Privacy Policy
Last updated: July 14, 2026
1. Data Controller
The data controller is Denys Nehometianov, operating the Polski B1 website (hereinafter: “Service”), available at polishb1.pl, and publishing the Polski B1 mobile application for iOS / iPadOS (hereinafter: “App”).
Contact: kontakt@polishb1.pl
The controller has not appointed a Data Protection Officer.
2. Purposes and Legal Basis for Data Processing (website)
| Purpose | Data | Legal basis |
|---|---|---|
| Newsletter (email subscription via Brevo) | Email address | Art. 6(1)(a) GDPR (consent) |
| Session cookies | Session identifier | Art. 6(1)(f) GDPR (legitimate interest — security) |
| Security and abuse prevention | IP address, device information | Art. 6(1)(f) GDPR (legitimate interest) |
| Google Ads (conversion tracking) | Cookies, click identifier | Art. 6(1)(a) GDPR (consent) |
Website account (sign-in)
Sign-in and accounts apply only to the polishb1.pl website — the mobile app still works without any account (see section 3). Signing in is optional: AI-graded exercises also work without an account after a short captcha verification (see “Guest AI features” below) — signing in removes the captcha; all other exercises always work without signing in. When you sign in with Google we receive and store your email address, name, profile picture and Google account ID, together with sign-in timestamps and your acceptance of the Terms and Privacy Policy. Legal basis: Art. 6(1)(b) GDPR (providing the AI feature you request) and Art. 6(1)(a) GDPR (consent to sign in).
We also store your email as an irreversible hash to enforce a daily AI limit (40 requests per day per account) and prevent abuse — Art. 6(1)(f) GDPR; this hash remains even if you delete and re-create your account. Your answers and recordings are sent to OpenAI for grading without any user identifier (anonymous to OpenAI), exactly as in the app. Account data is kept until you delete the account — you can do so from the profile page on the website or by writing to kontakt@polishb1.pl.
Guest AI features — Cloudflare Turnstile captcha
You can use AI-graded exercises without an account. Before a guest submission we ask you to pass a short captcha (Cloudflare Turnstile), which distinguishes humans from bots. During verification Cloudflare, Inc. processes technical data such as your IP address and browser/device signals; we receive only a single-use pass token. Legal basis: Art. 6(1)(f) GDPR (legitimate interest — abuse prevention). Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR; proof: https://www.cloudflare.com/privacypolicy/ and the official list https://www.dataprivacyframework.gov/list).
To enforce the daily guest AI limit we derive an irreversible hash of your IP address (for IPv6 — the /64 network) as a technical counter identifier — Art. 6(1)(f) GDPR; the hash cannot be reversed back to your IP address. Guest answers and recordings reach OpenAI without any user identifier — exactly as for signed-in users.
3. Polski B1 mobile application
This section covers the Polski B1 app for iOS / iPadOS. The app does not require account creation — all learning progress is stored locally on your device (SwiftData) and optionally synced through iCloud across your Apple devices (a toggle you control in the Profile tab). The administrator has no access to your progress or answers.
The app handles the following data categories:
| Category | Data | Purpose | Legal basis |
|---|---|---|---|
| Written answers | Student-typed text (writing tasks, dialogues, grammar transformations, photo descriptions) | AI grading | Art. 6(1)(b) GDPR (performance of contract) |
| Voice recordings | Short speaking-task recordings (Mówienie, Monolog) | Speech-to-text transcription (Whisper) and AI grading of the transcript | Art. 6(1)(b) GDPR |
| Learning progress | Exercise results, daily stats | Progress tracking (strictly local + iCloud) | Art. 6(1)(b) GDPR |
| Diagnostics | Device attestation (Firebase App Check), crash info | API abuse prevention | Art. 6(1)(f) GDPR |
AI processing (third parties)
Your text and voice submissions are forwarded to a single AI grading provider without any user identifier — every request is anonymous and unlinkable to you:
- OpenAI Ireland Ltd. — the only provider that processes user-submitted content. It receives all written text (writing tasks, grammar transformations, photo descriptions, dialogue practice) for substantive grading, and all voice recordings for speech-to-text transcription (Whisper). The EU controller is OpenAI Ireland Ltd.; processing may take place in the US. OpenAI is not certified under the EU-U.S. Data Privacy Framework, so the transfer relies on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) together with a Transfer Impact Assessment (proof: https://openai.com/policies/eu-privacy-policy/); a data processing agreement (Art. 28 GDPR) has been concluded with OpenAI. OpenAI commits that API data is not used for model training and is deleted within at most 30 days.
The technical intermediary is our backend hosted on Fly.io, Inc. (a US company), server region Stockholm (Sweden). Because Fly.io is a US company, any transfer to the US relies on the EU-U.S. Data Privacy Framework (adequacy decision, Art. 45 GDPR; Fly.io is certified — proof: https://fly.io/legal/data-privacy-framework/). The backend does not persist your answers or recordings — it proxies them to OpenAI and returns the result.
Text-to-speech providers (TTS) — do not receive your recordings or answers
The app plays Polish voice recordings in listening exercises and character lines. The audio is synthesised from our own script text and, in the interactive dialogue, from the AI partner’s generated replies (which may refer to the content of your conversation). These services never receive your recordings or the answers you type:
- Microsoft Ireland Operations Ltd. (Azure Speech — TTS) — voice synthesis from our text (EU region — West Europe, Netherlands). Receives no recordings or answers of yours. The provider is Microsoft Corporation; any transfers to the US rely on the EU-U.S. Data Privacy Framework (adequacy decision, Art. 45 GDPR; Microsoft is certified — proof: https://www.microsoft.com/en-us/privacy/microsoft-data-privacy-framework-covered-entities and the official list https://www.dataprivacyframework.gov/list).
- Amazon Web Services, Inc. (AWS Polly) — voice synthesis (Polish female voices; EU region — Frankfurt, eu-central-1). Receives no recordings or answers of yours. The provider is Amazon.com, Inc. (AWS is a DPF-certified entity); any transfers to the US rely on the EU-U.S. Data Privacy Framework (Art. 45 GDPR — proof: https://aws.amazon.com/compliance/eu-us-data-privacy-framework/).
Firebase App Check
The app uses Firebase App Check (Google Ireland Ltd.) to verify that requests originate from an authentic app install and not from scripts. To our understanding, the short-lived token issued by App Check contains no direct user identifier. When Google services are used, however, technical data such as the IP address and device/browser information may be processed. Where data is thereby transferred to Google LLC in the US, the transfer relies on the EU-U.S. Data Privacy Framework (adequacy decision, Art. 45 GDPR; Google is certified — proof: https://policies.google.com/privacy/frameworks). The same basis applies to Google Ads and Google Analytics on the website.
Children’s data
The app is aimed at learners preparing for the Polish B1 exam — typically adults or teenagers. We do not knowingly collect data from children under 13. If you notice a child using the app without a parent’s consent, write to kontakt@polishb1.pl and we will delete the associated data without delay.
4. Data Recipients
The website relies on the following providers:
- Brevo (Sendinblue SAS) — newsletter management and storage of subscriber email addresses (EU — France)
- Google Ireland Ltd. — website advertising, conversion tracking and traffic analysis (Google Ads, Google Analytics) — only with your consent (cookie banner); transfers to Google LLC in the US rely on the EU-U.S. Data Privacy Framework (Art. 45 GDPR; proof: https://policies.google.com/privacy/frameworks)
- Fly.io, Inc. — website and app-backend hosting — Fly.io, Inc. is a US company; the server region is Stockholm (Sweden), and transfers to the US rely on the EU-U.S. Data Privacy Framework (Art. 45 GDPR; proof: https://fly.io/legal/data-privacy-framework/)
- Cloudflare, Inc. (Turnstile) — captcha verification (Turnstile) for AI features without sign-in — processes the IP address and browser signals during verification; Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR; proof: https://www.cloudflare.com/privacypolicy/)
The app relies on the following providers — clearly indicating which of them receive your data and which do not:
| Recipient | Purpose | Receives user data? | Location |
|---|---|---|---|
| OpenAI Ireland Ltd. | Text grading + Whisper transcription | Yes — text and recordings | EU / US (SCCs + TIA) |
| Microsoft Azure Speech (TTS) | Voice synthesis from our script text | No | EU (West Europe) / US (DPF) |
| Amazon Web Services (AWS Polly) | Voice synthesis (female voices) | No | EU (Frankfurt) / US (DPF) |
| Google Ireland Ltd. (Firebase App Check) | Device attestation for app requests | Attestation token, no personal data | EU / US (DPF) |
| Apple Distribution International Ltd. (iCloud) | Syncing user progress | Yes, but directly from the device — not via our backend | EU |
5. Data Transfers
Part of the processing takes place within the EU (France — Brevo; Stockholm/Sweden — the Fly.io server region; West Europe/Netherlands — Azure Speech; Frankfurt/Germany — AWS Polly; Ireland — Apple iCloud). Several recipients, however, are US companies or transfer data to the US. For Fly.io, Inc. (hosting), Microsoft Corporation (Azure Speech), Amazon.com, Inc. (AWS Polly), Google LLC (Firebase App Check; Google Ads/Analytics) and Cloudflare, Inc. (Turnstile captcha), the transfer relies on the EU-U.S. Data Privacy Framework (adequacy decision, Art. 45 GDPR — these companies are DPF-certified; official list: https://www.dataprivacyframework.gov/list), and our data-processing agreements with these providers additionally include Standard Contractual Clauses as a fallback mechanism. For OpenAI (text grading and Whisper transcription) there is no DPF certification — the transfer relies on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) together with a Transfer Impact Assessment; the EU controller is OpenAI Ireland Ltd. The TTS providers (Azure, Polly) do not receive your recordings or answers — they synthesise audio from our script text and from the AI partner’s replies in the dialogue; the proof links for each transfer basis are in sections 3 and 4.
6. Data Retention
- Newsletter (email) — stored until the user unsubscribes from the mailing list
- Session cookies — expire on browser close or after 30 days
- Server logs — stored for 30 days
- Text and recordings forwarded to OpenAI — streamed through and not retained by our server. OpenAI commits to deletion within at most 30 days.
- Azure Speech (TTS), AWS Polly — receive only our script text and the AI partner’s replies in the dialogue; they do not store your data.
- Guest identifier (IP hash) for the AI limit — an irreversible hash of the IP address used solely as the daily guest AI-request counter; it cannot be reversed back to the IP address.
- Learning progress (SwiftData + iCloud) — stored locally on your device and in your iCloud until you delete them (progress never reaches our servers).
7. User Rights
Under the GDPR, you have the following rights:
- Right of access to your data (Art. 15)
- Right to rectification of your data (Art. 16)
- Right to erasure — “right to be forgotten” (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object to processing (Art. 21)
To exercise your rights, contact us at: kontakt@polishb1.pl
8. Withdrawal of Consent
If data processing is based on consent, you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.
9. Right to Complain
You have the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl.
10. Cookies and local storage
The Service uses cookies and browser local storage for the following purposes:
- Essential — session cookies to maintain sessions (no consent required)
- Functional (local, in your browser) — To provide the features you use, we store strictly necessary data locally in your browser (localStorage/sessionStorage): your exercise answers and progress, your cookie-consent state and the selected language. The sign-in feature also sets necessary session and security cookies (NextAuth, CSRF protection). These are strictly technically necessary (Art. 399 of the Polish Electronic Communications Law of 12 July 2024), need no consent and are not transmitted to us.
- Analytics & marketing — Google Analytics (traffic analysis) and Google Ads (conversion tracking) — require user consent; we use no ad personalization or remarketing
A consent banner is displayed on first visit to request permission for analytics and marketing cookies. You can withdraw or change your consent at any time — click the “Cookie settings” link in the page footer to reopen the banner (withdrawing consent is as easy as giving it, Art. 7(3) GDPR). You can additionally manage cookies in your browser settings.
11. Voluntary Data Provision
Providing personal data is voluntary. Subscribing to the newsletter only requires an email address.
12. Changes to Privacy Policy
The controller reserves the right to amend this Privacy Policy. Users will be notified of significant changes via a notice on the Service. The current version is always available on this page.
