legal
Privacy & Data Policy
Last updated 2026-07-17
1. Who we are
LingoTide is operated by Bitshore Ltd, a company registered in England & Wales (company no. 17123841). Bitshore Ltd is the data controller for the personal data described here. This policy explains what we collect, why, who we share it with, and the rights you have over it.
2. What data we hold and where
We hold the following personal data, in the places below:
Your account and identity. When you sign in, our authentication provider verifies you and holds your password and login credentials - LingoTide never sees or stores your password. In our own database we keep a user record that mirrors your sign-in identifier, your email address, an optional display name, and the dates your account was created and last updated.
Your subscription and billing. Payments run through our payment provider. We store a subscription record that links your account to your payment-provider customer and subscription references, the status (active, past due, or canceled), the current period end, and whether you have scheduled a cancellation. Your card details stay with our payment provider; we never hold them.
Your learning data. As you use LingoTide we store, in our database, the learning data you create: episodes you have completed, episodes you save, the vocabulary, grammar, and phrases you save (the word, its translation, the language, and the episode it came from), the words you mark as known (your known words), and your per-language playback preferences such as speed and auto-scroll.
Your sign-in session. To keep you signed in we set a single session cookie. It is encrypted (a JWE using AES-256-GCM), so its contents are opaque - even someone who copied the cookie value could not read it. It carries your sign-in identifier and authentication tokens (never your password, and not your internal database id), is HTTP-only, and expires after at most 14 days.
Your learning activity. While you are signed in, we record a first-party usage signal: which stories you play, roughly how long you listen, which reading tools you use, a coarse country (never your IP address), and your site language. We built and run this ourselves - no third-party analytics or advertising services, no advertising profiles, and we never sell or share it. You can turn it off, or delete what we hold, at any time from your Account page.
Anonymous visit statistics. On our public pages (the home page and learning-resource pages - never inside the app) we count page views: the page address, the site that linked you to us (with any search terms or query removed), campaign tags in the link you followed, the site language, a coarse screen-size class (mobile, tablet, or desktop), and a coarse country - never your IP address. This signal is anonymous by construction: it is linked to no account, carries no persistent identifier, sets no cookie, and is skipped entirely when your browser sends a Do Not Track or Global Privacy Control signal. If you go on to create an account, we also store with your new account the public page you first arrived on, the site that referred you, and any campaign tags - so we know which of our pages bring learners to LingoTide. That signup record is part of your account: it appears in your data export and is deleted with your account.
3. How we use your data
We use your data only to run the service: to sign you in, to give you access to the library you have subscribed to, to save your progress and saved items so they are there next time, to handle billing, and to understand how the library is used so we can improve it (the learning-activity signal described above). We do not use your data to build advertising profiles, and we do not sell it.
4. Legal basis for using your data
Where the GDPR (and UK GDPR) applies, our legal bases are: performing our contract with you (providing the service and taking payment), our legitimate interests, and your consent where it is required. The learning-activity signal relies on legitimate interests: we have weighed our interest in understanding and improving the service against your privacy, and consider it proportionate because the signal is stored in a separate, isolated system from your account, automatically deleted on a bounded schedule (see “How long we keep your data”), and you can object to it or have it erased at any time (see “Your rights”). The anonymous visit statistics also rely on legitimate interests, with a lighter footprint still: they identify no one. The signup record of your first page is stored only for accounts you choose to create, appears in your data export, and is deleted with your account.
5. Who we share your data with
We share the minimum personal data needed to run the service with a small set of processors, by category:
- Authentication providers - verifying your identity and sign-in.
- Payment providers - billing and subscriptions (your email and a reference to your account; your card details stay with them, never us).
- Cloud hosting and database providers - storing and serving your account, billing, learning data, and the learning-activity signal described above.
- Email providers - sending account and service emails such as verification.
We do not use any third-party advertising or analytics service - the learning-activity signal described above is first-party, built and operated by us, and is never shared with an advertising or analytics company.
6. How long we keep your data
We keep your account and learning data for as long as your account is active. If you delete your account, we remove that data (see below), keeping only limited billing records where the law requires us to. The session cookie expires within 14 days.
The learning-activity signal has its own, shorter retention: the detailed per-event record is deleted automatically after 90 days. Summaries linked to your account are deleted when you delete your account, or earlier on request. Fully anonymous statistics (for example, how many people completed a story) are kept indefinitely.
The anonymous visit statistics follow the same schedule: the detailed per-view record is deleted automatically after 90 days, while daily page totals - which contain no personal data - are kept. The record of the page you first arrived on lives with your account and is deleted with it.
7. Your rights
Depending on where you live, and under the UK and EU GDPR, you have the right to access the personal data we hold about you, to correct it, to export it, to ask us to delete it, to object to or restrict certain processing, and to complain to your data-protection authority. For the learning-activity signal specifically, you can turn off future collection at any time from your account settings (“don’t record my usage”) - this stops new collection immediately and does not affect anything else about your account. The next section explains how to make a fuller request, including erasing what has already been collected.
8. Accessing, exporting, or deleting your data
Two of these are self-serve in your account settings: you can delete your account (“Delete my account” — deactivated immediately, permanently erased after 14 days; email support within those 14 days if you change your mind), and you can turn off future collection of the learning-activity signal and request erasure of what has already been collected, without emailing us. You exercise the other rights (access, export, rectification) by emailing us at support@lingotide.com and we will action your request. Deleting your LingoTide account removes your account record and the learning data linked to it (saved episodes, saved items, known words, completions, preferences, the learning-activity signal, and the record of the page you first arrived on) and ends your subscription with our payment provider; we may retain limited billing records where the law requires. Your identity with our authentication provider is separate and stays under that provider’s control.
9. Cookies
The learning-activity signal described above sets no cookie of its own and needs none - it is identified only by your existing signed-in session, plus a short-lived identifier held in your browser tab’s memory for the length of one listening session, never written to a cookie or to your device’s storage. The anonymous visit statistics are cookieless too. The one narrow addition: when you open the sign-in or sign-up page, we copy the page you first arrived on into a short-lived cookie (30 minutes, first-party, containing no identifier - just the page address, referring site, and campaign tags) so that if you complete sign-up we can store it with your new account; it is deleted the moment you sign in. There is no cookie banner because nothing here is the kind of tracking that requires one.
10. Children
LingoTide is not directed at children under 16. We do not knowingly collect their data; if you believe a child has given us data, contact us and we will remove it.
11. International data transfers
Our processors may store or process data in countries outside your own (for example, in the US or the EU). Where we transfer personal data internationally, we rely on appropriate safeguards such as standard contractual clauses.
12. Changes to this policy
We may update this policy as the product and our processors change. If a change is material, we will give notice (for example, by email or in the app).
13. Contact us
Questions or requests about your data? Email support@lingotide.com.