Эта страница доступна только на английском языке.

Правовая информация

Privacy Policy

Last updated: August 3, 2026

PLTK ("we," "our," or "us") operates the PLTK - Uzbek Dictionary mobile application (the "App"), available on iOS and Android under the bundle identifier com.pltk.uzbekdictionary. This Privacy Policy describes how we collect, use, and protect your information when you use the App.

By using the App, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the App.


1. Information We Collect

PLTK works anonymously. You do not need to create an account or sign in to use the App's dictionary and translation features.

1.1 Anonymous Identifiers

When you first open the App, we create an anonymous user account using Supabase anonymous authentication. This generates a random UUID (universally unique identifier) that, on its own, is not linked to your real identity. Unless you choose to sign in (see 1.2), we do not collect your name, email address, phone number, or physical address.

1.2 Account Sign-In (Optional)

Signing in is optional and only needed if you want to link your purchases and token balance across devices. If you choose to sign in with Apple or Google, we collect your name and email address solely to link your data to that identity and to keep your purchases and token balance attached to your account. We do not use your name or email for advertising, profiling, or marketing, and we never sell it.

1.3 Diagnostic and Usage Data

We collect anonymous diagnostic and usage data to keep the App fast and reliable, including:

  • Translation mode used (text, voice, or camera)
  • Input and output unit counts (e.g., number of words or characters translated)
  • Token balance (the number of translation tokens remaining in your account)
  • Device ID(a per-device identifier used to prevent abuse. On iOS it is a random UUID stored on your device; on Android it is derived on your device from your Android ID using a one-way hash. We store this identifier on our servers to enforce one-time offers — for example, to prevent the same device from repeatedly claiming a new-user welcome bonus. The Android ID itself is never transmitted.)
  • Device and app details (device model, operating system version, app version, and your language and timezone settings)
  • Crash reports (diagnostic information when the App crashes or encounters an error)
  • Feature usage (which features are used, to help us prioritize improvements)

This data is used solely to operate the service (e.g., tracking token usage), diagnose problems, and improve the App experience. We do not use it for advertising or profiling, and we do not track you across other apps or websites. You can turn off usage analytics at any time in the App under Settings → Data & Privacy.

1.4 Purchase Information

When you purchase a subscription (Yearly Dictionary or a monthly Translator plan) through in-app purchases, the transaction is processed by Apple (App Store) or Google (Play Store) via our payment partner RevenueCat. We receive a transaction identifier, the product purchased, and renewal status in order to credit tokens and entitle features on your account. We do not receive or store your payment card details.


2. Information We Do Not Collect

We want to be explicit about our limits:

  • No selling of data: We never sell your data to anyone
  • No advertising: We do not show ads, and we do not track you across other apps or websites
  • Personal identity: Unless you choose to sign in with Apple or Google (which provides your name and email for account linking only), we do not collect your name, email, phone number, or physical address. We never collect your phone number or physical address in any case
  • Location data: We do not access GPS, IP-based geolocation, or any location services
  • Contacts: We do not access your contact list
  • Hardware identifiers: We do not collect your IMEI, MAC address, advertising ID, or similar hardware identifiers. On Android we derive a one-way hash from the Android ID solely to prevent abuse (see Section 1.3); we do not store or transmit the Android ID itself.

3. Content You Submit for AI Processing

Some App features work by sending the content you submit to third-party AI services. This section explains exactly what is sent, to whom, and how you stay in control.

3.1 What content is sent

  • Typed text you enter for translation
  • Words you look up with the online AI dictionary (used when a word is not in the offline dictionary)
  • Voice audio captured by the microphone during voice translation, streamed in real time
  • Camera or photo-library images, when you scan a photo to read its text. On Android this is how scanning normally works, because the reader built into the device handles only Latin script; on iPhone, and on Android when the cloud is unavailable, the text is read on the device instead

3.2 Who it is sent to

This content is sent to OpenAI and Google (Gemini API), which act as our service providers solely to produce the translation, definition, or extracted text you requested. See Section 5 for details on each provider.

3.3 Your permission

The App asks for your permission with a consent notice before the first time each kind of content is sent to an AI provider, and you can review or withdraw your choice at any time in the App's settings (Settings → Data & Privacy). If you decline, the offline dictionary keeps working — only the cloud AI features are disabled.

3.4 Storage

Translations, voice audio, and scanned images are not stored on our servers. AI-generated dictionary definitions are stored in a shared cache on our servers — keyed by the word looked up, never by who requested it — so each word only has to be generated once.

3.5 Third-party protection

We have confirmed that every third party the App shares this content with — OpenAI and Google — provides the same or equal level of protection for your data as described in this policy: each acts as our service provider under contractual API terms that prohibit selling your content, sharing it for advertising, or using it to train their models, and each retains inputs only briefly for abuse monitoring before deletion.


4. How We Use Your Information

The limited data we collect is used to:

  • Provide and operate translation services
  • Generate translations, dictionary definitions, and text extraction by sending the content you submit to our AI service providers (see Section 3)
  • Track and manage your token balance
  • Process and validate in-app purchases
  • Improve the quality and reliability of the App
  • Prevent abuse and enforce usage limits

5. Third-Party Services

The App uses the following third-party services. Each has its own privacy policy governing data handling. We have confirmed that each service provider listed in this section — including the analytics and diagnostics SDKs — processes data on our behalf under contractual terms that provide the same or equal level of protection for your data as described in this policy.

5.1 Supabase

We use Supabase for anonymous authentication, token balance management, and usage analytics. Data is stored in Supabase's cloud-hosted PostgreSQL database with row-level security.

5.2 OpenAI

We use OpenAI's API for text translation, voice translation, and image text extraction (OCR). Depending on the feature, the text you enter, the microphone audio captured during voice translation, and the photos you scan for OCR may be sent to OpenAI to perform the requested task. OpenAI acts as our service provider and processes this data only to provide the service; it does not sell or share it. Data sent to the OpenAI API is not used to train OpenAI's models by default, and OpenAI may retain API inputs for up to 30 days for abuse monitoring before deletion (except where a longer period is required by law). We use ephemeral session tokens and do not expose API keys to the client.

5.3 Google (Gemini API)

We use Google's Gemini API for image text extraction (OCR), as a fallback provider for text translation, and as the primary provider for AI dictionary definitions. The text you translate or look up, and the photos you scan, may be sent to Google to perform the requested task. Google acts as our service provider and processes this data only to provide the service; it does not sell or share it. Data sent to the paid Gemini API is not used to train Google's models. Google may retain inputs for a limited period for abuse monitoring, security, and legal compliance.

5.4 RevenueCat

We use RevenueCat for in-app purchase processing and receipt validation. RevenueCat may collect device-level identifiers for purchase verification.

5.5 Firebase (Google)

We use Google Firebase for anonymous usage analytics, crash reporting, push notification delivery, and remote app configuration. Firebase receives anonymous device and app identifiers, feature-usage events, and crash diagnostics — never the content you translate or look up. Usage analytics can be turned off at any time in the App under Settings → Data & Privacy; crash reporting remains active as a diagnostic necessary to keep the App reliable. We do not use Firebase for advertising, and no advertising identifier is requested.

5.6 Sentry

We use Sentry for error and crash diagnostics. Sentry receives crash stack traces, device model and OS version, and the anonymous account identifier — personally identifying information is explicitly disabled, and the content you translate or look up is never included in error reports.


6. Cookies and Similar Technologies

Our website (pltk.app) does not use advertising or cross-site tracking cookies, and it does not show a cookie consent banner because none is required for what we use:

  • Language preference cookie (NEXT_LOCALE) — remembers which language you chose to read the site in. Functional only.
  • Authentication cookies — set only if you sign in (for example on our admin or account pages) to keep your session active. Strictly necessary for signing in; never used for tracking.
  • Cookieless analytics — we use Vercel Web Analytics and Speed Insights, which measure aggregate page views and performance without cookies, fingerprinting, or persistent visitor identifiers.
  • First-party campaign attribution— if you arrive via a link that carries campaign tags (UTM parameters), we keep those tags in your browser's session storage (cleared when the session ends, never a cookie) and record them only as aggregate, non-identifying statistics — so we can tell which of our own announcements people found useful. Nothing is shared with advertising networks.
  • Local preferences— your theme choice (light/dark) and one-time notices are kept in your browser's local storage and never leave your device.

7. Data Storage and Security

Your data is stored securely in Supabase's cloud-hosted PostgreSQL database. We implement the following security measures:

  • Row-level security (RLS) to isolate user data
  • Encrypted local database (SQLCipher) for offline dictionary data
  • Certificate pinning for API connections
  • Ephemeral session tokens for third-party API access
  • CORS origin whitelisting on backend services

8. Data Retention

Anonymous usage data and token balance information are retained as long as your anonymous account exists. Because accounts are anonymous, we cannot associate stored data with any individual. If you uninstall the App, the locally stored device identifier is removed. On Android, because it is derived from your device, reinstalling may produce the same identifier — this is what lets us keep preventing repeated claims of one-time offers. Server-side anonymous records may be periodically purged.


9. Children's Privacy

The App is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at support@pltk.app and we will take steps to delete such information.


10. Your Rights

Because we use anonymous authentication and do not collect personally identifiable information, traditional data subject rights (access, correction, deletion) are limited. However:

  • You can delete the App at any time to remove all local data from your device
  • You can contact us to request deletion of server-side data associated with your anonymous ID

11. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. We encourage you to review this policy periodically for any changes. Continued use of the App after changes constitutes acceptance of the updated policy.


12. Contact Us

If you have any questions or concerns about this Privacy Policy, please contact us: