At a glance. Lengio is built privacy-first, and two things changed with this revision. An account is now required to use the App, and the App is gaining a copy of your study progress on a server we operate, so that it will survive a lost phone and follow you to a new one. The App both reads and writes that copy from this release onwards; Section 5A dates the change and says what makes it up. Your photos and your AI Chat Coach conversations are not part of that copy and never leave your device. We run no advertising SDKs, sell no data, and do not track you across other companies' apps and websites. Section 5A says exactly what is in the server copy, what is kept out of it, and how to switch it off.
The App does record anonymous usage events — which screens you open, which lessons you finish — so we can see what is worth building next. They carry no name, no email, no advertising identifier, no IP address and no location, and you can switch them off in Settings. Optional AI features run on our servers only when you choose to use them.
Four things we want to be precise about rather than flattering, because each of them is a place where the simple version of this sentence would be wrong:
What changed in this revision (17 September 2026). Two corrections to a plan, neither of which has ever described a released version of the App. (i) The 15 September revision staged the progress copy across two releases — reading in the first, writing in the one after. It no longer does: your device reads and writes from the same release. (ii) That revision also said accounts were arriving on iPhone and iPad first and the Android app would follow. It no longer does: the three arrive together. Both sentences were live for two days and no release accompanied either, so no version of the App has ever behaved the way they described. Section 5A and Section 4.6 carry the detail and say plainly that the plan changed.
What changed on 15 September 2026. Two things, and the first is the largest change this Policy has ever carried. (a) The previous version said, in bold, that there was no copy of your study progress on any server we control and that we operated no server-side sync of your progress. That is no longer the plan, and we are withdrawing the sentence rather than editing it away: the App is gaining a copy of your study progress on a server we operate, and Section 5A is a new section describing exactly what is in it, what is deliberately kept out, how long it lasts, and how to switch it off or erase it. (b) An account is now required to use the App, where the previous version said it was optional; Section 4.6 says why, and which phones it applies to today. Section 5, Section 6, Section 7, Section 11 and Section 15 were updated to agree with both. Nothing here is retroactive: no study progress has ever been held on our servers, and this page was live before the release of the App that begins it — which is what the withdrawn sentence promised we would do, and which remains true of the 17 September revision above.
This Privacy Policy ("Policy") describes how Lengio ("Lengio", "we", "us", or "our") processes information when you use the Lengio mobile application for iOS and Android (the "App") or visit the Lengio website at lengio.app (the "Site"), collectively the "Services".
This Policy applies to all users of the Services worldwide, with additional disclosures for residents of specific regions (see Region-Specific Disclosures). Where the App behaves differently on iOS and on Android, this Policy says so explicitly rather than describing only the more favourable case. It does not apply to third-party services you reach through links inside the Services — those are governed by their own privacy policies.
By using the Services you confirm you have read and understood this Policy. If you do not agree, please do not use the Services.
The Services are operated by Nexios Media LLC, a limited liability company organised under the laws of the State of Illinois, United States, trading as "Lengio" (nexios-media.com).
Nexios Media LLC maintains a registered agent in Illinois as required by state law, through whom formal service of process may be made. For every other purpose — including notices under this document, privacy requests, and support — please use [email protected], which we monitor and which is the fastest way to reach a person.
For the purposes of the EU/UK General Data Protection Regulation, similar laws, and CCPA/CPRA, that company is the data controller (or "business") responsible for the limited information we process. You can reach us at [email protected] for any privacy-related question, request, or complaint.
We have not appointed a statutory data protection officer because the nature and scale of our processing does not require one, but the contact above is monitored by a person with responsibility for privacy matters.
We have intentionally designed Lengio to collect as little personal information as possible. The categories below describe everything we receive.
The purchase identifier — stated plainly, because it is the one identifier that persists. The App generates a random identifier of its own the first time you buy something, and attaches it to the transaction: to Apple as appAccountToken, and to Google as obfuscatedAccountId. It is a random UUID. It is not derived from you, your device, your Apple Account, your Google Account, your email address, or your payment details, and on its own it identifies nobody — but it is stable, and it is the only durable thing the App creates that leaves your device.
Why it exists: without it, a purchase and a person cannot be reunited. Neither store lets it be added to a transaction after the fact, so if it is missing at the moment of purchase it is missing forever, and a subscriber who changes phone or loses a device has no way to prove the purchase was theirs. That is the problem it solves, and it is the only thing we use it for.
Three consequences we would rather state than have you discover:
If you want it gone, the only way is to remove the App and, on Android, to delete Lengio's data from your Google backup. We will also delete our copy on request, on the understanding described in Section 15 — that doing so may make a past purchase unrecoverable.
Which versions. This identifier is introduced in the release of the App that accompanies this revision of the Policy, alongside the account in Section 4.6. Purchases made with earlier versions carry no such identifier and cannot be given one retrospectively — neither store permits it — which is the reason it is being introduced now rather than later.
The App records a small number of anonymous usage events so we can see which features are worth building and where people get stuck. This is our own pipeline, running on servers we operate. There is no third-party analytics SDK, no advertising SDK, and no advertising identifier anywhere in the App on either platform.
Each stored event contains only:
iPhone16,1 or Pixel 8 — the same string for millions of devices).Event names are things like app_open, lesson_complete, paywall_view and purchase_success. We do not record the words you study, anything you type, anything you say, your photos, or the content of AI conversations.
A correction, September 2026 — what a reinstall actually does. Until this revision, this section said that deleting and reinstalling the App always produces a new install identifier and that we have no way to connect the two. On iPhone that holds for an ordinary delete-and-reinstall, though restoring a whole device from an iCloud backup does carry the old identifier across. On Android it was simply wrong. The identifier is held in the App's preferences, and Google's Auto Backup includes those preferences, so reinstalling Lengio — or setting up a new Android phone from your old one — restores the identifier you already had rather than minting a fresh one. We had not noticed; we are correcting it rather than leaving a comfortable sentence standing. The practical effect is that on Android a returning install may be counted as the same install, which is a slightly better statistic and a slightly weaker privacy claim than we were making. Nothing else about these events changed, and the switch in the next paragraph still stops them completely. We are keeping the current behaviour — turning it off would put the identifier outside your control of your own backup — and we have restated the retention argument in Section 11 so that it no longer rests on the sentence we have just withdrawn.
Being an identifier that can persist across a reinstall is, for what it is worth, the ordinary condition of anything inside your own device backup. We accept the accuracy cost of not adding anything else to these events, which is why there is nothing here to correlate the identifier against.
Your IP address is not stored. Our servers necessarily receive it in order to answer the request, as every web server does, but it is never written to the analytics archive. We do not record your country, region, or any other location. We removed the country field in July 2026 specifically so that this sentence would be true.
You can turn this off. Open the App → Settings → Share Usage Data. Switching it off stops collection immediately and discards anything still waiting to be sent from your device. Every feature behaves identically either way — nothing is withheld from you for opting out.
If you choose to use the AI Chat Coach (described on our website as the AI Speech Partner), the App captures audio from your microphone only while the feature is active and converts it to text. What happens to that audio depends on your platform, and we describe both cases exactly.
Before any of it is sent, we ask — inside the App. The first time you open the AI Chat Coach, the App tells you plainly what will be sent to Google to generate the reply — the messages you type or speak to the coach, your Interests text if you have filled it in, and your level and the vocabulary you are practising — and asks you to agree. If you decline, the Chat Coach does not open and nothing is sent; every other part of the App works exactly as it did. The check is made where the request is built, not on the screen, so there is no path into the AI that goes around it. You can withdraw at any time from inside the chat — the AI notice at the top, then Stop sharing — and that stops the very next request. It cannot recall what has already been sent, and we say so rather than implying otherwise. We ask inside the App rather than relying on your having found this page, because a policy is a description and a description is not a consent.
What is never sent on this path: your name, your email address, your account identifier, your age answer, and any identifier for your device. The coach does not know who you are.
You are told it is an AI, and you can report it. A permanent notice above the conversation says you are chatting with an AI and that it can be wrong. Every reply the AI generates carries a control that reports it to us without leaving the App; the report opens an email to [email protected] that you read and send yourself, so you see exactly what is going before it goes, and it reaches a mailbox a person reads rather than a counter.
If a conversation turns to self-harm. The App watches, on your device, for a message that expresses an intention to harm yourself. When it sees one it does not send it: the message does not reach Google, it is not written into the conversation, and it is not logged or counted anywhere. Instead the App shows emergency numbers and a link to an international helpline directory. We would rather this feature were never useful. It runs on the device because a rule we ask a language model to follow is a request, and this had to be something that holds when the model does not.
In neither case do we receive or store your audio. Lengio's servers receive only the resulting text.
The Interests field. Settings → Profile contains a free-text box labelled Interests, where you can list hobbies or topics you enjoy. If you fill it in, that text is sent to the AI provider with every Chat Coach message, including the coach's opening line, so the conversation can steer toward things you actually care about. It is truncated to a few hundred characters and it is sent exactly as you typed it. Nothing else in Settings is transmitted this way. If you would rather it were not sent, clear the box: an empty field is omitted entirely, and the feature works without it.
The App also used to send the name you entered during setup in the same place, so the coach could greet you by it. We removed it. A first name is personal data with no teaching value the coach cannot get another way, and it should not have been going to a third party to produce a nicety. The code that sent it was deleted from both apps on 11 September 2026; every release published after that date omits it, and if you are running an older release it is still being sent until you update. The name is still used for greetings inside the App, where it never leaves your device. We are recording the change here rather than silently benefiting from it.
Please do not speak or type personal, confidential, financial, health, or otherwise sensitive information about yourself or anyone else into the AI Chat Coach — and in particular, please do not put anything in the Interests box that you would not want sent to an AI provider with every message.
You can replace the picture on any vocabulary card. Tapping the picture offers Choose Photo, which uses your own photo library and sends nothing anywhere, and Search Images, which opens Google Image Search inside an in-app browser.
If you use Search Images, your search term — the word you are studying — goes to Google directly, along with your IP address, under Google's own privacy policy. We do not see the search or the results, and the image you pick is saved only on your device. The in-app browser is restricted to Google's own image-search pages — it will not follow a link off them — and SafeSearch is forced on and cannot be turned off from inside Lengio.
An account is required to use the App, and we are reversing what we told you before. The previous version of this Policy said the account was optional and that nothing in the App required one. The reason for the change is that a learner who loses a phone should not lose years of study with it, and that only works if the progress in Section 5A has an account to belong to. There is no charge for it, nothing is withheld from you for having one, and you can delete it at any time (Section 15). What you cannot do is use the App without one.
Which phones this applies to. Accounts arrive on iPhone, iPad and Android together, with the releases of the App that accompany this revision. The 15 September revision of this page said the Android app would follow later; it no longer does, and we would rather record that the plan changed than let the sentence quietly become true of nothing. Everything in Section 5A applies to all three from those releases onward.
There is no password. You sign in either with Apple or Google, or by typing an email address and entering a six-digit code we send to it. We hold no password, so there is no password to lose, reset, or breach.
If you create one, this is everything the account record contains:
What the account record itself does not contain. It holds no photos, no Chat Coach conversations and no audio. Those stay on your device exactly as described in Section 5. It does not hold your study progress either — that is kept as a separate record, in the same database and against the same account, and Section 5A describes it in full.
And a sentence we are withdrawing. The previous version of this Policy said that creating an account did not upload your learning data to us, that we were not building a sync service, and that if we ever did it would be described here before it existed. We have built one. This page is that description, published before the release of the App that uses it — which is the part of that promise we are keeping.
Where it lives. In a small database we operate on Cloudflare’s infrastructure in the United States, and nowhere else apart from the backups described in Section 5A and Section 11. The sign-in emails are delivered by Zoho's ZeptoMail, also in the United States. Both are listed in Section 9 and covered by Section 13.
On your device, the sign-in tokens are held in the iOS Keychain or the Android Keystore, are readable only after you have unlocked the device at least once since it booted, and are deliberately excluded from iCloud and Google backup and from phone-to-phone transfer — a session copied onto a second device is a second person signed in as you, with no way for you to see it or stop it. This is the exact opposite of how the purchase identifier is treated, and the difference is intentional.
Emails we will send you. A sign-in code when you ask for one; a notice when you request account deletion and again when it is executed; and, if you switch it on, a notice when your account is used to sign in on a new device. That is the complete list. We do not send marketing email and there is nothing to unsubscribe from.
Deleting the account is described in Section 15 and at lengio.app/delete-account.
The following information lives on your device only and is never transmitted to us. Operating-system encryption and application sandboxing apply on both iOS and Android.
This section changed on 15 September 2026. Before that date, your study progress was on this list. It is described in Section 5A instead, and moves to your Lengio account on the schedule set out there. Nothing you had already stored on your device was uploaded retroactively: the sync begins with the App version that introduces it, and only for an account you have signed in to.
Platform backup. Separately from the account sync in Section 5A, your device may back itself up to your own account with Apple or Google. That backup belongs to them, not to us:
Both stores belong to Apple and Google respectively and are tied to your account with them. We have no access to either, and neither is operated by us. Neither one moves your progress between iOS and Android — that is what the account sync in Section 5A is for.
Two items in those backups are handled deliberately rather than by default, and both are described above: the purchase identifier is kept inside them on purpose (Section 4.2), and account sign-in tokens are kept out of them on purpose (Section 4.6). On Android, the anonymous install identifier is inside them as a side-effect of where it is stored, which is the correction in Section 4.3.
When you are signed in to a Lengio account, the App keeps a copy of your study progress on a server we operate, so that your progress survives losing your phone and follows you to a new one — and from iPhone to Android and back, which your platform’s own backup cannot do. The paragraph below says which release starts doing that.
Which release, and in which direction. We are describing this before it is switched on, which is the promise we made and the reason this page is dated ahead of the App. Your device both reads and writes that copy from the first release that accompanies this Policy — 17 September 2026, iOS and Android together. Erase All My Progress and account deletion reach the server from the same release, because asking for a copy to stop existing has to work the moment there is anything to erase.
We changed this plan before it shipped, and we are not quietly restating it. The 15 September revision of this page said the first release would read only, with uploads following in the release after. That staging was a caution about our own rollout, not a protection for you, and holding it would have meant shipping a version that required an account, told you your progress was kept for you, and did not yet keep it. So the two were brought together. No published version of the App has ever behaved the way that sentence described, because that revision of this page was live for two days and no release accompanied it — which is why this is a correction to a plan and not to a practice.
One compressed record per account, replaced each time it changes. It contains:
And, held separately as running totals rather than as a history:
And two dates, which are not totals and are not a count of anything:
These are excluded by design, not by omission, and the exclusions are enforced in our code rather than left to policy:
Both the progress record and the usage totals are held to perform our contract with you (UK/EU GDPR Art 6(1)(b)). The account exists so that your progress is not tied to one handset, and the totals are your own numbers — your streak, your lessons, your bests, the ones the App already shows you — carried to the next device along with everything else. They are not analytics and we do not treat them as analytics: they are never joined to the anonymous usage events in Section 4.3, there is no field in either place that could join them, and we check our own source code at release time for the absence of one.
One secondary use, and it is the only thing here resting on legitimate interests. We read those totals in aggregate — grouped across everyone, never person by person — to decide what to build next and to understand what the AI features cost us to run. That rests on our legitimate interests (Art 6(1)(f)) in improving and pricing the Services, weighed against the fact that an aggregate cannot single you out. You can object at [email protected]. Objecting does not switch off the sync itself — the control for that is Settings → Account → Sync progress.
All of this is attached to your account, which is what makes it personal data rather than a statistic, and you can ask us for every one of these values at any time.
We do not sell it, we do not share it, we do not advertise against it, and we do not use it to build a profile of you as a person. It is not used to train any AI model, ours or anyone else’s.
Signing in is what turns this on. The App requires an account, but the progress sync can be switched off in Settings → Account → Sync progress, which stops future uploads and deletes the copy we hold. Your progress then lives on your device and in your platform’s own backup, exactly as described in Section 5.
The limited information we collect is used for the following purposes only:
We do not use your information for advertising, profiling, automated decision-making producing legal or similarly significant effects, or to train external machine-learning models.
If you are in the European Economic Area, United Kingdom, Switzerland, or any region with similar law, we rely on these legal bases under Article 6 GDPR (or its local equivalent):
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
We do not sell or rent personal information. We do not share information with advertisers. We share information only with the parties below, and only as needed to operate the Services or comply with law:
The Services rely on the third parties below. We disclose them so you can review their practices independently:
We integrate no third-party advertising SDKs, third-party analytics SDKs, marketing pixels, or session-replay tools inside the App on either platform. The only usage data collected by us is the first-party, anonymous event stream described in Section 4.3, which goes to servers we operate and is shared with nobody.
The Site is a static website that does not set marketing or analytics cookies. Your browser may use functional storage (e.g. cache) as part of normal operation. The App does not use web cookies for its own purposes because it is a native mobile application; the in-app browser used by the optional image search is a standard system browser component and is subject to that browser's and Google's own cookie practices.
Our hosting provider may set short-lived security cookies (e.g. to mitigate denial-of-service attacks). These are strictly necessary and exempt from consent under the ePrivacy framework.
Article 13(2)(a) GDPR requires us to tell you the period for which each kind of personal data is stored, or the criteria used to decide it. Here are all seven, with the actual periods rather than “as long as necessary”:
Backups. So that we can recover from a failure or a mistake, the account database is backed up three ways: Cloudflare’s own rolling 30-day point-in-time history of the live database, a daily export we keep for 35 days, and one copy on a company computer deleted after 40 days. Data you have deleted may still exist inside those windows. It is never restored back into the live service, and it ages out on its own within 40 days at the outside. The 7-day grace period in line 2 sits inside all three, so that by the time a deletion is final the oldest recoverable copy is already expiring.
Product-analytics events — the one thing with no period, and the argument for it. The raw event archive is append-only by design: written once, never modified, never deleted. Summaries are lossy, and a question nobody thought to ask on day one is unanswerable if only summaries were kept. These events carry no name, no email address, no account identifier, no IP address, no location and no device identifier — only the random install identifier in Section 4.3, which we do not join to anything and which the App never displays, so we hold nothing that could locate a person inside the archive. On that basis we treat the archive as anonymous rather than as personal data and apply no deletion schedule.
The previous version of this Policy also leaned on the claim that the identifier is replaced on every reinstall. That claim was wrong on Android and we have withdrawn it, so it is worth saying that this argument does not depend on it. The identifier persisting across a reinstall makes the archive slightly better at counting returning installs; it does not make the archive identify anybody, because there is still nothing in it, and nothing we hold elsewhere, that maps an identifier to a person. If you would rather these events did not exist at all, turn off Settings → Share Usage Data, which stops collection immediately and discards whatever is still queued on your device.
We use technical and organisational measures appropriate to the nature of the data we process. These include:
No method of transmission or storage is 100% secure. We cannot guarantee absolute security. If we discover a breach affecting personal information we will notify you and any regulator as required by law.
Lengio operates internationally and is established in the United States. When you contact us by email, when you use the AI Chat Coach, when you create an account, and when our service providers process server logs, your information may be transferred to and processed in the United States and in other countries outside your country of residence, including jurisdictions that may not provide the same level of data-protection law as your own.
To be specific rather than general about the account: the account database is in the United States (Cloudflare's Eastern North America region) and the sign-in emails are sent from the United States (Zoho's US data centre). We considered pinning the database to the EU and decided against it, because your email address — the primary identifier — passes through the US mail provider on every sign-in regardless, so an EU-pinned database would have split the data across two jurisdictions rather than keeping it in one. The GDPR imposes no residency requirement; it imposes the safeguards below, which apply either way. We would rather tell you the real reason than present a split as a protection.
Where required, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and adequacy decisions. A copy of the safeguards used is available on request from [email protected].
Subject to local law, you may have the following rights regarding your personal information. Because most data stays on your device, you can exercise many of these yourself directly inside the App.
If you have an account, every right above applies to it in full and most of them are self-service: your email address, name and languages are visible and editable in Settings → Account; “sign out all devices” revokes every session; and Delete Account is in the same place. Ask us at [email protected] for a machine-readable export of your account record and we will send it. Deletion is described in Section 15.
A note on usage analytics — restated, because the previous version's reasoning contained a claim we have since withdrawn. The events described in Section 4.3 are keyed only to a random install identifier. We do not join it to your email address, your account, your purchases, your device, or your Apple or Google account, nothing in the archive carries any of those, and the App does not display the identifier, so you cannot tell us which one is yours and we cannot work it out. We therefore cannot locate "your" events in order to export or delete them, and Article 11 GDPR does not oblige us to start collecting additional information about you for the sole purpose of being able to.
That argument used to be supported by a second claim — that a reinstall always produces a fresh identifier — which was wrong on Android (Section 4.3). We have withdrawn it, and it is worth being explicit that the argument does not need it: an identifier that survives a reinstall is still an identifier that points at nothing we hold. If you disagree with that reasoning, tell us at [email protected] and we will engage with it rather than restate it. And if you would rather these events were not collected at all, turn off Settings → Share Usage Data. Every other right in this section applies in full to information that does identify you — your account, your purchases, and your support email.
To make a request, email [email protected] with the subject line "Privacy Request". We may need to verify your identity (for example, by replying from the email address on your account, or the one you used when contacting us) before responding. We will respond within the statutory time frame applicable to you (typically 30 days, extendable as permitted by law).
There are two separate things you may want to delete, and they are not the same thing. The full, standalone instructions — including the route for someone who no longer has the App installed — are at lengio.app/delete-account, which requires no sign-in to read or to act on. In short:
Your words, streaks, statistics, saved content and settings live on your device, and — while you are signed in and have not turned the sync off — a copy of most of them also lives on our server (Section 5A). Settings → Erase All My Progress clears both: it erases what is on the device — including every AI Chat Coach conversation, in every language — withdraws your permission for the AI Chat Coach so that you are asked again before anything is sent, and deletes the server copy, in a way a second device cannot undo by re-uploading its own. Uninstalling does not. Removing the App takes its data off that device and leaves the server copy exactly where it is, so if getting rid of the server copy is what you want, use Erase All My Progress or delete the account before you uninstall — or email us and we will do it. If your device backs up to iCloud or to your Google account, a copy may also remain in that backup until you remove it there — and on Android, the anonymous install identifier is one of the things that comes back from it (Section 4.3).
In the App: Settings → Account → Delete Account. Without the App: email [email protected] with the subject "Delete my Lengio account", preferably from the address on the account, which is how we confirm the request is yours. We ask for nothing else — no password, no payment detail, no identity document.
Either way: you are signed out immediately and the account can no longer sign in anywhere; there is a 7-day grace period in which signing in again cancels the deletion; and after that it is executed and cannot be reversed. We email you when it is requested and again when it is executed. Requests made by email are acknowledged within 5 business days and completed within 30 days, usually the same day.
What is erased: your email address and any Apple relay address, your name, your languages, interface language and time zone, every linked sign-in identity, the Apple refresh token — used first to tell Apple to revoke the link, so Lengio stops appearing in your Apple Account settings — every session on every device, and any unused sign-in codes.
What survives, and why: the purchase and subscription records in line 4 of Section 11, for the seven years tax and consumer-protection law require, carrying no name and no email address once the account is gone; and a line in the security log recording that an account with a given internal identifier was deleted and when, which by construction contains no personal data at all. Data already deleted may persist in the 30-day recovery history described in Section 11 and is never restored into the live service.
Deleting your account does not cancel a paid subscription, and we cannot cancel one for you — only Apple or Google can. If you are subscribed, cancel there first: iPhone, Settings → your name → Subscriptions; Android, Play Store → Payments & subscriptions → Subscriptions. Deleting the account may also make a past purchase harder to restore, because the identifier in Section 4.2 is how a purchase is recognised as yours on a new device.
If you are a California resident, the California Consumer Privacy Act (as amended by the California Privacy Rights Act) gives you specific rights. The categories of personal information we collect are: identifiers (your email address when you contact us or create an account; your first name; the random purchase identifier in Section 4.2), internet or other network activity (server logs, and the anonymous in-app usage events in Section 4.3), commercial information (purchase and subscription records from Apple and Google), and other information you choose to provide (the Interests text, and anything you write to support). We do not collect sensitive personal information as CPRA defines it — no precise or coarse geolocation, no government identifiers, no log-in credentials (there are none; see Section 4.6), and no biometric information (see Section 17). One item on that statutory list deserves a straight answer rather than a denial: the contents of your communications. Your Chat Coach messages do pass through a server we operate on the way to the AI provider, so we do receive them. We are the intended recipient of a message you address to our own tutor, which is the exception the statute itself draws — and we hold none of it: the text is handled in memory, never written to disk, and never stored against your account (Section 5A keeps a count and nothing else). We do not use or disclose it for any purpose that would require us to offer a “Limit the Use of My Sensitive Personal Information” link. We retain each category for the periods in Section 11.
We have not sold or shared personal information for cross-context behavioural advertising in the past 12 months and have no intention to do so. We do not use or disclose sensitive personal information for purposes that would require us to offer a "Limit the Use of My Sensitive Personal Information" link.
You may exercise California rights — to know, delete, correct, opt out of sale/share, and not be retaliated against — by emailing [email protected]. An authorised agent may make a request on your behalf with written authorisation.
Shine the Light. California Civil Code § 1798.83 permits California residents to request information about disclosure of certain categories of personal information to third parties for direct-marketing purposes. We do not disclose information for such purposes.
The legal bases on which we process personal information are described in Section 7. You have the GDPR rights described in Section 14. You also have the right to lodge a complaint with your local supervisory authority.
Brazilian users have rights equivalent to those described in Section 14 under Lei Geral de Proteção de Dados. Email [email protected] to exercise them.
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Iowa (ICDPA), Tennessee (TIPA), Indiana (INCDPA), New Jersey (NJDPA), Delaware (DPDPA), New Hampshire (NHDPA), and other states with consumer-privacy laws have rights of access, deletion, correction, portability, and opt-out of targeted advertising or sale. We do not engage in targeted advertising or the sale of personal information. To exercise other rights, email [email protected].
Where local law gives you additional rights — for example the Australian Privacy Principles or Canadian PIPEDA — we will honour them. Contact us for specifics.
Because the App has a speech feature and because we are established in Illinois, we state this as plainly as we can:
We do not collect, capture, purchase, receive through trade, store, use, disclose, redisclose, disseminate, sell, lease, trade, or otherwise profit from any biometric identifier or biometric information — including any voiceprint, retina or iris scan, fingerprint, hand geometry, or scan of face geometry — as those terms are defined by the Illinois Biometric Information Privacy Act (740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act, the Washington biometric privacy statute, or any comparable law.
Specifically: the AI Chat Coach uses your device's speech-to-text service to obtain a transcript. It does not create, derive, or store a voiceprint or any biometric template, and it does not identify or attempt to identify you from your voice. We never receive the audio itself on either platform (see Section 4.4). Any audio buffer used by the operating system's recognition service is handled by Apple or Google under their own policies and is not retained by us. Nothing in the App performs facial recognition on photos you attach to vocabulary cards; those photos are never transmitted to us at all.
What would change this. Two things would, and neither is in the App today: scoring how closely your pronunciation matches a native speaker’s in a way that models your voice rather than the words you said, and sending audio to a server instead of a transcript. If we ever build either, the paragraph above stops being true. Before shipping it we would obtain the written release the Illinois Biometric Information Privacy Act requires, publish the retention and destruction schedule it requires, and date the change on this page — in that order, before the feature exists rather than after. We are writing the tripwire down so that it is harder for us to cross it quietly.
The Services are not directed to children under the age of 13 (or the equivalent minimum age in your jurisdiction — 14 in Spain, 15 in the Czech Republic and France, 16 in Germany and the Netherlands, and similar national variants under GDPR Article 8). We do not knowingly collect personal information from children below those ages, and the App is not listed in a children's or family programme on either store.
We ask how old you are, and we keep as little of the answer as we can. The first time you open the AI Chat Coach the App asks for your year of birth, once; it is not asked when the App opens. On iPhones and iPads new enough to offer it, the App asks the system for an age range instead, so that you are not asked at all and we never see a date. Either way we store a single coarse band — below the minimum, under 18, or 18 and over — and never a birthday. That band decides exactly two things: whether you may keep using the App on that device, and whether the AI Chat Coach opens. It personalises nothing, it is never sent to the AI provider, it is not in the account record in Section 4.6, it never appears in the usage events in Section 4.3, and we check our own source code at release time to keep it that way.
The AI Chat Coach is available from the same minimum age as the rest of Lengio. An earlier revision of this Policy gave the coach a higher minimum of its own; the App now uses a single minimum. The App still asks for your agreement, on the device, before the coach will open and before anything you type is sent.
If the answer is below the minimum for your country, you are signed out on that device and the App says so plainly rather than failing quietly; the account is not deleted, and can be deleted from Settings › Account or by email. We have deliberately not built a parental-consent route, because operating one properly is beyond what we can promise to do well.
Lengio carries an age rating on the App Store and a content rating on Google Play appropriate to general audiences, and contains no objectionable content, but parents are responsible for supervising their child's use — in particular of the AI Chat Coach, which generates its replies automatically and is not moderated by a human, and of the in-app image search, whose results come from Google rather than from us. If you believe a child has provided us with personal information, please email [email protected] and we will delete it promptly.
A note on what other apps reserve for children. Large services in this category publish a separate, better regime for their youngest users — non-personalised advertising, third-party behavioural tracking switched off, third-party analytics switched off. We mention it because we have nothing to switch off. There is no advertising in Lengio at any age, no advertising identifier on either platform, no third-party analytics or advertising SDK anywhere in the App, and no profiling of anyone. The protections other companies grant to a minority of their users are the only settings we have.
Lengio lets you attach personal photos to vocabulary entries. These photos remain on your device. We have no access to them and they are not transmitted to our servers. If you choose to share screenshots with our support team, the images become part of your support correspondence and are governed by this Policy.
We strongly discourage including sensitive personal information (e.g. images of identification documents, payment cards, health records) in support correspondence, or speaking or typing it into the AI Chat Coach. If you do send it to support, we will treat it confidentially and delete it once your inquiry is resolved.
The App may send local notifications (e.g. daily study reminders). These are scheduled and delivered entirely on your device by the operating system based on settings you control. We do not see when notifications are delivered or opened. You may disable notifications at any time — on iOS in Settings → Notifications → Lengio, and on Android in Settings → Apps → Lengio → Notifications.
Email from us. We do not send marketing emails, run no mailing list, and there is nothing to unsubscribe from. We will reply to support correspondence you initiate, and may send transactional emails strictly necessary to resolve an inquiry. If you create an account we will also send the account emails listed in Section 4.6 — a sign-in code when you ask for one, a notice when account deletion is requested and again when it is executed, and, only if you switch it on, a notice when your account signs in on a new device. Those cannot be turned off individually while you have an account, because each of them is either something you asked for or something you need to see, but deleting the account ends them all.
Because neither the Site nor the App tracks you across other companies' apps or websites, Do-Not-Track signals (DNT) and Global Privacy Control (GPC) have no behavioural effect. We honour these signals where they are legally required by treating them as a valid opt-out of any future sale or share of personal information.
The equivalent control for the App's own anonymous usage events is the Share Usage Data switch described in Section 4.3.
Apple requires app developers to publish "App Privacy" labels on the App Store, and Google requires a "Data safety" section on Google Play. Those summaries are generated to each store's own categories and format, which are coarser than this Policy.
We maintain both to be consistent with this Policy. Where a store summary and this Policy appear to differ, the difference is a matter of the store's categories rather than of our practice, and this Policy is the authoritative and more detailed description. If you spot an inconsistency you believe is substantive, please tell us at [email protected] and we will correct whichever is wrong.
We may update this Policy from time to time to reflect changes to our practices, technology, legal requirements, or for other operational reasons. The "Last updated" date at the top of the page indicates the most recent revision.
For material changes that affect your rights, we will provide additional notice — for example, an in-app message, a prominent notice on this page, or an email to known support contacts — before the change takes effect. Continued use of the Services after the effective date constitutes acceptance of the revised Policy.
For any privacy question, request, or complaint, please contact us:
We aim to acknowledge requests within 5 business days and resolve them within 30 days, or sooner where required by law. If you are not satisfied with our response, you may contact your local data-protection supervisory authority.
Disclaimer. This Policy is provided in good faith and reflects our practices as of the effective date above. It is not legal advice. Where translation conflicts with the English original, the English version controls. If a provision is held unenforceable, the remaining provisions remain in full effect.