1. Overview
This Privacy Policy explains how Devcode Ltd ("Englora", "we", "us") — the operator of the Englora app and the englora.devcodeltd.co.uk website — collects and processes personal data as the data controller. By downloading or using Englora, you acknowledge the practices described here.
We process personal data in accordance with the EU General Data Protection Regulation (GDPR), the UK GDPR and other applicable data-protection laws.
2. Data We Collect
2.1. Data you provide
- Account information: when you sign in with Google or Apple, your name and email address. You can also use Englora as a guest, without signing in.
- Profile: your display name (nickname) and, optionally, a profile photo you choose to upload.
- Preferences: notification settings, daily goal and language choice.
2.2. Data collected automatically
- Usage data: the questions and exercises you complete, correct/incorrect rates, study time, XP, streaks and practice results.
- Device & app information: device model, operating system and app version, language setting, device/app identifiers and your push-notification token.
- Advertising identifiers: where permitted and where you have consented, the Android Advertising ID (AAID) or Apple Identifier for Advertisers (IDFA), used to serve and measure ads (see Section 4).
- Approximate location: a region/city-level location derived from your IP address, used for analytics and ad delivery. This is not precise/GPS location.
- Diagnostics: crash reports and performance logs used to fix problems and improve the app.
Englora does not collect precise (GPS) location, contacts, or special-category (sensitive) personal data. A profile photo is only collected if you upload one. We do not ask for data beyond what is needed to run the app.
3. How We Use Data
We use the data we collect only to:
- Save your progress and show your statistics, streaks and weak areas.
- Calculate practice and exercise results and personalise your learning path.
- Send notifications and reminders (if you have allowed them).
- Show ads and, where you consent, measure their performance (see Section 4).
- Keep the service secure, prevent abuse and fix bugs.
4. Advertising & Consent
Englora is free and supported by advertising. We use Google AdMob (provided by Google) to display ads in the app. To serve and measure ads, AdMob and its partners may process your device information, advertising identifier (AAID/IDFA) and approximate location.
- Consent (EEA, UK & Switzerland): before ads and related identifiers are used, we show a consent request using Google's User Messaging Platform (UMP). You can choose to accept or decline, and you can change your choice at any time from the app. If you do not consent, you will only see non-personalised ads where available.
- Apple App Tracking Transparency (iOS): on Apple devices, we ask for your permission through the system App Tracking Transparency (ATT) prompt before any tracking that uses the IDFA. If you decline, the IDFA is not used to track you.
- Personalised vs. non-personalised ads: personalised ads use your consent and advertising identifier to show more relevant ads. Non-personalised ads are based on coarse, contextual signals only.
- Your controls: you can reset or limit your advertising identifier in your device settings (Android: Settings > Privacy/Ads; iOS: Settings > Privacy & Security > Tracking / Apple Advertising), and revisit the in-app consent choice at any time.
For more on how Google uses data from apps that use its services, see Google's "How Google uses information from sites or apps that use our services".
5. Google Sign-In and Google User Data
If you choose to sign in with Google, the app accesses basic Google profile information via Google Sign-In (Google OAuth): your name, email address and profile picture.
- Access and purpose: we use this data only to authenticate you and create/sign in to your account, to show your display name and avatar in the app, and to link your learning progress (XP, streaks, results) to your account and sync it across devices. We do not use Google user data for advertising or marketing.
- Processing and storage: this data is stored on our secure servers, encrypted in transit (HTTPS/TLS), and only for as long as your account is active.
- Sharing: we do not sell Google user data or share it with third parties for their own purposes; it is only processed by service providers acting on our behalf to run the service (e.g. Google Firebase Authentication).
- Deletion: you can delete your account and associated data at any time from the app (Profile → Delete Account) or via our account deletion page.
Englora's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Data Sharing
We do not sell your personal data. Your data is only processed in these limited cases:
- Service providers (processors) that process data on our behalf and under our instructions: Google Firebase (authentication and push notifications), Google Analytics for Firebase and Firebase Crashlytics (analytics and crash reporting), Google AdMob (advertising), and our cloud hosting/storage provider (content and media hosting).
- Legal obligations: where required to comply with the law or a valid request from a competent authority.
Some advertising activity (for example, showing personalised ads) may be considered "sharing" or a "sale" under certain US state privacy laws. Where that is the case, it is controlled by your consent and device choices described in Section 4, and you may opt out at any time.
7. Legal Bases for Processing (GDPR / UK GDPR)
- Performance of a contract: creating and running your account and delivering the app's core features.
- Consent: personalised advertising, use of advertising identifiers, and analytics where consent is required. You may withdraw consent at any time.
- Legitimate interests: keeping the service secure, preventing abuse, and improving the app — balanced against your rights.
- Legal obligation: where we must retain or disclose data to comply with the law.
8. Data Security
Your data is protected in transit with encryption (HTTPS/TLS), and we apply industry-standard measures against unauthorised access. No system is 100% secure, but we take all reasonable technical and organisational measures to protect your data.
9. Data Retention
We keep your data for as long as your account is active. You can delete your account at any time from the app (Profile → Delete Account) or via the steps on our account deletion page. When you delete your account, your personal data is deleted or anonymised within a reasonable period, except where retention is required by law.
10. Children's Privacy
Englora is intended for people preparing for an English proficiency test and is not directed to children. We do not knowingly collect personal data from children under 13 (or under the minimum age required in your country, such as 16 in parts of the EEA). If we learn that we have collected data from a child below that age, we will delete it. If you believe a child has provided us with personal data, please contact us.
11. Your Rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to withdraw consent, and to data portability. Under UK/EU law you also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office).
If you are a California resident, you have rights under the CCPA/CPRA, including to know, delete, correct, and to opt out of the "sale"/"sharing" of personal information; we do not sell your data, and you will not be discriminated against for exercising your rights.
To exercise any of these rights, contact us at [email protected].
12. International Data Transfers
We are based in the United Kingdom, and our service providers may process data in other countries. Where personal data is transferred internationally, we rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum) to protect it.
13. Changes to This Policy
We may update this policy from time to time. For significant changes, we will notify you in the app or on this page. The "Last updated" date at the top always reflects the current version.
14. Contact
For any privacy questions or requests: [email protected]
Data Controller: Devcode Ltd · 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.