Privacy policy
Last updated: 7 September 2026
The honest summary. Today the app runs entirely on your device. There is no account, no server, and nothing is sent anywhere. This website uses no cookies and no analytics either.
What this policy covers
Two separate things: this website (heyplumi.app) and the HeyPlumi mobile app. The app is not published yet; what follows describes the version that exists today.
This website
It is a static site. No cookies, no local storage, no pixels, no third-party analytics. There are no forms and nothing is collected about visitors. The hosting provider records HTTP requests in its own technical logs, as any web server does.
The app today: everything is local
The words you note, their senses, your notes, your languages, your settings and your game progress are stored in a database on your device. They are not sent to any server, because today there is no server to send them to.
The app asks for no account and works offline. A user without an account makes no authenticated calls at all: they simply never talk to a backend.
Not collected: location, contacts, advertising identifiers (IDFA/AAID), device fingerprints, or third-party analytics. The app ships no third-party SDK that can see what you type.
Your search history never leaves the device
This is an architectural decision, not a marketing promise. The search-history table has no sync columns, never enters the outbox queue, and has no counterpart on the server.
The reason: the words you save say what you are learning; the words you look up say what you do not know, and that can reveal education level, native language, country of origin, legal status or health. A list of searches is an intimate profile, and its value once synced is close to nil. The trade-off is accepted deliberately: reinstall the app and that history is gone.
What does not exist yet
Accounts, backup and sync across devices are under construction. When they exist they will work like this, and this policy will be updated with the date they start to apply:
- The account will stay optional. The app has to be fully usable with no account and no network.
- Identity will be handled by an external provider (Microsoft Entra External ID) via Apple, Google, or a one-time email code. We will not store passwords — what does not exist cannot leak.
- What would be stored: the identifier the provider issues, your email (which may be null: Apple allows private relay), your vocabulary and your settings. Nothing else.
- Product telemetry would be opt-in, switchable off in Settings, and the app would work identically if you decline.
- Search history still would not sync. That does not change.
Security
On the device, iOS and Android already encrypt app storage when the phone has a passcode, with hardware-backed keys, and the system sandbox stops other apps reading it. Once accounts exist, the long-lived credential will live in the Keychain (iOS) or Keystore (Android), and the access token will never be written to disk.
Your rights
While everything is local, control is direct: the data is yours and it is on your device; deleting the app deletes it. The app also includes an option to export your notebook.
Once accounts exist you will be able to exercise the GDPR rights of access, portability, rectification, erasure, restriction and objection. Erasure will carry a 30-day grace window — logging back in during that window cancels it, and the app tells you — so that accidentally deleting years of vocabulary is not irreversible.
Children
The app is not aimed at children under 14 and does not knowingly collect their data. As nothing at all is collected today, there is nothing to erase in that case.
Changes
When this policy changes, the date in the header changes with it. Changes that affect data leaving the device will be announced inside the app itself, not only here.
Contact
Write to privacidad@heyplumi.app.