Privacy Policy

Last updated: October 1, 2026

Gem Lingua is a mobile language-learning app. This policy explains what information we collect, why we use it, and how users can request deletion of their account data.

Information we collect

How we use information

Services that process information

Google Sign-In, Facebook Login and Sign in with Apple process sign-in information under their own policies. Firebase Authentication brokers Facebook sign-in and Apple sign-in in native iOS releases offering it; automatic usage-event logging is disabled in Android build 961 and later and in the current Flutter and native iOS builds. Earlier builds and upgrade-related SDK events may still have supplied technical or usage information to those providers. Firebase Cloud Messaging processes an app device token and notification delivery data when you enable review reminders. The reminder text does not include your saved words. Our API, database, storage and hosting providers process account data, learning activity, network addresses and operational diagnostics to deliver the service. Opening external content may send network/device information to the publisher or media host. These services may infer an approximate region from a network address and apply their own security, analytics or advertising policies.

Support and deletion emails are forwarded by Cloudflare Email Routing to a Gmail inbox monitored by the app operator. Those providers process message content and email addresses for delivery and storage.

Read Google’s privacy policy, Meta’s privacy policy, Apple’s privacy policy, Cloudflare’s privacy policy and how Google uses information from apps using its services.

Security and retention

Our application API, sign-in connections, and public media requests use HTTPS. Legacy podcast media is exposed only after a secure destination has been verified; public cleartext connections are blocked by Android build 961 and later. Account operations require server-verified authentication; the app stores its session in platform secure storage. Account-linked data is kept while the account is in use until deletion. Reminder registrations are removed when you turn reminders off or delete your account; the app also requests removal when you sign out. Anonymous device-linked settings and activity can also be stored to operate signed-out learning.

Confirmed in-app deletion removes account-linked records from the active application database. Restricted backups and operational logs may retain earlier records until rotation; deletion does not instantly erase backup copies. Firebase sign-in records held for Gem Lingua are queued for refresh-token revocation and deletion automatically. Provider outages are retried until cleanup succeeds. Your Google, Facebook or Apple account and the providers’ independently held login/security records are not deleted. Contact us for assistance with earlier device-linked analytics or signed-out activity.

We do not sell personal information. Authentication SDKs may retain provider sessions on your device until sign-out; application sessions are separate from your Google, Facebook or Apple account. Confirmed deletion immediately invalidates all existing Gem Lingua account sessions, including sessions on other devices.

Production database backups keep 14 local snapshots, scheduled every six hours. Cloud backup copies are scheduled for pruning after 30 days and can remain recoverable for a further seven days. These cleanup schedules depend on the backup service running. Centralized operational logs are scheduled for deletion after seven days, subject to compactor cleanup delay. The current infrastructure keeps no raw Docker log copies or disk spool. Restricted, pseudonymous session-revocation records are retained for 31 days after deletion, extended only when a newly issued session needs protection; Firebase cleanup identifiers remain only until cleanup succeeds. Earlier releases may have sent unlinked analytics to Google or Meta. Existing Google Analytics retention settings are two months for events and 14 months for users, reset by user activity; aggregate reports may remain outside those controls. Automatic usage-event logging and advertising-ID collection are disabled in Android build 961 and later and in the current Flutter and native iOS builds. This does not remove records already held by providers or prevent the technical processing needed for sign-in. Contact us for assistance with legacy provider-linked records.

Data deletion

You can request deletion of your account data by following the instructions at /delete-account.

Contact

For privacy questions or data deletion requests, contact info@polyglotmobileapp.uk.