Your learning, your information.

How Lilmod handles personal information on our website and in our learning apps.

Last updated: 23 September 2026.

Who is responsible and how to contact us

Lilmod is responsible for the personal information used to provide this service. For support, questions about this policy, or a request about your information, email learnlilmod@gmail.com or use our support email. This policy covers the public website, private previews, and Lilmod’s learning apps.

Accounts and learning progress

You can practise as a guest without creating an account. Guest progress, preferences, downloaded lessons, and audio caches are stored on your device. Clearing browser or app data may remove unsynced progress.

If you create an account, Supabase processes your email, sign-in credentials, account identifier, and profile details. Lilmod stores your learning activity, saved words, lesson and quiz results, practice history, XP, streaks, and progress so you can continue across devices. Account caches are kept separately on each device. We use this information to provide your account and the learning service you request.

Organisations, classrooms and invitations

Our classroom pilot is for adult ulpans and members aged 18 and over. An organisation provides invited email addresses and membership roles, individually or through a CSV import. Named invitations reserve places for seven days. Existing members use their personal Lilmod account; new members verify their email and choose their own login. Membership is accepted explicitly. An organisation administrator manages its roster, places and join requests.

We store classroom memberships, assignments, answers, scores, submission versions, feedback and server timestamps to provide homework and reports. Teachers see assigned-work results and weekly practice totals earned during membership, not unrelated personal lesson histories. Authorised staff can export these results. Printable individual reports exclude conversations, classmates’ information and individual written answers. Synced XP is a motivational total, not independently verified assessment data.

Class members can see class discussions and assignment questions. Optional weekly rankings show participating members’ XP; aggregate statistics are suppressed for groups smaller than five. Private student–teacher conversations are normally available only to their participants. Designated administrators may review explicitly reported private messages. Reports involving a designated administrator go to another designated administrator, or the Lilmod owner if none is available. Teachers may hide public messages and restrict posting. When a teacher leaves, private conversations close; a student can explicitly share selected messages with a replacement.

Teaching materials and classroom emails

Organisation materials are stored privately in Supabase. Our separate Cloudflare-hosted scanning service inspects uploaded PDFs, JPEGs and Word documents before downloads become available. Word documents are converted to PDF with macros disabled and network access blocked for the converter. PDFs are rewritten to repair recoverable structure problems and remove scripts, attachments, multimedia and external actions, including clickable external links. Only the revalidated copy is stored; temporary inspection files are deleted. Signed PDFs and dynamic forms require an unsigned, static teaching copy. JPEG metadata is removed and encrypted PDFs that cannot be inspected are rejected. Downloads require current permission and use short-lived links. Replacement versions preserve the resources used by published assignments. Shared materials remain with the organisation when a teacher leaves or deletes their account; do not upload personal information or material you do not have permission to share.

Resend processes invitation emails, optional daily classroom digests and retention notices. Invitation emails contain the organisation, role, expiry and a membership link. Digests contain activity summaries and links, not private-message contents or written submissions. Change digest preferences and your timezone in Classrooms. Delivery jobs retry failures and clear recipient and message payloads after provider acceptance. The owner-only test classroom uses synthetic identities and sends no invitation or digest emails.

Organisation billing and retention

Organisation agreements record term dates, timezone, currency, capacity and price. Organisation invoices use a separate Stripe customer and invoicing flow from personal Managed Payments subscriptions. Stripe receives the organisation’s billing details and handles invoice payment; Lilmod stores invoice identifiers and verified payment and access states. Organisation invoicing is not represented as having the same merchant-of-record treatment as personal Managed Payments checkout.

Leaving a class removes access to its materials and conversations. Losing an organisation seat ends its classroom memberships and funded Pro without removing independent entitlements. After a paid term ends, students have 30 days of read-only classroom access; staff can read and export authorised records and download materials. That term’s classroom records, including retained homework results and feedback, are deleted 12 months after term end. An inactive organisation’s reusable library is deleted 12 months after its last paid term, with advance notice. Renewal does not extend old classroom-record retention or restore deleted records.

Account deletion takes precedence over routine classroom retention and removes account-linked classroom data. It does not delete organisation-owned shared files or organisation billing records. Personal course progress is independent of classroom retention. Ask your organisation how it handles copies of reports or materials it downloads; those copies are outside Lilmod’s storage.

Support and feedback

When you use our forms, we store your message, category, optional name, reply email, submission time, and message status in a private inbox. The form also stores a hashed identifier derived from the sender’s network address to limit spam. Inbox access is restricted to the owner. Emails you send to our support address are processed by Google’s Gmail service.

We use these details to answer enquiries, investigate problems, and improve learning content. Please leave out passwords, sign-in codes, and payment-card details. Support messages are retained while needed to resolve your enquiry and relevant follow-up, address disputes, or meet legal obligations. You can ask us to delete them; the account-deletion process also removes form submissions matching your verified account email.

Device storage, security, and hosting

Essential browser and app storage keeps you signed in, remembers preferences, supports offline learning, and caches verified subscription access. You can remove this storage through your browser or device settings, which may sign you out or remove offline data. Lilmod does not use advertising trackers or sell personal information.

Cloudflare hosts the public website and serves cached assets and audio. Hosting and account providers process technical connection data, such as network addresses, request times, and error or security logs, to deliver and protect the service. A private preview may also require the hosting provider’s sign-in.

Audio and optional video

Playing pronunciation sends the selected learning text to our hosted audio service, which may use Microsoft Azure Speech. Generated audio is cached for reuse. Browser or device speech may be used as a fallback. Lilmod’s pronunciation feature does not record your microphone. Translation files are prepared in advance; your account details and learning history are not sent to translation services.

If an embedded video is available, it connects to the video provider only when you choose to play it. The video provider then receives connection information needed to play the video.

Website payments

Stripe Managed Payments handles payment details and transaction support for website subscriptions. Current checkout availability is shown on Pricing. Starting checkout sends your account email and an account identifier to Stripe. Lilmod stores subscription identifiers and access status; it does not store your payment-card details.

App-store payments

For subscriptions purchased through Apple or Google Play, the relevant store handles payment details. Lilmod sends a random account token, separate from your email and Lilmod user ID, with a purchase. The store provides transaction and product identifiers, subscription status, paid-through dates, and test or production status. Lilmod does not receive your payment-card details.

Purchase verification and store notifications help us grant Pro access, restore purchases, prevent duplicate account links, and handle renewals, cancellations, billing problems, expiry, and refunds. A purchase stays linked to the Lilmod account originally used.

Why we use information

Our legal basis for account, progress, and subscription processing is providing the service under our agreement with you. We rely on legitimate interests to answer enquiries, correct content, prevent abuse, and maintain service security. We process information where necessary to meet legal obligations, including applicable accounting requirements and information-rights requests. Where an optional activity requires consent, you can withdraw that consent without affecting earlier lawful processing.

Service providers and international processing

We share the information needed for each function with the providers described above and with Resend for account emails. Providers may process information outside the UK or your country. Where applicable, international transfers must use recognised safeguards, such as an adequacy decision or approved contractual protections. Contact us for details of the safeguards relevant to your information.

We may also disclose information where required by law or necessary to protect the service and people’s rights. Access to account data and the support inbox is restricted; no online service can guarantee absolute security.

How long information stays

Account and learning records remain while your account is active, unless you delete them or request deletion. Guest data stays on your device until you clear it. Cached audio can remain for reuse because it contains pronunciation content rather than your learning history. The support-message criteria and deletion exceptions in this policy explain other retention. Technical logs and restricted backups follow the relevant provider’s retention settings.

Deleting your account

Use Profile → Settings → delete account, or the website account-deletion pathway without installing the app. Confirm your email, password, and understanding that deletion is permanent. If you cannot sign in, use the support email to request deletion; we may verify your identity. We normally complete deletion immediately, and retry automatically if a provider is unavailable. We respond to privacy requests within the applicable legal deadline, normally one month.

Deletion removes your authentication account, profile, learning progress, saved words, practice and review history, and account-linked subscription data from active systems. Contact and feedback messages matching your verified account email are removed too. Other device caches clear when those devices next connect. Website subscriptions are cancelled and their Stripe customer profiles removed. Cancel Apple or Google Play subscriptions separately with the original store; immediate account deletion is still available.

Free trials and optional reminders

We store your account-linked trial start, expiry and reminder preference to provide seven days of access across devices and prevent repeat claims on the same account. Starting a trial does not send payment information to Stripe, Apple or Google. You can choose a one-time email reminder 24 hours before expiry and turn it off in Profile. Trial records and pending account-linked reminders are removed when your account is deleted. We do not retain a device fingerprint or permanent trial identity after deletion.

Confirmation emails and retention

Resend sends account-deletion, subscription-cancellation, and Free-plan confirmation emails using your account email and the relevant account or subscription event. We queue these messages securely and retry failed deliveries. Delivery payloads are cleared when the provider accepts the email. Minimal delivery and deletion receipts are removed within 30 days after completion; failed delivery records remain only while delivery is being resolved.

Payment providers may retain transaction records for their legal, tax, fraud-prevention, or dispute obligations. Restricted hosting backups expire under the provider’s configured retention schedule and must not be used to restore deleted accounts. A restore requires reapplying deletions before service resumes. Provider security and delivery logs follow their retention policies. We do not promise that legally required records or every backup copy disappear immediately.

Your information rights

Depending on applicable law, you can request access to, correction of, or deletion of your information; restriction of its use; a portable copy; or object to processing based on legitimate interests. These rights can have legal exceptions. Contact learnlilmod@gmail.com to make a request. We may need to verify your identity before releasing or changing account information.

If you are unhappy with our response, you can complain to the UK Information Commissioner’s Office (ICO) or your local data-protection authority. Learning recommendations and scores support your practice; Lilmod does not use them to make decisions with legal or similarly significant effects.

Updates to this policy

We will update this page when our service or information practices change and revise the date above. Material changes will be brought to your attention where required.