itsmy.beer

Language Learning Graph

Privacy Policy

This policy says what the service stores about you, why, who else sees it, and how to get rid of it.

Last updated August 18, 2026

The short version

There is no advertising here, no analytics, no tracking pixels, no third-party scripts in the pages, and nothing about you is sold or rented to anybody. The service stores what it needs to be your vocabulary and nothing beyond that.

The one thing worth reading in full is section 4: to write a definition, the service sends the word you saved to an external AI provider.

Your password is a special case, and a good one. It is stored as a one-way hash, which means it is not stored at all in a form anybody can read — not the operator, not anyone who obtains the database, not anyone who obtains a backup. See section 3.

1. Who is responsible

The service is run by one person, as a personal project. That person decides what is stored here and is the one to write to about it, at legal@itsmy.beer.

2. What is stored

Your account: your email address, your password in hashed form (section 3), and the profile you fill in — display name, short description, interface language, native language, the languages you are learning, time zone, and your notification preference. Also the date you joined, the date you last signed in, and the moment you accepted these documents and confirmed your age, together with the version of the documents you accepted.

What you save to learn: the words and phrases you add, the context and sentences you write yourself, the definitions — both the ones generated for you and the ones you write or correct — their examples, translations and synonyms, the topics your words fall into, the connections you draw between words, your practice sessions, the answers you give and the scores they receive.

Technical data: a session cookie so you stay signed in, and the ordinary records a web server keeps. Your IP address and your browser’s user-agent string are used to limit how fast requests can be made and to diagnose errors, and they appear in server logs.

A provider key, if your account is allowed to add one and you choose to. It is encrypted before it is stored (section 3).

Nothing else. There is no profile built about you, no behaviour scored, no data bought from anywhere, and no attempt to identify you beyond the account you created.

3. Passwords and keys

At no stage is your password saved in plain text. What is stored is a scrypt hash of it, with a random salt unique to your account. Hashing runs in one direction only: the stored value can confirm that a password you type is the right one, but it cannot be turned back into the password. Nobody can read your password out of this service — not the operator, not an administrator, not somebody who takes a copy of the database or of a backup. If you have reused that password elsewhere, that is the only place it is at risk, and it is a good reason not to reuse it.

If you forget it, the service cannot tell you what it was; it can only email you a link that lets you set a new one. That link works once, expires after one hour, and replaces any earlier one. Setting a new password signs out every session on every device.

A provider key you add yourself is a different case and is treated differently, honestly: the service has to be able to send that key to the provider, so it cannot be hashed. It is encrypted with AES-256-GCM before it is stored, and the encryption key is held only in the running server’s environment — it is never written into a backup, so the copies of the database that leave the machine hold that key as ciphertext with nothing beside it to open it. It can be decrypted by the running service, which means it is protected against a stolen backup rather than against the operator. You can delete a stored key at any time from your profile.

4. What is sent to an AI provider

On the add-word screen, after a short pause in typing, the word or phrase is automatically sent to TypeSafe (Jev) to identify its language, even before you save it. Only that text and the list of supported languages are sent; your context, translation, name, email and account identifier are not included.

To write a definition, check a sentence, extract words from a text or score an answer you have written, the service sends the relevant text to an external AI provider over the internet. That text is the word or phrase concerned, any context you wrote with it, the names of the languages involved, and — when you are being scored — the definition being compared with your answer.

To make search work by meaning rather than by spelling, your words and their definitions are also sent to Google to be turned into embeddings.

For definitions and analysis, OpenCode (opencode.ai) serves the default model, Nemotron 3 Ultra, and a DeepSeek model; Google serves Gemini. Your email address and your name are not sent with the request; the text is. OpenCode asks its callers to label each request so it can group one caller’s calls, and what is sent for that is a one-way hash of your account identifier — a value that groups your requests and leads nowhere back.

Each provider processes that text under its own terms and privacy policy, in its own country, and we cannot make promises on their behalf. If your account uses your own provider key, the request runs under your account with that provider and their terms apply to you directly.

If you do not want a piece of text sent to an external provider, do not type it into the add-word screen or the analysis tools, or use it in an AI generation request. Choosing a language manually does not undo a detection request already sent.

5. Why it is stored

To give you the service you asked for: to keep your vocabulary, show it to you, generate what you ask for, and ask you about it later. That is the performance of the agreement in the Terms of Service.

To keep the account working and safe: to sign you in, to let you reset a forgotten password, to limit request rates, and to find and fix errors. That is a legitimate interest in running a service that works.

Where the law requires your consent — for example, before you add your own provider key — you give it by the deliberate action of adding the thing, and you can withdraw it by deleting it.

6. Who else is involved

The server is hosted on a virtual machine rented from Hostinger. The databases run on the same machine and are not reachable from the internet.

Backups are encrypted in transit and stored in an Amazon S3 bucket controlled by the operator.

Password reset emails are sent through an SMTP relay (ImprovMX), which sees your email address and the message. It is the only email the service sends.

The AI providers in section 4.

That is the whole list. There is no analytics provider, no advertising network, no social-media plugin, no content delivery network for third-party scripts, and no data broker. Nothing about you is sold, and nothing is shared for anybody’s marketing.

Data may be disclosed if the law requires it — a valid court order, for example.

7. Cookies

Two cookies, both necessary for the service to work as you asked, and neither of them used to follow you anywhere.

The session cookie (session_token) keeps you signed in. It cannot be read by scripts in the page, is sent only to this site, and expires. Deleting it signs you out.

The interface-language cookie (ui_lang) remembers which language the interface should be in, so that the sign-in page is in your language before the service knows who you are.

Because neither cookie is used for advertising, analytics or tracking, there is no consent banner asking you to accept them. There is nothing to opt out of.

8. How long it is kept

Your account and everything saved under it are kept until you delete them or close the account.

A session expires by itself; signing out or changing your password ends it sooner. A password reset link lasts one hour and is destroyed the moment it is used.

Backups are kept for seven days on the server and for thirty days in the S3 bucket, and then expire.

Server logs, which may contain an IP address, are kept only as long as they are useful for finding a fault and are then rotated away.

9. What you can do about it

See it: everything the service holds about your learning is shown to you in the application itself, and the vocabulary page can print all of it to a PDF you keep.

Correct it: your profile, your words, your own sentences and even the generated definitions can all be edited in the application.

Delete it: a word can be deleted on its own page. The whole account can be deleted from the profile page. Deleting the account immediately and permanently removes your login, your sessions, any stored provider key, and every word, definition, topic link, practice session and score in the graph. The only copies that survive are inside the backups described above, which expire within thirty days and are not consulted except to restore the whole service after a failure.

Ask about it, or object to it: write to legal@itsmy.beer.

Complain about it: if you are in the European Economic Area or the United Kingdom and you think your data has been mishandled, you may complain to your national data protection authority. Please write to the address above first if you can — it is one person and it is usually a misunderstanding that can be fixed in an afternoon.

10. Children

The service is not intended for children under 16 and accounts are not knowingly created for them. If you believe a child has created an account, write to the address above and it will be removed.

11. Security

Traffic to the site is encrypted with HTTPS. Passwords are hashed one way and stored keys are encrypted, as described in section 3. The databases listen only on the machine itself, not on the internet. Backups leave the machine without the key that would open the encrypted parts.

None of that makes any service perfectly safe, and nobody who tells you otherwise should be believed. Use a password you use nowhere else, and do not save anything here that would harm you if it were exposed.

12. Changes to this policy

This policy will change when the service does. The date at the top of the page says when the current wording took effect, and a change that materially affects you will be announced to your account’s email address where that is practical.

13. Contact

Anything at all about privacy, or about this policy: legal@itsmy.beer.