Your learning belongs to you.
This policy explains how ZIPF LTD uses personal data when you create an account, sign in to Learn the Script, explore texts, study letters, save learning progress, or save a pasted text.
1. Who controls your data
ZIPF LTD is the controller of the personal data described in this policy. It is an active private limited company registered in England and Wales.
- Registered office
- 43 Donne Court, Bollo Bridge Road, London, England, W3 8YG
- Company number
- 16210723
2. Data we use
- Account details: your email address (and a username for older accounts), or—if you choose Google sign-in—your Google account identifier, verified email address, name, and profile picture.
- Password credentials: if you create a password account, we store a one-way Argon2id password hash, never your readable password.
- Profile settings: your display name and auto-skip preference.
- Learning progress: the language, alphabet version, letters and forms you complete, unlock dates, review dates and review counts.
- Learning sessions and activity: visit start and last-activity times, confirmed or estimated end times, elapsed and estimated active time, and actions such as choosing a text, opening a letter, playing audio, answering questions, and completing lessons or reviews. Events include language, text/letter/form identifiers and correct/incorrect results; they do not include the text of your answers, pasted text content, passwords, or authentication tokens. Signed-in activity is associated with your account ID. Guest activity uses a random browser identifier in a first-party cookie lasting up to 30 days; it is not retroactively attached to an account when you sign in.
- Your saved texts: the title, text content, language, source URL or source note, and creation/update times.
- Essential technical data: hashed security-session identifiers, request-forgery tokens, short-lived sign-in transactions, hashed login-throttling identifiers, and limited server logs needed to operate and protect the service. We do not store your Google password or Google access token.
3. Why we use it
| Purpose | Legal basis |
|---|---|
| Create and secure your account; provide profiles, cross-device progress, learning-session history, saved texts, export and deletion. | Performance of the service you request. |
| Prevent abuse, investigate faults, and maintain service security. | Zipf’s legitimate interests in operating a safe and reliable service. |
| Meet regulatory, tax, court, or law-enforcement obligations where applicable. | Legal obligation. |
We do not sell your personal data, use your pasted text for advertising, or use it to train an artificial-intelligence model.
4. How sign-in works
If you create an email-and-password account, ZIPF LTD verifies the password against its one-way hash. Email verification and self-service password recovery are not yet available.
If you choose Google sign-in, Google authenticates you and sends us only the Google account details listed above. Google processes information under its own privacy policy. You can remove Learn the Script’s Google access from your Google account settings, but this does not itself delete data already stored by ZIPF LTD; use “Delete account and data” in your profile for that.
5. Service providers and transfers
We use Google for authentication when you choose that method and Railway for application and database hosting. When account notifications are enabled, Resend delivers a new-account notification to our feedback mailbox containing the account ID, email address, sign-in method, and creation time. These notifications do not include your password or learning content. They may use vetted subprocessors. Some processing may take place outside the United Kingdom, including in the United States. Where UK data protection law requires safeguards for a transfer, we rely on the relevant provider terms and approved transfer mechanisms.
6. How long we keep data
- Your profile, learning progress, and saved texts remain until you delete individual texts or delete your account.
- Your password hash remains for the life of your password account and is deleted when the account is deleted.
- Detailed learning sessions and activity events are retained for up to 90 days and removed by regular automated maintenance. Account deletion also deletes the learning activity associated with that account. A learning session ends after 30 minutes without recorded activity; if we cannot observe an explicit ending, its end time is estimated from the last activity. Active time excludes hidden or unfocused tabs and time after two minutes without interaction, with overlapping tabs counted once.
- Sign-in sessions expire after no more than 30 days. Google sign-in transactions expire after 10 minutes. Login-throttling records are automatically removed after approximately 24 hours.
- Operational logs and backups are kept only for as long as reasonably needed for security, recovery, and legal purposes.
7. Your choices and rights
You can change your name and auto-skip preference, download a machine-readable copy of your account data, delete saved texts, sign out, or delete your account from the Profile panel.
Depending on the circumstances, the UK GDPR and Data Protection Act 2018 give you rights to access, rectify, erase, restrict, object to processing, and receive portable data. You can contact ZIPF LTD at its registered office above. You may complain to the UK Information Commissioner’s Office.
After five active minutes, we may invite you to share feedback. The form opens a draft in your own email app; feedback is not submitted automatically or stored by the website’s form.
8. Security
We use one-way Argon2id password hashing, login-attempt throttling, short-lived Google sign-in transactions, protected session cookies, request-forgery protection, ownership checks, encrypted transport in production, access controls, and database isolation. No online service can guarantee absolute security.
9. Children
Learn the Script is not currently designed for children to create accounts independently. A specific age policy and any parental-authorisation flow must be approved before the account feature is promoted to children.
10. Changes
We may update this policy when the service or its providers change. We will post the new effective date and give additional notice where a material change requires it.