Privacy Policy
Last updated: September 9, 2026Hanlo is operated by 惠州市云泉科技有限公司. Hanlo is a Mandarin learning app for adults aged 18 and over. This policy explains how we handle personal data when you use the app, website, support, or beta program. For privacy requests, contact support@hanlo.app.
Speaking-practice recordings stay on your device. They are not uploaded, transcribed, scored, used to clone a voice, or used to train AI models. Optional app analytics and crash diagnostics are off by default and start only after you enable them in General settings. Separately, our servers report limited technical error information with account and request content removed; this monitoring is not controlled by that setting.
Data We Handle
- Account data: user id, email address, authentication status, date of birth, and an optional verified phone number.
- Profile and learning preferences: display name, language level, goals, and learning preferences. Your profile may also contain a country, region, or city saved previously. You can view and remove that saved location in Personal details. This version does not ask you to enter a new location.
- Teaching data: prompts, AI replies, generated model audio, selected scenes, saved lessons, plans, learning memory, progress, and AI-reply reports.
- Subscription data: store product, entitlement, renewal, restore, and transaction-related identifiers. Hanlo does not receive your full payment-card number.
- Support and beta data: messages, email address, signup answers, referral or campaign parameters, and feedback you submit.
- Optional telemetry: pseudonymous product interaction, device/app identifiers, crash data, and performance data, only after consent.
Purposes And Legal Bases
| Purpose | Legal basis where GDPR applies |
|---|---|
| Create and secure your account; provide teaching, model audio, saved plans, support, subscriptions, data export, and deletion | Performance of our contract with you |
| Prevent abuse, protect accounts and services, enforce limits, and investigate AI-safety reports | Our legitimate interests in safety, security, and service integrity |
| Optional product analytics and crash diagnostics | Your consent, which you may withdraw at any time in General settings |
| Billing, tax, legal requests, and regulatory compliance | Compliance with legal obligations |
| Beta invitations and product email you requested | Your consent or our legitimate interests where permitted; every marketing message includes an opt-out |
AI Teaching
Hanlo identifies AI replies in the teaching interface. We send your teaching messages, relevant conversation history, language level, learning preferences, selected learning memories, and conversation and plan identifiers to MiniMax to generate teaching replies. Text selected for model audio is also sent to MiniMax. These lesson identifiers can be linked to your account within Hanlo.
MiniMax processes inputs and outputs under its published privacy policy and service terms, which cover operating, securing, and improving its services. Retention depends on the purpose of processing and applicable requirements. Its terms do not specify one deletion period for all Hanlo requests. See the MiniMax Privacy Policy and Terms of Service.
AI replies can be inaccurate. You can report an individual reply from the message controls for safety review.
On-Device Recordings
Recordings created in speaking practice remain in app storage on that device for playback and local attempt history. They are not part of a server data export. If you confirm account deletion on that device, Hanlo also attempts to remove its local recordings. On another device, clear Hanlo app storage or uninstall Hanlo to remove recordings that the server cannot reach.
Generated Model Audio
Model audio reads teaching text aloud using a synthetic voice. It is processed on our servers and by our providers; account-specific model audio is stored privately for playback and removed through account deletion. Shared audio for bundled lessons is stored separately. This audio does not contain recordings of your voice.
Service Providers And Disclosures
| Provider | Purpose and data |
|---|---|
| Supabase | Authentication, account identity, and storage of shared scene audio |
| Render | Application hosting and storage of account profiles, teaching conversations, saved plans, and service records |
| Cloudflare R2 | Private storage of generated model audio associated with your account |
| RevenueCat and the app store | Subscription identifiers, purchases, entitlement, renewal, and restore status |
| MiniMax | Teaching messages, relevant conversation history, selected learning memories, conversation and plan identifiers, and text used to generate teaching replies or model audio |
| PostHog | Pseudonymous product analytics, only after you opt in |
| Sentry | App crash and performance diagnostics after you opt in; service error monitoring with personal data removed |
We do not sell personal data, share it for cross-context behavioural advertising, or serve third-party advertising. We may disclose limited data when required by law or to protect users, rights, and service security.
International Transfers
Providers may process data in the United States and other countries. Where required, we use a lawful transfer mechanism such as an adequacy decision or standard contractual clauses and apply appropriate technical and organisational safeguards.
Retention
- Account, profile, teaching, generated model audio, plan, and learning data are kept while your account is active and removed or anonymised through the account-deletion process, unless limited retention is legally required.
- Subscription and transaction evidence is retained as needed for entitlement support, fraud prevention, tax, accounting, and store obligations.
- AI-safety reports and security records are retained for as long as reasonably necessary to review the report, prevent abuse, and establish or defend legal claims.
- Optional analytics and diagnostics follow the configured provider retention period and stop being collected after you withdraw consent.
- Waitlist and support records are kept until the request is resolved, you unsubscribe or request deletion, or they are no longer needed for the stated purpose.
Your Choices And Rights
Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to processing and to withdraw consent. You can request and receive a portable Hanlo account export, including saved AI-reply report details, and manage optional analytics in General settings, edit profile data, and request account deletion in the app. You may also email support@hanlo.app. We may need to verify your identity before fulfilling a request.
We delete the associated data held by Hanlo and request deletion from providers that process it for us. Provider follow-up may continue after the app shows that account deletion is complete. Contact support@hanlo.app with your request ID for the status of your request.
Support email, beta feedback, and waitlist records are kept in separate support or marketing systems and are not included automatically in the in-app export. Email support@hanlo.app to access or delete those records. Speaking-practice recordings remain on the device and are outside the server export.
EEA and UK users may complain to their local data-protection authority. US residents may exercise applicable state privacy rights without discrimination. Hanlo does not sell or share personal data for targeted advertising, so no sale/share opt-out is required for that activity.
Security
We use access controls, authenticated account boundaries, encryption in transit, data minimisation, and operational monitoring. No security method is perfect; contact support@hanlo.app if you believe your account or data is at risk.
Adults Only
Hanlo is not directed to children. You must be at least 18 years old to create an account. If we learn that an ineligible person created an account, we will take steps to delete it.
Changes And Contact
We will post material changes here and provide additional notice when required. For privacy requests or questions, contact support@hanlo.app.