Privacy Policy
Last updated 2 October 2026 · Nihao is in beta
The short version
- We store your email address, your learning progress and your answers — that is what the app is for.
- We never sell your data, and we never use it for advertising.
- Analytics only run if you accept them. Nothing analytics-related loads before you do.
- Your microphone audio never reaches our servers.
- You can delete your account and everything attached to it yourself, from Settings, at any time. It is immediate and it is not recoverable.
- There is nothing to pay during the beta, so we hold no payment details at all.
1. Who we are
Nihao is a Mandarin Chinese learning web app operated by Star-48 ("we", "us"). For data protection purposes we are the controller of the personal data described here.
Questions, requests or complaints about privacy: stephane@star48.io. We answer data requests within 30 days.
2. What we collect
We only collect what the app needs to work. There is no tracking pixel on our public pages, and no data broker anywhere in the picture.
Your account
When you sign in with Google, Apple or an email link we receive and store a user ID, your email address, the display name your provider gives us (if any), which provider you used, and your time zone. We never receive or store a password — sign-in is handled entirely by Firebase Authentication. If you sign in with Apple using "Hide My Email", we only ever see Apple's relay address.
Your learning data
Your estimated level in each skill, your placement result, which characters, words and grammar points you have seen and how well you know them, your sessions and their summaries, your streak, and your settings (voice, speech rate, daily session length). Also your answers: for each exercise we store what you answered, what was expected, whether it was correct, whether you used a hint, and how long it took. The app cannot schedule your revision or show you your progress without this.
Speaking exercises
Speaking exercises use your browser's own speech recognition. The microphone audio is handled by your browser and never reaches our servers — we neither receive nor store any recording. Depending on your browser, it may send that audio to its own vendor (Google for Chrome, Apple for Safari) in order to transcribe it; that is covered by your browser's privacy policy, not ours. We receive only the resulting text, which is stored as your answer, and the pronunciation score is calculated in your browser. You can skip any speaking exercise, and the app works without ever granting microphone access.
Beta feedback
If you use the in-app feedback button we store your message, whether you flagged it as a bug or an idea, the app version, which page you were on, your browser's user-agent string and your user ID, and we forward a copy to our team chat so we actually see it. Please don't put anything sensitive in that box.
Technical data
Server logs (IP address, timestamp, which endpoint was called, response status), crash and error reports, and counters we use to cap daily usage and keep costs predictable. Error reports deliberately exclude your request bodies — so your answers are not in them — along with authentication tokens and API keys.
Analytics — only with your consent
If you accept analytics, we record which screens you visit and what you do: signing in, finishing onboarding, starting and completing sessions, changing a setting, hitting an error. These events carry identifiers, option names, counts, buckets and true/false flags only. They never carry your email, your name, anything you typed, your answers, your feedback message, or a URL with a query string in it. The only identifier attached is the same pseudonymous user ID the app uses internally.
If you decline, no analytics code is loaded at all — not a cookie, not a request. You can change your mind either way at any time in Settings → Privacy, and turning it off deletes the analytics cookies and storage from your browser.
What we never collect
Payment or card details (the beta is free, so there is nothing to charge). Your precise location. Your contacts. Any special category of data — health, beliefs, biometrics. We also run no advertising and allow no ad personalisation, even if you accept analytics.
3. Why we use it, and our legal basis
- To run the app for you
- Your account, learning data and settings. Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)) — without this there is no app.
- To keep it working and affordable
- Logs, crash reports, usage caps, abuse prevention. Legal basis: our legitimate interest in a secure, functioning service (Art. 6(1)(f)).
- To improve it
- Analytics, and the feedback you choose to send. Legal basis for analytics: your consent (Art. 6(1)(a)), which you may withdraw at any time. Legal basis for feedback: our legitimate interest in fixing what you report (Art. 6(1)(f)).
We do not make any automated decision about you that has a legal or similarly significant effect. The app does adapt your lesson plan to your results — that is the product, and it changes nothing but which exercises you are shown next.
4. Cookies and browser storage
This page and our landing page set nothing at all. Inside the app:
- Sign-in session — strictly necessary, set by Firebase Authentication so you stay signed in. No consent required, and the app cannot work without it.
- Your analytics choice — strictly necessary. We have to remember that you said no, in order to keep honouring it.
-
A "signed in here before" flag — strictly necessary. Holds the value
1and nothing else; it lets an already signed-in visitor skip the landing page. Removed when you sign out. - Analytics cookies and storage — only after you accept. Google Analytics cookies expire after 13 months; our product analytics keeps a pseudonymous device ID in browser storage. Declining means these are never created; withdrawing deletes them.
5. Who else processes it
We use a small number of service providers, each under a data processing agreement, each acting only on our instructions:
-
Google — sign-in, hosting, our servers and database, file storage, and the AI and speech
services that grade free-text answers, plan your sessions and read Chinese aloud. Our servers and database are
in Google's
us-central1region (United States). - Amplitude (United States) — product analytics. Receives data only if you accept analytics.
- Google Analytics (United States) — website analytics. Receives data only if you accept analytics. Ad personalisation and Google Signals are switched off.
- Sentry (United States) — crash and error monitoring, so we can fix what breaks.
- Slack — receives a copy of feedback you choose to send us, so the team sees it.
Two details worth stating plainly. When an answer you typed is graded by an AI service, we send only the sentence you wrote and the reference answer — no user ID, no email, nothing that identifies you. When text is read aloud, we send only the Chinese text to be spoken, again with no identifier, and we cache the resulting audio under a hash of that text so the same phrase is never synthesised twice. Your data is not used to train anybody's models.
We never sell personal data, and we never share it for advertising. We may disclose data if the law genuinely requires it, or to protect our rights or someone's safety.
6. International transfers
Our infrastructure runs in the United States, so if you are in the European Economic Area, the United Kingdom or Switzerland your data is transferred outside your region. Those transfers rely on the European Commission's Standard Contractual Clauses, and where applicable on our providers' certification under the EU–US Data Privacy Framework. You can ask us for details of the safeguards in place.
7. How long we keep it
- Your account, learning data and feedback — for as long as your account exists. Deleted when you delete your account.
- Daily usage counters — about a week per user. Service-wide totals, which identify nobody, are kept about two months.
- Server logs — around 30 days. Error reports — up to 90 days.
- Cached audio — kept as a cache, stored under a hash of the Chinese text with no link to any user.
- Analytics events — retained by our analytics providers under their own schedules (Google Analytics: up to 14 months).
8. Deleting your account and your data
Go to Settings → Delete account. This removes your account and every row attached to it — progress, sessions, answers, preferences, feedback — and deletes your sign-in account itself, so the same email starts completely fresh next time. It happens immediately, it needs no email to us, and it cannot be undone.
Two things that deletion does not reach, so that you know: analytics events already collected are pseudonymous and are not removed automatically — email us and we will file a deletion request with our analytics providers. And a copy of any feedback you sent remains in our team chat; ask us and we will remove it.
9. Your rights
Depending on where you live you have the right to access a copy of your data, to correct it, to delete it, to restrict or object to how we use it, to take it elsewhere in a portable form, and to withdraw a consent you gave. You will never receive a worse service for exercising any of them.
The quickest routes are built in: delete everything from Settings → Delete account, and withdraw analytics consent from Settings → Privacy. For anything else — including a copy of your data — email stephane@star48.io.
If you are in the EEA or the UK and you think we have handled your data badly, you may complain to your national data protection authority. We would rather you told us first so we can fix it.
10. Security
Everything travels over HTTPS and is encrypted at rest. Sign-in is delegated to Firebase Authentication, so we never hold a password. Every API request is authenticated, and our secrets live in a managed secret store rather than in our code. Access to production data is limited to those who need it. No service can promise perfect security, but we treat a breach affecting you as something you must be told about, and we will notify you and the relevant authority where the law requires it.
11. Children
Nihao is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has created an account, email us and we will delete it.
12. Changes
Nihao is in active beta, so this policy will change as the product does. The date at the top always says when. If a change materially affects you we will tell you in the app before it takes effect, and where the law requires it we will ask for your consent again rather than assume it.
Contact
Star-48 — stephane@star48.io