Introduction
Xmentra is an AI-assisted, mentor-driven language learning platform. This Privacy Policy explains what information the Platform collects, why it is collected, where it is stored, how long it is kept, and the choices you have.
The Platform is designed to work with as little information about you as is reasonably necessary. Today, most of what the Platform knows about your learning stays on your own device, in your browser. This Policy describes that arrangement honestly, and also describes how information will be handled if and when features such as Accounts, AI Features, Premium Features, and Community are introduced.
This Policy forms part of the Terms of Use (/terms) and should be read together with the Cookie Policy (/cookie-policy).
1. Definitions
These definitions are shared across all Xmentra legal documents and are reproduced without modification in each of them.
- Platform — the Xmentra website at https://xmentra.com, together with any applications, subdomains, and interfaces operated by Xmentra.
- Services — all functionality offered through the Platform, including lessons, learning experiences, vocabulary, grammar, listening, revision, progress tracking, the educational blog, and any features added later.
- AI Features — any part of the Services that uses automated language models or similar techniques to generate, adapt, evaluate, or respond to content, including the AI Mentor and AI Conversations when introduced.
- Personal Information — information that identifies, or can reasonably be used to identify, an individual, either alone or combined with other information available to Xmentra.
- Cookies — small files placed on a device by the Platform or a Third Party Service to store or read information.
- Local Storage — browser storage mechanisms, including
localStorageandsessionStorage, used by the Platform to keep information on the User's own device. - Third Party Services — independent providers whose infrastructure or tools support the Platform, including hosting, analytics, and, where applicable, content delivery, payment, communication, and AI providers.
- User — any person who accesses or uses the Platform, with or without an Account.
- Content — any text, audio, image, code, exercise, translation, or other material available through the Platform, whether created by Xmentra, generated by AI Features, or submitted by a User.
- Account — a credentialed profile that a User may create when Accounts are available, allowing Learning Data to be stored by Xmentra rather than only on the device.
- Learning Data — information about a User's learning activity, such as lessons opened, experiences completed, confidence responses, saved vocabulary, and revision history.
- Educational Content — Content published by Xmentra for learning purposes, including lessons, learning experiences, explanations, audio, and blog articles.
- Mentor — the guiding instructional voice of the Platform, delivered through Educational Content and, where applicable, AI Features. A Mentor is not a certified teacher, examiner, translator, or adviser.
- Subscription — a recurring paid arrangement granting access to Premium Features, where such arrangements are offered.
- Premium Features — Services available only under a Subscription or other paid plan.
- Community — any feature allowing Users to interact with one another, including forums, comments, groups, or shared practice.
2. Our Privacy Approach
Privacy is treated as a design input at Xmentra, not as a document written after a feature ships.
Privacy is considered during product design. Before a feature is built, we ask what information it genuinely needs, where that information should live, and how long it should be kept. If a feature can work without Personal Information, it is built that way.
We aim to collect only what is reasonably necessary to operate, improve, and secure the Platform, and to meet obligations that apply to us.
On-device storage is preferred where it is sufficient. Learning is personal, and a record of your hesitations, revisions, and confidence responses is sensitive in a quiet way even when it contains no name. Keeping that record in your browser's Local Storage means it is available to you, useful to your learning, and not accumulated on our servers. Where a feature genuinely requires server storage — synchronising progress across devices, for example — we say so before the feature launches.
Documentation moves with the product. When a release changes what the Platform collects, this Policy is updated in the same release rather than afterwards.
3. Data Minimisation
We follow a principle of collecting the minimum information reasonably necessary for a stated purpose. In practice this means:
- Using the Services does not require you to create an Account, provide your name, or give us an email address.
- Technical and usage information is collected in aggregate form where that is sufficient for the purpose.
- Where information is needed only for a single interaction, it is not retained beyond that interaction, except to the extent required by applicable law.
- Where AI Features are involved, only the input reasonably needed to produce a useful response is sent for processing.
- Optional information stays optional. Where a field is not required to deliver a feature, you may leave it empty.
This is a principle we apply, not a guarantee that no information is collected. Sections 4 to 8 describe what is actually collected today.
4. Information We Collect
Xmentra collects three kinds of information:
- Information you provide — for example, the content of a message you send us, and, where Accounts are available, the details you use to register.
- Information collected automatically — limited technical and usage information generated when you visit the Platform.
- Learning Data — information about your progress through the Services, which is currently stored on your own device in Local Storage.
5. Information You Provide
5.1 Messages and enquiries
If you contact us at hello@xmentra.com, we receive the email address you write from and the content of your message. We use this to respond to you and to keep a reasonable record of the enquiry.
5.2 Accounts
Accounts are not currently required to use the Services. Where Accounts become available, registration may involve an email address, a display name, and authentication information, or sign-in through a Third Party Service. Where sign-in through a Third Party Service is used, we receive only the identifying details that service releases to us, not your password.
5.3 Payments
Payments are not currently processed on the Platform. Where Premium Features or Subscriptions are introduced, payment details will be handled by a specialised payment provider. Xmentra expects to receive confirmation of a transaction and the status of a Subscription, and does not intend to store complete card or bank credentials.
5.4 Community contributions
Where Community features are introduced, anything you post may be visible to other Users. Treat such contributions as public and share only what you are comfortable making public.
6. Information Collected Automatically
When you visit the Platform, our hosting and analytics providers process limited technical information such as:
- IP address, which may be truncated or anonymised by the relevant provider
- browser type, operating system, and device category
- the pages you view, and the page or search that referred you
- approximate location derived from network information, at city or region level
- timestamps and basic performance information
This information helps us keep the Platform available, diagnose faults, protect against abuse, and understand which Educational Content is useful. It is not used to build advertising profiles, and it is not sold.
7. Browser Local Storage
Local Storage is central to how Xmentra works today.
The Platform writes your Learning Data to your browser's Local Storage so that your progress is still there when you return. This includes items such as completed lessons and learning experiences, saved vocabulary, revision history, confidence responses, and interface preferences.
What this means in practice:
- This information stays on your device. It is not transmitted to Xmentra's servers while Accounts are unavailable.
- It is specific to the browser and device you used. Progress does not follow you to another device.
- Clearing your browser storage, using private browsing, or switching browsers removes or hides it.
- Xmentra holds no copy, and cannot recover Local Storage data once it has been cleared.
Full technical detail, including the categories of stored keys, is in the Cookie Policy (/cookie-policy).
8. Accounts and Future Data Migration
We recognise that moving learning information from a device to a server is a meaningful change, and we do not intend it to happen by surprise.
If Accounts or cloud synchronisation become available:
- You will be informed within the Platform before any locally stored Learning Data is migrated to Xmentra's systems.
- Migration will follow a deliberate action by you, such as creating an Account and choosing to synchronise. It will not happen silently in the background.
- You will be told, in plain terms, what is being moved and what remains on your device.
- This Policy will be updated to describe server-side storage, retention, and deletion before the feature is released, and the change will be recorded in the Revision History.
- Continuing to use the Services without an Account will remain possible for as long as the Services can reasonably be offered that way.
9. Cookies
The Platform uses only the storage and Cookies it needs to function and to measure aggregate usage. It does not currently use advertising Cookies.
Cookie categories, what they do, and how to control or refuse them are described in the Cookie Policy (/cookie-policy). Where non-essential Cookies are introduced in a jurisdiction that requires prior consent, consent will be requested before those Cookies are set.
10. Analytics
The Platform uses Google Analytics 4 to understand aggregate usage — for example, how many people read a lesson, and which pages are entered first.
- Measurement identifier in use:
G-3NRLBB8NWC. - Analytics reporting is aggregate. It is not used to identify individuals.
- Google Analytics advertising and audience-sharing features are not enabled.
- Google acts as an independent provider and processes this information under its own terms and privacy notice.
You can prevent Google Analytics from collecting information by using the Google Analytics opt-out browser add-on, or by using a browser setting or extension that blocks analytics scripts.
11. AI Governance Principles
Three principles govern every AI Feature on the Platform, present or future. They are stated here because they affect how information is handled, and they are expanded in the AI & Educational Use Policy (/ai-policy).
11.1 Transparency
Where a response, correction, or conversation is produced by AI Features, that will be evident in the interface. We do not present automated output as the work of a human teacher.
11.2 Human oversight
AI Features assist your learning; they do not replace your judgement. You remain the decision-maker about what to accept, question, or verify, and Xmentra reviews AI-assisted Educational Content as part of publishing it.
11.3 Educational assistance
AI Features exist to support language capability — explaining, prompting, practising, and responding. They are not a certification, an examination, a translation service, or professional advice, and their output may contain inaccuracies or omissions.
12. AI-Assisted Features
AI Features are part of the Platform's roadmap and are being introduced gradually. The following rules apply to them, and will not be weakened without updating this Policy first.
- Minimal input. Only the input reasonably needed to produce a useful response is sent for processing — typically the text or audio you submit and the immediate learning context, rather than your full history.
- Provider terms. Where AI processing is carried out by a Third Party Service, Xmentra seeks terms that restrict use of your input to delivering the response.
- Sensitive information. Please do not include personal, financial, medical, or confidential details in AI Features. They are language practice tools, not secure channels.
- Limits. The AI & Educational Use Policy (/ai-policy) explains the limits of AI output and the responsibilities that remain with you.
13. AI Training Transparency
Information you submit through the Services, including Learning Data and text or audio you send to AI Features, is not used to train general-purpose AI models by default, whether by Xmentra or, to the extent our provider terms allow us to require it, by a Third Party Service.
If this practice ever changes:
- the change will be described in this Policy and, where applicable, in the AI & Educational Use Policy (/ai-policy), before it takes effect;
- where applicable law requires consent, consent will be requested rather than assumed;
- the change will be recorded in the Revision History with its Effective Date.
Aggregate, de-identified information about how the Services are used — such as which lessons are opened most often — may be used to improve Educational Content and sequencing. This is product improvement, not model training, and it does not involve your identity.
14. Third Party Services
We work with a small number of providers, described by role so that this section remains accurate as the list evolves. Named providers appear in the final column.
| Role | What it does | Information involved | Currently used |
|---|---|---|---|
| Hosting | Serves the Platform and runs server-side code | Technical request data, including IP address | Vercel |
| Content delivery and network protection | Caches assets and protects availability | Technical request data, including IP address | Provided as part of hosting |
| Analytics | Aggregate usage measurement | Usage events, device and browser category, approximate location | Google Analytics 4 |
| Infrastructure and error monitoring | Detects faults and abuse | Technical logs, error traces | Provided as part of hosting |
| AI processing | Generates responses within AI Features | The input you submit and its immediate learning context | None yet |
| Payment processing | Handles Subscription transactions | Billing and transaction details, held by the provider | None yet |
| Communication | Sends service messages you have asked for | Email address and message content | Email only, at hello@xmentra.com |
Each provider may process information only for the purpose we engage it for, and each is selected with its security and privacy posture in mind. As the list of providers grows, it will be maintained here and, once it extends meaningfully beyond hosting and analytics, in a dedicated Subprocessors List linked from this Policy.
15. How We Use Information
We use information to:
- provide, maintain, and improve the Services and Educational Content
- keep your learning progress available to you
- understand aggregate usage so we can improve sequencing and clarity
- diagnose faults, protect the Platform, and prevent misuse
- respond to your messages
- operate Accounts, Subscriptions, Certificates, and Community features where those are available
- meet legal obligations that apply to us
We do not sell Personal Information, and Learning Data is not used for advertising.
16. Data Sharing
We share information only in these situations:
- With Third Party Services, as described in Section 14, to the extent needed for them to perform their role.
- Within Community features, where you choose to publish something.
- For legal reasons, where disclosure is required by applicable law or a valid legal request, or is reasonably necessary to protect the rights, safety, or integrity of Users, third parties, or the Platform.
- In a business transfer, if Xmentra is involved in a merger, acquisition, or reorganisation. Any successor would remain bound by commitments no less protective than those in this Policy, and material changes would be announced.
17. International Transfers
Xmentra operates from India, and its providers may process information in other countries, including within the European Economic Area and the United States.
Where information is transferred across borders, we rely on providers that offer recognised transfer safeguards and contractual protections. If you use the Platform, information relating to your use may be processed in a country other than your own. Where applicable law requires a specific transfer mechanism, we will use one.
18. Data Retention
We keep information only as long as it serves the purpose it was collected for.
| Information | Purpose | Where it is stored | Retention period | Deletion trigger | Future migration note |
|---|---|---|---|---|---|
| Learning Data | Keeps your progress, vocabulary, and confidence history available to you | Your browser's Local Storage | Held until you clear it | You clear browser storage, use private browsing, or switch browser or device | Where Accounts are introduced, Section 8 applies before any move to server storage |
| Interface preferences | Remembers display and playback choices | Your browser's Local Storage | Held until you clear it | You clear browser storage | Would follow the same migration process as Learning Data |
| Analytics information | Aggregate usage measurement and content improvement | Google Analytics 4, on Google infrastructure | Retained under the window configured for the Platform, currently 14 months | Automatic expiry at the end of the retention window | Unchanged by Accounts; consent controls may be added where required |
| Technical request logs | Availability, fault diagnosis, and abuse prevention | Hosting provider infrastructure | Short operational period set by the provider | Automatic log rotation | Unchanged by Accounts |
| Email enquiries | Responding to you and keeping a reasonable record | Our email provider | As long as needed to resolve the enquiry and keep a reasonable record | Resolution plus our internal review cycle, or your deletion request | Unchanged by Accounts |
| Account information, where applicable | Authenticating you and associating Learning Data with you | Xmentra's systems | While the Account is active | Account closure, then deletion or anonymisation within a reasonable period | Introduced only with the notice described in Section 8 |
| AI Feature input, where applicable | Producing the response you asked for | Processed by the AI provider; not retained by Xmentra beyond the interaction unless stated | Not retained beyond the interaction, except where required by law | End of the interaction | This Policy will be updated before any retained AI history is introduced |
| Transaction records, where applicable | Meeting tax and accounting obligations | Payment provider, with confirmations held by Xmentra | As long as required by applicable tax and accounting law | Expiry of the statutory period | Introduced with Premium Features |
Where applicable law requires a longer retention period, that period applies.
19. Security
We use measures proportionate to the information we hold and to the risks we can reasonably foresee.
19.1 Transport and encryption
The Platform is served over HTTPS, so information exchanged between your browser and the Platform is encrypted in transit. Information held by our providers is protected using the encryption measures those providers apply at rest and in transit.
19.2 Storage design
Learning Data stays on your device by default. This is a deliberate security choice: information we never hold cannot be exposed by a failure on our side.
19.3 Access control
Access to administrative surfaces, provider dashboards, and any system holding Personal Information is limited to those who need it for their role. Authentication on those systems uses strong credentials and, where the provider supports it, multi-factor authentication. Server-side credentials and keys are kept out of client code and out of version control.
19.4 Infrastructure security
The Platform runs on established hosting infrastructure that provides network protection, isolation between environments, and platform-level patching. We choose providers for their security posture as well as their function.
19.5 Monitoring
Availability, errors, and unusual traffic patterns are monitored so that faults and abuse can be identified and addressed.
19.6 Software maintenance
Dependencies and platform components are updated as part of ordinary maintenance, and security-relevant updates are prioritised.
19.7 What we cannot promise
No method of transmission or storage is completely secure, and no organisation can guarantee absolute protection. What we can commit to is applying reasonable and proportionate safeguards, reviewing them as the Platform grows, and responding promptly when something goes wrong.
20. Security Incident Response
If we become aware of a security incident that affects, or is reasonably likely to affect, Personal Information, we will:
- Investigate promptly to establish what happened, what information is involved, and whether the incident is ongoing.
- Contain and correct — take appropriate technical and organisational measures to stop the incident, limit its effect, and reduce the chance of recurrence.
- Notify affected Users and the relevant supervisory authority where applicable law requires notification, within the timeframe that law sets, and without undue delay.
- Explain what we know, what we are doing, and what steps you may wish to take, in plain language rather than in vague terms.
- Record the incident internally and review whether our safeguards, providers, or processes should change as a result.
Where Learning Data is held only in your browser's Local Storage, an incident on our infrastructure would not expose it. You can report a suspected vulnerability or incident to hello@xmentra.com.
21. Children's Privacy
The Platform is intended for Users aged 14 and above. It is not designed for younger children, and we do not knowingly collect Personal Information from them.
Where local law sets a higher age for independent use of an online service, that higher age applies, and a parent or guardian must agree to the Terms of Use on the User's behalf. If you believe a child below the applicable age has provided Personal Information to us, contact hello@xmentra.com and we will remove it.
22. Your Rights
Because information sits in different places, your rights are easiest to understand grouped by where the information lives.
22.1 Information stored on your device
While Learning Data is stored only in Local Storage, you exercise access, correction, and deletion directly. The data is on your device, your browser settings control it, and we hold no copy. Clearing site data for https://xmentra.com removes it. No request to us is needed, and none is possible — we cannot reach it.
22.2 Information held by Xmentra
For information we do hold — such as email correspondence — you may ask us to access, correct, or delete it, or to restrict how we use it. Write to hello@xmentra.com. We may need to confirm your identity before acting, and we will respond within the period required by applicable law, and in any case within 30 days.
22.3 Account information, where applicable
Where Accounts are available, the Platform will provide in-product controls to review and update your details, export your Learning Data in a portable format, and delete your Account. Deleting an Account deletes or anonymises the information associated with it, subject to any retention we are legally required to observe.
22.4 Rights under your local law
Depending on where you live, you may have additional or differently framed rights, which may include the right to:
- Access the Personal Information we hold about you
- Correct information that is inaccurate or incomplete
- Delete information we hold about you
- Restrict or object to certain processing
- Withdraw consent where processing relies on consent
- Port information you have provided to another service
- Appeal or complain to a data protection or consumer authority
We honour these rights where applicable law grants them, and we do not charge for a reasonable request or treat you differently for making one. Xmentra operates from India, and rights under Indian law apply alongside any additional rights your own jurisdiction provides.
23. Third-Party Links
The Platform links to external resources, including dictionaries, institutional pages, and reference material. Those sites are operated independently. We do not control their content or their privacy practices, and this Policy does not apply to them. Review their own notices before providing information to them.
24. Changes to this Policy
We update this Policy when the Platform changes, when new providers or features are introduced, or when law requires it.
- The Last Updated date at the top always reflects the most recent edit.
- Material changes take effect on the stated Effective Date, and, once Accounts exist, will be announced at least 14 days in advance.
- Changes that expand what we collect, or that introduce server-side storage of Learning Data, are treated as material.
- Previous versions are recorded in the Revision History below and retained internally for reference.
Continuing to use the Platform after a change takes effect means the updated Policy applies to you.
25. Contact Information
Questions, requests, or concerns about privacy:
Email: hello@xmentra.com Platform: https://xmentra.com
We aim to respond to every privacy request within 30 days.
26. Revision History
| Version | Effective Date | Summary of change |
|---|---|---|
| 1.1 | 4 August 2026 | Added Privacy Approach, Data Minimisation, Accounts and Future Data Migration, AI Governance Principles, AI Training Transparency, and Security Incident Response sections. Expanded Security, Third Party Services, Retention, and Your Rights. Future-proofed wording throughout. |
| 1.0 | 4 August 2026 | Initial publication under the Xmentra Legal Architecture v1.0 |