← Back to site
Privacy

Privacy Policy

Last updated: July 24, 2026

This policy applies to the website data-informed-decisions.com and to any app or web application published by Data Informed Decisions LLC — currently langsi (app & web at langsi.app). It fully replaces Section 5 of the Terms & Privacy page.

1. Data controller

The controller responsible for data processing under the General Data Protection Regulation (GDPR) and other applicable data protection laws is:

Data Informed Decisions LLC
8 The Green, Suite A, Dover, DE 19901, USA
Email: info@data-informed-decisions.com
Phone: +1 (716) 296-0224
Availability: Mon–Fri, 9:00–17:00 (ET)

For any privacy-related request — whether about the website or about langsi — the email address above is the central point of contact.

2. Scope

This Privacy Policy describes how Data Informed Decisions LLC processes personal data:

We may publish further apps under Data Informed Decisions LLC in the future. Once another app goes live, this policy will be extended with a corresponding section and the "Last updated" date above will be revised.

3. Principles & legal bases

We process personal data only where legally permitted. Our legal bases are in particular:

4. Privacy on the website data-informed-decisions.com

4.1 Hosting

The website is served as a static site via GitHub Pages. When you visit, the hosting provider technically processes server log data (e.g., IP address, timestamp, requested file) that may briefly arise for security and operational purposes, outside our direct control.

4.2 No cookies, no trackers

The company website itself does not use cookies, analytics scripts, or advertising trackers.

4.3 Contact form

The contact form opens your own email client (mailto) with a pre-filled subject and body. Your input is not transmitted to or stored on any Data Informed Decisions LLC server — it only leaves your device once your email client sends it.

5. Privacy in the app langsi

langsi is the first app by Data Informed Decisions LLC, available at langsi.app as well as a native/cross-platform app for iOS and Android. The sections below describe in full detail what data is processed.

5.1 Registration & account

Art. 6(1)(b) GDPR

When you register, we collect account and profile data such as name, email address, and password. Passwords are stored only in hashed form, never in plain text. Optionally, you may add a profile picture.

5.2 Third-party login (social login)

Art. 6(1)(b) GDPR

Alongside email/password, we offer login buttons for Google, Microsoft, Facebook, and Apple. Sign-in is handled technically through our platform provider Base44 as identity broker (server-side OAuth) — no native SDK from these providers is embedded directly in the app. When you use one of these logins, we receive basic profile data from the respective provider (e.g., name, email address, profile picture), to the extent you have authorized this with that provider. The privacy policies of the respective chosen provider (Google, Microsoft, Meta/Facebook, Apple) additionally apply.

5.3 Usage and device data

Art. 6(1)(f) GDPR

To provide and secure the app, we process technical data such as device type, operating system version, IP address, and app events (e.g., features used). The app does not currently integrate a dedicated crash-reporting SDK; automated crash logs in the strict sense do not currently arise on our end. Should this change (e.g., through the addition of a crash-reporting service), this section will be updated accordingly.

5.4 Payment data

Art. 6(1)(b), (c) GDPR

Paid features (subscriptions) are processed through the payment provider Stripe (checkout, customer portal, subscription management). We do not store complete payment data ourselves (e.g., credit card numbers) — these are processed exclusively by Stripe. In our backend, we store the following reference and status data to manage your subscription: the Stripe customer ID (stripe_customer_id), the Stripe subscription ID (stripe_subscription_id), the plan you booked, the subscription status (e.g., active, canceled, past due), and the associated billing-period/term data.

5.5 Push notifications

Art. 6(1)(a), (f) GDPR

If you enable push notifications, Firebase Cloud Messaging (Google) generates a device token that is transmitted to our backend functions so we can send you notifications. You can disable push notifications at any time in your device or app settings.

5.6 AI-powered features

Art. 6(1)(b), (f) GDPR

Certain langsi features (e.g., vocabulary generation, explanations, image generation) use AI language models. Content you enter is transmitted to and processed by the providers OpenAI and Anthropic, as well as by model integrations managed by Base44, in order to deliver the respective feature. Please do not enter especially sensitive personal data about third parties in these features beyond what the request requires.

5.7 Transactional emails

Art. 6(1)(b) GDPR

System emails (e.g., welcome email, invoices, account notifications) are sent through the email provider Resend.

5.8 Analytics (Google Analytics 4)

Art. 6(1)(a) GDPR — consent only

On langsi.app we use Google Analytics 4 (Google LLC) for statistical analysis of usage. The associated script (gtag.js) only loads after you have explicitly given consent via our cookie consent banner. Without your consent, no analytics processing takes place. See Section 8, "Cookies & consent," for details.

5.9 CRM (internal use)

Art. 6(1)(f) GDPR

We use HubSpot as a customer relationship management (CRM) system for internal purposes, such as managing contact and support requests. HubSpot is set up but is currently used only to a limited extent (internally, administratively). We disclose it here in full as a precaution, since the technical authorization for data transfer exists.

5.10 Text-to-speech

Art. 6(1)(f) GDPR

Certain content can be read aloud using text-to-speech. For this, we use the speech synthesis built into your browser or operating system (including the Web Speech API), which, depending on your device, relies on engines from Google (Android/Chrome) or Apple (iOS/Safari). The text processed for this purpose (the app content to be read aloud) is handled by the respective OS/browser engine; beyond this feature, no separate transmission to us or to third parties takes place.

5.11 Internal project & support tool

Art. 6(1)(f) GDPR

For internal task and support management, we use ClickUp. ClickUp has API access as part of this internal use and is therefore disclosed here as a processor as a precaution, even though no direct processing of your app user data occurs through it.

6. Recipients & processors overview

The table below lists all service providers to whom personal data may be transmitted in connection with langsi, along with their role:

ProviderRoleData processed
Base44 Inc.Hosting, backend, database, auth broker, managed LLM/image integrationAll app data (account, usage, payment reference data)
Google LLCSocial login (Google), Firebase Cloud Messaging (push), Google Analytics 4Login profile data, device tokens, usage statistics (consent only)
Microsoft CorporationSocial login (Microsoft)Login profile data
Meta Platforms, Inc.Social login (Facebook)Login profile data
Apple Inc.Social login (Apple)Login profile data
Stripe, Inc.Payment processing, subscriptions, customer portalPayment and billing data
OpenAI, L.L.C.AI features (text generation)Content you enter in AI features
Anthropic, PBCAI features (text generation)Content you enter in AI features
ResendDelivery of transactional emailsEmail address, email content (system emails)
HubSpot, Inc.CRM (internal management)Contact and inquiry data
Google LLC / Apple Inc.Text-to-speech (Web Speech API / OS engine)Text to be read aloud, processed on-device
ClickUp, Inc.Internal project & support tool (API access)Generally no direct app user data; disclosed as a precaution

With all providers acting as processors, the required data processing agreements (Art. 28 GDPR) or the provider's respective standard contractual terms are in place or apply.

7. International data transfers

Most of the providers listed in Section 6 are based in the United States. Using these services may result in personal data being transferred to the US or to other third countries outside the EU/EEA.

Where applicable, we base such transfers on:

A list of currently used providers based outside the EU/EEA can be found in the table in Section 6. On request, we will inform you of the specific legal basis for the transfer to a particular provider.

8. Cookies & consent

The company website data-informed-decisions.com does not use cookies.

On langsi.app, we use technically necessary cookies (e.g., to maintain your login session) as well as — after your explicit consent via our cookie consent banner — analytics cookies from Google Analytics 4. Without your consent, Google Analytics remains disabled; the associated script is technically loaded only after you agree. You can withdraw your consent at any time with effect for the future by adjusting your cookie settings in langsi.app or by contacting us.

9. Retention & deletion

We store personal data only as long as necessary for the respective purposes, or as required by statutory retention periods (in particular commercial and tax law requirements for payment data).

9.1 Self-service deletion in the app

You can delete your langsi account directly in the app: Profile → Account information → Delete account. This immediately deletes the following data:

The following data is not automatically removed by the in-app self-deletion and may require a separate request, or is subject to its own retention obligations:

If you additionally wish to have your user account, favorites, push tokens, or your data held at Stripe fully deleted, contact us at info@data-informed-decisions.com. We process such requests promptly, unless statutory retention obligations prevent this.

9.2 Further retention periods

10. Children & minors

langsi is primarily intended for users aged 16 and over. Users under 16 should only use langsi with the consent of a parent or legal guardian (Art. 8 GDPR). The app currently has no technical age verification or automated collection of parental consent — parents and guardians are therefore asked to actively supervise use by minor children.

Should we become aware that personal data of a child was collected without the required parental consent, we will delete that data without undue delay. Parents and guardians who wish to request deletion may contact us at any time at info@data-informed-decisions.com.

11. Data security

We use technical and organizational measures to protect your data against loss, misuse, and unauthorized access — including encrypted data transmission (TLS/HTTPS), hashed password storage, and access restrictions on backend systems. Our hosting and backend provider Base44 provides the underlying infrastructure and database security. No system can be guaranteed to be 100% secure against any form of access; we continuously adapt our measures to the state of the art.

12. Your rights

Under the GDPR, you have in particular the following rights:

To exercise these rights, an informal email to info@data-informed-decisions.com is sufficient.

13. Changes to this policy

We update this Privacy Policy whenever our data processing changes — for example, with new features in langsi, new service providers, or the publication of additional apps. The "Last updated" date at the top of this page shows the most recent revision. It's worth checking this page again from time to time.

14. Contact for privacy inquiries

Data Informed Decisions LLC
8 The Green, Suite A, Dover, DE 19901, USA
Email: info@data-informed-decisions.com
Phone: +1 (716) 296-0224
Availability: Mon–Fri, 9:00–17:00 (ET)