Privacy Policy

Effective: September 17, 2026  ·  Last updated: September 20, 2026  ·  Previous version: September 17, 2026

At a glance. Lengio is built privacy-first, and two things changed with this revision. An account is now required to use the App, and the App is gaining a copy of your study progress on a server we operate, so that it will survive a lost phone and follow you to a new one. The App both reads and writes that copy from this release onwards; Section 5A dates the change and says what makes it up. Your photos and your AI Chat Coach conversations are not part of that copy and never leave your device. We run no advertising SDKs, sell no data, and do not track you across other companies' apps and websites. Section 5A says exactly what is in the server copy, what is kept out of it, and how to switch it off.

The App does record anonymous usage events — which screens you open, which lessons you finish — so we can see what is worth building next. They carry no name, no email, no advertising identifier, no IP address and no location, and you can switch them off in Settings. Optional AI features run on our servers only when you choose to use them.

Four things we want to be precise about rather than flattering, because each of them is a place where the simple version of this sentence would be wrong:

  • Your voice. On iPhone, speech is turned into text on the device and the audio never leaves it. On Android, whether that happens on the device or on Google's servers depends on your device, your keyboard and speech settings, and whether an offline language model is installed — so on Android we cannot promise the audio stays local. Section 4.4 gives both cases exactly.
  • Your interests. If you fill in the free-text Interests field in Settings, that text is sent to our AI provider with every Chat Coach message, to steer the conversation toward topics you like. It is the one thing you type that leaves the device by design. Section 4.4.
  • Your purchases. When you buy Lengio Plus, the App attaches a random identifier of its own to the transaction, so that a purchase can be reunited with its owner on a new phone. It goes to Apple or Google, it is deliberately not cleared by “Erase All My Progress”, and on Android it deliberately survives an uninstall. Section 4.2 explains why.
  • The anonymous install identifier. We used to say a reinstall always produces a fresh one. On Android that is not true — Google's Auto Backup restores it. Section 4.3 now says so, and Section 11 re-states the retention argument that depended on it.

1. Overview & Scope#

This Privacy Policy ("Policy") describes how Lengio ("Lengio", "we", "us", or "our") processes information when you use the Lengio mobile application for iOS and Android (the "App") or visit the Lengio website at lengio.app (the "Site"), collectively the "Services".

This Policy applies to all users of the Services worldwide, with additional disclosures for residents of specific regions (see Region-Specific Disclosures). Where the App behaves differently on iOS and on Android, this Policy says so explicitly rather than describing only the more favourable case. It does not apply to third-party services you reach through links inside the Services — those are governed by their own privacy policies.

By using the Services you confirm you have read and understood this Policy. If you do not agree, please do not use the Services.

2. Who We Are (Data Controller)#

The Services are operated by Nexios Media LLC, a limited liability company organised under the laws of the State of Illinois, United States, trading as "Lengio" (nexios-media.com).

Nexios Media LLC maintains a registered agent in Illinois as required by state law, through whom formal service of process may be made. For every other purpose — including notices under this document, privacy requests, and support — please use [email protected], which we monitor and which is the fastest way to reach a person.

For the purposes of the EU/UK General Data Protection Regulation, similar laws, and CCPA/CPRA, that company is the data controller (or "business") responsible for the limited information we process. You can reach us at [email protected] for any privacy-related question, request, or complaint.

We have not appointed a statutory data protection officer because the nature and scale of our processing does not require one, but the contact above is monitored by a person with responsibility for privacy matters.

3. Key Definitions#

  • Personal information — any information that identifies, relates to, describes, or could reasonably be linked with an identified or identifiable person.
  • Processing — any operation performed on personal information, including collection, storage, use, disclosure, and deletion.
  • On-device data — information that is created, stored, and used only on your device's local storage and never transmitted to our servers.
  • Service providers / sub-processors — companies that process information on our behalf under contract (e.g. our website host).
  • Platform — Apple's iOS or Google's Android, and the associated store, operating-system services, and account you use with them.
  • Lengio account — the record described in Section 4.6, holding an email address (or an Apple private-relay address), your first name, your chosen languages, and whether you have a paid subscription. It is required to use the App, and it has no password. The study progress kept against it is a separate record, described in Section 5A.

4. Information We Collect#

We have intentionally designed Lengio to collect as little personal information as possible. The categories below describe everything we receive.

4.1 Information you provide directly

  • Support correspondence — if you email [email protected], we receive your email address, message content, and any attachments you choose to send (e.g. screenshots, device model). Used only to respond and improve the App.
  • Feedback — opinions, feature suggestions, or bug reports you voluntarily share.

4.2 Information collected automatically (limited)

  • Server log data (Site & content downloads) — when you visit lengio.app, or when the App downloads content such as a language pack, audio, images, or a conversation video, our hosting/CDN providers receive standard request data: IP address, user-agent string, requested URL, HTTP status, and timestamp. We use this only for delivery, security, and aggregate traffic statistics.
  • Crash diagnostics on iOS (only if you opted in with Apple) — if you have enabled Share with App Developers under Settings → Privacy & Security → Analytics & Improvements on your iOS device, Apple may share de-identified crash reports with us. You can disable this at any time in iOS Settings.
  • Crash and performance data on Android — Google provides us with aggregated crash and "Android Vitals" stability data through the Google Play Console. This comes from Google's own platform reporting; there is no crash-reporting or analytics SDK inside the App. The data we see is aggregated and de-identified — stack traces, device models, Android versions and counts — and is not presented to us in a form that identifies you.
  • Transaction confirmations — when you make an in-app purchase, Apple (App Store) or Google (Google Play) confirms the purchase to the App so we can unlock content. We do not receive your name, payment card details, or billing address from either.

The purchase identifier — stated plainly, because it is the one identifier that persists. The App generates a random identifier of its own the first time you buy something, and attaches it to the transaction: to Apple as appAccountToken, and to Google as obfuscatedAccountId. It is a random UUID. It is not derived from you, your device, your Apple Account, your Google Account, your email address, or your payment details, and on its own it identifies nobody — but it is stable, and it is the only durable thing the App creates that leaves your device.

Why it exists: without it, a purchase and a person cannot be reunited. Neither store lets it be added to a transaction after the fact, so if it is missing at the moment of purchase it is missing forever, and a subscriber who changes phone or loses a device has no way to prove the purchase was theirs. That is the problem it solves, and it is the only thing we use it for.

Three consequences we would rather state than have you discover:

  • It is deliberately excluded from Settings → Erase All My Progress. That control erases your learning data; erasing this identifier as well would silently orphan a purchase you paid for, and that cannot be repaired.
  • On Android it is deliberately included in Google's backup, so that it survives an uninstall and a move to a new phone. On iPhone it is likewise stored so that it travels with your iCloud Keychain. This is the opposite of what we do with sign-in tokens (Section 4.6), which are excluded from backup on purpose.
  • It reaches Apple or Google as part of the transaction, and — if you create a Lengio account — our own server, where it is the link between your subscription and your account. It is not shared with anyone else, and it never appears in the usage events in Section 4.3.

If you want it gone, the only way is to remove the App and, on Android, to delete Lengio's data from your Google backup. We will also delete our copy on request, on the understanding described in Section 15 — that doing so may make a past purchase unrecoverable.

Which versions. This identifier is introduced in the release of the App that accompanies this revision of the Policy, alongside the account in Section 4.6. Purchases made with earlier versions carry no such identifier and cannot be given one retrospectively — neither store permits it — which is the reason it is being introduced now rather than later.

4.3 Product analytics (the App)

The App records a small number of anonymous usage events so we can see which features are worth building and where people get stuck. This is our own pipeline, running on servers we operate. There is no third-party analytics SDK, no advertising SDK, and no advertising identifier anywhere in the App on either platform.

Each stored event contains only:

  • A random install identifier — a UUID generated on first launch and kept in the App's own storage. It is not Apple's advertising identifier (IDFA), not Apple's vendor identifier, not the Android Advertising ID (AAID), not the Android ID, and is not derived from anything about you or your hardware. It is not shared with any other app and is never sent to Apple, Google, or any other company. See the correction immediately below on what a reinstall does to it.
  • A session identifier, the event name, and the time.
  • App version and build, operating system and version, and device model (for example iPhone16,1 or Pixel 8 — the same string for millions of devices).
  • Your device locale, the App's display language, and the language you are studying.
  • Whether your plan is free or paid, and how many days ago the App was installed.
  • A small set of properties specific to the event — which screen was opened, how long a lesson took, which paywall was shown.

Event names are things like app_open, lesson_complete, paywall_view and purchase_success. We do not record the words you study, anything you type, anything you say, your photos, or the content of AI conversations.

A correction, September 2026 — what a reinstall actually does. Until this revision, this section said that deleting and reinstalling the App always produces a new install identifier and that we have no way to connect the two. On iPhone that holds for an ordinary delete-and-reinstall, though restoring a whole device from an iCloud backup does carry the old identifier across. On Android it was simply wrong. The identifier is held in the App's preferences, and Google's Auto Backup includes those preferences, so reinstalling Lengio — or setting up a new Android phone from your old one — restores the identifier you already had rather than minting a fresh one. We had not noticed; we are correcting it rather than leaving a comfortable sentence standing. The practical effect is that on Android a returning install may be counted as the same install, which is a slightly better statistic and a slightly weaker privacy claim than we were making. Nothing else about these events changed, and the switch in the next paragraph still stops them completely. We are keeping the current behaviour — turning it off would put the identifier outside your control of your own backup — and we have restated the retention argument in Section 11 so that it no longer rests on the sentence we have just withdrawn.

Being an identifier that can persist across a reinstall is, for what it is worth, the ordinary condition of anything inside your own device backup. We accept the accuracy cost of not adding anything else to these events, which is why there is nothing here to correlate the identifier against.

Your IP address is not stored. Our servers necessarily receive it in order to answer the request, as every web server does, but it is never written to the analytics archive. We do not record your country, region, or any other location. We removed the country field in July 2026 specifically so that this sentence would be true.

You can turn this off. Open the App → Settings → Share Usage Data. Switching it off stops collection immediately and discards anything still waiting to be sent from your device. Every feature behaves identically either way — nothing is withheld from you for opting out.

4.4 AI Chat Coach (optional feature) — and what happens to your voice

If you choose to use the AI Chat Coach (described on our website as the AI Speech Partner), the App captures audio from your microphone only while the feature is active and converts it to text. What happens to that audio depends on your platform, and we describe both cases exactly.

Before any of it is sent, we ask — inside the App. The first time you open the AI Chat Coach, the App tells you plainly what will be sent to Google to generate the reply — the messages you type or speak to the coach, your Interests text if you have filled it in, and your level and the vocabulary you are practising — and asks you to agree. If you decline, the Chat Coach does not open and nothing is sent; every other part of the App works exactly as it did. The check is made where the request is built, not on the screen, so there is no path into the AI that goes around it. You can withdraw at any time from inside the chat — the AI notice at the top, then Stop sharing — and that stops the very next request. It cannot recall what has already been sent, and we say so rather than implying otherwise. We ask inside the App rather than relying on your having found this page, because a policy is a description and a description is not a consent.

What is never sent on this path: your name, your email address, your account identifier, your age answer, and any identifier for your device. The coach does not know who you are.

You are told it is an AI, and you can report it. A permanent notice above the conversation says you are chatting with an AI and that it can be wrong. Every reply the AI generates carries a control that reports it to us without leaving the App; the report opens an email to [email protected] that you read and send yourself, so you see exactly what is going before it goes, and it reaches a mailbox a person reads rather than a counter.

If a conversation turns to self-harm. The App watches, on your device, for a message that expresses an intention to harm yourself. When it sees one it does not send it: the message does not reach Google, it is not written into the conversation, and it is not logged or counted anywhere. Instead the App shows emergency numbers and a link to an international helpline directory. We would rather this feature were never useful. It runs on the device because a rule we ask a language model to follow is a request, and this had to be something that holds when the model does not.

  • On iOS. Speech is converted to text on your device using Apple's on-device speech recognition. The audio never leaves your iPhone or iPad — not to us, not to Apple's servers, not to anyone.
  • On Android. Speech recognition is performed by the recognition service provided by your device. Depending on your device model, Android version, installed language packs, and your own speech settings, this may run entirely on your device, or Google's speech service may process the audio on Google's servers under Google's privacy policy. We do not control which of the two occurs and cannot promise the audio stays on your Android device. Many Android devices allow on-device recognition to be forced by downloading an offline language model in the system speech settings.

In neither case do we receive or store your audio. Lengio's servers receive only the resulting text.

  • Only the resulting text is sent, through a server we operate, to our AI provider so it can generate the tutor's reply, which is streamed back to your device.
  • Your device never contacts the AI provider directly. Requests pass through our own server, so no device identifier, IP-derived location, or install identifier reaches the provider.
  • Text is processed in memory and is not stored on our servers or used to train any model.
  • Conversation text may be retained by the AI provider for a limited period, solely to detect abuse of its API and to meet its legal obligations, and is then deleted. It is not retained for quality review and no human reviewer reads it.
  • Alongside your message, the App sends the language you are studying, your level, a short list of words the lesson is working on — and the Interests text described immediately below.
  • You can revoke microphone access at any time — on iOS in Settings → Privacy & Security → Microphone → Lengio; on Android in Settings → Apps → Lengio → Permissions → Microphone. Without microphone access the AI Chat Coach cannot listen to you, but the rest of the App continues to work.

The Interests field. Settings → Profile contains a free-text box labelled Interests, where you can list hobbies or topics you enjoy. If you fill it in, that text is sent to the AI provider with every Chat Coach message, including the coach's opening line, so the conversation can steer toward things you actually care about. It is truncated to a few hundred characters and it is sent exactly as you typed it. Nothing else in Settings is transmitted this way. If you would rather it were not sent, clear the box: an empty field is omitted entirely, and the feature works without it.

The App also used to send the name you entered during setup in the same place, so the coach could greet you by it. We removed it. A first name is personal data with no teaching value the coach cannot get another way, and it should not have been going to a third party to produce a nicety. The code that sent it was deleted from both apps on 11 September 2026; every release published after that date omits it, and if you are running an older release it is still being sent until you update. The name is still used for greetings inside the App, where it never leaves your device. We are recording the change here rather than silently benefiting from it.

Please do not speak or type personal, confidential, financial, health, or otherwise sensitive information about yourself or anyone else into the AI Chat Coach — and in particular, please do not put anything in the Interests box that you would not want sent to an AI provider with every message.

4.5 Image search (optional feature)

You can replace the picture on any vocabulary card. Tapping the picture offers Choose Photo, which uses your own photo library and sends nothing anywhere, and Search Images, which opens Google Image Search inside an in-app browser.

If you use Search Images, your search term — the word you are studying — goes to Google directly, along with your IP address, under Google's own privacy policy. We do not see the search or the results, and the image you pick is saved only on your device. The in-app browser is restricted to Google's own image-search pages — it will not follow a link off them — and SafeSearch is forced on and cannot be turned off from inside Lengio.

4.6 Your Lengio account — required, and what it holds

An account is required to use the App, and we are reversing what we told you before. The previous version of this Policy said the account was optional and that nothing in the App required one. The reason for the change is that a learner who loses a phone should not lose years of study with it, and that only works if the progress in Section 5A has an account to belong to. There is no charge for it, nothing is withheld from you for having one, and you can delete it at any time (Section 15). What you cannot do is use the App without one.

Which phones this applies to. Accounts arrive on iPhone, iPad and Android together, with the releases of the App that accompany this revision. The 15 September revision of this page said the Android app would follow later; it no longer does, and we would rather record that the plan changed than let the sentence quietly become true of nothing. Everything in Section 5A applies to all three from those releases onward.

There is no password. You sign in either with Apple or Google, or by typing an email address and entering a six-digit code we send to it. We hold no password, so there is no password to lose, reset, or breach.

If you create one, this is everything the account record contains:

  • An email address — the one you typed, or, if you used Sign in with Apple and chose Hide My Email, Apple's private relay address. We record which of the two it is. A relay address is the only address we will ever hold for you in that case; we cannot see the real one.
  • Your first name, as you typed it at setup — used to address you in the App and in an email from us, and nowhere else.
  • Which languages you study and your native language, your interface language, and your time zone. The time zone is stored because a streak has to know when your day ends, and a fixed offset cannot survive daylight saving.
  • The sign-in identities linked to the account — the opaque subject identifier Apple or Google gives us, the name Apple hands over once at first sign-in and never again, and, for Apple, an encrypted refresh token, which exists so that deleting your account can also tell Apple to revoke the link rather than leaving Lengio listed in your Apple Account settings forever.
  • Sign-in codes, stored hashed rather than in the clear, and valid for ten minutes.
  • Session tokens for the devices you are signed in on, with a label so that “sign out all devices” means something to you.
  • Your subscription status — which product, which store, which dates, the store's own transaction identifier, the purchase identifier from Section 4.2, and the renewal, expiry and refund notices Apple or Google send us about it.

What the account record itself does not contain. It holds no photos, no Chat Coach conversations and no audio. Those stay on your device exactly as described in Section 5. It does not hold your study progress either — that is kept as a separate record, in the same database and against the same account, and Section 5A describes it in full.

And a sentence we are withdrawing. The previous version of this Policy said that creating an account did not upload your learning data to us, that we were not building a sync service, and that if we ever did it would be described here before it existed. We have built one. This page is that description, published before the release of the App that uses it — which is the part of that promise we are keeping.

Where it lives. In a small database we operate on Cloudflare’s infrastructure in the United States, and nowhere else apart from the backups described in Section 5A and Section 11. The sign-in emails are delivered by Zoho's ZeptoMail, also in the United States. Both are listed in Section 9 and covered by Section 13.

On your device, the sign-in tokens are held in the iOS Keychain or the Android Keystore, are readable only after you have unlocked the device at least once since it booted, and are deliberately excluded from iCloud and Google backup and from phone-to-phone transfer — a session copied onto a second device is a second person signed in as you, with no way for you to see it or stop it. This is the exact opposite of how the purchase identifier is treated, and the difference is intentional.

Emails we will send you. A sign-in code when you ask for one; a notice when you request account deletion and again when it is executed; and, if you switch it on, a notice when your account is used to sign in on a new device. That is the complete list. We do not send marketing email and there is nothing to unsubscribe from.

Deleting the account is described in Section 15 and at lengio.app/delete-account.

4.7 Information we do not collect

  • Advertising identifiers — Apple's IDFA, the Android Advertising ID (AAID), or any other cross-app tracking signal.
  • Contacts, calendar entries, health data, financial data, biometric data, or location of any kind — including country or region derived from your IP address.
  • Camera images other than photos you explicitly choose from your photo library.
  • Microphone audio outside of an active AI Chat Coach session — and even then, we never receive the audio itself on either platform.
  • Behavioural analytics for advertising or user profiling, and any third-party analytics SDK. The usage events in Section 4.3 go only to servers we operate.
  • Inferences about your demographics, interests, or political views.

5. Information Stored Locally on Your Device#

The following information lives on your device only and is never transmitted to us. Operating-system encryption and application sandboxing apply on both iOS and Android.

This section changed on 15 September 2026. Before that date, your study progress was on this list. It is described in Section 5A instead, and moves to your Lengio account on the schedule set out there. Nothing you had already stored on your device was uploaded retroactively: the sync begins with the App version that introduces it, and only for an account you have signed in to.

  • Personal photos you attach to vocabulary entries (selected from your photo library; see Sensitive Information). Photos are never uploaded to us — not in the progress sync described in Section 5A, and not anywhere else.
  • Your AI Chat Coach conversations. The messages you type and the replies you receive are stored on your device and are not kept on any server we operate. What reaches us is a count of how many messages you sent, never what they said — see Section 5A.
  • Your individual review history — the record of each single answer, with its date and your rating. Only the resulting schedule is synced, not the answer-by-answer log.
  • Cached language-pack content you have downloaded.
  • Microphone audio, in every case. See Section 4.

Platform backup. Separately from the account sync in Section 5A, your device may back itself up to your own account with Apple or Google. That backup belongs to them, not to us:

  • iOS — if iCloud Backup is enabled at the operating-system level, Lengio's data may be included in your encrypted iCloud backup managed by Apple. Older versions of the App also synced a small set of values — streak, daily-goal progress, lesson completions, bookmarks, and game records — through Apple's iCloud key-value store. That is being replaced by the account sync in Section 5A, which works across both platforms; during the changeover a device may still read what it previously wrote there.
  • Android — if Android Backup is enabled at the operating-system level, Lengio's data may be included in the backup that Android stores in your Google account.

Both stores belong to Apple and Google respectively and are tied to your account with them. We have no access to either, and neither is operated by us. Neither one moves your progress between iOS and Android — that is what the account sync in Section 5A is for.

Two items in those backups are handled deliberately rather than by default, and both are described above: the purchase identifier is kept inside them on purpose (Section 4.2), and account sign-in tokens are kept out of them on purpose (Section 4.6). On Android, the anonymous install identifier is inside them as a side-effect of where it is stored, which is the correction in Section 4.3.

5A. Your Study Progress and Your Lengio Account#

When you are signed in to a Lengio account, the App keeps a copy of your study progress on a server we operate, so that your progress survives losing your phone and follows you to a new one — and from iPhone to Android and back, which your platform’s own backup cannot do. The paragraph below says which release starts doing that.

Which release, and in which direction. We are describing this before it is switched on, which is the promise we made and the reason this page is dated ahead of the App. Your device both reads and writes that copy from the first release that accompanies this Policy — 17 September 2026, iOS and Android together. Erase All My Progress and account deletion reach the server from the same release, because asking for a copy to stop existing has to work the moment there is anything to erase.

We changed this plan before it shipped, and we are not quietly restating it. The 15 September revision of this page said the first release would read only, with uploads following in the release after. That staging was a caution about our own rollout, not a protection for you, and holding it would have meant shipping a version that required an account, told you your progress was kept for you, and did not yet keep it. So the two were brought together. No published version of the App has ever behaved the way that sentence described, because that revision of this page was live for two days and no release accompanied it — which is why this is a correction to a plan and not to a practice.

What is in it

One compressed record per account, replaced each time it changes. It contains:

  • Words you have studied, bookmarked, marked as known, or completed, and when.
  • Sentences you have bookmarked or marked as learned, and when. These are sentences from Lengio’s own lessons, recorded as an identifier rather than as text — never anything you typed yourself.
  • When you take a word or a sentence back off one of those lists, the removal is recorded too — the item’s identifier and the time you removed it. We keep that rather than simply dropping the item, because it is the only way your other devices can be told it was removed instead of quietly adding it back on the next sync.
  • The review schedule for each word — when it is next due and how well you know it.
  • Lessons and courses you have completed.
  • Your streak, daily goal, totals, achievements, and study statistics.
  • Your chosen learning and native languages, and your study settings.
  • Whether reminders are switched on, and the time of day you asked for them.
  • Which display options you have chosen, and whether you have finished setting the App up.

And, held separately as running totals rather than as a history:

  • How many AI Chat Coach messages you have sent — one running total, not a breakdown by language, by topic or by day. Never the messages themselves, never a summary of them, never a topic derived from them.
  • How many games and practice sessions you have completed.

And two dates, which are not totals and are not a count of anything:

  • The first day and the most recent day your account was active — two day numbers, to the day and not to the hour. This says when you have used Lengio, not how much you have done. We keep it so that we can tell an account that is still in use from one that has gone quiet.
  • Which kind of device last sent us these numbers — the platform the App was running on, never a device name, a model, or an identifier for the device itself.

What is deliberately not in it

These are excluded by design, not by omission, and the exclusions are enforced in our code rather than left to policy:

  • Photos you attach to words. They never leave your device.
  • AI Chat Coach conversations. No message text, no summary, no inferred topic. We hold the count and nothing else. Language practice can touch health, beliefs, relationships and other sensitive subjects, and the way to keep that private is not to collect it.
  • Your answer-by-answer review log. Only the resulting schedule is synced.
  • Anything you type into the app as free text.

Why we hold it, and on what legal basis

Both the progress record and the usage totals are held to perform our contract with you (UK/EU GDPR Art 6(1)(b)). The account exists so that your progress is not tied to one handset, and the totals are your own numbers — your streak, your lessons, your bests, the ones the App already shows you — carried to the next device along with everything else. They are not analytics and we do not treat them as analytics: they are never joined to the anonymous usage events in Section 4.3, there is no field in either place that could join them, and we check our own source code at release time for the absence of one.

One secondary use, and it is the only thing here resting on legitimate interests. We read those totals in aggregate — grouped across everyone, never person by person — to decide what to build next and to understand what the AI features cost us to run. That rests on our legitimate interests (Art 6(1)(f)) in improving and pricing the Services, weighed against the fact that an aggregate cannot single you out. You can object at [email protected]. Objecting does not switch off the sync itself — the control for that is Settings → Account → Sync progress.

All of this is attached to your account, which is what makes it personal data rather than a statistic, and you can ask us for every one of these values at any time.

We do not sell it, we do not share it, we do not advertise against it, and we do not use it to build a profile of you as a person. It is not used to train any AI model, ours or anyone else’s.

How long we keep it, and how to get rid of it

  • It is replaced, not accumulated — there is one current copy, not a history of every version.
  • Deleting your account deletes it, as part of the same deletion described in Section 15.
  • “Erase All My Progress” in the App erases the server copy too, and does so in a way a second device cannot undo by re-uploading its own.
  • You can ask us for a copy of it in a portable format, or ask us to delete it, at [email protected]. See Section 14.
  • Backups. The account database is backed up in three places, and the longest of them is the one that matters to you. Cloudflare keeps a rolling 30-day point-in-time history of the live database; we export a copy of it daily to our own storage and keep that for 35 days; and one further copy is held on a company computer and deleted after 40 days. After you delete your data it is gone from the live service immediately and ages out of all three within 40 days. We do not restore a backup in order to bring deleted data back.

If you do not want it

Signing in is what turns this on. The App requires an account, but the progress sync can be switched off in Settings → Account → Sync progress, which stops future uploads and deletes the copy we hold. Your progress then lives on your device and in your platform’s own backup, exactly as described in Section 5.

6. How We Use Information#

The limited information we collect is used for the following purposes only:

  • To provide the Services — deliver the website and download language packs.
  • To respond to you — answer your support emails, feature requests, and feedback.
  • To improve reliability — investigate de-identified crash and stability reports from Apple and from the Google Play Console.
  • To decide what to build — understand, in aggregate, which features are used and where people get stuck, using the anonymous events described in Section 4.3. Never to profile you, target advertising, or make an automated decision about you.
  • To fulfil purchases — unlock paid content based on transaction confirmations from Apple or Google, and keep the records of a sale that tax and consumer-protection law require.
  • To operate your account — send the six-digit code that signs you in, keep you signed in, recognise your subscription on a new device, keep the copy of your study progress described in Section 5A so that it reaches your next device, notify you about a deletion request, and answer you when you contact support about it. We do not use your email address for anything else.
  • To meet legal obligations — comply with applicable laws and respond to lawful requests.
  • To protect rights and safety — detect, prevent, and address fraud, abuse, or security incidents.

We do not use your information for advertising, profiling, automated decision-making producing legal or similarly significant effects, or to train external machine-learning models.

7. Legal Bases for Processing#

If you are in the European Economic Area, United Kingdom, Switzerland, or any region with similar law, we rely on these legal bases under Article 6 GDPR (or its local equivalent):

  • Performance of a contract (Art. 6(1)(b)) — providing the Services, processing your purchases, creating your account, signing you in, recognising your subscription, and keeping the copy of your study progress and the usage totals described in Section 5A so that your progress survives a lost or replaced device. An account is required to use the App, and everything in Section 4.6 is necessary to operate it.
  • Legitimate interests (Art. 6(1)(f)) — keeping the Services secure, debugging, basic server logs, rate-limiting sign-in attempts, keeping the security log described in Section 11, sending the optional new-device sign-in notice, reading the Section 5A usage totals in aggregate only to decide what to build and what the AI features cost, and collecting the anonymous usage events in Section 4.3 — a random identifier written to the App’s own storage, and which screens you open and which lessons you finish — so that we can tell what is worth building next. We rely on legitimate interests rather than consent for those events because they carry no name, no email address, no advertising identifier, no IP address and no location, because they are never joined to your account and there is no field in either place that could join them, and because they are not used to profile you or to advertise to you. We have weighed each of these against your rights and freedoms. You may object to any of them at [email protected], and we will tell you what we did about it rather than restate the reasoning back at you. For the usage events specifically, Settings → Share Usage Data is how you object, and it takes effect immediately and without argument.
  • Consent (Art. 6(1)(a)) — for optional crash diagnostics that you enable through your device's privacy settings, and for replies to your unsolicited email.
  • Legal obligation (Art. 6(1)(c)) — where applicable law requires us to retain or disclose information, including the seven-year retention of purchase records in Section 11, which is the reason we cannot delete those on request.

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

8. How We Share Information#

We do not sell or rent personal information. We do not share information with advertisers. We share information only with the parties below, and only as needed to operate the Services or comply with law:

  • Service providers / sub-processors — hosting, content delivery, the database that holds account records, and the service that delivers sign-in emails. Contractually bound to confidentiality and to process information only on our instructions. They are named individually in Section 9.
  • Apple Inc. — App Store distribution, in-app purchases, optional crash diagnostics, and — if you use Sign in with Apple — verifying your identity and, at your request, revoking that link. When you buy something, the App also passes Apple the random purchase identifier. Apple's processing is governed by Apple's own privacy policy.
  • Google LLC — Google Play distribution and billing, Play Console crash and stability reporting, the AI model that generates Chat Coach replies (including the Interests text, if you have filled it in), the optional in-app image search, and — if you use Continue with Google — verifying your identity. When you buy something, the App also passes Google the random purchase identifier. Google's processing is governed by Google's own privacy policy.
  • Zoho Corporation (ZeptoMail) — delivers the account emails listed in Section 4.6. It receives your email address and the contents of that message, which is the only way an email can reach you. It is a transactional-mail service only; we run no mailing list, and nothing about you is used for marketing by us or by them.
  • Professional advisers — lawyers, accountants, and insurers where confidentiality applies.
  • Legal & safety — if required by law, court order, or to investigate fraud or threats to safety. We will challenge overbroad requests where appropriate.
  • Corporate transactions — if Lengio is acquired, merged, or undergoes a similar transaction, information may be transferred subject to confidentiality and to this Policy or one materially similar.

9. Third-Party Services#

The Services rely on the third parties below. We disclose them so you can review their practices independently:

  • Apple Inc. — App Store distribution, payment processing, optional crash diagnostics, iCloud backup and key-value sync operated by Apple under your Apple Account. apple.com/legal/privacy
  • Google LLC — several separate roles, which we list individually because they are not the same thing. (1) Google Play distributes the Android app, processes in-app purchases through Google Play Billing, and gives us aggregated crash and stability reporting in the Play Console. (2) Android Backup stores device backups in your own Google account, where you have enabled it. (3) Vertex AI generates AI Chat Coach replies, reached through a server we operate so your device never contacts Google directly and no identifier of yours is passed along. Vertex AI is a Google Cloud service, and we moved the Chat Coach onto it on 15 September 2026; before that date it ran on the Gemini Developer API, on Google’s paid tier. We are recording the change here rather than quietly restating the sentence, because it changes which of Google’s terms govern the text you type. Your Chat Coach messages and your Interests text are now handled under the Google Cloud terms for Vertex AI, and we would rather send you to Google’s own words than summarise them in our favour: cloud.google.com/terms/service-terms.
  • Cloudflare Inc. — Website hosting; the content-delivery network that serves language packs, audio, images, and conversation videos; the servers that receive the product-analytics events described in Section 4.3 and relay AI requests; and the database (Cloudflare D1) that holds the account records described in Section 4.6, located in Cloudflare's Eastern North America region. That database keeps an automatic rolling 30-day point-in-time history for disaster recovery, It is one of the three backups described in Section 11; the longest of the three is 40 days. cloudflare.com/privacypolicy
  • Zoho Corporation — ZeptoMail delivers our account and sign-in emails, and Zoho Mail hosts the [email protected] mailbox. Both are on Zoho's United States data centre. Your email address and the content of those messages pass through it. zoho.com/privacy
  • flagcdn.com — Country-flag imagery used on the marketing website (no user data sent).

We integrate no third-party advertising SDKs, third-party analytics SDKs, marketing pixels, or session-replay tools inside the App on either platform. The only usage data collected by us is the first-party, anonymous event stream described in Section 4.3, which goes to servers we operate and is shared with nobody.

10. Cookies & Similar Technologies#

The Site is a static website that does not set marketing or analytics cookies. Your browser may use functional storage (e.g. cache) as part of normal operation. The App does not use web cookies for its own purposes because it is a native mobile application; the in-app browser used by the optional image search is a standard system browser component and is subject to that browser's and Google's own cookie practices.

Our hosting provider may set short-lived security cookies (e.g. to mitigate denial-of-service attacks). These are strictly necessary and exempt from consent under the ePrivacy framework.

11. Data Retention#

Article 13(2)(a) GDPR requires us to tell you the period for which each kind of personal data is stored, or the criteria used to decide it. Here are all seven, with the actual periods rather than “as long as necessary”:

  1. Data on your device — saved words, streaks, photos you attached, settings, and cached content. Kept until you remove it, with Settings → Erase All My Progress or by uninstalling. The parts of it we also hold are in line 3 below; the rest — your photos, your Chat Coach conversations and your answer-by-answer review history — exists only on your device, so those we cannot delete for you. A copy may persist in your own iCloud or Google backup until you delete it there too.
  2. Your study progress on our server — the compressed record and the usage totals described in Section 5A. Kept for as long as the account exists, replaced rather than accumulated, and erased with the account on the same 7-day cancellable grace period as line 2. You do not have to wait for that: you can delete this one on its own, at any time and without touching the rest of your account, with Settings → Erase All My Progress or by turning off Settings → Account → Sync progress.
  3. Your account record — email address, first name, languages, interface language, time zone, and linked sign-in identities (Section 4.6). Kept for as long as the account exists. When you ask us to delete it there is a 7-day cancellable grace period, after which these fields are erased immediately. The backups described below are then the only place they can still exist, for at most 40 days, and they are never restored into the live service.
  4. Sign-in codes and session tokens — a six-digit code expires 10 minutes after it is sent and its row is deleted within 24 hours. A session expires 180 days after its last use and, regardless of use, 400 days after it was issued. Signing out, signing out all devices, or deleting the account deletes them at once.
  5. Purchase and subscription records — which product, which store, the store's transaction identifier, the purchase identifier, the dates, and the renewal, expiry and refund notices Apple or Google send us. Kept for 7 years from the transaction, because tax and consumer-protection law require records of a sale to be kept and we cannot delete them on request. After an account is deleted they carry no name and no email address: what remains is the record of a payment, not a record of you.
  6. Support correspondence — up to 24 months from your last message, then deleted or anonymised, unless law requires us to keep it longer for legal or accounting purposes.
  7. Operational logs — web and CDN server logs up to 30 days, then deleted or aggregated. Crash and stability reports up to 12 months in aggregate form, and on Android also subject to Google's own Play Console retention. The account security log — which records that a sign-in, an entitlement change or a deletion happened, and never an email address, a name, an IP address or a token — is kept for the life of the Service, because its entire purpose is to be checkable long after the fact.

Backups. So that we can recover from a failure or a mistake, the account database is backed up three ways: Cloudflare’s own rolling 30-day point-in-time history of the live database, a daily export we keep for 35 days, and one copy on a company computer deleted after 40 days. Data you have deleted may still exist inside those windows. It is never restored back into the live service, and it ages out on its own within 40 days at the outside. The 7-day grace period in line 2 sits inside all three, so that by the time a deletion is final the oldest recoverable copy is already expiring.

Product-analytics events — the one thing with no period, and the argument for it. The raw event archive is append-only by design: written once, never modified, never deleted. Summaries are lossy, and a question nobody thought to ask on day one is unanswerable if only summaries were kept. These events carry no name, no email address, no account identifier, no IP address, no location and no device identifier — only the random install identifier in Section 4.3, which we do not join to anything and which the App never displays, so we hold nothing that could locate a person inside the archive. On that basis we treat the archive as anonymous rather than as personal data and apply no deletion schedule.

The previous version of this Policy also leaned on the claim that the identifier is replaced on every reinstall. That claim was wrong on Android and we have withdrawn it, so it is worth saying that this argument does not depend on it. The identifier persisting across a reinstall makes the archive slightly better at counting returning installs; it does not make the archive identify anybody, because there is still nothing in it, and nothing we hold elsewhere, that maps an identifier to a person. If you would rather these events did not exist at all, turn off Settings → Share Usage Data, which stops collection immediately and discards whatever is still queued on your device.

12. Data Security#

We use technical and organisational measures appropriate to the nature of the data we process. These include:

  • HTTPS/TLS encryption for all traffic to lengio.app and language-pack downloads.
  • Operating-system application sandboxing and at-rest encryption for on-device data on both iOS and Android.
  • Access controls and the principle of least privilege for our internal systems.
  • Routine review of third-party providers' security posture.
  • For accounts: no password is stored anywhere, because there is none. Sign-in codes are stored hashed rather than in the clear and expire in ten minutes; the Apple refresh token is encrypted at rest; sign-in tokens on your device are held in the iOS Keychain or Android Keystore, are unreadable until the device has been unlocked at least once since it booted, and are kept out of cloud backup and phone-to-phone transfer so that a restored backup cannot become a second signed-in device.

No method of transmission or storage is 100% secure. We cannot guarantee absolute security. If we discover a breach affecting personal information we will notify you and any regulator as required by law.

13. International Data Transfers#

Lengio operates internationally and is established in the United States. When you contact us by email, when you use the AI Chat Coach, when you create an account, and when our service providers process server logs, your information may be transferred to and processed in the United States and in other countries outside your country of residence, including jurisdictions that may not provide the same level of data-protection law as your own.

To be specific rather than general about the account: the account database is in the United States (Cloudflare's Eastern North America region) and the sign-in emails are sent from the United States (Zoho's US data centre). We considered pinning the database to the EU and decided against it, because your email address — the primary identifier — passes through the US mail provider on every sign-in regardless, so an EU-pinned database would have split the data across two jurisdictions rather than keeping it in one. The GDPR imposes no residency requirement; it imposes the safeguards below, which apply either way. We would rather tell you the real reason than present a split as a protection.

Where required, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and adequacy decisions. A copy of the safeguards used is available on request from [email protected].

14. Your Privacy Rights#

Subject to local law, you may have the following rights regarding your personal information. Because most data stays on your device, you can exercise many of these yourself directly inside the App.

  • Access — request a copy of personal information we hold about you.
  • Rectification / correction — ask us to correct inaccurate information.
  • Erasure ("right to be forgotten") — ask us to delete information we hold about you.
  • Restriction — ask us to limit how we use your information in certain circumstances.
  • Objection — object to processing based on legitimate interests.
  • Portability — receive your information in a structured, machine-readable format.
  • Withdraw consent — where processing is based on consent, at any time.
  • Complain to a supervisory authority — in your jurisdiction (e.g. ICO in the UK, your national DPA in the EU).
  • Non-discrimination — we will not deny service, charge different prices, or provide a different level of quality because you exercised a privacy right.

If you have an account, every right above applies to it in full and most of them are self-service: your email address, name and languages are visible and editable in Settings → Account; “sign out all devices” revokes every session; and Delete Account is in the same place. Ask us at [email protected] for a machine-readable export of your account record and we will send it. Deletion is described in Section 15.

A note on usage analytics — restated, because the previous version's reasoning contained a claim we have since withdrawn. The events described in Section 4.3 are keyed only to a random install identifier. We do not join it to your email address, your account, your purchases, your device, or your Apple or Google account, nothing in the archive carries any of those, and the App does not display the identifier, so you cannot tell us which one is yours and we cannot work it out. We therefore cannot locate "your" events in order to export or delete them, and Article 11 GDPR does not oblige us to start collecting additional information about you for the sole purpose of being able to.

That argument used to be supported by a second claim — that a reinstall always produces a fresh identifier — which was wrong on Android (Section 4.3). We have withdrawn it, and it is worth being explicit that the argument does not need it: an identifier that survives a reinstall is still an identifier that points at nothing we hold. If you disagree with that reasoning, tell us at [email protected] and we will engage with it rather than restate it. And if you would rather these events were not collected at all, turn off Settings → Share Usage Data. Every other right in this section applies in full to information that does identify you — your account, your purchases, and your support email.

To make a request, email [email protected] with the subject line "Privacy Request". We may need to verify your identity (for example, by replying from the email address on your account, or the one you used when contacting us) before responding. We will respond within the statutory time frame applicable to you (typically 30 days, extendable as permitted by law).

15. Deleting Your Data & Your Account#

There are two separate things you may want to delete, and they are not the same thing. The full, standalone instructions — including the route for someone who no longer has the App installed — are at lengio.app/delete-account, which requires no sign-in to read or to act on. In short:

15.1 Your data on the device (everyone)

Your words, streaks, statistics, saved content and settings live on your device, and — while you are signed in and have not turned the sync off — a copy of most of them also lives on our server (Section 5A). Settings → Erase All My Progress clears both: it erases what is on the device — including every AI Chat Coach conversation, in every language — withdraws your permission for the AI Chat Coach so that you are asked again before anything is sent, and deletes the server copy, in a way a second device cannot undo by re-uploading its own. Uninstalling does not. Removing the App takes its data off that device and leaves the server copy exactly where it is, so if getting rid of the server copy is what you want, use Erase All My Progress or delete the account before you uninstall — or email us and we will do it. If your device backs up to iCloud or to your Google account, a copy may also remain in that backup until you remove it there — and on Android, the anonymous install identifier is one of the things that comes back from it (Section 4.3).

15.2 Your Lengio account (only if you created one)

In the App: Settings → Account → Delete Account. Without the App: email [email protected] with the subject "Delete my Lengio account", preferably from the address on the account, which is how we confirm the request is yours. We ask for nothing else — no password, no payment detail, no identity document.

Either way: you are signed out immediately and the account can no longer sign in anywhere; there is a 7-day grace period in which signing in again cancels the deletion; and after that it is executed and cannot be reversed. We email you when it is requested and again when it is executed. Requests made by email are acknowledged within 5 business days and completed within 30 days, usually the same day.

What is erased: your email address and any Apple relay address, your name, your languages, interface language and time zone, every linked sign-in identity, the Apple refresh token — used first to tell Apple to revoke the link, so Lengio stops appearing in your Apple Account settings — every session on every device, and any unused sign-in codes.

What survives, and why: the purchase and subscription records in line 4 of Section 11, for the seven years tax and consumer-protection law require, carrying no name and no email address once the account is gone; and a line in the security log recording that an account with a given internal identifier was deleted and when, which by construction contains no personal data at all. Data already deleted may persist in the 30-day recovery history described in Section 11 and is never restored into the live service.

Deleting your account does not cancel a paid subscription, and we cannot cancel one for you — only Apple or Google can. If you are subscribed, cancel there first: iPhone, Settings → your name → Subscriptions; Android, Play Store → Payments & subscriptions → Subscriptions. Deleting the account may also make a past purchase harder to restore, because the identifier in Section 4.2 is how a purchase is recognised as yours on a new device.

16. Region-Specific Disclosures#

16.1 California (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (as amended by the California Privacy Rights Act) gives you specific rights. The categories of personal information we collect are: identifiers (your email address when you contact us or create an account; your first name; the random purchase identifier in Section 4.2), internet or other network activity (server logs, and the anonymous in-app usage events in Section 4.3), commercial information (purchase and subscription records from Apple and Google), and other information you choose to provide (the Interests text, and anything you write to support). We do not collect sensitive personal information as CPRA defines it — no precise or coarse geolocation, no government identifiers, no log-in credentials (there are none; see Section 4.6), and no biometric information (see Section 17). One item on that statutory list deserves a straight answer rather than a denial: the contents of your communications. Your Chat Coach messages do pass through a server we operate on the way to the AI provider, so we do receive them. We are the intended recipient of a message you address to our own tutor, which is the exception the statute itself draws — and we hold none of it: the text is handled in memory, never written to disk, and never stored against your account (Section 5A keeps a count and nothing else). We do not use or disclose it for any purpose that would require us to offer a “Limit the Use of My Sensitive Personal Information” link. We retain each category for the periods in Section 11.

We have not sold or shared personal information for cross-context behavioural advertising in the past 12 months and have no intention to do so. We do not use or disclose sensitive personal information for purposes that would require us to offer a "Limit the Use of My Sensitive Personal Information" link.

You may exercise California rights — to know, delete, correct, opt out of sale/share, and not be retaliated against — by emailing [email protected]. An authorised agent may make a request on your behalf with written authorisation.

Shine the Light. California Civil Code § 1798.83 permits California residents to request information about disclosure of certain categories of personal information to third parties for direct-marketing purposes. We do not disclose information for such purposes.

16.2 European Economic Area, United Kingdom & Switzerland

The legal bases on which we process personal information are described in Section 7. You have the GDPR rights described in Section 14. You also have the right to lodge a complaint with your local supervisory authority.

16.3 Brazil (LGPD)

Brazilian users have rights equivalent to those described in Section 14 under Lei Geral de Proteção de Dados. Email [email protected] to exercise them.

16.4 Other US States

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Iowa (ICDPA), Tennessee (TIPA), Indiana (INCDPA), New Jersey (NJDPA), Delaware (DPDPA), New Hampshire (NHDPA), and other states with consumer-privacy laws have rights of access, deletion, correction, portability, and opt-out of targeted advertising or sale. We do not engage in targeted advertising or the sale of personal information. To exercise other rights, email [email protected].

16.5 Australia, Canada & other jurisdictions

Where local law gives you additional rights — for example the Australian Privacy Principles or Canadian PIPEDA — we will honour them. Contact us for specifics.

17. Biometric Information — Explicit Statement#

Because the App has a speech feature and because we are established in Illinois, we state this as plainly as we can:

We do not collect, capture, purchase, receive through trade, store, use, disclose, redisclose, disseminate, sell, lease, trade, or otherwise profit from any biometric identifier or biometric information — including any voiceprint, retina or iris scan, fingerprint, hand geometry, or scan of face geometry — as those terms are defined by the Illinois Biometric Information Privacy Act (740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act, the Washington biometric privacy statute, or any comparable law.

Specifically: the AI Chat Coach uses your device's speech-to-text service to obtain a transcript. It does not create, derive, or store a voiceprint or any biometric template, and it does not identify or attempt to identify you from your voice. We never receive the audio itself on either platform (see Section 4.4). Any audio buffer used by the operating system's recognition service is handled by Apple or Google under their own policies and is not retained by us. Nothing in the App performs facial recognition on photos you attach to vocabulary cards; those photos are never transmitted to us at all.

What would change this. Two things would, and neither is in the App today: scoring how closely your pronunciation matches a native speaker’s in a way that models your voice rather than the words you said, and sending audio to a server instead of a transcript. If we ever build either, the paragraph above stops being true. Before shipping it we would obtain the written release the Illinois Biometric Information Privacy Act requires, publish the retention and destruction schedule it requires, and date the change on this page — in that order, before the feature exists rather than after. We are writing the tripwire down so that it is harder for us to cross it quietly.

18. Children's Privacy#

The Services are not directed to children under the age of 13 (or the equivalent minimum age in your jurisdiction — 14 in Spain, 15 in the Czech Republic and France, 16 in Germany and the Netherlands, and similar national variants under GDPR Article 8). We do not knowingly collect personal information from children below those ages, and the App is not listed in a children's or family programme on either store.

We ask how old you are, and we keep as little of the answer as we can. The first time you open the AI Chat Coach the App asks for your year of birth, once; it is not asked when the App opens. On iPhones and iPads new enough to offer it, the App asks the system for an age range instead, so that you are not asked at all and we never see a date. Either way we store a single coarse band — below the minimum, under 18, or 18 and over — and never a birthday. That band decides exactly two things: whether you may keep using the App on that device, and whether the AI Chat Coach opens. It personalises nothing, it is never sent to the AI provider, it is not in the account record in Section 4.6, it never appears in the usage events in Section 4.3, and we check our own source code at release time to keep it that way.

The AI Chat Coach is available from the same minimum age as the rest of Lengio. An earlier revision of this Policy gave the coach a higher minimum of its own; the App now uses a single minimum. The App still asks for your agreement, on the device, before the coach will open and before anything you type is sent.

If the answer is below the minimum for your country, you are signed out on that device and the App says so plainly rather than failing quietly; the account is not deleted, and can be deleted from Settings › Account or by email. We have deliberately not built a parental-consent route, because operating one properly is beyond what we can promise to do well.

Lengio carries an age rating on the App Store and a content rating on Google Play appropriate to general audiences, and contains no objectionable content, but parents are responsible for supervising their child's use — in particular of the AI Chat Coach, which generates its replies automatically and is not moderated by a human, and of the in-app image search, whose results come from Google rather than from us. If you believe a child has provided us with personal information, please email [email protected] and we will delete it promptly.

A note on what other apps reserve for children. Large services in this category publish a separate, better regime for their youngest users — non-personalised advertising, third-party behavioural tracking switched off, third-party analytics switched off. We mention it because we have nothing to switch off. There is no advertising in Lengio at any age, no advertising identifier on either platform, no third-party analytics or advertising SDK anywhere in the App, and no profiling of anyone. The protections other companies grant to a minority of their users are the only settings we have.

19. Sensitive Information#

Lengio lets you attach personal photos to vocabulary entries. These photos remain on your device. We have no access to them and they are not transmitted to our servers. If you choose to share screenshots with our support team, the images become part of your support correspondence and are governed by this Policy.

We strongly discourage including sensitive personal information (e.g. images of identification documents, payment cards, health records) in support correspondence, or speaking or typing it into the AI Chat Coach. If you do send it to support, we will treat it confidentially and delete it once your inquiry is resolved.

20. Notifications & Communications#

The App may send local notifications (e.g. daily study reminders). These are scheduled and delivered entirely on your device by the operating system based on settings you control. We do not see when notifications are delivered or opened. You may disable notifications at any time — on iOS in Settings → Notifications → Lengio, and on Android in Settings → Apps → Lengio → Notifications.

Email from us. We do not send marketing emails, run no mailing list, and there is nothing to unsubscribe from. We will reply to support correspondence you initiate, and may send transactional emails strictly necessary to resolve an inquiry. If you create an account we will also send the account emails listed in Section 4.6 — a sign-in code when you ask for one, a notice when account deletion is requested and again when it is executed, and, only if you switch it on, a notice when your account signs in on a new device. Those cannot be turned off individually while you have an account, because each of them is either something you asked for or something you need to see, but deleting the account ends them all.

21. Do Not Track & Global Privacy Control#

Because neither the Site nor the App tracks you across other companies' apps or websites, Do-Not-Track signals (DNT) and Global Privacy Control (GPC) have no behavioural effect. We honour these signals where they are legally required by treating them as a valid opt-out of any future sale or share of personal information.

The equivalent control for the App's own anonymous usage events is the Share Usage Data switch described in Section 4.3.

22. App Store & Google Play Privacy Disclosures#

Apple requires app developers to publish "App Privacy" labels on the App Store, and Google requires a "Data safety" section on Google Play. Those summaries are generated to each store's own categories and format, which are coarser than this Policy.

We maintain both to be consistent with this Policy. Where a store summary and this Policy appear to differ, the difference is a matter of the store's categories rather than of our practice, and this Policy is the authoritative and more detailed description. If you spot an inconsistency you believe is substantive, please tell us at [email protected] and we will correct whichever is wrong.

23. Changes to This Policy#

We may update this Policy from time to time to reflect changes to our practices, technology, legal requirements, or for other operational reasons. The "Last updated" date at the top of the page indicates the most recent revision.

For material changes that affect your rights, we will provide additional notice — for example, an in-app message, a prominent notice on this page, or an email to known support contacts — before the change takes effect. Continued use of the Services after the effective date constitutes acceptance of the revised Policy.

24. How to Contact Us#

For any privacy question, request, or complaint, please contact us:

We aim to acknowledge requests within 5 business days and resolve them within 30 days, or sooner where required by law. If you are not satisfied with our response, you may contact your local data-protection supervisory authority.