Privacy Policy
Version 1.1
Effective date: 7 August 2026
This Privacy Policy explains how personal data is processed when you create an account, use LingoGap, purchase or manage a subscription, use learning and artificial-intelligence-assisted features, contact support or otherwise interact with the service.
Please read this Policy carefully.
1. Who is responsible for your personal data?
UgleCare ApS is the data controller for the customer-facing personal-data processing described in this Privacy Policy in connection with providing, selling and commercially administering LingoGap.
Service and trading name: LingoGap
Data controller: UgleCare ApS
CVR: 34353255
Registered address: Borups Allé 116, st. tv., 2000 Frederiksberg, Denmark
Website: https://lingogap.dk
Privacy and support email: support@lingogap.dk
References in this Privacy Policy to “LingoGap”, “we”, “us” or “our” mean the LingoGap service and UgleCare ApS when acting as the relevant data controller.
LingoGap is independently owned and technically operated. Development, hosting administration, maintenance, security, technical support and related technical operations may be performed by an independent technical operator on behalf of UgleCare ApS and only to the extent reasonably necessary to operate and support the service.
The technical operator does not acquire ownership of customer data and must not use personal data for unrelated independent purposes.
UgleCare ApS does not acquire ownership of the LingoGap brand, software, educational content, domain names or other intellectual property by acting as data controller, legal seller or commercial operator.
Certain third-party providers may act as processors on behalf of UgleCare ApS. Other providers, including payment, authentication or browser providers, may act as independent or separate controllers for some processing that they determine themselves.
For privacy questions or requests concerning your personal data, contact:
2. Scope of this Privacy Policy
This Privacy Policy applies to personal data processed through:
- the LingoGap website and web application;
- LingoGap account creation and authentication;
- Foundation lessons and exercises;
- learning progress and preferences;
- the Word Bank and flashcards;
- Danish Assistant;
- writing and speaking correction;
- PD3-style reading and writing simulators;
- AI-assisted educational assessment;
- subscriptions and billing;
- customer support;
- technical administration;
- service security; and
- related legal and operational processes.
- This Policy does not replace privacy information provided by third-party services where those providers process personal data for their own purposes.
3. Key principles
LingoGap aims to process personal data:
- lawfully, fairly and transparently;
- only for specified, explicit and legitimate purposes;
- only to the extent reasonably necessary;
- accurately and, where appropriate, kept up to date;
- no longer than necessary for the relevant purpose;
- using appropriate technical and organisational safeguards; and
- in a manner that respects applicable data-protection rights.
4. Personal data we process
Depending on how you use LingoGap, we may process the categories described below.
4.1 Account and identity data
This may include:
- Firebase user identifier or UID;
- email address;
- display name;
- profile photograph URL;
- authentication provider;
- provider identifiers;
- account creation and update information;
- last login time;
- last activity time; and
- authentication and account status.
- The profile photograph, name or email associated with a Google account may be received when you choose Google authentication.
4.2 Role and access data
This may include:
- user role;
- teacher, administrator or owner role;
- subscription plan;
- manual or administrative access level;
- access-grant history;
- previous and new access levels;
- the administrator responsible for an access change; and
- internal notes connected to a manual access grant.
4.3 Preferences and settings
This may include:
- theme preference;
- audio or text-to-speech speed;
- selected text-to-speech voice;
- support-language preference;
- flashcard review mode;
- placement or starting-level selection; and
- other application preferences.
- Some preferences may be stored both in your account and in your browser.
4.4 Learning progress
This may include:
- selected starting module;
- lessons opened;
- last opened lesson;
- last opened lesson section;
- completed lessons;
- completed sections;
- exercise state;
- answers;
- completion status;
- progress summaries;
- writing responses;
- speaking transcripts; and
- saved lesson corrections.
4.5 Word Bank and flashcard data
This may include:
- saved words, phrases and expressions;
- flashcard front and back text;
- source of a flashcard;
- creation and modification times;
- review mode;
- review ratings;
- review history;
- spaced-repetition scheduling;
- previous and new scheduling states; and
- audio-related preferences.
- Word Bank searches are not currently intended to be saved as a user-specific personal search history.
- A word or expression becomes user-linked data when you save it as a flashcard or otherwise associate it with your account.
4.6 Danish Assistant and AI-input data
This may include:
- text submitted for correction;
- text submitted for translation or rewriting;
- Danish-language prompts;
- speaking transcripts;
- selected tone or style;
- task instructions;
- lesson context;
- examination answers;
- educational context; and
- information voluntarily included in free-text submissions.
4.7 AI-generated data
This may include:
- corrections;
- suggested rewrites;
- grammar explanations;
- speaking feedback;
- writing feedback;
- educational scores;
- assessment explanations;
- model information;
- token usage;
- request status;
- latency information;
- error codes or error categories; and
- monthly AI-usage counters.
4.8 PD3-style simulator data
This may include:
- reading answers;
- writing answers;
- selected writing task;
- timers;
- attempt status;
- submitted-answer snapshots;
- automatic scores;
- AI-assisted grading;
- grading status;
- grading-model information;
- results;
- revealed-result status;
- retry or reset information; and
- grading-usage records.
4.9 Subscription and billing data
This may include:
- subscription plan;
- billing provider;
- billing status;
- subscription source;
- Stripe customer identifier;
- Stripe subscription identifier;
- Stripe Checkout session identifier;
- Stripe price and product identifiers;
- current subscription-period end;
- scheduled cancellation status;
- Stripe event identifier;
- subscription update time;
- withdrawal or refund records;
- invoice or receipt references; and
- plan information received through Stripe metadata.
- LingoGap and UgleCare ApS do not intend to receive or store your full payment-card number, card security code or complete card credentials.
- Payment-card details are entered through Stripe’s hosted payment interface and processed by Stripe.
4.10 Administrative data
Authorised personnel may process:
- user account details;
- role information;
- plan and billing status;
- AI-usage summaries;
- activity timestamps;
- manual-access information;
- selected learning information where operationally necessary;
- records of role or access changes;
- cancellation and refund records; and
- technical support information.
4.11 Support communications
When you contact LingoGap, we may process:
- your email address;
- name;
- account email;
- message content;
- attachments;
- screenshots;
- billing or subscription references;
- complaint information;
- privacy-request information; and
- correspondence history.
- Support email is handled through an external email service.
4.12 Technical and security information
Depending on the service provider and technical context, this may include:
- request and response information;
- server and application logs;
- route and feature names;
- user identifier;
- event identifiers;
- lesson or examination identifiers;
- model names;
- token counts;
- error messages;
- timestamps;
- IP address;
- browser or device information;
- authentication events; and
- security or fraud indicators.
- LingoGap does not currently intentionally store IP addresses or user-agent strings in its own ordinary Firestore application records.
- Hosting, authentication, payment, AI and infrastructure providers may nevertheless process this information as part of normal service delivery, security, fraud prevention and technical logging.
5. How we obtain personal data
We obtain personal data from several sources.
5.1 Directly from you
For example, when you:
- create an account;
- enter text;
- complete exercises;
- submit a writing response;
- use speaking functionality;
- create a flashcard;
- complete an exam-style task;
- change a preference;
- purchase or manage a subscription;
- request cancellation or a refund; or
- contact support.
5.2 Automatically from your use of the service
For example:
- lesson progress;
- activity timestamps;
- AI usage;
- review history;
- examination timers;
- completion states;
- request status;
- authentication events; and
- technical logs.
5.3 From authentication providers
Firebase Authentication or Google may provide:
- UID;
- email address;
- display name;
- profile photograph URL;
- authentication-provider information; and
- authentication status.
5.4 From Stripe
Stripe may provide:
- customer identifier;
- subscription identifier;
- Checkout session identifier;
- selected plan;
- billing status;
- subscription period;
- cancellation status;
- price and product information;
- invoice or receipt references;
- refund information; and
- payment or subscription event information.
5.5 From authorised administrators
Authorised administrators may create or update:
- user roles;
- manual access;
- subscription-related administrative information;
- cancellation or refund records; and
- related access records.
6. Why we process personal data
6.1 Creating and managing accounts
We process account and authentication information to:
- register users;
- sign users in;
- maintain authenticated sessions;
- reset passwords;
- identify accounts;
- display account information;
- protect accounts; and
- provide account support.
6.2 Providing educational services
We process learning information to:
- provide lessons and exercises;
- save progress;
- resume lessons;
- store answers;
- display completion;
- personalise the learning path;
- provide Word Bank and flashcard functionality;
- schedule flashcard reviews; and
- display learning history.
6.3 Providing AI-supported functions
We process submitted text, transcripts and learning context to:
- correct Danish writing;
- review speaking transcripts;
- provide grammar and vocabulary feedback;
- rewrite or generate Danish text;
- provide educational explanations;
- assess PD3-style practice answers;
- generate educational scores; and
- return requested AI-assisted feedback.
6.4 Operating usage limits
We process usage information to:
- calculate AI usage;
- apply plan allowances;
- apply grading allowances;
- prevent circumvention;
- control excessive or automated requests;
- estimate operational costs;
- prevent abuse; and
- maintain service availability.
6.5 Providing examination practice
We process answers, attempts and results to:
- run timed practice;
- save incomplete attempts;
- calculate automatic scores;
- request AI-assisted grading;
- display results;
- protect unrevealed results; and
- allow supported resets and retries.
6.6 Managing subscriptions and payments
UgleCare ApS processes billing and subscription information to:
- create or administer Checkout sessions;
- identify the selected plan;
- associate payments with the correct account;
- grant and maintain paid access;
- update subscription status;
- manage cancellation;
- provide Customer Portal access;
- issue or administer invoices and receipts;
- investigate payment issues;
- process withdrawals and refunds;
- handle chargebacks;
- comply with accounting and tax obligations; and
- establish, exercise or defend legal claims.
6.7 Providing support
We process support communications to:
- answer questions;
- identify accounts;
- investigate problems;
- resolve subscription or technical issues;
- handle complaints;
- process privacy requests; and
- maintain an appropriate correspondence record.
6.8 Security, abuse prevention and legal claims
We may process relevant account, activity, access, billing and technical information to:
- protect accounts;
- detect unauthorised access;
- prevent fraud;
- prevent account sharing or circumvention;
- investigate misuse;
- protect the service;
- respond to chargebacks;
- establish, exercise or defend legal claims; and
- comply with lawful requests or obligations.
6.9 Operating and improving the service
We may process limited operational information to:
- diagnose errors;
- maintain reliability;
- evaluate performance;
- improve learning functionality;
- correct defects;
- evaluate aggregate usage; and
- manage technical costs.
- LingoGap does not currently use third-party behavioural analytics, advertising pixels, session-replay tools or personalised advertising systems.
7. Legal bases
The legal basis depends on the purpose and circumstances of the processing.
7.1 Performance of a contract or steps requested before a contract
We generally rely on processing necessary to perform a contract or take steps requested before entering a contract when processing is required to:
- create and operate an account;
- provide requested learning functionality;
- save progress;
- provide flashcards;
- process requested AI feedback;
- operate examination practice;
- provide a paid subscription;
- manage access and allowances;
- process payments;
- manage cancellation or withdrawal; or
- provide subscription and technical support.
7.2 Legal obligations
We may process or retain data where necessary to comply with obligations concerning:
- accounting;
- taxation;
- payment records;
- consumer rights;
- statutory withdrawal;
- fraud prevention;
- regulatory requirements;
- legal proceedings; or
- lawful authority requests.
7.3 Legitimate interests
Where appropriate, we may rely on legitimate interests relating to:
- operating a secure and reliable service;
- preventing abuse and fraud;
- maintaining technical reliability;
- investigating errors;
- enforcing subscription entitlements;
- protecting intellectual property;
- improving service quality;
- maintaining limited administrative records; and
- establishing, exercising or defending legal claims.
- Before relying on legitimate interests, the relevant interests, necessity and potential effects on users must be assessed.
7.4 Consent
Consent may be used where required for a particular optional activity.
LingoGap does not currently rely on consent for behavioural advertising, marketing trackers or third-party analytics because those technologies are not currently implemented.
Browser microphone permission is managed through your browser or device. Granting microphone permission allows the selected speech-recognition function to operate but does not constitute consent to unrelated processing.
Where processing relies on consent, you may withdraw it at any time. Withdrawal does not affect processing lawfully carried out before withdrawal.
7.5 Legal claims
Information may be retained or processed where necessary to establish, exercise or defend legal claims, including disputes concerning:
- payments;
- subscriptions;
- refunds;
- chargebacks;
- fraud;
- account access;
- misuse; or
- contractual obligations.
- These legal bases and the required transparency information reflect the categories described in the GDPR, including contractual necessity, legal obligation, legitimate interests, consent and data-subject information duties.
8. Account and authentication
LingoGap uses Firebase Authentication.
Supported authentication methods may include:
- email and password; and
- Google authentication.
Firebase authentication information may include:
- UID;
- email;
- authentication-provider identifiers;
- display name;
- profile photograph URL;
- authentication state; and
- security information required to maintain a session.
- Password-reset messages may be sent through Firebase.
- LingoGap does not intend to have direct access to users’ plaintext passwords.
- Email verification may not be required for every current account flow.
- LingoGap does not currently offer anonymous accounts or a general self-service account-linking function.
- Authentication state may be retained by the Firebase SDK in browser storage so that you can remain signed in.
9. Learning progress and lesson state
LingoGap stores learning information under user-specific database paths.
This may include:
- placement selection;
- module and lesson progress;
- lesson completion;
- last opened lesson;
- exercise state;
- writing responses;
- speaking transcripts;
- AI corrections;
- lesson-section progress; and
- other saved learning state.
- The purpose is to provide continuity between sessions and devices.
- Some individual correction fields may be cleared through the relevant lesson interface.
- A complete account-wide learning-data deletion function is not currently available as self-service.
10. Word Bank and flashcards
Word Bank searches are currently performed against LingoGap’s word data and are not intended to create a user-specific personal search history.
When you save a word or phrase as a flashcard, the card becomes part of your account data.
Flashcard data may include:
- text;
- translation or explanation;
- source;
- review status;
- review rating;
- scheduling information;
- review history; and
- timestamps.
- You may create, edit and delete individual flashcards through supported controls.
- Flashcard review logs may be retained separately from the current card state. Deleting a card may not automatically delete every historic review event associated with that card.
11. Artificial-intelligence-assisted processing
LingoGap uses external AI services for selected features.
Depending on the feature, information sent for processing may include:
- text written by you;
- a speaking transcript;
- examination answers;
- lesson title;
- task description;
- grammar focus;
- vocabulary context;
- model answers;
- scoring rules;
- educational rubric;
- language preference; and
- instructions needed to generate a response.
- The application is not intended to include your email address or display name in AI prompt content unless technically necessary for a specific disclosed function.
- Your LingoGap UID may be used internally for authentication, allowances, security and logging but is not intended to be included in ordinary AI prompt content.
11.1 Danish Assistant
Text and transcripts submitted through Danish Assistant are sent for AI processing when you actively request the relevant function.
Assistant input and output may be held in the active interface and are not currently intended to be stored as a permanent Assistant conversation history in Firestore.
Operational AI-usage information may still be recorded.
11.2 Foundation corrections
When you request Foundation writing or speaking feedback:
- your response or transcript;
- lesson context; and
relevant educational instructions
may be sent to the AI provider.
Your response and generated correction may be saved in your lesson state so that they remain available when you return.
Supported lesson controls may allow you to clear individual correction fields.
11.3 PD3-style grading
Submitted PD3-style answers may be sent with:
- examination content;
- scoring criteria;
- source-supported evaluation rules; and
- educational rubrics.
- The resulting grade or feedback may be stored in a protected result record and displayed according to the examination flow.
11.4 AI usage logs
LingoGap may store:
- feature and route;
- model;
- input and output token usage;
- request status;
- cost estimate;
- latency;
- error category;
- timestamps; and
- monthly counters.
- These records are used for allowances, security, troubleshooting and operational management.
11.5 Sensitive information
Do not include unnecessary sensitive or confidential information in:
- Danish Assistant prompts;
- writing exercises;
- speaking responses;
- examination answers; or
- support messages.
In particular, avoid submitting unnecessary information about:
- health;
- ethnicity;
- religion;
- political opinions;
- sexual life or orientation;
- criminal allegations;
- identity documents;
- immigration case details;
- bank details;
- precise private addresses; or
- confidential information about another person.
- LingoGap does not require this type of information to provide ordinary language-learning functionality.
11.6 OpenAI API data handling
LingoGap currently uses OpenAI API services for supported AI functionality.
OpenAI states that data submitted through its API is not used to train its models by default unless the customer affirmatively opts in. OpenAI may retain API inputs and outputs for a limited period for service and abuse-monitoring purposes, subject to the applicable endpoint, account configuration and contractual terms. Eligible customers may be able to apply additional retention controls.
LingoGap will describe any more specific retention or regional configuration only after verifying the relevant account settings and contractual arrangement.
12. Speaking and speech recognition
Speaking functionality may use browser-based or third-party speech-recognition technology.
When you activate this function:
- your browser or device may request microphone permission;
- the browser or its speech provider may process microphone audio;
- speech may be converted into text; and
- the transcript may be sent to LingoGap and the AI provider for feedback.
- LingoGap’s speaking-correction flow sends transcript text to its server and AI provider.
- It is not designed to upload and permanently store the original microphone recording in LingoGap’s Firestore database.
- The browser or speech-recognition provider may process audio according to its own technology, privacy terms and configuration. Provider behaviour may vary by browser, operating system and device.
- You can deny or revoke microphone permission through your browser or device settings. Speaking functionality may then be unavailable.
13. PD3-style assessments and automated educational output
LingoGap uses automatic and AI-assisted methods to:
- score reading answers;
- assess writing;
- assess selected reading responses;
- generate educational feedback;
- calculate results; and
- apply usage allowances.
- These results are for educational practice only.
They do not:
- produce an official PD3 result;
- issue a recognised qualification;
- determine immigration status;
- determine employment;
- determine educational admission; or
- produce another legal or similarly significant decision.
- AI and automated scoring may be inaccurate.
- You may contact support@lingogap.dk to question a result or report a technical problem.
- LingoGap does not guarantee that a human language examiner will re-grade every educational result.
14. Subscriptions, UgleCare ApS and Stripe
Paid LingoGap subscriptions are sold and commercially administered by UgleCare ApS under a limited commercial licence.
UgleCare ApS is responsible for relevant customer-facing commercial processing, including:
- payment processing arrangements;
- recurring billing;
- subscription administration;
- invoices and receipts;
- VAT and accounting;
- cancellation;
- withdrawal requests;
- refunds;
- chargebacks; and
- billing-related customer communications.
LingoGap uses Stripe for:
- Checkout;
- payment processing;
- recurring subscriptions;
- subscription status;
- Customer Portal;
- invoices and receipts where configured;
- cancellation management; and
- refunds.
When creating or managing a subscription, LingoGap or UgleCare ApS may send Stripe:
- your account UID;
- account email;
- selected plan;
- price identifier;
- customer reference;
- Checkout metadata;
- subscription metadata; and
- policy-version information.
- Stripe returns subscription, payment and customer information required to maintain access and administer the subscription.
- Payment-card information is entered directly into Stripe’s hosted interface. LingoGap and UgleCare ApS do not intend to receive or store your complete card details.
- Stripe may independently process personal data for payment security, regulatory compliance, fraud prevention and other purposes described in Stripe’s own privacy information.
- When you use the Stripe Customer Portal, Stripe may process and retain information needed to manage your subscription and billing account, including your name, email address, billing address, phone number, payment-method information, invoices and receipts, subscription status, cancellation status and any optional cancellation reason you choose to provide. The Customer Portal currently allows customers to update their name, email address, billing address, phone number and payment methods, view invoice history and cancel at the end of the billing period.
- LingoGap or UgleCare ApS may receive limited Stripe customer, payment-method, invoice, subscription, cancellation and billing metadata where the relevant information is made available through the integration or Stripe records and is needed for subscription administration, paid-access management, refunds, disputes, support, accounting or legal obligations. This does not mean that LingoGap, UgleCare ApS or Firestore currently stores cancellation reasons.
- Stripe may collect or retain cancellation reasons, including optional additional text where offered by the Portal. Cancellation reasons are optional and are not used for marketing unless a separate lawful basis applies. Please avoid entering sensitive personal information in an optional cancellation reason.
- Depending on the processing activity, Stripe may act as a processor on behalf of UgleCare ApS and may also act independently as a controller for fraud prevention, security, regulatory compliance and related purposes described in Stripe’s own privacy information.
15. Support communications
Support requests are handled through:
Support communications may be processed through Zoho Mail EU or another approved email provider.
Messages may contain personal data provided by you.
Please do not send:
- passwords;
- full card numbers;
- card security codes;
- authentication tokens;
- private keys;
- identity documents unless specifically and lawfully requested; or
- unnecessary sensitive personal data.
Support correspondence may be retained while necessary to:
- resolve the request;
- maintain service records;
- handle complaints;
- administer cancellation or refunds;
- prevent abuse;
- comply with legal obligations; or
- establish, exercise or defend legal claims.
- Technical support may be handled by the independent technical operator where access is reasonably necessary to investigate or resolve the issue.
- Billing, cancellation, withdrawal and refund matters may be handled by or coordinated with UgleCare ApS.
16. Browser storage and similar technologies
LingoGap currently uses browser storage and similar technologies for authentication, operational and preference purposes.
16.1 Firebase authentication storage
Firebase may use browser storage such as IndexedDB or local storage to maintain authentication state.
Purpose:
- keeping you signed in;
- securing authenticated sessions; and
- enabling account functionality.
16.2 Theme preference
Storage key:
danish-coach-theme
Purpose:
remembering light, dark or system appearance.
16.3 Audio-speed preference
Storage key:
danish-coach-tts-rate
Purpose:
remembering selected audio or text-to-speech speed.
16.4 Support-language preference
Storage key:
foundationSupportLanguage
Purpose:
remembering the selected lesson-support language.
16.5 Activity coordination
Storage pattern:
danish-coach:lastActivityAt:{uid}
Purpose:
- limiting repeated account-activity updates; and
- coordinating activity across browser tabs.
- The key may include your LingoGap UID.
16.6 Flashcard preferences
Storage may include:
- flashcardReviewMode; and
- danish-coach-fast-fallback-offset.
Purpose:
- remembering flashcard review settings; and
- remembering queue position or fallback state.
16.7 BroadcastChannel
LingoGap may use an in-browser BroadcastChannel to coordinate recent activity between open tabs.
This information is temporary and normally exists only while the relevant browser context is active.
16.8 Cookies
No application-set advertising, behavioural analytics or marketing cookies were identified in the current reviewed implementation.
Third-party or SDK-managed storage may still be created by:
- Firebase;
- Google authentication;
- Stripe;
- browser speech recognition; or
- infrastructure providers.
- Further details are provided in the Cookie Policy.
17. Recipients and service providers
Personal data may be processed by the following recipients where necessary.
17.1 Independent technical operator
Purpose:
- technical operation;
- development;
- hosting administration;
- maintenance;
- security;
- technical support;
- troubleshooting;
- account administration; and
- implementation of privacy requests.
- The technical operator may access only information reasonably necessary for the relevant operational task and must not use customer personal data for unrelated independent purposes.
17.2 Firebase Authentication and Google Cloud Firestore
Purpose:
- authentication;
- account data;
- learning progress;
- flashcards;
- usage data;
- assessment data;
- subscription state; and
- administrative records.
17.3 Google authentication
Purpose:
enabling Google sign-in when selected by the user.
Data may include:
- Google account identifier;
- email;
- display name;
- profile photograph; and
- authentication information.
17.4 Stripe
Purpose:
- payment processing;
- subscription administration;
- Customer Portal;
- billing communications;
- refunds;
- payment security; and
- regulatory compliance.
17.5 OpenAI
Purpose:
- language correction;
- rewriting;
- explanations;
- speaking-transcript feedback;
- educational assessment; and
- PD3-style grading.
Data may include:
- user-submitted text;
- transcripts;
- examination responses;
- educational context; and
- technical usage information.
17.6 Vercel
Purpose:
- hosting;
- application execution;
- request processing;
- technical logging; and
- service delivery.
17.7 Browser speech-recognition provider
Purpose:
converting microphone speech into transcript text.
The relevant provider may depend on:
- browser;
- operating system;
- device; and
- browser configuration.
17.8 Zoho Mail EU
Purpose:
receiving, storing and responding to support, commercial and privacy communications.
17.9 Google Cloud text-to-speech and Cloudflare R2
These services are primarily used for generating, storing and delivering LingoGap’s pre-generated educational audio.
The relevant source content is generally platform lesson text rather than user-submitted content.
Cloudflare R2 may provide public delivery of static educational audio objects.
17.10 UgleCare ApS personnel and authorised commercial support
Authorised UgleCare ApS personnel may process information required for:
- billing;
- accounting;
- VAT;
- subscriptions;
- cancellation;
- withdrawal;
- refunds;
- chargebacks;
- customer communication; and
- legal compliance.
17.11 Professional and legal recipients
Information may be disclosed where reasonably necessary to:
- legal advisers;
- accountants;
- auditors;
- insurers;
- authorities;
- courts;
- payment-dispute participants; or
- other professional recipients.
- Such disclosure will be limited to what is necessary and legally permitted.
18. International transfers
Some providers may process personal data in countries outside Denmark or outside the European Economic Area.
Where personal data is transferred outside the EU/EEA, an appropriate lawful transfer mechanism must apply.
Depending on the provider and destination, this may include:
- a European Commission adequacy decision;
- the EU–US Data Privacy Framework where applicable to a participating recipient;
- European Commission Standard Contractual Clauses;
- supplementary technical or organisational safeguards; or
- another mechanism permitted by data-protection law.
- The applicable hosting region and transfer mechanism for Firebase, Google, Stripe, OpenAI, Vercel, Cloudflare and other providers depend on relevant account settings, provider arrangements and contractual documentation.
- You may contact support@lingogap.dk for available information about applicable transfer safeguards.
19. Administrative and technical access
Authorised persons may access personal data where reasonably necessary for:
- account support;
- subscription administration;
- access management;
- technical investigation;
- AI-usage management;
- abuse prevention;
- security;
- service maintenance;
- responding to a privacy request;
- billing and refund administration; or
- legal compliance.
Depending on role, authorised persons may be able to view:
- name;
- email;
- profile photograph URL;
- authentication provider;
- account timestamps;
- role;
- subscription status;
- billing identifiers;
- AI-usage summaries;
- selected progress information;
- technical support information; and
- manual-access records.
- Teacher roles may access lesson-management functionality but are not automatically full administrators.
- Access should be limited to authorised persons with a relevant operational need.
LingoGap currently records selected administrative events, such as:
- role changes; and
- manual access grants.
- A comprehensive audit log for every administrative action may not currently be implemented.
20. Analytics and advertising
LingoGap does not currently use:
- Google Analytics;
- Google Tag Manager;
- Meta Pixel;
- TikTok Pixel;
- Hotjar;
- Microsoft Clarity;
- Mixpanel;
- Amplitude;
- PostHog;
- Segment;
- Plausible;
- behavioural advertising;
- personalised advertising;
- session replay; or
- remarketing pixels.
- If analytics or marketing technology is introduced later, this Privacy Policy and the Cookie Policy will be updated, and consent will be requested where required.
21. Logs and operational information
LingoGap and its providers may create logs for:
- security;
- debugging;
- service availability;
- quota management;
- payment processing;
- error investigation;
- abuse prevention; and
- infrastructure operation.
Application or AI logs may include:
- UID;
- route or feature;
- event identifiers;
- lesson or examination identifiers;
- model;
- token count;
- status;
- timestamps;
- latency;
- error type; and
- limited error messages.
- LingoGap aims to avoid logging user-submitted content where it is not necessary.
- Infrastructure providers may process IP addresses, device information and request metadata according to their normal hosting and security operations.
22. Retention
Personal data is retained only while reasonably necessary for the relevant purpose, including legal, accounting, security and dispute-resolution requirements.
The following retention criteria apply.
22.1 Account data
Account and profile information may be retained while the account remains active.
After a valid deletion request, eligible account information will be deleted or anonymised unless retention is necessary for:
- accounting;
- payment disputes;
- fraud prevention;
- security;
- legal claims; or
- another legal obligation.
22.2 Learning data
Progress, lesson state, flashcards, review history, AI corrections and examination attempts may be retained while the account remains active so that the user can continue learning and access saved history.
Eligible data may be deleted or anonymised following a valid deletion request, subject to lawful exceptions.
22.3 AI usage data
AI usage logs and monthly counters may be retained for:
- plan enforcement;
- operational cost management;
- troubleshooting;
- security;
- abuse prevention; and
- legal claims.
- Monthly allowance reset does not automatically delete the previous month’s operational records.
22.4 Billing information
Subscription identifiers, invoices, refund records and billing records may be retained for:
- subscription administration;
- refunds;
- chargebacks;
- payment disputes;
- accounting;
- tax obligations;
- fraud prevention; and
- legal claims.
- Deletion of a LingoGap account does not necessarily require deletion of records that UgleCare ApS or another party must retain by law.
22.5 Support communications
Support correspondence may be retained while necessary to handle the matter and for a reasonable period afterwards for continuity, complaint handling, dispute resolution and legal compliance.
22.6 Administrative records
Role-change and manual-access records may be retained for security, accountability, fraud prevention and dispute resolution.
22.7 Provider and backup retention
Copies may remain temporarily in:
- technical backups;
- provider logs;
- security records; or
disaster-recovery systems
until overwritten or deleted according to the applicable provider process.
23. Account deletion
LingoGap does not currently provide a complete self-service account-deletion button.
To request account deletion, email:
Please use the email associated with your account where possible.
We may request reasonable information to verify:
- your identity;
- your authority over the account; and
- the scope of the request.
A complete deletion procedure may require actions concerning:
- Firebase Authentication;
- the main Firestore user document;
- user subcollections;
- progress;
- lesson state;
- flashcards;
- review logs;
- AI usage;
- PD3 attempts and results;
- local browser storage;
- support records;
- Stripe identifiers; and
- related provider information.
Some information may be retained where required or permitted for:
- accounting;
- tax;
- payment disputes;
- fraud prevention;
- security;
- legal obligations; or
- legal claims.
- Deleting an account is separate from cancelling a subscription.
- An active paid subscription must be cancelled or otherwise resolved before account deletion is completed.
24. Security
LingoGap uses technical and organisational measures intended to protect personal data.
Measures visible in the current service include:
- authenticated API routes;
- Firebase ID-token verification;
- access-control rules;
- user-specific database paths;
- role checks;
- server-side administrative checks;
- Stripe webhook-signature verification;
- hosted Stripe Checkout;
- transaction-based updates for sensitive entitlement processes;
- input validation;
- input-size limits;
- AI-usage limits;
- examination-access checks;
- separation of server-only functionality;
- environment-based secret handling; and
- HTTPS provided through the hosting platform.
- No online service can guarantee absolute security.
Users should:
- use a strong and unique password;
- protect access to their email;
- sign out on shared devices;
- avoid sharing authentication credentials; and
- report suspected unauthorised access promptly.
25. Personal-data breaches
A personal-data breach may include accidental or unlawful:
- destruction;
- loss;
- alteration;
- unauthorised disclosure of; or
- access to personal data.
- Where required by applicable law, the controller will assess and document the incident and notify the competent supervisory authority and affected individuals.
- A processor that becomes aware of a personal-data breach must inform the controller without undue delay. Datatilsynet states that reportable breaches should be notified by the controller where the incident presents a risk to affected individuals.
Suspected security incidents should be reported to:
26. Children
LingoGap is intended primarily for adult Danish learners.
A person must be at least 18 years old to independently purchase a subscription.
LingoGap does not currently:
- collect date of birth as part of ordinary registration;
- operate a general age-verification system;
- create child-specific profiles;
- record parental consent through a dedicated technical workflow; or
- intentionally provide a service specifically directed at young children.
- A person under 18 should use LingoGap only with the permission and supervision of a parent or legal guardian.
- Where processing of a child’s data requires parental consent or another safeguard under applicable law, the appropriate consent or authorisation must be obtained before use.
27. Your data-protection rights
Subject to the conditions and exceptions in applicable law, you may have the rights described below.
27.1 Right to information
You have the right to receive clear information about how your personal data is processed.
27.2 Right of access
You may request confirmation of whether personal data about you is processed and request a copy of relevant personal data.
27.3 Right to rectification
You may request correction of inaccurate personal data and completion of incomplete data.
Some preferences can be corrected directly through the application.
27.4 Right to erasure
You may request deletion of personal data in circumstances provided by law.
The right is not absolute. Information may be retained where processing remains necessary for:
- legal obligations;
- accounting;
- payment disputes;
- fraud prevention;
- security;
- legal claims; or
- another lawful purpose.
27.5 Right to restriction
You may request restriction of processing in circumstances provided by law, including while the accuracy or lawfulness of processing is being assessed.
27.6 Right to data portability
Where processing is based on consent or contract and carried out by automated means, you may have the right to receive personal data you provided in a structured, commonly used and machine-readable format.
LingoGap does not currently provide a self-service export tool. A request must therefore be handled manually.
27.7 Right to object
You may object to processing based on legitimate interests.
The relevant controller will then assess whether compelling legitimate grounds or legal-claim requirements justify continued processing.
27.8 Right to withdraw consent
Where processing is based on consent, you may withdraw it at any time.
Withdrawal does not affect processing lawfully carried out before withdrawal.
27.9 Rights concerning automated decisions
LingoGap does not currently use educational AI output to make decisions producing legal or similarly significant effects.
You may nevertheless contact LingoGap if you believe an automated educational result is technically incorrect or has been applied improperly.
27.10 Right to complain
You may lodge a complaint with a competent data-protection supervisory authority.
In Denmark, the supervisory authority is:
Datatilsynet — the Danish Data Protection Agency
Datatilsynet recommends contacting the relevant controller before filing a complaint.
28. Exercising your rights
Requests should be sent to:
Please state:
- the email associated with your account;
- the right you wish to exercise;
- the data or processing involved; and
- any information reasonably needed to understand the request.
- Do not send passwords or full payment-card details.
- We may request reasonable identity verification where necessary to prevent unauthorised disclosure or deletion.
- Requests will normally be handled without charge.
- A reasonable fee or refusal may be permitted where a request is manifestly unfounded or excessive, particularly where it is repetitive.
- Requests will be answered within the period required by applicable law. That period may be extended for complex or numerous requests where legally permitted, and the requester will be informed where required.
29. Data portability and manual exports
LingoGap does not currently provide an automated account-export function.
Where legally required and technically possible, a manual export may include relevant information such as:
- profile data;
- preferences;
- Foundation progress;
- flashcards;
- writing responses;
- speaking transcripts;
- examination attempts;
- AI feedback; and
- subscription data held by LingoGap or UgleCare ApS.
- Certain internal, third-party, legally protected or security-sensitive information may be excluded where permitted by law.
30. Third-party links and services
LingoGap may link to or use third-party services.
LingoGap and UgleCare ApS are not responsible for the independent privacy practices of third parties acting as separate controllers.
Users should review the relevant privacy information provided by:
- Stripe;
- Google;
- Firebase or Google Cloud;
- their browser provider; and
- other independently used services.
31. Changes to this Privacy Policy
This Privacy Policy may be updated because of:
- changes in law;
- new or changed functionality;
- new service providers;
- changes in data processing;
- security improvements;
- organisational changes;
- changes in the commercial or technical operating structure; or
- clarification of existing information.
- The version and effective date will be shown at the top.
- Where a change is material, an appropriate notice will be provided where required.
- A new policy version does not retroactively make previously unlawful processing lawful.
32. Language
The official Version 1.0 of this Privacy Policy is in English.
Translations may be provided for convenience.
A translation may not reduce information or rights required by applicable data-protection law.
33. Contact and legal information
For privacy questions, data-subject requests, account-deletion requests or security concerns:
Service and trading name: LingoGap
Data controller: UgleCare ApS
CVR: 34353255
Registered address: Borups Allé 116, st. tv., 2000 Frederiksberg, Denmark
Website: https://lingogap.dk
Email: support@lingogap.dk