Effective date: August 3, 2026
This privacy policy applies to the Langpush - AI Language Tutor mobile application (the "Application"), created by Kaindra Rizq Sachio (the "Service Provider"). This service is intended for use "AS IS".
When you sign in or create an account, the Application may collect:
Authentication is handled by Supabase Auth. If you sign up with email and password, the Application does not store your plain-text password in its own application database.
When you use the Application, we may collect content you create or generate through the service, including:
If you use microphone or voice features, the Application may process:
The Application requests microphone and speech-recognition permissions for these features. Some speech-to-text features rely on native speech-recognition capabilities provided by your device platform.
In the turn-based voice-practice experience, microphone audio is sent directly to ElevenLabs for real-time speech-to-text. The resulting transcript may be stored with the related conversation. Assistant response text is sent to Inworld or, for some voice features, OpenRouter and its selected text-to-speech model provider to generate spoken audio. These providers receive the content needed to provide the selected voice feature and related technical connection data. Do not use voice features to share sensitive information that you do not want processed by these providers.
The Application may collect information about how you use the service, including:
If analytics is enabled in the build you are using, the Application uses PostHog for product analytics and session replay. The current configuration masks text inputs, images, and protected replay views.
The Application may also use Sentry to receive error and crash reports. These reports can include technical and diagnostic information, such as error messages, stack traces, app/device/operating-system information, app version, request identifiers, and, where configured, an internal account identifier.
The Application stores some data locally on your device, including:
Based on the current implementation, the Application does not request or use:
Some builds use the TikTok Business SDK for advertising attribution and conversion measurement. This is not used to display advertisements in the Application. See Advertising and Attribution for details.
The current iOS application bundle includes photo-library usage descriptions. Based on the current implementation we reviewed, the Application does not provide a general user-facing photo feature, but certain native dependencies or platform integrations may still require these declarations to be present in the application metadata.
We use the information described above to:
The Application relies on third-party services to operate. The services below may process data as described here, and many of them provide their own privacy disclosures at the links below.
| Service | Purpose | Data Shared | Privacy / Service Link |
|---|---|---|---|
| Supabase | Authentication, database, backend functions, and storage of app data | Account identifiers, profile metadata, conversation content, feedback data, vocabulary data, and related app records | supabase.com/privacy |
| Google AI / Gemini and Google Cloud Speech-to-Text | AI-generated replies, translation, feedback generation, text-to-speech, speech-to-text, and live voice features | Conversation content, transcripts, room context, live voice audio, generated voice scripts, and related inputs required for the feature used | policies.google.com/privacy |
| ElevenLabs | Real-time speech-to-text for turn-based voice practice | Microphone audio sent directly from the device for transcription, resulting transcripts, language settings, and technical connection data | elevenlabs.io/privacy-policy |
| Inworld AI | Text-to-speech for turn-based voice practice | Assistant response text to be spoken, selected language, voice/model settings, and technical connection data | inworld.ai/privacy |
| OpenRouter | Text-to-speech for certain voice features, including routing to the selected model provider | Assistant response text to be spoken, voice instructions or settings, generated-audio request data, and technical metadata | openrouter.ai/privacy |
| Langfuse | Observability and tracing for AI requests | Request/response inputs and outputs, internal user/session identifiers, room identifiers, and technical metadata associated with traced AI requests | langfuse.com/privacy |
| PostHog | Product analytics and session replay when configured for the build | Usage events, account identifiers, app metadata, and limited replay data subject to the Application's masking configuration | posthog.com/privacy |
| Sentry | Error, crash, and backend failure monitoring | Error messages, stack traces, diagnostic and technical metadata, app/device/operating-system information, request identifiers, and, where configured, an internal account identifier | sentry.io/privacy |
| RevenueCat | Subscription status, purchases, restores, and customer subscription management | Internal app user ID, purchase status, entitlement data, and store-related subscription metadata | revenuecat.com/privacy |
| Google Sign-In | Optional authentication | Email address, name, profile image, and other Google account data you authorize for sign-in | policies.google.com/privacy |
| Apple Sign-In | Optional authentication | Email address and name provided through Apple Sign-In, subject to Apple's sharing settings, including use of Apple's private email relay when selected by the user | apple.com/privacy |
| FreeDictionaryAPI | Word lookup for adding vocabulary and dictionary-backed vocab enrichment | The word being looked up | freedictionaryapi.com |
| Expo | Application framework and related build/runtime infrastructure | Standard technical metadata associated with app framework and service operations | expo.dev/privacy |
| TikTok Business SDK | Advertising attribution and conversion measurement in builds where the SDK is configured | Device, network, and advertising identifiers as made available by the device and permissions; app install/launch events; completed store-transaction events; and the standard CompleteTutorial event after onboarding. We do not send conversation content, onboarding answers, or payment-attempt details through our TikTok event bridge. |
tiktok.com/privacy-policy |
The Application does not show third-party advertisements. In builds where the TikTok Business SDK is configured, TikTok may process device and technical information, app install/launch information, completed StoreKit transactions, and limited standard conversion events to measure the effectiveness of our advertising and attribute installs or subscriptions. The Application sends only the allow-listed conversion event described above through its own TikTok bridge; it does not send chat messages, transcripts, onboarding answers, or payment-attempt details through that bridge.
On iOS, the Application may request App Tracking Transparency permission after your first successful sign-in. TikTok receives the IDFA only if you grant that system permission. You can change this choice in your iOS privacy settings. Declining permission does not prevent you from using the Application, although advertising measurement may be less precise.
We may disclose your information:
Server-side data such as account records, conversations, feedback reports, and vocabulary records may be retained for as long as needed to operate the Application, maintain your account, comply with legal obligations, resolve disputes, and enforce our agreements.
Third-party service providers may retain data they process under their own privacy notices and our applicable agreements with them. Their processing and retention may occur outside your country of residence.
Data stored locally on your device, such as preferences and grammar drafts, remains on your device until it is removed by the Application, overwritten, or cleared through app removal or device/app storage controls.
You can initiate account deletion from within the Application. When your account is deleted, the Application is designed to remove the server-side app data associated with that account, subject to any data we may need to retain for legal, security, fraud-prevention, or compliance reasons. If you need help with account or data deletion, you may also contact us at kaindradev@gmail.com.
Depending on where you live, you may have rights to request access to, correction of, or deletion of certain personal information. You may also have rights related to how your information is used. You can contact us at kaindradev@gmail.com to make a request.
If the Application build you are using includes analytics or replay features, some controls may also be available through device settings, platform privacy controls, or future in-app settings as they are added.
You can manage iOS App Tracking Transparency permission in your device settings. Where available, you may also use the privacy choices offered by a third-party provider through the links in the table above.
The Application is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information through the Application, please contact us at kaindradev@gmail.com.
We use technical and organizational measures designed to protect information processed through the Application. These measures include authenticated access controls, database row-level access rules, and encrypted network transport for supported service communications. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
We may update this Privacy Policy from time to time. We will post the updated version on this page and update the effective date above. Your continued use of the Application after changes take effect means you accept the updated policy.
If you have questions about this Privacy Policy or the Application's privacy practices, please contact: kaindradev@gmail.com