Privacy Policy
This Privacy Policy applies to the mobile apps Zamiro (Spanish and French), Chumo (Korean), and Pizmon (Hebrew) (together, the "Apps"). The Apps are operated by Zamiro ("we", "us", or "our"), an independent developer based in Israel, and share one account system. This policy explains what personal data we collect, why we collect it, how we use and share it, and the rights you have over it.
- Who we are
- Shared accounts
- Data we collect
- How and why we use your data
- Third-party services and data sharing
- Legal bases (GDPR/UK GDPR)
- Where your data is stored and international transfers
- How long we keep your data
- Your rights
- Additional information for California residents
- Children's privacy
- Security
- Changes to this policy
- Contact
1. Who we are
The Apps are operated by Zamiro, an independent developer based in Israel (the "data controller" for the purposes of the GDPR).
For any privacy question or request, contact us at maria@zamiro.io.
2. Shared accounts
Zamiro, Chumo, and Pizmon share one user account. Signing in with the same email or Apple/Google account in more than one App uses the same login. Learning progress (vocabulary, reviews, streaks, comprehension) is kept per language and is not mixed. Subscriptions are per App — Zamiro Pro does not unlock Chumo or Pizmon, and vice versa.
Deleting your account in any App (Profile → Delete account) deletes the account everywhere: all three Apps, all languages, all progress. Cancel each App's subscription separately in your Apple ID or Google Play subscription settings before or after deletion; deleting the account does not cancel store subscriptions.
3. Data we collect
3.1 Data you give us
| Data | When |
|---|---|
| Email address and password (stored only as a secure hash) | When you register with email |
| Apple or Google account identifier and, if you share it, the email associated with that account | When you sign in with Apple or Google |
| Which App you are using (Zamiro, Chumo, or Pizmon), target language, and self-assessed level | During onboarding |
| Birth year | Only if you choose to disable the explicit-content filter (used solely to verify you are 18 or older) |
3.2 Data created as you use the Apps
| Data | Purpose |
|---|---|
| Learning activity: words you tap, save, or mark as known; spaced-repetition review history and grades; per-song comprehension progress; streaks; favorites; songs you open or import | This is the core of the product — your progress must be stored so it syncs across sessions and devices |
| Subscription status (free or premium, expiry date) | To unlock paid features you purchased |
| App version, platform (iOS/Android), time zone, and which App you are using | Sent with requests so the service works correctly (e.g., your streak counts days in your local time zone; free-tier limits and subscriptions are applied per App) |
3.3 Data collected automatically
| Data | Tool |
|---|---|
| Usage analytics: in-app events such as "song opened", "word saved", "review completed", with related identifiers (e.g., song and word IDs). Event data does not include your name, email, or lyric text. | PostHog |
| Crash and error reports: stack traces, device model, OS version, app version | Sentry |
| Standard server logs: IP address, request timestamps, endpoints called (used for security, rate limiting, and debugging; lyric content is never written to logs) | Our servers |
3.4 Optional speech answers
On review cards you may tap to answer by speaking. That uses the microphone and the device's speech-recognition service (on iOS, Apple's). Audio is used only to transcribe your answer in that moment. We do not store recordings, and we do not use speech data for analytics. You can always type instead, and you can refuse the microphone permission.
3.5 Data we do not collect
- Payment card details. Purchases are processed entirely by Apple's App Store or Google Play. We never see your payment instrument; we only receive confirmation of your subscription status.
- Contacts, location, camera, or photos. The Apps do not use these. A photo-library permission string may appear because of an included system component; we never read your photos.
- Advertising identifiers. We do not show third-party ads and do not use advertising SDKs for tracking.
4. How and why we use your data
- To provide the service: operating your account, syncing your vocabulary and progress, scheduling spaced-repetition reviews, computing your per-song comprehension percentage, and maintaining your streak.
- To manage subscriptions: knowing whether your account has an active subscription in that App so paid features unlock, and applying free-tier limits otherwise.
- To keep the service safe and working: authentication, rate limiting, abuse prevention, debugging, and crash diagnosis.
- To improve the product: aggregate analytics about how features are used (e.g., how many users complete a review session).
- To comply with legal obligations: for example, responding to lawful requests or enforcing our Terms of Use.
We do not sell your personal data, we do not share it for cross-context behavioral advertising, and we do not use it to train AI models.
5. Third-party services and data sharing
We share data only with the service providers below, only as needed to run the Apps. Each acts under its own privacy policy:
| Service | Role | Data involved |
|---|---|---|
| Apple App Store / Google Play | Payment processing and sign-in | Purchase transactions (handled by them); sign-in identity tokens |
| RevenueCat | Subscription management | An app-specific user ID and subscription events (no email, no payment details) |
| PostHog | Product analytics | Usage events as described in section 3.3 |
| Sentry | Crash and error reporting | Crash reports and device/app metadata |
| OneSignal | Push notifications (e.g., review reminders, streak alerts) | A push token, an app-specific user ID, and non-identifying app state used to time reminders (e.g., learning language, streak count). Notifications require your explicit OS-level permission and can be disabled anytime in system settings. Marketing emails are separate and sent only if you opt in inside the app. |
| Apple (speech recognition) | Optional spoken answers on review cards | If you choose to speak an answer, audio is processed by the device speech service; we do not receive or store the recording |
| YouTube (Google) | Music video playback via the official embedded YouTube player | When you play a song, the embedded player connects to YouTube/Google, which may collect data (e.g., IP address, viewing activity) under Google's own privacy policy — the same as watching an embedded video on any website |
| Musixmatch | Licensed lyrics catalog | Song search and lookup requests needed to fetch lyrics; these are made by our servers and are not tied to your identity by Musixmatch |
| Hetzner Online GmbH | Server hosting (Germany, EU) | All server-side data listed above is stored on infrastructure they host |
We may also disclose data if required by law, to protect our legal rights, or as part of a business transfer (in which case this policy continues to apply and we will notify you of any change of controller).
6. Legal bases (GDPR/UK GDPR)
If you are in the European Economic Area or the United Kingdom, we process your data on these bases:
- Performance of a contract (Art. 6(1)(b)) — account data, learning activity, subscription status: everything needed to deliver the app you signed up for.
- Legitimate interests (Art. 6(1)(f)) — analytics, crash reporting, server logs, and abuse prevention, balanced against your rights (events contain no direct identifiers and are used only to improve and secure the service).
- Consent (Art. 6(1)(a)) — birth year for the explicit-content age check; optional spoken review answers (microphone); marketing emails if you opt in inside the app. You can refuse or withdraw these at any time.
- Legal obligation (Art. 6(1)(c)) — where retention or disclosure is required by law.
7. Where your data is stored and international transfers
Our servers and database are hosted by Hetzner in Germany (European Union), and encrypted backups are kept within the EU. Some of our service providers (e.g., RevenueCat, Sentry, PostHog, Google) may process data in the United States or other countries. Where data leaves the EEA/UK, transfers rely on safeguards such as the EU Standard Contractual Clauses or the EU–US Data Privacy Framework, as applicable to each provider.
We operate from Israel. The European Commission has recognized Israel as providing an adequate level of data protection (an "adequacy decision"), so access to your data from Israel does not require additional transfer safeguards under the GDPR.
8. How long we keep your data
- Account and learning data: for as long as your account exists.
- Account deletion: deleting your account in any App (Profile → Delete account) immediately deactivates it across all Apps and revokes all sessions; all your personal data is permanently erased from our systems within 30 days. Deleted data also cycles out of backups within the backup retention window (up to 30 additional days).
- Crash reports and server logs: retained for up to 90 days.
- Analytics events: retained in identifiable form no longer than 24 months; aggregate statistics may be kept indefinitely.
- Subscription records: transaction-related records may be retained longer where required for tax, accounting, or dispute-resolution obligations.
9. Your rights
Depending on where you live, you have some or all of the following rights:
- Access — get a copy of the personal data we hold about you.
- Rectification — correct inaccurate data.
- Erasure — delete your data. The fastest way is the in-app account deletion; you can also email us.
- Portability — receive your data in a structured, machine-readable format.
- Objection and restriction — object to or restrict processing based on legitimate interests.
- Withdraw consent — at any time, where processing is based on consent (this does not affect processing already carried out).
To exercise any right, email maria@zamiro.io. We will respond within 30 days (or the period required by your local law). We may need to verify your identity — normally by confirming control of the email on your account. If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority.
10. Additional information for California residents
Under the CCPA/CPRA, California residents have the rights to know, correct, and delete personal information, the right to opt out of "sale" or "sharing" of personal information, and the right not to be discriminated against for exercising these rights.
- We collect the categories of personal information described in section 2: identifiers (email, account IDs), commercial information (subscription status), and internet activity (app usage events, crash data).
- We do not sell personal information and do not share it for cross-context behavioral advertising, and have not done so in the preceding 12 months. We therefore do not offer an opt-out, as there is nothing to opt out of.
- We do not use or disclose sensitive personal information for purposes requiring a right to limit.
- To exercise your rights, email maria@zamiro.io. You may use an authorized agent; we will verify the request as described in section 9.
11. Children's privacy
The Apps are not directed at children under 13, and you must be at least 13 years old to create an account (or older where your country sets a higher minimum age of digital consent — see the Terms of Use). We do not knowingly collect personal data from children under 13. If you believe a child under 13 has created an account, contact us at maria@zamiro.io and we will delete it.
Songs flagged as containing explicit lyrics are hidden by default and can only be shown by users who have confirmed a birth year indicating they are 18 or older.
12. Security
- All traffic between the app and our servers is encrypted with TLS (HTTPS).
- Passwords are stored only as bcrypt hashes — we cannot read them.
- Session tokens are short-lived; refresh tokens are stored hashed and can be revoked (signing out or deleting your account revokes them immediately).
- The database is not exposed to the public internet, and access to production systems is restricted.
- Backups are encrypted and stored off-site within the EU.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
13. Changes to this policy
We may update this policy as the Apps evolve. For material changes we will notify you in the Apps before the change takes effect. The "Last updated" date at the top always reflects the current version. Continued use of any App after a change takes effect means the updated policy applies.
14. Contact
Questions, requests, or complaints: maria@zamiro.io