Privacy Policy
Last updated: August 2026 · Version 1
1. Who Is Responsible
Stefan Lehner
Full contact details: Legal Notice
Email: privacy@simplevoc.de
2. Data We Process and Why
| Data | Purpose | Legal basis |
|---|---|---|
| Email address, display name | Account creation and sign-in | Art. 6(1)(b) GDPR |
| Vocabulary entries (words, sentences, translations) | Core service — your personal vocabulary collection | Art. 6(1)(b) GDPR |
| App settings (language preferences) | Providing a personalised experience | Art. 6(1)(b) GDPR |
| Usage count (number of words added) | Enforcing free-tier limits and premium entitlements | Art. 6(1)(b) GDPR |
| Voice recording (live audio stream) | Speech-to-text transcription by AssemblyAI — only when cloud speech recognition is switched on (see Section 4) | Art. 6(1)(b) GDPR |
| Transcribed or typed text | AI word extraction and translation via Vertex AI (Gemini) in Google's EU region — see Section 4.2 | Art. 6(1)(b) GDPR |
| Crash diagnostics (error and device data) | Finding and fixing app crashes and failed recordings — only when you switch crash reporting on (off by default, see Section 7) | Art. 6(1)(a) GDPR |
| Purchase & subscription status (not processed during the early-adopter phase) |
Verifying premium access | Art. 6(1)(b) GDPR |
| Year of birth (stays on your device) |
Deciding whether the two consent-based features may be offered to you at all — the age check required by Art. 8 GDPR (see Section 14). We never receive this value: it is stored on your device and is not sent to us, to any provider, or into your account | Art. 6(1)(c) GDPR |
| Anonymous device identifier | Quota tracking before sign-in; preventing abuse | Art. 6(1)(f) GDPR |
| Device attestation data (App Check) | Verifying requests come from the genuine app; fraud prevention | Art. 6(1)(f) GDPR |
| Server log data (IP address, timestamp, requested function, status) | Recorded automatically whenever the app contacts our backend — operational security, fault diagnosis, abuse prevention (see Section 10) | Art. 6(1)(f) GDPR |
We do not collect location data, contacts, browsing history, or advertising identifiers. We do not use your data for advertising.
3. Account & Authentication
You can register using Google Sign-In or Sign in with Apple, or continue anonymously as a guest. When you use Google Sign-In or Sign in with Apple, the respective provider shares your email address and display name with us.
All authentication is handled by Firebase Authentication (Google Cloud EMEA Limited, Ireland). Legal basis: Art. 6(1)(b) GDPR — necessary to perform the service contract.
Firebase Authentication is a sign-in and authentication service provided by Google. Under our cloud agreement the contracting entity is Google Cloud EMEA Limited (Ireland); Google LLC and other Google affiliates act as subprocessors (see Section 11). To simplify the sign-in and authentication process, Firebase Authentication may use third-party identity providers and store the information on its platform.
Using simplevoc with an account. We use Google's service so that information can be stored on a per-user basis. Knowing a user's identity is what allows our app to store their data securely in the cloud.
Using simplevoc as a guest (without an account). In guest mode we create an anonymous session (Firebase Anonymous Authentication) that has no email address or name attached to it. Your vocabulary and settings are then stored only on your device and are not uploaded to our cloud (see Section 8); the anonymous identifier is used solely for quota tracking and abuse prevention. When you later choose “Save data” and sign in with Google or Apple, your on-device vocabulary is uploaded to your account so it can be backed up and synced across devices. If you delete a guest session (Settings → Delete Account), the locally stored vocabulary is removed from your device.
4. Speech Recognition & AI Processing
Turning a spoken sentence into flashcards happens in two steps: first your speech is transcribed to text, then that text is analysed and translated. The two steps use different providers.
4.1 Step 1 — Speech to text
Under 16 there is no choice to make: the setting is not offered, and speech input runs on your device's own recognition. Nothing is streamed to AssemblyAI, and no session token is even requested. See Section 14.
Cloud speech recognition (AssemblyAI). While you are recording, the audio is streamed live over an encrypted WebSocket connection directly from your device to AssemblyAI's European endpoint (streaming.eu.assemblyai.com) and transcribed in real time. The details:
- Our backend never receives your audio. It only mints a short-lived, single-use session token (valid for a few minutes) so that your device can connect without our API key ever being exposed. The audio itself goes to AssemblyAI, not to us, and we do not store any recording.
- Transcription happens in AssemblyAI's EU infrastructure, and audio is processed for the duration of the session only. Processing stays within the EU; AssemblyAI does not commit to a specific member state.
- No model training, and nothing kept afterwards. Our account is opted out of AssemblyAI's model improvement program, so neither your audio nor the resulting transcript is used to train their models. That opt-out also activates zero data retention for streaming sessions: audio and transcript are not retained once the session ends. The transcript reaches your device over the WebSocket connection and is not stored for later retrieval. AssemblyAI keeps limited session metadata for logging and billing purposes.
- As with any internet connection, AssemblyAI necessarily sees the IP address of your device. The session token is not linked to your name or email address.
- Cloud transcription is used for the languages supported by the version you are using.
- If the feature is switched off, no connection to AssemblyAI is established.
- Should the service be unavailable, simplevoc automatically switches to on-device speech-to-text processing.
On-device speech recognition. In this mode your device transcribes the recording with the speech recognition engine built into the operating system:
- iOS — Apple Speech Recognition (SFSpeechRecognizer). Depending on the device, language, and Apple's own settings, Apple may perform recognition on the device or on Apple servers.
- Android — the system SpeechRecognizer API. Depending on the device and its settings, Android performs recognition on the device or via Google's speech service.
Legal basis for transcription: Art. 6(1)(b) GDPR — processing your recording is how the service you requested is provided. Microphone access itself is based on your consent via the system permission dialog (Art. 6(1)(a) GDPR) and can be withdrawn at any time.
4.2 Step 2 — Word extraction & translation (Google Vertex AI)
The transcribed text — or the text you typed instead of speaking — is sent to our backend (Firebase Cloud Functions in europe-west1), which forwards it to Google Vertex AI for word extraction and translation. For some languages the text first passes through our own linguistic pre-processing service (based on spaCy and Wiktionary) running on Google Cloud Run in europe-west1. Dictionary data used for word sense disambiguation is partly based on Wiktionary content, provided by the WikDict project and published under the Creative Commons licence CC BY-SA. No personal data is processed in the course of this.
We use Vertex AI on Google Cloud, pinned to Google's EU multi-region. The text is therefore processed inside the EU, as are our own backend components (Cloud Functions, Cloud Run), which remain in europe-west1. Our backend enforces this rather than merely intending it: it refuses to start at all if it is configured for any region outside the EU.
Google has committed contractually not to use submitted data to train its AI models. Google Cloud EMEA Limited engages Google LLC and other Google affiliates as subprocessors, so access from outside the EU/EEA — for support and administration — cannot be ruled out; those onward transfers are covered by Google's Cloud Data Processing Addendum, which incorporates the Standard Contractual Clauses approved by the European Commission, and Google LLC is certified under the EU–US Data Privacy Framework. Legal basis: Art. 6(1)(b) GDPR.
Important: Please do not include sensitive personal data (names, addresses, health information, or identification numbers) in vocabulary you record. The app is designed for learning words and sentences, not for storing personal documents.
4.3 What the AI does — and where it can be wrong
You are interacting with an AI system. It reads the words and sentences you record, works out which words to save, translates them into your target language, and generates practice material such as example sentences and conjugation exercises.
AI output can be wrong. A translation may be inaccurate, miss a shade of meaning, choose the wrong sense of an ambiguous word, or simply be confidently mistaken. Treat what you see as a study aid, not as an authoritative translation — where it matters, check a dictionary or ask someone who speaks the language.
Nothing is decided about you. The AI works on the language you give it, not on you. It does not build a profile of you, does not score or rank you, and no decision with legal or similarly significant effect is made about you by automated means (see Section 13).
The result stays in your hands. Every entry can be edited or deleted in your collection at any time, and your correction replaces whatever the AI produced.
5. Subscriptions & In-App Purchases
During the current early-adopter phase no purchases take place (see the Terms of Use, section 3): the app does not initialise the purchase SDK, and no purchase or payment data is transmitted to any payment or subscription provider. The following applies once subscriptions are offered.
Premium subscriptions are managed by RevenueCat, Inc. RevenueCat receives anonymised user identifiers, purchase history, and subscription status. It does not receive direct payment information — payment is processed entirely by Apple (App Store) or Google (Play Store).
Legal basis: Art. 6(1)(b) GDPR for contract performance; Art. 6(1)(c) GDPR for legal retention obligations.
6. Device Permissions
simplevoc requests the following device permissions:
- Microphone — to capture your voice for vocabulary input. You are asked for it the first time you tap the record button, not when the app starts: the permission dialog is where you consent to microphone access, so it appears at the moment you ask for the feature and never before. Where the recording is transcribed depends on the cloud speech-to-text setting described in Section 4: streamed to AssemblyAI when it is on, processed by your device when it is off. We never store a recording on our servers.
- Speech Recognition (iOS) — required for the on-device path, where Apple's framework (SFSpeechRecognizer) converts your spoken words to text.
- Speech Recognition (Android) — required for the on-device path, where the system SpeechRecognizer API converts your spoken words to text.
- Notifications — for the optional daily “time to learn” reminder. This reminder is purely local: it is scheduled by your device's operating system, the reminder time is stored only on your device, and no push token, device identifier, or notification content is sent to us or to any third party. We operate no push service. You are asked for this permission once, after the introductory tutorial, and you can decline without affecting any other function.
You can revoke microphone or notification permission at any time in your device or system settings. Cloud transcription can be switched off in the app under Settings → Speech input, and the daily reminder under Settings → Notifications → Daily reminder. Legal basis: Art. 6(1)(a) GDPR — your consent via the system permission dialog.
7. App Check & Crash Diagnostics
We use Firebase App Check to verify that requests to our backend originate from the genuine simplevoc app and not from bots or abusive scripts. On iOS, this uses Apple's DeviceCheck/App Attest framework; on Android, Google Play Integrity. These services attest device authenticity without identifying you personally. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in securing the service.
The app can use Firebase Crashlytics to report crashes and technical failures — including recordings that produced no transcript, in which case the technical connection status is reported, never the audio or the recognised text. A crash report contains the error, a stack trace, and general device data (model, operating system version, app version) plus a Crashlytics installation identifier.
Crash reporting is switched off by default. It is only active if you turn it on under Settings → Crash diagnostics → Send crash reports. While it is off, no crash report leaves your device. You can switch it back off at any time in the same place, which stops reporting immediately. Crash reporting is disabled in development builds regardless of this setting. Legal basis: Art. 6(1)(a) GDPR — your consent, given by enabling the switch and withdrawable at any time.
Under 16 the switch is not offered, and no crash report is sent regardless of what was set before (see Section 14).
8. Data Storage & Infrastructure
Depending on whether you are signed in, your vocabulary data is stored in one or two places:
- On your device — in a local database that works without an internet connection. No data is shared from local storage with any third party.
- Google Firestore — in the europe-west1 region (St. Ghislain, Belgium, EU), encrypted at rest and in transit.
Guest mode is device-only. If you use simplevoc as a guest (without an account), your vocabulary and settings are stored only on your device and are never uploaded to Firestore. Cloud storage and cross-device synchronisation begin only once you sign in with an account. (Note: this concerns where your collection is stored — the text you dictate or type is still sent to our backend for AI translation while you use the app, including in guest mode; see Section 4.)
Backend logic runs on Google Cloud Functions and Google Cloud Run, also in europe-west1. All data transmission uses TLS encryption.
9. Data Security
We protect your data with technical and organisational measures appropriate to the risk (Art. 32 GDPR):
- Encryption in transit — all traffic between the app, our backend, and our providers is TLS-encrypted; the speech stream to AssemblyAI runs over an encrypted WebSocket connection.
- Encryption at rest — data stored in Firestore is encrypted on Google's infrastructure.
- Strict access rules — our database rules confine every document to the account that owns it. A signed-in user can read and write their own data and nothing else; there is no collection that can be read across accounts. The app itself may only write a defined set of fields — quota and premium entitlements are written exclusively by our backend.
- App attestation — Firebase App Check rejects requests that do not originate from a genuine, unmodified installation of the app (see Section 7).
- No long-lived credentials on your device — our AssemblyAI API key never reaches the app; your device only ever receives a single-use token valid for a few minutes (see Section 4.1).
- Private backend services — our linguistic processing services on Cloud Run are not publicly reachable and accept requests only from our own Cloud Functions.
- Data minimisation — we store no audio, we do not log the content of your vocabulary, and the app contains no advertising or analytics SDKs.
Data breach notification. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we report it to the competent supervisory authority within 72 hours of becoming aware of it (Art. 33 GDPR). Where the breach is likely to result in a high risk to you, we also inform you directly and without undue delay (Art. 34 GDPR). Where they apply, we make the equivalent notifications required by US state breach-notification laws and by the Australian Notifiable Data Breaches scheme (see Section 18).
No online service can be made perfectly secure. These measures reduce risk; they cannot eliminate it.
10. Server Logs
Whenever the app contacts our backend — to translate a sentence, to request a speech session token, to check your quota, or to load the app configuration — the request is logged automatically by the underlying Google Cloud infrastructure. This happens for every internet service and is not something we switch on deliberately.
A log entry contains the IP address of your device, the timestamp, the function that was called, the response status, and general connection metadata. It does not contain your vocabulary, the text you dictated, or any audio.
These logs live in Google Cloud Logging in europe-west1 and are deleted automatically after 30 days. We do not combine them with your vocabulary collection, we do not use them to build a profile of you, and we do not pass them to anyone.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in operating the service securely, diagnosing faults, and preventing abuse.
11. International Data Transfers
Most processing takes place within the EU/EEA (europe-west1; speech transcription via AssemblyAI's EU endpoint), and our contract for the Google services is itself with an EU entity. Data can nevertheless reach the United States — either because a provider is based there, or because an EU provider engages US affiliates as subprocessors:
- Google Cloud EMEA Limited (Dublin, Ireland) — our processor for Firebase, Firebase Authentication, Crashlytics, Cloud Functions, Cloud Run and Vertex AI. That contract is intra-EU and needs no Art. 46 safeguard of its own. Google Cloud EMEA Limited engages Google LLC and other Google affiliates as subprocessors, so data can still be processed in the United States; those onward transfers are covered by Google's Cloud Data Processing Addendum, which incorporates the Standard Contractual Clauses, and Google LLC is certified under the EU–US Data Privacy Framework (adequacy decision)
- AssemblyAI, Inc. (cloud speech-to-text) — processing takes place on the EU endpoint; for the company's US-based access, Standard Contractual Clauses and a data processing agreement apply
- Apple Inc. (Sign in with Apple, App Attest) — Apple acts as an independent controller for these services rather than as our processor: you authenticate with Apple directly, and Apple's own terms and transfer safeguards govern that processing. We do not pass your data to Apple under a contract of ours.
- RevenueCat, Inc. — Standard Contractual Clauses
These safeguards ensure an equivalent level of data protection to that within the EU, as required by Art. 46 GDPR.
12. Data Retention
Voice recordings are not retained. Audio is transcribed while you speak and is not stored by us — neither on our servers nor as a file on your device. What remains is the resulting text, as part of your vocabulary collection.
Beyond that, we keep each category of data only for as long as it serves its purpose:
| Data | Retention |
|---|---|
| Vocabulary, conjugation exercises, settings, account | For as long as your account exists — and deleted automatically after 24 months without a sign-in (see below) |
| Voice recordings | Not stored at all — transcribed as you speak, then discarded |
| Server logs (incl. IP address) | 30 days, then deleted automatically |
| Crash reports | Up to 90 days in Firebase Crashlytics — and only if you switched crash reporting on |
| Billing records | Up to 7 years, where German commercial and tax law requires it |
Deleting your account. When you delete your account (Settings → Delete Account), your vocabulary entries, conjugation exercises, settings, and your Firebase Auth account are removed from our live systems immediately. We keep no separate archive or export of your vocabulary outside that database.
Accounts you stop using. If an account goes 24 months without a sign-in and without any activity, we delete it automatically, along with its vocabulary, conjugation exercises and settings. We do not keep data indefinitely just in case you come back (Art. 5(1)(e) GDPR). A weekly job checks this; deletion is the same as if you had deleted the account yourself, and it cannot be undone. We do not currently send a warning beforehand — simplevoc has no e-mail path to you, and we would rather not build one solely for this. If you want to keep your collection without using the app, signing in once resets the period. Using simplevoc as a guest? Your vocabulary lives only on your device, so nothing of it is ours to delete.
Legal retention obligations may require us to retain certain billing records for up to 7 years (Art. 6(1)(c) GDPR).
13. No Automated Decision-Making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. The spaced-repetition algorithm (FSRS) that schedules your reviews operates entirely on your device and on your own data — it does not profile you or produce legal effects.
14. Children's Privacy
simplevoc is a general-audience app. It is not directed at children, contains no advertising, and does not profile its users.
Minimum age. Under our Terms of Use you must be at least 13 years old to use simplevoc, and users under 18 need the consent of a parent or guardian.
EU/EEA — consent-based features. Two features rely on your consent rather than on contract: cloud speech recognition (and the microphone access it needs) and crash reporting. Under Art. 8 GDPR, the age at which a person can give that consent themselves is set nationally at between 13 and 16 — in Germany it is 16. Rather than rely on a parental consent we have no way of checking, we simply do not offer those two features below that age.
The age question. The app asks you once, during setup, for your year of birth — the year alone, not a full date, because that is all the question needs. What happens with it:
- It stays on your device. The year is saved in the app's local settings. It is not sent to us, not stored in your account, not synced to another device, and not included in a data export. Because it cannot travel with your account, a second device asks the question again.
- Below 16, cloud speech recognition and crash reporting are not offered: the two switches do not appear in Settings, speech input runs on your device's own recognition, and no crash report is sent — whatever may have been set before. Nothing else about the app changes, and no one is turned away: from 13 upwards simplevoc is fully usable.
- From 16, both switches appear in Settings, switched off. Nothing is enabled for you, and you are not prompted about them: turning either on is your decision, taken when you choose to take it.
- We apply the age of 16 — the highest of the national thresholds — to everyone, so the app never has to ask, or guess, which country you are in.
- Because we only ask for the year, the switch-over happens at the turn of the calendar year in which you reach 16, which may be a few months before your birthday. Both features are off by default in any case, so the difference is who is offered a choice, not what is switched on.
- Deleting your account (Settings → Delete Account) clears the app's local settings, and with them the stored year.
United States. We do not knowingly collect personal information from children under 13, as defined by the Children's Online Privacy Protection Act (COPPA). We ask for a year of birth, as described above, purely to apply the age rule on the device — we never receive it — and we ask for no other age or date information. We have no feature that would let a child share information publicly or with other users.
If we find out. If we become aware that we hold personal data from a child below the applicable age without the required parental consent, we delete it promptly.
Parents and guardians. Write to privacy@simplevoc.de to review, correct, or delete your child's data, or to withdraw a consent you gave. Deletion is also available directly in the app under Settings → Delete Account.
15. Your Rights
To exercise any right, contact us at privacy@simplevoc.de. We will respond within one month of receiving your request; for particularly complex requests we may extend this by up to two further months and will tell you why (Art. 12(3) GDPR). Requests under US state privacy law follow a different deadline — see Section 18.1.
16. Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority. The authority competent for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
lda.bayern.de
You may equally complain to the authority in your own country of residence or place of work. A list of EU supervisory authorities is available at edpb.europa.eu. If you live outside the EU/EEA, Section 18 names the authority responsible for your country.
17. Third-Party Services
| Service | Provider | Privacy policy |
|---|---|---|
| Firebase Auth, Firestore, App Check, Cloud Functions, Cloud Run, Crashlytics | Google Cloud EMEA Limited (Ireland) | policies.google.com/privacy |
| Google Sign-In | Google LLC | policies.google.com/privacy |
| AssemblyAI (cloud speech-to-text, EU endpoint — can be switched off in Settings) | AssemblyAI, Inc. | assemblyai.com/legal/privacy-policy |
| Sign in with Apple | Apple Inc. | apple.com/privacy |
| Vertex AI – Gemini (AI word extraction & translation, EU region) | Google Cloud EMEA Limited (Ireland) | cloud.google.com/terms/data-processing-addendum · cloud.google.com/privacy |
| RevenueCat | RevenueCat, Inc. | revenuecat.com/privacy |
| System speech recognition (fallback when cloud speech-to-text is off) — iOS: Apple SFSpeechRecognizer; Android: system SpeechRecognizer | Apple Inc. (iOS), Google (Android) | apple.com/privacy · policies.google.com/privacy |
| App Store / Play Store (app distribution, updates, and the platform's own install and crash statistics — collected by the platform independently of the app) | Apple Inc. (iOS), Google LLC (Android) | apple.com/legal/privacy · policies.google.com/privacy |
| WikDict (dictionary data for word sense detection — no personal data transmitted) | WikDict / Wiktionary contributors | wikdict.com · CC BY-SA |
18. Regional Information
simplevoc is offered in the countries set out in the Terms of Use, section 14.10. Wherever you live, we apply the standard described above as our baseline: the same limits on what we collect, the same processors, the same security measures, and the same ability to see and delete your data. The sections below add rights that apply specifically under the law of your country or state. Where a regional rule gives you more than this policy otherwise offers, the regional rule applies.
18.1 United States
This section applies to residents of US states with comprehensive privacy laws, including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Nevada, Delaware, Iowa, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and Montana. Each state's law applies on its own terms.
Notice at collection. In the past 12 months we have collected the following categories of personal information (categories as defined by the California Consumer Privacy Act):
- Identifiers — email address, display name, anonymous device identifier, IP address
- Internet or other electronic network activity — server logs; crash diagnostics, only if you switch them on
- Audio or similar sensory information — your voice recording, processed while you speak and never stored (see Section 4.1)
- Commercial information — purchase and subscription status. Not currently collected: no purchases take place during the early-adopter phase (see Section 5)
We do not collect precise geolocation, biometric identifiers, government identification numbers, financial account numbers, racial or ethnic origin, religious beliefs, union membership, health information, sexual orientation, or education and employment records.
The year of birth the app asks for during setup is deliberately absent from that list: it is held in the app's local settings on your device and is never transmitted to us, so there is nothing for us to collect, retain, or disclose (see Section 14).
The purpose of each category is set out in Section 2, the sources are you yourself, your sign-in provider (Apple or Google), and your device. Retention is described in Section 12; server logs are kept for 30 days (Section 10).
Your voice is not a biometric identifier. We do not create voiceprints, we do not use your voice to identify or authenticate you, and audio is discarded as soon as it has been transcribed. We therefore do not collect biometric identifiers or biometric information within the meaning of state biometric privacy laws such as the Illinois Biometric Information Privacy Act (BIPA).
Your rights. Subject to your state's law, you have the right to:
- Know and access the personal information we have collected about you, its sources, the purposes, and the categories of third parties we disclose it to
- Obtain a copy of your personal information in a portable, machine-readable format
- Correct inaccurate personal information
- Delete your personal information
- Opt out of the sale or sharing of personal information, of targeted advertising, and of profiling — we do none of these, so there is nothing to opt out of. Because we do not sell or share, there is also no opt-out preference signal (such as Global Privacy Control) for us to act on
- Limit the use of sensitive personal information — we do not collect sensitive personal information for any purpose that triggers this right
- Non-discrimination — we will not deny you service, charge you a different price, or give you a lower quality of service for exercising a privacy right. We offer no financial incentives in exchange for personal information
How to exercise your rights. Email privacy@simplevoc.de from the address associated with your account, or delete everything yourself in the app under Settings → Delete Account. An authorised agent may submit a request on your behalf with written permission; we may still ask you to verify your identity with us directly.
Verification. We verify a request by matching it against the email address on your account. If you use simplevoc as a guest, we hold no data that can be linked to you at all — in that case there is nothing for us to retrieve, correct, or delete, and your vocabulary is removed by deleting the guest session on your device.
Response times. We confirm receipt within 10 business days and respond substantively without undue delay and within 45 days. Where reasonably necessary we may extend once by a further 45 days and will tell you why.
Appeals. If we decline your request and you live in a state that provides an appeal right (including Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Delaware, New Jersey, New Hampshire, Nebraska, Minnesota, Maryland, Kentucky, Rhode Island and Indiana), you may appeal by replying to our decision with “Appeal” in the subject line. We will respond to the appeal within 45 days. If we deny the appeal, we will tell you how to lodge a complaint with your state Attorney General.
18.2 United Kingdom
If you are in the United Kingdom, the UK GDPR and the Data Protection Act 2018 apply. Your rights are the same as those listed in Section 15, and the legal bases in Section 2 apply in their UK GDPR equivalents. Transfers of personal data out of the UK are made under the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
You may lodge a complaint with the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow SK9 5AF — ico.org.uk.
18.3 Switzerland
If you are in Switzerland, the revised Federal Act on Data Protection (revFADP/nDSG) applies alongside this policy. You have the right to information about the data we process, to have inaccurate data corrected, to have data deleted, to object to processing, and to receive your data in a common electronic format. Requests are free of charge.
You may lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC/EDÖB), Feldeggweg 1, 3003 Bern — edoeb.admin.ch.
18.4 Canada
If you are in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) and equivalent provincial laws apply. You may request access to the personal information we hold about you and ask us to correct it. You may lodge a complaint with the Office of the Privacy Commissioner of Canada — priv.gc.ca.
18.5 Australia and New Zealand
If you are in Australia, the Privacy Act 1988 and the Australian Privacy Principles apply. You may request access to your personal information and ask us to correct it. Where a data breach is likely to result in serious harm, we will notify affected users and the regulator in line with the Notifiable Data Breaches scheme. You may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) — oaic.gov.au.
If you are in New Zealand, the Privacy Act 2020 and the Information Privacy Principles apply. You may request access to your personal information and ask us to correct it. We notify the regulator and affected users of a privacy breach that is likely to cause serious harm. You may lodge a complaint with the Office of the Privacy Commissioner — privacy.org.nz.
18.6 Africa
The following applies if you are in one of the African countries in which simplevoc is offered. In each case your rights are at least those set out in Section 15, and you may lodge a complaint with the authority named:
- South Africa — the Protection of Personal Information Act (POPIA). Complaints: Information Regulator. Note that POPIA treats anyone under 18 as a child, so processing requires the consent of a competent person
- Nigeria — the Nigeria Data Protection Act 2023. Complaints: Nigeria Data Protection Commission
- Kenya — the Data Protection Act 2019. Complaints: Office of the Data Protection Commissioner
- Ghana — the Data Protection Act 2012 (Act 843). Complaints: Data Protection Commission
Personal data of users in these countries is processed on our EU infrastructure as described in Sections 8 and 11; the transfer out of your country rests on your contract with us and on our contractual safeguards with our processors.
18.7 Latin America
The following applies if you are in one of the Latin American countries in which simplevoc is offered. Your rights are at least those set out in Section 15; where your national law grants more, that applies.
- Mexico — the Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) of 20 March 2025, which replaced the 2010 law. You hold the ARCO rights: access, rectification, cancellation and opposition, plus withdrawal of consent. The Spanish version of this policy serves as our aviso de privacidad. Since the dissolution of INAI, the competent authority is the Secretaría Anticorrupción y Buen Gobierno
- Argentina — Ley 25.326. Authority: Agencia de Acceso a la Información Pública (AAIP). Argentina is recognised by the European Commission as providing an adequate level of protection
- Uruguay — Ley 18.331. Authority: Unidad Reguladora y de Control de Datos Personales (URCDP). Uruguay also holds an EU adequacy decision
- Colombia — Ley 1581 de 2012. Authority: Superintendencia de Industria y Comercio
- Peru — Ley 29733. Authority: Autoridad Nacional de Protección de Datos Personales
- Chile — Ley 19.628 applies today. Ley 21.719 takes full effect on 1 December 2026, introducing complete ARCO rights, 72-hour breach notification, and a new Agencia de Protección de Datos Personales; we will meet its requirements from that date
- Ecuador — Ley Orgánica de Protección de Datos Personales. Authority: Superintendencia de Protección de Datos Personales
- Costa Rica — Ley 8968 (authority: PRODHAB) · Panama — Ley 81 de 2019 (authority: ANTAI) · Dominican Republic — Ley 172-13 · Paraguay — Ley 7359/2024 and its Agencia de Protección de Datos Personales
- Bolivia, El Salvador, Guatemala, Honduras and Nicaragua — these countries have no comprehensive data protection statute; your constitutional right to privacy and habeas data applies. We apply the GDPR standard described in this policy to you regardless
Personal data of users in these countries is processed on our EU infrastructure as described in Sections 8 and 11; the transfer out of your country rests on your contract with us and on our contractual safeguards with our processors. To exercise any right, write to privacy@simplevoc.de.
18.8 Everywhere else
If you live in a country not named above and its law grants you rights beyond those set out in this policy, write to privacy@simplevoc.de and we will honour them to the extent the law requires.
19. Changes to This Policy
We may update this policy to reflect changes in the service or legal requirements. The date at the top of this page shows the latest revision. For significant changes we will notify users within the app.
20. Contact
Stefan Lehner — simplevoc
privacy@simplevoc.de