is enabled, whether a refund/revocation occurred. Used to gate Pro features and to display correct subscription status in the app.
- Subscription lifecycle events from Apple — received via Apple App Store Server Notifications V2 (a server-to-server webhook from Apple to the Service). Includes events such as
SUBSCRIBED,DID_RENEW,EXPIRED,REFUND,REVOKE,DID_CHANGE_RENEWAL_PREF. Used solely to keep your entitlement status accurate; logged in an audit table for compliance and debugging.
We do not collect, see, or have any access to your Apple ID password, your
Apple ID email address (we see only the anonymous appAccountToken),
your billing address, or your country of residence beyond what Apple may
disclose to us indirectly through the regional pricing tier of the purchased
product.
2.5 Anonymous account creation after purchase
When you make a purchase in 12levels (subscription or one-time), the Service automatically creates an anonymous server-side record so that we can:
- Link your subscription to a stable identifier across app reinstalls
- Save your learning progress to enable recovery on device transfer or reinstall
- Send you to the correct account when you later sign in with Apple, Google, or email
This anonymous record contains:
- A unique device identifier (the UUID described in Section 2.1, generated on first launch and stored in your iOS Keychain)
- Your subscription state (linked via Apple's
appAccountToken) - Your learning progress (vocabulary, streaks, library, reading sessions) — only items you actively created after purchase
This anonymous record does not contain:
- Your email, name, Apple ID, or any directly identifying information
- Any data we did not collect through your active use of the app
Until you sign in with Apple, Google, or email, the anonymous record is identified by a randomly generated UUID. This is a pseudonymous identifier, not proof of anonymity: it identifies the account/device within 12levels and is also used for purchase recovery. When you later sign in, the same record is upgraded in place (the UUID is retained as the primary key) and your chosen sign-in identity (Apple ID, Google account, or email) is attached. You can permanently delete this record at any time via Profile → Delete Account.
If you neither make a purchase nor choose to sign in, no 12levels account or learning-progress record is created on the backend. Product analytics and diagnostics described in Sections 2.3 and 5.2 may still be transmitted from a guest session; local learning data otherwise remains on your device.
We retain anonymous records as long as the linked subscription is active. After subscription expiry (and absent any further activity), the anonymous record is automatically purged within 365 days.
3. Purposes of Processing
- Providing learning functionality — adaptive learning algorithms and personalized content selection based on your level and progress
- Saving progress across devices — backend synchronization
- Subscription management — verifying payment status with Apple, gating Pro features, processing renewal/refund/cancellation events
- Account recovery — via email if device is lost
- Service improvement — pseudonymous, account/device-linked product analytics and diagnostics for feature evaluation, reliability and UX improvement
- Legal compliance — tax reporting, retention of subscription records, responding to lawful requests
4. Legal Bases (GDPR Article 6)
- Consent — where the app presents an optional permission or an explicit just-in-time disclosure
- Contract performance — to provide learning, synchronization and subscription functionality, including verifying purchases and granting Pro entitlements
- Legitimate interest — for proportionate product analytics, reliability diagnostics, security (preventing fraud and abuse), and keeping subscription state consistent via Apple webhook processing; you may object by contacting us
- Legal obligation — for tax and other regulatory reporting
5. Sharing With Third Parties
5.1 Infrastructure and hosting
- Cloudflare — DNS, CDN, WAF, backend hosting (Containers + Workers), object storage (R2)
- Supabase — managed PostgreSQL database
- Apple Inc. (USA) — App Store, In-App Purchase (payment processor), push notifications, App Store Server Notifications V2 (webhook source for subscription lifecycle events), and Sign in with Apple (if you choose it)
- Google LLC (USA) — Sign in with Google identity provider, only if you choose to sign in with Google; processes your Google account email and name solely to authenticate you
- Resend — transactional email delivery (account recovery, important notifications)
5.2 Product analytics, diagnostics and support
- Apple MetricKit — anonymous, aggregated diagnostic data, processed by Apple
- PostHog Cloud EU (Frankfurt, Germany) — product analytics described in Section 2.3. Events use a random device identifier and, after provisioning/sign-in, the internal User ID. Tracking, advertising, session replay, surveys, element autocapture, screen autocapture, error autocapture and PostHog SDK swizzling are disabled. A project-level setting must discard stored client IP data.
- Sentry (Functional Software, Inc., USA) — crash reporting, performance monitoring, diagnostic breadcrumbs and optional feedback text. Diagnostics are linked to your internal User ID (UUID) for debugging; no email, name, payment credentials or request/response bodies are intentionally sent. Performance traces are sampled (about 10% in production).
5.3 AI features
The external-AI story and verification features are disabled in this release; this version does not send your answers or story directions to OpenAI, Anthropic or another third-party AI provider. Apple Translation and supported Apple Intelligence features run through Apple-provided system frameworks.
Before any future release sends personal data or user-authored text to a third-party AI provider, 12levels will name that provider in a just-in-time disclosure, explain what will be sent and why, request explicit permission, and update this Policy and the App Store privacy disclosures. Text is always transmitted as entered, so removing account fields alone would not make it anonymous if a user typed personal information into the text itself.
6. Data Retention
- Account and learning data — while your account exists. When in-app deletion succeeds, the primary database records and private R2 avatar versions are deleted immediately; residual processor or backup copies are removed within 30 days, except for the records below
- Backups — age out no later than 90 days after deletion and are not restored into active use except for disaster recovery
- Subscription transaction records and Apple webhook events — 5 years per tax law and to enable refund / dispute handling
- PostHog product analytics — up to 12 months; deleting an account first queues deletion of the linked PostHog person and all prior events
- Sentry diagnostics and feedback — up to 90 days, unless a shorter deletion is required by law or requested and technically identifiable
7. Your Rights
Under applicable law, you have the right to:
- Access your personal data and receive a copy
- Request correction or erasure of your data
- Withdraw consent (which may limit functionality)
- Restrict or object to processing
- Data portability (receive your data in a machine-readable format)
- Lodge a complaint with a supervisory authority
- Delete your account directly in the app: Profile → Delete Account
Deleting your account removes primary learning/account data, private avatars, and queues erasure of linked PostHog analytics; asynchronous processor and backup removal completes within 30 days. It does not automatically cancel your active Apple subscription — you must cancel it separately through Apple's subscription management (Settings → [your name] → Subscriptions). Records of past subscription transactions are retained for tax compliance as described in Section 6.
To exercise your rights, send a request to [email protected]. We respond within 30 days.
8. Security
- TLS 1.3 encryption in transit
- Tokens stored in device Keychain
- Password hashing (bcrypt)
- Apple JWS receipts cryptographically verified server-side against Apple Root CA before any entitlement is granted
- Idempotent processing of Apple webhooks via unique
notificationUUIDdeduplication - Regular dependency updates and vulnerability scanning
- Data minimization (we collect only what is necessary)
- Explicitly disabled analytics autocapture, replay, surveys and advertising/tracking features
9. Children
The Service is not intended for children under 13. The catalog can contain age-labelled fictional themes such as danger, violence, death or alcohol; the App Store age-rating questionnaire and in-app content metadata govern availability. If we learn that a user under 13 has created an account without parental consent, we will delete it. We do not knowingly sell paid subscriptions to children under 13.
10. Changes to This Policy
We may update this Policy. Material changes (expanded data categories, new purposes or recipients) will be notified in the app and may require renewed consent. The version and effective date are shown at the top.
11. Governing Law
For users in the European Union or the EEA, Regulation (EU) 2016/679 (GDPR) applies.
For all other users, the laws of the Republic of Armenia apply (the country of the Controller's registration), without prejudice to mandatory consumer protection provisions of the user's country of residence.
12. Contact
For all data protection inquiries:
Email: [email protected]
Website: https://12levels.app