Privacy Policy

Effective Date: January 1, 2025

Last Updated: January 1, 2025

Lingviko ("we", "us", "our") is operated by Lingviko Ltd, registered in the United Kingdom. We respect your privacy and are committed to protecting your personal data in compliance with the UK Data Protection Act 2018 and the EU General Data Protection Regulation (GDPR).

This Privacy Policy explains how we collect, use, and protect your data when you use our website and web application.


1. Data Controller

The data controller is:

Lingviko Ltd

Registered address: 128 City Road, London, EC1V 2NX, United Kingdom

Email: info@lingviko.com

2. Personal Data We Collect

We may collect and process the following types of personal data:

  • Account Information: Email address, password hash, profile details (via Clerk).
  • Authentication & Security Data: Session tokens, essential cookies (via Clerk).
  • Search Data: Search queries and technical metadata (via Algolia).
  • Learning Data: Test results, progress, answers, and interactions with AI learning assistant.
  • Payment Data: Payment method, billing details, transaction history (via LemonSqueezy).
  • Analytics Data: Usage events, device info, approximate location, session recordings (via Amplitude, PostHog, Google Analytics).
  • Marketing Data: User interactions with ads and tracking pixels (via Facebook Pixel).
  • Contact Data: Messages submitted through our contact form (email, name, inquiry).

3. How We Use Your Data

We use your personal data for the following purposes:

  • To provide and operate Lingviko (account creation, authentication, language learning features).
  • To deliver search functionality (via Algolia).
  • To process payments and subscriptions (via LemonSqueezy).
  • To measure product usage and improve features (via Amplitude, PostHog, Google Analytics).
  • To run marketing campaigns and measure effectiveness (via Facebook Pixel).
  • To provide customer support (via contact form and support emails).
  • To comply with legal obligations (tax, accounting, regulatory).

4. Legal Basis for Processing

We process your personal data under the following legal bases:

  • Contract (Art. 6(1)(b) GDPR): Necessary to provide our services (Clerk auth, Algolia search, subscription payments, learning features).
  • Legitimate Interest (Art. 6(1)(f) GDPR): For analytics, service improvement, fraud prevention, and limited marketing.
  • Consent (Art. 6(1)(a) GDPR): For cookies, tracking (Google Analytics, Facebook Pixel, Amplitude/PostHog), and marketing communications.
  • Legal Obligation (Art. 6(1)(c) GDPR): For tax, accounting, and regulatory compliance.

5. Cookies & Tracking

We use cookies and similar technologies:

  • Essential Cookies (no consent required): Authentication (Clerk), functional search (Algolia).
  • Functional Cookies: Contact form, UTM attribution (if used).
  • Analytics Cookies: Google Analytics, Amplitude, PostHog (only after consent).
  • Marketing Cookies: Facebook Pixel (only after consent).

You can manage your cookie preferences at any time via the Cookie Settings link in the footer.

6. Third-Party Services (Processors)

We work with trusted third-party service providers:

  • Clerk authentication and user management
  • Algolia search functionality
  • Amplitude product analytics
  • PostHog product analytics and optional session recordings
  • Google Analytics website analytics
  • Meta (Facebook Pixel) marketing attribution
  • LemonSqueezy (https://www.lemonsqueezy.com) payment processing
  • AI Providers (e.g., OpenAI, Anthropic) processing user text input to provide AI-powered learning features

All providers are bound by Data Processing Agreements (DPAs) and GDPR-compliant safeguards.

7. International Data Transfers

Some providers process data outside the UK/EU (e.g., USA). We rely on the EU–US Data Privacy Framework and Standard Contractual Clauses (SCCs) to ensure adequate protection.

8. Data Retention

  • Account data: kept until you delete your account.
  • Payment records: retained as required by tax/accounting laws (up to 6 years).
  • Analytics logs: retained per provider settings (typically 12–24 months).
  • Search logs (Algolia): kept for limited time for troubleshooting.
  • Support messages: retained as long as necessary to resolve the inquiry.

9. Your Rights

Under GDPR/UK-GDPR, you have the right to:

  • Access your data (Art. 15)
  • Correct inaccuracies (Art. 16)
  • Delete your data (Art. 17, "right to be forgotten")
  • Restrict processing (Art. 18)
  • Data portability (Art. 20)
  • Object to processing (Art. 21)
  • Withdraw consent at any time

You can exercise these rights by contacting us at: info@lingviko.com. You may also lodge a complaint with your local supervisory authority.

10. Security

We implement technical and organizational measures to protect your data, including encryption, pseudonymization, access controls, and regular audits. However, no system is 100% secure.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be published on this page with a new "Effective Date."

12. Contact

If you have questions about this Privacy Policy, contact us at: