Sign in

Privacy Notice

Last updated:

Who we are

Leonoria operates this language-learning platform and is the data controller for the personal data described here. That means we decide why and how your personal data is used when you use Leonoria.

What we collect and why

  • Account data (name, email, password credentials, role, avatar) — to create and secure your account. Legal basis: performance of our contract with you.
  • Profile data (bio, teaching specialties, certification status, CEFR level, learning goals, age category, time zone, intro video) — to run the marketplace and match students with teachers. Legal basis: contract performance.
  • Lesson data (bookings, schedules, attendance, messages between you and your teacher or student, lesson reviews, lesson plans) — to deliver and support lessons. Legal basis: contract performance.
  • Transaction data (coin balance, coin ledger entries, lesson charges, teacher earnings and payout requests) — to run the coin economy and pay teachers. Legal basis: contract performance and legal obligation.
  • Preference data (language, currency, Kids or Adult track) — to show the interface you expect. Legal basis: legitimate interests.
  • Technical data (IP address, device and browser information, security and error logs) — for security, fraud prevention and improving the service. Legal basis: legitimate interests.
  • Support messages — to answer your questions. Legal basis: legitimate interests.

Learning and lead data points we process

For transparency, these are the specific records our encrypted backend stores and tracks:
  • total_hours_completed — cumulative completed lesson hours held in the profiles tracking ledger, used to drive milestones, tier unlocks and certificate issuance.
  • cefr_level — the learner’s current proficiency band, used for teacher matching, group-class grouping and progress reporting.
  • placement_test_taken — a single flag recording whether the one-time 4-minute onboarding diagnostic has been completed.
  • company_name and corporate_email — business lead vectors captured only when an organisation submits our corporate enquiry form, stored in our validated corporate_leads schema and used solely to respond to that enquiry.
Legal basis: performance of our contract with you, and our legitimate interest in responding to business enquiries.

Children’s privacy framework (COPPA and GDPR aligned)

Our Kids Corner track is intended for children learning with the involvement of a parent or guardian. Accounts must be created and managed by an adult, who provides the child’s details and consents to this notice on their behalf. In addition:
  • No advertising, ever. The Kids Corner runs zero third-party advertising or behavioural tracking matrices. No child data is shared with advertisers, ad networks or data brokers.
  • Encrypted classrooms. All live video classroom channels are encrypted in transit and are accessible only to the enrolled participants and their teacher.
  • Row Level Security. Every child record sits behind database row-level security policies, so an account can only ever read the rows it owns.
  • 24/7 admin compliance monitoring. Bookings, chats and classroom sessions are logged and continuously reviewed by our human admin compliance team.
  • Isolated Kids Corner environment. Child profiles run inside a ring-fenced Kids Corner experience separated from the adult marketplace. Inside it, teacher messaging text blocks render in optimised high-contrast bubbles for readability, and any optional real-time translation helper line automatically adapts to the child’s registered native home language metric stored on their profile, instead of a single static language fallback. Translation output is generated only for the message shown and is never used to profile the child.
  • Teacher “Lock Translation Helper” toggle. Native instructors retain a Lock Translation Helper toggle block in their conversation workspace header. Activating it temporarily hides the translation reveal links from the child’s screen for focused immersion training. The toggle only changes what is displayed in that conversation; it stores a single per-conversation preference flag and processes no additional child data.
  • Limited-use interactive audio. Child accounts feature deliberately capped interactive audio buttons — for example the mascot audio interaction trigger is limited to 3 uses per lesson — so the classroom stays friendly, controlled and distraction-free. These triggers play pre-recorded platform audio only; no microphone recording of the child is made by them.
  • Reward tokens are not commerce. Leo-Gems earned in the Kids Corner have no monetary value and involve no payment data from the child.
A parent or guardian may request access to, correction of, or deletion of their child’s data at any time through their account.

Referral and invitation tracking

When you invite someone to Leonoria we process a cryptographically generated referral_code issued to your profile, and store the resulting referred_by_id string connection on the invited account. This referral map exists solely to authorise promotional token routing — crediting the deferred LeoCoin bonuses after a verified checkout, crediting teacher milestone hours after successful screening, and detecting fraudulent or automated invitation loops. Referral codes are not shared with advertisers and are never used for behavioural profiling. Legal basis: performance of our contract with you and our legitimate interest in preventing promotional fraud.

Who we share data with

  • Your teacher or student — the profile and lesson details needed to run your lessons.
  • Service providers (subprocessors) — our hosting and database provider, our email delivery provider and the provider of our in-browser video classroom, acting on our instructions.
  • Paystack, our payment processor — to take card payments for coins and lessons and to return approved refunds to the original payment method.
  • Professional advisers (legal, accounting) and authorities where we are required to disclose by law.
We do not sell your personal data.

International transfers

Our providers may process data outside your country, including outside the UK and EEA. Where that happens we rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses.

How long we keep it

We keep account, profile and lesson data for as long as your account is active and for a reasonable period afterwards to handle disputes. Financial and transaction records are kept for as long as tax and accounting law requires. After that, data is deleted or anonymised.

Your rights

Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to its processing, receive it in a portable format, withdraw consent and complain to your data protection authority. In the UK and EEA we will respond within one month. Contact us through your account to exercise any of these rights.

Security

We use appropriate technical and organisational measures to protect your data, including encryption in transit, row-level access controls on our database, restricted private storage for teacher videos and server-side authorisation for financial operations.

Cookies

We use essential cookies and local storage to keep you signed in and remember your language, currency and track preferences. Our payment provider sets cookies necessary to complete checkout. We do not use advertising cookies. You can clear or block cookies in your browser, though signing in will not work without the essential ones.