Privacy Policy

Last updated: November 9, 2025

Data Controller

Controller: Nomino Ltd ("Nomino," "we," "our," or "us")
Registered office: 71–75 Shelton Street, London, WC2H 9JQ, United Kingdom
Company registration: 12345678 (England & Wales)
Contact: support@nomino.pro

Introduction

Nomino is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services.

Information We Collect

Information You Provide

  • Account Information: Email address, name, and profile information
  • Learning Data: Language preferences, learning progress, conversation history
  • User Content: Voice recordings for pronunciation practice, chat messages, and learning materials

Information Collected Automatically

  • Usage Data: Features used, session duration, learning patterns
  • Device Information: Device type, operating system, unique device identifiers
  • Analytics: App performance data, crash reports, and usage statistics

How We Use Your Information

We use the information we collect to:

  • Provide and improve our language learning services
  • Personalize your learning experience
  • Process AI-powered conversations and feedback
  • Send you important updates and notifications
  • Analyze usage patterns to enhance our features
  • Process subscription payments through RevenueCat
  • Comply with legal obligations

Lawful Bases for Processing

We process your data under the following lawful bases:

  • App functionality (account, lessons, conversations): Art. 6(1)(b) – contract performance
  • Payments & subscriptions (via RevenueCat/Apple): Art. 6(1)(b) – contract; Art. 6(1)(c) – legal obligations (tax/records)
  • Analytics & crash diagnostics (Firebase, Sentry): Art. 6(1)(f) – legitimate interests (product improvement). You can opt out in-app at: Profile → Settings → Privacy → Analytics
  • Marketing emails (tips, offers): Art. 6(1)(a) – consent. You can withdraw any time
  • AI processing (OpenAI, Gemini) for conversation generation/feedback: Art. 6(1)(b) – contract; Art. 6(1)(f) – legitimate interests (service delivery & quality)
  • Voice synthesis (Cartesia, ElevenLabs) and real-time voice (LiveKit): Art. 6(1)(b) – contract

Third-Party Services & Sub-Processors

We use vetted providers to run Nomino. The current list (purposes, regions, data types, retention) is maintained at nomino.pro/subprocessors. Last updated: 9 November 2025.

Key sub-processors include:

  • OpenAI & Google Gemini: AI conversation processing
  • Cartesia & ElevenLabs: Voice synthesis
  • LiveKit: Real-time voice communication
  • Firebase (Google): Authentication, database, and analytics
  • RevenueCat: Subscription management
  • Sentry: Crash reporting

International Data Transfers

Primary Hosting Regions: Core application data is hosted in the EU region (europe-west) on Firebase/Firestore. Some processors may operate in the US.

When we transfer data outside the UK/EEA (e.g., to the US), we use the UK Addendum to the EU SCCs or the UK IDTA, plus supplementary measures where needed. Copies of the relevant transfer mechanism can be requested at support@nomino.pro.

Security

We use industry-standard security measures to protect your data:

  • Encryption in transit: All data transmitted between your device and our servers uses HTTPS/TLS
  • Encryption at rest: Sensitive data is stored encrypted in Firebase Firestore
  • Access controls: Role-based access control and least-privilege access to production data
  • Multi-factor authentication: MFA required for admin tools
  • Audit logging: Access and changes to user data are logged
  • Periodic reviews: Regular security audits and updates
  • Breach notification: If we become aware of a data breach that risks your rights and freedoms, we will notify you and regulators in line with legal requirements

Note: We do not use end-to-end device-level encryption. Conversations are encrypted in transit and at rest on our servers.

Data Retention

We retain your data for the following periods:

  • Account & profile: While the account is active; deleted within 30 days after account deletion
  • Learning progress: While the account is active; purged within 30 days after deletion
  • Conversation text: Visible to you while active; purged within 30 days after deletion
  • Voice recordings: Not stored unless you save them; saved items delete with account
  • Payments & invoices: 6 years (legal/tax obligations)
  • Crash & analytics: 24 months (aggregated thereafter)
  • Server access logs: 90 days (for security and fraud detection)

Backups: Deleted data may persist in encrypted backups for up to 30 additional days before being purged on the backup cycle.

Automated Decision-Making & Profiling

We personalise lessons, assess pronunciation (e.g., scoring 0–100), and recommend content automatically. These processes affect lesson ordering and feedback only and do not produce legal or similarly significant effects. You may object to profiling or request a manual review by emailing support@nomino.pro.

Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Export your data
  • Object to certain processing (including profiling)
  • Opt-out of marketing communications
  • Withdraw consent at any time

Response time: We respond to data subject requests within one month (we may extend by up to two months for complex requests).

Children's Privacy

Nomino is not directed to users under 13 and does not knowingly collect their data. We design our service with the UK Age-Appropriate Design Code in mind and do not use behavioural advertising or sell personal data. If we learn that a user is under 13, we will disable the account and delete associated personal data after reasonable verification. If you believe we have collected information from a child under 13, please contact us immediately at support@nomino.pro.

Marketing

Transactional vs Marketing: We send transactional emails (e.g., receipts, service notices) as part of our contract with you and they do not require consent. Marketing emails (tips, offers) are sent only with your consent. You can unsubscribe via any marketing email or in-app at Profile → Settings → Notifications.

Complaints

You can complain to the UK Information Commissioner's Office (ICO): ico.org.uk. We'd appreciate the chance to resolve concerns first at support@nomino.pro.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at support@nomino.pro or visit our Support Page.

Document History

  • 9 November 2025: Initial publication