Back to Aureloo

Privacy Policy

Effective: 2026-10-06 · Last updated: 2026-10-08

On this page

On this page

Effective 6 October 2026

This policy explains what Aureloo does with your information. It describes the Aureloo app for Android and for iPhone, and this website, and nothing else.

We have tried to write it so that you can actually read it. Where something is genuinely good for your privacy we say so, and where something is not, we say that too.

What is new in this version. Aureloo 1.1 adds promo codes, invitations, nicknames, sending to a friend, a daily streak with reminders, and achievement cards, and an account made with an email address and a password now has to confirm that address through a link emailed to it. With them comes, for the first time, a server of ours that holds some information about you. The new parts of this policy are Account emails, What our server keeps and Reminders and the daily streak. If you already had an account, version 1.1 of the app shows you a notice about this the first time you open it, before it makes any of the new requests to our server. This version also describes Aureloo on iPhone: Sign in with Apple, buying Pro through the App Store, and the iPhone's own services that the app uses.


The short version

  • Aureloo requires an account. You have to sign in before you can use the app — there is no guest mode and no way past it. So the first sign-in needs an internet connection, and an email address always reaches Firebase Authentication, a Google service. You sign in with an email address and a password, with Google, or on an iPhone with Apple. If you sign up with an email address and a password, you confirm the address through a link that Firebase Authentication emails to it.
  • After that it works offline. Your words, folders and practice history are stored on your phone. Practising needs no connection.
  • A small server of ours exists for four optional things: promo codes, invitations, your nickname, and sending a folder or a rule to a friend. It keeps what those need, and what it keeps is set out below. Something you send to a friend waits there only until they accept or decline it, and expires after 24 hours if they do neither.
  • We show no adverts. We use no analytics, no crash reporting and no tracking or advertising SDKs of any kind. Nobody is profiling you here, and we do not sell or share your data with anyone.
  • If you connect Google Drive — only when you tap Connect Drive in Profile; the app does not ask when you sign in — your data goes into a private folder in your own Google Drive that we cannot browse out of. We cannot see any of your other Drive files. Not "we promise not to" — the permission we hold makes it impossible.
  • Pro is sold through Google Play on Android and through the App Store on iPhone. We never see your card details, and the purchase is tied to your Aureloo account by its random user id — never by your email address or name.
  • Reminders are made on your phone. The daily-streak notifications are scheduled by the phone itself. No server sends them, and nothing about them leaves the device.
  • One thing to flag, and one we have fixed. The speaking exercise uses your phone's own speech recogniser, which normally sends the audio to Google on Android and may send it to Apple on an iPhone — neither the audio nor the result comes to us, and it is explained in full below. And the typeface: Aureloo used to download it from Google's font servers on first run, but it now ships inside the app, so that request is not made any more.

Who is responsible

Aureloo is made by:

AZ Smart Studios LLC
South Carolina, United States

Under data-protection laws such as the UK and EU GDPR, AZ Smart Studios LLC is the data controller for the personal data described here.

Contact: privacy@aureloo.com
Support: support@aureloo.com


What we collect, and when

Your account, which you must have

Aureloo requires an account. The first screen asks you to sign in or sign up, and there is no third option: no guest mode, no anonymous sign-in, no "look around first". That is a deliberate design decision, not an oversight — an account is what lets your Pro entitlement and your Drive sync follow you rather than the handset. It has a price, and this is it: there is no way to use Aureloo without giving us an email address.

Two things follow from that, and we would rather say them than let you discover them. The first sign-in needs a working internet connection. And there is no version of using this app in which nothing about you reaches us.

You can sign in with an email address and password, with Google, or — on an iPhone — with Apple. Sign-in is handled by Firebase Authentication, a Google service. The account information the app itself works with is four items:

WhatWhere it comes from
A user IDGenerated by Firebase when the account is created
Your email addressYou type it, or it comes from your Google account or from Apple
Your display nameFrom your Google account, if there is one; with Apple, the name you let Apple share, at the first sign-in only
Your profile photo URLFrom your Google account, if there is one

If you sign up with an email address and password, the display name and photo are normally empty; if you sign in with Google, the display name and photo URL held by that account come across with the sign-in. Apple gives no photo; see Signing in with Apple below.

Firebase also keeps when the account was created and last used, how you sign in, and whether your email address is confirmed. Our server reads the creation date, the sign-in method and that flag for the invite rules. It also turns away an account made with an email address and a password whose address is not confirmed; it learns that from the sign-in token the app sends with each request. What the optional features add to all this is set out below, in the section What our server keeps.

Confirming your email address. An account made with an email address and a password has to confirm its address before it can enter the app. Firebase Authentication emails a link to the address; you open the link, then tap I've confirmed in the app. A sign-in with Google or Apple needs no link. An account made before version 1.1 whose address was never confirmed is locked in the same way until it is; signing out from that screen leaves your words on the phone.

We never see your password. Firebase handles it. If you sign in with Google or Apple, no password reaches Aureloo or Firebase at all. If you forget your password, Firebase Authentication emails you a link to reset it, and the new password you then choose goes to Firebase, not to us.

Signing in with Apple

On an iPhone you can also use Sign in with Apple. Apple asks you what to share, then passes your email address to Firebase Authentication with the sign-in — or, if you choose Hide My Email, an address Apple makes for us alone, which forwards to yours. At the first sign-in only, Apple also gives the app the name you allow it to share. Apple gives Aureloo no photo and no password, and Firebase keeps the identifier Apple uses for your Apple Account with Aureloo, so that your next sign-in finds the same account.

When you delete your Aureloo account in the app, Aureloo asks you to sign in with Apple once more and then tells Apple to withdraw Aureloo's access to your Apple Account, so that Aureloo no longer appears among the apps that use Sign in with Apple; see Deleting your account and your data. You can also end that access yourself, in your Apple Account settings under Sign in with Apple; that does not delete your Aureloo account.

Account emails

The emails an account can receive are sent by Firebase Authentication, the Google service that already holds the account, not by our own server. There are three kinds: a link that confirms an email address, a link that resets a forgotten password, and — should the address on an account ever be changed — a link that undoes the change. Each goes to the account's address (the undo link to the address it had before the change), in the app's language where Firebase offers it (otherwise in English), and in Firebase's own words. It comes from "Aureloo" at noreply@mail.aureloo.com, and a reply reaches us. Our server takes no part in these emails and keeps no record of them.

The page the link opens. The link opens a page that Firebase Authentication hosts for Aureloo at aureloo-7393.firebaseapp.com, the address Firebase gives our project, not a page of this website. That page does what the link is for: it confirms the address, lets you choose a new password, or undoes the change. Like the emails, it is part of Firebase Authentication: Google runs it for us, as our processor, under its terms for that service.

What else leaves your phone

Beyond signing in, the app makes these connections. Only the last of them is to us:

  • Speech recognition, but only if you use the speaking exercise. See Microphone and speech below — this one deserves its own section.
  • The purchase service. Aureloo sets up its purchase system when the app starts and asks whether your account has Pro, so a request goes to RevenueCat even if you never open the purchase screen. No payment details are involved — see Purchases below, which also says how often it asks.
  • Google Drive, but only once you have given Aureloo permission for it, and then it is your own Drive it talks to. See Google Drive sync below.
  • A connection check, when you sign out. Without Drive connected, the app requests https://clients3.google.com/generate_204 before it signs you out, to find out whether the phone is online. With Drive connected, it makes the same request if the sync before signing out failed for lack of a connection, to tell a phone that is offline from a Drive that did not answer. Nothing about you or your account is sent, and the answer is an empty "204" with no content; like any connection, it does show Google the phone's IP address. See Signing out below.
  • Our own server, for four optional features only: promo codes, invitations, your nickname, and sending to a friend. Two requests are made whether or not you use them: each time the app starts while you are signed in, and at most once every fifteen minutes when you come back to it, the app asks whether a friend has sent you anything; and when you open the Profile tab, it asks for your sharing profile (nickname, the accept switch, blocked senders). Everything else happens only when you use one of those features. See What our server keeps below.

On an Android phone, the app also asks the Google Play app one question the first time it starts: which link the install came from. That is how an invite code in a link is picked up. An iPhone gives no such answer, so there a friend types the code, and the invite programme asks Apple's DeviceCheck service about the phone instead. Both are described under Inviting friends.

The typeface used to be on this list, and is not any more. Aureloo draws its text in a face called Quicksand. It was downloaded from Google's font servers on first run and cached on your phone, which meant the app contacted Google before you had done anything at all. The font file now ships inside the app, and the package that fetched it has been removed outright rather than switched off — so that request is not made any more, on first run or ever, online or offline.

What we do not collect

We want to be specific, because vagueness here is how policies mislead.

Aureloo has no advertising SDK, no analytics SDK, no crash or error reporting service and no attribution service, and it sends no push messages. We have checked the app's full dependency list to confirm this, not just its intent. The reminders the app shows are notifications the phone schedules for itself, and the only thing the app reads about the install is an invite code; both are described below.

A few things libraries do on their own belong here. On Android, the Firebase library that carries the app's requests to our server asks Google, the first time such a request is made, for an installation ID and a registration token for this copy of the app, and attaches the token to those requests. They identify the installation, not you; reinstalling or clearing the app's data gives new ones. Aureloo does not read, store or use them, and sends no push messages. On an iPhone, the Firebase libraries in Aureloo ask for neither. If you sign in with Google, Google's sign-in library may use your IP address to estimate a general location, for Google's fraud checks. Firebase's libraries tell Google the device, the operating system, the app's bundle ID and the platform, not linked to you, which Google uses to measure platform and version adoption.

We do not collect your location: the general estimate above stays with Google. We do not read your contacts. We do not access your photos, your files, your camera, your phone number, your call or message history, your installed-app list, or your advertising ID. The one identifier of an Android phone that Aureloo itself uses is a hash of its Android ID, for the invite programme only, and the ID itself never leaves the phone. On an iPhone, Aureloo keeps no identifier of the phone: the invite programme relies on Apple's DeviceCheck instead. Both are explained under Inviting friends.

A few things ask for your consent. The microphone, only for the speaking exercise; on an iPhone, speech recognition is asked for at the same moment. Notifications, only for the reminders, on Android 13 and later and on every iPhone. And on an iPhone, if you choose Save Image for an achievement card, permission to add pictures to your photo library, which does not let Aureloo see what is in it. You can refuse any of these and keep using everything else.

On Android, the rest of what the app declares are permissions the system grants without a prompt. For completeness, the installed app declares fourteen permissions in total: internet access and network state; the microphone; three for the reminders — showing notifications, putting the schedule back after the phone restarts, and vibration; the billing permission Google Play requires in order to sell anything; one that lets the app ask Google Play which link the install came from; five added automatically by Google's own libraries — access to Google Play services settings, the biometric and fingerprint permissions that Google's sign-in library declares whether or not we use them, and two that a Firebase library declares for Google's messaging service (keeping the phone awake for a moment, and receiving its messages) — the service the registration token above comes from, although Aureloo sends no push messages; and one that Android's support libraries define for Aureloo alone, com.azsmartstudios.aureloo.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION, which only lets the app deliver internal messages to itself and grants nothing outside it. We do not use biometric or fingerprint data, and Aureloo has no biometric feature. An iPhone app has no such list: there, the questions above are all that Aureloo can ask.

We build no profile of you, we run no behavioural tracking, and we do not sell, rent or share your personal data with anyone. There is no third party we hand your data to for their own purposes.


Your learning data

Everything you create in Aureloo — your word collections, folders, learning spaces, grammar notes, your spaced-repetition schedule and your practice progress — is stored in a database on your phone. So is the list of days on which you practised, which is what the daily streak is counted from.

Unless you connect Google Drive or send something to a friend, it never leaves the device. We do not keep a copy, and having an account does not change that: your account record holds your identity, not your words. Whether or not you use sync, we could not produce your learning data if you asked us to, because we do not have it. The one exception is an item you sent to a friend that is still waiting, or one that was reported — see Sending to a friend. And the one thing the app ever says about your practice is the "active today" signal of an invitation you accepted, described under Inviting friends.

Google Drive sync (optional, off by default)

If you want your data on more than one device, you can connect Google Drive. It stays off until you turn it on yourself. The app does not ask for it when you sign in: the Google Drive card in Profile has a Connect Drive button, and only tapping it opens Google's permission window.

Which Google account it may be depends on how you sign in to Aureloo:

  • If you sign in with Google, or your account's address is a Gmail address, Drive connects only to that same Google account. A different one is refused.
  • If your account's address is at another provider — this includes an address Apple makes when you hide your email — you may choose any Google account. When it is not your sign-in address, the app asks you once to confirm it.

A Drive connection made before this rule existed is left as it is. Whichever account it is, Aureloo asks Google for exactly one permission:

https://www.googleapis.com/auth/drive.appdata

This is worth understanding, because it is the strongest privacy property Aureloo has. drive.appdata grants access to a hidden, per-application folder inside your Drive called the app data folder. It does not grant access to your Drive. With this permission Aureloo:

  • cannot see, list, open or modify any file you have in Drive — not your documents, not your photos, not your spreadsheets, nothing;
  • can only read and write its own sync files, in a folder it cannot see out of;
  • cannot see files placed there by any other app, and no other app can see Aureloo's.

Each Aureloo account keeps its own sync file in that folder, named aureloo-sync-<account id>.json, where the account id is the random user id described above. If two Aureloo accounts are connected to the same Google Drive, each one reads and writes only its own file.

While Drive is connected, the app keeps it up to date by itself. Each time the app starts, and right after you connect Drive, it quietly fetches your sync file and merges it with what is on the phone; it syncs again shortly after you change something, when you leave the app, now and then when you come back to it, and whenever you tap Sync now.

The folder is inside your Google account. It counts against your storage quota, it disappears when you delete the app's data from your Google account, and you can revoke Aureloo's access at any time from your Google account permissions page. If you revoke it, sync simply stops; the app keeps working and your data stays on your phone.

The only addresses Aureloo contacts for sync are www.googleapis.com/drive/v3/files and www.googleapis.com/upload/drive/v3/files. Your synced data goes to your Drive. It does not pass through our server.

Signing out

Signing out does not delete your words, and Aureloo makes sure you know where they are before you go.

  • With Drive connected, the sign-out window says that your words will be sent to Drive first. The app syncs, and signs you out by itself only if that sync succeeded. If it did not — the phone is offline, say, or another of your devices is syncing at that moment — you stay signed in and the app tells you why. You can then try again, or sign out anyway once you have been told that your words stay on this phone only.
  • Without Drive, the window warns you that your words are only on this phone, and offers to connect Drive. If you sign out anyway, the app first checks that the phone is online by requesting https://clients3.google.com/generate_204, because nobody can sign back in without a connection. No data about you is sent: the address is the same for everyone, and all it returns is an empty "204". If no answer comes, you stay signed in.

Either way, your words stay on the phone after you sign out. They are filed under your account, so nobody else who signs in on that phone can see them, and they are there again when you sign back in. Signing out also ends that phone's Drive connection: after you sign back in, you connect it again in Profile.


What our server keeps

Aureloo has a small server of its own for four optional things: promo codes, invitations, your nickname, and sending something to a friend. It is built from Google Cloud services — Cloud Functions and a Firestore database, in Google's data centres in the European Union. The app cannot read that database. Every request goes through a function that first checks which account is asking, and turns away an account made with an email address and a password whose address is not confirmed.

Everything below is filed under your user id — the random string in the account table above — and not under your email address or your name. None of it is sold, handed to anyone for their own purposes, or used for advertising.

Besides the records themselves, the server keeps a few counters, so that these functions cannot be hammered: how often an account called each one in the current hour, how many wrong codes it tried, and how many items it sent on each day. Like any server it also writes technical logs of what it did — that a nickname was set, a code was used or an item was sent — with user ids, the ids of the records involved (for a promo or invite code, the code itself) and the outcome. The content of an item is never written to a log. Like any connection, a request shows Google Cloud the phone's IP address; its request log keeps it, with our own log lines, for 30 days.

Promo codes

A promo code gives an account Pro for a period without a payment. When you enter one, the app sends what you typed to our server. If the code is accepted, the server records, under that code, your user id, the date, and the date your gift Pro runs to. Under your user id it also notes when your gift time ends, so that a second code adds its time after the first. It then asks RevenueCat — the service that already keeps track of purchases — to give your user id Pro until that date; see Purchases.

A code that is not accepted is not recorded. Only the number of wrong tries in the current hour is kept, because five are allowed.

Inviting friends

Your invite code. The first time you open the invite page — or share an achievement card, which carries the same link — the server creates an invite code for your account. It keeps the code, the number of your friends who have counted, and the rewards you earned.

An invitation someone accepts. When a person accepts an invitation, by installing from an invite link on Android or by typing an invite code, the server keeps an invitation record under that person's user id: whose code it was, when it was accepted, and how it ended. On a day when that person finishes a practice test or a game round, the app tells the server "active today" — once a day at most, during the two weeks after accepting (the app stops after 15 days). The server takes note only during the first 14 days and only until the invitation is decided, which normally happens on the third such day. What it writes down is its own date for that day and nothing else: not what was practised, not for how long, not how well. Those dates stay in the invitation record. The inviter sees friends only as "Friend 1", "Friend 2", with a status and a count of active days — never a name, an email address or a user id.

A confirmed email address. For an invited friend to count, the friend's account has to sign in with Google or have a confirmed email address. Our server reads the "confirmed" flag that Firebase keeps with the account when the invitation is decided. How an address gets confirmed is described above, under Your account, which you must have.

A hashed phone identifier on Android, against abuse. One phone may count for an invitation only once, for the first account that shows it. To check that without learning which phone it is, on an Android phone the app reads the phone's Android ID, puts a fixed prefix in front of it and computes a SHA-256 hash, on the phone. Only that hash is sent. The Android ID itself never leaves the phone, and the app does not store or log it. The hash goes to the server when you enter a code in the promo-code field (for a promo code it is ignored and not stored), when an invitation is accepted, and when the app asks for your invite code and progress. The server keeps it in three places: in a friend's invitation record, in a list of the phones an inviter has used (the newest five), and in an index of which account first showed each phone. A hash cannot practically be turned back into the Android ID, but it is the same every time for the same phone — that is what makes the rule work — so it is an identifier of your phone, and we treat it as one.

Apple's DeviceCheck on iPhone, for the same purpose. An iPhone gives apps no such identifier. Instead, the app asks Apple for a new one-time token for the phone and sends it to our server when you enter a code in the promo-code field, which on an iPhone is where an invite code is typed (for a promo code the token is neither stored nor sent to Apple), when an invitation is accepted, and when the app asks for your invite code and progress. The server uses the token to ask Apple's DeviceCheck service about two bits that Apple keeps for that iPhone and for our developer account alone, with the month they last changed: one saying that the iPhone has been used to accept an invitation, the other that it is the phone of someone who invites friends. Accepting an invitation reads both and, if neither is set, sets the first; asking for your invite code and progress sets the second, but only once your account can no longer accept an invitation itself (it has accepted one, or it was created more than 7 days ago), and stores nothing about the phone. The token itself is not stored: the invitation record keeps only a one-way scrambled form of it, so that the same token cannot count twice, together with the kind of phone, the two bits as Apple reported them and whether we set the first. The bits hold no user id, name or email address, and we send Apple none. Apple keeps them for that iPhone, also when the app is deleted and installed again, and we never reset them, so an iPhone that has been used once does not count for an invitation again.

The install link. On an Android phone, the first time the app starts, it asks the Google Play app which link the install came from. If that link carried an invite code, the app keeps the code on the phone and sends it to our server once you have signed in. Nothing else from the link is kept or sent. When an invitation is accepted this way, the app tells you so once: the days you practise in the next 14 days count for the friend who invited you — only their dates — and that friend never sees your name or your email address. An iPhone does not tell an app which link it was installed from, so a friend on an iPhone types the code where promo codes go.

The page an invite link opens. Invite links, and the links that travel with achievement cards, open a page on this website, aureloo.com/get. A small script of our own on that page reads the invite code from the link and shows it. It sends an Android phone on to Google Play, passing the code on inside the link; on an iPhone, where the code has to be typed in the app, a link with a code stays on the page and shows it, and a computer stays on the page too. The script keeps nothing in your browser and sends nothing to us.

Your nickname

To send something to a friend, or to be sent something, you choose a nickname: 3 to 20 characters, made of Latin letters, digits and _. Until you choose one, none exists. The server stores it with your user id, together with two settings: whether you accept shared items, and — only if we have had to set it — a mark that stops the account from sending.

Who can see your nickname:

  • the people you send to, as the sender of the item;
  • anyone who types it exactly in the send window, who is told that it exists. There is no list of nicknames and no search by part of a name;
  • anyone who has blocked you, in their own list of blocked senders;
  • we, in our admin panel.

A person who accepted something from you also keeps your nickname on their phone, as the label of what came from you, and in their own Drive sync file if they use sync.

You can change your nickname, and the old one then becomes free for someone else. A nickname we reset because it was offensive stays unavailable to everybody.

Sending to a friend

You can send a friend one of your folders, a whole category, or a grammar rule you wrote. When you do, a copy of that content goes to our server, together with your user id and nickname, the recipient's user id, the title, the number of folders and words, the two languages and the time. This is the one case in which words you wrote are held by us.

They are held briefly:

  • the copy is deleted as soon as your friend accepts or declines it — blocking and reporting are ways of declining, described below;
  • if your friend does neither, it expires 24 hours after you sent it. From that moment neither of you can list or open it, and the database's own clean-up then erases it; Google states that this normally follows within 24 hours.

Both of you are told about the 24 hours: the sender when the item is sent, the recipient on the item itself.

When a friend accepts, the content becomes ordinary words on their phone. Their phone also remembers your nickname and a key that stands for you — a hash of your two user ids, from which neither can be read — so that the next thing you send lands in the same place.

You can stop receiving altogether with Accept shared items in Profile. While it is off, or if you have blocked the sender, the sender is told only that nothing can be delivered, not why.

Our admin panel shows us reported items, the number of items sent per day, and nicknames. It has no screen for the content of an item that is waiting, though the admin account could technically read the database while the item is there.

Reports and blocking

Blocking. When you block a sender, the server keeps the block — your user id, theirs and the date — and refuses their later items. Your blocked senders are listed in Profile, where you can unblock them.

Reporting. When you report an item, the server keeps a copy of it for review: the content, its title, the sender's user id and nickname, your user id as the person who reported it, and the dates. A person on our side reads it in the admin panel. The copy of the content is deleted when we close the report. What is left of the report — who reported whom, the title and the dates — is deleted 30 days after the report was made, and a report we have not closed by then is deleted whole at that point. As with the 24 hours above, the erasing is done by the database's clean-up and can follow the deadline by up to about a day.

When we act ourselves — closing a report, stopping an account from sending or resetting a nickname, and in the invite programme counting a friend by hand or withdrawing a reward — we keep a note of that action: what was done, to which user id, and when. A note about stopping an account from sending or resetting a nickname also holds the nickname the account had at the time. The terms of use say when we do these things.


Reminders and the daily streak

Aureloo counts a daily streak: the days in a row on which you finished at least one practice test or one game round. The list of those days, each with the time of day you first practised, is part of your learning data — on your phone, and in your Drive sync file if you use sync. It is not sent to us.

The reminders are notifications your phone schedules for itself. No server sends them and they need no connection. To choose their time the app uses three things that are already on the phone: the days you practised, the date you last opened the app, and the time of day you usually start. At most one reminder is shown in a day.

On Android 13 and later the phone asks before it shows any notification, and so does every iPhone. The app raises that question once: by itself after your second finished practice test at the earliest, or when you turn on the Reminders switch in Profile. An iPhone shows the question only once; if you decline it, the switch opens the iPhone's Settings, where notifications for Aureloo can be allowed later. On Android 12 and earlier the system allows notifications without asking, so the reminders are on from the start. Either way you can switch them off in Profile → Reminders, or in the phone's own notification settings. Signing out cancels the reminders that were scheduled.

Achievement cards

When you reach a milestone — a number of words learned, a streak, a new game record — the app can make a picture for you to share. It is drawn on your phone and handed to the phone's share sheet; you choose where it goes, and Aureloo uploads nothing itself. On an iPhone, if you choose Save Image there, the phone asks once whether Aureloo may add pictures to your photo library; it cannot see what is already in it. The picture carries no personal data: no name, no email address, no nickname — only the number, a sentence, the language you are learning and the Aureloo name. The text that travels with it contains a link to Aureloo, aureloo.com/get, which opens the App Store on an iPhone and Google Play elsewhere, and that link may include your invite code, so that a friend who installs from it — or, on an iPhone, types the code the page shows — counts as invited by you. To put the code in, the app may ask our server for it at that moment.


Microphone and speech

One practice exercise asks you to say a word out loud so the app can check your pronunciation. The microphone is used only while that exercise is listening, only after you have granted microphone permission (on an iPhone, speech recognition permission as well), and only when you start it. Nothing records in the background, and no other part of the app uses the microphone.

Here is the part we want to be straight about.

Aureloo never receives, stores or transmits your voice. The app does not save recordings and does not upload audio anywhere; nothing on our server accepts audio. What Aureloo receives back is the recognised text — the words you said, as text — which it compares with the expected answer and then discards. The text is not stored or sent anywhere either.

But the recognition itself is not done on your device. Aureloo hands the microphone to the speech recognition service built into your phone. On almost all Android phones, that is Google's, and it works by streaming the audio to Google's servers for recognition. Aureloo does not currently ask for offline recognition, so unless your phone is configured otherwise, you should assume that when you use the speaking exercise, your voice reaches Google.

On an iPhone, it is Apple's. Aureloo uses Apple's speech recognition and does not ask for recognition on the device, so Apple may send the audio to its servers to recognise it. You should assume that when you use the speaking exercise on an iPhone, your voice may reach Apple.

What happens to that audio is governed by Google's or Apple's privacy policy and your account settings with them, not by this policy. If you have offline speech recognition installed for the language, or your device uses a different recogniser, the audio may stay on the device — but that depends on your phone and your settings, and we cannot promise it. We are looking at requesting on-device recognition where the phone supports it.

If you would rather not do this, simply do not grant microphone permission, or do not use the speaking exercise. Everything else in Aureloo works without it.

Spoken audio (text to speech)

The app can read words aloud to you. It does this by sending the word being practised to your phone's own text-to-speech engine. It captures nothing and listens to nothing. As above, whether that engine is fully offline depends on your phone's engine and settings.


Purchases

Aureloo has a free version and a paid "Pro" version.

Pro is sold through Google Play on Android and through Apple's App Store on iPhone, with RevenueCat as the service that keeps track of whether your purchase is valid. There are three plans: a monthly and a yearly subscription, which renew until you cancel them in the store you bought them from, and a lifetime plan that is paid once. The price is the one the store shows you before you confirm.

We never see your card details. Payment is handled entirely by the store: Google Play, or Apple on an iPhone. What reaches us is limited to what is needed to know that you are entitled to Pro — the identifier of the Aureloo account the purchase belongs to, which product you bought, and whether the purchase is still active. Your name, card number and billing address stay with Google or Apple, whose own privacy policies cover how they handle the payment.

Gift Pro. Pro can also reach an account without a purchase: through a promo code, or as a reward for inviting friends. In that case our server asks RevenueCat to give your user id Pro until a certain date, and RevenueCat keeps that grant in the same record as any purchases. No payment is involved, nothing renews, and neither store takes part in it.

A purchase belongs to your Aureloo account, and that is deliberate. When you sign in, the app tells the billing service which account is asking. What it sends is your Aureloo user id — the random string Firebase issues for your account — and not your email address or your name, neither of which is given to it. Until you sign in, and again after you sign out, the billing library uses a random identifier of its own instead, which is not linked to you. This is what makes a purchase follow the person rather than the handset: Pro comes with you to a new phone and survives a reinstall, and it cannot be inherited by whoever signs in next on a shared device. It works the other way too: a purchase cannot be restored onto a different Aureloo account, not even on the same phone with the same Google Play account or Apple Account. Pro stays with the account that bought it. That is a matter of fairness, and of privacy too — what you paid for is yours, not the phone's.

How often the app asks. When you sign in, and each time the app starts while you are signed in, Aureloo asks RevenueCat once whether your account has Pro, and keeps the answer on the phone. After that, it asks again when you come back to the app only if the answer it keeps is a day old, or the subscription it describes ends within a day. The billing library also passes on a renewal, a cancellation or a refund that RevenueCat reports while the app is open. When you are offline, the app goes by the answer it kept. Restore purchases in the Profile tab — or I already bought Pro on the Pro screen — asks the store for the purchases of the account signed in to it on the phone: the Google account on Android, the Apple Account on an iPhone. It is for when a purchase has not shown up on the account that made it.

The store's purchase record itself stays with your Google account or Apple Account. Google or Apple keeps it for its own tax and accounting purposes, and we cannot delete it — not on request, and not when you delete your Aureloo account. Deleting your account ends this phone's claim to Pro: Aureloo clears what the device remembers about your subscription and tells the billing service that this handset is no longer signed in as you. It does not cancel a subscription; only the store can do that. And because a purchase cannot move to another Aureloo account, a new account you create later does not get Pro back through Restore purchases — if that is what you need, write to support@aureloo.com with the order number from Google Play or from Apple's receipt.


If you are in the UK, the EU or another region with similar law, our legal bases are:

  • Performing our contract with you — holding your account details so you can sign in, having Firebase Authentication send the emails your account needs, knowing whether your account has Pro, syncing your data when you have asked for sync, and doing what you ask of the optional features: applying a promo code, running the invite programme you take part in, keeping your nickname, and delivering what you send to a friend.
  • Your consent — for microphone access (on an iPhone, together with speech recognition), and for connecting Google Drive. Both are optional, both are off until you choose them, and you can withdraw either at any time (revoke the permission in your phone's settings, or disconnect Drive in the app).
  • Our legitimate interests — keeping the app secure and preventing abuse of accounts. That covers the hashed phone identifier of the invite programme and, on an iPhone, its DeviceCheck question, the counters that limit how often the server can be called, and the review of reported items.

We do not rely on legitimate interests for advertising or profiling, because we do neither.


How long we keep things

  • Data on your phone stays until you delete it, or until you uninstall the app.
  • Deleted items are kept for a short period as "tombstones" — hidden markers that tell your other devices the item was deleted rather than never received. These are cleared after 180 days. This exists so that deleting a word on one phone does not have it reappear from another.
  • Your Drive sync file stays in your Drive until it is deleted — by deleting your account in the app while it can reach Drive, or by removing Aureloo's hidden app data from your Google account. Disconnecting Drive or signing out leaves it where it is. It is yours, in your account.
  • Your account record (the four items listed above, and what Firebase keeps beside them) is kept until you delete your account. When you do, it is deleted — see below.
  • The customer record at RevenueCat exists for every account that has signed in, because the app asks it whether the account has Pro. It holds your user id and any purchases and gifts made on it — no name, email address or payment details. Deleting your account in the app only disconnects this phone from it; if you want the record removed as well, write to privacy@aureloo.com.
  • Your nickname, your sharing settings and your list of blocked senders stay on our server until you change them or delete your account.
  • An item you send to a friend stays on our server until it is accepted or declined. If neither happens, it expires after 24 hours and is then erased by the database's clean-up, normally within a further day.
  • A report keeps its copy of the content until we close it, and is deleted altogether 30 days after it was made (again with up to about a day for the clean-up).
  • Each use of a promo code — your user id, the code, the time and the period it gave — is kept, so that a code cannot be used twice and its count of uses stays right. It is not deleted with your account.
  • Your invite code and your record as an inviter — the number of counted friends, the rewards and the hashed ids of your own phones — are kept until you delete your account. The code is then retired, and stays reserved so that it is never given to anyone else.
  • The record of an invitation you accepted, with the dates you practised on (and, from an iPhone, the two bits Apple reported and the scrambled token), and the hashed phone identifiers are kept against abuse, so that the same account or phone cannot be counted twice. They are not deleted with your account, and neither are your user id and your invite code inside the invitation records of friends you invited.
  • The two DeviceCheck bits that Apple keeps for an iPhone stay with Apple for good: we never reset them. They belong to the phone, not to an account, and hold no user id, name or email address.
  • Counters hold numbers and dates only. They are deleted with your account, and so is the note of when your gift time ends.
  • Our own log of actions holds what was done, to which user id and when; an entry about stopping an account from sending or resetting a nickname also holds the nickname at the time. The entries are kept.
  • Technical logs, and the IP address in Google Cloud's request log, are kept for 30 days.
  • What stays after you delete your account, and how to have it removed, is listed under Deleting your account and your data.

Deleting your account and your data

You can delete your account yourself, from inside the app. There are three separate things you may want to remove, and you can do any of them independently.

1. Your account, in the app. Open Profile and tap Delete account. After a two-step confirmation — and, if you have not signed in for a while, one more entry of your password or a fresh Google sign-in; with Apple, a fresh Apple sign-in every time — Aureloo removes the account record (user ID, email address, display name and photo URL) from Firebase Authentication, tells Apple to withdraw Aureloo's Sign in with Apple access if you signed in with Apple, erases everything that account holds on that phone, clears what the phone remembers about your subscription, tells the billing service that this handset is no longer signed in as you, and deletes your Google Drive sync file if it can still reach it. If the account record itself cannot be deleted, nothing else is removed; if you signed in with Apple, Aureloo's Sign in with Apple access may already have been withdrawn, and signing in with Apple again restores it. We do not keep a shadow copy.

What our server then removes. When the account record goes, our server cleans up after it by itself, normally within a minute. It deletes your nickname, which becomes free for someone else; your sharing profile and your own list of blocked senders; everything that was waiting in your inbox, content included; your send counts, the hourly counters and the count of wrong codes; and the note of when your gift time ends. It deletes your record as an inviter — the number of counted friends, the rewards and the hashed ids of your own phones — and a reward not yet granted is never granted. Your invite code is retired: the code itself stays reserved, with no account attached to it, so that it is never given to anyone else. A nickname we had reset stays reserved in the same way.

What stays. These records stay on our server, filed under your user id, which no longer belongs to an account:

  • each use of a promo code: the code, the time and the period it gave;
  • the record of an invitation you accepted: the inviter's user id, the invite code, when you accepted, the calendar dates you practised on during the 14 days, the hashed id of your phone (from an iPhone, instead, the two bits Apple reported, whether we set the first, and the scrambled one-time token), and how it ended;
  • in the records of friends you invited: your user id as their inviter, and your invite code;
  • hashed phone identifiers, each with your user id and a time: the phone you accepted an invitation on, and the phones you opened the invite page on;
  • items you sent that the recipient has not yet dealt with: the recipient sees them without your nickname until 24 hours after you sent them, and the server's copy — the content and your user id — is then removed by automatic expiry, normally within a further day;
  • your entry on other people's block lists — your user id and a time — until that person next opens their profile;
  • reports, each deleted 30 days after it was made: a report you made keeps your user id, and a report about something you sent keeps your user id, your nickname at the time, the title and, until we close the report, a copy of the content;
  • our own log of actions: entries about your account keep your user id, and entries about stopping it from sending or resetting its nickname keep the nickname at the time;
  • technical logs, for 30 days: your user id, the ids of records (for a promo or invite code, the code itself) and outcomes, with no nickname, title or content;
  • the customer record at RevenueCat, under your user id.

None of this holds your name or your email address; a nickname appears only where the list says so. On an iPhone, the two DeviceCheck bits Apple keeps for the phone stay with Apple for good, as we never reset them; they hold no user id, name or email address.

Having the rest removed. Waiting items, reports and technical logs expire by themselves. The other records we remove when you ask: we delete the promo-code uses, the invitation and phone records, your entry on other people's block lists and the RevenueCat customer record, and we strike your user id out of your friends' invitation records and your user id and nickname out of our log. Write to privacy@aureloo.com from the email address of the account. If you can, write before you delete the account, or ask us in the same message to delete it for you: once the account record is gone, that address no longer leads us to your user id.

For up to an hour. If the app is still signed in to the account on another phone, that phone can make the server start the hourly counters again for up to an hour after the deletion. They hold numbers only. Nothing else comes back; only a request that reaches the server at the very moment of the deletion can leave behind a little of what the clean-up removes — for example a nickname, a sharing profile, an invite code, or an item being sent at that moment, still carrying your nickname until it expires — which we remove when you ask.

2. If you can no longer sign in. Write to privacy@aureloo.com from the email address on the account and ask us to delete it. We remove the same account record, aim to complete it within 30 days, and confirm by email when it is done. The server clean-up described above follows from that by itself. Your phone and your Drive are beyond our reach, so those are yours to clear, and so is Aureloo's Sign in with Apple access if you used Apple: you end it in your Apple Account settings, under Sign in with Apple.

3. What only you can reach. If Aureloo has lost its Drive permission it says so and leaves the sync file alone — remove it yourself in Drive → Settings → Manage apps → Aureloo → Delete hidden app data, or from your Google Account under Data & privacy → Apps and services; that removes the sync file of every Aureloo account connected to that Drive. Any other phone you used keeps its own local copy until you uninstall Aureloo there, or on Android clear its data from the app settings.

Because signing in is required, deleting your account also ends your access to the app: to use Aureloo again you would have to create a new one. Full instructions, including what survives deletion and why, are on our account deletion page.


Your rights

Depending on where you live, you may have the right to ask us for a copy of the personal data we hold about you, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable form. If you are in the EU or UK you also have the right to complain to your data protection authority.

Because we hold little — the account record, the customer record at RevenueCat, and whichever of the server records above apply to you — most of these requests are quick to answer. Your learning data is not something we can produce, because it is on your phone and, if you use sync, in a hidden app folder of your own Drive, which you can delete but not open. Aureloo 1.1 has no export file.

If you are in California, we do not sell or share personal information as the CCPA defines those terms, and we do not process it for cross-context behavioural advertising. We will not discriminate against you for exercising any privacy right.

To exercise any of these, email privacy@aureloo.com. We will not charge you, and we will not ask you for more information than we need to find your account.


Children

Aureloo is a general-audience app. It is not directed at children, and it is not enrolled in Google Play's Designed for Families programme or in the App Store's Kids category. We do not knowingly collect personal data from children under 13 (or under 16, where local law sets that age), and the app does not ask a user's age.

We want to be honest about what that means rather than claim a certification we have not implemented: Aureloo has not been built to COPPA or Families-programme requirements, and we do not operate a parental consent mechanism. A younger child should use it with a parent's involvement. Because an account is required, there is no way to use Aureloo without an email address reaching Firebase Authentication, so the sensible arrangement is for a parent to create the account, own it, and know that it exists.

If you believe a child has given us personal data, email privacy@aureloo.com and we will delete the account and the data promptly.


Where your data goes

AZ Smart Studios LLC is in the United States. The services we rely on — Firebase Authentication, Google Drive, Google Play — are operated by Google and run on infrastructure in several countries, so if you are outside the United States, your account information will be processed outside your country, including in the US. RevenueCat, which keeps the customer record described above, is also based in the United States, and so is Apple, which on an iPhone provides Sign in with Apple, the App Store, speech recognition and DeviceCheck.

Our own server — the functions and the database described under What our server keeps — is hosted by Google Cloud in the European Union. We are a company in the United States and read those records through our admin panel, so they are also accessed from outside the European Union.

Where the UK or EU GDPR applies, these transfers rely on the European Commission's Standard Contractual Clauses and the equivalent UK provisions, which Google incorporates into its terms for these services.

Your learning data is a different matter: it does not travel to us, except for an item you send to a friend, for the short time described above. It sits on your phone, and — if you turn on sync — in your own Google account, wherever Google stores that for you.


Security

Your account credentials are handled by Firebase Authentication, and connections to Google's and Apple's services, to RevenueCat and to our server use encrypted HTTPS. A sign-in with Apple carries a one-time value, so that Apple's answer cannot be used a second time. The database on our server answers only to its own functions and to our admin account; the app has no direct access to it. The sync file in your Drive is protected by your own Google account security, so turning on two-factor authentication there protects your Aureloo data too.

The data on your phone is protected by your phone: its lock screen and its encryption. If someone can unlock your phone, they can open Aureloo.

No system is perfectly secure, and we will not pretend otherwise. But the honest security story here is that there is little to steal from us — we hold no payment details and no passwords, and no learning data beyond an item on its way to a friend or a reported copy.


Changes to this policy

If we change this policy we will update the date at the top. If a change materially affects your privacy — for example if the app starts collecting something new — we will tell you in the app rather than quietly editing this page: the version of the app that brings the change shows a notice the first time you open it, with links to this policy and the terms, before the app makes any of the new requests to our server.


Contact

Questions, requests or complaints:

Email: privacy@aureloo.com
Support: support@aureloo.com

Postal:
AZ Smart Studios LLC
South Carolina, United States

We read everything sent to these addresses and will reply.