This Privacy Policy explains how Notoria (www.notoria.fi) handles personal data for its private language-learning web app. It is written to match how the product works today. If a practice is not described here, we do not claim to do it.
1. Who is responsible
Notoria is the language-learning service at www.notoria.fi, offered to users in Finland and the wider EU/EEA.
For privacy questions, data-subject requests, and other user contact, email contact@notoria.fi.
A registered company name and postal address for the data controller are not published in the current product. If you need formal controller identification for a GDPR request, email contact@notoria.fi and we will provide it.
2. What this policy covers
It covers personal data and learning content processed when you:
- create or use an account
- save material in private workspaces
- subscribe to Notoria Pro
- use optional AI-assisted tools
- upload media for listening or profile use
- use speaking practice
- send feedback or contact us
The current application code does not include a third-party marketing analytics or advertising SDK. We do not claim to use trackers that are not present in the product.
3. Data we process
Notoria processes different kinds of data for different reasons. The main categories are:
Account and authentication
- Name and email address
- Password hash for email/password accounts (passwords are never stored in plain text)
- Google account identifiers and OAuth tokens if you sign in with Google
- Optional profile photo (avatar)
- Account role and created/updated timestamps
Learning content you create
Content you add in private workspaces, such as vocabulary, theory notes, writing documents, exercises and imported practice material, listening lessons (including media references and transcripts), speaking session transcripts and related session fields, folders, tags, and study progress such as flashcard reviews.
This is your learning material. Notoria stores it so you can return to it and practise from it.
Subscription and payment metadata
- Plan (free or Pro) and subscription status
- Stripe customer and subscription identifiers, and current period end when applicable
Card numbers and payment-method secrets stay with Stripe. Notoria keeps only the billing metadata needed to reflect your Pro status.
Device and preference data
Cookies and browser storage used for sign-in, locale, active workspace, AI assistance preferences, theme, and similar product settings. See Cookies and device storage.
Support and feedback
- Emails you send to contact@notoria.fi
- In-app feedback from Support (message, feedback type, your email, whether you are signed in, optional account id, page path, user-agent, and up to three optional image attachments)
Feedback is delivered by email to Notoria’s technical inbox (ha.dh290702@gmail.com). It is not stored as a separate ticket database inside Notoria.
4. Why we process data
| Purpose | Typical GDPR basis |
|---|---|
| Provide accounts, workspaces, and your saved learning material | Contract (Art. 6(1)(b)) |
| Authenticate you (email/password or Google) and reset passwords | Contract (Art. 6(1)(b)) |
| Run Notoria Pro billing and subscription status via Stripe | Contract (Art. 6(1)(b)) |
| Optional AI help, listening transcription, and speaking practice when you use those features | Contract (Art. 6(1)(b)); preference controls where available |
| Keep the service secure and reliable (abuse prevention, debugging) | Legitimate interests (Art. 6(1)(f)) |
| Respond to support and feedback messages | Legitimate interests / contract, depending on the request |
| Comply with legal obligations | Legal obligation (Art. 6(1)(c)) |
If you need a formal legal-basis note for a specific activity, email contact@notoria.fi.
5. Accounts and sign-in
Notoria uses Auth.js (NextAuth) with a JWT session. You can sign in with email and password, or with Google OAuth when Google sign-in is configured.
Password-reset emails are sent only for accounts that have a password. Reset tokens are stored hashed, expire after 30 minutes, and are used only to set a new password.
6. AI features
Optional AI features in the current product use OpenAI. Depending on the tool you use, Notoria may send relevant learning content — for example vocabulary items, writing text or selections, exercise or theory context, listening transcripts, speaking transcripts, or live audio for the speaking tutor.
AI assistance preferences (including whether assistance is enabled) are stored in a browser cookie so the product can respect your settings. Many server actions that call the model check that assistance is enabled first. Turning assistance off in Settings blocks AI tools that require it.
Listening transcription via AssemblyAI can still run when you use Listening features that need a transcript, because transcription is part of that media workflow rather than the optional “AI assistance” preference alone.
The current codebase does not use other large-language-model providers besides OpenAI. OpenAI processes data under its own terms and privacy policy as a processor for these features.
7. Payments (Notoria Pro)
Paid subscriptions are handled by Stripe. Checkout, invoices, payment methods, and cancellation run through Stripe Checkout and the Stripe Customer Portal. Stripe webhooks update your plan and status in Notoria.
Stripe processes payment data as a payment provider. See Stripe’s own privacy documentation for card handling.
8. Service providers
Depending on which features you use, personal data or learning content may be processed by:
| Provider | Role in Notoria |
|---|---|
| PostgreSQL database (production documented as Neon) | Account and learning data |
| Vercel | Application hosting (configured region includes Frankfurt / fra1) |
| Cloudinary | Avatars, listening media, editor images, and exercise-import files |
| AssemblyAI | Transcription of listening audio |
| Stream Video | Live speaking calls; automatic transcription; session fields such as transcript URLs (and recording URLs only if a recording event is later received) |
| OpenAI | Optional AI assistance and speaking-tutor realtime audio |
| Resend | Password-reset email and Support feedback delivery |
| Stripe | Notoria Pro checkout, portal, and subscription status |
| OAuth sign-in when you choose Google; web fonts for the UI | |
| Dicebear | Generated avatar images used in speaking sessions (from a name seed; no account password is sent) |
Speaking calls are created with transcription enabled. Recording is disabled at call creation in the current implementation; a recording URL is stored only if the product later receives a recording-ready event from Stream.
10. International transfers
Some providers above are based outside the EEA (for example in the United States) or may process data in more than one region. Where personal data leaves the EEA/UK, transfers rely on the safeguards those providers offer under applicable law — such as Standard Contractual Clauses where they apply — and on their published privacy terms.
Application hosting for Notoria is configured toward the Frankfurt region (fra1). Ask contact@notoria.fi if you need help finding the relevant provider documentation for a specific feature.
11. How long we keep data
- Account and learning data are kept while your account remains open so you can use the service
- Password-reset tokens expire after 30 minutes
- Subscription metadata is kept as needed to reflect your current Pro status and Stripe billing relationship
- Support and feedback emails are retained as long as needed to handle your request and related follow-up
Exact backup retention windows for infrastructure providers are not hard-coded in the application and may follow those providers’ operational practices. Contact us if you need clarification for a deletion request.
12. Export and account deletion
Export
From Account you can download a JSON backup of workspaces and learning content (including vocabulary, theory notes, exercises/writing, listening lessons, and speaking sessions). Media files are referenced by URL rather than embedded as binary files.
The current export does not include every account-related record. For example, flashcard progress/reviews and exercise-import source records are not part of the JSON backup. OAuth tokens, password hashes, and Stripe identifiers are not exported.
Delete account
You can permanently delete your account from Account. When deletion succeeds, Notoria:
- deletes your user record and cascaded learning data from Notoria’s database
- cancels and removes related Stripe customer data where Stripe is configured (best effort)
- destroys avatar media and listening-lesson media that the deletion flow is implemented to remove from Cloudinary
The current deletion flow does not claim to purge every third-party artefact automatically. In particular, some Cloudinary assets (such as editor images or exercise-import files) and Stream speaking-call artefacts may remain subject to those providers until cleaned up separately or purged under their own schedules.
After deletion, limited residual copies may also remain briefly in encrypted backups or logs until those systems rotate. If something specific remains after you delete your account, email contact@notoria.fi.
13. Your rights (GDPR)
If you are in the EU/EEA or otherwise protected by GDPR, you may have the right to:
- access your personal data
- correct inaccurate data
- erase data (including by deleting your account)
- restrict or object to certain processing
- receive a portable copy of data you provided (see Export above)
- withdraw consent where processing is based on consent
- lodge a complaint with a supervisory authority — in Finland, the Office of the Data Protection Ombudsman (tietosuoja.fi)
To exercise these rights, email contact@notoria.fi. We may need to verify that the request comes from the account holder.
14. Children
Notoria requires an account and is built as a personal learning workspace. The product does not implement a dedicated age-gate. It is not directed at children. If you believe a child’s data has been submitted without appropriate authority, contact contact@notoria.fi.
15. Changes
We may update this Privacy Policy when the product or legal requirements change. The “Last updated” date at the top of the page changes when a revision is published.
When a change is material, we will communicate it in a reasonable way available at the time — for example by updating this page and, where appropriate, an in-product notice or email.
16. Contact
Privacy and general contact: contact@notoria.fi
Product feedback technical inbox (also listed on Contact Us): ha.dh290702@gmail.com
Website: www.notoria.fi