Lingoban

Privacy

Privacy Policy

This privacy policy explains how Lingoban processes account data, learning data, billing information, and AI-assisted features.

On this page
  1. 1. Controller
  2. 2. Website access and technical logs
  3. 3. Account, sign-in, and protected areas
  4. 4. Learning data
  5. 5. AI, TTS, image, and media features
  6. 6. Billing and subscriptions
  7. 7. Recipients and processors
  8. 8. Cookies and local storage
  9. 9. Retention and deletion
  10. 10. Data subject rights
  11. 11. Contact and rights requests
  12. 12. Lingoban browser extension
  13. 13. Updates to this privacy policy

1. Controller #

Company
Sesang, Inhaber Wonyoung Seo
Represented by
Wonyoung Seo
Address
Limburger Str. 15 65520 Bad Camberg
City / additional line
65520 Bad Camberg
Email
hello@sesang.de
Phone
+49 177 267 1468

2. Website access and technical logs #

When you access Lingoban, infrastructure and application layers may process technical connection data such as IP address, request time, requested path, user agent, and response status. This is necessary for stability, security, abuse prevention, and troubleshooting.

Service and contract performance, pre-contract requests, and legal obligations are further legal bases. Server-side connection and error processing rests on legitimate interests in security and abuse prevention. Optional browser, iOS, and Android diagnostics and analytics require consent; no ad tracking occurs.

3. Account, sign-in, and protected areas #

Sign-in, sign-up, email link verification, password reset, Google sign-in, and family-site auth linkage are processed through Firebase Auth and the shared authentication layer.

The server uses a server-visible access token cookie and session synchronisation data to protect application routes. Saved interface language and default study settings may also be stored in the user profile so the experience remains consistent across sessions.

4. Learning data #

Lingoban stores user-scoped folders, decks, cards, review schedules, last-accessed deck state, chat sessions, chat messages, and related study artefacts.

This data is used to preserve learning progress, restore the last workspace, run review flows, and support card creation and deck management.

5. AI, TTS, image, and media features #

Sentence analysis, AI story generation, study image generation, and TTS audio generation or playback are handled through shared AI and TTS infrastructure. The concrete provider can vary by feature, availability, plan, and deployment configuration.

Parts of the generated output may be stored in Lingoban tables or shared platform tables so the study flow can continue across requests. Uploaded or generated media is checked against the current user scope before access is granted.

6. Billing and subscriptions #

Paid plan checkout, plan changes, subscription cancellation, and billing state synchronisation are handled through Polar.

The Lingoban profile may store plan tier, subscription status, customer identifiers, and subscription identifiers required to decide feature access and usage limits.

7. Recipients and processors #

  • Firebase Auth / Google sign-in for account authentication and email verification
  • Cloud Run backend_api, Postgres, and Google Cloud Storage for app data processing, APIs, media storage, and delivery
  • AI, translation, image-generation, and TTS providers such as OpenAI, Google Gemini, Google Cloud services, or comparable processors, only where the corresponding feature is enabled
  • Polar for checkout, subscription state, and billing identifiers
  • Resend for sign-in, verification, and service notification emails
  • Sentry: consent-based browser, iOS, and Android error diagnostics; server-side error processing on legitimate interests
  • PostHog: consent-based browser, iOS, and Android usage analytics

8. Cookies and local storage #

Lingoban uses essential cookies and limited browser storage for sign-in, security, language preference, and protected application routes. This storage is limited to what is needed to provide the service requested by the user.

Optional diagnostics and analytics remain off until consent. In browsers, grant, change, or withdraw each via the cookie banner or footer settings. On iOS, use Settings > Privacy. On Android, use Settings > Privacy.

9. Retention and deletion #

Learning data and profile information are retained for as long as they are needed to operate the account and preserve study history. Session access tokens use short expiry, and maximum session and inactivity expiry follow the shared authentication policy.

Email lookup abuse logs and server security logs are designed to avoid raw email and IP storage and to keep records only for a limited period. When account deletion is scheduled, deletion follows the shared account cleanup flow after a 30-day recovery period; active subscriptions or legal retention duties may delay completion.

10. Data subject rights #

  • Access
  • Rectification
  • Erasure
  • Restriction of processing
  • Data portability
  • Objection to processing
  • Withdrawal of consent for consent-based processing
  • Complaint to the competent data protection supervisory authority

11. Contact and rights requests #

Please use the business contact details above if you want to request information about the processing of your personal data, exercise your rights, or ask about analytics consent withdrawal. Your right to complain to a supervisory authority remains separate from this contact route.

12. Lingoban browser extension #

The Lingoban Chrome extension reads the Lingoban session cookie (__session) from lingoban.com and www.lingoban.com through the chrome.cookies API and uses it as an Authorization header when calling the Lingoban backend on behalf of the signed-in user. It does not read cookies from other sites or collect browsing history.

The extension has no statically registered content script. At installation it requests HTTP/HTTPS page access so it can register a lightweight runtime bootstrap, which checks the local exclusion list, global web-analysis switch, sensitive-page guards, and browser permission before installing selection and keyboard listeners. When you select text, the heavier on-page UI loads locally and presents the Lingoban Analyze action. Only after you choose Analyze or use Alt+Shift+A is the selected text sent to the Lingoban backend. Card saving, AI story or image generation, and TTS requests likewise occur only after the corresponding explicit action; session cookies and backend requests remain limited to Lingoban origins.

The extension uses chrome.storage.sync, chrome.storage.local, and chrome.storage.session to keep your UI language, learning languages, language detection mode, web-analysis toggle, and a short-lived auth and plan cache. The session-storage auth cache is in-memory only and is cleared on TTL expiry or any 401 response.

Optional extension-side error diagnostics (Sentry) and usage analytics (PostHog) are off by default, and the Chrome Web Store release collects neither. Where they are available, each requires its own separate consent in the extension settings. They use only the extension version, Chrome major version, extension area, operation, safe result code, coarse duration bucket, and locale. They do not receive selected text, analysis or media content, URLs, browsing history, cookies, authentication data, email, account identifiers, raw error messages, stacks, screenshots, DOM data, or session replay.

The extension does not sell user data to third parties, does not use it for advertising tracking, and does not use it for any purpose outside the language-learning features described above.

13. Updates to this privacy policy #

We update this privacy policy when Lingoban's processing activities, service providers, or authentication and billing architecture change.