Privacy Policy
Last updated: 2026-07-24
This Privacy Policy explains how iLingo collects, uses, stores, and shares information when you use the iLingo mobile app and related sign-in services.
1. Who we are
iLingo is an English-learning app that helps students improve through interactive stories and vocabulary practice. Public site: https://admin.ilingo.app/
2. Information we collect
- Account data: name, email address, and user ID.
- Sign-in data from Google, Apple, or Facebook when you choose those providers (such as email and basic profile name provided by the identity provider).
- Profile and delivery data: country/flag supplied by the profile or inferred from request country headers, platform and app version, and a push token when notifications are enabled.
- Learning data: reading progress, saved vocabulary, quiz results, and server-computed XP/streak state.
- Speech practice data: optional voice recordings and transcript-match results during pronunciation practice; raw audio is not retained by default unless an explicit server retention flag is enabled.
- Assistant outputs: when you request free-form speech or translation, the synthesized-audio or translation cache record expires after 24 hours by default and never later than 7 days under server configuration, then is removed by the next successful scheduled cleanup. The record is linked to your account; raw request text is not stored in these cache tables.
- Billing data: subscription status and transaction identifiers via RevenueCat and the app stores (we do not store full payment-card numbers).
- Messaging/campaign operations data: a temporary delivery destination, delivery status, and send time, with destinations and message copy minimized after processing.
- Technical and diagnostics data: product interaction, device type, app version, crash diagnostics, and aggregated API route metrics after identifiers, emails, and vocabulary words are stripped.
3. How we use Google user data
If you sign in with Google, we use basic account information (such as email and name) to create a secure session and sync your learning progress. We do not sell Google user data, do not use it for advertising, and limit use to account authentication and delivering the learning experience.
4. Processors and purposes
- Supabase: authentication and user profiles.
- PostgreSQL / Neon: learning progress, subscriptions, and audit logs.
- Supabase Storage: audio/image objects required to operate features.
- RevenueCat + Apple/Google: subscriptions and restore flows.
- Firebase Analytics: product interaction only after explicit usage-analytics consent; advertising signals remain disabled.
- Firebase Messaging: notification delivery when enabled.
- The configured SMTP/email provider: operational or user-requested email delivery.
- Speech/translation providers when a feature is enabled: receive the text or audio needed to process your request and produce speech, assessment, or translation output.
- Sentry/Crashlytics (when enabled): aggregated crash diagnostics.
5. Retention
- Account, profile, learning progress, and push token: for the life of the account or until token revocation, then deleted/minimized on account deletion.
- Speech audio: by default, terminal job input is deleted; orphan input becomes eligible after 24 hours and is removed by the next successful daily cleanup. If explicit retention is enabled, the private retained copy is cleaned after 30 days or on account deletion.
- Assessment transcripts and scores: for the life of the account, then removed with the user account.
- Cached free-form synthesized audio and translation outputs: the record expires after 24 hours by default and never later than 7 days under server configuration, then is removed by the next successful scheduled cleanup; it is also removed on account deletion.
- Billing events: retained for financial/audit obligations required by stores and law.
- Notification and campaign logs: 90 days by default, with delivery destinations and message copy minimized according to processing state.
- Aggregated route metrics, system logs, and iLingo-controlled client crash records: 30 days by default; route templates contain no learner content, and attributed crash rows are also removed with the account.
- Optional deletion feedback: becomes eligible for purge after 180 days and is removed by the next successful daily cleanup; email/name is kept only with explicit follow-up consent.
- Admin audit logs: learner data is minimized; final retention follows security policy and applicable legal obligations.
- These periods cover storage controlled by iLingo; retention by all external processors — including speech, translation, billing, analytics, diagnostics, messaging, and email providers — follows their configured settings, policies, and applicable legal obligations.
6. Storage and sharing
Data is stored with trusted infrastructure providers. We do not share personal data with third parties except as needed to operate the service or comply with law.
7. Your rights
You may request access, a portable copy, correction, or account deletion from inside the app or by contacting support. We verify identity using the minimum necessary information; export requests follow a documented manual procedure.
8. Contact
Privacy questions: support@ilingo.app
See also our Terms of Service.