PhraseFold Privacy Notice
Revision of 24 August 2026. This is a courtesy translation: the Russian text governs.
1. Operator and Scope
Personal-data operator: Individual Entrepreneur Nikita Igorevich Glukhov, INN 027009336480, OGRNIP 321745600166067, address: 13-381, Geroya Rossii Rodionova E.N. Avenue, Chelyabinsk, Russia. Data enquiries: gneuro@djbloknote.com; legally significant messages: dot_nik@mail.ru. Processing follows Russian Federal Law No. 152-FZ “On Personal Data”.
This notice covers the PhraseFold pages on djbloknote.ru, checkout, licence delivery, support requests and the application’s network features. It does not constitute advertising consent.
2. What Happens Locally in the App
Core processing of audio, video, system sound, text and documents is designed to run on the Mac once the required models and components are installed. The local library and source materials are not sent to the Operator merely because local transcription, translation or asking about material was started.
The network is used for actions that cannot work without it or that the user explicitly chose: downloading models and components, updates, importing supported URLs, web search, payment, opening an external link and connecting a user-chosen remote Ollama server. On an external route the chosen external service receives the data on its own terms; the app marks network actions in its interface.
3. Data Processed
| Context | Data |
|---|---|
| Order and licence | e-mail, optional messenger handle, tier, price, currency, order number, PaymentId without card details, payment status, licence identifier, document revisions and server-side acceptance time |
| Site and security | IP address and proxy headers, browser/OS, language, page, technical logs, rate-limit/idempotency hash, cookies/localStorage/sessionStorage, UTM and referrer |
| Analytics, when the configuration permits | page views and UI events, an anonymised/pseudonymous identifier, tier and amount of a confirmed purchase without the e-mail in the analytics event |
| Support | e-mail/messenger, request content, PhraseFold/macOS version, Mac model, diagnostic details and voluntarily attached materials |
| The app’s network features | the URL, query or text fragment required by the external route the user chose; the exact set depends on the feature and recipient |
The Operator does not receive bank-card data. Do not send special data categories, biometrics, medical or other sensitive materials to support without a specific need and an agreed protected channel.
4. Purposes and Legal Bases
- creating and fulfilling the order, issuing and restoring the key, the fiscal receipt and bookkeeping — contract performance and legal obligations;
- storing the separate revisions and consent time — proving the lawfulness of checkout;
- support, diagnostics and security — contract performance, legitimate interest and/or consent where applicable;
- optional product and web analytics — only after the user’s corresponding choice where the law requires one;
- advertising messages — only under a separate marketing consent, which is not part of the purchase.
5. Recipients and Infrastructure
To the necessary extent, data may be received by:
- T-Bank, the fiscal-data operator and cash-register infrastructure — payment and receipt;
- the site’s and backend’s hosting, serverless and CDN providers — serving the site and API;
- the CRM and e-mail provider — order records and the key e-mail; order records and e-mails use Google services (Google Apps Script/Sheets and mail delivery) whose infrastructure may be located outside Russia — to that extent a cross-border transfer takes place, needed to fulfil the order and covered by the separate consent;
- analytics systems — only in a permitted configuration and without passing the order e-mail in the purchase-confirmation event;
- a user-chosen remote server, search or URL service — only for the corresponding network action;
- state authorities — upon a lawful binding request.
Information about storage location and data localisation is provided by the Operator on a data subject’s request.
6. Retention
Data is kept no longer than needed for the contract, mandatory accounting and tax records, claims, security and consent evidence. A withdrawn consent does not require deleting data that must be kept on another legal basis; when the bases expire, data is deleted or anonymised.
7. Cookies and Local Storage
Technical storage keeps the language, checkout state, Idempotency-Key, the secure claim token for returning from the bank and the analytics choice. The claim token is not a licence key but must be treated as confidential. Optional analytics does not load before the user’s corresponding choice. Settings can be changed via the cookies/analytics interface or by clearing site data in the browser.
8. User Rights
The user may request information about processing, access, correction, restriction or blocking, deletion where grounds exist, withdraw consent and complain to the competent authority (Roskomnadzor) or a court. Requests go to gneuro@djbloknote.com. The Operator may reasonably verify the requester’s identity and link to the order without asking for excessive data, and replies within the periods set by 152-FZ.
9. Security and Incidents
Access separation, secrets kept out of the frontend, TLS, signed keys, server-side payment verification, rate limiting, idempotency and logging without keys or secrets are applied. No system is absolutely secure; in an incident the Operator acts as required by law, including mandatory notifications.
10. Changes
The revision shown at checkout is stored with the order. Material changes are not applied retroactively to a completed purchase. A new revision is published with its date and applies to future actions.