Edmoro — Privacy Policy

Last updated: August 29, 2026
Effective date: August 29, 2026

Who we are

Edmoro (“we”, “us”, “our”) is published by Mohamed Ali, an individual (sole developer) responsible for the Edmoro mobile application (the “App”), an English-learning app.
For the purposes of the EU GDPR and UK GDPR, Mohamed Ali is the data controller.
Contact: support@edmoro.com
Postal address: Unit 158815, PO Box 6945, London, W1A 6US

Quick summary

  • No ads, no advertising identifiers, and no personalization for advertising.
  • No accounts or sign-in. You never give us an email address or password to use the App.
  • We collect and process only the information needed to provide the App’s features, process subscriptions, provide support, and keep the service secure and reliable.
  • Your learning progress is stored on your device and, if you use iCloud, synced to your own private iCloud account — we cannot read it.
  • Your profile photo never leaves your device.
  • We don’t sell your personal data and we don’t track you across other apps or websites.
  • We use trusted providers: Apple (purchases, iCloud sync), Amazon Web Services (AWS) (hosting, text recognition, media delivery, diagnostics), OpenAI (lesson text, speech-to-text, spoken audio), Google (illustrations, and YouTube video playback), and RevenueCat (subscription management).
  • We do not request App Tracking Transparency (ATT) because we don’t track you across apps or sites.
  • Identifier we use: an App Account Token — a randomly generated pseudonymous identifier that does not directly identify you, stored on your device (and in your iCloud keychain, so it survives a new phone). It is how our servers apply fair-use limits and how your subscription is recognised. It is never used for advertising.

Scope

This Policy explains what we collect, how we use it, how it’s shared, your choices and rights, and how to contact us. If this Policy changes, we’ll update the date above and, for material changes, notify you in-app or by other reasonable means.

Definition of “Personal Data”

“Personal Data” means information that identifies or can reasonably be linked to an identifiable person, including the categories described in this Policy. This can include pseudonymous identifiers such as the App Account Token and Apple’s originalTransactionId when used to associate purchases or usage limits with you.

What we collect and why

We collect the minimum necessary data to generate your lessons, fulfill purchases, and keep our service secure and reliable. Requests from the App to our API carry your App Account Token so that fair-use limits and subscription status can be applied; they carry no name, email address, advertising identifier, or precise location.

Your App Account Token is not sent with your content. The token is used by our own servers to apply your subscription and usage limits, and it is shared with our subscription provider as your subscriber id (see “Purchases & subscriptions” below). It is not forwarded to the providers that process your content: our calls to OpenAI, Google and Amazon Textract carry only the material to be processed (the text, the image, or the audio clip) together with model settings — no App Account Token, no device identifier, and no account identity. Those providers therefore receive the content without any identifier from us linking it to you, although they receive the request itself and apply their own security and abuse-prevention measures.

1) Learning content requests (our API on AWS)

Data: The word or short phrase you are learning or tap on, the language names involved (the language you are learning and the language you want it explained in), your self-selected English level (Beginner / Intermediate / Advanced), any optional interests you chose, and identifiers for the item you opened (for example a story number, a scenario id, a video id, a news week, a podcast episode id).

Why: Our servers build the prompt and generate the example sentences, definitions, word families, translations, stories and other lesson content, then cache the result so it can be reused. This is essential to core functionality — the App requires an internet connection to produce new content.

Source: Sent by the App as you learn. Generated content is cached on our servers by the content itself (for example, by the word), not by you, so the same lesson can be served to every learner without re-generating it.

2) Text you type or select for translation

Data: Text you type into the Translate tab, text you photograph and translate, and text you select inside the App to have translated or explained.

Why: To translate it and show you the result.

Storage: Translations of your own text are cached on our servers for up to 30 days so a repeat request is instant and free. An entry is stored under a one-way fingerprint of the text and carries no App Account Token and no account identity, so we do not maintain an association between a translation and the person who requested it — which also means we cannot retrieve “your” translations on request. We do not claim this makes the stored text anonymous: a fingerprint of a short, predictable phrase can in principle be matched by testing candidate inputs, and depending on what you typed the text itself may still constitute personal information. That is why these entries expire automatically rather than being retained. Translations of our own app content (stories, news, podcast and lesson text) are kept indefinitely, because that text is written by us, is identical for every learner, and contains nothing personal.

3) Photos of writing and printed pages (Amazon Textract)

Data: The photo you take (or pick from your library) when you write a word on paper to prove you learned it, or when you photograph a page to translate it. The image is cropped on your device and sent to our API, which passes it to Amazon Textract for text recognition.

Why: To read the words in the picture and check whether you wrote the word correctly, or to translate the text on the page.

Retention: Photos are processed to extract text and are not stored by us afterwards. Please avoid photographing pages containing information you do not want processed — only photograph what you want read.

4) Voice and speech

On device (speaking practice): When you say a word to pass the speaking challenge, recognition is performed by Apple’s speech recognition on your device. Depending on your device and settings, Apple may process some of that audio on Apple’s servers under Apple’s own privacy policy. We do not receive or store the audio, only whether you matched the word.

Sent to us (Edmoro Pro voice features): For subscribers, a short recording you make in the Translate tab, or a spoken reply in the “Start a conversation” activity, is uploaded to our API and passed to OpenAI’s speech-to-text service to be turned into text.

Why: To transcribe what you said so it can be translated or used as your turn in the conversation.

Not used to identify you: Voice audio is used only to work out the words you said. We do not use it to recognise or verify who you are, and we do not create or store a voiceprint.

Retention: Audio clips are processed and not stored by us. If you are not a subscriber, or you are offline, the App falls back to on-device recognition and no audio is uploaded.

5) Conversation practice

Data: The messages you type or speak in the role-play activity, plus the conversation so far, are sent to our API and to OpenAI on each turn (our servers do not store the conversation, so the App re-sends it).

Why: To generate the character’s reply and a gentle language tip.

Identifier: The transcript is sent to OpenAI without your App Account Token or any other identifier from us.

Storage: The finished chat is saved on your device (and in your own iCloud, if enabled) so you can re-read it. It is not stored on our servers.

6) Spoken audio and illustrations

Data: Text to be read aloud (a word, an example sentence, or text you asked to hear) is sent to our API and to OpenAI’s text-to-speech service; the word and example sentence being illustrated are sent to Google’s Gemini image service.

Identifier: The text or sentence is sent to OpenAI and Google without your App Account Token or any other identifier from us.

Why: To produce the audio you hear and the picture on the card. Both are cached on our servers by the content itself so most learners receive an existing file rather than a new generation. Audio generated from free text you typed is never added to that shared cache.

7) Video playback (YouTube)

Data: The “Watch a video” activity plays curated clips using YouTube’s official embedded player and loads thumbnails from YouTube. When it does, YouTube/Google receives your IP address and standard request data and may set cookies or similar storage in the player, under Google’s Privacy Policy. We send only our own clip identifiers to our API — never your identity — and we do not receive your YouTube account information.

Why: To play the video and show the synced transcript. This activity uses YouTube API Services; see the Google Privacy Policy.

8) Purchases & subscriptions (Apple StoreKit and RevenueCat)

Data:

  • App Account Token: the value described above, also used as your subscriber id with RevenueCat.
  • originalTransactionId (OTID) and other App Store transaction data Apple provides for the purchase or subscription.
  • Product identifiers, subscription status and expiry, and App Store country/storefront.

Why: To process purchases, verify and restore your Edmoro Pro entitlement across devices, prevent fraud and abuse, and provide support.

What we do and do not enable in RevenueCat: we configure the RevenueCat SDK with your App Account Token as the subscriber id, and nothing else. We do not enable RevenueCat’s device-identifier collection, so no advertising identifier is gathered for attribution, and we do not set subscriber attributes such as your name, email address, or phone number. Beyond that, the SDK sends its own standard technical information (such as device model, operating system, app and SDK version, and country), and your IP address is visible to it as it is to any network service, in order to validate and restore purchases. That baseline is determined by RevenueCat rather than configured by us, and may change with SDK versions; see RevenueCat’s privacy documentation at revenuecat.com/privacy for the current details.

Source: The App Account Token is generated on your device; transaction details come from Apple. RevenueCat notifies our servers when your subscription starts, renews or ends so the App can unlock Pro features.

Payment information: All payment details are processed by Apple. We do not receive or store your card numbers or billing details.

Not for tracking: We do not use these identifiers for advertising, cross-app tracking, or profiling.

9) Diagnostics & service logs (AWS CloudWatch)

Data: Error logs, performance metrics, timestamps, request counts, and standard server and API access logs. These record your IP address, the time and type of request, the result, and a shortened form of your App Account Token (its first characters only, never the whole value), so that per-user fair-use limits can be enforced, faults diagnosed, and abuse investigated. We do not log the content you send — the text, photos, and audio described above do not appear in our logs, only counts such as how many characters were processed.

Why: To fix bugs, monitor stability, enforce fair-use limits, protect the service from abuse, and control cost.

Source: Generated automatically by our servers when you use the App.

10) Your learning data (on your device and your iCloud)

Data: Your chosen name or nickname, avatar, language and level, learned and saved words, streak, XP and badges, daily progress, saved stories, read articles, watched clips, finished activities, chat history, and app settings.

Why: To save your progress and run the App.

Storage: Stored on your device and, if you are signed into iCloud, synced through Apple’s CloudKit to your own private iCloud database so your progress follows you to a new phone. That data is held in your Apple account under Apple’s privacy policy — we cannot access it, and it is not sent to our servers. You can turn this off by disabling iCloud for Edmoro in your device settings.

11) Your profile photo (device only)

Data: If you choose a photo instead of an emoji character, it is cropped on your device and saved as a small image inside the App’s own storage.

Why: To show your face in the App.

Storage: It stays on your device. It is deliberately not part of the synced database and cannot be reached by any part of the App that talks to our servers — it is never uploaded anywhere. Choosing a different photo, picking an emoji, or removing the photo deletes the file it replaces.

12) Downloaded lesson content

Data: Lesson text, images and audio the App downloads ahead of time so activities open instantly and work offline. Media files are delivered over our content delivery network (Amazon CloudFront, media.edmoro.com) using short-lived signed links.

Storage: Cached on your device within a storage limit and cleared automatically as it fills; you can clear it at any time in Settings → Storage.

13) Reminders and the home-screen widget

Data: If you turn reminders on and allow notifications, the App schedules local notifications on your device, chosen from your own progress. The optional widget reads a small summary file that the App writes on your device.

Why: To remind you to practise and to show your streak and today’s word.

Note: These are entirely on-device. There is no push token, no server-sent notification, and nothing about your reminders leaves your phone. You can turn them off in the App or in device settings at any time.

14) Support form & emails

  • Data: Your name (if provided), email address, subject, and message content.
    For security/anti-abuse, our servers may log IP address, user-agent, timestamps, and basic request metadata.
  • Why: To respond to your request, provide support, and protect our service from spam or abuse (e.g., rate-limiting).
  • Source: Submitted by you via our support page at https://edmoro.com/support/support.html or by emailing support@edmoro.com.
  • Providers: We use Amazon Web Services (AWS) to host the contact form endpoint and Amazon Simple Email Service (SES) to deliver support emails. AWS acts as our processor.

For our app users:

We do not collect: your phone number, contacts, calendar, precise GPS location, health data, advertising identifiers (IDFA), or other sensitive categories. We do not collect your name or email address in the App itself — the name and avatar you choose stay on your device and in your own iCloud — except where you voluntarily provide them in a support request.

We do not use: third-party analytics SDKs, advertising SDKs, or social logins.

How we use your data

  • Deliver core features: generating lesson content, translations, spoken audio, illustrations, text recognition from photos, speech-to-text, and conversation practice.
  • Operate in-app purchases: verify, link and restore your Edmoro Pro entitlement using the App Account Token and Apple transaction data; prevent abuse and fraud.
  • Apply fair-use limits so that generation costs stay sustainable for everyone.
  • Diagnose crashes, fix bugs, and maintain security.
  • Provide customer support.

Notifications: If you opt in, we may send non-personalized local practice reminders. You can turn these off anytime in the App or in device settings.

Content generation: Lesson content is produced by AI models operated by OpenAI and Google on our instructions. Our providers do not use the content sent through our API to train their models. AI-generated content can occasionally be inaccurate; it is educational material, not professional advice.

No automated decisions with legal effects: We do not engage in automated decision-making that produces legal or similarly significant effects about you.

Sharing & service providers

We do not sell your personal data. We share data only with essential service providers under contracts that limit their use:

  • Apple (App Store / StoreKit): purchase processing, entitlements, and receipt validation. Apple acts as an independent controller.
  • Apple (iCloud / CloudKit): stores your learning progress in your own private iCloud database. We have no access to it.
  • Amazon Web Services (AWS): hosting our backend API, storing generated lesson content, text recognition (Amazon Textract), media delivery (Amazon CloudFront), support email (Amazon SES), and diagnostics/logging (Amazon CloudWatch). AWS acts as our processor.
  • OpenAI: generating lesson text, translations and conversation replies; converting text to spoken audio; and, for subscribers, converting your voice recordings to text. OpenAI acts as our processor.
  • Google: generating illustrations (Gemini) as our processor; and, separately, YouTube video playback and thumbnails, where Google acts as an independent controller under its own privacy policy.
  • RevenueCat: managing and validating subscriptions and entitlements. RevenueCat acts as our processor.

Pre-recorded audio: Some voices in the App (for example podcast narration and the guide character) are recorded in advance by us using third-party voice technology. That happens before the App ships and involves no user data.

Legal disclosures: We may disclose information to comply with law or legal process; to enforce our terms and policies; or to protect the rights, property, or safety of users or the public.

Business transfers: If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction in compliance with applicable law. We will continue to protect the information and will notify you of any material change where required.

International transfers

Our providers operate globally (including the United States). We rely on appropriate transfer safeguards—where applicable, participation in the EU-U.S. Data Privacy Framework (and UK Extension) and/or Standard Contractual Clauses (SCCs) provided by our vendors—and implement measures to protect your information wherever it is processed.

Data retention

Photos and voice recordings: Processed to extract text and not retained by us afterwards.

Conversation messages: Not stored on our servers; the transcript lives on your device.

Generated lesson content (server cache): Kept indefinitely where it is stored as reusable, shared content — keyed by the content itself and not linked to your App Account Token or any account identity — so the same lesson can be served to every learner. This includes a word or short phrase you look up or tap, which is stored under that word rather than under you. Longer text you submit for translation is not stored this way and follows the 30-day rule above.

Translations of your own text: Kept for up to 30 days under a one-way fingerprint of the text, with no App Account Token or account identity attached, then automatically deleted. See section 2 above for what that does and does not mean.

Purchases & entitlements: We keep the App Account Token ↔ entitlement mapping and related transaction records for as long as your subscription is active, and then for up to 24 months after your subscription ends or, if you have no subscription, after your last purchase activity. We delete them at the end of that period unless a longer period is required by law (for example, tax and accounting records, which we keep for the period our tax authority requires) or the records are needed for an unresolved dispute or fraud investigation.

Usage counters: Fair-use counters keyed to your App Account Token expire automatically on a daily or weekly cycle.

Diagnostics, API access and server logs (CloudWatch): Retained for up to 90 days, then automatically deleted. This covers the IP-address-bearing API access logs as well as our application logs. These logs record a shortened form of your App Account Token — its first characters only, never the whole value — so that per-user usage limits can be enforced and abuse investigated; that period is long enough to investigate an incident and short enough that we are not holding activity records indefinitely. We may retain a specific log entry beyond that period only where needed for an active security or legal matter.

On-device and iCloud learning data: Remains until you delete it in the App, disable iCloud sync, or uninstall the App.

Support emails: Retained for up to 24 months after your request is resolved, then deleted. We keep a message longer only where it relates to an unresolved dispute, a legal claim, or a record we are required to keep by law.

Once retention periods expire, data is deleted or irreversibly aggregated. After deletion, rights like access or portability can no longer be exercised for that data.

Your rights

Depending on your location (e.g., EEA, UK, California), you may have rights to access, correct, delete, restrict, object, or export your data, and (where we rely on consent) to withdraw consent.

How to exercise your rights: Email support@edmoro.com. We may request information (e.g., your App Account Token, which you can find in Settings, and/or your Apple transaction id) to verify your identity. We respond within one month where required by law (and may extend by up to two months for complex requests, as permitted). You may also lodge a complaint with a data-protection authority where you live or work.

Data we cannot link to you: Most of what we hold on our servers — generated lesson content, cached translations of your text — carries no user identifier at all, so we are unable to locate it as “yours”. See “Identification limits” below.

EEA/UK (GDPR/UK GDPR) legal bases

  • Performance of a contract: to deliver the App and the features you ask for — generating your lesson content, translating text you submit, reading the text in a photo you take, transcribing a recording you make, generating conversation replies, and verifying/restoring your Edmoro Pro entitlement.
  • Legitimate interests: diagnostics, security, fraud prevention, enforcing usage limits, and service improvement (balanced against your rights).
  • Consent: where we genuinely rely on it — principally for sending you notifications, which you opt into and can withdraw at any time.
  • Legal obligation: record-keeping for tax/accounting and responding to lawful requests.

Device permissions are not the same as a legal basis. The iOS prompts for camera, microphone, speech recognition, photo library, and notifications control whether an app may use a capability of your device. They are an access-control mechanism under device-platform and, where applicable, ePrivacy rules — they are not, by themselves, our Article 6 basis for the processing that follows. When you photograph your writing or record a reply, we process that content to deliver the feature you asked for, which we base on performance of a contract; our diagnostics and abuse-prevention rest on legitimate interests. Refusing a permission, or withdrawing it later in device settings, disables the feature that needs it and stops further processing, but does not affect the lawfulness of processing already carried out.

Identification limits (GDPR Art. 11): We generally do not maintain content or logs in a manner that enables us to identify you without additional information. If we cannot identify you from the data we hold, we may be unable to honor certain requests unless you provide additional details that allow identification. Where we can identify you, we will act on your request.

EEA/UK representative: For data-protection queries from individuals in the EEA or UK (including those addressed to the Article 27 representative), please contact support@edmoro.com. We will publish the representative’s contact details here promptly once appointed.

California residents (CPRA)

No sale/share: We do not “sell” or “share” personal information for cross-context behavioral advertising.

Rights: Right to know, delete, and correct; we do not discriminate for exercising rights.

Authorized agents & verification: You may designate an authorized agent to make requests on your behalf. We will verify your or your agent’s identity and authority (e.g., by requesting matching information or written authorization) before fulfilling a request.

Do Not Track / GPC: We do not sell/share data; where Global Privacy Control signals apply, there is no sale/share to opt out of.

“Shine the Light”: We do not disclose personal information to third parties for their direct marketing. California Civil Code §1798.83 permits requests about such disclosures. Contact support@edmoro.com.

Children

The App is a general-audience English-learning app and is not directed to children under 16. We do not knowingly collect personal data from children below the applicable age. If you believe a child has provided data without parental consent, contact us and we will take steps to delete it.

Security

We use reasonable administrative, technical, and physical safeguards (e.g., encryption in transit and at rest, access controls, least-privilege access, short-lived signed media links, monitoring). Your App Account Token is stored in the device keychain. No method of transmission or storage is 100% secure, but we strive to protect your information. If we are legally required to notify you of a data breach, we will do so without undue delay.

Data deletion & choices

Reset your learning data: Settings → Reset erases your profile, progress, streak, saved words and history. Because your data is synced through your own iCloud account, this deletes it on every device signed into that Apple ID.

Downloaded content: Settings → Storage clears cached lesson text, images and audio at any time.

iCloud sync: Turn off iCloud for Edmoro in your device settings to keep your progress on one device only; delete Edmoro’s iCloud data from iOS Settings → your name → iCloud.

Uninstalling: Deleting the App removes on-device data, including your profile photo and downloaded content.

Permissions: Camera, microphone, speech recognition, photo library, and notification access can each be revoked at any time in device settings. Revoking one disables only the feature that needs it.

Purchases: Manage your subscription via your Apple account. To request deletion of our purchase and entitlement records, email support@edmoro.com (note: we may retain certain information as required by law for tax or anti-fraud purposes).

Diagnostics: Diagnostic/server logs are essential for security, reliability and fair use, and are deleted according to our retention policy; opting out of essential logging is not possible.

Reminders: You can turn these off in the App or in your device settings at any time.

Third-party links

The App may link to third-party sites or services not controlled by us, including news source articles and YouTube. Their privacy practices govern those services.

Terms reference

Your use of the App may also be governed by our Terms of Service. If a conflict arises, the Terms may control to the extent permitted by law.

Changes to this Policy

We may update this Policy from time to time. We’ll change the “Last updated” date above and, if changes are material, we’ll notify you in-app or by other reasonable means.

Contact us

Publisher & Data Controller: Mohamed Ali (individual/sole developer)
Email: support@edmoro.com
Postal address: Unit 158815, PO Box 6945, London, W1A 6US