Privacy Policy
LearnBook · Last updated 10 September 2026
Pilot notice. LearnBook is currently in a limited pilot: learners (who may include under-18s) use
admin-provisioned accounts set up by their teacher, tutor, school, or administrator — there is no self-sign-up.
This policy is written plainly and will be reviewed and expanded before any wider or public launch. If you have
questions, contact us at the address at the bottom.
Who this covers
This policy applies to people who use the LearnBook learning app to study, and to the teachers and administrators
who set up and manage student accounts.
What we collect
-
Account details. A display name and a username (login handle). If your teacher or administrator
sets one, an email address you use to sign in with Google or Microsoft. If you sign in with
Google or Microsoft, we also receive your verified email address, your name, and a provider account identifier
from that service.
-
Sign-in credentials. Your username (login handle) and password, stored via our authentication
provider so you can sign in.
-
Learning activity. The vocabulary decks and words you study, your answers and scores on reading
and grammar exercises (including written answers you type and how long you take), your practice history, streaks
and activity dates, and reading passages generated for you (we keep your recent readings — currently the last 20
— so you can revisit them).
-
Teacher notes. Details your teacher or administrator records about your learning, such as
targets, interests, strengths, challenges, notes, and reading level.
-
Messages. Chat messages you exchange with your teacher, administrator, or (where applicable) a
linked parent or guardian, within the app.
-
Technical basics. Standard information your browser or device sends when you use the app (for
example, IP address and browser type), used for security and to keep the service running. We do not use
advertising trackers.
We do not ask for or want financial information, government identifiers, health information, or
other sensitive personal data. Please do not enter such information into the app.
Why we use it
- To let you sign in and to keep your account secure.
-
To run the learning app: show your decks, track your progress, generate exercises, and let you and your teacher
communicate.
- To let your teacher or administrator see your progress and manage your account.
Who processes your data
-
Supabase hosts our database and authentication. Your account and learning data are stored there
(production data is hosted in Singapore).
-
Vercel serves the app itself in your browser. Vercel does not hold your learning data; it
delivers the pages that talk to Supabase.
-
Google and Microsoft handle sign-in if you choose “Continue with
Google” or “Continue with Microsoft”. We only request your basic profile and email.
-
Google (Gemini AI) generates reading passages and word explanations, and grades written answers
on open-ended grammar exercises. Text used to create or grade your exercises — for example, target vocabulary,
difficulty level, subject context, and written answers you type — is sent to that service to produce the content
or grade. Your request goes via our own server, which holds the AI key: the key itself is never in the app. Your
display name is not included in those AI requests.
We do not sell your personal information to anyone.
On your device
The app stores working data in your browser's local storage (keys starting
learnbook_) — for example your sign-in session, cached decks and progress, recent readings, chat
drafts, and display preferences — so the app works quickly and survives a refresh. Clearing your browser's site
data signs you out and removes these local copies; your account data on the server is unaffected. We do not use
advertising trackers, and the app itself sets no third-party cookies.
How long we keep it
We keep your account and learning data for as long as your account is active. If your account is removed, it is
first deactivated (trashed, recoverable by an administrator) and then permanently deleted on request: permanent
deletion removes your profile, learning progress, messages, and grammar submissions. Content a teacher created for
others (for example shared decks or exercises) is kept but detached from your account. You or your
teacher/administrator can request deletion at any time using the contact address below.
School-managed accounts
Where a school or organisation creates and manages accounts for its students, that organisation is responsible for
obtaining any consents required under its own agreements and local law, and its agreement with us governs how
student data is handled.
Your choices
- You can ask to see, correct, or delete the personal data we hold about you.
-
If you signed in with Google or Microsoft, you can unlink that sign-in by asking your teacher or administrator
to reset your account.
Changes
We will update this policy as the app develops and before any public launch. The “last updated” date
at the top will change when we do.
Contact
Questions or requests about your data: contact your teacher or administrator, who will pass the request to us.