1. Data we process
The account service stores email, verification status, account creation time and accepted policy versions. Passwords are stored only as Argon2id hashes, never plaintext.
For abuse prevention and account security, the service processes hashed session tokens, scoped one-way IP hashes, browser User-Agent and authentication events.
2. Data that stays local
Articles, notes, answers, lookup history and local settings in the desktop client remain on your device by default and are not uploaded merely because you register.
When using third-party AI features, the client sends content needed for the request to the provider you configure. That processing follows the provider's privacy policy.
3. Cookies and sessions
Sign-in uses an HttpOnly session cookie. Browser scripts cannot read it; it maintains the session without exposing the token to frontend code.
Account cookies are not used for advertising profiles.
4. Email delivery
Local development writes verification messages to service logs. Once Resend is enabled, email addresses and verification or reset message content are sent to Resend for transactional delivery.
We do not sell email addresses or use account security messages for third-party advertising.
5. Retention
The default policy removes long-unverified pending accounts after 7 days, stale token records after 7 days, expired session records after 30 days and authentication security events after 180 days.
This notice will be updated if production retention changes materially.
6. Deletion and contact
Account deletion revokes cloud sessions and anonymizes account personal information. Local articles, practice records and settings are not remotely deleted.
To request access, correction or deletion, contact support@english-praxis.com. Before public launch, this notice should be reviewed for applicable regions.