Privacy Policy
Last updated: 14 August 2026
This Privacy Policy explains how Bilang (“Bilang”, “we”, “us”), operated by MultionLabs, handles personal data when you use bilang.org and related apps (including Telegram Mini Apps).
This is a product notice for transparency — not legal advice. If you need a formal review for your jurisdiction, please consult counsel.
1. Who is responsible
Controller: MultionLabs (Bilang). Contact for privacy requests: [email protected]. See also our Impressum.
2. What we collect
Depending on how you use Bilang, we may process:
- Account data — email address (magic-link sign-in), optional display name, and Telegram user id / name when you sign in via Telegram Mini Apps.
- Learning content you create — dictionary entries, examples, practice training sets and items, diary entries (including optional gloss translations), titles, notes, and import/export payloads you upload.
- Access & sharing metadata — training-set visibility, ACL / invite emails you add, and related timestamps.
- Technical data — auth tokens stored in your browser (local storage / cookie), basic server logs (e.g. timestamps, request paths, error diagnostics), and security-related signals needed to run the service.
We do not require a profile photo or payment card details in the current product.
3. Why we process data
- To create and authenticate your account (email magic link or Telegram).
- To provide training sets, flashcard practice, diary practice, dictionary, translation, import/export, and sharing.
- To send transactional emails such as sign-in links.
- To secure the service, prevent abuse, and fix bugs.
- To comply with legal obligations when applicable.
4. Legal bases (EEA/UK where applicable)
Where GDPR/UK GDPR applies, we typically rely on:
- Contract — providing the service you request.
- Legitimate interests — securing and improving the service.
- Consent — where required (e.g. optional integrations you choose).
- Legal obligation — when we must retain or disclose information by law.
5. Processors & third parties
We use infrastructure and APIs that may process data on our behalf, including:
- Email delivery (e.g. Mailtrap / ZeptoMail) for magic-link messages.
- Translation (e.g. DeepL or Google Gemini) when you use translation features — text you submit is sent to the provider to return a translation and, for dictionary saves, structured word details.
- Hosting / networking providers that run bilang.org (including reverse-proxy and TLS termination).
Browser-assisted Quizlet import runs in your browser against Quizlet; we store the resulting cards/titles you choose to save in Bilang. We do not receive your Quizlet password.
6. Cookies and local storage
Bilang uses essential storage for your signed-in session (token). We do not use advertising trackers in the current product.
7. Sharing
We do not sell your personal data. We share data with processors as needed to run Bilang, when you explicitly share training sets, or when required by law.
Public training sets are intentionally readable without sign-in. Do not put secrets in public training-set content.
8. Retention
We keep account and learning data while your account is active. Magic-link tokens are short-lived. Server logs are kept only as long as useful for security and operations. You may request deletion of your account data via [email protected].
9. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or export your personal data, and to object to certain processing. Contact [email protected]. You may also lodge a complaint with your local data-protection authority.
10. Children
Bilang is not directed at children under 16 (or the minimum age required in your country). If you believe a child provided data, contact us and we will delete it.
11. International transfers
Providers may process data in the EU/EEA, US, or other regions. Where required, we rely on appropriate safeguards offered by those providers (such as standard contractual clauses).
12. Changes
We may update this policy as Bilang evolves. The “Last updated” date above will change when we do. Continued use after an update means you accept the revised policy.
13. Contact
Privacy questions: [email protected]
Also see Terms of Service and Impressum.