1. Data controller
LURNI LTD, registered in England and Wales (company number 16483590), is the controller of personal data used to operate Lurni. The Lurni name and mark are registered with the UK Intellectual Property Office under trade mark UK00004211235 (effective 29 May 2025, registered 22 August 2025). Contact us at hello@lurni.com. This policy covers our website, mobile app, accounts and available learning services. Describing a service here does not activate it or change your subscription.
2. Website, device and diagnostic data
Our systems process connection and security information, such as IP address, device/browser information, request identifiers and access events, to deliver the service, prevent abuse and investigate faults. We use essential cookies and device storage for sign-in, security and preferences.
- Vercel Analytics and Speed Insights measure website visits, page interactions, approximate country, referrers and performance. We do not use them to track your browsing across unrelated services.
- Error monitoring, including Sentry where enabled, processes error reports, app/OS versions and diagnostic identifiers. Some identifiers can be correlated with an account or request; we do not describe all diagnostics as anonymous.
- We do not sell personal data or use advertising trackers. Device notification permission, microphone access and photo selection are used for the functions you choose, not advertising. You can control device permissions in your operating-system settings.
3. Waitlist data
The waitlist contains the email address you voluntarily supplied to join it. We use it for the waitlist purpose you agreed to, including launch information. We retain the list for one year for launch history and any previously promised early-access eligibility, unless you withdraw consent or request deletion earlier. We do not convert a waitlist entry into a registered account or send it to AI providers for new app features. You decide whether to register and see the current policy during registration. This policy update does not send a message to the waitlist.
4. Account, profile and authentication data
To create and secure an account, we process your email address, name, account identifier, password hash where you use a password, verification and session records, and the policy/marketing choices you make. Your profile may include an optional photo, native and learning languages, learning preferences and information you choose to provide.
- If you choose Google or Apple sign-in, we receive the provider's account identifier and the email/name or profile details it makes available. Apple may supply a private relay email. These details support authentication, account management and security.
- Google sign-in requests only openid, email and profile scopes, not Gmail, Drive, Calendar or Contacts. Google account data is not used for advertising, resale or AI model training. Our use of Google API information follows the Google API Services User Data Policy, including Limited Use requirements.
- Disconnecting a sign-in provider is different from deleting your Lurni account. Local biometric unlock, where used, is handled by your device; we do not receive your fingerprint or face template.
5. Learning content and artificial intelligence
When you use learning features, we process the answers, recordings, transcripts, vocabulary, notes, questions and conversations you submit, together with generated explanations, feedback, scores and progress. These records let you use the feature and revisit your learning. Please do not include sensitive personal information about yourself or others in exercises or chats.
- OpenAI processes submitted text and, for relevant voice features, audio to provide transcription, explanations and AI feedback. Microsoft Azure Speech processes audio and reference text for pronunciation/speech assessment. Only the providers required for the feature you use receive its content.
- Real-time voice features, where available, also use LiveKit for session transport. A voice recording and its saved transcript or feedback are separate records and may have different retention periods.
- Learning AI can make mistakes. Scores and feedback support study; they are not an employment decision or a professional qualification. We do not use lesson answers to make automated decisions with legal or similarly significant effects about you.
- We use provider business/API services for these functions, not public chat accounts. We do not sell your learning content or intentionally submit it to train general-purpose AI models. Provider processing, security and retention terms still apply; this is not a promise that every provider retains nothing.
6. Subscriptions, support and notifications
For purchases, we process account-linked transaction and subscription identifiers, products, prices/currency, payment status, renewals, refunds and access rights. Apple or Google handles in-app payment details; RevenueCat helps verify and manage the subscription state. Stripe handles supported website payments. We do not receive your full payment-card number from these payment flows.
- We keep support messages you send and the records needed to resolve your request. Payment providers may retain their own records under their policies and legal duties.
- Account/security and service messages use your account contact details. Optional device push uses a device notification token, Expo and Apple/Google delivery services. Marketing requires its own applicable permission and can be unsubscribed from; accepting this policy is not blanket marketing consent.
7. Purposes and lawful bases for processing
- Contract: provide the account, learning functions, subscription and support you request.
- Legitimate interests: keep Lurni secure and reliable, prevent fraud and abuse, investigate faults and administer previously promised eligibility, balanced against your rights.
- Legal obligations: keep required financial records and respond to lawful requests.
- Consent: the waitlist and optional marketing or other processing for which we specifically ask. You may withdraw that consent without affecting processing already lawfully carried out. Device permission is not blanket consent to unrelated uses.
If information is needed to provide a requested function and you choose not to supply it, that function may not work. Updating this notice does not create consent or change your stored acceptance history.
8. Technical infrastructure and service providers
Authorised personnel and service providers receive only the access needed for their role. Our infrastructure includes Render and Vercel (hosting), Neon (database), Upstash (queues/cache), Cloudflare (media and temporary recording storage/delivery), Resend (email), and Sentry (diagnostics). Feature-specific providers are OpenAI, Microsoft Azure Speech and, where used, LiveKit; payment/notification providers are described above. We may disclose necessary information to professional advisers, authorities when legally required, or a successor in a business transfer with appropriate safeguards. We do not sell personal data.
9. Data retention and account deletion
We keep account and saved learning records while needed to provide your account and learning history. You can request deletion in the app or through the website link on this page. Deletion and cancellation of an Apple, Google or Stripe subscription are separate actions; manage the subscription with the relevant provider to stop future renewals.
- The deletion flow offers immediate deletion or, where selected, a 30-day recovery window. During a recovery window the account is restricted; you can restore it before final deletion. Immediate deletion does not include that recovery window.
- Ask AI lesson questions and AI replies are encrypted and kept for 30 days from each message, then deleted. Deleting your account removes them sooner.
- Temporary uploaded lesson recordings are scheduled for deletion after processing, with retry/cleanup controls for failures. This does not automatically erase the saved transcript, feedback or learning record. Real-time audio and temporary generated replies are handled according to the feature's session and cleanup lifecycle.
- Deletion removes account-linked content subject to necessary exceptions. Financial, dispute, anti-fraud, security and compliance evidence may be retained for the applicable legal period or while needed for the specific claim or security purpose. We restrict that retained data rather than continuing to use it for learning or marketing.
- Queued storage cleanup and restricted backups may take longer to expire than the primary account record. Support and operational records are retained only for their stated purpose and relevant legal needs. Contact us for the retention criteria applying to a particular record. Waitlist retention is described separately above.
10. Data protection rights
Depending on the applicable law, you can request access, correction, deletion, restriction or portability of your data, object to processing based on legitimate interests, and withdraw consent where it is used. These rights have legal exceptions; for example, deleting an account does not necessarily erase a legally required invoice.
Email hello@lurni.com. We may need to verify your identity. We normally respond within one calendar month; if a lawful extension is needed, we explain it within that period. You may complain to the UK Information Commissioner's Office (ico.org.uk) or your EU/EEA data protection authority.
11. International data transfers
Our core database is hosted in Frankfurt, Germany. Some providers operate globally and may process data outside the UK/EEA, including in the United States. We do not promise that all data remains in the EU. Restricted transfers require an applicable adequacy decision or appropriate safeguards, such as Standard Contractual Clauses and the UK Addendum/IDTA where required. Contact hello@lurni.com for information about the safeguards applicable to a particular provider and feature.
12. Age requirements
Lurni is intended for people aged 16 and over. If you believe a person under 16 has provided personal data, contact hello@lurni.com so we can investigate and take appropriate action.
13. Information security
We use encrypted connections, access controls, password hashing, protected session credentials and encryption for sensitive stored fields. Access is limited to authorised systems and people with an operational need. No system is risk-free; do not share your password or verification codes.
14. Changes to this Privacy Policy
The current dated policy is available on the website and in the app. This update explains app processing separately from the waitlist; it does not create accounts from waitlist entries, change features or subscriptions, send notification emails or require existing users to accept a new screen solely because the notice changed.
Our existing commitment to email waitlist subscribers at least 14 days before material changes to the handling of their waitlist information remains. This update does not introduce such a change. Any future use needing a separate notice or consent must be addressed before that use; publication alone is not consent.
15. Contact details
For privacy questions, complaints or data requests, contact LURNI LTD at hello@lurni.com.