Legal
Privacy Policy
How Liralang collects, uses, and protects personal data.
Last updated: 2026-08-31
Controller and contact
Liralang is the controller for personal data processed in the app and public site. For privacy requests, contact privacy@liralang.com.
Legal identity: Liralang, Italy.
Data we process
- Account data: name, email, base language, CEFR level, Google profile image if used, verification status, role, and preferences.
- Authentication and security: sessions, IP, user-agent, security events, 2FA, and verification or recovery tokens.
- Learning data: progress, answers, notes, vocabulary, phrases, conversation memory, tutor preferences, and note images you paste.
- AI and voice: prompts, corrections, conversation turns, generated replies, model, token usage, duration, and estimated cost.
- Billing: tier, subscription status, customer/subscription ids, billing events, currency, and amounts. Full card data is handled by Paddle, not Liralang.
- Funnel analytics (first-party): landing views and CTA clicks, with a salted hashed IP only to rate-limit abuse. Without measurement permission, we send only aggregatable counters and no visit identifier. We store neither the raw IP nor the user-agent.
- Optional advertising attribution: if you arrive from a campaign, we ask permission before saving a visit id and UTM labels to join the visit to a signup. Opaque advertising-platform click identifiers are not stored.
- Product analytics (Aptabase): anonymous, cookieless usage metrics (page views, device type, browser and operating system, approximate country), processed by Aptabase in the EU. It is anonymous, uses no cookies or persistent ids, and is not linked to your account.
- Support: feedback or messages you send, together with your account and current page.
Purposes
- Create and secure accounts, verify email, and maintain sessions.
- Save progress, adapt the course, and sync data across devices.
- Generate corrections, conversations, explanations, and audio with AI providers.
- Measure usage, cost, plan limits, conversions, and errors to operate the service.
- Manage subscriptions, gifts, invoices, cancellations, and support.
- Prevent abuse, investigate incidents, and comply with legal obligations.
Legal bases
Data necessary to provide Liralang is processed for contract performance. Security, abuse prevention, identifier-free aggregate metrics, and product improvement rely on legitimate interests. Attribution that writes browser storage or joins a campaign to your account relies on prior consent and is off by default. Do Not Track and Global Privacy Control keep it off. You can change the choice from the site's Privacy control; if you withdraw permission, account-linked attribution is removed when the signed-in app receives that choice. Transactional emails are necessary for account and security.
Providers and transfers
We use providers for hosting, database, authentication, email, payments, AI, analytics, and error logging, including Vercel, Neon/Postgres or the configured database provider, Resend, Paddle, Google OAuth, Anthropic, Inworld, Aptabase, and Sentry. Some providers may process data outside the EEA; applicable contractual safeguards are used where required.
Retention
Account and learning data is kept while your account exists. If you delete your account, linked data is deleted by cascade where the model supports it. Some security, billing, fraud, or compliance logs may be retained as needed for legal obligations, claims, or security.
Your rights
You can request access, correction, export, deletion, restriction, objection, and portability by contacting privacy@liralang.com. In the app you can also export data, disable local analytics, and delete your account. If you are in the EU/EEA, you may also complain to your data protection authority.
Children
Liralang is not directed to children under 14. If you believe a child sent us data without authorization, contact us so we can review and delete it where appropriate.