Tomyo

Privacy Policy

How Tomyo collects, uses, stores and protects the personal data of users of tomyo.app and the Tomyo mobile apps.

Last updated: September 13, 2026Service: tomyo.app

1. Data controller

The data controller (operator) is individual entrepreneur Maksim Zelenskiy, state registration number (OGRNIP) 326237500396730, taxpayer ID (INN) 234807956734 (the “Operator”, “Tomyo”, “we”).

Email for personal data requests: sendmail@tomyo.app. The Operator’s registered address is listed in the public register of data operators and is provided on request.

This Policy applies to all data the Operator receives when you use the website tomyo.app, the Tomyo mobile apps for iOS and Android, or contact support (together, the “Service”).

2. Definitions

  • Personal data — any information relating to a directly or indirectly identified individual.
  • User — an individual using the Service, including without registration.
  • Processing — any operation on personal data: collection, recording, systematisation, accumulation, storage, updating, retrieval, use, transfer, anonymisation, blocking, deletion, destruction.
  • Processor — a party processing data on the Operator’s instructions.

3. Principles

  • Processing has a legal basis and is limited to predefined purposes.
  • Only data necessary for the stated purpose is collected.
  • Data is kept no longer than the purpose or the law requires.
  • The user database is located in the Russian Federation, and all collection, storage and processing of account data is performed in it.
  • No special categories of personal data and no biometric data are processed.

4. What data, why, and on what basis

DataPurposeLegal basisRetention
Email address, encrypted password; when signing in with Yandex, Apple or Google — the name and avatar received from the providerAccount creation, sign-in, access recoveryContract (Terms of Service); consent to processingUntil the account is deleted
Display name, language, level and learning goals, “about me”Personalised learningContractUntil the account is deleted
Vocabulary, progress, session history, journal, AI dialogues, exercise texts, conversations with other learnersProviding the learning service, saving progressContract; consent as regards processing of texts by third-party servicesUntil the account is deleted
Email, amount, date and identifier of a payment; auto-renewal consent with date, IP address and deviceSubscription payment and renewal, receiptsContract (Public Offer); statutory tax and accounting record-keeping requirements5 years from the payment date
Reply email, subject and text of a support request, attachmentsUser supportContract3 years after the request is closed
IP address, device and browser type, device and push notification identifiers, app version, cookiesOperating the Service, protection against password guessing and abuse, error diagnosticsConsent; legitimate interest in securitySign-in and error logs — 90 days; device records — until the account is deleted
Pages visited, learning events, referral source and campaign tagsAnalytics and improvement of the ServiceConsent (cookies and analytics)180 days, then anonymised
Consent record: document version, date, IP address, device, sourceEvidence of the legal basis for processingLegal obligation to keep proof of consentUntil the account is deleted, then 3 years anonymised

Consent to personal data processing is given by a separate action when creating an account. Its text is published at Consent to Personal Data Processing.

5. Cookies and analytics

The website uses three kinds of cookies: cookies necessary for sign-in and operation of the Service, cookies that remember your language and settings, and analytics cookies of Yandex Metrica (including on-page action recording) and the Mail.ru counter. The mobile apps use AppMetrica for usage analytics and push notification delivery. Clicks on the App Store, Google Play and RuStore buttons are counted: the website section and page, the chosen store, the device type and the anonymised visitor identifier from the cookie are stored; the store link carries a website section tag that the store may pass to the app after installation.

On the first visit the website shows a cookie notice. Analytics cookies can be disabled in your browser settings or with a blocker; necessary cookies cannot be disabled, as the Service does not work without them. Analytics data is used to understand how the Service is used and is not used to show third-party advertising.

6. Recipients

The Operator does not sell personal data. Data is shared only with the parties listed below, to the extent needed for their function, and with public authorities where required by law.

RecipientCountryPurposeData received
TimewebRussiaHosting of the server, database and files; backupsAll Service data
UnisenderRussiaEmail deliveryEmail address, email content
RobokassaRussiaPayment processing, receiptsEmail address, amount, receipt items
Yandex (Metrica, AppMetrica, Yandex ID)RussiaAnalytics, push delivery, sign-in with YandexIP address, cookies, device identifiers, push tokens; on sign-in — name and email
VK (Mail.ru counter)RussiaVisitor counterIP address, cookies, page views
DeepSeekChinaAI generation of learning materials and text checksTexts entered by the user, without name or email
GoogleUSASign-in with Google, push delivery on Android, text-to-speech for learning textsOn sign-in — email and name; push token, installation ID; learning text with no user information
AppleUSASign-in with Apple, push delivery on iOSOn sign-in — identifier and email; push token, notification text
RollbarUSAApp error reportingIP address, device model, technical error data

7. Cross-border transfer

When you use the features listed in section 6, some data is transferred to the People’s Republic of China and the United States of America. Foreign recipients receive the minimum necessary data and, wherever possible, nothing that identifies you. You are informed of such transfers by this Policy and by the consent document. The Operator notifies the data protection authority of cross-border transfers as required by applicable law.

8. Emails and notifications

Service messages — email confirmation, sign-in codes, subscription notices, the weekly progress report and review reminders — are part of the service. The report and reminders can be switched off in account settings. Marketing emails are sent only with your separate consent.

9. How data is protected

  • Data in transit between your device and the Service is encrypted (TLS).
  • Passwords are stored only in encrypted form.
  • Access is segregated: you see only your own data; administrator access is limited to one person.
  • Sign-in and security event logs are kept; sign-in attempts are rate-limited.
  • The database and backups are located in the Russian Federation.
  • The level of protection is determined under Government Decree No. 1119; protective measures follow FSTEC Order No. 21.

In the event of an incident affecting personal data, the Operator notifies the data protection authority within the statutory deadlines and informs affected users where the incident may harm them.

10. Your rights

You have the right to:

  • obtain information on which of your data is processed, for what purposes, with whom it is shared and for how long it is kept;
  • correct your data — in account settings or by request;
  • request blocking or destruction of data that is processed unlawfully;
  • withdraw your consent to processing;
  • delete your account — in the website or app settings; the procedure is described at Account deletion;
  • appeal the Operator’s actions to the data protection authority or a court.

Requests are accepted at sendmail@tomyo.app and via the support form on the website and in the apps. To protect against requests from third parties, the Operator verifies your identity through access to your account or to the email address it is registered to. A reply is sent within 10 business days of receiving the request.

Withdrawal of consent ends processing and results in destruction of the data, except data the law requires us to keep (payment records). Because the Service cannot operate without account data, withdrawing consent is equivalent to deleting the account.

11. Destruction of data

When an account is deleted, the account, profile, learning data, devices, support requests and attachments are destroyed and logs are anonymised. Data whose retention period has expired is destroyed or anonymised automatically within the periods in section 4. Payment records are kept for 5 years under tax law and are no longer linked to the user after account deletion.

12. Age of users

The Service is intended for people aged 18 and over. People aged 14 to 18 may use the Service with the consent of a parent or legal guardian. The Operator does not knowingly collect data of children under 14; if such data has been received, it is destroyed at a parent’s request.

13. Users in the European Union and the United Kingdom

The Service is operated from the Operator’s country of registration and is governed by its law. Your data is stored on servers in that country, which has not been recognised by the European Union or the United Kingdom as providing an adequate level of data protection. By creating an account you acknowledge this. The Operator has not appointed a representative in the European Union or the United Kingdom.

If you are located in the European Economic Area, the United Kingdom or another jurisdiction with its own data protection law, you can exercise the following rights by emailing sendmail@tomyo.app:

  • access to your data and a copy of it in a machine-readable format;
  • rectification of inaccurate data and erasure of your data;
  • restriction of processing and objection to processing based on legitimate interests;
  • withdrawal of consent at any time, without affecting processing carried out before withdrawal;
  • lodging a complaint with the supervisory authority of your country of residence.

Requests are answered within 30 days. In the event of a personal data breach that is likely to result in a high risk to you, the Operator informs you without undue delay. Analytics cookies are used on the basis of your consent; you can withdraw it at any time by clearing cookies in your browser or using a blocker.

14. Changes to this Policy

The current version of the Policy is published at https://tomyo.app/privacy with its date. In case of material changes the Operator notifies users on the website, in the app or by email.

15. Related documents