Privacy Policy
Last updated: September 6, 2026
1. What We Collect
When you create an account, we collect your email address, display name, and password (stored securely via Supabase Auth). We also store your lesson progress, vocabulary review data, and app preferences.
2. Voice Data
Mirifer uses your browser's built-in Web Speech API for voice recognition. Your voice audio is processed locally by your browser and sent to your browser's speech recognition service (e.g. Google for Chrome). We do not record, store, or transmit your voice audio to our servers. We only receive the text transcript to compare against the target sentence.
3. How We Use Your Data
- To provide and improve the learning experience
- To track your lesson progress and spaced repetition schedule
- To sync your data across devices when signed in
We do not sell your data to third parties.
4. Analytics
We use Vercel Analytics and Microsoft Clarity to understand how visitors use our site. These tools collect anonymous usage data such as page views, device type, and interaction patterns. Clarity may record anonymized session replays to help us improve the user experience. No personally identifiable information is shared with these services.
For signed-in learners, we also store account-linked visit and lesson events in Supabase to understand where practice stops and identify technical obstacles. These events include lesson positions and content identifiers, answer correctness, hint and answer-reveal actions, replay requests, sampled active lesson time, microphone or playback error categories, coarse device and browser type, and interface language. They do not contain raw voice recordings, transcripts, answer text, or full page URLs. Pending events may be stored in your browser for up to 7 days before delivery. Only administrators can view reports across accounts.
Optional German progress checks store the question-set identifier, checkpoint dates, listening and reading scores, and skipped-question count. Answer choices are sent to the server for scoring and are not stored. No voice recording is required. For acquisition reporting, we keep an allowlisted source category (such as Google or a friend invitation) and capture dates, linked to your account after sign-in. The first source category may stay in this browser for up to 30 days before sign-in. We do not retain full referrer URLs or arbitrary campaign text in these reports. These pilot checks do not establish a certified language level.
5. Data Storage
Your account data is stored securely on Supabase (hosted on AWS). Passwords are hashed and never stored in plain text. All connections use HTTPS encryption.
6. Your Rights
You can request deletion of your account and all associated data at any time by contacting us. We will process deletion requests within 30 days.
7. Cookies
Mirifer uses essential cookies for authentication (keeping you signed in). Analytics tools may set their own cookies for anonymous usage tracking.
8. Changes
We may update this policy as Mirifer evolves. Significant changes will be communicated through the app.
9. Contact
Questions about your privacy? Reach us at afraz.jva@gmail.com.