Privacy Policy – BandForge

Last updated: 2026-02-12
Version: 2.0


1. Who We Are

This Privacy Policy explains how your personal information is collected, used, and protected when you use BandForge (the “Service”).

BandForge is operated by IP Pavlushkin Alexander (Individual Entrepreneur, registered in the Kyrgyz Republic), trading as BandForge (“we”, “us”, or “BandForge”).

We process your data in compliance with the EU General Data Protection Regulation (GDPR), the UK GDPR, and other applicable data protection laws.


2. Data We Collect

Account data

Writing data

Progress data

Device and technical data

Analytics data

Payment data


3. How We Use Your Data

We use your data to:


4. AI Processing


5. Payment Processing


6. Cookies

We use the following categories of cookies:

Essential cookies

Analytics cookies

Payment cookies

You can manage non-essential cookies via your browser settings or our cookie consent banner. Blocking analytics cookies will not affect the core functionality of the Service.


We process your personal data based on:

Legal basisWhat it covers
ContractProcessing necessary to provide the Service you signed up for (account management, AI feedback, progress tracking)
Legitimate interestsAnalytics, product improvement, security, and fraud prevention
ConsentNon-essential cookies (analytics), optional marketing communications
Legal obligationTax records and payment data retained as required by law

8. Data Sharing

We share your data with the following third parties, solely for the purposes described:

Third partyData sharedPurpose
OpenAI, Google (Gemini), AnthropicWriting submissions (essays, drill responses)AI feedback generation
PaddlePayment information (collected directly by Paddle)Payment processing, tax compliance
PostHogUsage events, feature interactions, session replaysProduct analytics
Microsoft ClarityAnonymised usage data, session replaysAnalytics, UX improvement
Google AnalyticsAnonymised page view and event dataAnalytics, traffic analysis

We do not sell your personal data. We do not share your data with advertisers or data brokers.


9. Infrastructure & Data Storage

ComponentProviderRegion(s)
Application backendGoogle Cloud Platform (Cloud Run)Multi-region (US, EU, and/or Asia — may change)
DatabaseNeon (managed Postgres)Multi-region (may change)
Frontend hostingCloudflare PagesGlobal CDN
AI processingOpenAI, Google (Gemini), Anthropic, and othersUS and/or EU (varies by provider)
AnalyticsPostHogEU (PostHog Cloud EU)
PaymentsPaddleEU/UK

We may change hosting regions and providers as the Service scales. Your data may be processed in any of the regions listed above, or in additional regions in the future.

Where your data is transferred outside the UK or EU, transfers are protected by Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Addendum.


10. Data Retention

Data typeRetention period
Account data (name, email)Kept while your account is active + 24 months after deletion
Writing samples and progress dataKept while your account is active; deleted upon account deletion
Analytics data12 months
Payment recordsRetained as required by tax law (typically 7 years, managed by Paddle)
BackupsMay retain data for up to 90 days after deletion

11. Your Rights

If you are in the UK or EU, you have the right to:

How to exercise your rights:

You also have the right to lodge a complaint with a supervisory authority in your country of residence.


12. Children


13. Security

We take reasonable measures to protect your data, including:

No system is 100% secure. If you become aware of a security vulnerability, please report it to support@linguo.me.


14. Changes to This Policy

We may update this Privacy Policy from time to time. The latest version will always be available at /privacy. If we make material changes, we will notify you via email or a prominent notice on the Service.


15. Contact

For any questions about this Privacy Policy or your personal data:


Last updated: 2026-02-12