Privacy Policy
Last updated: 12 September 2026
We prioritize protecting your personal data. This privacy statement outlines the personal data that Nora languages AB, based in Stockholm, Sweden (hereinafter referred to as "we" or "Nora"), processes from you. "Personal data" refers to any information related to an identified or identifiable individual. In this document, you will learn about the personal data we collect from you when you visit our website, web app, iOS app, or Android app, how we use it for language practice and other purposes, and your data protection rights.
I. Responsible Entity
The entity responsible for the data processing described in this privacy policy is:
Nora languages AB
LÖVÄNGSGATAN 12 LGH 1001,
115 44 Stockholm, Sweden
Org.no: 559499-2736
E-mail: contact@hellonora.ai
For any concerns or questions about data protection or this privacy policy, please contact us at any time.
II. Collection, Processing, and Use of Personal Data
1. Affected Persons
Nora collects and processes personal data from visitors to the website hellonora.ai, users of the app, other Nora channels, and newsletter subscribers. Personal data is typically collected directly from the data subjects, such as during a conversation using our app or when creating a user account ("Nora account") or subscribing to our newsletter.
Each time the app or our website hellonora.ai is accessed, our system automatically collects information transmitted by your device's internet browser. This includes:
- Date and time of access
- Browser type/version
- Operating system
- URL of the previously visited website
- Domain accessed
- Search terms used
- IP address
This data is collected for technical reasons and stored in server log files for a short period until automated deletion. This ensures a functional, stable, and secure website or app and the services provided. We use this data for error analysis, security, logging access, and improving our offerings, which aligns with our legitimate interest.
2. Data Collected and Purposes of Data Processing
2.1 Conversation Service
Regardless of whether you use our paid or free service, data is collected during and in connection with our conversation service as described below.
You choose what to say or type. We capture microphone audio when you use speaking features and process it for speech recognition, transcription, and AI replies. Depending on the feature, audio goes to your device's speech recognition service or to the AI and speech providers in section III. Conversation text, relevant conversation history, and learning preferences are sent to model providers to generate replies. Live calls stream audio through LiveKit to realtime models.
For ordinary speech input, the mobile app does not save a local recording of your voice. Our speech API returns generated audio for playback without saving an audio archive in Nora's database. The mobile app caches generated speech clips on your device for replay. These files can remain after a session until the app or operating system clears the cache; there is no fixed time limit. Removing the app's local data removes those cached files.
LiveKit can also retain call audio, transcripts, and diagnostics when cloud session recording is enabled. Its published retention window for this session data is 30 days. Operational logs can contain conversation text. We therefore do not promise that all voice data disappears when a session ends. Provider retention and any legal or security exceptions are explained in section III.
We store conversation transcripts, typed messages, learning progress, and learning memories linked to your account to provide conversation history and personalized practice. We keep this account content while you have an account, unless you delete it sooner where the app provides that option. Account deletion removes it from our active account database. To request deletion, use the account-deletion page or email help@hellonora.ai. Deleting your account does not automatically erase all provider logs, backups, or records that must be kept by law. Contact us to exercise your deletion rights for those records too.
Additionally, the following data is stored for each conversation:
- Conversation length
- Selected conversation language
- Selected conversation topic
- Voluntary user feedback on the conversation
This data is processed to improve our products' functionality and ensure relevant responses. It is retained with your account and removed from our active account database upon account deletion, subject to the retention limits described above. Users of our Conversation Service are assigned a randomly generated user ID to recognize you in future visits. This data helps us improve our conversation service and prevent fraud. For data stored in connection with our paid service and a Nora account, see section II.2.2.
2.2 Creating a Nora Account
You can create a free Nora account at any time. Registration for a Nora account is required to conclude a membership and use the conversation service under Nora's applicable GTC (see section II.2.1).
You can create a Nora account by providing a username, email address, and password (email login) or with Sign in with Apple or Sign in with Google on web or mobile. The sign-in provider sends us an account identifier and the email address and name it makes available. Apple may supply a private relay email address if you choose to hide your email. You can also add a profile picture and learning preferences. Regardless of the registration method, we process your data for account creation, administration, membership management, and access control (including fraud prevention). Additional details and information (such as language preference) are requested to provide our conversation service.
We also process additional (usage) data relevant for the provision and billing of our conversation service, such as membership number, membership start time, successful payment processing, and number of conversations conducted. This data processing and storage are necessary for contract fulfillment.
We store this data for the duration of the contract period (membership) and any legally required retention periods. Your account will remain active after membership cancellation unless you request deletion. If you have created a Nora account but do not subscribe to a membership, your account will remain until you request its deletion. One Nora account works across web, iOS, and Android.
2.3 Mobile Apps
The iOS and Android apps process the account and conversation data described above, plus:
- Microphone and speech recognition data: audio and transcripts for speaking practice. We request the microphone permission and, where needed, speech recognition permission. You can change these in your device settings. Without them, the affected speaking features will not work.
- Push notification tokens: if you opt in, we store an Expo push token linked to your account to send practice reminders. You can turn notifications off in your device settings. Account deletion removes your stored push tokens.
- Device and attribution identifiers: AppsFlyer receives install and campaign information, device and app details, and identifiers used to measure which marketing brought you to Nora. IP addresses may be used to infer approximate location for attribution and service routing; this is not GPS location. Android also uses Google Play Install Referrer. Advertising identifiers are subject to your device's tracking and advertising choices.
- Crash reports and diagnostics: Sentry receives error reports, device and app details, and your user ID and email when signed in, so we can investigate problems.
On iOS, the App Tracking Transparency prompt says: "This lets Nora know which recommendations bring learners like you to the app. It never affects your experience or what you pay."
Choosing Allow permits access to the advertising identifier and tracking for advertising measurement across companies' apps and websites. Choosing Ask App Not to Track denies that permission and access to the iOS advertising identifier. AppsFlyer still runs after either choice, so denying tracking does not stop all install measurement, app analytics, or crash reporting. Privacy-preserving attribution, such as Apple's aggregated install reports, can still be used. You can change your choice in iOS Settings. On Android, you can reset or delete your advertising ID in device settings; Install Referrer campaign information is separate from that ID.
Apple and Google also collect data when you download the app, use their platform services, or make a purchase. They handle that data under Apple's Privacy Policy and Google's Privacy Policy.
2.4 Children and Age Requirements
Nora is not directed to children and has no child-directed features. The age requirements in section 3.3 of our Terms of Service apply: users must be at least 18, or at least 14 with written consent from their legal representative. An app store content rating, including Apple's 4+ rating, does not change these account requirements.
III. Data Disclosure and Transfer Abroad
We use the providers below to run Nora. Providers acting as our processors are bound by data processing terms. Stores, sign-in providers, payment services, and advertising networks may also act independently for their own purposes under their privacy policies. We do not sell personal data.
Data may be processed inside or outside the EU/EEA. The locations below distinguish configured service regions from services whose processing locations depend on provider settings and subprocessors. An EU hosting region does not mean that every support, diagnostic, or subprocessor operation takes place in the EU. For transfers that require safeguards, we use applicable adequacy decisions or contractual safeguards such as the EU Standard Contractual Clauses. You can ask us for information about these safeguards at help@hellonora.ai.
1. Hosting and Database
- Supabase: account authentication, database, and file storage, including profiles and conversation history. Our primary database is in the EU. Regional read-replica routing is also supported; the precise deployment and replica locations depend on our hosting configuration.
- Google Cloud Run: hosts our API and processes requests and operational logs. Our infrastructure configuration includes Belgium (
europe-west1), Iowa, USA (us-central1), and Tokyo, Japan (asia-northeast1). - Redis: caches data and supports temporary application state and message delivery. Our regional infrastructure includes Belgium, the USA, and Japan; production database locations depend on the configured Redis services.
2. AI and Speech
- OpenAI: processes conversation text and context to generate replies and other learning content. OpenAI realtime models process call audio through LiveKit, including deployments through Microsoft Azure. Direct API processing is not restricted to an EU region by our application configuration; the provider's deployment terms apply.
- Anthropic through Google Cloud Vertex AI: processes conversation text and context for AI replies. Nora uses a global Vertex endpoint, which does not provide an EU-only processing guarantee.
- Google Gemini through Vertex AI: processes conversation text and context for AI replies. Nora's configured region is Belgium (
europe-west1); model-specific processing and retention terms apply. - Microsoft Azure Cognitive Services and Azure OpenAI: speech recognition, speech generation, and realtime AI voice processing. Audio, text, and conversation context are processed in the selected Azure region. Realtime routing includes Sweden (
swedencentral) and the USA (eastus2); speech services use their configured regional endpoints. - Soniox: transcribes streamed speech. Processing location depends on the Soniox endpoint and account configuration; we do not promise EU-only processing.
- LiveKit: transports live audio and text and hosts voice agents in Europe and the USA. It can also process session recordings, transcripts, and diagnostics as described in section II.2.1. Its inference service can use ElevenLabs Scribe for transcription as a default or fallback, and Deepgram Flux when configured. These services receive audio through LiveKit; their processing locations and terms depend on the inference service.
- Apple and Google device speech services: process microphone audio for mobile speech recognition, depending on the device and feature. On-device and remote processing depend on the operating system and service settings; their own privacy terms apply to remote processing and locations.
OpenAI's API terms exclude API content from model training by default unless the customer opts in. They allow retention for abuse monitoring, generally up to 30 days, with exceptions. Google Cloud's terms prohibit training on customer data without permission or instructions. These protections apply to the relevant contracted services, including our Vertex AI processing; they are not a promise of zero retention. Anthropic's processing through Vertex is governed by the applicable Google Cloud and partner-model terms.
Soniox's policy states that customer content is not used for model training and that its realtime API does not retain audio or transcripts after processing. Microsoft's documentation states that realtime speech-to-text and standard text-to-speech do not store the input or output content for those operations. These statements do not cover separate diagnostics or every AI feature. For other services and configurations, the provider's applicable data processing, training, and retention terms apply. LiveKit's session-data terms are separate from those of the AI models it connects to.
3. Payments and Subscriptions
- Stripe Payments Europe Ltd.: processes web card payments and subscriptions, including billing details and purchase history. Based at Block 4, Harcourt Centre, Harcourt Road, Dublin 2, Ireland; data may also be transferred to Stripe, Inc. in the USA. See Stripe's Privacy Policy.
- Apple App Store and Google Play: process mobile purchases, payments, renewals, and refunds under their own terms. They provide purchase and subscription information used to grant access to Nora. Processing may take place globally under their policies; Nora does not receive your full store payment card details.
- RevenueCat: manages mobile subscription status across your Nora account. It processes your app user ID, email, display name, purchase history, and AppsFlyer ID. RevenueCat stores customer data in the USA; its subprocessor terms also apply.
- Sign in with Apple and Sign in with Google: authenticate you and provide the account details described in section II.2.2. Their global services operate under their own privacy policies.
4. Analytics and Attribution
- PostHog: product analytics hosted in the EU, linked to your user ID. Person properties include email, name, plan, learning languages, proficiency, interests, motivation, and profile-picture URL where supplied. Events include screens viewed, feature use, and subscription activity.
- Sentry: crash and error reporting, including user ID, email, device details, and diagnostics. The mobile app uses Sentry's Germany ingestion endpoint; support and subprocessor locations are governed by Sentry's terms.
- AppsFlyer: install attribution, campaign measurement, and subscription conversion reporting using device identifiers, your app user ID, install and campaign data, and purchase events from RevenueCat. AppsFlyer's subprocessor list identifies EU data hosting; other processing and international access depend on its subprocessors and account settings.
- Google Analytics and Google Tag Manager, with Stape server-side hosting: website and web purchase measurement, including account, browser, transaction, campaign, and matching identifiers. Google processing may occur globally; the Stape deployment region depends on the configured service.
- Google Ads, Meta, TikTok, and Reddit: receive attribution and conversion reports for the marketing channel that brought you to Nora. Web purchase reporting to Google Ads, Meta, and Reddit uses a server-side tag manager. These networks process data globally under their own terms. See section V for the information involved and your choices.
5. Communication
- Expo push notification service, Apple Push Notification service, and Google Firebase Cloud Messaging: deliver opt-in practice reminders using push tokens and notification content. Delivery uses global platform infrastructure; exact routing depends on the provider.
- Resend: sends transactional email, such as account and service messages, using your email address and message content. Resend stores customer data in the USA, even when email is sent from another region.
- EngageBay: manages marketing email and customer communication using contact details, subscription status, and email engagement. EngageBay's data processing agreement provides for storage in the USA; its subprocessor terms also apply. Marketing emails include an unsubscribe option.
IV. Cookies and Web Storage Objects
Nora uses cookies and web storage to keep you signed in, remember settings, understand use of the service, and measure marketing. Cookies are small values saved by your browser; web storage also saves data on your device. These technologies are used on the marketing site as well as the web app.
The marketing site saves campaign information and click identifiers in a cross-domain attribution cookie on .hellonora.ai, so the web app can connect a later signup or purchase with the visit. This cookie has a 30-day lifetime and can be updated by a later campaign visit. Captured fields include gclid, gbraid, wbraid, fbclid, rdt_cid, ttclid, UTM campaign fields, and the referring page. The marketing site can also pass campaign information to store links.
You can block or clear cookies and web storage in your browser settings. Blocking essential storage may affect sign-in and other functions. Marketing and analytics storage serves different purposes from essential storage. Where consent is legally required, merely visiting the site or accepting this policy does not provide that consent. To object to processing or withdraw consent, contact help@hellonora.ai; device and browser controls are also available as described here and in section II.2.3.
V. Analytics, Attribution, and Advertising
We use Google Analytics and Google Tag Manager for website and web conversion measurement, with a server-side endpoint hosted through Stape.
We use PostHog to understand which screens and features people use and to improve Nora. This is identified product analytics, not anonymous analytics: signed-in activity is linked to your user ID and account properties listed in section III.4. Sentry helps us identify and fix crashes and errors. These uses support our legitimate interests in improving and securing the service, subject to consent where required by law.
AppsFlyer measures which marketing led to an app install. RevenueCat sends subscription conversion information through the AppsFlyer integration so conversions can be reported to the ad network the learner came from, including Meta, Google, TikTok, or Reddit. This can link your app user ID, install, device, campaign, and purchase information for advertising measurement. On iOS, tracking requires your ATT permission; refusing it does not stop all privacy-preserving attribution. See section II.2.3 for what each choice changes.
For web purchases, we send conversion reports to Google Ads, Meta, and Reddit through a server-side tag manager. Reports include available website click identifiers, campaign details, purchase value and currency, and identifiers used to match the conversion. They can also include hashed email and available billing contact fields, such as name, phone number, and address components, along with your Nora user ID, transaction identifiers, and browser identifiers. Hashing transforms these values for matching; it does not make them anonymous. This web reporting is separate from mobile store purchase reporting.
We do not sell personal data. You can deny or withdraw ATT permission on iOS, reset or delete the advertising ID on Android, block or clear website storage, and unsubscribe from marketing emails. These choices do not prevent the processing needed to operate your account or provide a feature you request. You may also object to direct marketing and ask us to stop related processing at help@hellonora.ai.
Deleting an account does not automatically delete historical analytics, crash reports, or marketing-provider records. Our deletion flow updates marketing contact status and records a deletion event in analytics. You can request deletion of remaining personal data by email under section IX, subject to lawful retention requirements.
VI. Nora Newsletter and Customer Satisfaction Surveys
We use Resend for transactional email and EngageBay for marketing email and customer communication.
If you sign up for our newsletter, you will receive occasional emails about our company, products, services, special offers, and news. This processing is based on your consent, which you can revoke at any time by emailing help@hellonora.ai or using the unsubscribe link in our emails.
We may also invite you to participate in customer satisfaction surveys via email. Participation is voluntary, and responses can be anonymous. Providing your name and/or email address is optional and allows us to contact you for further feedback. You can revoke this consent at any time. Sending and evaluating the survey corresponds to our legitimate interest in improving our products based on customer feedback.
VII. Company Profiles on Social Media
We create and manage company profiles on social media channels like Facebook, LinkedIn, X, Discord, Reddit, Line, YouTube, etc., to present Nora's offerings and communicate with interested parties. If you contact us through these channels and are a member of the respective social network, we may receive data that identifies you. We use personal data disclosed during communication solely for processing contact and communication.
As profile page operators, we may access anonymous statistics on visitor interactions (insights function) through cookies and similar technologies. More detailed information on data processing by these services can be found in the respective social network's privacy policy. The use of company profiles and insights functions is based on our legitimate interest in providing information about our company and improving our presence. If users have consented to data processing on social platforms, processing is based on this consent.
Note that we share responsibility with the social network operators for data processing triggered when visiting our profile pages. However, social networks may also process your data for their purposes, which are not covered in this privacy policy. Data collected about you may be transferred to third countries, particularly the USA. We have no control over these data processing procedures and refer you to the respective service or channel operator's privacy policy.
VIII. Data Security
We implement appropriate administrative and technical safeguards to protect the confidentiality, integrity, and availability of your personal information. We use access controls and encrypted connections between your device and Nora to protect data in transit. Provider security and internal infrastructure settings also form part of these safeguards.
IX. Your Rights
You can delete your Nora account at any time in the app under Profile > Settings > Delete account, or follow our account-deletion instructions. If you cannot sign in, email contact@hellonora.ai from your registered email address with the subject "Account deletion request". You can also email help@hellonora.ai to exercise any of the rights below. We may need to verify your identity before acting on a request. As a Nora user or website visitor, you have specific data subject rights, including the right to information, data correction, deletion, data processing restriction, and objection to data processing. You can revoke your consent to specific data processing at any time with future effect.
In the EU or EEA, data subjects have the right to receive data generated by online services in a structured, commonly used, and machine-readable format for further use and transmission.
You can contact us at any time with a request to this effect at help@hellonora.ai. Please note that some of your rights are not absolute and we reserve the right to limit the rights of data subjects under applicable law and, for example, not to provide certain information under given circumstances.
We use account and conversation data to provide our contract with you; billing records may also be retained to meet legal obligations. Optional push reminders and marketing email rely on your choice to receive them. You can withdraw consent without affecting processing that was lawful before withdrawal.
Account deletion is permanent. It removes account content and push tokens from our active database, deletes the RevenueCat customer, and cancels Stripe subscriptions and deletes the Stripe customer. It does not cancel an App Store or Google Play subscription. Cancel that subscription in your store account settings before deleting your Nora account. Billing records required by law, backups, and provider logs may remain for their applicable retention periods. You can ask us about those periods and request deletion of remaining personal data. You also have the right to complain to a data protection authority, including the Swedish Authority for Privacy Protection (IMY).
X. Changes to the Privacy Policy
Since we would like to adapt this privacy policy from time to time, we reserve the right to change the privacy policy. The current version of the Privacy Policy is available on our website at all times and we encourage you to consult our Privacy Policy regularly.
To the extent that the Privacy Policy is part of an agreement with users of Nora or any other data subject, we will notify them of the change by email or other appropriate means in the event of an update. You may contact us within 30 days of that notice to raise an objection. An update to this policy does not itself provide consent to new processing or remove your data protection rights. Where a change requires consent, that consent must be obtained separately.