Privacy Policy
Effective Date: April 7, 2026 • Last Updated: April 7, 2026
This Privacy Policy explains how Nawrec Edtech OÜ ("we", "our", or "us"), the operator of LearnTurkish AI ("the App", "Service"), collects, uses, stores, and protects your personal data when you use our mobile application or website.
We are committed to protecting your privacy and complying with the European Union General Data Protection Regulation (GDPR), Estonia's Personal Data Protection Act, the California Consumer Privacy Act (CCPA), and other applicable data protection laws.
Data Controller:
Nawrec Edtech OÜ
Sepapaja tn 6, 15551 Tallinn, Estonia
Registry Code: 16834729
Email:
kilinc.metin266@gmail.com
1. Information We Collect
1.1 Information You Provide Directly
- Account Information: Email address, display name, language preferences, and password (encrypted).
- Authentication Data: If you sign in with Apple or Google, we receive your verified email address and unique user identifier from the respective provider.
- Profile Data: Optional profile picture, native language, and learning goals.
- Communication Data: Information you provide when contacting customer support.
1.2 Information Collected Automatically
- Usage Data: XP points, streaks, completed lessons, quiz results, scenario progress, and chat history with AI coaches.
- Device Information: Device model, operating system version, app version, language, time zone, and unique device identifiers.
- Voice Data: When you use speech recognition features, your voice is processed in real-time and is NOT stored on our servers.
1.3 Permissions We Request
- Microphone: Required for speech recognition and pronunciation practice. Voice data is processed locally or through Apple/Google speech APIs and not stored.
- Push Notifications: Optional. Used to send daily learning reminders and streak notifications.
- Speech Recognition: Required to evaluate your Turkish pronunciation.
2. How We Use Your Information
We process your personal data for the following purposes, based on the legal grounds specified:
- Service Provision (Contract): To provide and maintain the App, personalize your learning experience, track your progress, and process payments.
- AI Personalization (Legitimate Interest): To improve AI conversations and adapt content to your level using anonymized usage patterns.
- Communication (Consent): To send push notifications about daily reminders, streaks, and new features (only if you opt in).
- Customer Support (Legitimate Interest): To respond to your questions and resolve issues.
- Legal Compliance (Legal Obligation): To comply with applicable laws, tax requirements, and respond to lawful requests.
- Security (Legitimate Interest): To detect, prevent, and address fraud, abuse, and security incidents.
3. Third-Party Services
We use carefully selected third-party services to operate the App. These providers process your data under their own privacy policies:
- Supabase Inc. (USA / EU servers) — Database hosting and authentication. Privacy Policy
- Anthropic, PBC (USA) — AI conversation processing (Claude API). Privacy Policy
- ElevenLabs Inc. (USA) — Text-to-speech voice generation. Privacy Policy
- Apple Inc. — In-App Purchase processing (iOS), Apple Sign In, Push Notifications. Privacy Policy
- Google LLC — Google Sign In, Google Play Billing (Android), Push Notifications via FCM. Privacy Policy
- Paddle.com Market Ltd. (UK) — Payment processing for Android web purchases only. Privacy Policy
- Expo, Inc. (USA) — App infrastructure and over-the-air updates. Privacy Policy
4. International Data Transfers
Some of our service providers are located outside the European Economic Area (EEA), primarily in the United States. When transferring data internationally, we rely on:
- EU Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Your explicit consent where required
5. Data Storage and Retention
Your data is stored on secure servers operated by Supabase (PostgreSQL infrastructure with EU regional hosting where available). We retain your personal data for the following periods:
- Account data: Until you delete your account.
- Learning progress: Until you delete your account.
- Subscription records: 7 years after the end of subscription, for tax and accounting purposes (Estonia legal requirement).
- Support communications: Up to 2 years from the date of last contact.
- Anonymized analytics: Indefinitely, with no possibility of re-identification.
6. Your Rights Under GDPR
If you are a resident of the European Economic Area (EEA), Switzerland, or the United Kingdom, you have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Correct inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your data.
- Right to Restrict Processing: Limit how we use your data.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Object: Object to processing based on legitimate interests.
- Right to Withdraw Consent: Withdraw any consent you have given at any time.
- Right to Lodge a Complaint: File a complaint with the Estonian Data Protection Inspectorate (www.aki.ee) or your local supervisory authority.
To exercise any of these rights, contact us at kilinc.metin266@gmail.com. We will respond within 30 days.
7. Your Rights Under CCPA (California Residents)
California residents have the right to:
- Know what personal information is collected about them
- Know whether their personal information is sold or disclosed
- Opt out of the sale of personal information (we do not sell personal data)
- Access their personal information
- Request deletion of their personal information
- Equal service and price, even if they exercise their privacy rights
8. Account Deletion
You can permanently delete your account and all associated data at any time:
- Open the App and go to Profile → Account → Delete Account
- Confirm the deletion when prompted
- All your data will be permanently removed within 30 days
Alternatively, email us at kilinc.metin266@gmail.com with the subject "Account Deletion Request".
9. Children's Privacy
LearnTurkish AI is rated 4+ on the Apple App Store and is suitable for general audiences. However, we do not knowingly collect personal information from children under the age of 13 without verifiable parental consent.
If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us at kilinc.metin266@gmail.com and we will promptly delete such information.
We comply with the Children's Online Privacy Protection Act (COPPA) in the United States and the GDPR's special protections for children's data in the European Union.
10. Security
We implement industry-standard security measures to protect your data, including:
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Secure password hashing (bcrypt)
- Row-Level Security (RLS) policies on our database
- Regular security audits and updates
- Access controls and authentication for our systems
However, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but commit to notifying affected users within 72 hours of any data breach, in accordance with GDPR Article 33.
11. Cookies and Tracking
The mobile App does not use cookies. Our website (learnturkishai.com) uses only essential cookies necessary for site functionality. We do not use third-party advertising cookies or cross-site tracking.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by:
- Posting a notice in the App
- Sending an email to your registered address
- Updating the "Last Updated" date at the top of this page
Your continued use of the App after changes constitutes acceptance of the updated policy.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us: