Polski B1

Privacy Policy

Last updated: July 14, 2026

1. Data Controller

The data controller is Denys Nehometianov, operating the Polski B1 website (hereinafter: “Service”), available at polishb1.pl, and publishing the Polski B1 mobile application for iOS / iPadOS (hereinafter: “App”).

Contact: kontakt@polishb1.pl

The controller has not appointed a Data Protection Officer.

2. Purposes and Legal Basis for Data Processing (website)

PurposeDataLegal basis
Newsletter (email subscription via Brevo)Email addressArt. 6(1)(a) GDPR (consent)
Session cookiesSession identifierArt. 6(1)(f) GDPR (legitimate interest — security)
Security and abuse preventionIP address, device informationArt. 6(1)(f) GDPR (legitimate interest)
Google Ads (conversion tracking)Cookies, click identifierArt. 6(1)(a) GDPR (consent)

Website account (sign-in)

Sign-in and accounts apply only to the polishb1.pl website — the mobile app still works without any account (see section 3). Signing in is optional: AI-graded exercises also work without an account after a short captcha verification (see “Guest AI features” below) — signing in removes the captcha; all other exercises always work without signing in. When you sign in with Google we receive and store your email address, name, profile picture and Google account ID, together with sign-in timestamps and your acceptance of the Terms and Privacy Policy. Legal basis: Art. 6(1)(b) GDPR (providing the AI feature you request) and Art. 6(1)(a) GDPR (consent to sign in).

We also store your email as an irreversible hash to enforce a daily AI limit (40 requests per day per account) and prevent abuse — Art. 6(1)(f) GDPR; this hash remains even if you delete and re-create your account. Your answers and recordings are sent to OpenAI for grading without any user identifier (anonymous to OpenAI), exactly as in the app. Account data is kept until you delete the account — you can do so from the profile page on the website or by writing to kontakt@polishb1.pl.

Guest AI features — Cloudflare Turnstile captcha

You can use AI-graded exercises without an account. Before a guest submission we ask you to pass a short captcha (Cloudflare Turnstile), which distinguishes humans from bots. During verification Cloudflare, Inc. processes technical data such as your IP address and browser/device signals; we receive only a single-use pass token. Legal basis: Art. 6(1)(f) GDPR (legitimate interest — abuse prevention). Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR; proof: https://www.cloudflare.com/privacypolicy/ and the official list https://www.dataprivacyframework.gov/list).

To enforce the daily guest AI limit we derive an irreversible hash of your IP address (for IPv6 — the /64 network) as a technical counter identifier — Art. 6(1)(f) GDPR; the hash cannot be reversed back to your IP address. Guest answers and recordings reach OpenAI without any user identifier — exactly as for signed-in users.

3. Polski B1 mobile application

This section covers the Polski B1 app for iOS / iPadOS. The app does not require account creation — all learning progress is stored locally on your device (SwiftData) and optionally synced through iCloud across your Apple devices (a toggle you control in the Profile tab). The administrator has no access to your progress or answers.

The app handles the following data categories:

CategoryDataPurposeLegal basis
Written answersStudent-typed text (writing tasks, dialogues, grammar transformations, photo descriptions)AI gradingArt. 6(1)(b) GDPR (performance of contract)
Voice recordingsShort speaking-task recordings (Mówienie, Monolog)Speech-to-text transcription (Whisper) and AI grading of the transcriptArt. 6(1)(b) GDPR
Learning progressExercise results, daily statsProgress tracking (strictly local + iCloud)Art. 6(1)(b) GDPR
DiagnosticsDevice attestation (Firebase App Check), crash infoAPI abuse preventionArt. 6(1)(f) GDPR

AI processing (third parties)

Your text and voice submissions are forwarded to a single AI grading provider without any user identifier — every request is anonymous and unlinkable to you:

  • OpenAI Ireland Ltd.the only provider that processes user-submitted content. It receives all written text (writing tasks, grammar transformations, photo descriptions, dialogue practice) for substantive grading, and all voice recordings for speech-to-text transcription (Whisper). The EU controller is OpenAI Ireland Ltd.; processing may take place in the US. OpenAI is not certified under the EU-U.S. Data Privacy Framework, so the transfer relies on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) together with a Transfer Impact Assessment (proof: https://openai.com/policies/eu-privacy-policy/); a data processing agreement (Art. 28 GDPR) has been concluded with OpenAI. OpenAI commits that API data is not used for model training and is deleted within at most 30 days.

The technical intermediary is our backend hosted on Fly.io, Inc. (a US company), server region Stockholm (Sweden). Because Fly.io is a US company, any transfer to the US relies on the EU-U.S. Data Privacy Framework (adequacy decision, Art. 45 GDPR; Fly.io is certified — proof: https://fly.io/legal/data-privacy-framework/). The backend does not persist your answers or recordings — it proxies them to OpenAI and returns the result.

Text-to-speech providers (TTS) — do not receive your recordings or answers

The app plays Polish voice recordings in listening exercises and character lines. The audio is synthesised from our own script text and, in the interactive dialogue, from the AI partner’s generated replies (which may refer to the content of your conversation). These services never receive your recordings or the answers you type:

Firebase App Check

The app uses Firebase App Check (Google Ireland Ltd.) to verify that requests originate from an authentic app install and not from scripts. To our understanding, the short-lived token issued by App Check contains no direct user identifier. When Google services are used, however, technical data such as the IP address and device/browser information may be processed. Where data is thereby transferred to Google LLC in the US, the transfer relies on the EU-U.S. Data Privacy Framework (adequacy decision, Art. 45 GDPR; Google is certified — proof: https://policies.google.com/privacy/frameworks). The same basis applies to Google Ads and Google Analytics on the website.

Children’s data

The app is aimed at learners preparing for the Polish B1 exam — typically adults or teenagers. We do not knowingly collect data from children under 13. If you notice a child using the app without a parent’s consent, write to kontakt@polishb1.pl and we will delete the associated data without delay.

4. Data Recipients

The website relies on the following providers:

  • Brevo (Sendinblue SAS)newsletter management and storage of subscriber email addresses (EU — France)
  • Google Ireland Ltd.website advertising, conversion tracking and traffic analysis (Google Ads, Google Analytics) — only with your consent (cookie banner); transfers to Google LLC in the US rely on the EU-U.S. Data Privacy Framework (Art. 45 GDPR; proof: https://policies.google.com/privacy/frameworks)
  • Fly.io, Inc.website and app-backend hosting — Fly.io, Inc. is a US company; the server region is Stockholm (Sweden), and transfers to the US rely on the EU-U.S. Data Privacy Framework (Art. 45 GDPR; proof: https://fly.io/legal/data-privacy-framework/)
  • Cloudflare, Inc. (Turnstile)captcha verification (Turnstile) for AI features without sign-in — processes the IP address and browser signals during verification; Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR; proof: https://www.cloudflare.com/privacypolicy/)

The app relies on the following providers — clearly indicating which of them receive your data and which do not:

RecipientPurposeReceives user data?Location
OpenAI Ireland Ltd.Text grading + Whisper transcriptionYes — text and recordingsEU / US (SCCs + TIA)
Microsoft Azure Speech (TTS)Voice synthesis from our script textNoEU (West Europe) / US (DPF)
Amazon Web Services (AWS Polly)Voice synthesis (female voices)NoEU (Frankfurt) / US (DPF)
Google Ireland Ltd. (Firebase App Check)Device attestation for app requestsAttestation token, no personal dataEU / US (DPF)
Apple Distribution International Ltd. (iCloud)Syncing user progressYes, but directly from the device — not via our backendEU

5. Data Transfers

Part of the processing takes place within the EU (France — Brevo; Stockholm/Sweden — the Fly.io server region; West Europe/Netherlands — Azure Speech; Frankfurt/Germany — AWS Polly; Ireland — Apple iCloud). Several recipients, however, are US companies or transfer data to the US. For Fly.io, Inc. (hosting), Microsoft Corporation (Azure Speech), Amazon.com, Inc. (AWS Polly), Google LLC (Firebase App Check; Google Ads/Analytics) and Cloudflare, Inc. (Turnstile captcha), the transfer relies on the EU-U.S. Data Privacy Framework (adequacy decision, Art. 45 GDPR — these companies are DPF-certified; official list: https://www.dataprivacyframework.gov/list), and our data-processing agreements with these providers additionally include Standard Contractual Clauses as a fallback mechanism. For OpenAI (text grading and Whisper transcription) there is no DPF certification — the transfer relies on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) together with a Transfer Impact Assessment; the EU controller is OpenAI Ireland Ltd. The TTS providers (Azure, Polly) do not receive your recordings or answers — they synthesise audio from our script text and from the AI partner’s replies in the dialogue; the proof links for each transfer basis are in sections 3 and 4.

6. Data Retention

  • Newsletter (email)stored until the user unsubscribes from the mailing list
  • Session cookiesexpire on browser close or after 30 days
  • Server logsstored for 30 days
  • Text and recordings forwarded to OpenAIstreamed through and not retained by our server. OpenAI commits to deletion within at most 30 days.
  • Azure Speech (TTS), AWS Pollyreceive only our script text and the AI partner’s replies in the dialogue; they do not store your data.
  • Guest identifier (IP hash) for the AI limitan irreversible hash of the IP address used solely as the daily guest AI-request counter; it cannot be reversed back to the IP address.
  • Learning progress (SwiftData + iCloud)stored locally on your device and in your iCloud until you delete them (progress never reaches our servers).

7. User Rights

Under the GDPR, you have the following rights:

  • Right of access to your data (Art. 15)
  • Right to rectification of your data (Art. 16)
  • Right to erasure — “right to be forgotten” (Art. 17)
  • Right to restriction of processing (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object to processing (Art. 21)

To exercise your rights, contact us at: kontakt@polishb1.pl

8. Withdrawal of Consent

If data processing is based on consent, you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.

9. Right to Complain

You have the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl.

10. Cookies and local storage

The Service uses cookies and browser local storage for the following purposes:

  • Essentialsession cookies to maintain sessions (no consent required)
  • Functional (local, in your browser)To provide the features you use, we store strictly necessary data locally in your browser (localStorage/sessionStorage): your exercise answers and progress, your cookie-consent state and the selected language. The sign-in feature also sets necessary session and security cookies (NextAuth, CSRF protection). These are strictly technically necessary (Art. 399 of the Polish Electronic Communications Law of 12 July 2024), need no consent and are not transmitted to us.
  • Analytics & marketingGoogle Analytics (traffic analysis) and Google Ads (conversion tracking) — require user consent; we use no ad personalization or remarketing

A consent banner is displayed on first visit to request permission for analytics and marketing cookies. You can withdraw or change your consent at any time — click the “Cookie settings” link in the page footer to reopen the banner (withdrawing consent is as easy as giving it, Art. 7(3) GDPR). You can additionally manage cookies in your browser settings.

11. Voluntary Data Provision

Providing personal data is voluntary. Subscribing to the newsletter only requires an email address.

12. Changes to Privacy Policy

The controller reserves the right to amend this Privacy Policy. Users will be notified of significant changes via a notice on the Service. The current version is always available on this page.