Privacy Policy
Last updated: October 1, 2026
Gem Lingua is a mobile language-learning app. This policy explains what information we collect, why we use it, and how users can request deletion of their account data.
Information we collect
- Account identity information when you sign in, such as email address, display name, profile photo URL, and provider user ID.
- Learning activity, including selected language, lesson progress, vocabulary, review history, settings, daily goal target, server-recorded focused-study time and time zone, and account status. Focused-study time is counted while you actively use learning screens or listen to learning audio; idle and background time is excluded.
- An app-generated installation identifier, stored on your device and sent to our API to link settings and learning activity when you are signed out.
- Basic technical information needed to operate the app, such as app version, device platform, API requests, diagnostics, and error details, including reports you choose to submit.
- Account-linked product usage records needed to operate and improve learning features, such as content opened and learning activity. Android build 961 and later and the current Flutter and native iOS builds do not enable Google Analytics for Firebase.
- Google, Facebook and (in native iOS releases offering Sign in with Apple) Apple sign-in identifiers and technical information needed for authentication. Automatic Facebook app-event logging and advertising-ID collection are disabled in Android build 961 and later and in the current Flutter and native iOS builds. Sign-in SDKs still process authentication and technical metadata; an upgrade from an earlier build may send previously queued events or an SDK settings-change event.
- Issue reports and other information you choose to submit, including the description and learning context of a reported problem.
- If you enable review reminders, a Firebase Cloud Messaging device token, time zone, language preference, and chosen reminder time so we can send a daily notification when saved words are due.
How we use information
- To sign you in and keep your learning progress synced across devices.
- To provide lessons, vocabulary review, audio, news, and other learning features.
- To maintain security, prevent abuse, debug errors, and improve app reliability.
- To understand product usage and improve the app experience.
- To deliver optional vocabulary review reminders at your chosen local time when words are ready.
Services that process information
Google Sign-In, Facebook Login and Sign in with Apple process sign-in information under their own policies. Firebase Authentication brokers Facebook sign-in and Apple sign-in in native iOS releases offering it; automatic usage-event logging is disabled in Android build 961 and later and in the current Flutter and native iOS builds. Earlier builds and upgrade-related SDK events may still have supplied technical or usage information to those providers. Firebase Cloud Messaging processes an app device token and notification delivery data when you enable review reminders. The reminder text does not include your saved words. Our API, database, storage and hosting providers process account data, learning activity, network addresses and operational diagnostics to deliver the service. Opening external content may send network/device information to the publisher or media host. These services may infer an approximate region from a network address and apply their own security, analytics or advertising policies.
Support and deletion emails are forwarded by Cloudflare Email Routing to a Gmail inbox monitored by the app operator. Those providers process message content and email addresses for delivery and storage.
Read Google’s privacy policy, Meta’s privacy policy, Apple’s privacy policy, Cloudflare’s privacy policy and how Google uses information from apps using its services.
Security and retention
Our application API, sign-in connections, and public media requests use HTTPS. Legacy podcast media is exposed only after a secure destination has been verified; public cleartext connections are blocked by Android build 961 and later. Account operations require server-verified authentication; the app stores its session in platform secure storage. Account-linked data is kept while the account is in use until deletion. Reminder registrations are removed when you turn reminders off or delete your account; the app also requests removal when you sign out. Anonymous device-linked settings and activity can also be stored to operate signed-out learning.
Confirmed in-app deletion removes account-linked records from the active application database. Restricted backups and operational logs may retain earlier records until rotation; deletion does not instantly erase backup copies. Firebase sign-in records held for Gem Lingua are queued for refresh-token revocation and deletion automatically. Provider outages are retried until cleanup succeeds. Your Google, Facebook or Apple account and the providers’ independently held login/security records are not deleted. Contact us for assistance with earlier device-linked analytics or signed-out activity.
We do not sell personal information. Authentication SDKs may retain provider sessions on your device until sign-out; application sessions are separate from your Google, Facebook or Apple account. Confirmed deletion immediately invalidates all existing Gem Lingua account sessions, including sessions on other devices.
Production database backups keep 14 local snapshots, scheduled every six hours. Cloud backup copies are scheduled for pruning after 30 days and can remain recoverable for a further seven days. These cleanup schedules depend on the backup service running. Centralized operational logs are scheduled for deletion after seven days, subject to compactor cleanup delay. The current infrastructure keeps no raw Docker log copies or disk spool. Restricted, pseudonymous session-revocation records are retained for 31 days after deletion, extended only when a newly issued session needs protection; Firebase cleanup identifiers remain only until cleanup succeeds. Earlier releases may have sent unlinked analytics to Google or Meta. Existing Google Analytics retention settings are two months for events and 14 months for users, reset by user activity; aggregate reports may remain outside those controls. Automatic usage-event logging and advertising-ID collection are disabled in Android build 961 and later and in the current Flutter and native iOS builds. This does not remove records already held by providers or prevent the technical processing needed for sign-in. Contact us for assistance with legacy provider-linked records.
Data deletion
You can request deletion of your account data by following the instructions at /delete-account.
Contact
For privacy questions or data deletion requests, contact info@polyglotmobileapp.uk.