Privacy Policy
Last updated 29 August 2026
Worbi is a spaced-repetition vocabulary app. This policy explains what we collect, why we are allowed to, who processes it on our behalf, how long we keep it, and how you stay in control.
Who can use Worbi
Worbi is not directed to children under 13. You must be at least 13 years old (or older where your country sets a higher minimum age for consenting to online services) to create an account.
What we collect
- Account details. Your email address, your display name, and (if you add one) a short profile bio.
- Profile photo. Optional. If you upload one, its metadata, including any location your camera recorded, is stripped on your device before the photo is sent.
- Your learning content. The folders, collections, and cards you create, and your review history (which cards you have studied and how they scored).
- Device details. To keep your account secure we record basic device information (model, operating system, app version, and language) and a per-install identifier. We also record the IP address you sign in from.
- Community activity. If you publish a collection, vote, or comment, that content is public together with your display name. Please do not put personal information into content you intend to publish.
- Usage data. Pseudonymous product events describing how the app is used: for example which screens are opened, which study sessions are started, completed, or abandoned, when an account is created or signed in to, when a card is created or imported and from which source, which free-plan limits are reached, and which plan is chosen at the paywall. Each event carries a name, a timestamp, a temporary session identifier, short single-token screen and source labels, counts and durations, your app version, platform, language and region (for example sv-SE), whether you are signed in, and whether you are on the free or Premium plan. It never carries your words, your cards, your collection titles, or anything you typed. See Product analytics below.
- Purchases. If you buy Worbi Premium, we receive purchase evidence from Apple or Google (product, transaction identifiers, and subscription status) and verify it on our server to grant Premium access. Apple or Google processes your payment, and we never receive your card or bank details.
Why we may use it
Under the GDPR we need a legal basis for each purpose. Ours are:
- To provide the service you asked for. Creating and running your account, storing and syncing your learning content, operating community features you choose to use, and verifying and honouring purchases. Legal basis: performance of a contract with you.
- To keep Worbi secure and working. Device records, sign-in IP addresses, request logs, server-side error reporting, abuse and fraud prevention, and moderating reported content. Legal basis: our legitimate interest in a secure, functioning, and lawful service.
- To diagnose crashes and understand how Worbi is used. On-device diagnostics (Firebase Crashlytics, Google Analytics for Firebase, and Firebase Performance) and our pseudonymous product-analytics events, which show where people get stuck, which features go unused, and where a study session is abandoned, so we can fix the app rather than guess at it. Legal basis: your consent, which we ask for once and record with the date and policy version. All of it is off until you opt in, and you can withdraw at any time in the app under Profile → Privacy & legal.
- To send you transactional email. Account verification, password reset, and share invitations you or another user triggered. Legal basis: performance of a contract, and our legitimate interest in account security.
- To send push notifications. Study reminders, where you have enabled them. Legal basis: your consent, which you can withdraw at any time in the app or in your device settings.
- To meet legal obligations. For example retaining accounting records for purchases. Legal basis: compliance with a legal obligation.
We do not make decisions about you by automated means that produce legal or similarly significant effects, and we do not profile you for advertising.
What we do not do
We do not sell your data and we show no ads. Worbi ships with no advertising SDK: the diagnostics and analytics SDKs we use (Firebase, only after you opt in) run for stability and product improvement, never for advertising, and no advertising identifier is collected. We do not build advertising profiles, and we do not share your data with data brokers or ad networks.
Crash and error reporting
When something breaks we collect diagnostics so we can fix it. Both apps use Firebase Crashlytics, Google Analytics for Firebase and Firebase Performance Monitoring. These are off by default and collect nothing until you opt in: we ask you once, and you can change your choice at any time in the app under Profile → Privacy & legal. When switched on they send crash details, anonymous performance measurements and anonymous usage events, together with technical device information and, when signed in, your internal account ID. No advertising identifier is collected and neither app ships an advertising SDK. Firebase is provided by Google and may process this data outside the EU (see below). On our servers we use Sentry; those reports identify your account by its internal ID only, never by your email address or IP. Our server request logs are pseudonymised. They reference your account by ID and never store your email address in the clear.
Product analytics
To improve Worbi we record pseudonymous product events, for example: an app open, an onboarding step, an account created or signed in to, continuing as a guest and later upgrading to an account, a collection opened, a study session started, completed, or abandoned, a card created or imported and the source it came from, a free-plan limit reached, a paywall shown, a plan chosen, a purchase attempted. Each event carries its name, a timestamp, a session identifier covering one visit, and a small set of labels and counts such as the study mode, the number of cards seen, or the name of the limit that was reached. Every label is one short token, no spaces. Our server refuses anything else, so ordinary text you typed cannot be stored. We never record the words you study, your card contents, your collection titles, your notes, or your searches.
The session identifier is renewed after you have been away from the app for half an hour, and survives a short switch to another app.
Events are linked to your device’s per-install identifier, and to your internal account identifier when you are signed in. Events also carry whether you are on the free or Premium plan. If you use Worbi as a guest and later create an account, the events from that device in the previous 30 days are attached to the new account so the picture of your first days is not broken in two. Legal basis: your consent, which we ask for once and record with the date and policy version. Nothing is recorded until you give it.
Turning it on or off. We ask once, after onboarding, whether we may collect diagnostics and usage data. You can change your mind at any time in Profile → Privacy & legal under Send diagnostics. Switching it off stops recording immediately, deletes the events still queued on the device, and tells our server. One batch already on its way may still arrive. The setting belongs to the device, not to the account, so a device that has withdrawn stays silent even if you sign in with a different account or delete your account altogether.
Where it goes and how long we keep it. Events reach our own server first. We forward them to PostHog, which analyses them for us as a processor under a data processing agreement, on its European Union cloud region. Raw events on our server are deleted after 90 days. If you delete your account, the events linked to it are deleted with it, and we ask PostHog to delete the matching person as well. Events recorded before you signed up, which were never linked to an account, stay keyed to the device identifier until the 90-day deletion reaches them. Aggregate counts that identify nobody may remain.
Who processes your data
We use a small number of processors to run the service:
- Firebase (Google). Crash reporting, performance monitoring and product analytics on both platforms (only after you opt in), and push-notification delivery. Google LLC processes this data, which may be transferred to the United States. That transfer relies on Google’s certification under the EU–US Data Privacy Framework and on the standard contractual clauses in Google’s data processing terms.
- Apple / Google. Sign-in (where offered), push delivery, and purchase processing and verification, under their own terms.
- Sentry. Server-side error reporting.
- PostHog. Product analytics, on its European Union cloud region, as our processor under a data processing agreement.
- Brevo. Sending transactional email (for example account verification and password reset).
- Zoho. Hosting the mailboxes that receive your privacy and support correspondence, in the European Union.
- Cloudflare. Storing our encrypted offsite backups (database and uploads) in a European Union bucket (Cloudflare R2).
- Hetzner. Hosting our servers and database, in the European Union.
Your account data and learning content are stored in the European Union. Where a processor above transfers data outside the EU, that transfer relies on the European Commission’s standard contractual clauses or an adequacy decision, including the EU–US Data Privacy Framework for United States recipients such as Google. Cloudflare stores our backups in its EU region; as a US-headquartered provider it processes them under the standard contractual clauses in its data processing addendum.
How long we keep it
We keep your account data for as long as your account exists. IP addresses are erased after 90 days. Raw product events are deleted after 90 days. Server request logs are removed automatically within 14 days, and email delivery logs within 90 days. Backups are transmitted over TLS and stored in the European Union: on the server for up to 7 days, and in offsite storage (Cloudflare R2, EU region) for up to 90 days, so deleted data can persist in a backup for up to 90 days before it is rotated out. Administrative audit records that reference an account are kept for up to 365 days for security and accountability. Crash reports already sent to Firebase, and error events in Sentry, age out under those providers’ retention periods (around 90 days). If you switch diagnostics off, we keep a small suppression record (your device identifier only) so that device stays silent; that record is not tied to your account and is retained for as long as the app is in use. Records we are legally required to keep (for example accounting records for purchases) are retained for the legally required period only.
Your rights
You can exercise most of these yourself in the app, and we will answer any request within one month:
- Access and portability. Download everything we hold about you, as machine-readable JSON, from Profile → Account → Export.
- Erasure. Permanently delete your account from Profile → Account. See our account deletion page.
- Rectification. Correct your display name, bio, and photo from your profile; email privacy@worbi.se for anything you cannot edit yourself.
- Withdraw consent. Diagnostics and product analytics run only on your consent. Turn them off at any time under Profile → Privacy & legal (Send diagnostics); this stops collection for that device and is recorded. Withdrawing does not affect processing that already happened.
- Restriction. Ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
- Objection. Where we process your data on the basis of our legitimate interests, you can object and we will stop unless we have compelling legitimate grounds to continue. Email privacy@worbi.se.
- Withdrawing consent. Turn off push notifications at any time in the app or in your device settings. Withdrawing does not affect processing that already happened.
Deletion removes your content, your uploads, and your personal details. Aggregate community counts remain, and your display name can stay visible in notifications already delivered to other users.
Changes to this policy
We update this policy when the service or the law changes. The date at the top always reflects the current version. If a change materially affects how we use your data, we will tell you in the app or by email before it takes effect, and where the law requires it we will ask for your consent.
Who is responsible, and contact
Worbi is operated by Rasoul Miri, Hammarby allé 48, 120 61 Stockholm, Sweden, the data controller for the processing described here. Questions about your data or this policy? Email privacy@worbi.se. You also have the right to complain to the Swedish Authority for Privacy Protection (IMY), or to the supervisory authority in your own country.