Privacy Policy
Last updated: September 5, 2026
This policy explains what AILE collects, why, who we share it with, and the choices you have. It covers both the AILE iOS app and this website. We keep it short and plain on purpose.
1. Who we are
AILE is operated by AILE LLC, located at 9251 West 22nd Street, Minneapolis, MN 55426. For any privacy question or request, email us at learnailesupport@gmail.com. AILE is the data controller for the personal information described here.
2. What the app collects
AILE is a learning app for iPhone. You can use most of it without an account, in guest mode, and then everything below that is marked as syncing simply stays on your device.
- Account and authentication data: your email address and, if you set one, a display name. If you create a password we store it securely hashed, never in readable form. If you use Sign in with Apple or Google, we receive the email address that provider gives us (Apple may give us a private relay address) and never see your password. Session tokens are stored encrypted on your device in the iOS Keychain.
- Learning progress and assessment data: XP, streaks, gems, lessons and modules completed, quiz and lesson scores, badges, and daily goals and quests. This is what lets your progress survive a reinstall and follow you across devices.
- Answer history and skill rating: which practice questions you answered, when, how quickly, whether you got them right, and, when a question asks, how sure you were. From those answers we compute a single skill rating, one number, that decides which question or lesson to show you next and when to bring something back for review. Your skill rating is never used to decide what you pay or to grade a credential.
- Onboarding answers: the goals, experience level, learning preferences, kind of work you do, and age range you give in the welcome questions, used to pick what we show you first. With an account these sync to our database. Without an account they stay on your device.
- Ask Spark messages: what you type to our AI tutor, and its replies. These are held on our server for up to 24 hours and then deleted. Section 4 explains exactly how, including the messages we never store or send anywhere at all.
- AI usage records: for each AI request we keep a count, token totals, and an estimated cost on your account, so we can apply fair rate limits and control cost. These records never contain your words.
- Reports and safety records: what you send us when you report an answer, and short labels describing safety events. Section 5 covers both.
- Subscription and purchase data: whether you have an active AILE Pro subscription, which plan, and the related purchase events. Section 6 covers this.
- Usage analytics: events that describe what you do in the app, for example a lesson started or finished, sent to PostHog and tied to your account id so we can see how the app is used and where it fails. Unlike the analytics on this website, these events are not anonymous. You can turn them off at any time in the app under You, then Privacy & data, with the "Share usage analytics" switch.
- Crash reports: if the app crashes or hits an unexpected error, a report goes to Sentry with the device model, iOS version, app version, and a technical trace of what the code was doing. Crash reports carry no name, no email address, and nothing you typed.
- Technical and log data: standard server logs (such as request times and error information) used to operate and secure the service.
We do not collect precise location, your contacts, photos, biometrics, health data, or advertising identifiers. The app contains no advertising SDK and does not track you across other companies' apps or websites; the analytics and crash-reporting tools it uses work for us alone (section 8). Reminders are off by default. If you turn them on, your device schedules up to eight local notifications over the 28 days after you stop practicing, then goes quiet. No push token or device identifier is sent to us.
3. What this website collects
- Waitlist details: your email address or US mobile phone number (whichever you choose), the page or source you signed up from, and a timestamp. We also store a one-way hashed version of your IP address to prevent spam and abuse (we do not keep your raw IP for the waitlist), and a record of the exact consent language you saw when you joined.
- Technical and log data: standard server logs used to operate and secure the site.
We do not knowingly collect special-category data and we ask you not to send us sensitive information through the waitlist.
4. Ask Spark, and how we process AI messages
When you ask Spark a question, or request a hint, your message is sent to our AI provider, Anthropic, which processes it to generate a reply. Per Anthropic's commercial terms, it does not use API data to train its models. Our AI keys live on our server and are never shipped inside the app.
So a conversation holds together from one turn to the next, our server keeps both sides of an Ask Spark chat, your messages and Spark's replies, for up to 24 hours from the start of that conversation. After that they are deleted automatically. The 24-hour limit is enforced rather than merely promised: expired messages are filtered out on every read, purged on your next request, and swept globally by an hourly job. Nobody else's account can read your transcript, and deleting your account deletes it immediately.
Crisis messages are the exception. If what you write reads as a crisis disclosure, AILE answers you itself with support resources we wrote in advance. That message is never sent to our AI provider and is never stored: it stops before the transcript is written and before any model is called. Nothing about it is attached to your account. We count only the number of times crisis resources were shown, as a daily total with no identifier and no text (see section 5).
You can turn AI answers off. In the app, under You, the "AI answers" switch turns them off entirely. With it off the app makes no AI calls at all, so nothing you type is sent to our AI provider. Lessons, quizzes, and the hints we wrote ourselves keep working, because none of those involve AI.
AI output can be wrong or incomplete. Spark is for learning only and is not professional, legal, medical, or financial advice. Always verify anything important with a trusted source.
5. Reports and safety records
Reports. If you report an answer in the app, we store Spark's reply so a person can review it, the reason you picked, and anything you type in the report. Your own question is included only while the "include the question I asked" option stays ticked. A report is linked to your account so we can follow up on a pattern. If a report reads as a crisis disclosure, we drop your words and keep only the reply being reported. We keep reports until a person has reviewed them and for one year after that, then delete them automatically.
Safety telemetry. When a safety filter declines a request or blocks a reply, we record what kind of event it was as short labels on your account. We never store the text of the message, only the labels. This is how we tell a filter that is working from one that has started misfiring.
Crisis referrals. Moments where we show crisis support resources are counted only as a daily total. There is no user identifier, no message text, and nothing to join a count back to a person. We keep that aggregate so we can report the number where law requires it.
6. Subscriptions and purchases
AILE Pro is an auto-renewable subscription, offered monthly and annually, and sold through the App Store. Apple processes the payment and the billing. We never see or receive your card details.
We use RevenueCat to manage subscription status and validate purchase receipts, so your Pro access follows you across your devices. RevenueCat and Apple tell us the state of your subscription (whether it is active, which plan, and the purchase, renewal, or cancellation events behind it). We store an entitlement record on your account and a log of those purchase events.
You manage or cancel a subscription in your App Store account settings, not here. If you delete your AILE account, the entitlement record goes with it; the purchase event log is kept as a financial record with your account identifier unlinked, so it can no longer be traced to you.
7. Why we use it, and our legal bases
AILE is not currently offered on the App Store in the European Union. Where the GDPR or UK GDPR applies, for example to visitors to this website, we rely on the following legal bases:
- Consent: to send you waitlist and launch emails, or, if you join by phone, a single launch text message. You can withdraw consent at any time by unsubscribing (email) or replying STOP (text). Message and data rates may apply to texts. We record the time of your consent, a hashed IP, and the version of the consent language you saw; we will not send recurring marketing texts, and we send nothing at all until launch. Practice reminders in the app are also consent based, off until you turn them on.
- Contract: to give you an account, run the app, save and sync your progress, answer your questions with the AI tutor, and provide the subscription you bought.
- Legitimate interests: to keep the service secure, prevent abuse, apply fair rate limits and control cost, review the reports you send us, and understand and improve how the product works, including through the app's usage analytics (which you can switch off) and crash reports, balanced against your rights.
- Legal obligation: to comply with applicable law, including keeping financial records and reporting aggregate safety statistics where required.
8. Cookies, local storage, and analytics
The public website sets no advertising or analytics cookies and stores nothing persistent on your device. We use two privacy-respecting, cookieless analytics tools: Vercel Analytics (aggregate page statistics, no cookies or device identifiers) and PostHog in memory-only mode (no cookies, no local storage, a fresh anonymous identifier on every page load). Analytics events describe interactions, for example "waitlist form submitted", and never contain your email address or phone number. We use no advertising trackers and no cross-context behavioral advertising.
On-device storage is limited to session-only flags (whether the intro animation has played, and which feedback posts you have upvoted) plus strictly necessary login cookies in the signed-in admin area. Because nothing non-essential is stored on your device, we do not show a cookie consent banner. Because we do not sell or share personal information, a Global Privacy Control signal has nothing to switch off; we treat it as an opt-out request should that ever change. If we ever add advertising or tracking that stores data on your device, we will update this policy and present a consent choice first.
The AILE iOS app is different, and we want to be plain about it. The app sends usage events to PostHog tied to your account id, so we can follow how the product is used over time rather than page by page. These events describe interactions, such as a lesson finished or a screen opened, and they are never used for advertising. You can turn app analytics off at any time under You, then Privacy & data. Crash reports go to Sentry with device and app version details and a technical trace, and carry no name, email address, or typed text.
The app carries no advertising SDK. Its analytics and crash-reporting tools work for us alone: the app does not read the advertising identifier and does not track you across other companies' apps or websites.
9. How we share information
We do not sell or share your personal information, and we do not use it for cross-context behavioral advertising (as those terms are defined under the CCPA/CPRA). We share data only with the service providers (subprocessors) that help us run AILE:
- Supabase: Database, authentication, and hosting of application data (United States). Data terms.
- Vercel: Website hosting, content delivery, and cookieless aggregate site analytics (United States). Data terms.
- PostHog: Product analytics: cookieless and anonymous on this website (nothing stored on your device); in the iOS app, usage events tied to your account id, with an in-app opt-out under You, then Privacy & data (United States). Data terms.
- Sentry: Crash reporting for the iOS app (device model, iOS and app version, and a technical trace; no name, email address, or typed text) (United States). Data terms.
- Anthropic: AI model processing for learning features (does not train on API data) (United States). Data terms.
- RevenueCat: Subscription management and App Store purchase receipt validation for AILE Pro (United States). Data terms.
- Resend: Transactional and waitlist email (when enabled) (United States). Data terms.
- Cloudflare: Turnstile bot protection on the waitlist and feedback forms (United States). Data terms.
- Formspree: Form delivery fallback for waitlist and feedback (when enabled) (United States). Data terms.
Apple also processes App Store payments and billing for AILE Pro as an independent party under its own privacy policy. We receive the resulting subscription status, never your payment details.
The current list is also on our subprocessors page. We may also disclose information if required by law or to protect rights, safety, and the integrity of the service.
10. International data transfers
We are based in the United States and our providers process data in the United States. If you are in the EEA, the UK, or Switzerland, your data is transferred to the US under appropriate safeguards, including the European Commission's Standard Contractual Clauses with our subprocessors.
11. How long we keep it
- Account, progress, answer history, skill rating, and onboarding answers: for as long as your account exists. Deleted when you delete your account.
- Ask Spark chat: up to 24 hours from the start of the conversation, then deleted automatically.
- Crisis messages: never stored at all, so there is no retention period.
- AI usage records (counts, tokens, cost): kept with your account for rate limits and cost control, and deleted with it.
- Reports: until a person has reviewed them and for one year after that, then deleted automatically.
- Safety telemetry: label-only records, kept while we need them to monitor the safety filters. When you delete your account, the user identifier is removed and only the unlinked labels remain.
- Crisis referral counts: kept as daily totals. They carry no identifier and never did.
- Usage analytics and crash reports: held by PostHog and Sentry under their retention settings. Email us to have the analytics tied to your account id removed sooner.
- Purchase records: your entitlement is deleted with your account. The purchase event log is retained as a financial record, with your account identifier unlinked.
- Waitlist information: until the product launches plus a reasonable window, then deleted if you have not become a user.
- Server logs: kept only as long as needed to operate and secure the service.
We delete or anonymize personal data when it is no longer needed, and sooner on a valid deletion request, unless we must retain it to meet a legal obligation.
12. Your rights, choices, and deleting your account
If you are in the EEA, the UK, or Switzerland, you may have the right to access, correct, delete, restrict, or object to our use of your data, to data portability, and to withdraw consent (GDPR/UK GDPR). Section 13 sets out the rights of United States residents state by state, and we honor those rights for everyone, wherever you live.
- Export: in the app, You then "Export my data" gives you the data held on your device (progress and onboarding answers) as a file. For a copy of what we hold on our servers, email us and we will send it.
- Delete your account: in the app, You then "Delete account". It is immediate and irreversible. It hard-deletes your account and everything that hangs off it: progress and scores, your answer history and skill rating, synced onboarding answers, any Ask Spark transcript still inside its 24-hour window, your reports, your AI usage records, and your entitlement. The only things that survive are records stripped of any link to you: safety labels with the user identifier removed, aggregate crisis counts that never had one, and the purchase event log kept as an unlinked financial record.
- Use it without an account: guest mode keeps your progress on your device.
- Turn AI off: the "AI answers" switch stops all AI calls (section 4).
- App analytics: the "Share usage analytics" switch under You, then Privacy & data, stops analytics events (section 8).
- Reminders: off by default, and you can turn them off again at any time in the app or in iOS Settings.
To exercise any right, email learnailesupport@gmail.com. Section 13 explains how we verify requests and the timelines we hold ourselves to. You may also unsubscribe from any marketing email using the link in its footer. EEA/UK users may lodge a complaint with their local data protection authority.
13. Your privacy rights by state
Depending on where you live, you may have the right to know what personal information we hold about you and receive a copy, to correct it, to delete it, to obtain it in a portable format, to opt out of targeted advertising, sale, sharing, and profiling that produces legal or similarly significant effects (we do none of these), and to not be discriminated against for exercising these rights. Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island have some or all of these rights under their state laws, and Minnesota residents also have the right to question the result of any profiling and to obtain a list of the specific third parties we have shared their data with. We honor these rights for everyone, regardless of where you live.
To exercise a right, use the controls in the app (You, then Export my data or Delete account) or email learnailesupport@gmail.com. We will confirm receipt within 10 days, verify that you are the account holder by sending a confirmation to the email on your account, and respond within 45 days, extendable once by 45 days where the law allows if we tell you why. An authorized agent may act for you with your written permission. If we decline a request, you may appeal by replying to our decision; we will answer the appeal within 45 days and tell you how to contact your state Attorney General if you disagree.
14. Children
AILE is intended for people aged 13 and older. We ask you to confirm you are 13 or older the first time you open the app, and we do not knowingly collect personal information from children under 13. If we learn that a user is under 13, we delete the account and its data promptly and confirm the deletion to a parent who contacted us. If you believe a child has provided us data, contact us at learnailesupport@gmail.com and we will delete it.
15. How we protect your data
We use industry-standard safeguards including encryption in transit (HTTPS/TLS), database row-level security so an account can only ever read its own rows, session tokens stored encrypted on your device in the iOS Keychain, AI keys held server-side and never shipped in the app, least-privilege access, multi-factor authentication on administrative accounts, and regular security review. No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant authorities as required by law.
16. Changes and contact
We may update this policy as AILE evolves; we will revise the “Last updated” date and, for material changes, give prominent notice. Questions or requests: learnailesupport@gmail.com or AILE, 9251 West 22nd Street, Minneapolis, MN 55426.
Effective date: September 5, 2026.