Ortio Icon Ortio
Effective: 7 June 2026

Privacy Policy

How Ortio collects, uses, and protects your personal information.

Last Updated: 7 June 2026

Contents

1 Introduction

Prasad Mahankal ("I", "me", or "the developer") operates the mobile application Ortio, available on Android (Google Play Store) (the "Service").

Ortio is a multilingual language learning app that helps users practice and prepare for official language certifications including Goethe-Institut (German), DELF/DALF (French), DELE (Spanish), HSK (Chinese), JLPT (Japanese), and more.

This Privacy Policy describes how I collect, use, store, and protect your personal information, and the rights you have regarding your data.

This policy aims to comply with:

ℹ️ The disclosures in this Privacy Policy are intended to be fully consistent with Ortio's Data Safety disclosures on the Google Play Store.

2 Data Controller

App Name: Ortio

Developer: Prasad Mahankal (individual / sole developer)

Contact: support.ortio@gmail.com

ℹ️ If required under applicable law, Ortio will designate a GDPR representative and provide the relevant contact details upon request.

3 Information We Collect

3.1 Account Information

Creating an account is required to use Ortio. I collect:

Public Visibility: Your display name / username and profile photo (if uploaded) are public and visible to other users on the community feed and in chat features.

3.2 Practice & Learning Data

3.3 Social & Communication Data

3.4 Technical & Device Information

4 How I Use Your Information

5 Legal Basis for Processing (GDPR)

PurposeLegal Basis
Account creation & core app featuresContract (Art. 6(1)(b))
Analytics & crash reportingLegitimate Interest (Art. 6(1)(f))
Push notificationsConsent (Art. 6(1)(a))
Advertising personalization (where required by applicable law)Consent (Art. 6(1)(a))
Non-personalized advertisingLegitimate Interest (Art. 6(1)(f)) or Consent depending on jurisdiction
Security & abuse preventionLegitimate Interest (Art. 6(1)(f))
Legal complianceLegal Obligation (Art. 6(1)(c))

6 Data Storage

Server-Side (Supabase)

Your account details, practice history, posts, notes, and encrypted chat messages are stored in a Supabase PostgreSQL database hosted on secure cloud infrastructure. All data in transit is protected by TLS/HTTPS. Supabase Row-Level Security (RLS) ensures each user can only access their own data.

On Your Device (Local Storage)

Using AsyncStorage and react-native-keychain, the following is stored locally:

⚠️ Important: If you uninstall the app or clear app data, your local E2EE private key is permanently deleted. You will not be able to decrypt old Human Chat messages afterwards.

7 Third-Party Services

🗄️
Supabase
Authentication, database, and real-time messaging infrastructure.
Privacy Policy ↗
🔥
Firebase (Android only)
Push notifications (FCM), app analytics, and crash reporting (Crashlytics).
Privacy Policy ↗
🔐
Google Sign-In
If you sign in with Google, I receive your name, email, and Google account ID via OAuth.
Privacy Policy ↗
📢
Google AdMob (Advertising)
Ortio displays ads through Google AdMob. AdMob may collect and process advertising IDs, device specifications, IP address, and app usage data to measure and deliver ads. Consent choices are stored and shared with Google and advertising partners to respect user preferences. AdMob may use data for personalized ads if you consent. You can manage ad consent in app settings.
Privacy Policy ↗
🤖
Google Gemini 2.5 Flash Lite (AI Chat)
Powers the AI tutor feature. Your text input is sent to Google's API to generate learning responses.
Privacy Policy ↗
🎙️
Groq Whisper API (Speech / Mock Tests)
For speaking-based mock test features, your audio input is processed by Groq's Whisper API for speech-to-text transcription.
Privacy Policy ↗
🛒
Google Play Billing (Android)
In-app purchases and subscriptions on Android are processed by Google Play. I receive only purchase confirmation and subscription status — never your payment details.
Privacy Policy ↗

Note on AI Processing: Messages and voice recordings submitted to AI-powered features (such as AI Chat and mock tests) are transmitted to the respective AI providers (Google and Groq) solely to produce transcriptions or replies, and are governed by their respective policy terms. Ortio does not retain audio files after processing.

Ortio does not sell personal information to third parties as that term is traditionally defined. California users can opt out of the "sharing" of their personal information for targeted advertising in the app settings.

8 End-to-End Encryption (Human Chat)

Human Chat messages in Ortio are protected with end-to-end encryption (E2EE) powered by TweetNaCl:

9 Push Notifications

With your permission, Ortio may send push notifications for:

You can disable notifications at any time in Settings → Apps → Ortio → Notifications on your Android device.

10 Billing & Subscriptions

Ortio offers paid subscription plans through a credit-based system. In-app purchases are processed through Google Play Billing.

When you make a purchase:

🔒 Your payment information is never shared with or stored by Ortio. All billing is managed securely by Google Play.

11 Data Security

12 Data Retention

Data TypeRetention Period
Account & profile dataRetained while your account exists
Practice history & notesRetained while your account exists
Social posts & commentsRetained until you delete them or your account
Human Chat messages (ciphertext)Retained until deleted by users or upon account deletion
Firebase Analytics data14 months (Firebase default)
Crash reports (Crashlytics)90 days
Purchase receiptsWhile subscription is active + 1 year for tax/legal compliance
AI Chat conversationsRetained while your account exists or until deleted by you
Audio recordings & TranscriptionsAudio recordings are not stored by Ortio after processing; transcriptions are kept while your account exists
Local device data (AsyncStorage, Keychain)Until app is uninstalled or app data is cleared

13 Account & Data Deletion

Ortio provides an in-app account deletion feature accessible from Settings → Danger Zone → Delete Account.

When you request and confirm account deletion within the app (by entering the required confirmation phrase), your account data, profile details, messages, and progress are deleted from our systems. Account deletion requests are typically processed immediately or within 30 days, except where limited retention is required for legal, security, fraud-prevention, tax, or regulatory obligations.

You can also request account deletion using our online request form: Ortio Account Deletion Request Form.

Alternatively, you may request account deletion by emailing support.ortio@gmail.com with the subject "Account Deletion Request". We will process your request within 30 days.

14 Your Privacy Rights

Your Privacy Rights

RightWhat It Means
AccessRequest a copy of your personal data
RectificationAsk me to correct inaccurate data
ErasureRequest deletion of your account and all data
PortabilityReceive your data in a structured, portable format
ObjectionObject to certain types of processing
RestrictionRequest restriction of processing your personal data
Withdraw ConsentDisable push notifications at any time via device Settings

Advertising Consent & Choices

Users in the EEA, UK, and Switzerland may grant, refuse, or withdraw consent for personalized advertising at any time through the in-app "Manage Privacy Choices" option in the Settings menu.

CCPA Rights (California Residents)

To exercise any right, email support.ortio@gmail.com. I will respond within 30 days.

15 App Permissions

Internet Required for all network features — authentication, content, chat, AI responses, push notifications
Notifications For push notification delivery — practice reminders and chat messages
Microphone For speaking-based mock test features (audio recorded and sent to Groq Whisper API)
Camera / Photos For uploading profile photos and post images (accessed via system media picker or if camera access is explicitly granted)
Storage (if requested) For caching content locally or reading selected media files on older device versions
Network State To detect connectivity type and optimize data usage

You can revoke any permission at any time from Settings → Apps → Ortio → Permissions on your Android device.

16 Children's Privacy

Ortio is not intended for children under 13 years of age (or 16 in the EU). I do not knowingly collect personal information from children.

If you are a parent or guardian and believe your child has created an account, please contact me immediately at support.ortio@gmail.com and I will delete the account and all associated data promptly.

17 International Data Transfers

Your data is processed and stored on infrastructure operated by Supabase and Google (Firebase), which may be located in the United States or other countries outside your country of residence.

For EU users, such transfers are covered by appropriate safeguards (such as Standard Contractual Clauses) as implemented by these providers. By using Ortio, you acknowledge this.

18 Changes to This Policy

If I make significant changes to this Privacy Policy, I will:

Continued use of Ortio after changes constitutes your acceptance of the updated policy.

19 Contact

Questions or Requests?

For any privacy-related questions, data access requests, or account deletion, reach out directly:

support.ortio@gmail.com

EU Residents: You have the right to lodge a complaint with your national data protection authority. Find your DPA at: edpb.europa.eu

California Residents: Contact the CPPA at: cppa.ca.gov