LangLearn App Privacy Policy

Last updated: 14 September 2026

This policy covers the LangLearn language-learning app for Android and iOS and the website it is built on, language.ctoteachings.com. It is separate from, and more specific than, the CTO Teachings website privacy policy, which covers our consulting business. CTO Teachings is the controller of the information described here.

LangLearn helps you learn a language by tracking which words you know and giving you reading passages and audio pitched at that level. Everything below follows from that: we keep the information needed to know your level and remember your material, and we do not build an advertising or behavioural profile from it ourselves. The Android app is paid for by ads from Google AdMob, and Google's part in that is described in its own section below.

The Short Version

  • You sign in with Google. We receive and store your email address, display name, and profile picture URL.
  • We store your learning progress — the language you are studying, your word level, which words you have marked known, and the passages and playlists you have saved.
  • We store how much time you have spent listening in each language. It ranks you on the public leaderboard, and in the Android app it decides when an ad is due.
  • The Android app shows full-screen ads from Google AdMob at breaks in listening. Google collects the device's advertising ID, IP address, device information, and ad interactions to serve them. In the EEA, the UK, and Switzerland you are asked for consent first. The website and the iOS app show no ads.
  • We do not sell your personal information. The only advertising partner is Google, through the AdMob ads in the Android app.
  • The app never asks for your contacts, location, camera, photos, or microphone. Microphone access is affirmatively blocked in the app's manifest.
  • You can ask us to delete your account and data at any time — see how to delete your account.

Information We Collect

Account information, from Google Sign-In. Signing in is the only way to use the app. We use Google Sign-In with the email and profile scopes, and from the identity token Google returns we store: your email address, your Google account identifier, your display name, and the URL of your Google profile picture. Your display name and picture URL are refreshed each time you sign in. We do not request or hold a Google access or refresh token, so we cannot read your Gmail, Drive, contacts, calendar, or anything else in your Google account — the only thing we ever receive is the identity token that proves who you are.

Learning data. As you use the app we store, against your account: the language you are learning and your native language; your word level and how many new words you want introduced; the status of individual words (known, learning, unknown); references to the passages you have generated or saved; the playlists you have created and their names and ordering; and the timestamps of these changes. If you request a language we do not yet support, we record that request together with your email address so we can tell you when it is available.

Diagnostic and crash information. When something fails, the app and the website report the error to Sentry, our error-reporting provider, so we can fix it. A report contains the error and its stack trace, the platform, the app version, which part of the app failed, and your account identifier so we can find the problem. Reports from the web interface also carry your email address and display name; reports from the app's native shell carry only the account identifier. Crashes inside the Android and iOS apps' native code, which the web interface cannot see, are reported to Firebase Crashlytics (a Google service), with the same account identifier and no name or email.

Session recordings, on error only. The web interface inside the app uses Sentry's session-replay feature, and we are telling you plainly what that captures: for a session that hits an error, it records a reconstruction of what was on screen, including text and anything you typed in that session. It is switched on only for sessions that encounter an error — ordinary sessions are not recorded — and it exists so a bug report shows what actually happened rather than a stack trace with no context. If you would rather this did not apply to you, contact us.

Technical information. Our servers receive the ordinary technical details of any internet request — IP address, device and app version, and which requests were made — and log them for security and debugging. The app sends us no analytics events about what you tap or which screens you visit.

Listening time. The app and the website count how long the audio player is actually playing (not time spent reading, on other screens, or paused) and send it to us in batches. For your account we store a running total of listening time for each language you are learning and overall, plus a record of each batch received (the listening time per language it contained) so that a retried upload is never counted twice. We do not store which passages you listened to or the times at which you listened. These totals are used for two things:

  • The public leaderboard. The leaderboard on the website can be viewed without signing in. For accounts that have recorded listening time or generated stories, it shows your display name, profile picture, native language, total listening time, the number of stories you have generated, and a score based on them.
  • Deciding when an ad is due in the Android app, as described in the next section. The app also keeps, on your device, the listening total at which it last showed you an ad.

Ads in the Android App

Where ads appear. The Android app shows full-screen (interstitial) ads served by Google AdMob, using Google's Mobile Ads SDK. Ads are shown only at a natural break, when a story or lesson finishes, when playback stops, or when you leave the player with nothing playing, and never over audio that is playing. They appear only after an ad-free listening allowance. Today a new account listens for its first 120 minutes with no ads, after which the app shows about one ad per 10 minutes of listening. We may change these numbers. The website, including when it is opened in a desktop or mobile browser, shows no ads, and the iOS app currently shows no ads and requests none.

Who never sees ads. An account we have marked ad-free, and an account whose native language (the first language set in your LangLearn settings) is on our list of ad-free languages. We decide this on our servers each time you sign in or your session refreshes; for those accounts the app never asks Google for an ad.

What Google collects. Google is our advertising partner, and it receives information directly from the app through the Mobile Ads SDK. The app does not ask for consent or request an ad until the first time an ad is due, and never for an ad-free account. Google uses the device's advertising ID, your IP address (from which an approximate location can be inferred), information about your device and the app (such as the device model, operating-system version, and app version), and your interactions with ads (such as views and taps), together with diagnostic information about the SDK. Google uses this to deliver and measure ads, to prevent fraud and abuse, and, where your consent allows, to show personalised ads. An ad request carries none of your account details: we do not pass AdMob your name, email address, account identifier, learning data, or listening history. Google's use of this information is governed by its own privacy policy; see How Google uses information from sites or apps that use our services.

Consent in the EEA, the UK, and Switzerland. Before the first ad is requested, the app runs Google's User Messaging Platform, which shows a consent form to users in regions where one is required, including the European Economic Area, the United Kingdom, and Switzerland. You can refuse. If you do not agree to personalised ads, Google may still show non-personalised or limited ads, which use less data. Until a choice has been made where one is required, the app does not request ads. The app does not yet have its own button to reopen the consent form; to change your choice, clear the LangLearn app's storage in Android settings (this also signs you out) and you will be asked again the next time an ad is due, or contact us.

Your advertising ID. You can reset your advertising ID, or delete it so apps can no longer use it for personalised ads, in your device's settings. On most Android devices this is under Settings › Privacy › Ads (or Settings › Google › Ads).

What We Do Not Collect

The app requests no permission for contacts, location, camera, photo library, calendar, or the microphone. The Android manifest explicitly blocks the microphone and audio-settings permissions, so the app cannot request them even by accident. The permissions the app declares are internet access, keeping the screen awake, notifications, and the foreground-service permissions Android requires to keep audio playing while the screen is off; the Google Mobile Ads SDK adds network-state access and the permission to read the device's advertising ID. The app has no App Tracking Transparency prompt, and no analytics or attribution SDK.

Where Your Information Is Stored

Your account and learning data are stored in Google Cloud Firestore, in a Google Cloud project we control. Audio and passage files are stored in Google Cloud Storage. Crash and error reports go to Sentry. These providers process this information on our behalf and may store it in countries other than yours; we take reasonable steps to keep it protected in line with this policy.

On your device. Your sign-in session is held as a token in the device's own encrypted keystore (iOS Keychain / Android Keystore), so you do not have to sign in on every launch. If you download passages for offline listening, the audio and the passage text are written to the app's private storage area, where no other app can read them. Deleting the app removes both.

A Note About Shared Passages and Audio

Reading passages and their audio are stored in a publicly readable cloud bucket, addressed by unguessable URLs, so that they can be played quickly by the app and the website. That means a passage's text and audio should be treated as shareable content rather than private notes. Your progress — your word level, which words you know, and which passages are yours — is not public and is only readable through your signed-in account. Do not put anything you consider confidential into a passage.

Passages Generated Through Your Own AI Assistant

Passages can be created by connecting LangLearn to your own AI assistant. When you do that, the passage text is produced by that assistant under your account with that provider, and their privacy terms apply to that step. What reaches us is the finished passage.

How We Use Your Information

  • to sign you in and keep you signed in;
  • to track your level and choose material that matches it;
  • to store and return the passages, playlists, and word lists you have created;
  • to produce the audio for a passage (the passage text is sent to Google Cloud Text-to-Speech for synthesis);
  • to count your listening time, rank you on the leaderboard, and, in the Android app, decide when an ad is due and whether your account is ad-free;
  • to show ads in the Android app through Google AdMob, as described above;
  • to diagnose and fix crashes and errors;
  • to keep the service secure and available, and to meet legal obligations.

Where data-protection law applies, we rely on the performance of our agreement with you (running the app), our legitimate interests (security, debugging, improving the service, and funding it through ads), and your consent where we ask for it, including the consent Google's consent form asks for before personalised ads in the EEA, the UK, and Switzerland.

How We Share Information

We do not sell your personal information. We share it with the service providers that make the app work — Google (sign-in, Cloud Firestore, Cloud Storage, Text-to-Speech, and Firebase Crashlytics), Sentry (error reporting), and Cloudflare (hosting of the website and this page) — each of which processes it on our instructions and for the purposes described here. In the Android app, Google AdMob is our advertising partner and collects the information described in "Ads in the Android App" directly from your device, for advertising, measurement, and fraud prevention, under Google's own privacy policy. Your display name, profile picture, native language, and totals appear on the public leaderboard, as described above. Beyond that we disclose information only where we are legally required to, where it is necessary to protect our rights or someone's safety, or to a successor entity in a merger or reorganisation of our business.

Data Retention

We keep your account and learning data for as long as your account exists, because it is your progress — deleting it would reset your level. Listening totals and batch records are kept for as long as your account exists, so an old upload retried from an offline device is never counted twice. Error reports and session replays are retained by Sentry, and native crash reports by Firebase Crashlytics, under their own retention schedules, on the order of weeks to months, not indefinitely. Information Google AdMob collects is retained by Google under its own policies. When you ask us to delete your account we delete your account record and your learning data as described below.

Deleting Your Account and Data

There is no in-app delete button today, and rather than imply otherwise: to delete your account and your learning data, follow the steps on our account deletion page from the email address you signed in with, and we will action it and confirm when it is done. You can also ask for a copy of what we hold about you, or for a correction. Passages you created that are already in the shared catalogue may remain there without your account attached.

Your Rights and Choices

Depending on where you live, you may have the right to access, correct, update, or delete your personal information, to object to or restrict certain processing, to withdraw consent, and to request a copy of your data. Reach us through our contact page and we will respond in line with applicable law. You can also sign out of the app at any time, which clears the session stored on your device. For ads, you can refuse or change consent where Google's consent form is shown, and reset or delete your advertising ID in Android settings, as described in "Ads in the Android App".

Children's Privacy

LangLearn is not directed to children, and we do not knowingly collect personal information from children. Signing in requires a Google account.

Security

Sign-in and every request to our servers use encrypted connections. Your session token is held in the device's encrypted keystore rather than in browser storage. Access to production data is limited to the people who need it. No system is perfectly secure, but we work to protect your information and to limit who can reach it.

Changes to This Policy

We may update this policy as the app changes. When we do, we will revise the "Last updated" date above, and the change takes effect once posted on this page.

Contact Us

Questions about this policy, a request to exercise your rights, or a request to delete your account: please get in touch through our contact page.