Privacy Policy
Effective date: August 18, 2026
Bubblegum Languages, LLC (“Bubblegum,” “we,” “our,” or “us”) builds AI‑powered language learning tools and the Bubblegum mobile and web apps (collectively, the “Services”). This privacy policy explains the data we collect, how we use and store it, the third parties involved, and the choices available to you.
1. Information We Collect
- Account & Profile Data. Name, email, display name, selected learning language(s), goals, app preferences, and optional profile photo. When you sign in with Apple or Google we receive identifiers and the email address they expose.
- Learning Activity. Lessons you generate or view, vocabulary interactions (saved words, lookups, reviews), session metrics, and in‑app actions that help us personalize content and power spaced‑repetition features.
- Content & Media You Provide. Prompts, lesson topics, chat transcripts, audio you upload, and screenshots or drawings you attach when submitting feedback.
- Device & Diagnostic Logs. Device model, operating system, app version, connection quality, and crash or error traces collected to troubleshoot problems.
- Website Interactions. On bubblegum.la we use Google Tag Manager to load Google Analytics and Google Ads measurement in cookieless mode. Analytics storage, advertising storage, advertising user data, and advertising personalization remain denied for every visit. Google may receive cookieless page and event pings with the page URL, referral source, campaign parameters, and basic device metadata, but we do not create analytics or advertising cookies or keep a persistent website analytics identifier. Temporary page-journey IDs stay in memory and reset when the page reloads. Ordinary app buttons use a Bubblegum page to try the installed app, followed by a direct App Store or Google Play link if the app is not present. The temporary journey values travel only in that one-time app link; store fallbacks receive campaign labels, not journey or session IDs.
- Payments & Subscriptions. When you subscribe in the app, Apple or Google share anonymized receipt metadata. When you buy on the web we process payments through Stripe; we do not see full card numbers.
- Advertising & Attribution.To understand which marketing brings learners to Bubblegum, our mobile apps use Airbridge (a mobile measurement partner) and share install and in-app event signals (such as completing your first lesson or starting a subscription) with advertising platforms including Meta and Google, so we can measure which campaigns work and improve our ads. On Apple devices, attribution also uses Apple’s privacy-preserving SKAdNetwork framework, which reports results in aggregate. We ask for your permission before accessing your device’s advertising identifier (IDFA), and we only use it if you allow it — you can change your mind at any time in your device settings. On Android, attribution uses your device’s advertising identifier (Google Advertising ID), which you can reset in your device settings. We do not upload your name, email, or other contact details to advertising platforms. You can limit ad measurement as described in Your Rights below.
- Support & Moderation. Messages sent to support@bubblegum.la, BetterFeedback reports (including screenshots and device metadata), and moderation reports about user‑generated content.
2. How We Use Information
- Provide, personalize, and improve lessons, review queues, and in‑app experiences.
- Generate AI content (lessons, audio narration, explanations) using the prompts you author.
- Maintain safety: flag or hold content for moderation, investigate policy violations, and prevent abuse.
- Operate customer support, respond to requests, and debug crashes or performance issues.
- Process purchases, confirm subscription status, and manage receipts.
- Measure marketing performance and attribute installs and subscriptions to the campaigns that drove them.
- Comply with legal obligations and enforce our Terms of Service.
3. Legal Bases (EEA/UK/Switzerland)
Where GDPR or UK data protection law applies we rely on the following bases: (i) performance of a contract to deliver the Services you request; (ii) legitimate interests for analytics, safety, and product improvement; (iii) consentfor optional cookies or marketing; and (iv) legal obligationto meet regulatory or accounting requirements.
4. Where Your Data Lives & How Long We Keep It
We run on Google Cloud in the United States and use a mix of managed storage systems. The table below summarizes what goes where and the default retention period:
| System | Purpose | Data Stored | Retention & Deletion |
|---|---|---|---|
| Firestore (Google Cloud) | Source of truth for accounts, lessons, progress, moderation queues. | Profile details, lesson metadata, saved words, moderation reports. | Deleted when you use the in‑app “Delete data” or “Delete account” flow, except records we must keep for legal reasons. |
| Memorystore for Valkey (Redis) | Low‑latency caches for review queues and lesson feeds. | Short‑lived queue scores, cached lesson payloads. | Keys expire automatically (30 days or less). Our deletion workflow also clears cached keys for your UID. |
| Cloud Bigtable | Durable spaced‑repetition stats and learning analytics. | Per‑word review history, lesson completion records. | Erased during the account deletion job. We do not currently export this data into BigQuery. |
| Cloudflare R2 | Storage for generated lesson audio and related assets. | M4A/OGG lesson narration files, version metadata. | Retained indefinitely so published lessons keep working, even if a creator later deletes their account. We strip personal identifiers from lesson documents and will remove or revoice specific files on request. |
| Sentry (U.S./EU regions) | Error monitoring and in‑app feedback handling. | Crash traces, BetterFeedback text, attachments, reporter UID. | Stored in the region tied to your project and deleted under Sentry’s default 90‑day retention unless an incident requires a longer legal hold. |
| App stores & Stripe | Payment processing and subscription status. | Receipt tokens, subscription tier, billing country. | Stored by Apple, Google, or Stripe under their own retention schedules. Bubblegum keeps minimal metadata required for accounting. |
We capture infrastructure logs in Google Cloud Logging for security and troubleshooting; those logs typically roll off within 30–90 days unless we are investigating abuse. Google’s generative AI services may retain prompts and outputs for up to 30 days to monitor abuse per the Vertex AI data governance policy.
5. Third‑Party Processors
We partner with vendors that process data under contracts and confidentiality obligations:
- Google Cloud Platform. Hosts Firestore, Bigtable, Memorystore (Valkey), Cloud Functions, Google Cloud Storage, and Google Gemini / Text‑to‑Speech models that generate or analyze lesson content. Prompt logs used for abuse monitoring are subject to a 30‑day retention window.
- Cloudflare R2. Stores generated audio assets so lessons stream quickly worldwide.
- OpenAI. Provides alternative AI chat and lesson generation models when selected by the learner.
- ElevenLabs. Performs forced alignment when we synchronize audio narration with text.
- Sentry. Receives crash reports and user submitted feedback, including screenshots.
- Stripe. Processes web payments. Apple App Store and Google Play handle purchases made in their ecosystems.
- Airbridge (AB180). Mobile measurement partner that attributes installs and subscriptions to the marketing campaign or channel that drove them, and forwards conversion signals to advertising platforms. Bubblegum.la does not load the Airbridge SDK, and app buttons do not use an Airbridge redirect. Direct installed-app links can carry the current campaign into the app. Google Play can also receive standard campaign fields through its install-referrer link. Apple does not offer the same deferred handoff without a separately issued campaign-provider token, so those website journey details may not survive a new iOS install.
- Meta Platforms (Facebook and Instagram). We run ads on Meta and share campaign conversion signals (such as installs and subscriptions) so we can measure and improve ad performance. Meta acts as our advertising partner for these activities.
- Email & analytics providers. We use email delivery vendors for transactional messages and Google Tag Manager / Google Analytics / Google Ads to measure our marketing funnel with analytics and advertising storage denied.
When our AI pipelines call an external model (e.g., Google Gemini, OpenAI, Google TTS, ElevenLabs) the prompt, audio, and relevant metadata are sent to that provider solely to fulfill your request. Providers may temporarily retain data to monitor abuse or debug service issues as described above. We require that each third‑party AI provider offers the same or equivalent level of data protection as described in this policy.
6. YouTube API Services
Bubblegum uses YouTube API Services and Google OAuth to publish Bubblegum-produced language lesson videos to channels owned and operated by Bubblegum. This is an internal publishing workflow. Learners do not connect their Google or YouTube accounts, and we do not use YouTube API Services to read learner data, track viewers, or build advertising profiles.
- Access requested. Our production integration requests only the
youtube.uploadscope. We use it solely to upload videos and their titles, descriptions, tags, and privacy settings to Bubblegum-owned channels. - Data stored. We keep company-channel OAuth refresh tokens and channel identifiers in Google Secret Manager. Our internal publishing records may retain the resulting YouTube video ID, channel ID, upload status, and error details. Operational logs normally roll off within 30–90 days.
- Sharing and use. We send rendered lesson video files and their publishing metadata only to Google for the purpose of publishing them on YouTube. We do not sell YouTube API data or share it with advertising partners.
- Retention and deletion. We retain a channel token only while that Bubblegum-owned channel participates in automated publishing. If access is revoked or a channel is disconnected, we disable publishing and delete the stored token. Published videos and their metadata remain on YouTube until Bubblegum removes them. Requests can be sent to support@bubblegum.la.
- Control and revocation. The owner of a connected Bubblegum channel can revoke access at any time from the Google Account third-party connections page. We also revoke and delete credentials when the integration is retired.
Bubblegum's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google processes data under the Google Privacy Policy.
7. Moderation & Safety
Lessons created by AI start as private drafts withis_public = false. Automated safety checks flag high‑risk content, and human moderators review reports submitted by the community. Reported items disappear from the reporter’s feed immediately and remain hidden until the issue is resolved. We keep moderation case files in Firestore (“moderation_reports” and “moderation_failures”) for the duration of the investigation and no longer than 18 months after closure unless a legal obligation or active dispute requires extended retention.
“Private” lessons are not discoverable by other learners and do not appear in shared feeds or search results. Authorized Bubblegum staff may access private lessons when necessary for analytics, product improvement, trust & safety, or to resolve a support request.
8. Deletion & Data Management
You can manage your data inside the app:
- Delete Data. In Settings → Account → Delete data you can trigger a backend job that removes your profile, saved progress, analytics events, Bigtable review stats, and Valkey caches. Audio hosted in Cloudflare R2 may remain so published lessons keep working; we scrub personal identifiers from lesson metadata and will delete or replace specific audio on request via support@bubblegum.la.
- Delete Account. The same flow optionally deletes your Firebase Auth user. If you signed in with Apple, we revoke the associated tokens.
- Access & Portability. Email us to request a structured export of your data or to correct inaccurate information.
After deletion we may retain limited records needed for legal, accounting, or security purposes (for example, tax receipts or logs of abuse investigations).
9. Your Rights
- Email Preferences. Opt out of non‑essential emails using the unsubscribe link or in settings.
- Cookies & tracking. Bubblegum.la does not use a tracking-consent banner because Google measurement remains in cookieless, storage-denied mode and cannot be upgraded to tracking storage. You can still block measurement requests or delete functionality cookies in your browser; some functionality cookies are required for choices such as language and sign-in state.
- Advertising choices.On Android you can reset your advertising identifier (Google Advertising ID) in your device settings; on Apple devices we use aggregate SKAdNetwork measurement with no device advertising identifier. Using Delete Data (above) stops all further sharing of your activity with advertising and analytics partners. Residents of California and similar jurisdictions may also opt out of the “sharing” of personal information for cross-context advertising by emailing support@bubblegum.la.
- Access, deletion, correction, and portability.Residents of California, the EEA, UK, Switzerland, and similar jurisdictions can exercise statutory rights by emailingsupport@bubblegum.la. We respond within 30 days (or the timeframe required by law) and may request additional information to verify your identity before fulfilling the request.
- Complaints. You may lodge a complaint with your local supervisory authority. We welcome the chance to resolve issues directly—contact us anytime.
10. Children
The Services are not directed to children under 13 (or the minimum age required in your jurisdiction). If you believe a child provided us data, contact us so we can delete it.
11. Security
We use industry‑standard safeguards such as encryption in transit, role‑based access controls, and audit logging. No system is perfectly secure; please use strong, unique passwords and keep your devices up to date.
12. International Transfers
We operate mainly in the United States. When personal data is transferred internationally we rely on approved safeguards such as Standard Contractual Clauses where required by law.
13. Changes to This Policy
We will update this policy when practices change. If we make material updates we will notify you in the app, by email, or on our website. Continued use of the Services after the effective date means you accept the revised policy.
14. Contact Us
Controller: Bubblegum Languages, LLC
Email: support@bubblegum.la
Mailing address:
68 Harrison Ave Ste 605 PMB 309915
Boston, Massachusetts 02111-1929 US (Attn: Privacy)
See also our Terms of Service.