Privacy Policy
Last updated: 25 September 2026
This policy explains what personal data Pivot collects, why, who else handles it, and what you can do about it. The controller is Oleksii Kaminskyi, an individual based in Ireland. Contact: pivotsub.help@gmail.com. It follows the EU General Data Protection Regulation (GDPR) and the UK GDPR.
1. What we collect
- Account: your email address, and your name and profile picture if you sign in with Google. If you sign up with a password, we keep only a salted scrypt hash of it, never the password itself — nobody, including us, can read it.
- Your vocabulary: words and phrases you save, their translations, the sentence they came from, and where you found them (platform, video title, link and timestamp, or document page).
- Learning data: words you mark as known, vocabulary test results, review grades and schedule, and settings such as your language pair.
- History: the videos and web pages you used Pivot on while the extension was active — title, link and date, plus the word counts of a video — so they appear in your History and in the estimate of how much of each video you understand.
- Documents you upload to the reader.
- Usage counters: how many AI explanations you used today and similar counts needed to apply plan limits.
- Subscription: plan, status and period end received from Polar, and Polar's subscription identifier. We never receive your card details.
- Technical data: the IP address and browser name of each signed-in session, stored with the session for security and deleted when it ends; and request information in server logs, kept briefly for troubleshooting.
2. What we don't collect
We don't record video or audio, and we don't read your browsing outside the sites Pivot works on. Subtitles are read inside your browser; what reaches our servers is the words you save and, for each video you watch with Pivot on, its title, link and word counts (see “History” above). We use no analytics, advertising or tracking tools.
3. Why, and on what legal basis
- To provide the service you signed up for — account, translations, explanations, review, subscriptions (contract, Art. 6(1)(b) GDPR).
- To keep it secure and prevent abuse of plan limits (legitimate interests, Art. 6(1)(f)).
- To meet legal duties, such as keeping payment records (legal obligation, Art. 6(1)(c)).
We don't sell personal data and don't use it for advertising.
4. Who else handles data
- Google (USA) — sign-in if you choose it; machine translation of subtitle lines and words; Gemini AI explanations of the word and sentence you click. Translation and explanation requests contain text only, not your account identity.
- DeepL SE (Germany) — machine translation of subtitle lines and words for Premium and trial users. Requests contain text only, not your account identity.
- Polar Software Inc. (USA) — merchant of record: checkout, billing, invoices and sales taxes. Polar receives your email and billing details directly.
- Anthropic (USA) — only if you add your own Anthropic API key in Settings: explanations are then requested from Anthropic under your key. Requests contain text only, not your account identity.
- Hosting provider — runs our servers and database.
5. Transfers outside the EU
Some providers above are in the United States. Such transfers rely on the safeguards required by Chapter V GDPR — the EU–US Data Privacy Framework where the provider is certified, or the European Commission's Standard Contractual Clauses.
6. Cookies
Only what the site needs to work: a session cookie that keeps you signed in, and cookies remembering your interface language and theme. No advertising or analytics cookies.
7. How long we keep data
- Account and learning data — until you delete them or your account.
- Documents — until you delete them.
- Server logs — a short rotation period.
- Payment records — held by Polar as tax law requires.
Deleted data is removed from our database at once and from backups within 30 days.
8. Security
Data is encrypted in transit, access to it is limited to what running the service needs, and every request is scoped to the signed-in account. If a personal data breach happens that is likely to put you at risk, we notify the supervisory authority within 72 hours where required and tell affected users without undue delay.
9. Your rights
You can access, correct, export and delete your data, restrict or object to its processing, and withdraw consent where processing relies on it. Settings has a one-click export of everything as a file and a button to delete all data; for anything else write to pivotsub.help@gmail.com. We reply within one month. You can also complain to the data protection authority of your country — in Ireland, the Data Protection Commission.
10. Children
Pivot isn't meant for children under the age of digital consent in their country (16 in most of the EU, never below 13) without a parent's consent. If we learn that we hold such a child's data without it, we delete it.
11. Automated processing
The review schedule is computed automatically from your grades (a spaced-repetition algorithm), and plan limits are applied automatically. Neither has legal or similarly significant effects on you.
12. California residents
We don't sell or share personal information as defined by the CCPA/CPRA. You can ask to know, correct or delete it, and won't be treated differently for doing so.
13. Changes
If this policy changes in a way that matters, we tell you before the change applies.