Privacy Policy
6 October 2026
Privacy Policy
Last updated: 6 October 2026
This Privacy Policy explains how MTech & IT (“we”, “us”, or “our”) collects, uses, and protects personal data when you use Workword — the mobile application and the website at https://workword.eu (together, the “Service”).
We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Dutch privacy law.
This document is provided for transparency and website publication. It is not a substitute for professional legal advice. We recommend independent legal review before relying on it as final counsel for store listings or commercial contracts.
1. Who we are (data controller)
| Controller | MTech & IT |
| Address | Wismar, Hattem, The Netherlands |
| contact@workword.eu | |
| Website | https://workword.eu |
For privacy requests (access, deletion, questions), contact us at contact@workword.eu.
2. What Workword is
Workword is a language-learning product for foreign and migrant workers. It teaches job-specific Dutch, English, German, French, Italian, Spanish, and Portuguese through workplace vocabulary, phrases, listening practice, and safety-related language for sectors such as welding, hospitality, butchery, and related tracks.
The Service may be used by individual learners and, where an employer has an account, in connection with an employer invite or company link.
3. Personal data we process
Depending on how you use the Service, we may process the following categories of data.
3.1 Account and profile
- Email address
- Whether your email address is verified (
email_verifiedon your profile), mirrored from Firebase Authentication after you confirm the link we send (or when your sign-in provider already marks the address as verified) - Name (
name) — your full name for regular accounts, or the company name for company accounts (also mirrored todisplay_namefor compatibility) - Username (
username) — a unique public handle without spaces (lowercase letters, numbers, underscore), chosen at email/password sign-up or derived from the email local-part for Google/Apple sign-in - Timestamps of the last name and username change (
name_changed_at,username_changed_at) so we can enforce a maximum of one change per week for each field after the first set - Profile photo (if you upload one)
- Authentication identifiers (for example Firebase Auth user ID)
- Sign-in method metadata when you use email/password, Google Sign-In (available in the mobile apps and on the website, including mobile browsers via Google OAuth redirect), or Sign in with Apple (iOS app)
- A one-time age eligibility confirmation (16+) stored as a timestamp (
age_confirmed_at) on your user profile — we do not collect your date of birth - Account type (
user_type: regular or company) and, when you request a switch in Settings, a pending confirmation flag and a 48-hour provisional window (account_type_provisional_until,account_type_previous) so you can revert in the app. We email you signed confirmation links (Yes/No) to your account email via our SMTP mailer before the switch takes effect - When you finish onboarding, we may send a one-time welcome email to your account email (via our SMTP mailer), chosen for your account type — individual learner, learner linked to an employer, or company/employer — and delivered in your My language setting where available
3.2 Learning and preferences
- Selected target and source languages
- Selected sector / learning path
- Optional default job under that sector (
default_job_id) when you choose a role or an employer invite assigns one; company / multi-sector accounts may also store per-sector jobs (default_job_ids) - Optional Start with the alphabet preference (
script_bridge_enabled) when your My Language does not use the Latin alphabet — alphabet, first words, and starter grammar alongside sector Basics - Lesson and module progress, completion status, streaks, experience points (XP), gamification level, and related learning history
- Review Mistakes — when you answer incorrectly in a learning-path lesson or exit quiz, we may store a per-item miss count and last-missed time (
word_mistakes/phrase_mistakes) on your device and in your sector learning snapshot underuser_learning_history, together with spaced-repetition (SRS) card state, so you can rehearse weak items from the Practice tab. Successful practice reviews can clear those mistake entries - Listening practice audio — when you tap listen on a lesson word or phrase while online and signed in, the spoken prompt text may be sent to our Cloud Functions and processed by ElevenLabs to synthesize speech; a short audio clip may be cached on your device. If cloud synthesis is unavailable (for example offline), the app falls back to on-device text-to-speech and does not send the prompt text to ElevenLabs
- Hands-free listening exercises — on the Exercises tab, Listening: words & phrases and Listen & answer play learned vocabulary with on-device or cloud text-to-speech. On mobile, an ongoing media-style notification lets you play, pause, or stop while the screen is off. Listen & answer also uses on-device speech recognition (microphone) to grade your spoken translation; transcripts are processed on your device and are not sent to ElevenLabs or our servers as speech audio
- Official exam prep practice progress — A1 Official Exam Prep (for example Basisexamen inburgering or Cambridge A2 Key–style modules) and A2 Exam Prep practice packs after you complete A2 on a sector path — including module completion and mock exam attempt scores stored on your device and optionally synced to your account so you can continue across devices
- Sector completion certificates stored on your account under
user_certificates(sector, optional job role badge, certificate kind, display name, issue time) when you earn a downloadable completion certificate — including full sector-track certificates, words & phrases milestone certificates after passing the sector words and phrases exam, and Workword A2 certificates after finishing the A2 learning path (A2.0–A2+) and A2 Exam Prep practice when that prep is offered for your target language - Learning progress may also record whether you passed the sector words and phrases exam (
words_phrases_exam_passed) and related certificate timestamps (legacy / sync support) - Sector completion certificate issue timestamps on learning progress (legacy / sync support)
- Onboarding and placement-related choices
- Lesson reminder and language settings stored on your device and/or synced to your account
- Challenge results — when you complete, decline, or cancel solo challenges (shown in the app as Goals & Challenges), we store a history entry under
user_challenges_history(challenge id, mode, outcome, XP earned, optional target-date metadata, and your default sector when known). After you set a personal target date, solo challenges may auto-complete from your learning progress (for example words learned, phrases completed, lessons finished, streak days, safety-critical vocabulary, or simulated conversations) measured against that challenge’s threshold in your default sector (and, for safety challenges, the safety-critical overlay for that sector). Optional solo target goals underuser_solo_challenge_goalsmay store a numeric baseline snapshot of those counts when you start the challenge (not a full list of word or phrase IDs) so only progress after you set the target counts, and may include an optional recurrence setting (interval unit of day, week, or month and an amount) so a completed goal can start the next period with a new deadline and baseline instead of being cleared. - Workplace exercise sessions — when you invite colleagues to or join a sector exercise with colleagues (async same-set drills such as vocab battle, safety call-out, phrase check, toolbox talk, handover race, listen challenge, picture call-out, or type-off), we store an
exercise_sessionsdocument with company link, host, invited/participant uids, sector, exercise kind, start conditions (start_mode, optionalscheduled_start_at,min_accept_count), play duration (duration_ms, default eight hours), activation and play-window timestamps (started_at,play_ends_at), invite deadline (expires_at; for accept-count starts this is ten hours after creation), invite-reminder scheduling fields (invite_reminder_at,invite_reminder_sent), pre-generated question prompts/options, your submitted scores and elapsed time, and ranked results among participants. Correct-answer keys are stored in a server-only secrets subcollection. Sessions stay pending until start conditions are met, then become active for the play window. Outstanding invites that hit the deadline without enough accepts are marked expired. Personal drills on the Exercises tab are scored on your device; completing them may award XP via the same XP pipeline as other learning actions. Colleague exercise scores and answers are not shared with the employer company account. - Streak Buddy pairs — when you send or accept a Streak Buddy request from the Employer screen, we store a
streak_buddiesdocument with company link, member uids, requester/recipient, status (pending,active,declined,ended, orexpired), shared streak counters (shared_streak,highest_shared_streak), last mutual practice date, per-member last practice dates in each member’s timezone, and timestamps (including pending invite expiry). Shared streak counters advance only when both buddies complete qualifying practice on their own local calendar day. Personal streak counters on your profile remain separate. Streak Buddy pair data is visible to the two members only; the employer company account cannot read pair documents or shared streak numbers. - Custom flashcards — when you create decks and cards in Flashcards (Custom) on the Exercises tab, we store deck names, prompt/answer text, sector id, deck id, and timestamps under
user_custom_flashcards(also cached on-device). These decks and cards are only for your account and are not shared with employers or colleagues. - Flashcard exercise history — when you complete Flashcards or Flashcards (Custom) personal drills, we store your session score, timing, sector, languages, optional deck id, and per-card self-grades (prompt, answer, knew/didn't know) under
user_flashcard_exercise_history. This history is private to your account and is not shared with employers or colleagues.
Mock exam results are practice scores only. They are kept private to your account by default and are not shared with employers unless we clearly ask for a separate opt-in in the future.
3.3 Device and notifications
- Push notification tokens (for example FCM device tokens) when notifications are enabled (for example lesson reminders, flashcard review reminders, workplace exercise invites, invite expiry reminders (about three hours before an unanswered invite closes), workplace exercise started alerts from linked colleagues, Streak Buddy requests, Streak Buddy accept/decline/end notices, Streak Buddy practice nudges, company announcements from your linked employer, and for company accounts notices such as colleague reports and employee seat opened when a linked learner reaches A1). Tokens are stored under your user document’s private push settings (
users/{uid}/private/push) so linked employers cannot read them from your profile document. - Local preferences stored on your device (for example via SharedPreferences) to support offline use and settings, including appearance choices such as light/dark mode and color theme, notification toggles (lesson reminders and optional flashcard review reminders), flashcard reviewing options (learning steps and intervals), and optional solo challenge target dates (plus baseline progress counts for auto-complete and optional recurrence interval unit/amount) you set on the home screen
- An optional encrypted offline lesson pack you download from the learning path screen: illustration files for your sector track (Basics and A1 levels, plus any overlay paths you selected) and, when you are linked to an employer, a local snapshot of that employer’s basic-words override and custom words. Media is stored encrypted in the app’s private storage; the encryption key is kept in the platform secure store. You can remove the pack from the same screen
- Optional offline flashcard packs you download from Flashcards or Flashcards (Custom): card text, spaced-repetition state for those cards, and any images or audio attached to your custom notes. Packs are stored in the app’s private storage on the device; you can remove them from the same download screen
- Images or audio you attach to custom flashcards (for example image occlusion or audio-to-text notes), stored in Firebase Storage under your account
- Completion certificate PDFs you generate and share from your device (you control where you send them)
- An encrypted local screen cache on mobile devices (iOS/Android): snapshots of data shown on Home (including challenges and achievements), Profile, Employees, Employer, Employee Results, Learning Paths Overview (admin engagement metrics), User management in the Admin Panel (first page of the user list for operators), and Achievements. Payloads are sealed with AES-GCM; the encryption key is kept in the platform secure store. Screens paint from this cache immediately, then refresh from our servers in the background while you use the app (not while the app is closed). The cache is cleared when you sign out
- An encrypted in-app Notifications inbox stored in Firestore collection
user_notifications(default database): achievement unlock notices, company announcement notices, workplace exercise invite notices, and Streak Buddy request notices. Each notification body is sealed with AES-GCM on your device before sync; the encryption key is kept in the platform secure store. Operators and other accounts cannot read the plaintext. On mobile, a local warm cache of the same inbox may also be kept for faster display and is cleared when you sign out - For operator (admin) accounts, the same Notifications screen may also show server-authored operational alerts (plaintext rows under
user_notifications): new in-lesson content reports (reports), new contact form submissions (contact_messages), new support report submissions (support_reports), new user sign-ups, successful blog post generation awaiting approval, blog generation failures, and successful blog social shares after an approved post is set visible. These alerts are written by Cloud Functions to each eligible admin’s inbox and are gated by the same Admin Notifications preference toggles used for push
3.4 Employer / company link (if applicable)
- Employer or company association when you redeem an invite code or open an invite link (for example
https://workword.eu/invite/...) - An employer may enter an employee email address in the app so Workword can send that person an invite email (via our SMTP mailer) containing a one-time invite code and invite link. We may store that email on the invite record (
invite_codes) for delivery and audit; it is not used to restrict who may redeem the code - When you link to a company (for example by redeeming an invite), we may email a confirmation to your account email and to the company account email. When either party ends the company link, we may email both sides a unlink confirmation. These transactional notices use your My language setting where available
- Either party may end the company link without deleting the learner account: a linked employee may unlink from Settings, and an employer may unlink an employee from the Employees screen. Unlinking clears the company association and employer-assigned learning goals; learning progress stays on the learner’s account
- Sector or content assignment linked to that employer relationship (your employer may assign or later change your workplace sector and job among the sectors they offer; changing sector clears any employer-assigned learning goal for the previous sector; changing only the job keeps the current learning goal)
- Employer-assigned learning goals (a target learning level for your current sector), including a default goal that an employer may configure so newly linked employees receive it automatically on invite redeem
- Workplace vocabulary that an employer account adds or customizes for the basic words learning level of a sector (for example Dutch and English lemmas), which is then shown to linked employees in that company’s learning path
- Progress information made available to an employer in a privacy-bounded way (see Section 6)
- Employer display name, profile photo, and company account email shown to linked employees on Home and the Employer screen (see Section 6)
- Display name and default sector id shared with linked coworkers via the in-app colleague directory when you are linked to the same employer (peer email is not shared through that directory — see Section 6)
- Company announcements — when your linked employer posts an announcement in the Employees screen, we store the title, message, audience (all linked employees or selected employees), recipient list, and timestamps in
company_announcements. Linked employees who are recipients may receive a push notification and can open the announcement in the app; employers can create, edit, and delete announcements for their company - A pending invite code may be stored locally on your device (for example via SharedPreferences) until you sign in or sign up and the invite is applied during onboarding
3.5 Legacy messaging data (product removed)
In-app Messaging (direct chats, learning groups, company employee-group chats, Study Buddy, group challenges, and chat voice) is no longer offered in Workword. We no longer process new chat content for that product.
If you used Messaging before it was removed, residual encrypted chat metadata or message ciphertext may still exist in our systems (user_chats, user_chat_messages, and related Storage paths) until operators purge it. On account deletion, we remove you from legacy user_chats membership and null your chat_public_key. Historical ciphertext may remain until purged and is not usable without the corresponding keys.
3.6 Technical and security data
- Data necessary to operate authentication, sync progress, and store files securely through our infrastructure providers
- API usage counters used to enforce per-account rate limits (for example requests per minute, day, week, and month)
- Security monitoring signals when automated abuse checks trigger (for example repeated failed invite redemptions, rate-limit breaches, or repeated denied privileged actions). Operators with an admin Workword account may receive a push notification and/or email that includes the affected account’s name (display name), username (when set), account email (when available), Firebase Auth user ID, the signal type, time, and limited technical context so we can investigate abuse. These alerts are sent only to admin operators, not to employers or other learners.
- New Support contact form submissions. Operators with an admin Workword account may receive a device push notification, and an email is sent to contact@workword.eu with the submission details (sender email, user ID when signed in, subject, message, and related metadata) so we can respond. These Support operational notices are not sent to employers or other learners.
- New support report submissions. Operators with an admin Workword account who have enabled Support report alerts may receive a device push notification and/or an email to their admin account email address with the report details (sender email, user ID when signed in, category, message, and related metadata). A copy is also sent to contact@workword.eu for triage when the global Support report email toggle is on. These notices are not sent to employers or other learners.
- New user / colleague reports about other accounts (from the colleague directory / Employer screen). When a colleague report is sent to the company, the linked company account may receive a push notification and an email to that company’s account email address with report details (reporter and reported identifiers, reason, message, and related metadata) so the employer can follow up. Workword operators may also review these reports where needed for safety.
3.7 Crash reports and diagnostics (mobile apps)
When you use the Workword mobile apps (Android or iOS), we may process diagnostic data to detect and fix crashes and stability issues, including:
- Crash and non-fatal error reports (for example stack traces and error messages)
- Device and app context (for example device model, OS version, app version, and build)
- Limited breadcrumb / usage context leading up to a crash (via Google Analytics integrated with Crashlytics), such as screen or event names
- Product / acquisition events via Firebase Analytics (for example
sign_upwhen a new account is created), which may be linked to Google Ads for conversion reporting when that link is enabled
We do not collect the Android Advertising ID (GAID) or use advertising identifiers for device advertising. On Android, Analytics advertising-ID collection is disabled and the related permission is not included in the app.
This diagnostic processing applies to the mobile apps via Crashlytics. On the website at https://app.workword.eu, unexpected errors may be stored in Firestore collection client_error_reports (error message, optional stack snippet, signed-in user ID, and platform) so we can fix web stability issues. These web reports are create-only for the signed-in user and are not readable by other clients.
3.8 In-app Support (contact and reports)
When you use the in-app Support screens to contact us or submit a report, we process:
- The subject and message you enter on the Contact form (stored in Firestore collection
contact_messages) - The category and message you enter on the Report form (stored in Firestore collection
support_reports), such as bug, content problem, account/privacy, or other - Your Firebase Auth user ID and account email address (when available) so we can identify and reply to you
- Optional device/app context on reports (for example app version and platform) to help triage technical issues
Operators with access to the Workword Firebase project may read these submissions to respond to support requests and improve the product. Please do not include special-category or highly sensitive personal data in free-text fields unless we expressly ask for it for a defined purpose.
We do not require you to provide special-category data (for example health data) to use Workword. Please do not submit sensitive personal information in free-text fields unless we expressly ask for it for a defined purpose.
3.8a User / colleague reports
You may report a colleague to your linked employer from the Employer screen. When you do, we process:
- Your Firebase Auth user ID and account email (reporter)
- The reported user’s Firebase Auth user ID
- Report source (for example
colleague), reason, optional free-text details, optional sharedcompany_uid, platform, and app version - Records stored in Firestore collection
user_reports
Colleague reports are directed to the linked company account (push and email as described in Section 3.6). Workword operators may also review reports where needed for safety.
3.8b Employer lead form (freemium bonus)
When you are on free access and finish your first free sector basic-words lessons, the app may invite you to share employer details in exchange for unlocking additional free sector basic-words lessons. If you submit that form, we process:
- Company name, city, and contact email you enter
- The primary official language of the country for the city you select
(
city_language, ISO 639-1 such asnlorde), derived from that selection — not from free-typed text - Your Firebase Auth user ID and a submission timestamp
- A profile flag that you unlocked the freemium bonus (
employer_lead_bonus_unlocked)
To help you pick a real city, the app sends your city search text from your device to Photon (komoot; OpenStreetMap data) and shows matching suggestions. Only the city you select (plus the derived language code) is stored with the lead; search queries are not stored in Firestore.
These details are stored in Firestore collection company_leads for operator follow-up about workplace / company subscriptions (B2B outreach). Submitting the form does not create an employer account link, send an invite to that company, or share your learning progress with the organisation you named. Access is limited to Workword operators (Admin SDK / console); company accounts cannot read company_leads. You may skip the form and keep the base freemium limits, or subscribe instead.
When we send employer-prospect marketing emails (Workword for companies), each message includes an Unsubscribe link. Confirming opt-out stores your email address in Firestore collection marketing_email_suppressions so we do not send further prospect marketing to that address, and stops any active outreach sequence on matching company_leads records. This marketing opt-out is separate from in-app operational email preferences for signed-in users.
3.9 In-lesson content flags and job requests
During progressive sector lessons, you may tap a flag control to report a specific word or phrase. When you do, we process:
- Identifiers for the flagged item (
content_typeof word or phrase,content_id, and a short snapshot of the displayed target-language text ascontent_text) - Lesson context (
sector,lesson_id,level_id) so we can find and fix the item - An optional free-text reason you enter
- Your Firebase Auth user ID and account email address (when available)
- Optional device/app context (for example app version and platform)
From the sector details popup (onboarding and settings), you may also request a missing job. When you do, we process:
- The job name you enter (
content_typejob_request, stored asjob_name/content_text) - An optional job description
- An optional sector you select from the current tracks, or an optional suggested sector name if you choose “Suggest sector”
- Your Firebase Auth user ID and account email address (when available)
- Optional device/app context (for example app version and platform)
These in-lesson flags and job requests are stored in the Firestore collection reports (separate from Support form submissions in support_reports). Operators with access to the Workword Firebase project may read them to correct content, improve lessons, and consider new job roles. Please do not include special-category or highly sensitive personal data in free-text fields.
3.10 Subscriptions and billing
When you or your employer subscribe:
- Individual plans: App Store / Play purchase identifiers and verification data needed to confirm the purchase, plus subscription status and trial/expiry timestamps we store on your profile to gate access
- Company plans: Stripe customer and subscription identifiers, selected plan / seat limit, and subscription status on the company profile
- Linked employees do not carry personal billing fields for the employer plan; access follows the company’s entitlement
- Subscription emails: when a personal or company subscription starts or ends, we may send a transactional confirmation to the account email (and, when a company entitlement starts or ends, to linked employees about employer-covered access). Copy is delivered in the recipient’s My language where available
- Targeted discounts and offers: operators may create allow-list-only offers (no public promo codes). We store offer metadata and redemption records (
discount_offers) so we can grant complimentary access days to listed regular users or apply a Stripe coupon at company Checkout. Only listed account identifiers are associated with an offer
4. Purposes and legal bases
| Purpose | Examples | Legal basis (GDPR) |
|---|---|---|
| Provide the Service | Create account, sync progress, deliver lessons, listening practice (cloud or on-device TTS), offline cache (including optional encrypted offline lesson packs and the encrypted local screen cache on mobile), issue completion certificates | Performance of a contract (Art. 6(1)(b)) |
| Subscriptions and billing | Process individual App Store / Play purchases and company Stripe subscriptions; store entitlement status and seat limits to gate access; track whether a linked employee currently occupies a company seat (employer_seat_occupied) and when that seat became occupied (employer_seat_occupied_at) so seats can reopen after the words & phrases exam while the link remains; apply operator-targeted discount offers (complimentary access or Stripe Checkout coupons) to allow-listed accounts |
Performance of a contract (Art. 6(1)(b)); legitimate interests to run promotions (Art. 6(1)(f)); legal obligation for invoicing where applicable (Art. 6(1)(c)) |
| Employer-linked features | Apply invite code or invite link; optionally email an invite code/link to an address the employer enters (SMTP); show limited progress to an employer account; store employer-authored workplace vocabulary for linked learners | Contract and/or legitimate interests (Art. 6(1)(b)/(f)), balanced against learner rights |
| Push notifications | Lesson reminders and similar product alerts where enabled | Consent where required (Art. 6(1)(a)); you can disable notifications in Settings → Notifications and/or device system settings |
| In-app support | Process contact and report submissions so we can reply and fix issues | Performance of a contract (Art. 6(1)(b)); legitimate interests to improve the product (Art. 6(1)(f)) |
| User / colleague reports | Process colleague reports (user_reports); notify, where applicable, the linked company and operators |
Performance of a contract (Art. 6(1)(b)); legitimate interests to keep the Service safe and usable (Art. 6(1)(f)) |
| In-lesson content flags and job requests | Process flagged words/phrases and missing-job requests (reports) so we can correct lesson content and consider new job roles |
Performance of a contract (Art. 6(1)(b)); legitimate interests to improve the product (Art. 6(1)(f)) |
| Security and abuse prevention | Authenticate users; protect accounts and infrastructure; rate-limit API calls; alert admin operators about suspicious automated activity | Legitimate interests (Art. 6(1)(f)) |
| Improve and maintain the product | Fix bugs; ensure reliability of learning sync; crash and stability diagnostics via Crashlytics | Legitimate interests (Art. 6(1)(f)) |
| Website advertising and measurement (marketing site) | Separate analytics and advertising consent choices; Google Ads destination measurement; intended enhanced-conversion measurement, conversion-based customer-list advertising, and Analytics-audience remarketing where enabled — subject to consent and actual data flows (see Section 11) | Consent where required (Art. 6(1)(a)); you can withdraw via the website’s cookie settings |
| Legal compliance | Respond to lawful requests; keep required records | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we balance those interests against your rights and expectations as a learner and, where relevant, as an employee.
5. Processors and subprocessors
We use trusted service providers to host and operate parts of the Service. In particular, we use Google Firebase / Google Cloud for:
- Firebase Authentication — account sign-in (email/password, Google Sign-In, and Sign in with Apple on iOS)
- Cloud Firestore — profiles, learning history (including sector learning-path lesson progress under the
user_learning_historycollection on the default database), employer-authored company vocabulary overrides, company announcements (company_announcements), company activity feed (company_activity) for linked coworkers, challenge catalogs (challenges), solo challenge target dates (user_solo_challenge_goals), learner-authored custom flashcards (user_custom_flashcards), flashcard review settings and exercise SRS state (user_flashcard_review_settings,user_exercise_flashcard_srs), flashcard exercise history (user_flashcard_exercise_history), challenge results history (user_challenges_history), workplace exercise sessions (exercise_sessions, including server-only answer secrets), Streak Buddy pairs (streak_buddies), encrypted in-app Notifications inbox (user_notifications, including server-authored admin operational alerts), in-app Support contact and report submissions (contact_messages,support_reports), freemium employer leads (company_leads), marketing email opt-outs (marketing_email_suppressions), user/colleague safety reports (user_reports), in-lesson content flags (reports), public product release notes and upcoming updates (release_notes,app_upcoming), the public FAQ catalog (faqs), operator Automations social generate/publish audit records (automations_in_output), targeted discount offers and redemptions (discount_offers), and related app data. Residual legacy chat collections (user_chats,user_chat_messages) may still exist until operators purge them (see Section 3.5) - Firebase Storage — profile photos, vocabulary illustration images used in lessons and quizzes (royalty-free stock hosted by us; not user uploads), blog preview images for the in-app blog, and social-post images generated by operators for LinkedIn / Facebook / Instagram publishing (operator-generated; not user uploads). Residual legacy chat voice files under chat-scoped paths may still exist until operators purge them
- Firebase Cloud Messaging — push notifications
- Cloud Functions — server-side app logic where configured (including XP awards and lesson listening speech synthesis proxy)
- Firebase Crashlytics — crash and non-fatal error reporting for the mobile apps
- Google Analytics for Firebase — app analytics for product and acquisition
measurement (for example the standard
sign_upevent after a new account is created). Crashlytics may also use Analytics breadcrumbs for diagnostics. Android Advertising ID / GAID is not collected. When our Firebase / GA4 property is linked to Google Ads, selected Analytics events (such assign_up) may be imported as conversion actions for campaign reporting
Marketing measurement (website and app-store ads)
When we run paid acquisition (for example Google Ads Search campaigns to https://workword.eu), we may use:
- Google Ads — ad delivery, click measurement, and conversion reporting for campaigns we operate
- Google Play (linked to Google Ads) — install and related app conversion
signals for the Android app (
com.mtechit.workword) when our Ads account is linked in Play Console. This does not require Workword to collect the Android Advertising ID (GAID) inside the app - Firebase Analytics / GA4 (app + linked property) — in-app events such as
sign_upimported into Google Ads when the Firebase/GA4 property is linked - Google tag / Google Analytics 4 on marketing pages (for example
/app,/for-employers,/contact) when enabled — page views, campaign parameters (such as UTM / click identifiers), and optional secondary events such as store-button clicks, subject to consent where required (see Section 11) - Google Tag Manager (container
GTM-WJ6G8B7F) on the Flutter web app at https://app.workword.eu — loads tags configured in that container on each visit. Those tags may process page context, network metadata (including IP address), browser/device information, and cookies or similar identifiers that the configured tags set (for example Google Analytics 4 or Google Ads measurement tags). See Section 11
We also use ElevenLabs as a processor for text-to-speech when cloud listening audio is generated for lesson words and phrases (prompt text only; not your microphone recordings). On-device speech synthesis may use the platform TTS engines on your device without sending that text to ElevenLabs.
For the freemium employer lead city field, the app may send city search queries from your device to Photon (operated by komoot; powered by OpenStreetMap data) so you can select a real city. Photon receives the search text you type; we do not send your account email or user ID to Photon.
We use Activepieces to publish operator-authored marketing posts from the Admin Panel Automations screen to LinkedIn, Facebook Pages, and Instagram (Meta). The webhook payload contains only the generated post text, selected platform names, an optional public image URL, and a Workword website link — not learner profiles, emails, or learning history. LinkedIn and Meta process that content as the destination social networks for those operator posts. Operator generate/publish attempts from that screen are also stored in Firestore collection automations_in_output (prompt/platforms, generated text and optional image URL, Activepieces response or error, and the operator account id) for operational audit — not for learner profiling.
Payment processors
Depending on how you subscribe, we use:
- Apple (App Store / StoreKit) — individual subscription purchases and renewals on iOS
- Google (Google Play Billing) — individual subscription purchases and renewals on Android
- Stripe — company (employer) subscription Checkout, invoices, and the Customer Portal
We receive purchase and entitlement metadata needed to unlock the Service (for example product or price identifiers, subscription status, trial and expiry timestamps, seat limits for company plans, and Stripe customer/subscription identifiers for company accounts). Card numbers are processed by Apple, Google, or Stripe — not stored by Workword.
Where these providers act as processors, they process data on our instructions. Provider roles depend on the service and the applicable contractual terms. Google publishes separate controller and processor terms for its advertising and measurement services; Google Ads must not be treated as a processor for every use solely because Firebase or other Google services are also used. Google's terms address international processing and transfers, with service-specific provisions for applicable transfer safeguards. See Google’s controller terms and processor terms for the service-specific roles and transfer provisions that may apply.
Marketing website Google Ads / Analytics (account details)
On the marketing website at https://workword.eu, advertising measurement is configured to send data to Google Ads destination AW-17181401897 only with your separate advertising permission. That configured identifier does not by itself describe every destination linked through Google’s account settings.
Our linked Google Analytics property is workword-c1032 (property ID 545533994), with measurement ID G-42N0ETYX3P and reported Google tag GT-MJPR357P. In our Ads / Analytics product linking, import of Google Analytics audiences is on and app and web metrics are off. Our Google Ads account settings currently enable enhanced conversions, conversion-based customer lists, and automatic detection of user-provided data for email, phone number, and name and address. Those settings establish configured capabilities; they do not prove that the marketing website collects or transmits each of those fields on every visit.
Under the regional Google Ads Advertising Program Terms we use for business purposes (effective 1 July 2026), the applicable Google contracting entity is Google Ireland Limited. We accepted the Google Analytics Data Processing Terms on 2 December 2020. We have accepted Google Ads customer-data terms; the acceptance date for those Ads customer-data terms is not recorded in this policy. Advertising Program Terms acceptance evidence beyond the regional text and business-use confirmation is not reproduced here.
Data may be processed in the European Union and/or other regions where Google (including Firebase, Google Ads, Google Play, and Analytics), ElevenLabs, Apple, Stripe, Activepieces, LinkedIn, Meta, or Photon (komoot / OpenStreetMap) operate infrastructure. Where personal data is transferred outside the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) and provider compliance programmes, as applicable.
We may update our list of processors as the Service evolves. Material changes will be reflected in this policy and the “Last updated” date.
6. Employer visibility
If you link your account to an employer (for example via an invite code):
- Your employer may see information needed to support workplace language training — typically completion and progress status, including whether you passed a sector words and phrases exam, and safety-related module completion where relevant.
- Your employer may also see company-level aggregate usage and learning trends (for example on their home dashboard and on Employees → Analysis & results), including weekly active learner counts and words/phrases completed. Those charts do not identify individual employees; named progress remains available only in the employer’s employee-results views (including the results section on that same Employees tab).
- Your employer may add or edit company-specific words used in the basic words learning level for sectors they assign; those words are shown to linked employees as part of the learning path.
- Linked coworkers at the same employer may see a colleague directory limited to display name (name) and default sector id (and your own entry may appear in that list). Peer email addresses are not shared through this directory. Other profile fields such as username handles, push tokens, and detailed learning history are not shared through this directory.
- Linked employees may see their employer’s display name, profile photo, and company account email on Home (Profile → Employer) and on the Employer screen, so they can recognise and contact the workplace account they are linked to.
- Linked coworkers may also see an Employer & colleague updates feed on Home (
company_activity) with short summaries such as company announcements, colleagues joining, workplace exercise invites/completions, and lesson or level milestones. Items show display name and an event summary only (not exercise scores, quiz failure detail, or full learning history). Your own activities are hidden from your view of that feed. The employer company account can review the same short activity summaries on Employees → Activity feed (filterable by event type and sort order). Items still exclude exercise scores, quiz failure detail, and full learning history. - Linked coworkers may invite you to workplace exercise sessions. Participants can see shared question prompts and each other’s scores/results for that session. The employer company account cannot read those session payloads or scores.
- Linked coworkers may send or accept Streak Buddy requests from the Employer screen. Streak Buddies can see each other’s shared streak counters and whether each person has practiced on their local calendar day for that pair. Your personal streak remains on your profile. The employer company account cannot read Streak Buddy pair documents or shared streak numbers.
- When a linked employee reports a colleague, your company account may receive a push notification and an email with the report details (reporter and reported identifiers, reason, message, and related metadata) so you can follow up. These notices are separate from Workword Support and security alerts.
- When a linked employee passes the words & phrases exam and unlocks the A1 learning path, their company seat opens again. Your company account may receive a push notification and an email so you can invite another learner. The employee stays linked and keeps employer-covered access.
- When a learner links to or unlinks from your company, your company account may receive a transactional email confirming the join or leave (display name of the employee). The employee may receive a matching confirmation to their account email.
- We design employer-facing visibility to be privacy-bounded. We avoid exposing detailed performance in ways that could reasonably be used punitively (for example raw quiz failure detail), consistent with our product principles.
- Exact fields shown to employers and coworkers may change as workplace features develop; we will update this policy when visibility expands.
Your employer is separately responsible for how they use any information they receive through their workplace account, under their own policies and employment obligations.
6.1 Operator / admin access
A small number of operator (admin) accounts, provisioned by MTech & IT, may access user profile fields needed for support and operations — for example account type, company link identifiers, email, name, username, display name, onboarding status, and account activity timestamps — through an in-app Admin Panel. Operators may also view, edit, soft-delete, and record replies on Support contact form and report submissions (contact_messages, support_reports), including status and internal notes. Operators may also view and update user/colleague safety reports (user_reports), including status and internal notes. When a new contact form or colleague report is created, authorised admin devices may receive a push notification, and contact@workword.eu receives an email (via our SMTP mailer) with the submission content for triage. When a new support report is created, opted-in admin operators may also receive a push notification and/or an email to their admin account address, and contact@workword.eu may receive a triage copy when the global Support report email toggle is enabled. Operators with Firebase project access may also read in-lesson content flags stored in the reports collection (word/phrase identifiers, lesson context, optional reason, and submitter identifiers) to correct learning content. Operators may generate a password-reset link to share with a user and may reset onboarding completion so a user can complete setup again (without wiping learning sectors or account type). Operators may also view and update subscription entitlement fields on a user profile (subscription_status, subscription_provider, product and price identifiers, expiry and trial timestamps, and company seat_limit) for support — for example complimentary access. Those Admin Panel changes update Workword access records only; they do not cancel or refund App Store, Google Play, or Stripe billing. Through the Admin Panel Mailing tools, authorised operators may also create and manage reusable email templates (mail_templates) and send operational emails to selected groups of users (for example by account type, company link, or individually selected accounts) using the account email addresses on file, via our SMTP mailer. Outbound admin mailings use a branded General HTML layout with header/footer links (website, web app, terms, privacy) and a per-user Unsubscribe link to https://app.workword.eu/email-preferences/... so you can opt out of or restore operational emails (admin_mailing_enabled on your profile; default on). Each send is logged in mailings for audit. Through Blog Management, authorised operators may also create, edit, publish, and soft-delete public editorial posts stored in blogposts (localized titles, excerpts, and bodies). These posts are product content shown in the in-app Blog and do not contain user personal data. Through Automations, authorised operators may generate marketing copy and optional images (via OpenRouter) and publish that operator-authored content to LinkedIn, Facebook, and/or Instagram through Activepieces. The share payload is post text, selected platforms, and an optional public image URL only — learner accounts are not included. Admin access is limited to authorised operators and is used to operate and secure the Service, not for third-party marketing of learner data. Replies recorded in the Admin Panel are stored on the submission for operators; they are not automatically emailed to the user unless a later notification channel is enabled.
7. Retention
We retain personal data only as long as needed for the purposes described above:
- Account data — while your account remains active, and for a reasonable period afterward if needed for security, dispute handling, or legal obligations
- Learning progress — while your account is active and needed to provide the Service
- Device tokens — while notifications are enabled or until the token is replaced/invalid
- Legacy messaging data — in-app Messaging is no longer offered. On account deletion we remove you from legacy
user_chatsmembership and nullchat_public_key. Residual encrypted historical messages and related Storage objects may remain until operators purge them and are not usable without the corresponding keys - Support submissions — contact messages and reports while needed to handle your request and for a reasonable period afterward for product improvement, security, or legal obligations; we delete or anonymise them when no longer needed, including after account erasure where feasible
- User / colleague reports —
user_reportswhile needed to review safety concerns (by operators and, where applicable, the linked company) and for a reasonable period afterward for security or legal obligations; we delete or anonymise them when no longer needed, including after account erasure where feasible - Admin mailing logs —
mailingsaudit records (subject, body, recipient selection metadata, send counts, and limited failure details) while needed for operations, security, dispute handling, or legal obligations; we delete or anonymise them when no longer needed - In-lesson content flags and job requests —
reportsdocuments while needed to correct content or review job-role requests and for a reasonable period afterward for product improvement or legal obligations; we delete or anonymise them when no longer needed, including after account erasure where feasible - Crash and diagnostic reports — retained according to Firebase Crashlytics / Google Analytics retention for the project, then deleted or aggregated
- Google Analytics (linked property) — for the linked Analytics property workword-c1032, event-data retention is 2 months and user-data retention is 14 months, with reset on new user activity enabled. These settings are not the retention period of all Google Ads measurement data
- Website advertising measurement — advertising cookie lifetimes (see Section 11) are different from the retention of measurement data on Google's servers. Google's general advertising information describes partial IP-address removal after nine months and cookie-information removal after eighteen months for ad-serving logs; that does not establish the retention period of our website Google Ads measurement destination (
AW-17181401897) or of all advertising data. No Ads measurement-data retention period is defined by the website’s Google Ads loader - Local device data — until you clear app data, uninstall the app, or sign out (includes the encrypted local screen cache of Home/Profile/Employees/Employer/Results/Learning Paths/Admin/Achievements snapshots)
When you delete your account (or request erasure), we delete or anonymise personal data that we no longer need to retain, subject to legal retention requirements.
8. Security
We take appropriate technical and organisational measures to protect personal data, including:
- Authentication and access controls
- Encrypted transport (HTTPS/TLS) for network communication
- Restricted access to production systems and data
- Use of established cloud platforms with security controls
No method of transmission or storage is completely secure. Please use a strong password and keep your login credentials confidential.
9. Your rights (GDPR)
If you are in the EEA/UK (or otherwise protected by GDPR-equivalent rules), you may have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase data (“right to be forgotten”), subject to legal exceptions
- Restrict processing in certain cases
- Data portability for data you provided, where applicable
- Object to processing based on legitimate interests
- Withdraw consent where processing is based on consent (without affecting prior lawful processing)
- Lodge a complaint with a supervisory authority
In the Netherlands, the supervisory authority is the Autoriteit Persoonsgegevens (https://www.autoriteitpersoonsgegevens.nl).
To exercise your rights, email contact@workword.eu. We may need to verify your identity before fulfilling a request.
10. Children
Workword is designed for adult workplace learners. It is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data, contact us and we will take appropriate steps to delete it.
11. Cookies and the website
The website at https://workword.eu may use cookies or similar technologies that are strictly necessary for the site to function (for example security or load balancing).
When we enable analytics or advertising measurement on the marketing site (for example Google tag / Google Analytics 4 and Google Ads tags on pages such as /app, /for-employers, and /contact), those tools are non-essential. Where required by law (including in the EEA/UK), we will:
- Provide appropriate notice and choice before setting non-essential cookies or similar identifiers
- Default measurement tags so non-essential storage remains off until you accept the relevant categories (Consent Mode–style controls where we use Google tags)
- Honour reject / withdraw choices for non-essential analytics and ads measurement
Website measurement, data and withdrawal
On the Workword marketing website, analytics and advertising measurement have separate choices. With your separate advertising permission, the website loads a Google Ads measurement destination (AW-17181401897) to support measurement of our advertising. The supplied website configuration disables advertising personalisation, Google signals and enhanced conversions in the page configuration. It adds no named conversion events, remarketing audiences, account user IDs, email addresses, names or contact-form values to that advertising configuration. However, our Google Ads / Analytics account settings enable enhanced conversions, conversion-based customer lists, and automatic detection of email, phone number, and name and address. Page-level flags alone do not establish that all connected Google services are disabled for these uses or that these fields are never collected.
We intend to use the marketing website for enhanced-conversion measurement (matching customer-provided data to improve ad-conversion attribution), customer-list advertising (using conversion-based customer lists to reach customers with ads), and Analytics-audience remarketing (reaching previous visitors or purchasers with ads). These intended purposes are not a statement that each feature currently operates on the website; actual customer-data flows remain subject to reconciliation with consent and account behaviour. Our linked Analytics property includes imported audiences (for example purchasers and all users of workword-c1032). Inspected campaigns have shown no use of those imported audiences; that does not establish that they are unused in every advertising context.
Advertising measurement can involve online and ad-click identifiers and first-party cookies, such as _gcl_au and _gcl_aw. Google receives network metadata, including your IP address, and may process browser/device information and page context. The website supplies page and referring-page URLs without their query strings or fragments, and a fixed “Workword” page title. This sanitisation of the explicitly supplied fields does not establish that Google's library never processes ad-click identifiers. The library's initial script request is configured not to send an HTTP referrer header; that does not describe every later measurement request.
Google lists _gcl_au and _gcl_aw with durations of 90 days in its advertising cookie documentation. These are vendor-listed durations, not a verified inventory of cookies set on Workword. Cookie lifetime is different from the retention of measurement data on Google's servers (see Section 7).
Your analytics and advertising choices are stored separately in this browser's local storage. The current website does not assign an automatic expiry to those saved choices. You can change them through the website's cookie settings. Withdrawing a previously granted choice reloads the page when the Google library is loaded. Withdrawing advertising permission also attempts to remove accessible first-party advertising cookies. The website cannot remove Google's inaccessible third-party or HttpOnly cookies or recall data already sent. Withdrawal is not a Google data-deletion request.
See Google's advertising information, Google's advertising-cookie information, and Google's Privacy Policy. My Ad Center lets you manage Google's advertising preferences where available. Those Google preferences are separate from Workword's website measurement consent; changing one does not replace changing the other.
The Flutter web app at https://app.workword.eu is part of the Service for signed-in learning and account use. It loads Google Tag Manager container GTM-WJ6G8B7F on each visit so tags configured in that container can run. The marketing-site cookie banner and choice controls on https://workword.eu do not apply to app.workword.eu.
We do not use the Android Advertising ID (GAID) inside the Workword Android app for analytics or marketing (see Section 3.7). App-install conversion reporting for Google Ads, when used, relies on Google Play ↔ Google Ads account linking rather than in-app advertising identifiers.
Details may be expanded in a separate cookie notice on the website when applicable.
12. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. For material changes, we may provide additional notice via the Service or email where appropriate.
Continued use of the Service after an update means you acknowledge the revised policy, to the extent permitted by law.
13. Contact
MTech & IT
Wismar, Hattem, The Netherlands
Email: contact@workword.eu
Web: https://workword.eu