[REQUIRES LAWYER REVIEW] — This is a working draft prepared by the YoluBand team. It is published so that we can submit our app to platform stores, but it has not yet been reviewed by a qualified data-protection lawyer. We will replace this notice with a finalised version before a public launch.
This Privacy Policy explains what personal information YoluBand collects when you use the service, why we collect it, who we share it with, and what choices you have. We try to keep this document short and readable. If anything is unclear, write to us at the email at the bottom of this page.
1. Who we are
YoluBand is an English-learning app for Azerbaijani and Russian speakers, with a particular focus on IELTS preparation. The service is offered through the website yoluband.az and through our mobile app.
For the purposes of data-protection law, the data controller is the YoluBand team. Our primary processing locations are described in section 5 below.
2. What we collect
We try to collect only what we genuinely need to run the product. In practice that means:
- Account data — your email address, display name and a unique user ID. Account creation and sign-in are handled for us by Clerk (clerk.com). When you sign up, Clerk stores your credentials; we do not see your password.
- Learning progress — lessons you have started or completed, XP, streak counts, vocabulary you are reviewing, mock-test sessions, essay submissions, speaking submissions, daily goal, and your placement level. This data is stored in our PostgreSQL database hosted by Neon.
- Speaking and writing submissions — when you record a speaking response or submit an essay for grading, we send that content to our AI grader and store the grading result and your original submission against your account. Audio recordings are temporarily uploaded to Vercel Blob storage so that they can be transcribed and graded, and they may be retained while we develop and improve the grader.
- Push-notification tokens — if you install the mobile app and grant permission, we receive an Expo push token so that we can send streak reminders and lesson nudges. You can revoke this at any time in your device settings.
- Analytics events — non-content events such as 'lesson started', 'lesson completed', or 'mock test submitted' are sent to PostHog from our server. These events include your user ID so that we can debug per-account issues; they do not include the text of your essays or your audio.
- Technical data — our hosting provider (Vercel) automatically receives standard request data such as your IP address, user-agent and the URL you visited. This is used to serve the site, to defend against abuse, and to write request logs.
3. How we use this data
We use the information above for the following purposes:
- To provide the service — sign you in, remember your progress, grade your essays and speaking responses, show you the right lessons next, and send you the notifications you have opted in to.
- To improve the product — to understand which lessons help users improve and which do not, to debug bugs, and to develop better AI-grading prompts.
- To keep the service healthy and safe — to detect abuse, prevent automated scraping of paid content, and meet legal obligations.
We do not sell your personal data, and we do not run third-party advertising on YoluBand.
4. Third parties we share data with
YoluBand is a small team, and we rely on a number of well-known infrastructure providers to run the product. Each is bound by its own privacy policy and, where applicable, a data-processing agreement with us.
- Clerk (clerk.com) — authentication, password storage, session management.
- Neon (neon.tech) — managed PostgreSQL database where your learning data is stored.
- Vercel (vercel.com) — hosting and serverless functions; also provides our Blob storage for temporary audio uploads.
- AI Gateway providers — when we send your essay or speaking transcript for AI grading, the content is routed through providers such as Google (Gemini) and OpenAI under Vercel's AI Gateway. We do not allow these providers to use your content to train their public models.
- PostHog (posthog.com) — product analytics; receives only the event names and user ID described in section 2.
- Resend (resend.com) — transactional email delivery, for example streak reminders and password-reset emails.
- Expo / Apple / Google — when you use the mobile app, Expo and the platform stores receive your push token in order to deliver notifications.
We do not share your data with anyone else for marketing or advertising purposes.
5. Where your data is stored
Our primary database is hosted by Neon in their Frankfurt (eu-central-1) region inside the European Union. Vercel hosting and Blob storage runs from a similar European region by default. Some of our sub-processors (Clerk, PostHog, Resend, the AI Gateway providers) are based in the United States and may process data on US-based servers. By using YoluBand you understand that your data may be transferred to those providers under the terms of their respective privacy policies.
6. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to export a copy, or to object to certain processing. To make any of these requests:
- You can request a copy of your learning data at any time from the in-app endpoint /api/user/export. The response is a JSON file containing your account record and learning progress.
- To delete your account, write to privacy@yoluband.az from the email address associated with your account. We will erase your personal data within 30 days, except for records we are legally required to keep.
- For any other request, write to the same address. We try to reply within 14 days.
We will not charge you a fee for exercising these rights in the normal case.
7. Cookies
YoluBand uses one strictly-necessary cookie: the session cookie set by Clerk so that we can keep you signed in. We do not set advertising cookies and we do not use third-party tracking pixels.
8. How long we keep your data
We keep your account record and learning progress for as long as your account is active. When you delete your account, we delete your personal data within 30 days. Audio recordings of speaking submissions may be kept for up to 90 days for grading-quality review, and are deleted on request.
Anonymised analytics events (for example, aggregate counts of how many users completed a given lesson) may be retained for longer in order to monitor product health.
9. Children
YoluBand is intended for users aged 13 and over. We do not knowingly create accounts for children under 13. If you believe a child under 13 has signed up, please write to privacy@yoluband.az and we will delete the account.
10. Changes to this policy
We may update this policy from time to time, particularly as our product grows and our sub-processor list changes. Material changes will be communicated through an in-app notice or an email. The date at the top of this page is the effective date of the current version.
11. Contact
If you have questions about this policy or want to exercise any of the rights above, write to privacy@yoluband.az. We read every message.