Privacy Policy
Application: Langpa · Learn Spanish (com.langpa.app) • Effective Date: October 2026
Langpa's lesson content and learning progress work offline on your device. Recorded audio downloads, account sync, optional AI, ads, and purchases use network services when you choose or need them.
1. Offline-First Architecture & Local Device Storage
Langpa is an offline-first mobile application. The 40-day course (1433 exercises, 405 lesson-linked vocabulary associations, and 204 contextual sentences) ships with the app. Lesson content and progress are available locally. Recorded audio clips are downloaded from Firebase Storage when available and cached on your device; offline playback depends on a cached clip or a compatible Spanish system voice being installed.
- Guest Mode: You can use Langpa without creating an account or providing an email address. All lesson progress, quiz attempts, study streaks, and personal settings are saved in a local, sandboxed SQLite database on your device.
- Local Guest Progress: Guest lesson progress, quiz attempts, study streaks, and settings remain on your device unless you sign in to enable sync. Crash reports and error details are sent to Firebase Crashlytics to diagnose failures. Optional usage analytics are off by default; enabling them is separate from crash reporting.
2. Information We Collect (When You Choose to Sign In)
You may optionally choose to connect an Apple ID or Google Account to back up your progress across devices or restore purchases. When you do so:
- Authentication Identity: We receive a unique identifier (
uid) and your verified email address from Apple or Google via Firebase Authentication. - Progress Sync: High-level learning events (e.g. lesson completion timestamps, review scores, selected goal category) sync to your private Cloud Firestore document (
users/{uid}). Firestore Security Rules enforce that only your authenticated account can access this data. - No Sensitive Personal Data: We do not collect your physical address, phone number, contacts list, location coordinates, or financial account credentials.
3. Microphone & Spoken Voice Processing
Langpa includes interactive pronunciation exercises and conversational speaking turns:
- On-Device Speech Recognition: Speaking exercises request on-device recognition on supported devices. Offline speech may require an initial voice or system language download. When unavailable, use the typing or transcript alternative.
- No Voice Storage on Servers: Raw microphone audio recordings are never uploaded, stored, analyzed, or retained on our remote servers. Audio waveforms are discarded immediately after transcription finishes.
- Permission Control: Microphone access is requested only when you actively trigger a speaking exercise. You may revoke microphone permissions at any time via your device settings, and alternate typing or selection modes remain fully functional.
4. Typing, Spelling & Offline Learning Data
Writing, typing, and spelling exercises evaluate your answers locally on your device. Your typed inputs and practice results stay private and are never shared with advertising networks or third-party data brokers.
5. AI Conversational Practice & Third-Party LLM Policy
Langpa offers an optional conversational tutor powered by Firebase AI Logic / Google Vertex AI (Gemini 3.5 Flash Lite):
- Explicit Cloud Consent: The AI tutor requires explicit opt-in confirmation before your first dialogue session.
- Structured Prompts Only: The client communicates with Vertex AI via pre-defined server templates (
langpa-tutor-v1) guarded by Firebase Functions. No open-ended relays or unrestricted endpoints are exposed. - Provider Processing: Google states that Vertex AI customer data is not used to train or fine-tune models without prior permission or instruction. Google may retain or log prompts in limited cases, including abuse monitoring and temporary in-memory caching, under its Vertex AI data terms.
- Local Chat Retention: Conversations and corrections are saved locally on your device SQLite database for your private review and are not archived on our cloud database.
- Generated Learning Audio: Recorded pronunciation uses generated Spanish voices. Optional cloud playback sends the text to be spoken to Google and caches the returned audio on your device. Raw microphone recordings are not sent to this service.
- Reporting Replies: If you choose Report reply, the selected reply, its corrections and explanation, scenario, selected reason, and your account identity are stored for the Langpa team to review. Other conversation messages are not included. Reports are scheduled for removal after 90 days and are also removed when your account is deleted.
6. In-App Subscriptions & Purchases (RevenueCat)
In-app subscriptions and transactions are processed directly by Apple App Store (In-App Purchase) or Google Play Billing.
- We utilize RevenueCat as our subscription infrastructure partner to securely validate purchase receipts and synchronize entitlement status.
- We do not collect or store your payment card numbers, bank details, or billing addresses.
7. Push Notifications & Device Tokens
If you enable daily study reminders, your device registers a Firebase Cloud Messaging (FCM) token under fcm_tokens/{uid}_{installationId}:
- FCM tokens are used strictly to deliver timely study reminders according to your chosen quiet hours.
- Tokens are immediately purged from our servers when you disable notifications, log out, or delete your account.
8. Advertising & Google UMP Consent
Free learners may optionally watch rewarded ads to unlock extra lessons or experience occasional app-open ads upon returning.
- We implement the Google User Messaging Platform (UMP) SDK to present transparent consent choices for learners in the European Economic Area (EEA), UK, and applicable jurisdictions.
- Subscribed premium members experience a 100% ad-free environment.
9. Your Rights: Access, Export & Immediate Account Deletion
Under GDPR, CCPA, and Apple App Store / Google Play requirements, you maintain full control over your information:
- In-App Deletion: Go to Profile → Account → Delete Account. Your cloud record, authentication user, FCM push tokens, and RevenueCat profile are permanently deleted immediately.
- Web Deletion URL: If you uninstalled the application or cannot access your device, submit a deletion request via our deletion page. We store your supplied email, request reference, submission time, and processing status while verifying ownership and completing deletion. A daily hash derived from your network address limits abusive requests; these counters expire after two days. A received request does not mean account deletion is complete. The team removes the request record after resolution.
- Data Export: You can export your study records and SQLite learning events at any time.
10. Contact Us
For questions, data inquiries, or privacy requests regarding Langpa, please contact our Data Protection team: