Jengolang, doing business as Jengo, operates the Jengo application and jengolang.com.
Jengo does not sell personal information, show targeted advertising, or track people across other companies’ apps and websites. Questions and privacy requests can be sent to [email protected].
1. Information Jengo processes
Account and authentication information
When you create or use an account, Jengo processes your username, email address, account identifier, authentication status, and session information. Supabase handles credentials for the primary sign-in flow. A legacy Jengo sign-in flow may process a password, but Jengo stores only a salted password hash, never a readable password. Password-reset tokens are stored as hashes and expire after one hour.
Study and user content
Jengo stores the information needed to provide and synchronize study features, including:
- languages, preferences, timezone, and study settings;
- flashcard decks, cards, notes, vocabulary, review history, scheduling state, and progress;
- reading interests, stories, books, chapters, encounters, and related progress; and
- text you submit for generation, explanations, training feedback, text-to-speech, or other requested features.
AI inputs, outputs, and usage records
When an AI feature is used, Jengo records the complete system prompt, user prompt, generated output, model, language or level, token count, latency, and related feature metadata. These records are linked to the Jengo account and used to operate, troubleshoot, evaluate, and improve generation quality and performance.
Free-form study and AI fields can contain information you choose to enter. Jengo does not ask for sensitive personal information. Please do not include health, financial, government-identification, or other sensitive information in prompts, cards, notes, text-to-speech requests, or support messages.
Technical and usage information
Jengo and its infrastructure providers process ordinary request and security information such as IP address, requested route, request time, browser or operating-system characteristics, broad device class, last-active time, errors, and rate-limit events. Approximate region may be inferred from an IP address by infrastructure providers. Jengo does not request precise location, contacts, photos, camera, or microphone access.
Information stored on your device
To support offline use and normal app operation, Jengo stores session state, preferences, recent searches, decks, cards, review events, progress, pending synchronization work, reference data, and cached content in browser or app storage. This may include local storage, IndexedDB, service-worker caches, and native app storage.
Handwriting recognition and local reminders
On iOS, handwritten strokes are processed on the device by Google ML Kit. Jengo does not upload the handwriting strokes or recognition result through that feature. Google’s bundled SDK may process unlinked app or device identifiers, product interaction, performance, and diagnostic information for app functionality and analytics, and downloads recognition models when needed. Jengo does not use that information to track you across apps or websites.
If you enable study reminders, Jengo requests permission to schedule local notifications on your device. Reminder preferences and schedules remain on the device; Jengo does not register a remote push-notification token for this feature.
Support messages
If you contact Jengo, the email address, message, and attachments you choose to send are processed to respond to the request and maintain appropriate support records.
2. How the information is used
Jengo uses information to:
- create and authenticate accounts;
- provide, personalize, synchronize, and restore study features;
- generate requested content, explanations, training feedback, and speech;
- operate offline synchronization and prevent duplicate review events;
- provide support and password resets;
- protect the service, enforce rate limits, diagnose failures, and prevent abuse;
- evaluate feature usage, generation quality, reliability, cost, and performance; and
- comply with legal obligations and protect legal rights.
3. Service providers and disclosures
Jengo shares information only as needed to provide a requested feature, operate the service, meet legal obligations, or complete a business transfer. Jengo does not sell personal information or share it for cross-context behavioral advertising.
- Supabase provides authentication and processes account identifiers, email, username metadata, credentials, sessions, and authentication events.
- Railway hosts the application, PostgreSQL database, files, caches, and operational logs.
- Cloudflare provides network delivery and security and processes request metadata such as IP addresses and routes.
- Resend delivers transactional email and processes the recipient, subject, message content, delivery logs, and password-reset link.
- OpenRouter and routed model providers, which may include Anthropic and DeepSeek, process the prompts and related context required for an AI request. OpenAI may also process requests for configured AI or speech features.
- Microsoft Azure or OpenAI, depending on configuration, processes text submitted for server-generated speech.
- Google provides ML Kit model delivery and SDK diagnostics for on-device handwriting recognition, and provides hosted fonts to the web application.
- Jisho and KanjiAPI may receive a searched word or character when Jengo needs an online dictionary fallback. Requests are made by Jengo’s server rather than directly from the user’s device.
Providers may process information in countries other than your own. Jengo remains responsible for information processed on its behalf and requires providers to handle it consistently with this notice, their contractual obligations, and applicable law.
4. AI and speech-provider choices
The provider used for a feature can vary as Jengo changes models or service configuration. Providers may have their own retention practices. Jengo does not promise that third-party providers never retain or use request data unless that guarantee is explicitly part of the active provider configuration. Avoid submitting sensitive or confidential information.
Generated speech may be cached using a one-way hash of the provider, language, voice, and submitted text. Cached audio is not labeled with a user identifier and may remain after an account is deleted.
5. Retention and deletion
- Account, study, and account-linked AI records are kept while the Jengo profile remains active, unless they are deleted earlier or must be retained for legal or security reasons.
- Password-reset links expire after one hour. Authentication sessions and operational logs follow their applicable expiry or provider retention settings.
- Support messages are retained while needed to respond, maintain support history, resolve disputes, or meet legal obligations.
- De-identified shared caches, including generated speech, may remain until they are replaced or cleared.
- Provider logs and residual backup copies may remain until the provider’s normal retention or backup rotation completes.
You can delete the data associated with your active Jengo application profile from Settings > Profile > Delete Account. This deletes the linked records in Jengo’s active application database, including study data and account-linked AI logs.
The current deletion flow does not delete the separate Supabase authentication identity or information stored locally on your device. To request deletion of the authentication record, email [email protected]. To remove device-local copies, clear Jengo’s browser data or delete the app after deleting the profile.
6. Security
Jengo uses reasonable technical and organizational measures intended to protect personal information, including encrypted network transport, access controls, and hashed legacy passwords and reset tokens. No storage or transmission system can be guaranteed completely secure.
7. Children
Jengo is a general-audience language-learning service and is not directed to children under 13. Jengo does not knowingly collect personal information from a child under 13. If you believe a child under 13 has provided personal information, contact us so it can be deleted. Where local law requires parental consent at a higher age, the service should be used only with the required parent or guardian involvement.
8. Privacy rights and choices
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or obtain a portable copy of personal information, or to withdraw consent. Jengo does not make decisions that produce legal or similarly significant effects solely through automated processing.
For users in the European Economic Area, United Kingdom, or similar jurisdictions, Jengo processes account and study information to provide the requested service, processes security and service-improvement information for legitimate interests, and relies on consent where required. You may also complain to your local data-protection authority.
Because Jengo does not sell personal information or share it for targeted advertising, there is no sale or targeted-advertising opt-out to apply. Jengo does not claim to detect browser Global Privacy Control signals.
To exercise a privacy right, request authentication-record deletion, or ask a question, email [email protected]. Jengo may need to verify your identity before completing a request.
9. Changes to this policy
Jengo may update this policy as the service, providers, or legal requirements change. The date at the top identifies the current version. Material changes will be communicated through the service when appropriate.