Molim Privacy Policy
This is a courtesy translation. If it ever differs from the Russian original, the Russian text prevails.
Molim is an app where you learn Serbian with flashcards. This page explains what it knows about you, why it needs that, where it all lives, and how to remove it. No fog and no words you have to read twice: if a question remains after this text, write to us and we’ll answer in the same plain language.
In short
- You can learn without telling us anything about yourself: no name, no email, no phone number is asked for at the door.
- From the very first launch the app has a nameless account — a random number your progress is tied to. There is no email or name in it.
- An email appears only if you decide to create an account yourself: it exists for exactly one thing — getting your progress back on a new phone.
- Analytics are anonymous. Not a single letter of what you type in exercises, card reports or messages goes there.
- The conversation with a character is the only place where what you write leaves the app: a language model answers, and it has nothing to answer with without your line. We store the conversation nowhere.
- The account and everything tied to it is erased with one button: “Profile” → “Delete account”. Two exceptions — the name on the “Hvala” list, which is deliberately not linked to your account and is removed by writing to us, and the anonymous analytics, which are switched off by the toggle at the bottom of this text.
- We don’t sell data, there are no ads in the app, and nothing is passed to ad networks.
Who is responsible for this
The app and the data in it are the responsibility of the Molim developer — Nikita Shmyrev. This is not a corporation: an email to privacy@molim.talk is read by the same person who writes the code. That address is for everything data-related: finding out what we have about you, correcting it, getting a copy, deleting it.
If you use the app version from RuStore, your data is governed by a separate policy: molim.talk/ru/privacy. This text is about the App Store and Google Play versions; the Russian data contour does not touch them — except for payments made on the website: the record of such a payment is stored on our server in Russia (see “If you buy Molim+”).
What you need to get started
Nothing. The app doesn’t ask for a name, an email or a phone number, and doesn’t request access to contacts, camera, photos or location — it simply doesn’t have those permissions. In its whole life it will ask about two things: whether it may send reminders, and whether it may switch on the microphone in the exercise where a Serbian word is said out loud. Refusing breaks neither.
On first launch the app quietly creates itself a nameless account on the server: a random number, no email and no name. It exists so that what you’ve learned doesn’t depend on one phone. Which means a copy of your progress goes to the cloud before you’ve asked for anything — we say this outright, because there is no way you could have guessed it.
What goes to the cloud
The cloud is Supabase, Frankfurt region: the data sits in the European Union and never leaves it. The connection is encrypted, and access to rows is separated at the database level — your rows are visible only to your account.
- Progress on every word: which cards you have already seen, when they are due again, how many times you remembered and how many times the word slipped away.
- Your streak: how many days in a row you practise, what your best run was and how many times you came back after a break.
- How many new words you took on each of the days — the daily quota is calculated from this number.
- A service row saying the account exists: the app language and the result of your first level check.
- Subscription: what was bought, where it was bought and until what date it runs. There are no payments inside the app yet; rows appear here after a purchase on the website or in an app store.
- Card reports: which card, what’s wrong with it, your comment and — if you ticked the box yourself — a name for the “Hvala” list.
- Messages about the app from your profile: what you wrote, what you filed it under, the app version and the system — iOS or Android.
- Conversation counters: how many lines and scenes fell on each day and how many times you asked for a translation or a hint. Three numbers and a date — they power the free trial and the subscription cap. Not a single line of the conversations themselves is in this table.
If you created an account, next to it live your email and your password as a fingerprint from which the password itself cannot be recovered. We don’t see your password and cannot see it.
Supabase also keeps a sign-in journal there: when you signed in, when the account was created, when the email was changed — with the email itself and the network address the request came from. It exists for exactly one thing: working out whether someone else’s hands got into your account. The “Delete account” button erases it too — records about an account do not outlive the account.
What stays on the phone
The app is offline-first: everything a lesson needs lives on the phone itself and works without a network.
- Progress: cards, the repetition schedule, the streak, the daily counter.
- Settings: reminder time, the voice you chose, your answers about analytics and the microphone.
- Drafts: card reports and messages written offline wait for a connection right on the phone.
- The “Hvala” list saved from your last visit, so it opens on a plane too.
- The account key — in the system’s protected storage: Keychain on iPhone, Keystore on Android.
Delete the app and all of this disappears with it. The cloud copy stays — that one is removed by the “Delete account” button.
Reminders
Reminders are computed by the phone itself. The app checks how many cards are ripe and schedules a notification for the hour you chose — without a server and without the internet. Which means: we have no push token, your practice schedule is not sent anywhere, and nobody except the phone knows that you didn’t drop in today.
Microphone
In one exercise a Serbian word has to be said out loud. The microphone is needed there for exactly one thing: noticing that you started speaking and waiting until you finish — so the card doesn’t change mid-word. Permission is asked at the moment this exercise first appears, not at install.
What the app hears: loudness. One number, many times a second — it shows whether it got louder around you than it was. It doesn’t make out words and doesn’t grade pronunciation: on-device Serbian speech recognition doesn’t exist from any developer, and we are not building it. What you said goes nowhere — not to us and not to anyone else: the sound doesn’t leave the phone and isn’t stored anywhere. The app may use the network at that time — for progress sync and the anonymous analytics described above — but the recording isn’t in it.
An honest detail about how this works. The loudness comes from the recording status, and on both systems a recording goes into a file: there is no other way to get that number. The file is created by the system in the phone’s service folder for the few seconds you look at the card, and is erased as soon as the exercise ends. The app never opens or reads it — out of the whole recording it needs one number. If the app closes right in the middle of the exercise, the file stays in the service folder until the phone cleans it up itself; it doesn’t leave the phone in that case either.
The microphone is on only during the exercise itself and goes dark as soon as you answer or leave the card. It doesn’t work in the background — the build itself has no such capability. Refuse the permission and the exercise stays the same: you say the word out loud and tap “Next” yourself.
Audio
Words and examples are voiced by real people, and there are a lot of these files. Some ship inside the app, and the rest it downloads from our server molim.talk as you reach new topics: otherwise the install would weigh twice as much, and your mobile plan pays for it.
What the server sees: the ordinary traces of any download — the network address the request came from, the file name, the time and the app’s signature. From them it is clear that someone at such-and-such address fetched such-and-such word; there is no email and no account number in the request, and these lines are never joined with your account. The app goes there for sound only: it sends nothing about you.
What’s downloaded stays on the phone and isn’t requested twice. Delete the app — it leaves with it.
The molim.talk website
The site has no cookies and no counters: pages are just pages, no analytics stands on them. As on any website, the hosting logs keep request addresses (IP); they aren’t joined with anything and are erased as the logs rotate.
The site has a personal account area — molim.talk/account. It keeps your sign-in session (tokens and email) in your browser’s localStorage: that is your device, not our server, and signing out erases it. You sign in with a code sent to your email — it’s the same account as in the app.
Analytics
To understand whether the app works or only seems to, we count anonymous analytics. PostHog counts them, and we use its European cloud — eu.i.posthog.com; the data stays in the EU.
There are few events, and all of them are about the app, not about you. We note:
- that the app was opened — this is how we count whether people come back on day two and day seven
- that the first onboarding started, which screen it stopped on, whether it reached the end or was skimmed
- how many words out of twenty you marked as familiar at the very start — the daily quota of new words is tuned by this number
- which of the four goals you picked during onboarding — it sets the order of topics; the goal is a service code, not your own words
- that a session started, how many cards it had and how it ended — reached the end or closed midway
- that a session was launched from the “Topics” screen and which topic was chosen — the topic is a service code, not its name
- that the first session turned out real, not “opened and closed”
- that the answer to a specific card was accepted or not — the only event that is off by default; we switch it on only when analysing the words themselves
- that a streak survived to three, seven, fourteen or thirty days, and that another word moved to learned
- that the subscription screen was shown, closed or led to a purchase, and what exactly led to it — a locked deck, the daily quota, the first learned word or a week-long streak; the deck and the trigger are service codes
- that today’s new words ran out while open decks still have them, and that the free decks were finished entirely — these two marks show where the free part hits its border
- that the screen explaining reminders was shown and what you answered on it — before the phone’s system prompt
- that the reminder request was answered “yes” or “no”
- that the hint about the “Can’t hear” button was shown — it happens once ever
- that a conversation with a character started and how it ended: who you talked to, whether you’re new to Serbian or not, how many lines it took and whether the scene’s goal was reached — the character is a service code, and not a letter leaves the conversation itself
- that a translation of a line or a hint for a reply was needed in the conversation — they show where the Serbian runs short
- that the conversation hit the free limit and showed the Molim+ screen — and what exactly it hit
Event properties contain only numbers, flags and service codes in Latin script: a card number, a topic code, an exercise type. Everything else is cut off by a separate filter in the code — both by field name (email, name, input) and by the value itself: a string that reads like speech won’t pass even under a harmless name. This is not “we do our best” — it is a condition checked by tests.
Along with an event, the PostHog library attaches the app version, phone model, system and its version, language, time zone and screen size. And a random device number the app makes up itself — it is linked neither to an email nor to an account.
Country detection by network address is off. But the request still travels the network, and the IP address reaches PostHog’s servers — the same way it reaches any website you open. Session replay, surveys and remote toggles in the library are off as well.
You can switch the collection off in the same place you read this text: at the bottom of the “Privacy policy” screen there is a toggle. It doesn’t “stop sending” — after it, the app doesn’t create the PostHog client at all, and not a single request goes out. Whatever accumulated before the tap and hadn’t left yet isn’t sent either: the queue is discarded together with the client.
What you write yourself
The “something’s wrong here” flag on a card and “Write about the app” in the profile are your words, and they reach us as they are. We read them only to fix the card or the screen. The text doesn’t go into analytics: a person may write anything, including something personal.
The name on the “Hvala” list appears only via a checkbox you tick yourself, and you invent the name yourself — it is not the account name and not the email. The list is public, so every line passes through our hands before becoming visible. Changed your mind — write to us, we’ll remove it.
Separately — the email on the website. If you left your address in the “beta invite” form, it goes into our waiting list and lives there while the closed launch runs: one invitation email will come to it. Changed your mind — write to privacy@molim.talk, we’ll remove it. This list is not linked to the account in the app.
One honest detail: a line on the “Hvala” list is deliberately not linked to your account — otherwise the public name would give away who sent the card report. Because of this it doesn’t disappear by itself when the account is deleted: removing it takes an email from you.
The conversation with a character
The app has a conversation: a waiter in a kafana, a taxi driver, a landlord, a clerk at the MUP counter — Serbian in text, with a scene goal and hints. It doesn’t appear in all builds at once; if there is no “Conversation” card on your home screen, this section doesn’t concern you yet.
A language model answers in it, and this is the only place in the app where what you write leaves it: to answer, the model has to read your line. There is no conversation otherwise. Along with your line go the scene opening, the character’s replies and a list of Serbian words from your repetitions — the ones the character should put to work. There is no email and no account number in that request: our server calls the model, in its own name.
The answers come from OpenAI’s gpt-5.6-luna model, which we call directly. Its servers are outside the European Union, and what happens to the text on their side is decided by OpenAI’s rules: for API traffic they promise not to train their models on what’s sent and to keep it briefly — just long enough to investigate abuse. This is the only part of the path that isn’t in our hands, so we’ll say it plainly: don’t tell the character anything you wouldn’t tell a stranger in a kafana. If we change the model, the name in this paragraph changes too.
We don’t store the conversation. Not in the database, not in server logs — the server retells it to the model and forgets. The conversation lives in the phone’s memory while the screen is open and leaves with it: there is no conversation history in the app. What remains on our side is numbers only — how many scenes and lines there were in a day, so the free trial and the subscription cap work — and the scene’s outcome in your statistics: how many lines you managed and how many repetition words you put to work.
If you buy Molim+
There are two ways to buy, and the data differs. In an app store — Apple, Google or RuStore: there the payment is entirely theirs; we only learn that the purchase happened, which product it is and until what date it runs.
The second way is paying right on the molim.talk website: one-off, by card or via SBP (the Russian fast-payments system), or — if you switch it on yourself — as an auto-renewing subscription, by card. It exists for people the stores don’t work for. Then we get: the email you enter at payment, the amount, the date, the payment number and the period of access you bought; with SBP payments the bank also tells us the payer’s name. A card number never appears: the payment is processed by Tochka Bank, you enter the card on the bank’s page, and for a subscription the link to your card is stored with the bank as well. The receipt is sent by the bank’s fiscalisation service — the fiscal data operator’s name is on the receipt itself. The payment record is stored on our server in Russia. Access is tied to the email you paid with — that is how the app finds it, on any phone.
Who we give it to
- Supabase — the cloud where the account and progress live. Frankfurt region, European Union.
- PostHog — anonymous analytics. European cloud.
- The mail service connected to Supabase — delivers the sign-in code emails. It sees the recipient’s address and the code itself.
- OpenAI — the language model that answers in the conversation with a character. It gets the conversation text and nothing more: no email, no account number. Servers outside the European Union; details in the conversation section.
- The molim.talk website hosting — the audio the app downloads lives there too. Server in Europe.
- Apple and Google — the stores the app is installed through and will one day be paid through. We pass them nothing extra.
- Tochka Bank — processes payments on the website and keeps the debit schedule if you set up a subscription. It gets the email and the amount — to process the payment and have its fiscalisation service send the receipt. It doesn’t show us the card number.
Nobody else. There are no ad networks, data brokers or “partners” in the app, and none are planned. The data is not for sale — not for money and not in exchange for anything.
How long it lives
- The account, progress, card reports and messages live while the account lives. Delete the account — they vanish that same minute, all at once.
- Anonymous analytics events are kept no longer than 12 months.
- Deleting the account erases the progress on the phone itself too: the app becomes what it was right after install. Words, the repetition schedule, the streak — everything leaves with the account, and there will be nothing to restore it with.
How to delete everything
In the app: “Profile” → “Delete account”. We’ll ask once, and then we remove the account together with everything tied to it in the cloud — the email, the progress copy, the streak, card reports and messages — and erase the lessons on this phone. It is forever: there will be nothing to restore it with, even for us.
Want nothing left on the phone either — delete the app. Need help, or something went wrong — write to privacy@molim.talk, we’ll delete by hand.
Your rights
If you are in the European Union, you have GDPR rights — and we honour them for everyone, not only those with a European address:
- learn what exactly we have about you and get a copy in a file;
- correct what is recorded inaccurately;
- delete everything — with the button in the app or by email;
- ask us to pause processing while we sort something out;
- object to analytics — the toggle is enough, no email needed;
- withdraw consent for the name on “Hvala” without explaining why;
- complain about us to a data protection authority: in your own country if you live in the EU, or to the Serbian Commissioner for personal data protection.
Requests come to privacy@molim.talk. We answer within ten business days, usually within a couple.
What it all rests on legally: the account and progress — to do the thing the app was installed for; analytics — our legitimate interest in seeing whether it works, and you can opt out with one move; the name on “Hvala” — only your explicit consent.
About age
Molim is made for adults who have moved and are working out Serbian along the way, and we don’t make it for children on purpose. From fourteen you can create an account yourself. If you are younger — only together with a parent: at that age decisions about your data are theirs. In parts of the European Union the threshold is higher, up to sixteen; there, a parent is needed until that age too.
If this text changes
It lives in the same place as the app code and changes together with it. If something substantial changes, the date at the top changes too, and the text updates in the app and at the public link at the same time: the Russian original is built from a single source, so its copies have nothing to drift apart with. This English page is a courtesy translation updated together with it; if the two ever differ, the Russian text prevails.
Where to write
privacy@molim.talk — for any question about this text. Or “Write about the app” in the profile, if that’s easier right from the app.