← Back to home

Privacy Policy

Last updated: 2026-09-15

1. Introduction

kalbuosi ("we", "us", "our") respects your privacy. This Privacy Policy explains how we collect, use, share, and protect personal data when you use our website and app (the "Service"). This policy should be read together with our Terms of Use.

2. What data we collect

Depending on how you use the Service, we may collect:

A) Account and contact data: Email address (required to create an account); basic account details you provide (e.g., name, language preferences, settings). If you sign in with Google, we receive your name, email address, and profile image from Google.

B) Learning and usage data: Practice activity (e.g., modules used, attempts, answers, scores, progress); group-session bookings; feature usage and interactions within the Service.

C) Payment data: Purchase status, pass type, and receipt/invoice metadata for your one-time course purchase. Card and payment details are entered on and processed by our payment provider, Stripe. We do not receive or store full card numbers.

D) Device, log, and technical data: IP address, device type, browser information, timestamps; error and diagnostic logs, and security/fraud-prevention signals.

E) Cookies and analytics: We use only essential cookies required for login, sessions, and security. We do not use advertising or tracking cookies. We use Vercel Analytics, a cookieless, privacy-friendly analytics tool that reports aggregated, anonymous page-view and visitor counts and does not identify individual users. See "Cookies" below.

3. How we use your data (purposes)

We use personal data to:

  • Provide and operate the Service (account access, saved progress, course features, group-session booking).
  • Process your payment and deliver purchased course access.
  • Send service/transactional communications (account verification, password resets, receipts, booking and access notifications, important updates).
  • Maintain security, prevent fraud/abuse, and protect the Service.
  • Diagnose errors and maintain the reliability and quality of the Service.

We do not currently send marketing communications or use your data for advertising. If this changes, we will update this policy and, where required, ask for your consent first.

4. Legal bases (GDPR)

We process personal data under one or more of these legal bases, depending on the purpose:

  • Contract: to provide the Service, deliver paid access, and maintain your account.
  • Legal obligation: to meet accounting, tax, and compliance requirements.
  • Legitimate interests: to secure the Service, prevent fraud, diagnose errors, and maintain reliability (balanced against your rights).

5. Communications

We currently send only service / transactional messages that are necessary to operate the Service, such as account verification and security codes, password-reset codes, a welcome message, group-session application and access-granted notifications, purchase receipts, and important service changes. These are not marketing and are sent as part of providing the Service.

We do not send promotional or marketing emails. If we introduce marketing communications in the future, they will be opt-in where required and every message will include an unsubscribe option.

6. Cookies

We use only essential cookies that are strictly necessary to run the Service, for example to keep you signed in, maintain your session, and protect against security threats (CSRF). Because these cookies are essential, they do not require consent, but blocking them will prevent login and core functionality from working.

We use Vercel Analytics to understand overall site traffic (e.g., page views and visitor counts). It does not use cookies and does not collect personal data or track you individually; it only reports anonymous, aggregated statistics. We do not use advertising or other tracking cookies, and we do not use Google Analytics. If we add any non-essential cookies in the future, we will update this policy and, where required, request your consent through a cookie banner.

7. Sharing of data (processors and third parties)

We share personal data only as necessary to provide and secure the Service, with the following categories of processors:

  • Payments (Stripe): to process your purchase and produce receipts.
  • Authentication (Google Sign-In): if you choose to sign in with Google.
  • Email delivery (Resend): to send transactional emails.
  • Hosting, infrastructure & analytics (Vercel): to run and serve the Service, and to provide anonymous, aggregated traffic analytics (Vercel Analytics).
  • Database (Supabase): to store your account, progress, and booking data.
  • Error monitoring (Sentry): to capture diagnostic and error data so we can keep the Service reliable.

These providers process data on our behalf under contractual safeguards and instructions (data processing agreements where applicable). We may also disclose data if required to comply with legal obligations or to protect rights, safety, and security. We do not sell your personal data.

8. International data transfers

Some service providers may process data outside the European Economic Area (EEA). Where international transfers occur, we rely on appropriate safeguards, such as Standard Contractual Clauses (SCCs) and other legally recognized mechanisms, as required.

9. Data retention

We keep personal data only as long as needed for the purposes described in this policy. Typical retention periods:

  • Account data: while your account is active; then deleted or anonymized within a reasonable period upon request or account closure, unless needed longer.
  • Learning progress and bookings: while your account is active; then deleted/anonymized after closure.
  • Billing and purchase records: as required by applicable accounting and tax law.
  • Security and error logs: a limited period (typically 30–180 days).

We may retain some data longer if necessary to comply with law, resolve disputes, or enforce agreements.

10. Data security

We use industry-standard measures to protect personal data, including access controls, encryption in transit, and monitoring for security incidents. Passwords are stored hashed, never in plain text. No system is 100% secure, but we work to safeguard your information.

11. Your rights (GDPR)

Depending on your situation and applicable law, you may have the right to:

  • access your personal data;
  • correct inaccurate data;
  • request deletion ("right to be forgotten");
  • restrict or object to processing;
  • data portability;
  • withdraw consent at any time (where processing is based on consent).

To exercise your rights, contact labas@kalbuosi.lt. We may need to verify your identity before fulfilling requests.

12. Complaints

If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local supervisory authority. In Lithuania, this is the State Data Protection Inspectorate (VDAI).

13. Changes to this policy

We may update this Privacy Policy from time to time. We will update the "Last updated" date and may notify you of significant changes via email and/or in-app notice.

14. Contact

Privacy questions or requests: labas@kalbuosi.lt