Hermeno
Support

Privacy Policy

Last updated: 24 August 2026


1. Introduction

Hermeno is a language-learning application that allows users to create and manage personal vocabulary, review learning material, import text from images, receive AI-assisted learning content, and participate in vocabulary quizzes.

This Privacy Policy explains how personal data is collected, used, stored, and shared when you use the Hermeno mobile application, related backend services, support services, and associated website pages.

Hermeno processes personal data only for defined purposes connected with providing, securing, supporting, and improving the service. This policy should be read together with the Hermeno Terms of Service and AI Notice.


2. Data Controller

The controller responsible for processing personal data in connection with Hermeno is:

Bijan Sooli
Operating under the name Hermeno
c/o IP-Management #10354, Ludwig-Erhard-Straße 18, 20459 Hamburg, Germany
Germany

Email: support@hermeno.de

Website: https://hermeno.de


3. Information We Collect

Depending on how you use Hermeno, we may process the following categories of information.

3.1 Account and profile information

  • email address;
  • username;
  • optional display name;
  • password in hashed form;
  • email-verification status;
  • account creation and update timestamps.

Hermeno does not store your password in readable form.

Hermeno may provide an optional password-generation feature. Generated passwords are created locally on the user's device using cryptographic random generation. Hermeno does not store generated passwords and does not transmit them during generation. Users decide whether to use a generated password for their account.

3.2 Authentication and session information

  • random application-installation identifier;
  • optional device name;
  • authentication-session records;
  • access-token and refresh-token information;
  • session creation, expiration, revocation, and security information.

3.3 Learning information

  • vocabulary entries;
  • translations, explanations, and example sentences;
  • vocabulary status and review scheduling;
  • review history and learning progress;
  • dashboard statistics;
  • linguistic metadata such as domains, categories, translations, explanations, examples, and other learning-related enrichment information;
  • quiz content, quiz participation, and quiz results;
  • language, theme, learning, and personalization settings.

3.4 Content submitted for OCR and AI features

  • words, phrases, sentences, and longer text entered by the user;
  • text extracted from images;
  • images selected from the photo library or captured using the camera when the user activates an image-import feature;
  • language selections and instructions required to generate translations, explanations, examples, vocabulary candidates, or quizzes.

Images submitted to the OCR feature are transmitted for processing as part of the active request. Hermeno does not intentionally persist the original OCR image after that request has been processed. This does not apply to profile images, which are stored separately when a user chooses to upload one.

3.5 Communications

When you contact support or use account-related email functions, we may process:

  • your email address;
  • the contents of your request;
  • email-delivery and technical status information;
  • verification, password-reset, and account-recovery communications.

3.6 Technical and security information

The backend may process technical information required to operate and protect the service, including:

  • request identifiers;
  • requested API path and HTTP method;
  • response status;
  • timestamps;
  • security and error logs.

Hermeno creates technical and security logs needed to operate, secure, diagnose, and maintain the service. These logs may include request identifiers, request methods and paths, response status information, processing duration, and application or security events. Log retention is limited according to operational, security, and legal requirements.

Hermeno also performs application-level operational monitoring to measure service operation and selected usage patterns. Depending on the feature, this may include feature-usage counts, UI-language usage, translation language pairs, vocabulary language pairs, learning activity, AI and credit usage, authentication and session activity, and aggregated alerts or trends.

This monitoring is operated by the Hermeno backend and is not currently based on third-party analytics platforms such as Firebase Analytics, Crashlytics, Sentry, or advertising analytics SDKs.

Applicable monitoring records are subject to the application's operational retention and deletion processes. Exact retention periods may differ by data category and are not stated where the applicable production retention period has not yet been finalized.


4. Authentication

Hermeno uses account-based authentication to provide secure access to user data.

Authentication information may include:

  • email address;
  • hashed password;
  • email-verification status;
  • device identifier;
  • optional device name;
  • authentication sessions;
  • access tokens;
  • refresh tokens.

Hermeno implements email verification, password-reset functionality, account recovery, session revocation, and refresh-token rotation to improve account security.

Passwords are stored only as secure hashes and are never stored in plain text.


5. Learning Data

Hermeno stores learning-related information necessary to provide the application's educational functionality.

This may include:

  • vocabulary;
  • translations;
  • explanations;
  • example sentences;
  • review schedules;
  • review history;
  • learning statistics;
  • dashboard information;
  • quiz participation;
  • quiz results;
  • personalization and learning preferences.

This information is associated with your account so that your learning progress can be restored across sessions. User-owned learning records are removed as part of account deletion where they are governed by the application's user cascade relations. Certain shared application records may remain after account deletion without retaining the deleted user's association.


6. Artificial Intelligence and Automated Processing

Hermeno uses several automated services for different language-learning functions.

Google Cloud Translation may be used for runtime translation of words and text when a corresponding entry is not available in the Hermeno dictionary or an existing translation cache.

Google Gemini is used for additional AI-assisted functions, including:

  • OCR-assisted vocabulary extraction;
  • explanations;
  • example sentences;
  • vocabulary enrichment;
  • quiz generation;
  • other AI-assisted learning functions.

Translation results may be stored in a shared cache to avoid repeated processing, improve response times, and reduce the need to repeatedly use external services. The shared translation cache is not associated with an individual user account in the current application schema.

Google states that text submitted to Cloud Translation is used only to provide the translation service and is held briefly in memory for processing.

A stored translation result may subsequently be processed automatically for further vocabulary enrichment. This enrichment may take place asynchronously and may process multiple words together.

Depending on the feature being used, user-provided text, words, and, where applicable, images may be transmitted to the external service required for that function.

AI-generated or automatically generated content may be incomplete or inaccurate and should therefore be reviewed by the user.


7. OCR Processing

Users may import text by selecting an image from the photo library or capturing a new image with the device camera.

The submitted image is processed automatically to extract textual content. The extracted text may then be used to identify vocabulary and for further language-learning and AI-assisted functions.

OCR processing and subsequent processing of the extracted content may use different technical services. Where required for the relevant function, the corresponding content may be transmitted to external service providers for processing.

Hermeno does not intentionally retain the original OCR image as an application database record after the OCR request has been processed. Provider-side processing and retention are governed by the applicable provider terms and configuration.


8. Transactional Emails

Hermeno uses Resend to deliver transactional emails required for account functionality and security.

These communications may include:

  • email-verification messages;
  • password-reset messages;
  • account-recovery messages.

These emails are sent to operate and protect the user's account. Hermeno does not send marketing emails as part of the current MVP.


9. Data Storage and Security

Hermeno applies technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure.

These measures include:

  • password hashing;
  • short-lived access tokens;
  • rotating refresh tokens;
  • email verification;
  • password-reset controls;
  • authentication-session management;
  • encrypted HTTPS communication in production;
  • secure storage of authentication tokens on supported mobile platforms.

No method of transmission or storage is completely secure. Hermeno therefore cannot guarantee absolute security, but reasonable safeguards are applied according to the nature of the service and the data processed.

Security and abuse-prevention data

To protect user accounts, service availability, and cost-sensitive features, Hermeno may process limited security and abuse-prevention information when authenticated requests are submitted.

This may include:

  • the user account identifier;
  • the affected feature or protection scope;
  • counters representing invalid or excessive submissions;
  • security violation categories;
  • timestamps associated with security events and recovery periods;
  • temporary restriction or block expiry times.

These security records are used to identify repeated invalid submissions, excessive request patterns, and attempts to consume protected or cost-sensitive resources. Depending on the pattern detected, Hermeno may temporarily restrict the affected capability. More serious patterns may result in a broader temporary restriction.

Security restrictions are designed to recover over time. Relevant counters and restriction state may therefore be reduced, reset, expired, or deleted when they are no longer required for the security purpose.

Hermeno's input-abuse records are designed not to store the raw text, words, passwords, images, or other submitted user content that caused a validation or rate-limit event. Ordinary typing or keystrokes are not recorded as input-abuse submissions by this mechanism.

Personal data is retained only for as long as necessary for the relevant service, security, operational, or legal purpose. Different categories may therefore have different retention periods. The retention and deletion treatment of shared translation and dictionary data is documented separately and depends on whether such data can be associated with an identifiable user.


10. Data Sharing

Hermeno does not sell personal data.

Personal data is shared only where necessary to provide the requested functionality, maintain the service, or comply with legal obligations.

Depending on the feature being used, information may be processed by carefully selected service providers, including:

  • Google Cloud Translation, for automated translation;
  • Google Gemini, for OCR, AI-assisted language-learning features, and vocabulary enrichment;
  • Resend, for transactional emails such as email verification, password reset, and account recovery;
  • Hosting and infrastructure providers responsible for operating Hermeno's backend services.

Hermeno is implementing optional rewarded advertising as part of its AI-credit system. Rewarded advertising is user-initiated: a user may choose to watch an eligible rewarded advertisement in exchange for AI credits.

During development and testing, Hermeno uses test advertising configurations. Production rewarded advertising must not be enabled until the required production advertising configuration, privacy disclosures, platform settings, and server-side reward protections have been completed and verified.

Hermeno does not reward users for app-store ratings or reviews, merely opening the application, passive screen time, or arbitrary engagement.

Personal information may also be disclosed if required by applicable law or to protect the security, integrity, or legal rights of Hermeno and its users.


11. Your Rights

If the General Data Protection Regulation (GDPR) applies to you, you may have the following rights:

  • access your personal data;
  • request correction of inaccurate data;
  • request deletion of your personal data;
  • request restriction of processing;
  • receive your personal data in a portable format where applicable;
  • object to certain processing activities;
  • withdraw consent where processing is based on consent.

Requests may be submitted using the contact information provided in this Privacy Policy.

You may also lodge a complaint with the competent data protection authority if you believe that your personal data is being processed unlawfully.


12. Account Deletion

Hermeno allows users to delete their account directly from within the application.

For security reasons, account deletion requires confirmation using the user's current password.

After deletion is requested, account-related information is removed in accordance with the application's deletion process. User-owned database records governed by the application's cascade relations are deleted with the account. Profile-image references are removed and associated stored profile images are also deleted by the application where applicable.

Certain technical records or backups may remain temporarily where necessary for security, disaster recovery, or legal compliance. Shared application data that is not associated with the user's account, such as shared dictionary data, is not deleted merely because one user deletes their account.


13. Children's Privacy

Hermeno is an advanced vocabulary and language-learning application whose primary intended audience is adults (18+). Hermeno is not designed, marketed, or positioned as a children's application.

Hermeno is not intended for inclusion in children's or kids-specific store categories, and its product presentation, marketing, learning rewards, and advertising strategy are not designed to target children.

If we become aware that personal data has been collected from a child in violation of applicable law, reasonable steps will be taken to remove such information.

Parents or legal guardians who believe that a child has provided personal information may contact us using the details provided below.


14. Changes to this Policy

This Privacy Policy may be updated from time to time to reflect changes in Hermeno, legal requirements, or our processing activities.

The "Last updated" date at the beginning of this document will always indicate the most recent revision.

Material changes may also be communicated through the application where appropriate.


15. Contact

Questions regarding this Privacy Policy or the processing of personal data may be directed to:

Hermeno

Website: https://hermeno.de

Contact email: support@hermeno.de

HermenoLearn languages smarter.
PrivacyTermsAI NoticeSupportLegal Notice
© 2026 Hermeno