1. Who we are
Nebulingo ("we", "us") operates the Nebulingo language-learning platform. For the purposes of the EU/UK General Data Protection Regulation (GDPR) we are the data controller of the personal data described below. If you have any privacy question or wish to exercise your rights, contact us at privacy@nebulingo.com.
2. Data we collect
- Account & profile: username, a securely hashed password, an email address when you provide one, your target and origin languages, and your study preferences — including your timezone (the one your browser reports, or the one you choose in Learning settings), stored so that streaks and daily goals follow your own day; it is included in your data export and deleted with your account.
- Learning data: your progress — words and lessons studied, review history, XP, streaks, exam results, your own answers to "Can you do this now?" at the end of a lesson, and similar study records.
- Session & cookies: a functional session cookie to keep you signed in and, if you tick "Keep me signed in", a persistent login cookie plus a matching server-side record (a random token and its last-used time) valid for up to 30 days; removed when you log out, change your password, or delete your account.
- Activity & security logs: a record of key account events — see Section 4.
- Billing data: if you subscribe to Pro, we and our payment processor process the data needed to take payment and manage your subscription — see Section 5.
- AI interactions (Nova): the messages you send to Nova and related requests — see Section 6.
- Support tickets: if you contact support, the subject, category and messages of your ticket, any files you choose to attach, and the resulting conversation with our team. For a public ticket without an account, we also process the name and email address you provide, a one-time email-verification request, and a keyed hash of your IP address for abuse limits; we do not retain the raw IP in the ticket system. Public attachments are accepted only after verification and only when the administrator has enabled them. Account holders may optionally attach a summary of recent account activity and browser-session errors by ticking the diagnostics box; a copy of exactly what was shared stays downloadable on the ticket.
- In-app notifications: the notification type, title, message, internal destination, item count, creation time and read time for account, support and operational events relevant to you.
- Administrator external-API records: if an administrator issues a machine credential, we retain its non-secret label, scopes, allowed languages, configured IP allowlist, actor, status and timestamps, plus bounded claim and security-event metadata. We never retain the bearer validator, prompts, model replies, request bodies or request-source IP addresses in these API tables.
3. Why we use your data, and our legal bases
- To provide the service (run your account, the spaced-repetition engine, lessons, dashboards) — performance of our contract with you.
- To improve our lessons — we look at learning data in aggregate, for example how learners rate what they can do after a lesson against how they did on its exercises — our legitimate interest in making the lessons better.
- To keep accounts secure and detect abuse (the activity & security logs) — our legitimate interests in the security and integrity of the service and our users.
- To prevent fraud and defend payment disputes and chargebacks (documenting that a subscription existed and was actively used) — our legitimate interests, and the establishment, exercise or defence of legal claims.
- To meet legal and accounting obligations (e.g. tax records for payments) — compliance with a legal obligation.
We do not sell or share your personal data, and we do not use it for advertising or cross-context behavioural profiling.
4. Activity & security logging
To protect your account, investigate security incidents, and defend against fraud and payment disputes, we keep a log of significant account events. This is not surveillance of your every action — we deliberately record only account-level and milestone events, never your individual keystrokes, answers, or page views. Logged events include:
- Security events: sign-in and sign-out (with the IP address and time), failed sign-in attempts, password and email changes, password resets, and turning two-factor authentication on or off.
- Account & billing events: registration, subscription changes and payments, and administrative actions taken on an account.
- Proof of use: completed study sessions and lessons/exams — used to show that a subscriber actively used the service (relevant to payment disputes).
These logs, including IP addresses, are visible only to you (where applicable) and to our administrators, and are never used for advertising, profiling, or geolocation. We keep general security/behavioural logs for up to 12 months, and billing and proof-of-use logs for up to 24 months to cover payment-dispute windows, after which they are automatically deleted.
For the administrator-only external generation API, bounded API events are kept for up to 180 days, terminal claim metadata for up to 90 days, request-idempotency records for up to 24 hours, and short fixed-window counters only as long as operationally needed. These records contain identifiers, operation and language, byte/item counts, outcomes, timings and lease state, but no prompt, reply, bearer material, raw request body or application-level IP address.
5. Payments
Pro subscriptions are handled by our payment processor, Paddle, which acts as merchant of record. When you subscribe, your payment details (such as card information) are collected and processed directly by Paddle under Paddle's privacy policy — we never see or store your full card number. We receive and store subscription and transaction metadata (e.g. plan, status, renewal/cancellation dates and processor references) to manage your Pro access, provide receipts, and handle refunds and disputes.
6. AI systems (Nova) & automated decision-making
Nova, our conversation co-pilot, lets you practise your target language through chat. When you message Nova (or request a translation, a word explanation, or the spoken audio of Nova's replies), the text of that request — together with your chosen study language and level — is processed by Google Cloud's Vertex AI (Gemini), acting as our data processor under Google Cloud's data-processing terms, in order to generate the reply. Google does not use this data to train its models. Your conversations with Nova are stored in your account so you can resume them: up to 20 of them, each deleted automatically after at most 30 days without use, and when you start one beyond that limit, the conversation you used least recently is removed first. You can delete any conversation at any time, and all of them are permanently deleted with your account; only the date and time of your first message to Nova (not its content) is kept as a study record after a conversation is deleted.
Pronunciation practice uses your browser's built-in speech recognition — your voice audio is handled by your browser and is never sent to or stored on Nebulingo's servers.
Administrators may use Nebulingo's authenticated external work API to have a machine client author bounded learning content under a scoped, per-language grant. Nebulingo exposes only the exact contracted work items to that authorised client and does not proxy the provider call or retain its prompt or reply. The client submits its validated result back to Nebulingo, where it is held as a draft until a human administrator approves it in Content Review — no machine-submitted content becomes part of the product without that review. The administrator operating that client is responsible for using an approved provider and secret-management process.
Learning content in Nebulingo's dictionary and lessons (such as definitions, example sentences and exercises) is authored with the help of AI model providers selected by our administrators — Google Cloud's Vertex AI (Gemini), OpenAI, or models accessed through OpenRouter, Inc. (which routes the request to the model's host — such as OpenAI, Google or Microsoft Azure — and does not retain its content) — each acting as our data processor under its respective data-processing terms. These generation requests contain only the language-learning material being authored (words, sentences and lesson structures); they never include your personal data, account information, learning history or chat messages. All machine-generated content is reviewed by a human administrator before it becomes part of the product. Spoken audio for dictionary words and lessons, and pictures for words, may be produced by the same providers, or by speech and image models reached through OpenRouter and hosted by providers such as DeepInfra; these requests contain only the words, sentences or picture descriptions being voiced or illustrated — never your personal data. Nova chat, including the spoken audio of Nova's replies, is processed exclusively by Google Cloud's Vertex AI as described above and is not affected by this provider selection.
No automated decision-making: Nebulingo does not carry out automated decision-making or profiling that produces legal or similarly significant effects concerning you within the meaning of Article 22 GDPR. Our AI features generate practice conversations and learning content only; review scheduling uses FSRS, a deterministic (non-AI) spaced-repetition formula, and exercise answers are checked by literal text comparison.
7. Data retention
We keep your account and learning data for as long as your account is active. Read in-app notifications are kept for up to 90 days and unread notifications for up to 180 days. Nova conversations are kept for at most 30 days after their last use, and at most 20 per account (Section 6). Security/behavioural logs are kept up to 12 months and billing/proof-of-use logs up to 24 months (Section 4). Account support tickets are kept while the account is active; after account deletion their text is retained in pseudonymised form for up to 24 months (Section 8) while attached files are deleted immediately. Unverified public-support requests become unusable after the configured verification window (30 minutes by default) and are removed during the next public-support cleanup; cleanup runs whenever the support system is accessed. Verified public tickets, including their name, email and keyed abuse hashes, are deleted with their files after the closed-ticket retention period configured by the administrator (12 months by default). Payment records may be kept longer where required by tax or accounting law. When data is no longer needed for the purpose it was collected for, it is deleted or anonymised.
The external-API retention periods in Section 4 apply independently of the longer security and proof-of-use periods above.
8. Deleting your account
You can delete your account from your profile's Danger Zone (a 14-day grace period applies, during which you can cancel). When an account is deleted we permanently remove your profile, learning data, chat history, in-app notifications and behavioural logs, and any files attached to your support tickets are deleted. As permitted by Article 17(3)(e) GDPR, we retain a minimised set of billing and proof-of-use records, and the text of your support-ticket conversations — with your direct identifiers removed (pseudonymised) — for the limited period needed to defend payment disputes, chargebacks and fraud claims, after which they too are deleted.
Scheduling account deletion immediately revokes that account's Operator API credentials. Final deletion removes those credentials and their ephemeral claim, rate and idempotency state.
9. Cookies
We use minimal functional cookies to keep you signed in and secure. We deploy no third-party advertising or tracking beacons. You can accept or decline non-essential cookies via the cookie banner without affecting core study features. Your answer is stored in your browser together with the version of this policy it was given under; if we change the policy in a way that needs your answer again, the banner asks again.
9a. Anonymous usage counters
Our dictionary word pages are readable without an account. So that we can tell whether they are useful, we keep a small set of daily counters — for example, how many times a given word page was read, how many readers arrived from a search engine, and how often a pronunciation clip was unavailable. These counters record no IP address, no visitor or device identifier, no cookie, no account and no time of day: each entry is only a running total for one day, so it cannot be linked to you, to a session, or to a sequence of pages. Because nothing in them identifies anyone, they are not personal data and there is nothing in them for a deletion request to remove.
We keep counters of the same shape for a small number of other public moments — for example, that somebody began filling in the registration form. They record no more than the counters above: a running daily total, with nothing recording who, when within the day, or in what order. We use them to see where people get stuck before they finish signing up. Likewise, while we are testing the homepage it shows one of two headlines at random on each visit, and for each headline we count how many times it is shown, how often a sign-up link on that page is pressed, and how many sign-ups it leads to start or finish — daily totals only, with no identifier and no cookie. So that a sign-up counts towards the headline you saw, your browser tab remembers which one it was (a single letter that disappears when you close the tab). To stop any of these counters being flooded, each counted moment also passes a short-lived abuse limit keyed to a one-way hash of your IP address, which is deleted within a day.
If you create an account after reading a word page, we store a short label on your account recording which surface you came from (for example "dictionary, Spanish"). It is a category, never a web address or a search term, and it is included in your data export. The marker that carries it lives only in your browser tab and disappears when you close it.
10. Security
Data is transmitted over encrypted channels (HTTPS) and protected on our servers. Passwords are stored using industry-standard hashing, and two-factor authentication is available for your account.
Bot protection: to keep sign-up, sign-in and support free of automated abuse, these surfaces may present a Cloudflare Turnstile challenge; public ticket intake requires it. Turnstile is operated by Cloudflare, Inc. as our processor: it processes the challenge response and your IP address solely to distinguish people from bots, and we use it in its non-intrusive mode with no advertising cookies. See Cloudflare's privacy policy for details.
11. Your rights
Subject to applicable law, you have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent where we rely on it. Where we process data under legitimate interests (including our security and fraud-prevention logs), you may object based on your particular situation. Some data may be retained where we have an overriding legitimate interest or legal obligation, such as defending a legal claim. The self-service JSON export in your profile covers your account, learning, support, notification, subscription, service-usage and non-secret Operator API data; it excludes security credentials, other people’s data and internal administrative records. You may make a broader access request, or exercise any other right, by emailing privacy@nebulingo.com. EU/UK users also have the right to lodge a complaint with their data-protection supervisory authority.
12. Users in the United States & elsewhere
Where U.S. state privacy laws apply (such as the California Consumer Privacy Act as amended by the CPRA), you have comparable rights to know, access, correct and delete your personal information, and to be free from discrimination for exercising them. We do not "sell" or "share" personal information as those terms are defined under those laws. Requests can be made at privacy@nebulingo.com. Where the strictest applicable law affords you a stronger protection, that protection applies.
13. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, communicated to you.