Skip to content

Privacy

What we store about you, who else sees it, and how to delete all of it. Last updated 2026-09-14.

Who we are

Katalava is a Modern Greek course. It is a personal project run by one individual, who is the person responsible for the data described here — there is no company behind it.

If you have a question, a request or a complaint about your data, write to privacy@katalava.app.

This policy was last updated on 2026-09-14.

The short version

The rest of this page is the detail. This is the whole of it in six lines.

  • You need an account to study. The landing page and the entire grammar reference are readable without one.
  • We store what the course needs in order to teach you, plus a small number of counts that tell us whether the course actually works.
  • There are no ads and nothing that follows you around other websites. Page views are counted, by a privacy-preserving counter our host runs, which sets no cookie. We do not sell your data and we do not share it for advertising.
  • Billing is not switched on, so we hold no payment or card information whatsoever.
  • Nothing you write is fed to an AI system.
  • You can delete your account yourself, and it really does delete.

What we collect

Five groups, and this is all of them.

  • Your accountYour name, your email address, whether that address has been confirmed, and whether you are an ordinary learner or the site owner. If you sign in with a password, we store only a scrambled (hashed) version of it and never the password itself. If you sign in with Google, we store the link to your Google account and the sign-in tokens Google issues for it.
  • Security recordsEach sign-in creates a session record, which includes the IP address and browser user-agent it was created from. We also keep short-lived tokens for confirming your address and resetting your password, and counters that limit how often one address can hit sensitive pages.
  • Your learningWhich lessons you have finished, your review schedule and how you rated each card, every exercise attempt — including the exact answer text you type, right or wrong — your mistakes, exam results, the topics you have tested out of, your XP and streak, the goal you chose, and your settings.
  • Product eventsA small timestamped note when one of these happens: you create an account; you sign in; you open the app; you finish a lesson; you choose a learning goal, or skip the question; you tell us you can already read the Greek alphabet; your speech is transcribed during a speaking drill. Each carries a little context and nothing more. These feed one private dashboard that only the owner can open, and they answer three questions: how many people signed up, how many are studying each day and week, and how many are still here two weeks later.
  • Page viewsWhich page was opened, the site that linked you there, and coarse things like country, browser and device type. No cookie is set and nothing is stored on your device. The visitor is worked out from a one-way scramble of the request itself, which is thrown away within a day — so it cannot be connected to another visit after that, it cannot follow you to other sites, and it is never tied to your account. The web address is stripped of anything after the question mark before it is counted, so a confirmation or password-reset link can never be recorded. This runs on every page whether or not you are signed in, and it answers one question: does anyone find this course, and where from.

Speaking practice

The speaking drill records a short clip in your browser so it can check what you said.

By default that clip is transcribed by your browser's own speech recognition. In some browsers — Chrome in particular — that means the audio is sent to the browser maker's servers. That is your browser's behaviour rather than ours, we cannot see or control it, and we mention it because you would reasonably want to know.

There is also an optional hosted transcription engine, run by OpenAI. It is switched off in production today. If it is ever switched on, the clip is sent to OpenAI to be turned into text and is not stored by us afterwards.

Either way, the only thing we keep is a per-day count of how many transcriptions you ran, so the feature cannot run up a bill or be abused.

Cookies and local storage

One cookie, and it is the one that keeps you signed in. It is checked against the database on every request that matters, with a short cache of a few minutes so that ordinary page loads are quick.

Your browser also stores three small preferences locally, which never leave your device: your light or dark mode, your colour palette, and a one-time note that you have already imported progress from the old offline version of the app.

There are no advertising or tracking cookies, and the page-view counter described above sets no cookie at all. The fonts are served from our own domain — they are bundled when the site is built, not fetched from Google when you open a page.

Email we send

Two kinds, and nothing else. No newsletter, and your address is never passed to anyone for marketing.

  • Account emailConfirming your email address, and resetting your password. We send these because you asked us to, and you cannot switch them off while you have an account — without them you could not get back in.
  • Encouragement emailThere are two: a short nudge a few days after you sign up, if you have not been back, and a heads-up when your daily streak is about to lapse. This is switched on by default, and you get at most one message of each kind per day. You can switch it off in Settings, under Notifications, or with the one-click unsubscribe link at the bottom of every one of these messages. Switching it off never affects confirming your address or resetting your password.

Why we are allowed to

For readers in Europe, these are the legal bases we rely on.

  • Performing our agreement with youRunning your account and teaching you the course — your progress, your review schedule and your settings exist because that is the thing you signed up for.
  • Legitimate interestsKeeping the service secure and rate-limited, understanding in aggregate whether the course works and whether anyone can find it at all, and gently encouraging a learner who has stopped to come back. In each case we have weighed that against what you would reasonably expect, which is why the counts are small, the dashboard is private, and the encouragement mail is one click from off.
  • ConsentWhere the law where you live requires consent for the encouragement email rather than an opt-out, that is what the setting records. Withdraw it at any time in Settings or by unsubscribing.
  • Legal obligationsWhere we are required to keep or produce something by law.

Who else sees it

These companies, for these reasons, and no one else. We do not sell your data to anybody.

  • VercelHosts the site and runs its server code. Its platform logs record the IP address and browser user-agent of requests, as any web host's do. It also runs the page-view counter described above, which sets no cookie and keeps no lasting identifier.
  • NeonRuns the database that holds your account and everything you do in the course.
  • ResendDelivers our email. It receives the address we are writing to and the contents of the message.
  • CloudflareStores the course's audio recordings. Your browser downloads them directly, so Cloudflare sees the IP address and user-agent of those requests.
  • GoogleSigns you in, and tells us your name and email address when it does. Only if you choose the “Continue with Google” button. If you use a password, Google is not involved at all.
  • OpenAITranscribes the short clip you record in a speaking drill. It is not kept afterwards. Only if the optional hosted speaking engine is switched on. It is switched off today, so no recording of yours reaches OpenAI.

Where your data is

Your data sits with the providers listed above, on infrastructure in the European Union and/or the United States depending on the region each service is configured in.

Where data leaves the European Economic Area, the transfer relies on the standard contractual clauses those providers publish, which is the mechanism European law provides for exactly this.

How long we keep it

Your account and everything you have learned stay for as long as the account does. That is the point of them: a review schedule you cannot look back on is not a review schedule.

  • A link for confirming your address stops working after 48 hours; a password reset link stops working after about an hour, and is then deleted.
  • Sign-in sessions expire on their own.
  • Deleting your account removes the rest immediately — see the next section.
  • Database backups keep a short point-in-time window, during which a copy of a deleted row may still exist in the backup before it rolls off.
  • Our hosting and email providers keep their own request and delivery logs under their own retention policies.

Deleting your account

In Settings, at the bottom, there is a Danger Zone with a delete button. You do not have to ask us.

For safety it asks for your password first, or a recent sign-in if you use Google — so that somebody who walks up to an unlocked laptop cannot erase your course.

It deletes every row we hold about you: your settings, your progress, every attempt and its answer text, your review history, your mistakes and exam results, your XP and streak, the product events above, your transcription counts, and your email preference and send history. The database enforces the same removal underneath as a second guarantee.

There is no undo and no recovery window. If you want a copy of anything, take it first.

The site owner can also delete an account, using exactly the same mechanism.

Your rights

If you are in the UK or the European Economic Area you have the following rights, and we will honour them wherever you are.

  • Access — a copy of what we hold about you.
  • Correction — fixing anything inaccurate.
  • Erasure — deleting it. The in-app delete does this immediately and completely.
  • Restriction — asking us to stop using it while something is in dispute.
  • Objection — objecting to processing we base on legitimate interests.
  • Portability — receiving your data in a machine-readable form.
  • Withdrawing consent — for the encouragement email, at any time, in Settings or by unsubscribing.
  • Complaining to a supervisory authority — in the European Economic Area, your national data-protection authority; in the UK, the Information Commissioner's Office. We would rather you told us first, but it is your right either way.

How to exercise those rights

For erasure, use the delete button in Settings — it is faster than asking us and it is final.

For anything else, write to privacy@katalava.app. We will answer within 30 days, and usually much sooner — there is one person reading that address, and they would like to help.

How we protect it

Passwords are hashed and never stored in a readable form, so nobody — including us — can read yours.

Everything travels over an encrypted connection.

Sign-in sessions live in the database rather than only in your browser, which means they can actually be revoked.

Signing in and other sensitive actions are rate-limited, so an attacker cannot guess at them repeatedly.

Administrative access is limited to the project owner.

Children

The course is not intended for children under 16, and we do not knowingly create accounts for them. If you believe a child has created an account, write to us and we will remove it.

Changes to this policy

If we change this policy, the date at the top changes with it.

If a change materially affects what we do with data we already hold, we will say so by email rather than leaving you to notice.