1. Scope
This Privacy Policy applies to the Lingo Pal mobile app, its widgets, this website, and related support. “We,” “us,” and “our” refer to the operator of Lingo Pal. It does not replace the separate privacy notices of Apple or other services you choose to use.
2. Information we use
Account and authentication
We use your phone number to send a one-time SMS sign-in code. Authentication is handled by Supabase and an SMS delivery provider. After sign-in, an internal account identifier—not your phone number—is used to link app records and billing status. One-time codes and access tokens are not stored in our ordinary app database.
SMS verification and your consent
When you enter your mobile number and tap “Text me a code,” you affirmatively request and consent to receive an automated, non-marketing SMS from Lingo Pal containing a one-time security code at the number you provided. Each resend requires another action from you. Message frequency varies with your sign-in and resend requests, and message and data rates may apply. You do not need to purchase anything to request or receive a code, and this consent does not authorize marketing messages.
By providing the number, you represent that you are its subscriber or customary user and are authorized to receive messages at it. We use the number for authentication and account security—not advertising. Supabase, our configured SMS delivery provider, and telecommunications carriers receive the number and limited delivery information needed to send, secure, and troubleshoot the code. We do not sell your phone number or share it for another company’s marketing.
You may withdraw consent before another message is sent by not requesting or resending a code. You may also follow any opt-out instructions shown in the message or contact Support. Because SMS verification is the app’s current sign-in method, blocking or opting out of these messages may prevent future sign-in. Delivery is not guaranteed, and carriers are not liable for delayed or undelivered messages. See our Terms of Use for the terms that apply to the service.
Learning and pet activity
We store your selected language and timezone, learned-sentence progress, authored quiz answer identifiers and scores, pet name and color, health, XP, level, world history, and server-calculated learning deadlines. Quiz answers are selections from lesson content; the app does not ask for free-form learner writing.
Purchases and subscriptions
Apple processes payment. RevenueCat helps us verify subscriptions, Revive purchases, refunds, and entitlements. We receive product, transaction, entitlement, environment, and timing information, but not your full payment-card details. Your internal app account identifier is used as the RevenueCat customer identifier.
Notifications, widgets, and device information
If you enable notifications, we may store an Expo push token and limited delivery status information. Local reminder schedules and a safe widget snapshot may be stored on your device. The widget snapshot is limited to pet presentation, health/state, three lesson focus chunks, a deadline, and an app link; it does not contain your phone number, credentials, or transaction identifiers.
Product analytics and support
We may record a limited set of app events and bounded settings—such as lesson started or completed—to understand reliability and product use. These events are linked to your internal account while it exists. We do not include phone numbers, one-time codes, tokens, lesson answers, or free-form personal text in analytics. If you contact support, we receive the information you include in your message.
3. How we use information
We use information to:
- authenticate you and protect your account;
- deliver and grade lessons, preserve progress, and calculate pet state;
- verify purchases, restore entitlements, prevent duplicate credits, and handle refunds;
- schedule optional reminders and update the widget;
- operate, secure, troubleshoot, and improve the service;
- respond to support, privacy, and account-deletion requests; and
- comply with legal, tax, accounting, fraud-prevention, and security obligations.
4. Service providers and disclosure
We disclose only the information reasonably needed to providers that help operate the service. These may include:
- Supabase for authentication, database, and application infrastructure.
- Apple for App Store distribution, purchases, subscriptions, notifications, and device services.
- RevenueCat for purchase and entitlement verification.
- Expo and Apple Push Notification service for optional remote-notification delivery.
- Hosting and operational providers for secure app delivery, logs, and service monitoring.
OpenAI may be used by an administrator to prepare editable curriculum drafts. We do not send OpenAI learner phone numbers, pet names, lesson history, or learner answers.
We may also disclose information when required by law, to protect users or the service, or as part of a business transaction subject to appropriate safeguards. We do not sell personal information or share it with data brokers.
5. Tracking, ads, and device permissions
The current app does not use information to track you across other companies’ apps or websites, does not serve behavioral advertising, and does not request App Tracking Transparency permission. It does not request access to contacts, photos, camera, microphone, health, motion, or precise location. Your selected timezone is used to calculate a learning day; it is not GPS location.
Notification permission is optional. You can change it at any time in iPhone Settings. Reminder delivery never determines your learning progress or pet state.
6. Retention and deletion
We keep active account, learning, and pet information while your account is open and as needed to provide the service. Signing out clears your session, but limited account-keyed recovery information may remain on the device so unfinished verified actions can resume safely. Device-only information is cleared during successful account deletion or when you remove the app or its data.
When you complete account deletion, ordinary account-linked profile, progress, quiz, pet, subscription-cache, push, notification, analytics, and authentication records are deleted. We also request deletion of the linked RevenueCat customer record.
Limited purchase, refund, Revive-ledger, fraud-prevention, security, tax, accounting, or legal records may be retained in de-identified form. They are detached from your account. The final production retention schedule—including the applicable periods for financial records, security logs, provider logs, and backups—will be published here before the service accepts live accounts.
Account deletion does not cancel an Apple subscription. Apple may retain purchase information under its own terms, and restoring purchases can recreate billing-provider records. Read our account deletion guide before deleting.
7. Your choices
- Turn notifications off in iPhone Settings.
- Change your learning language and eligible timezone settings inside the app.
- Manage or cancel Apple subscriptions through your Apple Account.
- Initiate permanent account deletion in Settings → About & account → Delete account.
- Ask support about access, correction, deletion, or other privacy rights available where you live.
We may need to verify your identity before fulfilling a privacy request. We will not ask you to send a one-time sign-in code by email.
8. Security and international processing
We use technical and organizational measures intended to protect information, including verified authentication, encrypted network transport, access controls, server-side authorization, and restricted administrative access. No system can be guaranteed completely secure.
Providers may process information in countries other than your own. The production operator will document the providers, processing locations, and legally required transfer safeguards here before the service accepts live accounts.
9. Children and changes to this policy
The service is not directed to children below the minimum age required to consent to an online service in their country. If you believe a child has provided information without appropriate permission, contact us. We may update this policy when the service or legal requirements change and will update the date shown above.
10. Contact
For privacy questions or requests, email hello@rip.bet with “Privacy request” in the subject. You can also visit Support for app help.