Privacy Policy

Zamiro · Chumo · Pizmon · Effective date: July 12, 2026 · Last updated: August 15, 2026

This Privacy Policy applies to the mobile apps Zamiro (Spanish and French), Chumo (Korean), and Pizmon (Hebrew) (together, the "Apps"). The Apps are operated by Zamiro ("we", "us", or "our"), an independent developer based in Israel, and share one account system. This policy explains what personal data we collect, why we collect it, how we use and share it, and the rights you have over it.

Summary (not a substitute for the full policy): We collect your email and sign-in details to run your account, your learning activity (saved words, reviews, progress) to make the Apps work, and limited analytics and crash data to improve them. Optional speech answers on review cards use your microphone and the device's speech service; we do not store recordings. We do not sell your personal data, we do not show third-party advertising, and you can delete your account and all your data from inside any of the Apps at any time — deletion applies across all three.
  1. Who we are
  2. Shared accounts
  3. Data we collect
  4. How and why we use your data
  5. Third-party services and data sharing
  6. Legal bases (GDPR/UK GDPR)
  7. Where your data is stored and international transfers
  8. How long we keep your data
  9. Your rights
  10. Additional information for California residents
  11. Children's privacy
  12. Security
  13. Changes to this policy
  14. Contact

1. Who we are

The Apps are operated by Zamiro, an independent developer based in Israel (the "data controller" for the purposes of the GDPR).

For any privacy question or request, contact us at maria@zamiro.io.

2. Shared accounts

Zamiro, Chumo, and Pizmon share one user account. Signing in with the same email or Apple/Google account in more than one App uses the same login. Learning progress (vocabulary, reviews, streaks, comprehension) is kept per language and is not mixed. Subscriptions are per App — Zamiro Pro does not unlock Chumo or Pizmon, and vice versa.

Deleting your account in any App (Profile → Delete account) deletes the account everywhere: all three Apps, all languages, all progress. Cancel each App's subscription separately in your Apple ID or Google Play subscription settings before or after deletion; deleting the account does not cancel store subscriptions.

3. Data we collect

3.1 Data you give us

DataWhen
Email address and password (stored only as a secure hash)When you register with email
Apple or Google account identifier and, if you share it, the email associated with that accountWhen you sign in with Apple or Google
Which App you are using (Zamiro, Chumo, or Pizmon), target language, and self-assessed levelDuring onboarding
Birth yearOnly if you choose to disable the explicit-content filter (used solely to verify you are 18 or older)

3.2 Data created as you use the Apps

DataPurpose
Learning activity: words you tap, save, or mark as known; spaced-repetition review history and grades; per-song comprehension progress; streaks; favorites; songs you open or importThis is the core of the product — your progress must be stored so it syncs across sessions and devices
Subscription status (free or premium, expiry date)To unlock paid features you purchased
App version, platform (iOS/Android), time zone, and which App you are usingSent with requests so the service works correctly (e.g., your streak counts days in your local time zone; free-tier limits and subscriptions are applied per App)

3.3 Data collected automatically

DataTool
Usage analytics: in-app events such as "song opened", "word saved", "review completed", with related identifiers (e.g., song and word IDs). Event data does not include your name, email, or lyric text.PostHog
Crash and error reports: stack traces, device model, OS version, app versionSentry
Standard server logs: IP address, request timestamps, endpoints called (used for security, rate limiting, and debugging; lyric content is never written to logs)Our servers

3.4 Optional speech answers

On review cards you may tap to answer by speaking. That uses the microphone and the device's speech-recognition service (on iOS, Apple's). Audio is used only to transcribe your answer in that moment. We do not store recordings, and we do not use speech data for analytics. You can always type instead, and you can refuse the microphone permission.

3.5 Data we do not collect

4. How and why we use your data

We do not sell your personal data, we do not share it for cross-context behavioral advertising, and we do not use it to train AI models.

5. Third-party services and data sharing

We share data only with the service providers below, only as needed to run the Apps. Each acts under its own privacy policy:

ServiceRoleData involved
Apple App Store / Google PlayPayment processing and sign-inPurchase transactions (handled by them); sign-in identity tokens
RevenueCatSubscription managementAn app-specific user ID and subscription events (no email, no payment details)
PostHogProduct analyticsUsage events as described in section 3.3
SentryCrash and error reportingCrash reports and device/app metadata
OneSignalPush notifications (e.g., review reminders, streak alerts)A push token, an app-specific user ID, and non-identifying app state used to time reminders (e.g., learning language, streak count). Notifications require your explicit OS-level permission and can be disabled anytime in system settings. Marketing emails are separate and sent only if you opt in inside the app.
Apple (speech recognition)Optional spoken answers on review cardsIf you choose to speak an answer, audio is processed by the device speech service; we do not receive or store the recording
YouTube (Google)Music video playback via the official embedded YouTube playerWhen you play a song, the embedded player connects to YouTube/Google, which may collect data (e.g., IP address, viewing activity) under Google's own privacy policy — the same as watching an embedded video on any website
MusixmatchLicensed lyrics catalogSong search and lookup requests needed to fetch lyrics; these are made by our servers and are not tied to your identity by Musixmatch
Hetzner Online GmbHServer hosting (Germany, EU)All server-side data listed above is stored on infrastructure they host

We may also disclose data if required by law, to protect our legal rights, or as part of a business transfer (in which case this policy continues to apply and we will notify you of any change of controller).

If you are in the European Economic Area or the United Kingdom, we process your data on these bases:

7. Where your data is stored and international transfers

Our servers and database are hosted by Hetzner in Germany (European Union), and encrypted backups are kept within the EU. Some of our service providers (e.g., RevenueCat, Sentry, PostHog, Google) may process data in the United States or other countries. Where data leaves the EEA/UK, transfers rely on safeguards such as the EU Standard Contractual Clauses or the EU–US Data Privacy Framework, as applicable to each provider.

We operate from Israel. The European Commission has recognized Israel as providing an adequate level of data protection (an "adequacy decision"), so access to your data from Israel does not require additional transfer safeguards under the GDPR.

8. How long we keep your data

9. Your rights

Depending on where you live, you have some or all of the following rights:

To exercise any right, email maria@zamiro.io. We will respond within 30 days (or the period required by your local law). We may need to verify your identity — normally by confirming control of the email on your account. If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority.

10. Additional information for California residents

Under the CCPA/CPRA, California residents have the rights to know, correct, and delete personal information, the right to opt out of "sale" or "sharing" of personal information, and the right not to be discriminated against for exercising these rights.

11. Children's privacy

The Apps are not directed at children under 13, and you must be at least 13 years old to create an account (or older where your country sets a higher minimum age of digital consent — see the Terms of Use). We do not knowingly collect personal data from children under 13. If you believe a child under 13 has created an account, contact us at maria@zamiro.io and we will delete it.

Songs flagged as containing explicit lyrics are hidden by default and can only be shown by users who have confirmed a birth year indicating they are 18 or older.

12. Security

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.

13. Changes to this policy

We may update this policy as the Apps evolve. For material changes we will notify you in the Apps before the change takes effect. The "Last updated" date at the top always reflects the current version. Continued use of any App after a change takes effect means the updated policy applies.

14. Contact

Questions, requests, or complaints: maria@zamiro.io