Privacy Policy
Last Updated: July 2026
This Privacy Policy explains how we (“we,” “our,” or “us”) collect, use, and protect your information when you use our web application and services (the “Service”).
1. Information We Collect
When you sign in to our Service using Google OAuth (or other supported single sign-on providers), we collect limited personal information necessary to authenticate your identity and maintain your user account:
- Account & Identity Data: Your full name, primary email address, and profile image provided by Google OAuth.
- Service Activity Logs: Usage metadata tied to your interactions, such as lesson access history and language preferences.
- Technical Diagnostics: IP address, browser user-agent, and session identifiers automatically recorded for system monitoring and security.
2. How We Use Your Information
We process user data strictly for service operation and support. Specifically, we use your information to:
- Authenticate your account and grant authorized access to restricted features.
- Log and present your progress, preferences, and personal access history.
- Deliver critical administrative notifications, operational updates, and security alerts.
- Detect and mitigate security threats, system abuse, or unauthorized access attempts.
3. Google API User Data Disclosure
Our application’s use and transfer to any other app of information received from Google APIs adheres strictly to the Google API Services User Data Policy, including the Limited Use requirements.
- We do not sell, rent, or monetize your personal or Google account data to third parties.
- We do not use or transfer Google user data for serving targeted advertising or cross-site tracking.
- We only request basic authentication scopes (
openid,email,profile) required to verify your identity.
4. Data Storage and Infrastructure
Your user account records are stored securely in cloud-hosted databases utilizing encryption at rest and TLS/SSL encryption in transit. Administrative access is strictly limited to authorized personnel and infrastructure operations.
5. Third-Party Service Providers
We utilize trusted third-party cloud infrastructure providers to run our web application under strict confidentiality standards:
- Authentication: Clerk / Google OAuth
- Hosting & Serverless Operations: Vercel
- Database Infrastructure: Neon Database
6. Data Retention and Account Deletion
You maintain full control over your personal data. You may request account deletion or data removal at any time by contacting our team. Upon receipt and confirmation of your request, your user record and associated application logs will be permanently deleted from our primary databases within 30 days.
7. Changes to This Policy
We may update this Privacy Policy from time to time. Any updates will be posted directly to this page with a revised “Last Updated” date at the top.
8. Contact Us
If you have questions regarding this Privacy Policy or wish to request data deletion, please reach out to us:
- Email: vanderbem@sou.edu