Legal & Compliance

Privacy Policy

Effective Date: September 1, 2026Last Updated: September 1, 2026

Key Highlights at a Glance

  • We process minimal account information necessary to deliver and personalize your Turkish language learning experience.
  • We never sell, rent, or monetize your personal data or study history with third-party advertisers or data brokers.
  • AI Tutor prompts are never used to train AI models. Our AI provider holds them briefly for abuse monitoring only, then deletes them.
  • You maintain full control over your personal data: you can request export or permanent deletion of your account and records at any time via our Contact page.
  • We employ industry-standard safeguards: encryption in transit and at rest, and per-user database rules so no account can read another account.

1. Data Controller and Contact Information

This Privacy Policy describes how Dilsever ("we", "us", or "our") collects, uses, stores, and protects personal data when you access or use our Turkish language learning platform, website, applications, and related services (collectively, the "Services").

Dilsever is operated by DomiLabs. For the purposes of the European Union General Data Protection Regulation (GDPR), the United Kingdom Data Protection Act, the California Consumer Privacy Act (CCPA/CPRA), and the Turkish Personal Data Protection Law (KVKK No. 6698), the data controller responsible for your personal information is DomiLabs.

Registered entity details and postal address: [TO BE COMPLETED ON INCORPORATION]. Until then, the fastest and most reliable way to reach us about any privacy matter is the email address and contact form below, both of which are monitored.

If you have questions, concerns, or requests regarding this Privacy Policy or our data handling practices, you can contact our privacy team by email at hello@dilsever.com or by submitting an inquiry through our dedicated Contact page at /contact.

2. Information We Collect

We collect only the personal information required to maintain your account, personalize your curriculum, and provide reliable learning tools.

Depending on how you interact with Dilsever, we may collect the following categories of information:

Account and Profile Information

When you register an account, we collect your email address, display name, and authentication identifiers through Google Firebase Authentication. If you authenticate using Google Sign-In, Firebase receives your basic profile information (such as your public avatar and verified email address). We use this information solely to identify your account, secure your sessions, and communicate vital service updates.

Learning Progress and Spaced Repetition Telemetry

To power our spaced repetition system (SM-2 algorithm), curriculum tracks, and practice drills, we store learning metrics. This includes review schedules, ease factors, repetition counts, interval histories, quiz scores, daily streak records, custom vocabulary decks, and personal grammar notes you create.

AI Tutor and Speech Synthesis Interactions

When you submit questions or conversational prompts to the AI Tutor, your input is sent to OpenAI for real-time contextual evaluation and grammatical feedback. Your prompts are not used to train OpenAI models or ours. OpenAI retains API inputs and outputs for a limited period (currently up to 30 days) solely for abuse and misuse monitoring, after which they are deleted. When you listen to Turkish pronunciation audio, the text is processed through Google Cloud Text-to-Speech (Chirp 3: HD).

Technical, Device, and Usage Telemetry

We collect essential technical telemetry necessary to operate and secure the platform. This includes your IP address, browser type, operating system, preferred interface locale (English or Arabic), referring URLs, session timestamps, and client error logs.

Payment and Billing Details

When you purchase a paid subscription, your payment is processed by Lemon Squeezy, our Merchant of Record, which is PCI-DSS compliant. Dilsever does not store, collect, or have access to full card numbers or banking credentials. We receive only non-sensitive transaction metadata, such as billing cycle status, payment verification tokens, country code, and plan tier.

4. Third-Party Service Providers and Sub-Processors

We partner with vetted infrastructure and software providers who process data on our behalf under strict confidentiality and security agreements.

Our primary sub-processors and external service providers include the following entities:

Google Firebase (Google LLC)

Purpose: User authentication, cloud database storage (Firestore), and secure media hosting. Data is hosted in secure Google Cloud data centers with encryption at rest and in transit.

Vercel Inc.

Purpose: Next.js edge application hosting, global content delivery network (CDN), serverless compute execution, and privacy-preserving web analytics.

OpenAI, L.L.C.

Purpose: Powering the interactive AI Tutor, contextual sentence generation, and morphological grammar explanations. API inputs and outputs are not used for model training, and are retained by OpenAI for a limited abuse-monitoring window (currently up to 30 days) before deletion.

Google Cloud Platform (Google LLC)

Purpose: High-fidelity Turkish speech synthesis via Google Cloud Text-to-Speech (Neural Chirp 3: HD models).

Lemon Squeezy LLC

Purpose: Payment processing, subscription lifecycle management, sales tax and VAT calculation, and automated invoice delivery. Lemon Squeezy acts as the Merchant of Record for all Dilsever purchases, which means it is the seller of record on your receipt and is responsible for collecting and remitting applicable taxes.

Email delivery

Purpose: Delivery of transactional authentication emails, verification links, and password reset notifications. These are currently sent by Google Firebase Authentication. If we move transactional email to a dedicated provider, this policy will be updated to name it before the change takes effect.

Telegram Messenger Inc.

Purpose: Delivery of support and operations messages to a private staff channel. When you submit our contact form, the content of your message, together with the email address you supply and, if you are signed in, your account identifier, is delivered to that channel so we can read and answer it. Telegram processes that message in transit and stores it in the channel history. Do not include sensitive personal information in a contact form message.

5. Data Retention and Security Measures

We retain your personal data for as long as your account remains active or as needed to provide you with the Services. If you choose to delete your account, we will erase or irreversibly anonymize your personal records within thirty (30) days, except where retention is legally required for financial auditing, tax compliance, or dispute resolution.

Specific retention periods: account and learning records are kept until you delete your account, then erased within thirty (30) days. Server and client error logs, which may contain an IP address, are kept for up to ninety (90) days. Contact form messages delivered to our support channel are kept for up to twelve (12) months so we can follow up on an earlier conversation. AI Tutor prompts are held by our AI provider for up to thirty (30) days for abuse monitoring and are not stored by us beyond your chat session.

Dilsever implements technical and organizational security controls designed to safeguard your personal data against unauthorized access, loss, destruction, alteration, or disclosure. Data in transit is encrypted using Transport Layer Security (TLS 1.2 or higher). Records stored in Google Cloud Firestore are encrypted at rest with AES-256 by the platform. Access to your learning data is enforced at the database layer by per-user security rules, so one account cannot read another account, and our AI and support endpoints require an authenticated session and are rate limited. Access to production administration is limited to authorized personnel.

6. User Rights, Data Portability, and Deletion

Regardless of your geographical location, Dilsever respects your fundamental rights to control your personal data.

Depending on your jurisdiction (including the European Economic Area, United Kingdom, California, and Turkey), you hold specific statutory rights regarding your personal information:

How to Submit a Data or Deletion Request

To exercise any of these rights, or to request permanent deletion of your Dilsever account and all associated study data, please submit a request through our Contact form at /contact or email hello@dilsever.com with the subject line "Privacy Data Request". We will verify your identity and process your request within thirty (30) calendar days at no charge.

  • Right of Access and Portability: You have the right to request a machine-readable copy of the personal data and learning records we hold about you.
  • Right to Rectification: You have the right to correct inaccurate, outdated, or incomplete personal information associated with your profile.
  • Right to Erasure (Right to Be Forgotten): You have the right to request the complete deletion of your account, learning history, notes, and associated records.
  • Right to Restriction and Objection: You may restrict or object to our processing of your personal data under certain statutory circumstances.
  • California Privacy Rights (CCPA/CPRA): We do not sell your personal information or share your data for cross-context behavioral advertising. You have the right to non-discrimination for exercising your privacy rights.
  • Turkish KVKK Rights: Under Article 11 of the KVKK, Turkish data subjects have the right to inquire whether personal data is processed, request information regarding processing, and demand correction or deletion.
  • Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew.
  • Right to Lodge a Complaint: If you believe we have handled your personal data unlawfully, you have the right to complain to your national data protection supervisory authority. In the European Economic Area this is the authority of your country of residence or workplace; in the United Kingdom it is the Information Commissioner’s Office (ico.org.uk); in Turkey it is the Kişisel Verileri Koruma Kurumu (kvkk.gov.tr). You are welcome, but never required, to contact us first.

7. Cookies and Local Storage

Dilsever uses strictly necessary cookies and browser LocalStorage items to maintain authenticated user sessions, store your active interface locale preference (English or Arabic), and preserve your current learning theme state.

We do not deploy third-party advertising cookies, invasive tracking pixels, or cross-site fingerprinting scripts. Web analytics are configured in a privacy-friendly manner that respects user privacy and does not build persistent cross-domain profiles.

8. Children's Privacy

Dilsever is designed for adult and older teenage language learners. Our Services are not directed to children under the age of 13, or under the applicable age of digital consent in your country, which is between 13 and 16 across the European Union and 13 in the United Kingdom. Learners under 18 may use Dilsever only with the agreement of a parent or legal guardian, and only an adult may purchase a subscription. See section 1 of our Terms of Service.

We do not knowingly collect or solicit personal information from children under the applicable age of consent. If we become aware that we have collected personal data from a child without verified parental consent, we will promptly delete that information. Parents or guardians who believe their child has provided personal information to us may contact us at hello@dilsever.com.

9. International Data Transfers and Policy Updates

Dilsever operates globally. Personal information may be transferred to, stored, and processed in cloud data centers located in the United States and the European Union. When data is transferred internationally, we ensure appropriate safeguards are implemented in compliance with applicable law, including Standard Contractual Clauses (SCCs) approved by the European Commission.

Representative in the European Union and United Kingdom (GDPR Article 27 and UK GDPR): [TO BE COMPLETED ON INCORPORATION]. Until a representative is appointed, data subjects in the EEA and the United Kingdom may address any request directly to us using the email address and contact form in section 1, and we will answer within the statutory time limit.

We may periodically update this Privacy Policy to reflect enhancements to our platform, changes in legal requirements, or evolving industry practices. When material changes are made, we will update the "Last Updated" date at the top of this document and provide prominent notice on the platform or via email prior to the changes taking effect. Your continued use of the Services after the effective date of an updated Privacy Policy constitutes your acknowledgment of the revisions.

Frequently Asked Questions

Questions or Data Requests?

Contact our privacy and legal compliance team anytime via our contact form or directly by email.