Mandarin Ear

Privacy Policy

This Privacy Policy explains how Mandarin Ear collects, uses, stores, and protects personal data when you access our website and learning services.

Effective March 26, 2026 · Updated September 1, 2026

1. Data We Collect

We collect account and profile details you provide directly, such as your email address, login credentials managed by authentication providers, and account preferences.

We also collect service usage data, including challenge progress, victory runs, mistake assets, and technical metadata needed for reliability and security.

  • Account identity and authentication events
  • Challenge records, scores, and victory history
  • Device, browser, and log information for operational security

2. How We Use Data

We process data to operate and improve the service, authenticate users, persist learning records, support analytics, prevent abuse, and communicate important service notices.

Where required by applicable law, we rely on user consent for specific processing activities and provide controls to withdraw that consent.

3. Google Sign-In

When you choose Sign in with Google, Mandarin Ear requests only the standard OpenID Connect identity scopes needed for authentication: openid, email, and basic profile. Google may provide a stable Google account identifier, your primary email address and whether it is verified, and basic profile information such as your name and profile image URL. We use the account identifier and email address to authenticate you, create or link your Mandarin Ear account, maintain your session, prevent duplicate or abusive accounts, and protect account security.

Mandarin Ear does not request or access your Gmail messages, Google Drive files, contacts, calendars, payment information, passwords, or other Google product data. We do not use your Google profile image as your Mandarin Ear avatar, and we do not use Google Sign-In data for advertising or sell it.

Google and Supabase Auth process the OAuth exchange. Supabase Auth stores the Google identity and provider metadata needed to maintain your authentication account and session. Mandarin Ear does not store Google provider access tokens or refresh tokens in its product database, send them to product APIs, or include them in analytics. Google-derived identity data is shared only with service providers that operate authentication and hosting on our behalf, subject to the safeguards described in this Policy.

Google-derived identity data follows the retention, security, and deletion rules below. Deleting your Mandarin Ear account removes the associated Supabase authentication identity and product records. You may also revoke Mandarin Ear's Google access from your Google Account connections; revocation prevents future Google authorization but does not by itself delete an existing Mandarin Ear account or learning records.

4. Cookies and Similar Technologies

Mandarin Ear uses cookies and similar technologies to maintain signed-in sessions, improve product performance, and understand high-level usage patterns.

You can manage cookies through your browser settings, but disabling essential cookies may affect authentication and core product functions.

5. Data Sharing and Disclosure

We do not sell personal data. We may share data with trusted infrastructure, analytics, and payment service providers that process information under contractual confidentiality and security obligations.

We may disclose information when required by law, to protect rights and safety, or in connection with a merger, acquisition, financing, or asset transfer.

6. Data Retention

We retain personal data only for as long as needed to provide the service, maintain legitimate business records, resolve disputes, enforce agreements, and meet legal obligations.

Retention periods may vary by data type and legal context. When no longer needed, data is deleted or anonymized according to our internal retention practices.

7. Security Measures

We implement technical and organizational safeguards designed to protect personal data, including access controls, secure transport, and operational monitoring.

No method of transmission or storage is fully secure, and we cannot guarantee absolute security. Users are responsible for maintaining account credential confidentiality.

8. Your Privacy Rights

Subject to applicable law, you may request access, correction, deletion, portability, or restriction of certain personal data, and you may object to certain processing.

You can permanently delete your account from the Account screen in the iOS app. This removes your authentication identity, profile, learning records, progress, XP, mistakes, and feedback; external feedback projections are stripped of identifying details and content. The action cannot be undone.

You may also contact us at the email listed below to exercise privacy rights. We may request identity verification before processing requests, and may retain limited records only where required by law or necessary for security and dispute resolution.

9. Children's Privacy

Mandarin Ear is not directed to children under 13 years of age. We do not knowingly collect personal data from children under 13.

If you believe a child has provided personal data, contact us and we will investigate and take appropriate action.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the last updated date and, where appropriate, by providing additional notice.

11. Contact

If you have questions about this Privacy Policy or our data practices, contact Mandarin Ear at hi@mandarinear.com.