Skip to main content
Legal

Privacy Policy

What Xmentra stores, where it is stored, how long it is kept, and the choices you have.

Version
1.1
Effective date
4 August 2026
Last updated
5 August 2026
Contents

Introduction

Xmentra is an AI-assisted, mentor-driven language learning platform. This Privacy Policy explains what information the Platform collects, why it is collected, where it is stored, how long it is kept, and the choices you have.

The Platform is designed to work with as little information about you as is reasonably necessary. Today, most of what the Platform knows about your learning stays on your own device, in your browser. This Policy describes that arrangement honestly, and also describes how information will be handled if and when features such as Accounts, AI Features, Premium Features, and Community are introduced.

This Policy forms part of the Terms of Use (/terms) and should be read together with the Cookie Policy (/cookie-policy).

1. Definitions

These definitions are shared across all Xmentra legal documents and are reproduced without modification in each of them.

  • Platform — the Xmentra website at https://xmentra.com, together with any applications, subdomains, and interfaces operated by Xmentra.
  • Services — all functionality offered through the Platform, including lessons, learning experiences, vocabulary, grammar, listening, revision, progress tracking, the educational blog, and any features added later.
  • AI Features — any part of the Services that uses automated language models or similar techniques to generate, adapt, evaluate, or respond to content, including the AI Mentor and AI Conversations when introduced.
  • Personal Information — information that identifies, or can reasonably be used to identify, an individual, either alone or combined with other information available to Xmentra.
  • Cookies — small files placed on a device by the Platform or a Third Party Service to store or read information.
  • Local Storage — browser storage mechanisms, including localStorage and sessionStorage, used by the Platform to keep information on the User's own device.
  • Third Party Services — independent providers whose infrastructure or tools support the Platform, including hosting, analytics, and, where applicable, content delivery, payment, communication, and AI providers.
  • User — any person who accesses or uses the Platform, with or without an Account.
  • Content — any text, audio, image, code, exercise, translation, or other material available through the Platform, whether created by Xmentra, generated by AI Features, or submitted by a User.
  • Account — a credentialed profile that a User may create when Accounts are available, allowing Learning Data to be stored by Xmentra rather than only on the device.
  • Learning Data — information about a User's learning activity, such as lessons opened, experiences completed, confidence responses, saved vocabulary, and revision history.
  • Educational Content — Content published by Xmentra for learning purposes, including lessons, learning experiences, explanations, audio, and blog articles.
  • Mentor — the guiding instructional voice of the Platform, delivered through Educational Content and, where applicable, AI Features. A Mentor is not a certified teacher, examiner, translator, or adviser.
  • Subscription — a recurring paid arrangement granting access to Premium Features, where such arrangements are offered.
  • Premium Features — Services available only under a Subscription or other paid plan.
  • Community — any feature allowing Users to interact with one another, including forums, comments, groups, or shared practice.

2. Our Privacy Approach

Privacy is treated as a design input at Xmentra, not as a document written after a feature ships.

Privacy is considered during product design. Before a feature is built, we ask what information it genuinely needs, where that information should live, and how long it should be kept. If a feature can work without Personal Information, it is built that way.

We aim to collect only what is reasonably necessary to operate, improve, and secure the Platform, and to meet obligations that apply to us.

On-device storage is preferred where it is sufficient. Learning is personal, and a record of your hesitations, revisions, and confidence responses is sensitive in a quiet way even when it contains no name. Keeping that record in your browser's Local Storage means it is available to you, useful to your learning, and not accumulated on our servers. Where a feature genuinely requires server storage — synchronising progress across devices, for example — we say so before the feature launches.

Documentation moves with the product. When a release changes what the Platform collects, this Policy is updated in the same release rather than afterwards.

3. Data Minimisation

We follow a principle of collecting the minimum information reasonably necessary for a stated purpose. In practice this means:

  • Using the Services does not require you to create an Account, provide your name, or give us an email address.
  • Technical and usage information is collected in aggregate form where that is sufficient for the purpose.
  • Where information is needed only for a single interaction, it is not retained beyond that interaction, except to the extent required by applicable law.
  • Where AI Features are involved, only the input reasonably needed to produce a useful response is sent for processing.
  • Optional information stays optional. Where a field is not required to deliver a feature, you may leave it empty.

This is a principle we apply, not a guarantee that no information is collected. Sections 4 to 8 describe what is actually collected today.

4. Information We Collect

Xmentra collects three kinds of information:

  • Information you provide — for example, the content of a message you send us, and, where Accounts are available, the details you use to register.
  • Information collected automatically — limited technical and usage information generated when you visit the Platform.
  • Learning Data — information about your progress through the Services, which is currently stored on your own device in Local Storage.

5. Information You Provide

5.1 Messages and enquiries

If you contact us at hello@xmentra.com, we receive the email address you write from and the content of your message. We use this to respond to you and to keep a reasonable record of the enquiry.

5.2 Accounts

Accounts are not currently required to use the Services. Where Accounts become available, registration may involve an email address, a display name, and authentication information, or sign-in through a Third Party Service. Where sign-in through a Third Party Service is used, we receive only the identifying details that service releases to us, not your password.

5.3 Payments

Payments are not currently processed on the Platform. Where Premium Features or Subscriptions are introduced, payment details will be handled by a specialised payment provider. Xmentra expects to receive confirmation of a transaction and the status of a Subscription, and does not intend to store complete card or bank credentials.

5.4 Community contributions

Where Community features are introduced, anything you post may be visible to other Users. Treat such contributions as public and share only what you are comfortable making public.

6. Information Collected Automatically

When you visit the Platform, our hosting and analytics providers process limited technical information such as:

  • IP address, which may be truncated or anonymised by the relevant provider
  • browser type, operating system, and device category
  • the pages you view, and the page or search that referred you
  • approximate location derived from network information, at city or region level
  • timestamps and basic performance information

This information helps us keep the Platform available, diagnose faults, protect against abuse, and understand which Educational Content is useful. It is not used to build advertising profiles, and it is not sold.

7. Browser Local Storage

Local Storage is central to how Xmentra works today.

The Platform writes your Learning Data to your browser's Local Storage so that your progress is still there when you return. This includes items such as completed lessons and learning experiences, saved vocabulary, revision history, confidence responses, and interface preferences.

What this means in practice:

  • This information stays on your device. It is not transmitted to Xmentra's servers while Accounts are unavailable.
  • It is specific to the browser and device you used. Progress does not follow you to another device.
  • Clearing your browser storage, using private browsing, or switching browsers removes or hides it.
  • Xmentra holds no copy, and cannot recover Local Storage data once it has been cleared.

Full technical detail, including the categories of stored keys, is in the Cookie Policy (/cookie-policy).

8. Accounts and Future Data Migration

We recognise that moving learning information from a device to a server is a meaningful change, and we do not intend it to happen by surprise.

If Accounts or cloud synchronisation become available:

  1. You will be informed within the Platform before any locally stored Learning Data is migrated to Xmentra's systems.
  2. Migration will follow a deliberate action by you, such as creating an Account and choosing to synchronise. It will not happen silently in the background.
  3. You will be told, in plain terms, what is being moved and what remains on your device.
  4. This Policy will be updated to describe server-side storage, retention, and deletion before the feature is released, and the change will be recorded in the Revision History.
  5. Continuing to use the Services without an Account will remain possible for as long as the Services can reasonably be offered that way.

9. Cookies

The Platform uses only the storage and Cookies it needs to function and to measure aggregate usage. It does not currently use advertising Cookies.

Cookie categories, what they do, and how to control or refuse them are described in the Cookie Policy (/cookie-policy). Where non-essential Cookies are introduced in a jurisdiction that requires prior consent, consent will be requested before those Cookies are set.

10. Analytics

The Platform uses Google Analytics 4 to understand aggregate usage — for example, how many people read a lesson, and which pages are entered first.

  • Measurement identifier in use: G-3NRLBB8NWC.
  • Analytics reporting is aggregate. It is not used to identify individuals.
  • Google Analytics advertising and audience-sharing features are not enabled.
  • Google acts as an independent provider and processes this information under its own terms and privacy notice.

You can prevent Google Analytics from collecting information by using the Google Analytics opt-out browser add-on, or by using a browser setting or extension that blocks analytics scripts.

11. AI Governance Principles

Three principles govern every AI Feature on the Platform, present or future. They are stated here because they affect how information is handled, and they are expanded in the AI & Educational Use Policy (/ai-policy).

11.1 Transparency

Where a response, correction, or conversation is produced by AI Features, that will be evident in the interface. We do not present automated output as the work of a human teacher.

11.2 Human oversight

AI Features assist your learning; they do not replace your judgement. You remain the decision-maker about what to accept, question, or verify, and Xmentra reviews AI-assisted Educational Content as part of publishing it.

11.3 Educational assistance

AI Features exist to support language capability — explaining, prompting, practising, and responding. They are not a certification, an examination, a translation service, or professional advice, and their output may contain inaccuracies or omissions.

12. AI-Assisted Features

AI Features are part of the Platform's roadmap and are being introduced gradually. The following rules apply to them, and will not be weakened without updating this Policy first.

  • Minimal input. Only the input reasonably needed to produce a useful response is sent for processing — typically the text or audio you submit and the immediate learning context, rather than your full history.
  • Provider terms. Where AI processing is carried out by a Third Party Service, Xmentra seeks terms that restrict use of your input to delivering the response.
  • Sensitive information. Please do not include personal, financial, medical, or confidential details in AI Features. They are language practice tools, not secure channels.
  • Limits. The AI & Educational Use Policy (/ai-policy) explains the limits of AI output and the responsibilities that remain with you.

13. AI Training Transparency

Information you submit through the Services, including Learning Data and text or audio you send to AI Features, is not used to train general-purpose AI models by default, whether by Xmentra or, to the extent our provider terms allow us to require it, by a Third Party Service.

If this practice ever changes:

  • the change will be described in this Policy and, where applicable, in the AI & Educational Use Policy (/ai-policy), before it takes effect;
  • where applicable law requires consent, consent will be requested rather than assumed;
  • the change will be recorded in the Revision History with its Effective Date.

Aggregate, de-identified information about how the Services are used — such as which lessons are opened most often — may be used to improve Educational Content and sequencing. This is product improvement, not model training, and it does not involve your identity.

14. Third Party Services

We work with a small number of providers, described by role so that this section remains accurate as the list evolves. Named providers appear in the final column.

RoleWhat it doesInformation involvedCurrently used
HostingServes the Platform and runs server-side codeTechnical request data, including IP addressVercel
Content delivery and network protectionCaches assets and protects availabilityTechnical request data, including IP addressProvided as part of hosting
AnalyticsAggregate usage measurementUsage events, device and browser category, approximate locationGoogle Analytics 4
Infrastructure and error monitoringDetects faults and abuseTechnical logs, error tracesProvided as part of hosting
AI processingGenerates responses within AI FeaturesThe input you submit and its immediate learning contextNone yet
Payment processingHandles Subscription transactionsBilling and transaction details, held by the providerNone yet
CommunicationSends service messages you have asked forEmail address and message contentEmail only, at hello@xmentra.com

Each provider may process information only for the purpose we engage it for, and each is selected with its security and privacy posture in mind. As the list of providers grows, it will be maintained here and, once it extends meaningfully beyond hosting and analytics, in a dedicated Subprocessors List linked from this Policy.

15. How We Use Information

We use information to:

  • provide, maintain, and improve the Services and Educational Content
  • keep your learning progress available to you
  • understand aggregate usage so we can improve sequencing and clarity
  • diagnose faults, protect the Platform, and prevent misuse
  • respond to your messages
  • operate Accounts, Subscriptions, Certificates, and Community features where those are available
  • meet legal obligations that apply to us

We do not sell Personal Information, and Learning Data is not used for advertising.

16. Data Sharing

We share information only in these situations:

  • With Third Party Services, as described in Section 14, to the extent needed for them to perform their role.
  • Within Community features, where you choose to publish something.
  • For legal reasons, where disclosure is required by applicable law or a valid legal request, or is reasonably necessary to protect the rights, safety, or integrity of Users, third parties, or the Platform.
  • In a business transfer, if Xmentra is involved in a merger, acquisition, or reorganisation. Any successor would remain bound by commitments no less protective than those in this Policy, and material changes would be announced.

17. International Transfers

Xmentra operates from India, and its providers may process information in other countries, including within the European Economic Area and the United States.

Where information is transferred across borders, we rely on providers that offer recognised transfer safeguards and contractual protections. If you use the Platform, information relating to your use may be processed in a country other than your own. Where applicable law requires a specific transfer mechanism, we will use one.

18. Data Retention

We keep information only as long as it serves the purpose it was collected for.

InformationPurposeWhere it is storedRetention periodDeletion triggerFuture migration note
Learning DataKeeps your progress, vocabulary, and confidence history available to youYour browser's Local StorageHeld until you clear itYou clear browser storage, use private browsing, or switch browser or deviceWhere Accounts are introduced, Section 8 applies before any move to server storage
Interface preferencesRemembers display and playback choicesYour browser's Local StorageHeld until you clear itYou clear browser storageWould follow the same migration process as Learning Data
Analytics informationAggregate usage measurement and content improvementGoogle Analytics 4, on Google infrastructureRetained under the window configured for the Platform, currently 14 monthsAutomatic expiry at the end of the retention windowUnchanged by Accounts; consent controls may be added where required
Technical request logsAvailability, fault diagnosis, and abuse preventionHosting provider infrastructureShort operational period set by the providerAutomatic log rotationUnchanged by Accounts
Email enquiriesResponding to you and keeping a reasonable recordOur email providerAs long as needed to resolve the enquiry and keep a reasonable recordResolution plus our internal review cycle, or your deletion requestUnchanged by Accounts
Account information, where applicableAuthenticating you and associating Learning Data with youXmentra's systemsWhile the Account is activeAccount closure, then deletion or anonymisation within a reasonable periodIntroduced only with the notice described in Section 8
AI Feature input, where applicableProducing the response you asked forProcessed by the AI provider; not retained by Xmentra beyond the interaction unless statedNot retained beyond the interaction, except where required by lawEnd of the interactionThis Policy will be updated before any retained AI history is introduced
Transaction records, where applicableMeeting tax and accounting obligationsPayment provider, with confirmations held by XmentraAs long as required by applicable tax and accounting lawExpiry of the statutory periodIntroduced with Premium Features

Where applicable law requires a longer retention period, that period applies.

19. Security

We use measures proportionate to the information we hold and to the risks we can reasonably foresee.

19.1 Transport and encryption

The Platform is served over HTTPS, so information exchanged between your browser and the Platform is encrypted in transit. Information held by our providers is protected using the encryption measures those providers apply at rest and in transit.

19.2 Storage design

Learning Data stays on your device by default. This is a deliberate security choice: information we never hold cannot be exposed by a failure on our side.

19.3 Access control

Access to administrative surfaces, provider dashboards, and any system holding Personal Information is limited to those who need it for their role. Authentication on those systems uses strong credentials and, where the provider supports it, multi-factor authentication. Server-side credentials and keys are kept out of client code and out of version control.

19.4 Infrastructure security

The Platform runs on established hosting infrastructure that provides network protection, isolation between environments, and platform-level patching. We choose providers for their security posture as well as their function.

19.5 Monitoring

Availability, errors, and unusual traffic patterns are monitored so that faults and abuse can be identified and addressed.

19.6 Software maintenance

Dependencies and platform components are updated as part of ordinary maintenance, and security-relevant updates are prioritised.

19.7 What we cannot promise

No method of transmission or storage is completely secure, and no organisation can guarantee absolute protection. What we can commit to is applying reasonable and proportionate safeguards, reviewing them as the Platform grows, and responding promptly when something goes wrong.

20. Security Incident Response

If we become aware of a security incident that affects, or is reasonably likely to affect, Personal Information, we will:

  1. Investigate promptly to establish what happened, what information is involved, and whether the incident is ongoing.
  2. Contain and correct — take appropriate technical and organisational measures to stop the incident, limit its effect, and reduce the chance of recurrence.
  3. Notify affected Users and the relevant supervisory authority where applicable law requires notification, within the timeframe that law sets, and without undue delay.
  4. Explain what we know, what we are doing, and what steps you may wish to take, in plain language rather than in vague terms.
  5. Record the incident internally and review whether our safeguards, providers, or processes should change as a result.

Where Learning Data is held only in your browser's Local Storage, an incident on our infrastructure would not expose it. You can report a suspected vulnerability or incident to hello@xmentra.com.

21. Children's Privacy

The Platform is intended for Users aged 14 and above. It is not designed for younger children, and we do not knowingly collect Personal Information from them.

Where local law sets a higher age for independent use of an online service, that higher age applies, and a parent or guardian must agree to the Terms of Use on the User's behalf. If you believe a child below the applicable age has provided Personal Information to us, contact hello@xmentra.com and we will remove it.

22. Your Rights

Because information sits in different places, your rights are easiest to understand grouped by where the information lives.

22.1 Information stored on your device

While Learning Data is stored only in Local Storage, you exercise access, correction, and deletion directly. The data is on your device, your browser settings control it, and we hold no copy. Clearing site data for https://xmentra.com removes it. No request to us is needed, and none is possible — we cannot reach it.

22.2 Information held by Xmentra

For information we do hold — such as email correspondence — you may ask us to access, correct, or delete it, or to restrict how we use it. Write to hello@xmentra.com. We may need to confirm your identity before acting, and we will respond within the period required by applicable law, and in any case within 30 days.

22.3 Account information, where applicable

Where Accounts are available, the Platform will provide in-product controls to review and update your details, export your Learning Data in a portable format, and delete your Account. Deleting an Account deletes or anonymises the information associated with it, subject to any retention we are legally required to observe.

22.4 Rights under your local law

Depending on where you live, you may have additional or differently framed rights, which may include the right to:

  • Access the Personal Information we hold about you
  • Correct information that is inaccurate or incomplete
  • Delete information we hold about you
  • Restrict or object to certain processing
  • Withdraw consent where processing relies on consent
  • Port information you have provided to another service
  • Appeal or complain to a data protection or consumer authority

We honour these rights where applicable law grants them, and we do not charge for a reasonable request or treat you differently for making one. Xmentra operates from India, and rights under Indian law apply alongside any additional rights your own jurisdiction provides.

The Platform links to external resources, including dictionaries, institutional pages, and reference material. Those sites are operated independently. We do not control their content or their privacy practices, and this Policy does not apply to them. Review their own notices before providing information to them.

24. Changes to this Policy

We update this Policy when the Platform changes, when new providers or features are introduced, or when law requires it.

  • The Last Updated date at the top always reflects the most recent edit.
  • Material changes take effect on the stated Effective Date, and, once Accounts exist, will be announced at least 14 days in advance.
  • Changes that expand what we collect, or that introduce server-side storage of Learning Data, are treated as material.
  • Previous versions are recorded in the Revision History below and retained internally for reference.

Continuing to use the Platform after a change takes effect means the updated Policy applies to you.

25. Contact Information

Questions, requests, or concerns about privacy:

Email: hello@xmentra.com Platform: https://xmentra.com

We aim to respond to every privacy request within 30 days.

26. Revision History

VersionEffective DateSummary of change
1.14 August 2026Added Privacy Approach, Data Minimisation, Accounts and Future Data Migration, AI Governance Principles, AI Training Transparency, and Security Incident Response sections. Expanded Security, Third Party Services, Retention, and Your Rights. Future-proofed wording throughout.
1.04 August 2026Initial publication under the Xmentra Legal Architecture v1.0

Ready to start with your language mentor?

German is the first language available, taught through short, mentor-guided experiences.