Privacy Policy
Last updated 31 August 2026
This policy covers the Frasero mobile app and this website. Who is responsible for the information described here – the data controller, in European terms – is SwagEazy LLC, d/b/a KDV Labs, of 1755 Broadway Front 3 PMB 1245, New York, NY 10019, United States, reachable at info@frasero.com.
The short version
- There is no account. You never give us a name, an email, or a password to use the app.
- Your practice progress is backed up against a random identifier that we cannot trace to you.
- The app sends crash and performance reports to Sentry. Those carry your device model, your OS version, an approximate city derived from your IP address, and a device identifier.
- We do not run ads, we do not use advertising identifiers, we do not track you across other apps or websites, and we have never sold or shared personal information.
- This website sets no cookies and stores nothing in your browser.
- You can have what we hold deleted. Here is how, and what little survives.
1. There is no account
Frasero has no sign-up, no email, no password, and no social login. So that your progress can be backed up, the app signs in to Google Firebase anonymously, which produces a random identifier tied to your app installation. That identifier is not linked to your name, your email address, or your device's advertising ID, and on its own it does not tell us who you are.
It is still personal data under the GDPR and similar laws, because it distinguishes one user from another. We treat it that way. It also means that if you reinstall the app, the old identifier and its progress are usually unreachable – to us and to you.
2. What we collect
| What | Specifically | When |
|---|---|---|
| Anonymous identifier | A random Firebase user ID created for your installation | First launch |
| Practice progress | Which exercises you answered, whether each was right, when each is next due, your streak, your level, and your interface language | As you practice |
| Exercise reports | The exercise ID, the category you picked, a snapshot of the item, any note you type, your app version, and your anonymous identifier | Only when you report a card |
| Messages to us | What you write, plus your app version and level so a reply makes sense, and your email address if you write by email | Only when you contact us |
| Crash and performance data | See section 3 | On errors, and on a sample of app sessions |
| Waitlist signup | Your email address, and your first name if you choose to give it – the name field is optional and the form works without it | Only if you submit the form |
| Anti-abuse check | A one-way hash of your IP address, used only to stop the waitlist form being submitted in a loop. We do not store the address itself and cannot recover it from the hash | When you submit the waitlist form |
| Server logs | IP address, browser user agent, requested URL, and timestamp, recorded by our hosting provider | When you visit this website |
The exercises download to your device the first time you open a level. Practice after that works offline and sends us nothing, so the only thing an exercise needs a connection for is arriving.
3. Crash and performance reporting, in detail
The app uses Sentry to tell us when it crashes or misbehaves, and to sample how long screens take. This is the part of Frasero that collects the most about your device, so it is worth being exact about.
A report can include:
- your device model, operating system version, locale, and app version;
- the error itself and a stack trace, plus a breadcrumb trail of the screens and taps that led to it;
- an approximate location – city level – that Sentry derives from the IP address your device connects from. We have configured the app not to store your IP address on the report itself, but this city-level estimate is produced when the report arrives and we cannot switch it off;
- a stable identifier for your installation: normally your anonymous Firebase ID, and where that is unavailable, a persistent installation ID that Sentry generates itself.
We do not send Sentry your practice answers, your notes, or your email address, and the app is configured not to attach the extra personal data the SDK can collect by default. Performance sampling covers a fraction of sessions rather than all of them.
4. Notifications
The optional daily reminder is scheduled on your device. There is no push server, we do not collect a push token, and we cannot see whether you have reminders on, when you set them for, or whether you opened one. Turning the permission off in your device settings ends it.
5. What we do not do
- No advertising, no ad networks, no ad identifiers (IDFA or Android Advertising ID).
- No cross-app or cross-site tracking, and no third-party trackers on this website.
- No profiling and no automated decision-making that produces legal or similarly significant effects.
- We do not and have not sold or shared personal information, in the sense California and other U.S. state privacy laws give those words, and we do not process it for cross-context behavioral advertising.
- We do not collect special-category data – health, biometrics, precise location, race, religion, or the rest – and you should not send us any.
6. Why we process it, and on what legal basis
| Purpose | Data | Legal basis (UK/EU GDPR) |
|---|---|---|
| Run the app and back up your progress | Anonymous identifier, practice progress | Performance of our contract with you (Art. 6(1)(b)) |
| Fix wrong exercises | Exercise reports | Legitimate interests – correcting our content and keeping it useful (Art. 6(1)(f)) |
| Answer you | Messages to us | Contract, and legitimate interests in supporting our users |
| Keep the app working and secure | Crash and performance data, server logs | Legitimate interests – diagnosing faults, preventing abuse (Art. 6(1)(f)) |
| Tell you once when Frasero launches | Waitlist email and name | Your consent (Art. 6(1)(a)), withdrawable at any time |
| Stop the signup form being abused | Hashed IP address | Legitimate interests – keeping a public form usable (Art. 6(1)(f)) |
| Comply with the law and defend claims | Whatever is relevant | Legal obligation (Art. 6(1)(c)) and legitimate interests |
7. Who else sees it
We are one person, and we use other companies to run Frasero. They process data on our instructions under contracts that restrict what they may do with it. They are not permitted to use it for their own purposes.
| Provider | What it handles | Where |
|---|---|---|
| Google (Firebase, Cloud) | Anonymous sign-in, progress backup, exercise reports, this website's hosting, server logs | United States and other Google regions |
| Sentry (Functional Software, Inc.) | Crash and performance reports | United States |
| Telegram | A notification copy of exercise reports and contact messages, so we see them promptly | Outside the United States |
About the Telegram relay: when you report an exercise or write to us through the app, the content of that report – including any note you typed – is copied into a private Telegram chat that only we can read. It is a notification channel, not a support desk, and it is why you should not put anything sensitive in a report note.
Beyond these, we will disclose information if the law requires it, if we need to establish or defend a legal claim, or to protect someone's safety. If Frasero is ever transferred to a company or another owner, information covered by this policy may transfer with it, still subject to this policy or one at least as protective. We will say so before that happens.
8. Where your data goes
We are based in the United States and our providers process data there and elsewhere. If you are in the UK, the EEA, or Switzerland, that means your information is transferred out of your region. Those transfers rely on the safeguards in each provider's data processing terms – the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, or the provider's certification under the EU–U.S. Data Privacy Framework and its UK extension, as applicable. You can ask us which applies to a given provider.
9. How long we keep it
| What | Kept for |
|---|---|
| Practice progress | Until you ask us to delete it, or 24 months after the installation last syncs |
| Exercise reports | 24 months, because a report can stay open against an item for a long time |
| Messages to us | 24 months after the conversation ends |
| Crash and performance data | 90 days, then deleted by Sentry automatically |
| Waitlist email and name | Until 30 days after the launch announcement, or until you ask us to remove it – whichever comes first |
| Hashed IP from the signup form | Overwritten on your next submission; not retained as a record |
| Server logs | Up to 30 days |
We may keep something longer where the law requires it or where we need it to defend a legal claim, and only for as long as that lasts.
10. Your rights
Everyone
Whatever law applies where you live, we will honor a request to see what we hold about you, correct it, or delete it. The deletion page explains exactly what happens.
UK, EEA, and Switzerland
You have the right to access your data, to have it corrected or erased, to restrict or object to our processing of it – including any processing we base on legitimate interests – to receive it in a portable form, and to withdraw consent at any time without affecting what we did before you withdrew it. You can complain to your national supervisory authority; in the UK, that is the Information Commissioner's Office.
California, and other U.S. states with privacy laws
If you live in California, Colorado, Connecticut, Virginia, or another state with a comparable law, you have the right to know what we collect and why, to access it, to have it corrected, to have it deleted, and to opt out of its sale, sharing, or use for targeted advertising or profiling. We do none of those last three, so there is nothing to opt out of. We will not treat you worse for exercising any right. You may use an authorized agent, and if we refuse a request you can ask us to reconsider by replying to our response.
California residents may also request the categories of personal information we disclosed for a business purpose in the past year. Those categories are identifiers and internet or device activity, disclosed to the providers listed in section 7.
How to ask, when there is no account
Email info@frasero.com. Because sign-in is anonymous, we cannot look you up by name – send the identifier shown on the app's Contact screen, or write from the address you gave us. Without one of those we have no way to find your records, and the GDPR and the U.S. state laws all allow us to decline a request we cannot verify. We answer within 30 days, or 45 where a U.S. state law allows longer, and we will tell you if we need an extension.
11. Deleting your data
Deleting the app removes the copy held on your device. To have the backed-up progress, a report, a message, or your waitlist email removed from our side – subject to the narrow exceptions in section 9 and on that page – follow the deletion instructions.
12. Children
Frasero is for people who already speak some Spanish, and it is not directed at children. You must be at least 16 to use it, as our Terms of Use say. We do not knowingly collect personal information from children under 13, and we have not designed Frasero to appeal to them. If you believe a child has given us information, email us and we will delete it.
13. Security
Progress backups are readable and writable only by the installation that created them, enforced at the database level rather than in the app. Exercise reports can only be written through a server function, never directly by a device, and no user can read another's. Traffic is encrypted in transit.
No system is perfectly secure, and we cannot guarantee that yours will never be compromised. If a breach affects you and the law requires notice, we will tell you and the relevant authority within the time the law allows.
14. Cookies and browser storage
This website sets no cookies. It stores nothing in your browser – no local storage, no session storage, no pixels, no fingerprinting – and it loads no fonts, scripts, or other assets from anyone else's domain, so opening a page here tells no third party that you did. There is nothing to consent to, which is why you were never asked. What our hosting provider records is the server log in section 2.
The app keeps your downloaded exercises, your progress, and your anonymous Firebase identifier on your device, because that is what lets practice work offline. That is storage the app needs to run rather than a tracking technology, and removing the app removes it from your device.
15. Do Not Track and Global Privacy Control
This website has no third-party tracking to disable, so a Do Not Track or Global Privacy Control signal has nothing to change here. We do not sell or share personal information regardless of the signal your browser sends.
16. Changes to this policy
If we change what we collect, why, or who we share it with, we will update this page and change the date at the top. If the change is material, we will give notice in the app or on this website before it takes effect. Please look at it now and then.
17. Contact
SwagEazy LLC
1755 Broadway Front 3 PMB 1245
New York, NY 10019
United States
info@frasero.com