Privacy Policy

Effective: September 12, 2026  ·  Last updated: September 12, 2026  ·  Previous version: August 28, 2026

At a glance. Lengio is built privacy-first. Your vocabulary, photos, and study progress stay on your device. An account is optional — nothing in the App requires one — and we run no advertising SDKs, sell no data, and do not track you across other companies' apps and websites.

The App does record anonymous usage events — which screens you open, which lessons you finish — so we can see what is worth building next. They carry no name, no email, no advertising identifier, no IP address and no location, and you can switch them off in Settings. Optional AI features run on our servers only when you choose to use them.

Four things we want to be precise about rather than flattering, because each of them is a place where the simple version of this sentence would be wrong:

  • Your voice. On iPhone, speech is turned into text on the device and the audio never leaves it. On Android, whether that happens on the device or on Google's servers depends on your device, your keyboard and speech settings, and whether an offline language model is installed — so on Android we cannot promise the audio stays local. Section 4.4 gives both cases exactly.
  • Your interests. If you fill in the free-text Interests field in Settings, that text is sent to our AI provider with every Chat Coach message, to steer the conversation toward topics you like. It is the one thing you type that leaves the device by design. Section 4.4.
  • Your purchases. When you buy Lengio Plus, the App attaches a random identifier of its own to the transaction, so that a purchase can be reunited with its owner on a new phone. It goes to Apple or Google, it is deliberately not cleared by “Erase All My Progress”, and on Android it deliberately survives an uninstall. Section 4.2 explains why.
  • The anonymous install identifier. We used to say a reinstall always produces a fresh one. On Android that is not true — Google's Auto Backup restores it. Section 4.3 now says so, and Section 11 re-states the retention argument that depended on it.

1. Overview & Scope#

This Privacy Policy ("Policy") describes how Lengio ("Lengio", "we", "us", or "our") processes information when you use the Lengio mobile application for iOS and Android (the "App") or visit the Lengio website at lengio.app (the "Site"), collectively the "Services".

This Policy applies to all users of the Services worldwide, with additional disclosures for residents of specific regions (see Region-Specific Disclosures). Where the App behaves differently on iOS and on Android, this Policy says so explicitly rather than describing only the more favourable case. It does not apply to third-party services you reach through links inside the Services — those are governed by their own privacy policies.

By using the Services you confirm you have read and understood this Policy. If you do not agree, please do not use the Services.

2. Who We Are (Data Controller)#

The Services are operated by Nexios Media LLC, a limited liability company organised under the laws of the State of Illinois, United States, trading as "Lengio" (nexios-media.com).

Nexios Media LLC maintains a registered agent in Illinois as required by state law, through whom formal service of process may be made. For every other purpose — including notices under this document, privacy requests, and support — please use support@lengio.app, which we monitor and which is the fastest way to reach a person.

For the purposes of the EU/UK General Data Protection Regulation, similar laws, and CCPA/CPRA, that company is the data controller (or "business") responsible for the limited information we process. You can reach us at support@lengio.app for any privacy-related question, request, or complaint.

We have not appointed a statutory data protection officer because the nature and scale of our processing does not require one, but the contact above is monitored by a person with responsibility for privacy matters.

3. Key Definitions#

  • Personal information — any information that identifies, relates to, describes, or could reasonably be linked with an identified or identifiable person.
  • Processing — any operation performed on personal information, including collection, storage, use, disclosure, and deletion.
  • On-device data — information that is created, stored, and used only on your device's local storage and never transmitted to our servers.
  • Service providers / sub-processors — companies that process information on our behalf under contract (e.g. our website host).
  • Platform — Apple's iOS or Google's Android, and the associated store, operating-system services, and account you use with them.
  • Lengio account — the optional record described in Section 4.6, holding an email address (or an Apple private-relay address), your first name, your chosen languages, and whether you have a paid subscription. It exists only if you choose to create one, it has no password, and no feature of the App is withheld from you without it.

4. Information We Collect#

We have intentionally designed Lengio to collect as little personal information as possible. The categories below describe everything we receive.

4.1 Information you provide directly

  • Support correspondence — if you email support@lengio.app, we receive your email address, message content, and any attachments you choose to send (e.g. screenshots, device model). Used only to respond and improve the App.
  • Feedback — opinions, feature suggestions, or bug reports you voluntarily share.

4.2 Information collected automatically (limited)

  • Server log data (Site & content downloads) — when you visit lengio.app, or when the App downloads content such as a language pack, audio, images, or a conversation video, our hosting/CDN providers receive standard request data: IP address, user-agent string, requested URL, HTTP status, and timestamp. We use this only for delivery, security, and aggregate traffic statistics.
  • Crash diagnostics on iOS (only if you opted in with Apple) — if you have enabled Share with App Developers under Settings → Privacy & Security → Analytics & Improvements on your iOS device, Apple may share de-identified crash reports with us. You can disable this at any time in iOS Settings.
  • Crash and performance data on Android — Google provides us with aggregated crash and "Android Vitals" stability data through the Google Play Console. This comes from Google's own platform reporting; there is no crash-reporting or analytics SDK inside the App. The data we see is aggregated and de-identified — stack traces, device models, Android versions and counts — and is not presented to us in a form that identifies you.
  • Transaction confirmations — when you make an in-app purchase, Apple (App Store) or Google (Google Play) confirms the purchase to the App so we can unlock content. We do not receive your name, payment card details, or billing address from either.

The purchase identifier — stated plainly, because it is the one identifier that persists. The App generates a random identifier of its own the first time you buy something, and attaches it to the transaction: to Apple as appAccountToken, and to Google as obfuscatedAccountId. It is a random UUID. It is not derived from you, your device, your Apple Account, your Google Account, your email address, or your payment details, and on its own it identifies nobody — but it is stable, and it is the only durable thing the App creates that leaves your device.

Why it exists: without it, a purchase and a person cannot be reunited. Neither store lets it be added to a transaction after the fact, so if it is missing at the moment of purchase it is missing forever, and a subscriber who changes phone or loses a device has no way to prove the purchase was theirs. That is the problem it solves, and it is the only thing we use it for.

Three consequences we would rather state than have you discover:

  • It is deliberately excluded from Settings → Erase All My Progress. That control erases your learning data; erasing this identifier as well would silently orphan a purchase you paid for, and that cannot be repaired.
  • On Android it is deliberately included in Google's backup, so that it survives an uninstall and a move to a new phone. On iPhone it is likewise stored so that it travels with your iCloud Keychain. This is the opposite of what we do with sign-in tokens (Section 4.6), which are excluded from backup on purpose.
  • It reaches Apple or Google as part of the transaction, and — if you create a Lengio account — our own server, where it is the link between your subscription and your account. It is not shared with anyone else, and it never appears in the usage events in Section 4.3.

If you want it gone, the only way is to remove the App and, on Android, to delete Lengio's data from your Google backup. We will also delete our copy on request, on the understanding described in Section 15 — that doing so may make a past purchase unrecoverable.

Which versions. This identifier is introduced in the release of the App that accompanies this revision of the Policy, alongside the optional account in Section 4.6. Purchases made with earlier versions carry no such identifier and cannot be given one retrospectively — neither store permits it — which is the reason it is being introduced now rather than later.

4.3 Product analytics (the App)

The App records a small number of anonymous usage events so we can see which features are worth building and where people get stuck. This is our own pipeline, running on servers we operate. There is no third-party analytics SDK, no advertising SDK, and no advertising identifier anywhere in the App on either platform.

Each stored event contains only:

  • A random install identifier — a UUID generated on first launch and kept in the App's own storage. It is not Apple's advertising identifier (IDFA), not Apple's vendor identifier, not the Android Advertising ID (AAID), not the Android ID, and is not derived from anything about you or your hardware. It is not shared with any other app and is never sent to Apple, Google, or any other company. See the correction immediately below on what a reinstall does to it.
  • A session identifier, the event name, and the time.
  • App version and build, operating system and version, and device model (for example iPhone16,1 or Pixel 8 — the same string for millions of devices).
  • Your device locale, the App's display language, and the language you are studying.
  • Whether your plan is free or paid, and how many days ago the App was installed.
  • A small set of properties specific to the event — which screen was opened, how long a lesson took, which paywall was shown.

Event names are things like app_open, lesson_complete, paywall_view and purchase_success. We do not record the words you study, anything you type, anything you say, your photos, or the content of AI conversations.

A correction, September 2026 — what a reinstall actually does. Until this revision, this section said that deleting and reinstalling the App always produces a new install identifier and that we have no way to connect the two. On iPhone that holds for an ordinary delete-and-reinstall, though restoring a whole device from an iCloud backup does carry the old identifier across. On Android it was simply wrong. The identifier is held in the App's preferences, and Google's Auto Backup includes those preferences, so reinstalling Lengio — or setting up a new Android phone from your old one — restores the identifier you already had rather than minting a fresh one. We had not noticed; we are correcting it rather than leaving a comfortable sentence standing. The practical effect is that on Android a returning install may be counted as the same install, which is a slightly better statistic and a slightly weaker privacy claim than we were making. Nothing else about these events changed, and the switch in the next paragraph still stops them completely. We are keeping the current behaviour — turning it off would put the identifier outside your control of your own backup — and we have restated the retention argument in Section 11 so that it no longer rests on the sentence we have just withdrawn.

Being an identifier that can persist across a reinstall is, for what it is worth, the ordinary condition of anything inside your own device backup. We accept the accuracy cost of not adding anything else to these events, which is why there is nothing here to correlate the identifier against.

Your IP address is not stored. Our servers necessarily receive it in order to answer the request, as every web server does, but it is never written to the analytics archive. We do not record your country, region, or any other location. We removed the country field in July 2026 specifically so that this sentence would be true.

You can turn this off. Open the App → Settings → Share Usage Data. Switching it off stops collection immediately and discards anything still waiting to be sent from your device. Every feature behaves identically either way — nothing is withheld from you for opting out.

4.4 AI Chat Coach (optional feature) — and what happens to your voice

If you choose to use the AI Chat Coach (described on our website as the AI Speech Partner), the App captures audio from your microphone only while the feature is active and converts it to text. What happens to that audio depends on your platform, and we describe both cases exactly.

  • On iOS. Speech is converted to text on your device using Apple's on-device speech recognition. The audio never leaves your iPhone or iPad — not to us, not to Apple's servers, not to anyone.
  • On Android. Speech recognition is performed by the recognition service provided by your device. Depending on your device model, Android version, installed language packs, and your own speech settings, this may run entirely on your device, or Google's speech service may process the audio on Google's servers under Google's privacy policy. We do not control which of the two occurs and cannot promise the audio stays on your Android device. Many Android devices allow on-device recognition to be forced by downloading an offline language model in the system speech settings.

In neither case do we receive or store your audio. Lengio's servers receive only the resulting text.

  • Only the resulting text is sent, through a server we operate, to our AI provider so it can generate the tutor's reply, which is streamed back to your device.
  • Your device never contacts the AI provider directly. Requests pass through our own server, so no device identifier, IP-derived location, or install identifier reaches the provider.
  • Text is processed in memory and is not stored on our servers or used to train any model.
  • Conversation text may be retained by the AI provider for a short period for abuse-prevention and quality-assurance purposes and is then deleted.
  • Alongside your message, the App sends the language you are studying, your level, a short list of words the lesson is working on — and the Interests text described immediately below.
  • You can revoke microphone access at any time — on iOS in Settings → Privacy & Security → Microphone → Lengio; on Android in Settings → Apps → Lengio → Permissions → Microphone. Without microphone access the AI Chat Coach cannot listen to you, but the rest of the App continues to work.

The Interests field. Settings → Profile contains a free-text box labelled Interests, where you can list hobbies or topics you enjoy. If you fill it in, that text is sent to the AI provider with every Chat Coach message, including the coach's opening line, so the conversation can steer toward things you actually care about. It is truncated to a few hundred characters and it is sent exactly as you typed it. Nothing else in Settings is transmitted this way. If you would rather it were not sent, clear the box: an empty field is omitted entirely, and the feature works without it.

The App also used to send the name you entered during setup in the same place, so the coach could greet you by it. We removed it. A first name is personal data with no teaching value the coach cannot get another way, and it should not have been going to a third party to produce a nicety. The code that sent it was deleted from both apps on 11 September 2026; every release published after that date omits it, and if you are running an older release it is still being sent until you update. The name is still used for greetings inside the App, where it never leaves your device. We are recording the change here rather than silently benefiting from it.

Please do not speak or type personal, confidential, financial, health, or otherwise sensitive information about yourself or anyone else into the AI Chat Coach — and in particular, please do not put anything in the Interests box that you would not want sent to an AI provider with every message.

4.5 Image search (optional feature)

You can replace the picture on any vocabulary card. Tapping the picture offers Choose Photo, which uses your own photo library and sends nothing anywhere, and Search Images, which opens Google Image Search inside an in-app browser.

If you use Search Images, your search term — the word you are studying — goes to Google directly, along with your IP address, under Google's own privacy policy. We do not see the search or the results, and the image you pick is saved only on your device.

4.6 Your Lengio account — optional, and what it holds

Lengio is introducing an optional account in the release of the App that accompanies this revision. Its only purpose is that a new phone means signing in rather than starting again, and that a Lengio Plus subscription can be recognised as yours on it. Nothing in the App requires an account — every lesson, every language, every feature and every purchase works exactly as before if you never create one, and the setup screen that offers it can be skipped with a single tap.

There is no password. You sign in either with Apple or Google, or by typing an email address and entering a six-digit code we send to it. We hold no password, so there is no password to lose, reset, or breach.

If you create one, this is everything the account record contains:

  • An email address — the one you typed, or, if you used Sign in with Apple and chose Hide My Email, Apple's private relay address. We record which of the two it is. A relay address is the only address we will ever hold for you in that case; we cannot see the real one.
  • Your first name, as you typed it at setup — used to address you in the App and in an email from us, and nowhere else.
  • Which languages you study and your native language, your interface language, and your time zone. The time zone is stored because a streak has to know when your day ends, and a fixed offset cannot survive daylight saving.
  • The sign-in identities linked to the account — the opaque subject identifier Apple or Google gives us, the name Apple hands over once at first sign-in and never again, and, for Apple, an encrypted refresh token, which exists so that deleting your account can also tell Apple to revoke the link rather than leaving Lengio listed in your Apple Account settings forever.
  • Sign-in codes, stored hashed rather than in the clear, and valid for ten minutes.
  • Session tokens for the devices you are signed in on, with a label so that “sign out all devices” means something to you.
  • Your subscription status — which product, which store, which dates, the store's own transaction identifier, the purchase identifier from Section 4.2, and the renewal, expiry and refund notices Apple or Google send us about it.

What the account does not contain. It holds no study progress, no words, no lesson history, no photos, no Chat Coach conversations and no audio. Those stay on your device exactly as described in Section 5. Creating an account does not upload your learning data to us, and we are not building a sync service; if we ever do, it will be described here before it exists, not after.

Where it lives. In a small database we operate on Cloudflare's infrastructure in the United States, and nowhere else. The sign-in emails are delivered by Zoho's ZeptoMail, also in the United States. Both are listed in Section 9 and covered by Section 13.

On your device, the sign-in tokens are held in the iOS Keychain or the Android Keystore, are readable only after you have unlocked the device at least once since it booted, and are deliberately excluded from iCloud and Google backup and from phone-to-phone transfer — a session copied onto a second device is a second person signed in as you, with no way for you to see it or stop it. This is the exact opposite of how the purchase identifier is treated, and the difference is intentional.

Emails we will send you. A sign-in code when you ask for one; a notice when you request account deletion and again when it is executed; and, if you switch it on, a notice when your account is used to sign in on a new device. That is the complete list. We do not send marketing email and there is nothing to unsubscribe from.

Deleting the account is described in Section 15 and at lengio.app/delete-account.

4.7 Information we do not collect

  • Advertising identifiers — Apple's IDFA, the Android Advertising ID (AAID), or any other cross-app tracking signal.
  • Contacts, calendar entries, health data, financial data, biometric data, or location of any kind — including country or region derived from your IP address.
  • Camera images other than photos you explicitly choose from your photo library.
  • Microphone audio outside of an active AI Chat Coach session — and even then, we never receive the audio itself on either platform.
  • Behavioural analytics for advertising or user profiling, and any third-party analytics SDK. The usage events in Section 4.3 go only to servers we operate.
  • Inferences about your demographics, interests, or political views.

5. Information Stored Locally on Your Device#

The following information lives on your device only and is never transmitted to us. Operating-system encryption and application sandboxing apply on both iOS and Android.

  • Words you have studied, bookmarked, marked as known, or completed.
  • Personal photos you attach to vocabulary entries (selected from your photo library; see Sensitive Information).
  • Your chosen learning language(s) and native language.
  • Daily goal, streak count, and study statistics.
  • Notification and reminder preferences.
  • App language and onboarding state.
  • Cached language-pack content you have downloaded.

Platform backup and sync. There is no copy of your study progress on any server we control, and the optional account in Section 4.6 does not change that — it holds who you are and what you have paid for, never what you have learned. We operate no server-side sync of your progress. Where your progress leaves your device, it does so through your platform's own backup service, under your own account with Apple or Google:

  • iOS — if iCloud Backup is enabled at the operating-system level, Lengio's data may be included in your encrypted iCloud backup managed by Apple. If you are signed in to iCloud, the App also syncs a small set of values — your streak, daily-goal progress, lesson completions, bookmarks, and game records — through Apple's iCloud key-value store, so a second device picks up where the first left off.
  • Android — if Android Backup is enabled at the operating-system level, Lengio's data may be included in the backup that Android stores in your Google account.

Both stores belong to Apple and Google respectively and are tied to your account with them. We have no access to either, and neither is operated by us. Progress does not transfer between iOS and Android.

Two items in those backups are handled deliberately rather than by default, and both are described above: the purchase identifier is kept inside them on purpose (Section 4.2), and account sign-in tokens are kept out of them on purpose (Section 4.6). On Android, the anonymous install identifier is inside them as a side-effect of where it is stored, which is the correction in Section 4.3.

6. How We Use Information#

The limited information we collect is used for the following purposes only:

  • To provide the Services — deliver the website and download language packs.
  • To respond to you — answer your support emails, feature requests, and feedback.
  • To improve reliability — investigate de-identified crash and stability reports from Apple and from the Google Play Console.
  • To decide what to build — understand, in aggregate, which features are used and where people get stuck, using the anonymous events described in Section 4.3. Never to profile you, target advertising, or make an automated decision about you.
  • To fulfil purchases — unlock paid content based on transaction confirmations from Apple or Google, and keep the records of a sale that tax and consumer-protection law require.
  • To operate your account, if you create one — send the six-digit code that signs you in, keep you signed in, recognise your subscription on a new device, notify you about a deletion request, and answer you when you contact support about it. We do not use your email address for anything else.
  • To meet legal obligations — comply with applicable laws and respond to lawful requests.
  • To protect rights and safety — detect, prevent, and address fraud, abuse, or security incidents.

We do not use your information for advertising, profiling, automated decision-making producing legal or similarly significant effects, or to train external machine-learning models.

7. Legal Bases for Processing#

If you are in the European Economic Area, United Kingdom, Switzerland, or any region with similar law, we rely on these legal bases under Article 6 GDPR (or its local equivalent):

  • Performance of a contract (Art. 6(1)(b)) — providing the Services, processing your purchases, and — where you have chosen to create an account — creating it, signing you in, and recognising your subscription. Creating an account is your own request, and everything in Section 4.6 is necessary to honour it.
  • Legitimate interests (Art. 6(1)(f)) — keeping the Services secure, debugging, basic server logs, rate-limiting sign-in attempts, keeping the security log described in Section 11, and sending an optional new-device sign-in notice. Balanced against your rights.
  • Consent (Art. 6(1)(a)) — for optional crash diagnostics that you enable through your device's privacy settings, and for replies to your unsolicited email.
  • Legal obligation (Art. 6(1)(c)) — where applicable law requires us to retain or disclose information, including the seven-year retention of purchase records in Section 11, which is the reason we cannot delete those on request.

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

8. How We Share Information#

We do not sell or rent personal information. We do not share information with advertisers. We share information only with the parties below, and only as needed to operate the Services or comply with law:

  • Service providers / sub-processors — hosting, content delivery, the database that holds account records, and the service that delivers sign-in emails. Contractually bound to confidentiality and to process information only on our instructions. They are named individually in Section 9.
  • Apple Inc. — App Store distribution, in-app purchases, push notification routing, optional crash diagnostics, and — if you use Sign in with Apple — verifying your identity and, at your request, revoking that link. When you buy something, the App also passes Apple the random purchase identifier. Apple's processing is governed by Apple's own privacy policy.
  • Google LLC — Google Play distribution and billing, Play Console crash and stability reporting, push notification routing on Android, the AI model that generates Chat Coach replies (including the Interests text, if you have filled it in), the optional in-app image search, and — if you use Continue with Google — verifying your identity. When you buy something, the App also passes Google the random purchase identifier. Google's processing is governed by Google's own privacy policy.
  • Zoho Corporation (ZeptoMail) — delivers the account emails listed in Section 4.6. It receives your email address and the contents of that message, which is the only way an email can reach you. It is a transactional-mail service only; we run no mailing list, and nothing about you is used for marketing by us or by them.
  • Professional advisers — lawyers, accountants, and insurers where confidentiality applies.
  • Legal & safety — if required by law, court order, or to investigate fraud or threats to safety. We will challenge overbroad requests where appropriate.
  • Corporate transactions — if Lengio is acquired, merged, or undergoes a similar transaction, information may be transferred subject to confidentiality and to this Policy or one materially similar.

9. Third-Party Services#

The Services rely on the third parties below. We disclose them so you can review their practices independently:

  • Apple Inc. — App Store distribution, payment processing, push notifications, optional crash diagnostics, iCloud backup and key-value sync operated by Apple under your Apple Account. apple.com/legal/privacy
  • Google LLC — several separate roles, which we list individually because they are not the same thing. (1) Google Play distributes the Android app, processes in-app purchases through Google Play Billing, and gives us aggregated crash and stability reporting in the Play Console. (2) Android Backup stores device backups in your own Google account, where you have enabled it. (3) Gemini API generates AI Chat Coach replies, reached through a server we operate so your device never contacts Google directly and no identifier of yours is passed along; content sent to that API is covered by an agreement that prohibits using it to train Google's models. (4) Android speech recognition may process audio on Google's servers, as described in Section 4.4. (5) Google Image Search powers the optional in-app image search. The AI provider may change over time as the underlying models evolve; we will update this page if it does. policies.google.com/privacy
  • Cloudflare Inc. — Website hosting; the content-delivery network that serves language packs, audio, images, and conversation videos; the servers that receive the product-analytics events described in Section 4.3 and relay AI requests; and the database (Cloudflare D1) that holds the account records described in Section 4.6, located in Cloudflare's Eastern North America region. That database keeps an automatic rolling 30-day point-in-time history for disaster recovery, which is what Section 11 means when it says a deletion takes up to 30 days to age out of backups. cloudflare.com/privacypolicy
  • Zoho Corporation — ZeptoMail delivers our account and sign-in emails, and Zoho Mail hosts the support@lengio.app mailbox. Both are on Zoho's United States data centre. Your email address and the content of those messages pass through it. zoho.com/privacy
  • flagcdn.com — Country-flag imagery used on the marketing website (no user data sent).

We integrate no third-party advertising SDKs, third-party analytics SDKs, marketing pixels, or session-replay tools inside the App on either platform. The only usage data collected by us is the first-party, anonymous event stream described in Section 4.3, which goes to servers we operate and is shared with nobody.

10. Cookies & Similar Technologies#

The Site is a static website that does not set marketing or analytics cookies. Your browser may use functional storage (e.g. cache) as part of normal operation. The App does not use web cookies for its own purposes because it is a native mobile application; the in-app browser used by the optional image search is a standard system browser component and is subject to that browser's and Google's own cookie practices.

Our hosting provider may set short-lived security cookies (e.g. to mitigate denial-of-service attacks). These are strictly necessary and exempt from consent under the ePrivacy framework.

11. Data Retention#

Article 13(2)(a) GDPR requires us to tell you the period for which each kind of personal data is stored, or the criteria used to decide it. Here are all six, with the actual periods rather than “as long as necessary”:

  1. Data on your device — progress, saved words, streaks, photos you attached, settings, and cached content. Kept until you remove it, with Settings → Erase All My Progress or by uninstalling. We hold no copy and cannot delete it for you. A copy may persist in your own iCloud or Google backup until you delete it there too.
  2. Your account record — email address, first name, languages, interface language, time zone, and linked sign-in identities (Section 4.6). Kept for as long as the account exists. When you ask us to delete it there is a 7-day cancellable grace period, after which these fields are erased immediately. The 30-day recovery history described below is then the only place they can still exist, and it is never restored into the live service.
  3. Sign-in codes and session tokens — a six-digit code expires 10 minutes after it is sent and its row is deleted within 24 hours. A session expires 180 days after its last use and, regardless of use, 400 days after it was issued. Signing out, signing out all devices, or deleting the account deletes them at once.
  4. Purchase and subscription records — which product, which store, the store's transaction identifier, the purchase identifier, the dates, and the renewal, expiry and refund notices Apple or Google send us. Kept for 7 years from the transaction, because tax and consumer-protection law require records of a sale to be kept and we cannot delete them on request. After an account is deleted they carry no name and no email address: what remains is the record of a payment, not a record of you.
  5. Support correspondenceup to 24 months from your last message, then deleted or anonymised, unless law requires us to keep it longer for legal or accounting purposes.
  6. Operational logs — web and CDN server logs up to 30 days, then deleted or aggregated. Crash and stability reports up to 12 months in aggregate form, and on Android also subject to Google's own Play Console retention. The account security log — which records that a sign-in, an entitlement change or a deletion happened, and never an email address, a name, an IP address or a token — is kept for the life of the Service, because its entire purpose is to be checkable long after the fact.

Backups. The account database keeps an automatic rolling 30-day point-in-time history so that we can recover from a failure or a mistake. Data you have deleted may still exist inside that window. It is never restored back into the live service, and it ages out on its own within 30 days. The grace period in line 2 and this window are deliberately the same length, so that by the time a deletion is final the oldest recoverable copy is already expiring.

Product-analytics events — the one thing with no period, and the argument for it. The raw event archive is append-only by design: written once, never modified, never deleted. Summaries are lossy, and a question nobody thought to ask on day one is unanswerable if only summaries were kept. These events carry no name, no email address, no account identifier, no IP address, no location and no device identifier — only the random install identifier in Section 4.3, which we do not join to anything and which the App never displays, so we hold nothing that could locate a person inside the archive. On that basis we treat the archive as anonymous rather than as personal data and apply no deletion schedule.

The previous version of this Policy also leaned on the claim that the identifier is replaced on every reinstall. That claim was wrong on Android and we have withdrawn it, so it is worth saying that this argument does not depend on it. The identifier persisting across a reinstall makes the archive slightly better at counting returning installs; it does not make the archive identify anybody, because there is still nothing in it, and nothing we hold elsewhere, that maps an identifier to a person. If you would rather these events did not exist at all, turn off Settings → Share Usage Data, which stops collection immediately and discards whatever is still queued on your device.

12. Data Security#

We use technical and organisational measures appropriate to the nature of the data we process. These include:

  • HTTPS/TLS encryption for all traffic to lengio.app and language-pack downloads.
  • Operating-system application sandboxing and at-rest encryption for on-device data on both iOS and Android.
  • Access controls and the principle of least privilege for our internal systems.
  • Routine review of third-party providers' security posture.
  • For accounts: no password is stored anywhere, because there is none. Sign-in codes are stored hashed rather than in the clear and expire in ten minutes; the Apple refresh token is encrypted at rest; sign-in tokens on your device are held in the iOS Keychain or Android Keystore, are unreadable until the device has been unlocked at least once since it booted, and are kept out of cloud backup and phone-to-phone transfer so that a restored backup cannot become a second signed-in device.

No method of transmission or storage is 100% secure. We cannot guarantee absolute security. If we discover a breach affecting personal information we will notify you and any regulator as required by law.

13. International Data Transfers#

Lengio operates internationally and is established in the United States. When you contact us by email, when you use the AI Chat Coach, when you create an account, and when our service providers process server logs, your information may be transferred to and processed in the United States and in other countries outside your country of residence, including jurisdictions that may not provide the same level of data-protection law as your own.

To be specific rather than general about the account: the account database is in the United States (Cloudflare's Eastern North America region) and the sign-in emails are sent from the United States (Zoho's US data centre). We considered pinning the database to the EU and decided against it, because your email address — the primary identifier — passes through the US mail provider on every sign-in regardless, so an EU-pinned database would have split the data across two jurisdictions rather than keeping it in one. The GDPR imposes no residency requirement; it imposes the safeguards below, which apply either way. We would rather tell you the real reason than present a split as a protection.

Where required, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and adequacy decisions. A copy of the safeguards used is available on request from support@lengio.app.

14. Your Privacy Rights#

Subject to local law, you may have the following rights regarding your personal information. Because most data stays on your device, you can exercise many of these yourself directly inside the App.

  • Access — request a copy of personal information we hold about you.
  • Rectification / correction — ask us to correct inaccurate information.
  • Erasure ("right to be forgotten") — ask us to delete information we hold about you.
  • Restriction — ask us to limit how we use your information in certain circumstances.
  • Objection — object to processing based on legitimate interests.
  • Portability — receive your information in a structured, machine-readable format.
  • Withdraw consent — where processing is based on consent, at any time.
  • Complain to a supervisory authority — in your jurisdiction (e.g. ICO in the UK, your national DPA in the EU).
  • Non-discrimination — we will not deny service, charge different prices, or provide a different level of quality because you exercised a privacy right.

If you have an account, every right above applies to it in full and most of them are self-service: your email address, name and languages are visible and editable in Settings → Account; “sign out all devices” revokes every session; and Delete Account is in the same place. Ask us at support@lengio.app for a machine-readable export of your account record and we will send it. Deletion is described in Section 15.

A note on usage analytics — restated, because the previous version's reasoning contained a claim we have since withdrawn. The events described in Section 4.3 are keyed only to a random install identifier. We do not join it to your email address, your account, your purchases, your device, or your Apple or Google account, nothing in the archive carries any of those, and the App does not display the identifier, so you cannot tell us which one is yours and we cannot work it out. We therefore cannot locate "your" events in order to export or delete them, and Article 11 GDPR does not oblige us to start collecting additional information about you for the sole purpose of being able to.

That argument used to be supported by a second claim — that a reinstall always produces a fresh identifier — which was wrong on Android (Section 4.3). We have withdrawn it, and it is worth being explicit that the argument does not need it: an identifier that survives a reinstall is still an identifier that points at nothing we hold. If you disagree with that reasoning, tell us at support@lengio.app and we will engage with it rather than restate it. And if you would rather these events were not collected at all, turn off Settings → Share Usage Data. Every other right in this section applies in full to information that does identify you — your account, your purchases, and your support email.

To make a request, email support@lengio.app with the subject line "Privacy Request". We may need to verify your identity (for example, by replying from the email address on your account, or the one you used when contacting us) before responding. We will respond within the statutory time frame applicable to you (typically 30 days, extendable as permitted by law).

15. Deleting Your Data & Your Account#

There are two separate things you may want to delete, and they are not the same thing. The full, standalone instructions — including the route for someone who no longer has the App installed — are at lengio.app/delete-account, which requires no sign-in to read or to act on. In short:

15.1 Your data on the device (everyone)

Your words, streaks, statistics, saved content and settings live on your device. Settings → Erase All My Progress clears them; uninstalling Lengio removes them along with the App. We never held a copy, so there is nothing for us to delete. If your device backs up to iCloud or to your Google account, a copy may remain in that backup until you remove it there — and on Android, the anonymous install identifier is one of the things that comes back from it (Section 4.3).

15.2 Your Lengio account (only if you created one)

In the App: Settings → Account → Delete Account. Without the App: email support@lengio.app with the subject "Delete my Lengio account", preferably from the address on the account, which is how we confirm the request is yours. We ask for nothing else — no password, no payment detail, no identity document.

Either way: you are signed out immediately and the account can no longer sign in anywhere; there is a 7-day grace period in which signing in again cancels the deletion; and after that it is executed and cannot be reversed. We email you when it is requested and again when it is executed. Requests made by email are acknowledged within 5 business days and completed within 30 days, usually the same day.

What is erased: your email address and any Apple relay address, your name, your languages, interface language and time zone, every linked sign-in identity, the Apple refresh token — used first to tell Apple to revoke the link, so Lengio stops appearing in your Apple Account settings — every session on every device, and any unused sign-in codes.

What survives, and why: the purchase and subscription records in line 4 of Section 11, for the seven years tax and consumer-protection law require, carrying no name and no email address once the account is gone; and a line in the security log recording that an account with a given internal identifier was deleted and when, which by construction contains no personal data at all. Data already deleted may persist in the 30-day recovery history described in Section 11 and is never restored into the live service.

Deleting your account does not cancel a paid subscription, and we cannot cancel one for you — only Apple or Google can. If you are subscribed, cancel there first: iPhone, Settings → your name → Subscriptions; Android, Play Store → Payments & subscriptions → Subscriptions. Deleting the account may also make a past purchase harder to restore, because the identifier in Section 4.2 is how a purchase is recognised as yours on a new device.

16. Region-Specific Disclosures#

16.1 California (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (as amended by the California Privacy Rights Act) gives you specific rights. The categories of personal information we collect are: identifiers (your email address when you contact us or create an account; your first name; the random purchase identifier in Section 4.2), internet or other network activity (server logs, and the anonymous in-app usage events in Section 4.3), commercial information (purchase and subscription records from Apple and Google), and other information you choose to provide (the Interests text, and anything you write to support). We do not collect sensitive personal information — including precise or coarse geolocation, government identifiers, account log-in credentials, biometric information, or the contents of your communications — as CPRA defines it. We retain each category for the periods in Section 11.

We have not sold or shared personal information for cross-context behavioural advertising in the past 12 months and have no intention to do so. We do not use or disclose sensitive personal information for purposes that would require us to offer a "Limit the Use of My Sensitive Personal Information" link.

You may exercise California rights — to know, delete, correct, opt out of sale/share, and not be retaliated against — by emailing support@lengio.app. An authorised agent may make a request on your behalf with written authorisation.

Shine the Light. California Civil Code § 1798.83 permits California residents to request information about disclosure of certain categories of personal information to third parties for direct-marketing purposes. We do not disclose information for such purposes.

16.2 European Economic Area, United Kingdom & Switzerland

The legal bases on which we process personal information are described in Section 7. You have the GDPR rights described in Section 14. You also have the right to lodge a complaint with your local supervisory authority. We are not currently required to appoint an EU/UK representative under Article 27 GDPR; if this changes we will list the representative here.

16.3 Brazil (LGPD)

Brazilian users have rights equivalent to those described in Section 14 under Lei Geral de Proteção de Dados. Email support@lengio.app to exercise them.

16.4 Other US States

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Iowa (ICDPA), Tennessee (TIPA), Indiana (INCDPA), New Jersey (NJDPA), Delaware (DPDPA), New Hampshire (NHDPA), and other states with consumer-privacy laws have rights of access, deletion, correction, portability, and opt-out of targeted advertising or sale. We do not engage in targeted advertising or the sale of personal information. To exercise other rights, email support@lengio.app.

16.5 Australia, Canada & other jurisdictions

Where local law gives you additional rights — for example the Australian Privacy Principles or Canadian PIPEDA — we will honour them. Contact us for specifics.

17. Biometric Information — Explicit Statement#

Because the App has a speech feature and because we are established in Illinois, we state this as plainly as we can:

We do not collect, capture, purchase, receive through trade, store, use, disclose, redisclose, disseminate, sell, lease, trade, or otherwise profit from any biometric identifier or biometric information — including any voiceprint, retina or iris scan, fingerprint, hand geometry, or scan of face geometry — as those terms are defined by the Illinois Biometric Information Privacy Act (740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act, the Washington biometric privacy statute, or any comparable law.

Specifically: the AI Chat Coach uses your device's speech-to-text service to obtain a transcript. It does not create, derive, or store a voiceprint or any biometric template, and it does not identify or attempt to identify you from your voice. We never receive the audio itself on either platform (see Section 4.4). Any audio buffer used by the operating system's recognition service is handled by Apple or Google under their own policies and is not retained by us. Nothing in the App performs facial recognition on photos you attach to vocabulary cards; those photos are never transmitted to us at all.

If this ever changes, we will obtain any written release required by law and publish a retention and destruction schedule before enabling the feature.

18. Children's Privacy#

The Services are not directed to children under the age of 13 (or the equivalent minimum age in your jurisdiction — 14 in Spain, 15 in the Czech Republic and France, 16 in Germany and the Netherlands, and similar national variants under GDPR Article 8). We do not knowingly collect personal information from children below those ages, and the App is not listed in a children's or family programme on either store.

Lengio carries an age rating on the App Store and a content rating on Google Play appropriate to general audiences, and contains no objectionable content, but parents are responsible for supervising their child's use — in particular of the AI Chat Coach, which generates its replies automatically and is not moderated by a human, and of the in-app image search, whose results come from Google rather than from us. If you believe a child has provided us with personal information, please email support@lengio.app and we will delete it promptly.

19. Sensitive Information#

Lengio lets you attach personal photos to vocabulary entries. These photos remain on your device. We have no access to them and they are not transmitted to our servers. If you choose to share screenshots with our support team, the images become part of your support correspondence and are governed by this Policy.

We strongly discourage including sensitive personal information (e.g. images of identification documents, payment cards, health records) in support correspondence, or speaking or typing it into the AI Chat Coach. If you do send it to support, we will treat it confidentially and delete it once your inquiry is resolved.

20. Notifications & Communications#

The App may send local notifications (e.g. daily study reminders). These are scheduled and delivered entirely on your device by the operating system based on settings you control. We do not see when notifications are delivered or opened. You may disable notifications at any time — on iOS in Settings → Notifications → Lengio, and on Android in Settings → Apps → Lengio → Notifications.

Email from us. We do not send marketing emails, run no mailing list, and there is nothing to unsubscribe from. We will reply to support correspondence you initiate, and may send transactional emails strictly necessary to resolve an inquiry. If you create an account we will also send the account emails listed in Section 4.6 — a sign-in code when you ask for one, a notice when account deletion is requested and again when it is executed, and, only if you switch it on, a notice when your account signs in on a new device. Those cannot be turned off individually while you have an account, because each of them is either something you asked for or something you need to see, but deleting the account ends them all.

21. Do Not Track & Global Privacy Control#

Because neither the Site nor the App tracks you across other companies' apps or websites, Do-Not-Track signals (DNT) and Global Privacy Control (GPC) have no behavioural effect. We honour these signals where they are legally required by treating them as a valid opt-out of any future sale or share of personal information.

The equivalent control for the App's own anonymous usage events is the Share Usage Data switch described in Section 4.3.

22. App Store & Google Play Privacy Disclosures#

Apple requires app developers to publish "App Privacy" labels on the App Store, and Google requires a "Data safety" section on Google Play. Those summaries are generated to each store's own categories and format, which are coarser than this Policy.

We maintain both to be consistent with this Policy. Where a store summary and this Policy appear to differ, the difference is a matter of the store's categories rather than of our practice, and this Policy is the authoritative and more detailed description. If you spot an inconsistency you believe is substantive, please tell us at support@lengio.app and we will correct whichever is wrong.

23. Changes to This Policy#

We may update this Policy from time to time to reflect changes to our practices, technology, legal requirements, or for other operational reasons. The "Last updated" date at the top of the page indicates the most recent revision.

For material changes that affect your rights, we will provide additional notice — for example, an in-app message, a prominent notice on this page, or an email to known support contacts — before the change takes effect. Continued use of the Services after the effective date constitutes acceptance of the revised Policy.

24. How to Contact Us#

For any privacy question, request, or complaint, please contact us:

We aim to acknowledge requests within 5 business days and resolve them within 30 days, or sooner where required by law. If you are not satisfied with our response, you may contact your local data-protection supervisory authority.