Privacy
Privacy notice
What εpsγlo does with your personal data, why, for how long, and what you can ask of us — the information Article 13 of the GDPR requires.
Last updated 14 September 2026
Who is responsible
The controller of your personal data is:
- Name
- Simone Piccagli
- [email protected]
- Certified email (PEC)
- [email protected]
- VAT number (Partita IVA)
- 04407441205
For questions or requests about your personal data, contact [email protected]. This is also the contact for exercising your rights.
What this notice covers
The website, the web app, and the desktop and mobile builds of εpsγlo. They are one product with one account; whichever you use, the data described here is handled the same way and by the same people.
What is processed, and why
Each part of the product handles a different kind of data. Where a feature processes something without keeping it, that is said explicitly — it is the most important fact about several of them.
- Account. Your email address, a sign-in credential (a password hash, a magic-link token, or a Google or SSO identity — never your Google password), and the times you signed in. Needed to have an account at all. If you sign in through an organisation’s SSO, that organisation can see that you are a member of its workspace.
- Translation requests and history. The sentences you translate, the settings you translate them with, and the explained result. They are sent to the language models described below and stored in your account so you can return to them; you can delete any entry, and deleting the account deletes them all.
- Vocabulary and Learn progress. The words and phrases you save, your review schedule, your placement results and lesson progress. Stored in your account so they follow you across devices.
- Critique. Text submitted for correction is processed by the model and returned to your device. We do not store Critique text on our servers.
- Scan. The images and PDF pages you scan are processed in flight — sent to the model, read, and discarded. We keep the extracted text only as part of a translation you chose to keep, never the image.
- Tutor (text). The transcript is stored server-side by design for conversation continuity and service integrity. Deleting the account deletes it, subject to the retention rules below.
- Tutor (live call). Audio is streamed through our relay to Google and back. We do not record or store the audio. We retain call duration and usage metadata to meter the service.
- Billing. Paddle, our merchant of record, processes payments, calculates and remits tax, and holds payment-card data; we do not hold card data. We retain purchase amounts, subscription status, billing identifiers and details needed for invoices, including a business name or VAT number when supplied.
- The device mirror. A copy of your account state (settings, vocabulary, recent translations) is kept on the device, in the browser’s IndexedDB and localStorage, so the app opens instantly and the bank works offline. It is yours to clear; the server copy is the one that counts.
- Security and abuse prevention. Request logs with IP address, timestamps, the endpoint called and the result, kept for a limited time to rate-limit abuse, debug failures and attribute model usage. They are not used to profile you.
- Usage statistics and service improvement. We record which feature you used, when, how much of your allowance it consumed and which model served it — never the content — to meter your plan and to see, in aggregate, which parts of the product are used. We may also review stored translation requests and their results internally to improve prompts, catch failures and check quality. Critique text, scanned images and call audio are never stored, so they are never reviewed. We do not sell this data and do not use it to train third-party models. You can object at any time by writing to [email protected].
- Waitlist. If you join the waitlist before launch, we store your email address, a salted hash of your IP address, and your consent record. An unconfirmed address is deleted after 30 days; a confirmed one is kept until launch or until you ask us to remove it.
We do not sell personal data, run advertising, or use your text to train our own models. Provider processing and retention depend on the applicable service terms and account configuration; contact [email protected] for the safeguards applicable to your data.
The legal bases
- Performance of a contract (Art. 6(1)(b) GDPR) for everything the service consists of: the account, translations, vocabulary, Learn, Critique, Scan, the tutor, and billing.
- Consent (Art. 6(1)(a)) for optional processing that asks for your permission, including any future non-essential storage. You may withdraw consent at any time without affecting earlier lawful processing. Authentication, including Google sign-in and SSO, is used to perform the service contract.
- Legitimate interest (Art. 6(1)(f)) for security, rate limiting, fraud and abuse prevention, and keeping the service working. Our interest here is the one every online service has; your interests are protected by keeping these logs short-lived and using them for nothing else. The same basis covers aggregated usage statistics and internal quality review of translation requests, described above; you may object at any time.
- A legal obligation (Art. 6(1)(c)) for the invoices and payment records Italian tax law requires us to keep.
Who processes it on our behalf
These providers support the service as processors under the applicable data processing agreements. Some also act as independent controllers for their own purposes, such as Paddle, our merchant of record, for payment compliance, tax and fraud prevention, and Google for your Google sign-in account. Their own privacy notices govern those activities.
| Provider | What they do | Where |
|---|---|---|
| Supabase | Hosts the database, the account system (Supabase Auth) and the server functions. | EU region; the company is in the United States. |
| Runs the Gemini models behind Explain, Learn, Scan, the spoken voices (Gemini and Cloud Text-to-Speech), the live call, and the checking steps of the text tutor; and the Cloud Run relay behind the live call. | EU and United States. | |
| OpenRouter and its upstream providers | Routes model calls to third-party hosts. Today the sentences you translate are processed by Google’s Gemma model hosted by Friendli, on every plan, and the text tutor’s replies by Z.ai’s GLM models. Which model a feature uses is decided by the plan, not per person. | United States and the upstream provider’s own region. |
| Paddle | Merchant of record: takes payments, calculates and remits tax, issues invoices and receipts, runs the billing portal, and handles refunds and the right of withdrawal. | United Kingdom and United States. |
| Cloudflare | Serves the website and the app, protects them from attack, runs the Turnstile anti-spam check on the waitlist form, and stores waitlist signups (Cloudflare D1) before launch. | Global network; the company is in the United States. |
| Resend | Sends transactional email: account sign-in links and waitlist confirmation messages. | United States. |
Transfers outside the EU
Providers may process data outside the EU/EEA, including in the United States and other countries used by upstream model providers such as Z.ai. Where applicable, transfers rely on adequacy decisions, including the EU–US Data Privacy Framework for certified recipients, or the European Commission’s Standard Contractual Clauses with supplementary safeguards where required. Contact [email protected] for a copy of the relevant safeguards.
Security and breaches
We use encryption in transit, access controls that limit who can reach the database, and the retention limits described below, to reduce what could ever be exposed. If a personal-data breach is likely to put your rights or freedoms at risk we notify the Garante within 72 hours of becoming aware of it (Art. 33 GDPR), and we tell you directly where the risk to you is high (Art. 34).
How long it is kept
- Account data, translation history, vocabulary, Learn progress and Tutor transcripts are retained for the account lifetime, unless you delete supported items sooner. Request deletion by writing to [email protected] or use the in-app Delete account button in Settings → Privacy & data. Records that must be kept by law are retained separately, with restricted access.
- Paddle billing records, invoices and payment records needed for Italian fiscal obligations are kept for 10 years, including after account deletion. Paddle also retains data under its own legal obligations and privacy notice.
- Security logs: up to 90 days, unless a specific incident requires longer.
- Usage records (feature, time, allowance consumed, model — no content): for the account lifetime; aggregated statistics, which identify nobody, indefinitely.
- Critique text, scanned images and live-call audio: not retained at all — processed and discarded, as described above.
- Waitlist signups: an unconfirmed address is deleted after 30 days; a confirmed address is kept until launch, or deleted on request.
Your rights
Under Articles 15 to 22 of the GDPR you may ask for access to the data held about you, ask for it to be corrected or erased, ask for the processing to be restricted, object to processing based on our legitimate interest, and receive the data you gave us in a portable form. Where processing rests on consent you may withdraw it. One email to [email protected] is enough; we answer within a month, and we may ask you to prove you are the account holder first. If you belong to a Team organisation, deletion may be blocked until you leave it or transfer ownership; the app tells you which.
If you think your data has been handled unlawfully you may lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or with the authority of the EU country where you live or work. You may also seek a judicial remedy.
No decision with legal or similarly significant effects on you is made automatically. The models produce translations and explanations; they do not decide anything about you.
Age
εpsγlo requires users to be at least 14, following the consent threshold for information-society services in art. 2-quinquies of the Codice Privacy. Contact [email protected] if someone younger has opened an account. This threshold does not itself establish capacity to enter a paid contract.
Changes to this notice
When the product changes in a way that changes what is done with your data, this notice is rewritten and the date at the top moves. A change that adds a new purpose or a new recipient for your data is announced at least 30 days before it takes effect, on the site and, for account holders, by email. A correction or clarification that does not change what is done with your data may take effect immediately.
εpsγlo