Privacy Policy
How Nebulingo collects, uses, and protects your personal data.
Last updated: 26 July 2026
1. Who we are
Nebulingo ("we", "us") operates the Nebulingo language-learning platform. For the purposes of the EU/UK General Data Protection Regulation (GDPR) we are the data controller of the personal data described below. If you have any privacy question or wish to exercise your rights, contact us at privacy@nebulingo.com.
2. Data we collect
- Account & profile: username, a securely hashed password, an email address when you provide one, your target and origin languages, and your study preferences.
- Learning data: your progress — words and lessons studied, review history, XP, streaks, exam results and similar study records.
- Session & cookies: a functional session cookie to keep you signed in and, if you tick "Keep me signed in", a persistent login cookie plus a matching server-side record (a random token and its last-used time) valid for up to 30 days; removed when you log out, change your password, or delete your account.
- Activity & security logs: a record of key account events — see Section 4.
- Billing data: if you subscribe to Pro, we and our payment processor process the data needed to take payment and manage your subscription — see Section 5.
- AI interactions (Nova): the messages you send to Nova and related requests — see Section 6.
- Support tickets: if you contact support, the subject, category and messages of your ticket, any files you choose to attach, and the resulting conversation with our team. For a public ticket without an account, we also process the name and email address you provide, a one-time email-verification request, and a keyed hash of your IP address for abuse limits; we do not retain the raw IP in the ticket system. Public attachments are accepted only after verification and only when the administrator has enabled them. Account holders may optionally attach a summary of recent account activity and browser-session errors by ticking the diagnostics box; a copy of exactly what was shared stays downloadable on the ticket.
3. Why we use your data, and our legal bases
- To provide the service (run your account, the spaced-repetition engine, lessons, dashboards) — performance of our contract with you.
- To keep accounts secure and detect abuse (the activity & security logs) — our legitimate interests in the security and integrity of the service and our users.
- To prevent fraud and defend payment disputes and chargebacks (documenting that a subscription existed and was actively used) — our legitimate interests, and the establishment, exercise or defence of legal claims.
- To meet legal and accounting obligations (e.g. tax records for payments) — compliance with a legal obligation.
We do not sell or share your personal data, and we do not use it for advertising or cross-context behavioural profiling.
4. Activity & security logging
To protect your account, investigate security incidents, and defend against fraud and payment disputes, we keep a log of significant account events. This is not surveillance of your every action — we deliberately record only account-level and milestone events, never your individual keystrokes, answers, or page views. Logged events include:
- Security events: sign-in and sign-out (with the IP address and time), failed sign-in attempts, password and email changes, password resets, and turning two-factor authentication on or off.
- Account & billing events: registration, subscription changes and payments, and administrative actions taken on an account.
- Proof of use: completed study sessions and lessons/exams — used to show that a subscriber actively used the service (relevant to payment disputes).
These logs, including IP addresses, are visible only to you (where applicable) and to our administrators, and are never used for advertising, profiling, or geolocation. We keep general security/behavioural logs for up to 12 months, and billing and proof-of-use logs for up to 24 months to cover payment-dispute windows, after which they are automatically deleted.
5. Payments
Pro subscriptions are handled by our payment processor, Paddle, which acts as merchant of record. When you subscribe, your payment details (such as card information) are collected and processed directly by Paddle under Paddle's privacy policy — we never see or store your full card number. We receive and store subscription and transaction metadata (e.g. plan, status, renewal/cancellation dates and processor references) to manage your Pro access, provide receipts, and handle refunds and disputes.
6. AI systems (Nova) & automated decision-making
Nova, our conversation co-pilot, lets you practise your target language through chat. When you message Nova (or request a translation, word explanation, or spoken audio), the text of that request — together with your chosen study language and level — is processed by Google Cloud's Vertex AI (Gemini), acting as our data processor under Google Cloud's data-processing terms, in order to generate the reply. Google does not use this data to train its models. Your chat history is stored in your account so you can resume conversations; you can wipe it at any time by starting a new chat, and it is permanently deleted with your account.
Pronunciation practice uses your browser's built-in speech recognition — your voice audio is handled by your browser and is never sent to or stored on Nebulingo's servers.
No automated decision-making: Nebulingo does not carry out automated decision-making or profiling that produces legal or similarly significant effects concerning you within the meaning of Article 22 GDPR. Our AI features generate practice conversations and learning content only; review scheduling uses FSRS, a deterministic (non-AI) spaced-repetition formula, and exercise answers are checked by literal text comparison.
7. Data retention
We keep your account and learning data for as long as your account is active. Security/behavioural logs are kept up to 12 months and billing/proof-of-use logs up to 24 months (Section 4). Account support tickets are kept while the account is active; after account deletion their text is retained in pseudonymised form for up to 24 months (Section 8) while attached files are deleted immediately. Unverified public-support requests become unusable after the configured verification window (30 minutes by default) and are removed during the next public-support cleanup; cleanup runs whenever the support system is accessed. Verified public tickets, including their name, email and keyed abuse hashes, are deleted with their files after the closed-ticket retention period configured by the administrator (12 months by default). Payment records may be kept longer where required by tax or accounting law. When data is no longer needed for the purpose it was collected for, it is deleted or anonymised.
8. Deleting your account
You can delete your account from your profile's Danger Zone (a 14-day grace period applies, during which you can cancel). When an account is deleted we permanently remove your profile, learning data, chat history and behavioural logs, and any files attached to your support tickets are deleted. As permitted by Article 17(3)(e) GDPR, we retain a minimised set of billing and proof-of-use records, and the text of your support-ticket conversations — with your direct identifiers removed (pseudonymised) — for the limited period needed to defend payment disputes, chargebacks and fraud claims, after which they too are deleted.
9. Cookies
We use minimal functional cookies to keep you signed in and secure. We deploy no third-party advertising or tracking beacons. You can accept or decline non-essential cookies via the cookie banner without affecting core study features.
10. Security
Data is transmitted over encrypted channels (HTTPS) and protected on our servers. Passwords are stored using industry-standard hashing, and two-factor authentication is available for your account.
Bot protection: to keep sign-up, sign-in and support free of automated abuse, these surfaces may present a Cloudflare Turnstile challenge; public ticket intake requires it. Turnstile is operated by Cloudflare, Inc. as our processor: it processes the challenge response and your IP address solely to distinguish people from bots, and we use it in its non-intrusive mode with no advertising cookies. See Cloudflare's privacy policy for details.
11. Your rights
Subject to applicable law, you have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent where we rely on it. Where we process data under legitimate interests (including our security and fraud-prevention logs), you may object based on your particular situation. Some data may be retained where we have an overriding legitimate interest or legal obligation, such as defending a legal claim. You may exercise your rights from your profile settings or by emailing privacy@nebulingo.com. EU/UK users also have the right to lodge a complaint with their data-protection supervisory authority.
12. Users in the United States & elsewhere
Where U.S. state privacy laws apply (such as the California Consumer Privacy Act as amended by the CPRA), you have comparable rights to know, access, correct and delete your personal information, and to be free from discrimination for exercising them. We do not "sell" or "share" personal information as those terms are defined under those laws. Requests can be made at privacy@nebulingo.com. Where the strictest applicable law affords you a stronger protection, that protection applies.
13. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, communicated to you.