Privacy Policy
Last updated: October 3, 2026
This policy explains what personal data InputTrail collects, why, and the choices you have. InputTrail is anonymous-first: you can watch and track your hours with no account, and your statistics are kept on your device whether or not you have one. InputTrail uses YouTube API Services, and section 6 explains what YouTube data it uses and how.
1. Who we are
InputTrail is operated by Mawal AB, a Swedish private limited company (aktiebolag), organization number 559279-0462, registered at Hallandsgatan 38, 118 57 Stockholm, Sweden. For personal data processed through InputTrail, Mawal AB is the Data Controller under the EU General Data Protection Regulation (GDPR) and the equivalent UK and Swiss laws.
You can reach us about privacy at hello@inputtrail.com or by post at the address above.
2. Personal data we collect
We collect only what the service needs.
- Account data. When you create an account, we store your Firebase user identifier and, where you provide it, your email address, plus the time you accepted our Terms of Service and this Privacy Policy. After your first sign-in, we may show you a one-time, optional prompt asking where you heard about InputTrail: if you answer it, we store your answer, and either way we store the time we asked, so the prompt is not shown again. We also store your email preference: whether you asked for occasional tips and product news by email or declined them, when and where you made that choice (the sign-up form or Email preferences on the More page in the app), and which version of the checkbox wording you were shown. If you change your choice later, the new choice is recorded the same way and replaces the earlier one. Sign-in is handled by Firebase Authentication using Google or an email and password.
- Learning statistics. The hours you watch and your progress: watch segments (the language, the YouTube video and playlist identifiers, the position in the playlist, seconds watched, the start and end times, the time zone offset your device reported when the run started, the playback speed, and whether the run was a replay of a video you had already watched), the status you give a video (watched, skipped, or hidden, plus the playlist and position the video was in and when you marked it watched), any external hours you report yourself, the dated days of input you log yourself for time you spent outside the app (a date, a duration, and the video it was for if you claimed it when marking one watched), your continue-watching position, and your daily watch-time goal. While you are anonymous, this data stays in your browser (see section 4) and is sent to us only if you sign in and sync.
- Files you upload to import hours. If you use the optional spreadsheet import, the CSV file you upload is sent to OpenAI, our AI processor, to read it into a draft of daily hours. We keep only the resulting hours (a date and a duration per day), which you review before they are saved; we do not retain the file itself. Please do not include personal or sensitive information beyond what is needed to import your hours.
- Subscription and billing data. When you start a checkout, we store the Paddle transaction identifier for it against your account, so that a payment Paddle later confirms is credited to the account that started the checkout and to no other. We keep that record whether or not you go on to pay. If you subscribe, we also store your subscription status, the Paddle subscription identifier, the end of the current billing period, and the time of the last billing event. We never receive or store your full payment card details (see section 8).
- Technical and diagnostic data. Like any website, our servers receive your IP address and basic request information when you use the service. We use Sentry to record error reports so we can find and fix faults. If you turn on the optional performance category, Sentry also records diagnostic session replays, with text and media masked by default. We also measure aggregate, cookieless usage and performance through Vercel, such as page views, videos started and finished, and page-load speed. Those measurements carry no identifier stored on your device and are not tied to your account.
We do not intentionally collect special category data (such as health, ethnicity, or political opinions), and we ask that you do not submit it.
3. How we use your data and our legal bases
- To provide the service: running your account, tracking and syncing your hours, remembering where you left off, and applying the free trial and any subscription. Legal basis: performance of our contract with you (Article 6(1)(b) GDPR). For anonymous use, the processing happens on your device and we hold no personal data about you.
- To keep the service secure, reliable, and improving: diagnosing errors through Sentry error reports, preventing abuse of the trial, the tracking endpoints and adding your own YouTube content, and understanding aggregate usage. Legal basis: our legitimate interests in a working, secure service (Article 6(1)(f) GDPR).
- To meet legal obligations: for example, keeping records related to purchases. Legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR).
- Where you give consent: for the optional functional category (Paddle's script on your account page for your local price, which sends Paddle your IP address and browser information), the optional performance category (Sentry's session replay and any performance cookies we may add later), and the optional "Where did you hear about us?" answer, which you may dismiss instead of answering. Legal basis: consent (Article 6(1)(a) GDPR), which you can withdraw at any time.
- To send you tips and product news by email, only if you ask for them: we use your email preference (see section 2) to decide whether we may send you occasional tips and product news by email. Legal basis: consent (Article 6(1)(a) GDPR). You can withdraw it at any time in Email preferences on the More page in the app, or by emailing us, and withdrawing does not affect processing that already took place. We keep the record of your choice, including a choice to decline or withdraw, to show what you chose and when. Legal basis for that record: our legitimate interest in being able to demonstrate your choice (Article 6(1)(f) GDPR).
4. Anonymous use and data stored on your device
You can use InputTrail without an account. When you do, your hours, video statuses, external hours, the days of input you log yourself for time spent outside the app, your daily goal, and your continue-watching position are stored locally in your browser using IndexedDB. This data stays on your device and we cannot read it. If you create an account and sync, the records are uploaded to our server and verified, and a copy of your account stays on this device: it is how the app shows your hours without asking our servers on every screen, and how it keeps working when it cannot reach the network. That copy is kept for as long as you stay signed in on the device: it does not expire on its own, though your browser can also delete it on its own, as described below. Signing out removes it. Anything you recorded on the device while signed in that has not reached us yet is kept when you sign out, so that it is not lost: it is sent to your account the next time you sign in there, and we do not make it available to anyone else signing in on this browser. If you never sign in again on that device, it stays there until you clear your browser storage, which removes all of it (and resets the anonymous trial counter). Your browser can also delete this data on its own, and without an account there is no other copy of it: private browsing data is usually deleted when the private session ends, a browser can delete it when the device runs low on storage, and Safari, with its default settings, deletes it after seven days of Safari use without any interaction with InputTrail.
5. Cookies
InputTrail uses a small set of strictly necessary cookies. Only with your consent, it also uses the optional functional category (your account page loading Paddle's script to show your local price) and the optional performance category (Sentry's diagnostic session replay, and any performance cookies we may add later). For the full list, their purposes, and their lifetimes, see our Cookie Policy. You can change your choice at any time through the cookie settings in the footer.
6. Who we share data with
We do not sell your personal data. Apart from the disclosures described in sections 14 and 15, we share it only with the recipients listed below. Where a recipient acts on our behalf, it does so under a data processing agreement; where the table names one an independent controller, it decides for itself how it uses the data.
| Recipient | What they do | Where | Role |
|---|---|---|---|
| Vercel | Hosting, feature flags, and cookieless analytics | United States and global edge network | Processor |
| Neon | Managed PostgreSQL database for accounts and statistics | The region we select (EU or United States) | Processor |
| Google (Firebase Authentication) | Account sign-in and authentication | United States and global | Processor |
| Google (YouTube) | Embedded video playback and playlist information | United States and global | Independent controller for your use of YouTube |
| Sentry | Error monitoring and masked diagnostic session replays | European Union (Germany) | Processor |
| OpenAI | AI-assisted reading of files you upload to import external hours | United States and global | Processor |
| Paddle | Payment processing and billing as Merchant of Record, and, if you turn on the functional cookie category, showing your local price on your account page before you buy (your IP address and browser information reach Paddle for that) | United Kingdom and global | Independent controller |
YouTube API Services
InputTrail uses YouTube API Services. The videos in InputTrail are hosted on YouTube, and we do not own or host them. We use the YouTube Data API to read information about the videos and playlists in the app, and YouTube's embedded player to play them. Google and YouTube handle your use of YouTube as their own controller, under the Google Privacy Policy.
Our server makes these requests with InputTrail's own API key, never with your Google account. For each video it reads the title, the duration, the address of the thumbnail image, the channel, the position in its playlist, and whether YouTube marks the video as made for kids, and for a playlist its title and description. We use that information to show you the videos and playlists, to list them in order, to limit the hours a video can count to its length, and to turn off tracking for videos made for kids. We store it in our database, refresh it regularly, and delete or replace anything we have not refreshed within 30 days, and we delete a playlist's videos straight away when YouTube reports the playlist removed. Thumbnail images load in your browser directly from YouTube; we do not copy or store them. So that the app can open without a connection, your browser also keeps a copy of our offline page, which contains some of those titles, durations, and thumbnail addresses. A copy more than 30 days old is never shown, and it is replaced or deleted the next time you use InputTrail; clearing your browser storage removes it.
The watch records described in section 2 identify the YouTube videos and playlists you watched by their YouTube identifiers, and we keep them as described in section 9. If you add your own YouTube videos or playlists while signed in, we read and store the same information for them under the same 30-day rule, and we keep a record linked to your account of what you added until you remove it or delete your account. So that no one account can use up the daily YouTube allowance the service shares, we also count, against your account, how much of it the videos and playlists you add use each day; we keep each day's count for about a week, and it is deleted with your account. When you add a playlist, we save its YouTube title as the name of your copy and refresh that name along with the rest of this information. If YouTube reports the playlist removed, or we cannot refresh the name within 30 days, we replace YouTube's title with a generic name. If you rename the playlist, the name you choose is yours: we stop refreshing it and keep it until you remove the playlist or delete your account. For a video YouTube marks as made for kids, or whose status YouTube does not report, InputTrail records none of your playback (no watch time, no position, and no automatic watched mark), though you can still mark it watched or skipped yourself.
We do not sell this information or use it for advertising, and InputTrail shows no advertising of its own. We share it only with the providers in the table above that host and run InputTrail for us. The player itself is YouTube's: YouTube serves the videos in it and may show advertisements there. When the player or a thumbnail loads, your browser connects to YouTube and Google, which receive your IP address and information about your browser and device, and, through the player, which video you play and how you use the player. We show the video in YouTube's privacy-enhanced mode, but the script that starts the player comes from youtube.com, and YouTube and Google may still store or read cookies and similar technologies on your device through the player and that script, under their own policies; our Cookie Policy says more. What InputTrail itself stores on your device is described in sections 4 and 5.
InputTrail never asks for access to your YouTube account, and it holds no YouTube data under such a permission. You can review and remove the access you have given to apps, including through Sign in with Google, on the Google security settings page. Removing access there does not delete your InputTrail account or the data we hold; to have that deleted, use our normal deletion process in section 10. If you have questions or complaints about how InputTrail handles YouTube data, email us at hello@inputtrail.com.
7. International data transfers
Some recipients process data outside the European Economic Area (EEA). Sentry processes our diagnostic data in the European Union. Paddle is based in the United Kingdom, which the European Commission recognizes as providing adequate protection. For transfers to the United States or other countries (for example, Google, Vercel, Neon, and OpenAI depending on configuration), we rely on the European Commission's Standard Contractual Clauses and, where the recipient is certified, the EU-US Data Privacy Framework (with the UK Extension for UK transfers). You can ask us for more detail using the contact above.
8. Payments
Payments are handled by Paddle.com Market Limited (the Paddle entity shown in checkout and on your order confirmation) as our Merchant of Record. Paddle is an independent data controller for the buyer relationship, including payment, billing, fraud prevention, and tax compliance. Your card details are entered with Paddle and handled by Paddle under the PCI DSS standard; we never receive or store them. We receive only the transaction and subscription details we need to give you access, such as your subscription status, identifiers, and the billing period. Your browser can load Paddle's script on your account page and on the checkout page, and your IP address and browser information reach Paddle whenever it loads. On your account page, while you have no subscription, it loads only if you have turned on the optional functional category in our cookie banner, or when you press Subscribe. The price you see there first is one we render ourselves, with no request from your browser to Paddle. With the functional category on, the script replaces it with the price in your local currency and the tax that applies, when Paddle answers with a price we can display (otherwise our price simply stays), and Paddle uses your IP address and browser information to work that out. On the checkout page it loads as soon as you arrive, because that page is the checkout itself. Paddle also stores a cookie on its own domain whenever that script loads, and inside the checkout both Paddle and Stripe, which Paddle uses to process card payments, store more on their own domains and receive your IP address and browser information in the same way; our Cookie Policy says what that is for, how long the one we can document lasts, and how to limit it. When you start a checkout while signed in with an email address you have verified (a Google sign-in counts), we send that address to Paddle so it can prefill the checkout and create or find your customer record there (Paddle keeps that record even if you do not complete the purchase). Otherwise Paddle asks you for your email address in the checkout itself. We also attach your InputTrail account identifier to the transaction, so the purchase is identifiable in Paddle's dashboard, and we separately record on our side which account that transaction belongs to, so the payment Paddle confirms is credited to the account that started the checkout and to no other. See Paddle's privacy notice. The order process itself is described in our Terms of Service.
9. How long we keep data
We keep personal data for as long as needed for the purposes described in this policy, and longer where the law requires it.
- Account data and learning statistics: kept while your account is active and deleted when you delete your account (see section 10).
- Local data on your device: without an account, it stays in your browser until you clear your browser storage. Your browser can also delete local data on its own, with or without an account (see section 4). With an account, your device keeps a copy of your account for as long as you stay signed in on it. Signing out removes that copy, and anything you recorded while signed in that has not reached us yet is kept so it is not lost, then sent to your account the next time you sign in there, or held until you clear your browser storage if you never do. Deleting your account removes the copy on the device you delete it from, including anything not yet sent to us. Other devices you are signed in on remove their copy the next time they connect, except anything recorded there that had not reached us, which stays on that device until you clear your browser storage. We cannot access any of it.
- Billing and transaction records: retained as required by law. Swedish accounting law requires accounting records to be kept for seven years. Paddle retains payment records under its own policy as Merchant of Record. When an account that paid is deleted, we keep a minimal billing record: the Paddle subscription identifier, its status and its dates. It is not linked to your learning data or to your sign-in, and we keep it for as long as accounting law requires.
- Diagnostic data: kept only as long as needed to investigate faults and keep the service reliable.
- Cookies: for the lifetime stated in the Cookie Policy.
10. Your rights
Under the GDPR and equivalent laws, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict how we process your data;
- receive your data in a portable format and have it transferred;
- object to processing based on our legitimate interests (see section 11);
- withdraw consent at any time where we rely on consent; and
- not be subject to a decision based solely on automated processing (see section 12).
You can download a copy of your data yourself at any time from the More page in the app, with or without an account. The download is a ZIP of spreadsheet (CSV) files and one JSON file. The CSV files hold the learning data the device you use holds: your input per day for each language, your playback sessions, video marks, logged hours and resume points. The JSON file holds the same playback sessions, video marks, logged hours and resume points in one machine-readable file, without the per-day totals. When you are signed in, the download also includes your account details (account ID, email address, sign-up date, terms acceptance, referral answer and daily goal) and your subscription record.
For anything the download does not include, such as playlists you added, or to exercise any other right, including having your data transferred to someone else, email us at hello@inputtrail.com. You can delete your account yourself on the Account page in the app: choose Delete account, type the confirmation phrase, and sign in again if you have not signed in within the last few minutes. A subscription that renews has to be cancelled first. You can also ask us by email to delete your account and data. We may need to verify your identity, for example by confirming control of the account email, before we act. We respond within one month, which we may extend by two further months for complex requests, and we will tell you if we do. Withdrawing consent or objecting does not affect processing that already took place.
11. Your right to object
You have the right to object, at any time and on grounds relating to your particular situation, to our processing of your personal data that is based on our legitimate interests (section 3). If you object, we will stop that processing unless we have compelling legitimate grounds that override your interests, rights, and freedoms, or we need the data to establish, exercise, or defend legal claims. To object, email us at hello@inputtrail.com.
12. Automated decision-making
We do not make decisions that produce legal or similarly significant effects about you using solely automated processing. The free-trial limit (based on the hours you watch inside the app) and subscription access are applied automatically by fixed rules. This is not profiling and has no legal or similarly significant effect on you.
13. US state privacy rights
We do not meet the thresholds that make laws such as the California Consumer Privacy Act (CCPA) mandatory for us. We nonetheless voluntarily extend the following to residents of US states with comprehensive privacy laws: the right to know about and access your personal information, to correct it, to delete it, and to be free from discrimination for exercising these rights. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. That covers InputTrail's own processing only; it says nothing about what YouTube and Google do with what they receive or store when the video player or a thumbnail loads, which section 6 of this policy and our Cookie Policy cover. Because there is no sale or sharing of ours to stop, a Global Privacy Control (GPC) signal has nothing of ours to act on; we honor it as an opt-out preference to the extent it would apply. To make a request, email us at hello@inputtrail.com. We respond within 45 days and may extend by a further 45 days with notice.
14. Government and legal requests
We may disclose personal data where we are legally required to do so, for example to comply with a court order, applicable law, or a valid request from a public authority. The legal basis is compliance with a legal obligation (Article 6(1)(c) GDPR).
15. Business transfers
If Mawal AB is involved in a merger, acquisition, financing, reorganization, or sale of assets, your personal data may be transferred as part of that transaction. We will continue to protect it and will notify you of any change of control or any material change to this policy. Under US state privacy laws, transferring personal information as an asset in such a transaction is not a sale.
16. Children
InputTrail is intended for adults and is not directed to children. We do not knowingly collect personal data from children under the age of digital consent, which is 16 under the GDPR and 13 in Sweden. If you believe a child has given us personal data, contact us at hello@inputtrail.com and we will delete it.
17. Security and data breaches
We protect your data with measures appropriate to the risk: connections encrypted over HTTPS with HSTS, HttpOnly session cookies, server-side validation and access controls, and keeping payment card details with Paddle rather than on our systems. No method of transmission or storage is completely secure. If a breach affects your personal data and is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority and, where required, you, in line with Articles 33 and 34 GDPR.
18. Complaints and supervisory authorities
If you have a concern, please contact us first so we can try to resolve it. You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), imy.se. EEA residents can find their local authority through the European Data Protection Board. UK residents may contact the Information Commissioner's Office, and residents of Switzerland the Federal Data Protection and Information Commissioner.
19. Changes to this policy
We may update this policy as the product or the law changes. When we do, we revise the "Last updated" date at the top. For material changes, we will give notice by email or a prominent notice on the site before they take effect.
20. Contact us
Mawal AB, Hallandsgatan 38, 118 57 Stockholm, Sweden. Email: hello@inputtrail.com.