Last updated: 26 July 2026 (Paris time)
This policy explains what personal data we collect, how we use it, who we share it with and what rights you have. Apple’s guidelines require that an iOS privacy policy disclose the data collected, how it is collected and used, third‑party sharing, retention periods and mechanisms for withdrawing or deleting data.
1. Data Controller
The data controller is Yanis Cherifi, Sole Trader (auto‑entrepreneur), registered in France and domiciled at 8 rue Guynemer, 94300 Vincennes, France. For privacy‑related questions you can contact us at contact.shortlearn@gmail.com.
2. Data We Collect
In keeping with the data minimisation principle, we collect only the information necessary to operate Short Learn. Categories of data include:
| Category | Description | Purpose |
|---|---|---|
| Account data | Name, email address, encrypted password | To create and manage the account, communicate with the user and provide the service |
| Usage statistics | Number of videos submitted per day, number of lessons generated per day, source and target languages, timestamps | To analyse and improve our service; aggregated statistics are anonymised |
| Technical data | Device identifier (IDFV), connection logs, IP address, operating system information | To ensure security, prevent fraud and measure performance |
| Content data | URL and metadata of the shared content, temporary transcription and translation | To generate the language lesson; transcription is deleted after processing |
| Speaking practice data | Audio recordings, transcriptions, evaluations, corrections and feedback from speaking exercises | To provide speaking practice features, evaluations and feedback on pronunciation, grammar and vocabulary |
We do not collect sensitive data (such as race, political opinions) and we do not collect precise location or health data.
With the user's prior consent on the website, we also collect advertising and product analytics data: pages and funnel steps viewed, conversion events, campaign parameters (UTM and Meta click identifiers), first-party Meta cookie identifiers (`_fbp` and `_fbc`), approximate technical connection data (IP address and user agent), and a pseudonymous account ID. Email addresses and account IDs sent through Meta's Conversions API are normalised and hashed before transmission. These data are used to measure campaign performance, prevent duplicate conversion counting, attribute web subscriptions and improve the onboarding experience.
3. How We Collect Data
4. Purposes and Legal Bases
| Purpose | Legal basis | Details |
|---|---|---|
| Provide the service (account creation, lesson generation) | Performance of a contract | Account data and shared URLs are necessary to deliver the requested functionality. |
| Measure audience and improve the application | Legitimate interest | The Publisher analyses aggregated usage statistics (number of videos, languages, timestamps) to enhance user experience without individual profiling. |
| Security and fraud prevention | Legitimate interest | Logs and technical identifiers are used to detect misuse or faults and to ensure service integrity. |
| Compliance with legal obligations | Legal obligation | Retention of connection data and response to lawful requests from authorities. |
| Communication with users (support, important notifications) | Legitimate interest | We may contact users regarding the service (confirmations, responses to queries). We do not send marketing without consent. |
| Advertising measurement and consented product analytics on the website | Consent | Meta and PostHog are not activated until the user accepts the analytics choice. Consent can be withdrawn at any time. |
5. Recipients and Data Transfers
Personal data are not sold. They are processed by:
In some cases, data may be transferred outside the European Economic Area (for example to the United States when using AI services). Such transfers are governed by the European Commission’s Standard Contractual Clauses or adequacy decisions ensuring an adequate level of protection.
6. Retention
We retain personal data only for as long as necessary for the purposes described above:
These retention periods align with the obligation to specify how long data are kept and to delete them when they are no longer needed.
7. User Rights
Under the GDPR and French law, users have the following rights:
The app offers an "Account" section where users can view and edit their information. To exercise another right or request assistance, users may contact the Publisher via the address in § 1. The Publisher may request proof of identity. Users may also lodge a complaint with the CNIL (French data protection authority).
Speaking Practice Data Management
How will you use my data?
We use your audio recordings to create and provide you with speaking practice evaluations, feedback, corrections and key vocabulary suggestions. Your audio recordings are sent to Whisper AI for processing. We do not use your recordings for marketing purposes.
Can I delete my speaking practice data?
Yes, you can delete your data at any time. You can choose to delete the audio, transcript and evaluation results at any time directly from each speaking exercise. When you delete an exercise response, your audios are immediately deleted from our servers. You can also export your results and audio recordings at any time before deletion. Please contact our customer support team at contact.shortlearn@gmail.com if you'd like to access or remove all of your speaking practice data.
Is my data secure?
Yes, your data is secure. Short Learn uses encryption and robust security measures to protect your information. We are fully GDPR-compliant and maintain the highest security standards. Your speaking practice data is only shared when strictly necessary to provide the service, with a limited number of trusted third-party transcription providers, and never for marketing purposes. Audio recordings are automatically deleted after 10 days, or immediately when you delete an exercise response.
8. Data Security
The Publisher implements appropriate technical and organisational measures to protect data against accidental or unlawful destruction, loss, alteration, disclosure or unauthorised access. Measures include password encryption, access logging and database segregation. However, no method of electronic transmission or storage is completely secure. Despite our efforts, we cannot guarantee absolute security, and users use the service at their own risk.
9. Children
Short Learn is not intended for children under 16. Individuals aged 16 or above but under the age of majority in their country must obtain consent from a legal guardian before creating an account. We do not knowingly collect data from children; if we discover that a child under 16 has provided information, we will delete the data and disable the account.
10. Cookies and Similar Technologies
The app does not use third-party cookies in the native interface. Technical cookies and local storage may be used on the website and login area to ensure security and functionality.
On the website, Meta Pixel, Meta Conversions API and PostHog are activated only after an affirmative choice in the privacy banner. Accept and reject options are presented at the same level. Refusing does not block access to the service. The choice is retained for up to 6 months.
When accepted, Meta may set or read first-party identifiers such as `_fbp` and `_fbc`. ShortLearn also stores UTM campaign parameters and the Meta click identifier locally for no more than 90 days so that a confirmed Stripe subscription can be attributed to the relevant campaign. PostHog measures page and funnel usage after the same consent.
The user can reopen the banner at any time through the Privacy button and select Reject all. This revokes future tracking and removes ShortLearn's locally stored Meta attribution data and first-party Meta cookies to the extent technically possible. Browser settings can also be used to delete cookies and local storage.
11. Changes to This Policy
We may modify this policy to reflect legal or service changes. Significant updates will be notified to users via the app or by email. Continued use of the service after the effective date of the new policy constitutes acceptance.
12. Contact
For privacy‑related questions or to exercise your rights, please contact us at contact.shortlearn@gmail.com.