Worbi Privacy

Privacy Policy

Last updated 27 July 2026

Worbi is a spaced-repetition vocabulary app. This policy explains what we collect, why we are allowed to, who processes it on our behalf, how long we keep it, and how you stay in control.

Who can use Worbi

Worbi is not directed to children under 13. You must be at least 13 years old (or older where your country sets a higher minimum age for consenting to online services) to create an account.

What we collect

Why we may use it

Under the GDPR we need a legal basis for each purpose. Ours are:

We do not make decisions about you by automated means that produce legal or similarly significant effects, and we do not profile you for advertising.

What we do not do

We do not sell your data, we show no ads, and we run no analytics on your behaviour. Worbi ships with no advertising or tracking SDKs.

Crash and error reporting

When something breaks we collect diagnostics so we can fix it. Both apps use Firebase Crashlytics, which is enabled by default (including in guest mode) and sends crash details together with technical device information and, on Android, the app’s per-install identifier and your internal account ID when signed in. You can turn crash reporting off at any time in the app under Profile → About. Neither app ships analytics or advertising SDKs. On our servers we use Sentry; those reports identify your account by its internal ID only, never by your email address or IP. Our server request logs are pseudonymised. They reference your account by ID and never store your email address in the clear.

Who processes your data

We use a small number of processors to run the service:

Your account data and learning content are stored in the European Union. Where a processor above transfers data outside the EU, that transfer relies on the European Commission’s standard contractual clauses or an adequacy decision.

How long we keep it

We keep your account data for as long as your account exists. IP addresses are erased after 90 days. Server request logs are removed automatically within a few days, and email delivery logs within 90 days. Encrypted backups are kept for up to 7 days, so deleted data can persist in backups for up to that long. Administrative audit records that reference an account are kept for up to 365 days for security and accountability. Crash reports already sent to Firebase, and error events in Sentry, age out under those providers’ retention periods (around 90 days). Records we are legally required to keep (for example accounting records for purchases) are retained for the legally required period only.

Your rights

You can exercise most of these yourself in the app, and we will answer any request within one month:

Deletion removes your content, your uploads, and your personal details. Aggregate community counts remain, and your display name can stay visible in notifications already delivered to other users.

Changes to this policy

We update this policy when the service or the law changes. The date at the top always reflects the current version. If a change materially affects how we use your data, we will tell you in the app or by email before it takes effect, and where the law requires it we will ask for your consent.

Who is responsible, and contact

Worbi is operated by Rasoul Miri, Hammarby allé 48, 120 61 Stockholm, Sweden, the data controller for the processing described here. Questions about your data or this policy? Email privacy@worbi.se. You also have the right to complain to the Swedish Authority for Privacy Protection (IMY), or to the supervisory authority in your own country.