Privacy Policy
Last Updated: May 14, 2026
1. Introduction
Welcome to InfinLume ("we," "our," or "us"). We are committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our websites, mobile application available on iOS and Android, and related services (collectively, the "Services").
By using InfinLume, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Services.
2. Information We Collect
2.1 Information You Provide
- Account Information: When you create an account using Google Sign-In or Apple Sign-In, we may receive your name, email address, and profile picture or avatar from those services, depending on the provider and your settings.
- Learning Data: Your responses to lessons, quiz answers, progress through courses, and learning preferences.
- Profile Information: Any additional information you choose to add to your profile, such as language learning goals.
- Website Diagnostic, Waitlist, and Feedback Data: If you use our website diagnostic, waitlist, or feedback tools, we may collect information you submit or generate there, such as declared level, diagnostic answers, answer timing, diagnostic results, claim or session identifiers, waitlist information, feedback submissions, votes, and contact details you choose to provide.
2.2 Information Collected Automatically
- Usage and Product Analytics Data: Information about how you interact with the Services, including screens or pages viewed, features used, lessons or reading content opened, quiz or diagnostic progress, paywall views, purchase funnel actions, notification prompts, clicks, scroll depth, referrers, and approximate time spent in parts of the Services.
- Website Analytics, Heatmaps, and Session Recording: On our website, we may use analytics tools such as PostHog, Google Analytics, and Vercel Analytics to understand visits, page views, page exits, downloads, clicks, diagnostic-result carousel usage, and similar product behavior. Selected website diagnostic or results pages may use PostHog heatmaps or session recording to help us understand usability problems. Session recording is not intended to collect sensitive information, and claim-code text is masked where recording is used.
- Device, Browser, and App Information: Device type, browser type, operating system, app platform, app version, build number, page URL, timestamps, and pseudonymous identifiers such as a locally generated app installation identifier or analytics identifier.
- Local Storage and Cookies: We use local storage, cookies, and similar technologies to cache lesson content, progress data, preferences, website diagnostic session or claim identifiers, feedback identity cookies, and analytics identifiers for performance, continuity, fraud prevention, and product measurement.
- Analytics Safeguards: Our current mobile analytics implementation disables automatic capture and does not use mobile screen recording or session replay. Before sending mobile analytics events, we also filter sensitive property names such as authentication tokens, claim tokens, question text, translation text, selected or correct answer text, names, and email addresses. Website diagnostic events are designed around metadata, progress, and results rather than raw free-form personal content.
2.3 Information from Third-Party Services
When you sign in using Google or Apple, we receive limited information as permitted by your privacy settings with those services. We do not have access to your passwords for these services.
2.4 Payment and Subscription Information
InfinLume offers optional paid auto-renewing subscriptions, including InfinLume Plus, through Apple App Store or Google Play Store billing. Payment is processed by the applicable app store, and we use subscription infrastructure providers such as RevenueCat to validate, restore, and manage subscription entitlements.
We and our payment infrastructure providers may process limited subscription-related data, including:
- Product, package, offering, plan, and entitlement identifiers, including Plus entitlement status
- Subscription status (active, trial, canceled, expired, billing issue)
- Purchase, renewal, cancellation, expiration, grace-period, and billing-issue timestamps
- Original and latest transaction identifiers where provided by the app store or subscription provider
- Store, environment, storefront, country, and currency metadata when provided by the store or subscription provider
- The app user or account identifier needed to connect a purchase to your InfinLume account
We do not receive or store your full payment card number in InfinLume systems.
2.5 Notifications and Reminder Data
If you enable notifications, we may process data needed to send and manage reminders and other app notifications, such as:
- Push notification token(s) associated with your device
- Notification permission status
- Your notification preferences, quiet hours, and preferred reminder time
- Your timezone and limited streak, review-due, or progress data used to schedule relevant reminders
- Records needed to avoid duplicate sends, troubleshoot delivery, and understand whether notifications are enabled
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Services' functionality
- Personalize your learning experience and adapt content to your skill level
- Track your progress and provide learning analytics
- Operate the website diagnostic, generate diagnostic results, and let you claim diagnostic progress in the mobile app
- Measure engagement, funnels, retention, and time spent in order to understand which parts of the Services are useful or confusing
- Measure paywall views, purchase funnel behavior, subscription status, and entitlement access
- Send you updates, notifications, and learning reminders (with your consent)
- Respond to your comments, questions, and support requests
- Monitor and analyze usage patterns to improve our services
- Process notification preferences, schedule reminders, and deliver push notifications if you enable them
- Validate, restore, and manage paid features such as InfinLume Plus
- Detect, prevent, and address technical issues or fraudulent activity
3.1 Legal Bases (where applicable)
Depending on your location, we process personal information under one or more legal bases, including performance of our contract with you, legitimate interests (such as security and product improvement), your consent (for optional communications/features), and compliance with legal obligations.
4. Data Storage and Security
We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using TLS/SSL
- Secure cloud infrastructure with industry-standard protections
- Regular security assessments and updates
- Limited access to personal data by authorized personnel only
Local data stored on your device is protected by your device's security features. We recommend using a device passcode or biometric authentication for additional protection.
5. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:
- Payment and Subscription Infrastructure: With billing and subscription providers needed to process, validate, restore, and manage purchases, including Apple App Store, Google Play Store, and subscription infrastructure providers such as RevenueCat.
- Service Providers: With trusted third-party service providers who assist us in operating the Services, such as backend/database and authentication providers, analytics providers (for example, PostHog, Google Analytics, and Vercel Analytics), and push notification infrastructure providers (for example, Expo), subject to contractual or comparable obligations to protect data.
- Authentication Providers: With identity providers such as Google and Apple as needed to support sign-in and account access you request.
- Legal Requirements: When required by law, court order, or governmental authority.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, where your information may be transferred as a business asset.
- Protection of Rights: To protect our rights, privacy, safety, or property, or that of our users or the public.
We do not sell personal information and do not share personal information for cross-context behavioral advertising.
6. Third-Party Authentication
Our App uses Google Sign-In and Apple Sign-In for authentication. When you use these services:
- You are subject to Google's and Apple's respective privacy policies
- We only receive the information you authorize these services to share
- We do not have access to your Google or Apple account passwords
- You can manage permissions through your Google or Apple account settings
7. Your Rights and Choices
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate personal information
- Deletion: Request deletion of your account and associated data
- Portability: Request a copy of your data in a portable format
- Opt-out: Opt out of marketing communications at any time
You can request account deletion directly in the app via Account Settings > Delete Account, or through our web form at infinlume.com/delete-account.
You can control push notification permissions in your device settings and, where available, update reminder preferences inside the App.
You can use browser or device settings to block or delete cookies, reset advertising or analytics identifiers where supported, and limit certain tracking technologies. Some analytics and diagnostic continuity features may not work as intended if cookies or local storage are disabled.
To exercise rights requests, contact privacy@infinlume.com. We may verify your identity before completing sensitive requests. We respond within the timeframe required by applicable law (for example, up to 45 days for certain U.S. state requests, with extension where permitted).
7.1 U.S. State Privacy Notice
For residents of U.S. states with privacy laws (including California), we do not sell personal information. Subject to applicable law, you may request access, correction, deletion, or a copy of your data and may appeal a denied request by replying to our decision email or contacting us at privacy@infinlume.com.
8. Children's Privacy
InfinLume is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us so we can delete such information.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws.
Where required, we use appropriate safeguards for cross-border transfers (for example, contractual protections or equivalent legal mechanisms) and limit access to authorized parties.
10. Data Retention
We retain your personal information for as long as your account is active or as needed to provide services. When you request account deletion, we delete or anonymize personal data from active systems within a reasonable period, except where retention is required by law.
Deletion requests are typically completed within 30 days. Some data may remain in secure backups for a limited cycle before being overwritten. We may retain limited records needed for legal compliance, fraud prevention, dispute handling, enforcement of our agreements, and reconciliation of any past purchases.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy in the Services or on our website and updating the "Last Updated" date. Your continued use of the Services after such modifications constitutes your acknowledgment and acceptance of the updated policy.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
Email: privacy@infinlume.com
We will respond to your inquiry within a reasonable timeframe.