Privacy Policy
Last updated: 2026-10-03
This Privacy Policy explains how iLingo collects, uses, stores, and shares information when you use the iLingo mobile app and related sign-in services.
1. Who we are
iLingo is an English-learning app that helps students improve through interactive stories and vocabulary practice. Public site: https://admin.ilingo.app/
2. Information we collect
- Account data: name, email address, and user ID.
- Sign-in data from Google, Apple, or Facebook when you choose those providers (such as email and basic profile name provided by the identity provider).
- Profile and delivery data: country/flag supplied by the profile or inferred from request country headers, platform and app version, and a push token when notifications are enabled.
- A profile photo you explicitly select from your library or capture, if you use the profile-photo feature; the app does not receive other photos from your library that you do not select.
- Your Google profile photo, if Google provides one when you sign in: we may use it as your iLingo profile photo, and you can replace or remove it from your profile.
- Learning data: reading progress, saved vocabulary, quiz results, and server-computed XP/streak state.
- Content you provide: vocabulary or free-form text/phrases submitted for translation or enrichment, assessment transcripts, and optional deletion feedback.
- Your private library: text and titles you import or choose to save, import details, and your selected basis for using the material. For document text extraction, we process only the image you capture or select and then agree to send. For article capture, we fetch the web page at the HTTPS address you enter.
- Speech practice data: optional voice recordings and transcript-match results during pronunciation practice; raw audio is not retained by default unless an explicit server retention flag is enabled.
- Assistant outputs: a free-form synthesized-audio cache record expires after 24 hours by default and never later than 7 days under server configuration. A translation-output cache record expires after 90 days by default and never later than 365 days. Expired records are removed by the next successful scheduled cleanup. Free-form text and phrase records are linked to your account. Enrichment for one bounded dictionary token may instead be reused across learners in an ownerless record keyed by a hash of the token, languages, and schema version. Raw request text is not stored in the cache tables.
- Billing data: subscription status and transaction identifiers via RevenueCat and the app stores (we do not store full payment-card numbers).
- Optional messaging/campaign data: offers or learning updates are not sent remotely without affirmative consent. When enabled, we may use subscription status, country, inactivity, or learning activity to select an audience and may personalize a message with name, streak, level, and XP. We process a delivery destination, status, and send time, then minimize destinations and message copy after processing.
- Technical and diagnostics data: product interaction, device type, app version, bounded launch/interaction timings, sanitized crash diagnostics that may be linked to your account while signed in, sanitized system logs associated with a one-way user reference, and aggregated API route metrics that exclude route parameters and learner content.
3. How we use Google user data
If you sign in with Google, we use basic account information (such as email and name) to create a secure session and sync your learning progress. We do not sell Google user data or share it for third-party advertising. Basic profile data may be used in direct iLingo messages only when you affirmatively enable the relevant offers-and-learning-updates channel; you can withdraw that consent in Settings.
4. Processors and purposes
- Supabase: authentication and user profiles.
- PostgreSQL / Neon: learning progress, subscriptions, and audit logs.
- Supabase Storage: audio/image objects required to operate features.
- RevenueCat + Apple/Google: subscriptions and restore flows.
- Firebase Analytics: product interaction only after explicit usage-analytics consent; advertising signals remain disabled.
- Firebase Messaging: operational notification delivery or direct iLingo messages after the relevant channel is enabled.
- The configured SMTP/email provider: operational or user-requested delivery, and direct iLingo messages only with explicit email-marketing consent.
- Speech/translation providers and language assistance: Groq or OpenAI may process pronunciation recordings; OpenAI may process the transcript and practice text for assessment. For translation, word explanations, illustrations, and generated speech, text may be sent to Google, OpenAI, Groq, Anthropic, DeepSeek, xAI, Moonshot AI, Z.ai, Alibaba Cloud, ElevenLabs, Fish Audio, or Tatoeba, depending on the selected service.
- OpenAI for document text extraction: after your permission for each image, the iLingo server sends a prepared copy of the selected image to OpenAI to extract its visible text. Camera permission or selecting an image alone does not send it. Capturing web articles does not send their content to an AI provider.
- Sentry/Crashlytics (when enabled): sanitized crash diagnostics; iLingo-controlled crash records may be linked to an authenticated account.
The app asks for separate permission to share recordings and personal text with these services before sending them. You can decline or turn sharing off later in Settings; reading and listening to published content remain available. Your choice is saved for this account on this device. Microphone permission alone does not authorize sharing.
5. Retention
- Account, profile, profile photo, learning progress, and push token: for the life of the account or until the photo is replaced/removed or the token is revoked, then deleted/minimized on account deletion.
- Document and article extraction: the iLingo server does not save document images or extraction drafts to files or a database. The draft is returned for your review; a private library item is created only when you choose to save it. Saved text, titles, and private import records remain for the life of your account and are deleted with it. OpenAI retention of images and results follows the service settings and its policies; not saving an image in the iLingo library does not mean the provider retains no data.
- Speech audio: by default, terminal job input is deleted; orphan input becomes eligible after 24 hours and is removed by the next successful daily cleanup. If explicit retention is enabled, the private retained copy is cleaned after 30 days or on account deletion.
- Assessment transcripts and scores: for the life of the account, then removed with the user account.
- Cached free-form synthesized audio: the record expires after 24 hours by default and never later than 7 days under server configuration. Cached translation outputs: the record expires after 90 days by default and never later than 365 days. Expired records are removed by the next successful scheduled cleanup. Owner-linked records are also removed on account deletion; an ownerless public-token result remains only until its fixed expiry.
- Billing events: retained for financial/audit obligations required by stores and law.
- Notification and campaign logs: 90 days by default, with delivery destinations and message copy minimized according to processing state.
- Aggregated route metrics, system logs, and iLingo-controlled client crash records: 30 days by default; route templates contain no learner content, and attributed crash rows are also removed with the account.
- Optional deletion feedback: becomes eligible for purge after 180 days and is removed by the next successful daily cleanup; email/name is kept only with explicit follow-up consent.
- Admin audit logs: learner data is minimized; final retention follows security policy and applicable legal obligations.
- These periods cover storage controlled by iLingo; retention by all external processors — including speech, translation, billing, analytics, diagnostics, messaging, and email providers — follows their configured settings, policies, and applicable legal obligations.
6. Storage and sharing
Data is stored with trusted infrastructure providers. We do not share personal data with third parties except as needed to operate the service or comply with law.
We use HTTPS to protect data in transit between the app and our online services. In the native iOS and Android apps, saved sign-in session credentials use operating-system secure storage.
7. Your rights
You may request access, a portable copy, correction, or account deletion from inside the app or by contacting support. We verify identity using the minimum necessary information; export requests follow a documented manual procedure.
Optional competition
Joining the competition is optional. You choose a competition alias and a built-in avatar, and control whether they appear with your points and rank publicly or to accepted friends. We do not copy your email, private name, or profile photo into the competition. You can turn participation off, change visibility, and remove or block friends in Activity.
Points recognize chapter-reading participation supported by server-timed receipts; they do not attest comprehension or language mastery. Daily, weekly, and monthly periods use UTC. Competition settings, friendships, and durable award evidence remain for the life of the account. Detailed reading receipts become eligible for deletion 30 days after expiry and are removed by the next successful daily cleanup. Resetting learning progress excludes these points from rankings while retaining award deduplication; account deletion cascades this linked data.
8. Contact
Privacy questions: support@ilingo.app
See also our Terms of Service.