Privacy Policy
Last updated: August 31, 2026
For users in the European Union, the United Kingdom, and other jurisdictions with similar data protection laws, the data controller for personal data processed by 5Learn is reachable at [email protected].
Introduction
This Privacy Policy describes how 5Learn ("we", "our", or "the app") handles information when you use our language learning application. We are committed to protecting your privacy and being transparent about our practices.
Your learning content is stored locally on your device. In the new subscription version, AI features are provided through your 5Learn account and an active subscription, trial, or other access granted by 5Learn. That version sends AI requests only through the 5Learn backend and does not accept or use a personal OpenAI API key.
Earlier app versions may still offer legacy token-pack billing or an optional personal OpenAI API key. Those versions continue to be covered by this policy while they remain available or installed. The sections below identify where their behavior differs from the current subscription version.
Accounts and Authentication
In the subscription version, signing in is required to start or restore a subscription and use AI features. A legacy app version may allow AI use without an account when a personal OpenAI API key is selected. Your cards, lists, and learning history remain local to your device in either version.
Authentication for 5Learn is handled by Clerk, a third-party identity provider that acts as a data processor for us. Clerk supports three sign-in methods, and we offer all three:
- Sign in with Apple
- Sign in with Google
- Email and password
What Clerk receives and stores:
- For Sign in with Apple and Sign in with Google: the provider's subject identifier, your email address (for Apple, this may be a private relay address that forwards to your real inbox), and your display name if the provider returns one.
- For the email and password method: your email address and a one-way hash of your password. We never see or store your password in plaintext.
- Verification and password-reset emails are sent by Clerk directly. No separate email service provider is involved.
What 5Learn's own backend receives: your Clerk user ID and, when available from Clerk, your email address and display name. 5Learn never sees your password and does not receive the raw OAuth tokens issued by Apple or Google.
Purpose: to identify you, associate your subscription and purchases with the correct account, and authorize access to backend AI features. Lawful basis for users in the EU/UK: performance of a contract.
Clerk is based in the United States, so for EU/UK users signing in involves an international transfer of personal data. Clerk provides Standard Contractual Clauses as the legal mechanism for this transfer. For full details, see Clerk's Privacy Policy.
Subscriptions and Purchases
Subscription payments are processed by Apple (on iOS) or Google (on Android) through their in-app purchase systems. 5Learn never sees your card number, billing address, or other payment-method details.
To validate purchases and manage your entitlements, we use RevenueCat. RevenueCat receives an app user ID tied to your signed-in account, the transaction receipt issued by Apple or Google, and standard device and app metadata (operating system version, app version, country). See RevenueCat's Privacy Policy for full details.
On our backend we store subscription and entitlement status, product and transaction identifiers, relevant dates, and internal AI usage-accounting metadata. We do not store payment-method details of any kind.
Legacy versions may offer consumable token packs instead of a subscription. For those purchases, the backend stores the product, transaction identifier, date, and resulting token balance. Payment processing and refund handling remain with Apple or Google.
Refunds are handled by Apple or Google — please use their standard refund flows. We cannot issue refunds directly because we never receive the payment.
Purchase records may be retained for tax and bookkeeping purposes even after you delete your account, for as long as applicable law requires.
Lawful basis for users in the EU/UK: performance of a contract. International transfers: RevenueCat is based in the United States. For EU/UK users, data is transferred to RevenueCat under Standard Contractual Clauses. Apple and Google process payment data under their own policies and legal frameworks.
AI Processing
In the subscription version, 5Learn uses the OpenAI API to generate translations, explanations, learning cards, and speech. You must be signed in and have an active subscription, trial, or other access granted by 5Learn. Every AI request is sent from the app to the 5Learn backend, which selects the OpenAI model and forwards the request. Personal OpenAI API keys and direct device-to-OpenAI requests are not supported in that version.
- What data is transmitted: text, images, and other inputs that you submit or that are required for the requested AI feature are sent to the 5Learn backend and then to OpenAI. Text sent for speech generation is also forwarded to OpenAI.
- What our backend stores: we do not persist prompt or response content in our application database. We record usage and token-accounting metadata such as model, token or character counts, cost, timestamp, and account reference. Operational AI error logs are designed to contain only allowlisted status and routing metadata, not request content or raw upstream error bodies.
- Who receives it: 5Learn's backend, then OpenAI, Inc.
Legacy app versions
An older version may expose a Use own API key setting. When enabled, that app sends the text and instructions required for the selected AI feature directly to OpenAI using the key you supplied. The key is stored locally by that app version and is not uploaded to 5Learn. When the setting is disabled, the older app sends the request through the 5Learn backend and charges its legacy token balance. Subscription-only builds remove the personal-key option.
OpenAI processes the input required for your requested feature under its own privacy terms. For full details: OpenAI Privacy Policy.
Lawful basis for users in the EU/UK: performance of a contract — you requested the AI generation. International transfers: OpenAI is based in the United States; data is transferred under Standard Contractual Clauses as described in OpenAI's Data Processing Addendum. The backend used by the subscription version is configured on DigitalOcean App Platform in Frankfurt, Germany, and its PostgreSQL database is configured in Frankfurt, Germany. Named service providers may process data in other jurisdictions under their own privacy and transfer terms.
When you initiate an AI generation, the request is processed as described above.
Data We Collect and Use
Stored on your device (all users)
Your word cards, lists, learning history, and app settings are stored locally on your device. We do not upload or sync this local learning data to our servers. A legacy app version may also store a personal OpenAI API key locally when you explicitly enter one.
Stored by Clerk (signed-in users only)
Your email address, display name, and either the Apple/Google subject identifier or a hashed password, depending on the sign-in method you chose.
Stored on 5Learn's backend (signed-in users only)
Your Clerk user ID, email address and display name when available, subscription and entitlement status, legacy token balance where applicable, in-app purchase history, and AI usage-accounting metadata. We do not persist your prompt or response content in the application database.
Server logs
Our hosting and application infrastructure creates operational request and error logs for security, abuse prevention, reliability, and debugging. These may include request metadata such as timestamp, path, method, response status, IP address, or user-agent. AI error logging is restricted to allowlisted operational metadata and is designed not to include prompts, responses, audio input, or raw upstream error bodies. Logs are kept according to the retention configured for our cloud logging environment and only for as long as needed for those purposes.
Product Analytics
When product analytics is enabled, the mobile app uses Mixpanel to understand feature usage and improve reliability. The app sends manually defined events and limited metadata such as app version, platform, locale, screen or feature name, counts, durations, and purchase-package metadata. It does not send words, translations, prompt or response content, email addresses, API keys, authentication tokens, or raw errors.
Analytics is enabled by default when the app has been configured with a Mixpanel token. Events use an anonymous app identifier until sign-in; after sign-in the app associates analytics with your Clerk user ID. You can turn analytics off at any time under Settings → Share analytics. The app is configured to use Mixpanel's EU ingestion endpoint. Mixpanel processes this data under its own privacy policy.
What We Do Not Do
- We do not sync your cards, lists, or learning history to our servers.
- We do not see or store your payment card details.
- We do not persist the content of your AI prompts or OpenAI's responses in our application database.
- We do not send learning content, AI content, email addresses, API keys, authentication tokens, or raw errors to Mixpanel.
- We do not sell or rent personal data, or share it for cross-context behavioral advertising.
- We do not use advertising, the IDFA, or any cross-app tracking, and the app does not prompt for App Tracking Transparency.
Your Rights
Local data. Because your learning data is stored on your device, you control it from the app and your device. Uninstalling removes the app database and ordinary settings. Device backup and restore behavior varies by platform. If you use a legacy version with a personal OpenAI API key, remove the key in that version's Settings before uninstalling or handing the device to someone else.
Account and purchase data. If you signed in, you can delete your account from inside the app at Settings → Delete account. This immediately deactivates and anonymizes the account on our backend, clears its profile fields and access state, and starts deletion of the related Clerk identity and RevenueCat customer. The backend makes several attempts; an incomplete external deletion is marked for later operational cleanup. The anonymized internal account record and purchase and AI usage-accounting metadata may be retained for tax, bookkeeping, fraud prevention, legal, and operational purposes. Historical Mixpanel events are not automatically erased by the in-app account deletion flow; email us to exercise applicable data rights concerning analytics data.
Deleting your 5Learn account does not cancel a subscription managed by Apple or Google. Cancel it separately in your App Store or Google Play subscription settings to prevent future renewals.
GDPR rights (EU/UK users). You have the right to access, rectify, delete, port, restrict, or object to the processing of your personal data, and to withdraw any consent you have given. To exercise any of these rights, email us at [email protected]. You also have the right to lodge a complaint with your local data protection supervisory authority (for example, the ICO in the United Kingdom, the CNIL in France, or the data protection authority in your EU member state).
Data Retention
- Local learning data and settings: until you delete them from within the app or uninstall; platform backup and restore behavior may vary.
- Active account profile data: until you delete your account via Settings → Delete account; external provider deletion may finish asynchronously after retries.
- Anonymized account, purchase, and usage-accounting records: retained as needed for tax, bookkeeping, fraud prevention, legal, and operational purposes.
- Server logs: according to the retention configured for our cloud logging environment and only as long as needed for security, reliability, and debugging.
- Analytics: according to the retention configured for our Mixpanel project; contact us to exercise applicable data rights.
Children's Privacy
5Learn is not directed to children under 13 (or under 16 in the European Union). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
Changes
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent changes. Continued use of the app after changes constitutes acceptance of the updated policy.
Contact
For privacy-related questions: [email protected]