Back to home

Privacy Policy

How Mazelingo handles accounts, reading text, browser history and payments.

Last updated: 2026-10-02

Scope and operator

This policy applies to Mazelingo at mazelingo.co. It explains the information we process when you browse the site, use mixed reading or AI lessons, create an account, contact support or use a checkout.

Information we process

  • Account information: name, email address, password hash, authentication sessions and account settings. We store a password hash rather than your plain-text password.
  • Reading requests: text you submit for translation, language choices, style notes, and the sentence or context needed for an AI explanation. Only submit material you are entitled to use; avoid confidential or sensitive personal data.
  • Local reading history: original text, translations, saved explanations, language choices, pins and preferences are saved in browser storage on the current device. Signed-in and guest histories are separated locally. They are not currently a cross-device cloud backup.
  • Payments and subscriptions: account email, order references, plan, currency, amount, transaction references, billing periods and payment or refund status. Card information is collected by the hosted payment service, not by a Mazelingo card form. We do not store full card numbers or security codes.
  • Support information: messages and attachments you choose to send, and the details needed to resolve your request.
  • Technical and traffic information: visited paths, timestamps, referral sources, campaign parameters, browser user agent, locale, approximate region and pseudonymous visitor/session identifiers. Our traffic records store a derived IP hash rather than the raw IP; our hosting provider also processes request data to deliver and secure the service.

Why we use information

We use these data to operate the site, generate requested translations and lessons, authenticate accounts, handle subscriptions and refunds, answer support requests, understand site usage, and prevent misuse. We do not sell personal information.

AI and other service providers

Text translation and explanation requests send the required text and context to the configured AI service. The current deployment uses APIMart to route requests to a language model provider. AI providers process requests under their own policies; this service does not promise zero retention or that provider-side training is always disabled. Changing the mix ratio, switching an already translated sentence and reopening a cached explanation do not by themselves require a new AI request.

Cloudflare provides hosting and server data storage. Waffo handles hosted checkouts as Merchant of Record and processes payment data under its own privacy policy and checkout terms. We may also share necessary information to comply with applicable law, resolve payment disputes or protect users and the service. Providers may process information outside your country.

Cookies and browser storage

We use authentication cookies, language/theme preferences, visitor and acquisition identifiers, session storage for visit/session attribution, and local storage for reading history. Some traffic identifiers persist for up to one year; acquisition identifiers may persist for up to 30 days. You can manage cookies and site storage in your browser. Blocking or clearing them can sign you out or remove saved reading history.

Browser/device speech features are supplied by your browser or operating system and are subject to their own settings and policies. Optional third-party analytics or chat services, if enabled, are subject to the notice and settings shown on the site.

Retention and security

We retain server records for as long as reasonably necessary for the service, support, security, payment/accounting requirements and applicable legal obligations. Browser history remains on your device until you delete it, storage limits remove older items, or site data are cleared. Payment providers may have separate legal retention duties.

We use HTTPS and access controls to protect server information. Browser reading history is not an encrypted vault, and no internet service can guarantee absolute security. Use caution on shared devices.

Your choices and requests

You can edit available profile settings and delete local reading-history items in the workspace. Contact us to request access, correction, export or deletion of server-held personal information, or to raise an objection or other request available under applicable law. We may verify your identity and may need to retain limited records required by law.

Updates

We will update the date on this page when this policy changes. Material changes will be communicated through an appropriate website or account notice. Read the terms and contact page for related information.