1. Introduction
TaleLingo ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our language learning application and services.
By using TaleLingo, you consent to the collection and use of your information as described in this Privacy Policy. If you do not agree with our policies and practices, please do not use our Service.
This Privacy Policy complies with Thailand's Personal Data Protection Act (PDPA) and other applicable data protection regulations.
2. Information We Collect
2.1 Information You Provide
When you create an account and use our Service, you provide us with:
- Account information: name, email address, password, profile picture
- Payment information: billing address, payment card details (processed securely by Stripe)
- Communication data: messages you send to our support team
2.2 Information Collected Automatically
When you use our Service, we automatically collect:
- Learning data: stories read, vocabulary saved, test scores, CEFR level, learning progress, time spent on activities
- Usage data: features used, buttons clicked, pages visited, session duration
- Device information: device type, operating system, browser type, app version, unique device identifiers
- Log data: IP address, access times, referring URLs, error logs
2.3 Information from Third Parties
If you sign in using Google, we receive your name, email address, and profile picture from Google according to the permissions you grant.
3. How We Use Your Information
We use your personal information for the following purposes:
3.1 Providing and Improving the Service
- Create and manage your account
- Deliver personalized learning content based on your level and progress
- Track your learning progress and recommend appropriate stories and vocabulary
- Process payments and manage your subscription
- Provide customer support and respond to your inquiries
3.2 Communication
- Send important service updates, security alerts, and account notifications
- Send learning reminders and progress reports (you can opt out)
- Inform you about new features and content (you can opt out)
3.3 Analytics and Improvement
- Analyze usage patterns to improve our Service and user experience
- Conduct research and development for new features
- Monitor and prevent fraud, abuse, and security threats
4. Data Storage and Security
4.1 Where We Store Your Data
Your data is stored on secure cloud servers provided by MongoDB Atlas and other reputable cloud service providers. Our servers may be located in different countries, and by using our Service, you consent to the transfer of your data to these locations.
4.2 How We Protect Your Data
We implement industry-standard security measures to protect your personal information, including:
- Encryption of data in transit using TLS/SSL
- Encryption of sensitive data at rest
- Secure authentication using Firebase Authentication
- Regular security audits and vulnerability assessments
- Access controls limiting employee access to personal data
While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
4.3 Data Retention
We retain your personal data for as long as your account is active or as needed to provide you with our Service. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain certain information by law.
5. Third-Party Services
We use the following third-party services to operate our platform:
- Firebase (Google): Authentication, analytics, and crash reporting. Google's privacy policy applies to data processed by Firebase.
- Stripe: Secure payment processing. Stripe handles your payment card information directly and is PCI-DSS compliant. We do not store your full card number.
- MongoDB Atlas: Database hosting with enterprise-grade security and encryption.
- Cloudflare: Content delivery and security services.
These third-party services have their own privacy policies governing the use of your information. We encourage you to review their policies.
We do not sell your personal information to third parties. We only share your information with third parties as necessary to provide our Service or as required by law.
6. Your Rights
Under applicable data protection laws, including Thailand's PDPA, you have the following rights:
- Right to Access: You can request a copy of the personal data we hold about you
- Right to Rectification: You can update or correct inaccurate personal data through your account settings or by contacting us
- Right to Erasure: You can request deletion of your personal data by deleting your account or contacting us
- Right to Data Portability: You can request your data in a structured, machine-readable format
- Right to Object: You can object to certain processing of your personal data
- Right to Withdraw Consent: Where we rely on consent, you can withdraw it at any time
To exercise these rights, please contact us at [email protected]. We will respond to your request within 30 days.
You can manage your communication preferences and download your data from your account settings at any time.
7. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience:
- Essential cookies: Required for the Service to function properly (authentication, security)
- Preference cookies: Remember your settings and preferences
- Analytics cookies: Help us understand how users interact with our Service
You can control cookies through your browser settings. However, disabling certain cookies may affect the functionality of our Service.
We do not use cookies for advertising or sell data to advertisers.
8. Children's Privacy
TaleLingo is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13 without parental consent.
If you are a parent or guardian and believe that your child under 13 has provided us with personal information, please contact us immediately at [email protected]. We will take steps to remove such information from our systems.
For users between 13 and 18 years old, we recommend that parents or guardians review this Privacy Policy and supervise their child's use of the Service.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes:
- We will post the updated Privacy Policy on our website and app
- We will update the "Last Updated" date at the top of this policy
- We will notify you via email or in-app notification at least 30 days before the changes take effect
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after the changes take effect constitutes your acceptance of the revised Privacy Policy.
10. Contact Us
If you have any questions about this Privacy Policy, want to exercise your rights, or have concerns about how we handle your personal data, please contact us:
Email: [email protected]
We will respond to all legitimate requests within 30 days.