At a glance. Lengio is built privacy-first. Your vocabulary, photos, and study progress stay on your device. An account is optional — nothing in the App requires one — and we run no advertising SDKs, sell no data, and do not track you across other companies' apps and websites.
The App does record anonymous usage events — which screens you open, which lessons you finish — so we can see what is worth building next. They carry no name, no email, no advertising identifier, no IP address and no location, and you can switch them off in Settings. Optional AI features run on our servers only when you choose to use them.
Four things we want to be precise about rather than flattering, because each of them is a place where the simple version of this sentence would be wrong:
What changed on 12 September 2026. This revision (a) discloses the purchase identifier described above, which the previous version did not mention; (b) discloses the Interests field, which the previous version did not mention, and records that the App stopped sending your name to the AI provider; (c) corrects the claim that the anonymous install identifier is always fresh after a reinstall, which was wrong on Android; (d) adds Section 4.6 and Section 15 covering the optional account — email address, sign-in tokens and subscription status — which is being introduced in the next release of the App; and (e) rewrites Section 11 as explicit retention periods. Points (a) and (b) describe behaviour that was already happening and should have been disclosed here sooner; we are saying so rather than quietly folding them in.
This Privacy Policy ("Policy") describes how Lengio ("Lengio", "we", "us", or "our") processes information when you use the Lengio mobile application for iOS and Android (the "App") or visit the Lengio website at lengio.app (the "Site"), collectively the "Services".
This Policy applies to all users of the Services worldwide, with additional disclosures for residents of specific regions (see Region-Specific Disclosures). Where the App behaves differently on iOS and on Android, this Policy says so explicitly rather than describing only the more favourable case. It does not apply to third-party services you reach through links inside the Services — those are governed by their own privacy policies.
By using the Services you confirm you have read and understood this Policy. If you do not agree, please do not use the Services.
The Services are operated by Nexios Media LLC, a limited liability company organised under the laws of the State of Illinois, United States, trading as "Lengio" (nexios-media.com).
Nexios Media LLC maintains a registered agent in Illinois as required by state law, through whom formal service of process may be made. For every other purpose — including notices under this document, privacy requests, and support — please use support@lengio.app, which we monitor and which is the fastest way to reach a person.
For the purposes of the EU/UK General Data Protection Regulation, similar laws, and CCPA/CPRA, that company is the data controller (or "business") responsible for the limited information we process. You can reach us at support@lengio.app for any privacy-related question, request, or complaint.
We have not appointed a statutory data protection officer because the nature and scale of our processing does not require one, but the contact above is monitored by a person with responsibility for privacy matters.
We have intentionally designed Lengio to collect as little personal information as possible. The categories below describe everything we receive.
The purchase identifier — stated plainly, because it is the one identifier that persists. The App generates a random identifier of its own the first time you buy something, and attaches it to the transaction: to Apple as appAccountToken, and to Google as obfuscatedAccountId. It is a random UUID. It is not derived from you, your device, your Apple Account, your Google Account, your email address, or your payment details, and on its own it identifies nobody — but it is stable, and it is the only durable thing the App creates that leaves your device.
Why it exists: without it, a purchase and a person cannot be reunited. Neither store lets it be added to a transaction after the fact, so if it is missing at the moment of purchase it is missing forever, and a subscriber who changes phone or loses a device has no way to prove the purchase was theirs. That is the problem it solves, and it is the only thing we use it for.
Three consequences we would rather state than have you discover:
If you want it gone, the only way is to remove the App and, on Android, to delete Lengio's data from your Google backup. We will also delete our copy on request, on the understanding described in Section 15 — that doing so may make a past purchase unrecoverable.
Which versions. This identifier is introduced in the release of the App that accompanies this revision of the Policy, alongside the optional account in Section 4.6. Purchases made with earlier versions carry no such identifier and cannot be given one retrospectively — neither store permits it — which is the reason it is being introduced now rather than later.
The App records a small number of anonymous usage events so we can see which features are worth building and where people get stuck. This is our own pipeline, running on servers we operate. There is no third-party analytics SDK, no advertising SDK, and no advertising identifier anywhere in the App on either platform.
Each stored event contains only:
iPhone16,1 or Pixel 8 — the same string for millions of devices).Event names are things like app_open, lesson_complete, paywall_view and purchase_success. We do not record the words you study, anything you type, anything you say, your photos, or the content of AI conversations.
A correction, September 2026 — what a reinstall actually does. Until this revision, this section said that deleting and reinstalling the App always produces a new install identifier and that we have no way to connect the two. On iPhone that holds for an ordinary delete-and-reinstall, though restoring a whole device from an iCloud backup does carry the old identifier across. On Android it was simply wrong. The identifier is held in the App's preferences, and Google's Auto Backup includes those preferences, so reinstalling Lengio — or setting up a new Android phone from your old one — restores the identifier you already had rather than minting a fresh one. We had not noticed; we are correcting it rather than leaving a comfortable sentence standing. The practical effect is that on Android a returning install may be counted as the same install, which is a slightly better statistic and a slightly weaker privacy claim than we were making. Nothing else about these events changed, and the switch in the next paragraph still stops them completely. We are keeping the current behaviour — turning it off would put the identifier outside your control of your own backup — and we have restated the retention argument in Section 11 so that it no longer rests on the sentence we have just withdrawn.
Being an identifier that can persist across a reinstall is, for what it is worth, the ordinary condition of anything inside your own device backup. We accept the accuracy cost of not adding anything else to these events, which is why there is nothing here to correlate the identifier against.
Your IP address is not stored. Our servers necessarily receive it in order to answer the request, as every web server does, but it is never written to the analytics archive. We do not record your country, region, or any other location. We removed the country field in July 2026 specifically so that this sentence would be true.
You can turn this off. Open the App → Settings → Share Usage Data. Switching it off stops collection immediately and discards anything still waiting to be sent from your device. Every feature behaves identically either way — nothing is withheld from you for opting out.
If you choose to use the AI Chat Coach (described on our website as the AI Speech Partner), the App captures audio from your microphone only while the feature is active and converts it to text. What happens to that audio depends on your platform, and we describe both cases exactly.
In neither case do we receive or store your audio. Lengio's servers receive only the resulting text.
The Interests field. Settings → Profile contains a free-text box labelled Interests, where you can list hobbies or topics you enjoy. If you fill it in, that text is sent to the AI provider with every Chat Coach message, including the coach's opening line, so the conversation can steer toward things you actually care about. It is truncated to a few hundred characters and it is sent exactly as you typed it. Nothing else in Settings is transmitted this way. If you would rather it were not sent, clear the box: an empty field is omitted entirely, and the feature works without it.
The App also used to send the name you entered during setup in the same place, so the coach could greet you by it. We removed it. A first name is personal data with no teaching value the coach cannot get another way, and it should not have been going to a third party to produce a nicety. The code that sent it was deleted from both apps on 11 September 2026; every release published after that date omits it, and if you are running an older release it is still being sent until you update. The name is still used for greetings inside the App, where it never leaves your device. We are recording the change here rather than silently benefiting from it.
Please do not speak or type personal, confidential, financial, health, or otherwise sensitive information about yourself or anyone else into the AI Chat Coach — and in particular, please do not put anything in the Interests box that you would not want sent to an AI provider with every message.
You can replace the picture on any vocabulary card. Tapping the picture offers Choose Photo, which uses your own photo library and sends nothing anywhere, and Search Images, which opens Google Image Search inside an in-app browser.
If you use Search Images, your search term — the word you are studying — goes to Google directly, along with your IP address, under Google's own privacy policy. We do not see the search or the results, and the image you pick is saved only on your device.
Lengio is introducing an optional account in the release of the App that accompanies this revision. Its only purpose is that a new phone means signing in rather than starting again, and that a Lengio Plus subscription can be recognised as yours on it. Nothing in the App requires an account — every lesson, every language, every feature and every purchase works exactly as before if you never create one, and the setup screen that offers it can be skipped with a single tap.
There is no password. You sign in either with Apple or Google, or by typing an email address and entering a six-digit code we send to it. We hold no password, so there is no password to lose, reset, or breach.
If you create one, this is everything the account record contains:
What the account does not contain. It holds no study progress, no words, no lesson history, no photos, no Chat Coach conversations and no audio. Those stay on your device exactly as described in Section 5. Creating an account does not upload your learning data to us, and we are not building a sync service; if we ever do, it will be described here before it exists, not after.
Where it lives. In a small database we operate on Cloudflare's infrastructure in the United States, and nowhere else. The sign-in emails are delivered by Zoho's ZeptoMail, also in the United States. Both are listed in Section 9 and covered by Section 13.
On your device, the sign-in tokens are held in the iOS Keychain or the Android Keystore, are readable only after you have unlocked the device at least once since it booted, and are deliberately excluded from iCloud and Google backup and from phone-to-phone transfer — a session copied onto a second device is a second person signed in as you, with no way for you to see it or stop it. This is the exact opposite of how the purchase identifier is treated, and the difference is intentional.
Emails we will send you. A sign-in code when you ask for one; a notice when you request account deletion and again when it is executed; and, if you switch it on, a notice when your account is used to sign in on a new device. That is the complete list. We do not send marketing email and there is nothing to unsubscribe from.
Deleting the account is described in Section 15 and at lengio.app/delete-account.
The following information lives on your device only and is never transmitted to us. Operating-system encryption and application sandboxing apply on both iOS and Android.
Platform backup and sync. There is no copy of your study progress on any server we control, and the optional account in Section 4.6 does not change that — it holds who you are and what you have paid for, never what you have learned. We operate no server-side sync of your progress. Where your progress leaves your device, it does so through your platform's own backup service, under your own account with Apple or Google:
Both stores belong to Apple and Google respectively and are tied to your account with them. We have no access to either, and neither is operated by us. Progress does not transfer between iOS and Android.
Two items in those backups are handled deliberately rather than by default, and both are described above: the purchase identifier is kept inside them on purpose (Section 4.2), and account sign-in tokens are kept out of them on purpose (Section 4.6). On Android, the anonymous install identifier is inside them as a side-effect of where it is stored, which is the correction in Section 4.3.
The limited information we collect is used for the following purposes only:
We do not use your information for advertising, profiling, automated decision-making producing legal or similarly significant effects, or to train external machine-learning models.
If you are in the European Economic Area, United Kingdom, Switzerland, or any region with similar law, we rely on these legal bases under Article 6 GDPR (or its local equivalent):
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
We do not sell or rent personal information. We do not share information with advertisers. We share information only with the parties below, and only as needed to operate the Services or comply with law:
The Services rely on the third parties below. We disclose them so you can review their practices independently:
We integrate no third-party advertising SDKs, third-party analytics SDKs, marketing pixels, or session-replay tools inside the App on either platform. The only usage data collected by us is the first-party, anonymous event stream described in Section 4.3, which goes to servers we operate and is shared with nobody.
The Site is a static website that does not set marketing or analytics cookies. Your browser may use functional storage (e.g. cache) as part of normal operation. The App does not use web cookies for its own purposes because it is a native mobile application; the in-app browser used by the optional image search is a standard system browser component and is subject to that browser's and Google's own cookie practices.
Our hosting provider may set short-lived security cookies (e.g. to mitigate denial-of-service attacks). These are strictly necessary and exempt from consent under the ePrivacy framework.
Article 13(2)(a) GDPR requires us to tell you the period for which each kind of personal data is stored, or the criteria used to decide it. Here are all six, with the actual periods rather than “as long as necessary”:
Backups. The account database keeps an automatic rolling 30-day point-in-time history so that we can recover from a failure or a mistake. Data you have deleted may still exist inside that window. It is never restored back into the live service, and it ages out on its own within 30 days. The grace period in line 2 and this window are deliberately the same length, so that by the time a deletion is final the oldest recoverable copy is already expiring.
Product-analytics events — the one thing with no period, and the argument for it. The raw event archive is append-only by design: written once, never modified, never deleted. Summaries are lossy, and a question nobody thought to ask on day one is unanswerable if only summaries were kept. These events carry no name, no email address, no account identifier, no IP address, no location and no device identifier — only the random install identifier in Section 4.3, which we do not join to anything and which the App never displays, so we hold nothing that could locate a person inside the archive. On that basis we treat the archive as anonymous rather than as personal data and apply no deletion schedule.
The previous version of this Policy also leaned on the claim that the identifier is replaced on every reinstall. That claim was wrong on Android and we have withdrawn it, so it is worth saying that this argument does not depend on it. The identifier persisting across a reinstall makes the archive slightly better at counting returning installs; it does not make the archive identify anybody, because there is still nothing in it, and nothing we hold elsewhere, that maps an identifier to a person. If you would rather these events did not exist at all, turn off Settings → Share Usage Data, which stops collection immediately and discards whatever is still queued on your device.
We use technical and organisational measures appropriate to the nature of the data we process. These include:
No method of transmission or storage is 100% secure. We cannot guarantee absolute security. If we discover a breach affecting personal information we will notify you and any regulator as required by law.
Lengio operates internationally and is established in the United States. When you contact us by email, when you use the AI Chat Coach, when you create an account, and when our service providers process server logs, your information may be transferred to and processed in the United States and in other countries outside your country of residence, including jurisdictions that may not provide the same level of data-protection law as your own.
To be specific rather than general about the account: the account database is in the United States (Cloudflare's Eastern North America region) and the sign-in emails are sent from the United States (Zoho's US data centre). We considered pinning the database to the EU and decided against it, because your email address — the primary identifier — passes through the US mail provider on every sign-in regardless, so an EU-pinned database would have split the data across two jurisdictions rather than keeping it in one. The GDPR imposes no residency requirement; it imposes the safeguards below, which apply either way. We would rather tell you the real reason than present a split as a protection.
Where required, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and adequacy decisions. A copy of the safeguards used is available on request from support@lengio.app.
Subject to local law, you may have the following rights regarding your personal information. Because most data stays on your device, you can exercise many of these yourself directly inside the App.
If you have an account, every right above applies to it in full and most of them are self-service: your email address, name and languages are visible and editable in Settings → Account; “sign out all devices” revokes every session; and Delete Account is in the same place. Ask us at support@lengio.app for a machine-readable export of your account record and we will send it. Deletion is described in Section 15.
A note on usage analytics — restated, because the previous version's reasoning contained a claim we have since withdrawn. The events described in Section 4.3 are keyed only to a random install identifier. We do not join it to your email address, your account, your purchases, your device, or your Apple or Google account, nothing in the archive carries any of those, and the App does not display the identifier, so you cannot tell us which one is yours and we cannot work it out. We therefore cannot locate "your" events in order to export or delete them, and Article 11 GDPR does not oblige us to start collecting additional information about you for the sole purpose of being able to.
That argument used to be supported by a second claim — that a reinstall always produces a fresh identifier — which was wrong on Android (Section 4.3). We have withdrawn it, and it is worth being explicit that the argument does not need it: an identifier that survives a reinstall is still an identifier that points at nothing we hold. If you disagree with that reasoning, tell us at support@lengio.app and we will engage with it rather than restate it. And if you would rather these events were not collected at all, turn off Settings → Share Usage Data. Every other right in this section applies in full to information that does identify you — your account, your purchases, and your support email.
To make a request, email support@lengio.app with the subject line "Privacy Request". We may need to verify your identity (for example, by replying from the email address on your account, or the one you used when contacting us) before responding. We will respond within the statutory time frame applicable to you (typically 30 days, extendable as permitted by law).
There are two separate things you may want to delete, and they are not the same thing. The full, standalone instructions — including the route for someone who no longer has the App installed — are at lengio.app/delete-account, which requires no sign-in to read or to act on. In short:
Your words, streaks, statistics, saved content and settings live on your device. Settings → Erase All My Progress clears them; uninstalling Lengio removes them along with the App. We never held a copy, so there is nothing for us to delete. If your device backs up to iCloud or to your Google account, a copy may remain in that backup until you remove it there — and on Android, the anonymous install identifier is one of the things that comes back from it (Section 4.3).
In the App: Settings → Account → Delete Account. Without the App: email support@lengio.app with the subject "Delete my Lengio account", preferably from the address on the account, which is how we confirm the request is yours. We ask for nothing else — no password, no payment detail, no identity document.
Either way: you are signed out immediately and the account can no longer sign in anywhere; there is a 7-day grace period in which signing in again cancels the deletion; and after that it is executed and cannot be reversed. We email you when it is requested and again when it is executed. Requests made by email are acknowledged within 5 business days and completed within 30 days, usually the same day.
What is erased: your email address and any Apple relay address, your name, your languages, interface language and time zone, every linked sign-in identity, the Apple refresh token — used first to tell Apple to revoke the link, so Lengio stops appearing in your Apple Account settings — every session on every device, and any unused sign-in codes.
What survives, and why: the purchase and subscription records in line 4 of Section 11, for the seven years tax and consumer-protection law require, carrying no name and no email address once the account is gone; and a line in the security log recording that an account with a given internal identifier was deleted and when, which by construction contains no personal data at all. Data already deleted may persist in the 30-day recovery history described in Section 11 and is never restored into the live service.
Deleting your account does not cancel a paid subscription, and we cannot cancel one for you — only Apple or Google can. If you are subscribed, cancel there first: iPhone, Settings → your name → Subscriptions; Android, Play Store → Payments & subscriptions → Subscriptions. Deleting the account may also make a past purchase harder to restore, because the identifier in Section 4.2 is how a purchase is recognised as yours on a new device.
If you are a California resident, the California Consumer Privacy Act (as amended by the California Privacy Rights Act) gives you specific rights. The categories of personal information we collect are: identifiers (your email address when you contact us or create an account; your first name; the random purchase identifier in Section 4.2), internet or other network activity (server logs, and the anonymous in-app usage events in Section 4.3), commercial information (purchase and subscription records from Apple and Google), and other information you choose to provide (the Interests text, and anything you write to support). We do not collect sensitive personal information — including precise or coarse geolocation, government identifiers, account log-in credentials, biometric information, or the contents of your communications — as CPRA defines it. We retain each category for the periods in Section 11.
We have not sold or shared personal information for cross-context behavioural advertising in the past 12 months and have no intention to do so. We do not use or disclose sensitive personal information for purposes that would require us to offer a "Limit the Use of My Sensitive Personal Information" link.
You may exercise California rights — to know, delete, correct, opt out of sale/share, and not be retaliated against — by emailing support@lengio.app. An authorised agent may make a request on your behalf with written authorisation.
Shine the Light. California Civil Code § 1798.83 permits California residents to request information about disclosure of certain categories of personal information to third parties for direct-marketing purposes. We do not disclose information for such purposes.
The legal bases on which we process personal information are described in Section 7. You have the GDPR rights described in Section 14. You also have the right to lodge a complaint with your local supervisory authority. We are not currently required to appoint an EU/UK representative under Article 27 GDPR; if this changes we will list the representative here.
Brazilian users have rights equivalent to those described in Section 14 under Lei Geral de Proteção de Dados. Email support@lengio.app to exercise them.
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Iowa (ICDPA), Tennessee (TIPA), Indiana (INCDPA), New Jersey (NJDPA), Delaware (DPDPA), New Hampshire (NHDPA), and other states with consumer-privacy laws have rights of access, deletion, correction, portability, and opt-out of targeted advertising or sale. We do not engage in targeted advertising or the sale of personal information. To exercise other rights, email support@lengio.app.
Where local law gives you additional rights — for example the Australian Privacy Principles or Canadian PIPEDA — we will honour them. Contact us for specifics.
Because the App has a speech feature and because we are established in Illinois, we state this as plainly as we can:
We do not collect, capture, purchase, receive through trade, store, use, disclose, redisclose, disseminate, sell, lease, trade, or otherwise profit from any biometric identifier or biometric information — including any voiceprint, retina or iris scan, fingerprint, hand geometry, or scan of face geometry — as those terms are defined by the Illinois Biometric Information Privacy Act (740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act, the Washington biometric privacy statute, or any comparable law.
Specifically: the AI Chat Coach uses your device's speech-to-text service to obtain a transcript. It does not create, derive, or store a voiceprint or any biometric template, and it does not identify or attempt to identify you from your voice. We never receive the audio itself on either platform (see Section 4.4). Any audio buffer used by the operating system's recognition service is handled by Apple or Google under their own policies and is not retained by us. Nothing in the App performs facial recognition on photos you attach to vocabulary cards; those photos are never transmitted to us at all.
If this ever changes, we will obtain any written release required by law and publish a retention and destruction schedule before enabling the feature.
The Services are not directed to children under the age of 13 (or the equivalent minimum age in your jurisdiction — 14 in Spain, 15 in the Czech Republic and France, 16 in Germany and the Netherlands, and similar national variants under GDPR Article 8). We do not knowingly collect personal information from children below those ages, and the App is not listed in a children's or family programme on either store.
Lengio carries an age rating on the App Store and a content rating on Google Play appropriate to general audiences, and contains no objectionable content, but parents are responsible for supervising their child's use — in particular of the AI Chat Coach, which generates its replies automatically and is not moderated by a human, and of the in-app image search, whose results come from Google rather than from us. If you believe a child has provided us with personal information, please email support@lengio.app and we will delete it promptly.
Lengio lets you attach personal photos to vocabulary entries. These photos remain on your device. We have no access to them and they are not transmitted to our servers. If you choose to share screenshots with our support team, the images become part of your support correspondence and are governed by this Policy.
We strongly discourage including sensitive personal information (e.g. images of identification documents, payment cards, health records) in support correspondence, or speaking or typing it into the AI Chat Coach. If you do send it to support, we will treat it confidentially and delete it once your inquiry is resolved.
The App may send local notifications (e.g. daily study reminders). These are scheduled and delivered entirely on your device by the operating system based on settings you control. We do not see when notifications are delivered or opened. You may disable notifications at any time — on iOS in Settings → Notifications → Lengio, and on Android in Settings → Apps → Lengio → Notifications.
Email from us. We do not send marketing emails, run no mailing list, and there is nothing to unsubscribe from. We will reply to support correspondence you initiate, and may send transactional emails strictly necessary to resolve an inquiry. If you create an account we will also send the account emails listed in Section 4.6 — a sign-in code when you ask for one, a notice when account deletion is requested and again when it is executed, and, only if you switch it on, a notice when your account signs in on a new device. Those cannot be turned off individually while you have an account, because each of them is either something you asked for or something you need to see, but deleting the account ends them all.
Because neither the Site nor the App tracks you across other companies' apps or websites, Do-Not-Track signals (DNT) and Global Privacy Control (GPC) have no behavioural effect. We honour these signals where they are legally required by treating them as a valid opt-out of any future sale or share of personal information.
The equivalent control for the App's own anonymous usage events is the Share Usage Data switch described in Section 4.3.
Apple requires app developers to publish "App Privacy" labels on the App Store, and Google requires a "Data safety" section on Google Play. Those summaries are generated to each store's own categories and format, which are coarser than this Policy.
We maintain both to be consistent with this Policy. Where a store summary and this Policy appear to differ, the difference is a matter of the store's categories rather than of our practice, and this Policy is the authoritative and more detailed description. If you spot an inconsistency you believe is substantive, please tell us at support@lengio.app and we will correct whichever is wrong.
We may update this Policy from time to time to reflect changes to our practices, technology, legal requirements, or for other operational reasons. The "Last updated" date at the top of the page indicates the most recent revision.
For material changes that affect your rights, we will provide additional notice — for example, an in-app message, a prominent notice on this page, or an email to known support contacts — before the change takes effect. Continued use of the Services after the effective date constitutes acceptance of the revised Policy.
For any privacy question, request, or complaint, please contact us:
We aim to acknowledge requests within 5 business days and resolve them within 30 days, or sooner where required by law. If you are not satisfied with our response, you may contact your local data-protection supervisory authority.
Disclaimer. This Policy is provided in good faith and reflects our practices as of the effective date above. It is not legal advice. Where translation conflicts with the English original, the English version controls. If a provision is held unenforceable, the remaining provisions remain in full effect.