Logo Diglot

© 2026 Diglot

LegalsPrivacyLicencesCommunity requests

Last updated: 8 August 2026

This policy explains how Diglot processes personal data under the General Data Protection Regulation (GDPR) and applicable French law.

1. Controller

Michel Hognerud, individual entrepreneur
SIREN: 499 229 490
Email: [email protected]

2. Data we process

Depending on how you use Diglot, we process:

  • Account data: email address, username, locale, account identifier, email preferences, and account status.
  • Authentication data: hashed password, sessions, verification and reset tokens, and, when you use social login, the provider, provider account identifier, access or refresh tokens, and their expiry.
  • Learning data: selected languages, level estimates, reading progress, vocabulary, reading activity, reports, and preferences.
  • Waitlist data: email address, languages, levels, onboarding answers, invitation and referral information, and hashed IP metadata.
  • Billing data: subscription, customer, product, status, and invoice identifiers. Payment-card details are handled by Stripe and are not stored by Diglot.
  • Support data: messages, content reports, and screenshots you choose to submit.
  • Technical and security data: timestamps, referrer information, hashed IP metadata, session information, logs, and information used to prevent abuse and diagnose failures.
  • Analytics data: page views, product events, invitation and in-product engagement signals, interaction and session-replay data, and pseudonymous account identifiers.

3. Why we process data

PurposeLegal basis
Create and operate accounts; provide learning, progress, and subscription featuresPerformance of a contract (Article 6(1)(b) GDPR)
Process payments, subscriptions, invoices, and accounting recordsPerformance of a contract and legal obligations
Answer support requests and review content reportsPerformance of a contract or our legitimate interest in supporting and improving Diglot
Secure the service, prevent abuse, and diagnose failuresOur legitimate interest in operating a secure and reliable service and, where applicable, legal obligations
Measure use and improve usability and performanceOur legitimate interest in understanding and improving Diglot
Send optional marketing communicationsConsent, where requested

Email, authentication information, and the learning data required by a feature must be provided for us to deliver the corresponding account service. Other fields are optional when identified as such.

We do not use personal data to make decisions producing legal or similarly significant effects based solely on automated processing.

4. Analytics

Diglot uses self-hosted Umami to measure page views and product events. For signed-in users, Umami receives a pseudonymous account identifier. Diglot also enables Umami session replay in the production application. Depending on the configured sample and masking settings, replay records can include mouse movement, clicks, scrolling, navigation, form interactions, and rendered page structure. Diglot configures replay masking and block selectors for sensitive areas; session replays are currently retained for 30 days.

Analytics information remains personal data where it can be linked to an account or device.

Diglot also stores a small number of first-party funnel signals, such as whether an invited waitlist member reached the site and whether an account opened the introduction text. These signals are used to understand onboarding and are linked to the relevant waitlist or account record.

5. Recipients

We use service providers only where needed for the relevant feature:

  • OVHcloud for hosting;
  • Stripe for payments and subscriptions;
  • Facturation.pro for invoicing;
  • Brevo for email delivery;
  • Sentry for error monitoring;
  • enabled sign-in providers, such as Google, Facebook, or X, when you choose that sign-in method.

These providers receive only the data needed to supply their service. Diglot personnel and authorized contractors may access data when necessary to operate, secure, or support the service.

6. International transfers

Some providers may process data outside the European Economic Area. Where required, transfers are covered by an adequacy decision or appropriate safeguards such as the European Commission’s Standard Contractual Clauses. Contact us to request information about the safeguards applicable to a particular provider.

7. Retention

We retain personal data only for as long as needed for the purposes above. The period is determined by the status of your account, the feature concerned, security and support needs, and applicable accounting, tax, limitation, or other legal duties.

In particular, temporary authentication tokens are retained until expiry or use; account and learning data are retained while the account is active and as needed to handle deletion or legal claims; billing and invoice records are retained for the legally required period; session replays are retained for 30 days under the current Umami configuration; and other analytics, logs, and error reports follow the shortest operational period compatible with their purpose and the relevant provider settings.

8. Your rights

Depending on the processing concerned, you may request access, correction, deletion, restriction, or portability of your data, or object to processing based on our legitimate interests. Where processing is based on consent, you may withdraw that consent at any time without affecting earlier lawful processing.

To exercise a right, contact [email protected]. We may request information needed to confirm your identity.

You may also lodge a complaint with the French data-protection authority (CNIL).

9. Children

Diglot is not available to children under 15. If you believe that we have collected data from a child under 15, contact us.

10. Cookies

Diglot uses cookies required for functions such as authentication and language preferences.

11. Changes

We may update this policy when the service or applicable requirements change. The current revision date appears at the top of the page.