Privacy Policy

Last updated: 2026-09-23

This notice describes what the Service does with your data today, in closed early access. It has not yet been reviewed by counsel for each market we plan to open in, and it is not legal advice.

1. Who processes your data

Namanu English (the "Controller") decides why and how personal data is processed.

There is no published contact address yet. The Service is in closed early access, it takes no payment, and a contact of record together with a designated personal-information protection officer are part of opening it commercially. The controls described in section 7 act on your data directly, without needing to write to anyone.

2. What we collect

Account: email address, display name, date of birth, password hash (bcrypt), Google account identifier (only if you sign in with Google), role, and sign-up date. Date of birth is collected to apply the minimum-age rule in section 10 and is used for nothing else.

Learning: the languages you study, the level you tell us you are at, speaking-session transcripts and the AI feedback on them, writing submissions and their corrections, practice answers, flashcards, and study progress.

Billing: plan, status, and trial dates. No payment is possible today — the Service accepts no card and holds no card data. When paid plans open, card details will be handled by the payment provider and the card networks, not stored on our servers.

Operational: rate-limit counters, request logs, an audit trail of administrator actions such as role changes and suspensions, and error records.

Performance timing, when switched on: your browser may report how long a page took to become usable (which page, the timing, and whether the screen was phone- or desktop-sized). These samples carry no account identifier, no persistent visitor identifier, and no device details, and are used only to keep the Service fast.

3. Why we process it

To provide what you signed up for: generating feedback, storing your progress, and keeping you signed in.

To keep the Service working and safe: rate limiting, abuse and fraud prevention, and diagnosing errors.

To meet record-keeping obligations that begin once the Service charges money — tax and transaction records.

Marketing email and non-essential analytics are switched off. If either is ever turned on, it will be by an explicit opt-in you choose, never a pre-ticked box.

4. Who else receives your data (processors)

We run the Service ourselves, on a single server, and hand parts of the work to the companies below. Each receives only what the task in front of it needs, at the moment you use that feature — nothing is sent in bulk or in advance.

Model providers — Anthropic, OpenAI, and Google (Gemini API), all in the United States. They receive what you say and write in speaking sessions, writing tasks and practice; the text of documents you upload (résumés, slides, reference files); text you ask to have translated; and the small amount of context a good reply needs — your target language, the level you told us, the profession and industries you entered at onboarding, the lesson or scenario you chose, and the notes a story character keeps about you from earlier sessions. We never attach your account details to these requests — your name, email address, date of birth and password stay here. What you wrote or uploaded is sent as you wrote it, so anything personal inside it (a name or a phone number on a résumé, for instance) goes with it. Which of the three handles a given request is an operator setting; all three are in use today.

Google Cloud Text-to-Speech (Google LLC, United States) — receives the text spoken aloud in the app: the practice partner's lines, hints and listening passages. Those lines are generated by the model and can repeat things you said in the conversation.

OpenAI also runs one check that is not about generating anything: when you create a share link for a speaking report, the topic you typed for that session is sent to OpenAI's content-moderation service to decide whether it is shown on the shared page and its link preview. Only that one line of text is sent, and only when a share link is created or re-opened for a session whose topic has not been checked yet. The outcome changes nothing about the session itself.

Resend (United States) — delivers account email: approval, password-reset and similar notices. It receives your email address and the content of that message, which may include your display name. Nothing else, and no marketing mail.

Google sign-in (Google LLC) — only if you choose it. Google confirms who you are and gives us your Google account identifier, email address and name; we send Google nothing about your learning.

Your browser's speech recognition — when you speak, transcription happens in your browser's own speech-recognition service, which depending on the browser may run on your device or on the browser maker's servers (Google for Chrome, Apple for Safari). We never receive, record or store your voice — what reaches our server is text. When your browser does send the audio to its maker for transcription, that transfer is the browser's own and is governed by that company's privacy policy, not by this notice. Your browser's settings are where it can be turned off.

Hosting — the Service, its database and its nightly backups run on a virtual server rented from Cafe24, a hosting company in the Republic of Korea; a copy of the backups is held on the operator's own equipment, also in Korea. No other company receives a copy of the database.

Operational alerts — a small number of health signals (error counts, provider failures, spend against caps) reach the operator over Telegram. They carry counts and numeric account ids, never an email address or anything you wrote.

These companies act as processors for that content. The model providers may keep API inputs for a limited period for abuse monitoring under their own API terms, under which inputs are not used to train their public models by default. We make no claim here about executed data-processing agreements: negotiating and publishing those is part of opening commercially, and this notice will say so plainly when it is done. We do not use your content to train models of our own. Adding a recipient to this list is a change to this notice, not a quiet operational choice.

5. Where it goes

Storage stays in Korea: the database and its backups are in the Republic of Korea (section 4). Processing crosses a border: the three model providers and Resend handle the text you submit — and, for Resend, your email address — at the moment you use the feature, over an encrypted connection, for as long as their API terms say. All four are United States companies and each names the United States as its principal place of processing; we use their standard endpoints rather than a region-locked one, so we cannot promise that no request is ever served from another country they operate in. Under 개인정보보호법 (PIPA) §28-8 the recipients, their location, what they receive and why are named in section 4 so that the transfer is disclosed rather than assumed. Because the Service cannot produce feedback or deliver account email without them, the way to withhold your content from a provider is not to use that feature, or to delete your account under section 7.

Our planned payment provider (PortOne, in Korea) receives nothing today, because no payment is possible.

6. How long we keep it

Active accounts: kept for as long as the account exists.

Uploaded documents (resumes, slides, and writing reference files): they stop being usable 30 days after upload and are permanently deleted within 37 days.

Speaking and writing sessions: kept for as long as your account exists, so your progress, streaks and collection stay intact. You can delete any individual session at any time from Speaking history or Writing history, and everything is erased when you delete your account.

The one exception: speaking sessions you left before saying anything — where the practice partner opened and the conversation never started — hold no feedback and no progress, and are deleted automatically 30 days after they were opened. You can also clear them yourself at any time from Speaking history.

Deleted accounts: personal data is erased within 30 days. Operational records are stripped of the address at the same time: the delivery log for account email keeps only an anonymous record (which message, whether it was sent, when) with the address, subject and details removed; administrator audit entries keep the account's numeric id, never the address; and error reports never contain your text and lose their link to the account. One honest limit: nightly database backups are kept for 14 days, so anything deleted from the live database still exists in backups taken before the deletion until those rotate out.

Records that law requires us to keep, such as tax and transaction records once the Service charges money, are kept for the minimum period required (5 years under KR 전자상거래법).

7. What you can do

Export: download your data at any time from Settings → Account, in JSON.

Correct: edit your profile, languages, and level directly in the app.

Delete: delete your account at any time from Settings → Account, subject to the limits in section 6.

These act on your data immediately and do not require a request to anyone. You may also lodge a complaint with the Korea Personal Information Protection Commission (개인정보보호위원회).

8. Cookies and browser storage

Necessary cookies: llwc_session keeps you signed in; NEXT_LOCALE remembers whether you want the interface in Korean or English; llwc_referral records an invite link you followed so the invitation can be credited when you sign up.

Google sign-in cookies: g_oauth_state, g_oauth_verifier, g_oauth_from, g_oauth_invite, g_oauth_referral, and g_oauth_pending are created only when you use Google sign-in, and are cleared as soon as it finishes or expires.

Your cookie choice is stored in your browser's local storage under llwc_cookie_consent — it is not itself a cookie and it never leaves your device.

There are no advertising cookies and no third-party tracking. Analytics is off by default; if it is ever enabled it will collect aggregated, non-identifying usage statistics only.

9. Security

Passwords are hashed with bcrypt. Session cookies are HttpOnly and, in production, Secure. Traffic is HTTPS only.

There is no published address for vulnerability reports yet.

10. Minimum age

You must be at least 14 to create an account — the threshold in 개인정보보호법 above which a guardian's consent is not required. Date of birth is checked at sign-up on every route, including Google sign-in, and an account is not created for anyone below it.

If you believe someone under 14 holds an account, tell us and we will delete the account and its data.

11. Changes to this notice

Material changes will be sent to your registered email at least 30 days before they take effect.