Privacy Policy
Last updated: July 19, 2026
In short
- No accounts, no names, no emails. velzo never collects personal information.
- Anonymous statistics only — random identifiers in your browser, never linked to you.
- Do-Not-Track and Global Privacy Control are honored: with either enabled, analytics are off entirely.
- No cross-site tracking, no fingerprinting, no data selling. No marketing cookies.
- Hosted in the EU (AWS Frankfurt), delivered via Cloudflare.
This policy explains what data velzo (velzo.app) handles, why, and what your rights are. We’ve written it to be readable by a human; the formal detail is all here too.
1. Who we are
velzo is operated by Mikheil Andguladze, 4 Shartava St., Tbilisi 0186, Georgia (“we”, “us”). For anything in this policy, contact mikheilandghuladze@gmail.com. To the extent any processing of personal data occurs, Mikheil Andguladze is the data controller.
2. What we don’t collect
The simplest privacy protection is not having the data. velzo has:
- no accounts, sign-ups, or profiles;
- no names, email addresses, phone numbers, or payment details;
- no precise location data;
- no cross-site tracking and no browser fingerprinting;
- no third-party advertising or marketing cookies;
- no sale or sharing of data for anyone’s marketing. Ever.
3. What we do collect: anonymous usage statistics
To understand what’s working (which words people study, how long sessions last), we record anonymous usage events, such as:
- a card was viewed, or a translation was tapped;
- a page was visited (feed, word page, or pair page);
- a session started or ended, and how far you scrolled;
- a language pair was selected.
These events are tied to two random identifiers generated in your browser: a visitor identifier (a random UUID stored in localStorage) and a per-session identifier that your browser discards when the tab closes. They are random strings — they don’t contain, and can’t be traced back to, your name, email, or identity, because we never have those. Analytics events do not include your IP address.
Opting out is built in: if your browser sends the Do-Not-Track signal or Global Privacy Control, velzo disables analytics entirely — no identifier is created and no events are sent. See the cookie & storage policy for every stored key.
4. Technical data handled by our infrastructure
Like any website, velzo is delivered by servers that momentarily process your IP address and standard request metadata to serve pages and defend against abuse. Our infrastructure providers are:
| Provider | Role | Location |
|---|---|---|
| Amazon Web Services (AWS) | Application hosting and databases | EU — Frankfurt (eu-central-1) |
| Cloudflare | Content delivery, DDoS and abuse protection | Global edge network; EU entry points for EU visitors |
These providers act as processors under standard data-processing agreements. Routine server logs are short-lived and used only for security and operations.
5. Legal basis (GDPR)
Where the GDPR applies, our basis for the minimal processing above is legitimate interest (Art. 6(1)(f)): operating, securing, and improving a free service, using the least data possible. We deliberately chose anonymous, in-browser identifiers over accounts or tracking precisely to keep this footprint minimal. If we ever introduce processing that requires consent — such as advertising — we will ask for it first (see section 9).
6. Storage and retention
- Raw analytics events are kept for no longer than 90 days, then aggregated into daily statistics that contain no identifiers.
- Identifiers live in your own browser storage — clearing your browser data for velzo.app deletes them; a fresh, unrelated identifier is generated next time (or none, with DNT/GPC on).
- All application data is stored in the EU (AWS Frankfurt).
7. Your rights
Under the GDPR you have rights of access, rectification, erasure, restriction, portability, and objection. An honest note about how they apply here: because velzo’s identifiers are random and unlinked to any identity, we generally cannot tell which data is yours — even if you ask — which is by design. The practical way to exercise erasure is to clear your browser’s stored data for velzo.app, which severs any link between your browser and past events. For any request or question, contact mikheilandghuladze@gmail.com. You also have the right to lodge a complaint with your data-protection authority, or ours in Georgia.
8. Children
velzo is suitable for all ages. Because there are no accounts and no personal data collection, we do not knowingly process personal data from anyone — children included. If you believe a child has somehow provided us personal data (for example by email), contact us and we will delete it.
9. Advertising, if it ever arrives
velzo is free and may one day show ads to stay that way. If we introduce advertising, we will update this policy before anything changes, explain exactly what data (if any) is involved, and add a consent mechanism where required. The current promise stands until this page says otherwise: no ad tracking exists on velzo today.
10. Changes to this policy
We’ll post changes here and update the “Last updated” date above. Material changes will be announced visibly on the site, not buried.
11. Contact
Questions, concerns, requests: mikheilandghuladze@gmail.com, or by post at 4 Shartava St., Tbilisi 0186, Georgia.