NuVoka Privacy Policy

Last updated: 16 August 2025

Welcome to NuVoka (the “Service”). This Privacy Policy explains what data we collect, how we use it, and the choices you have. It is written to satisfy major privacy regimes (GDPR/UK GDPR, CCPA/CPRA, Singapore PDPA) and Meta’s Instagram Platform Terms, including Instagram Public Content Access (PCA).

Quick summary

We collect the minimum data needed to run a language‑learning platform with AR features and a contributor community.

For Instagram PCA, we only ingest public posts that include approved hashtags (e.g., #nuvoka) and we store a limited set of fields.

We don’t sell personal data. You can opt out of analytics and training uses, and request access or deletion at any time.

1) Who we are

Controller: NuVoka ("NuVoka", "we", "us").

Contact: info@ironlioninternational.com

Update before publishing: Replace with your legal entity name and address (e.g., NuVoka Pte. Ltd. or NuVoka (HK) Limited), and add a postal address. If you appoint an EU/UK representative or a DPO, add those details here.

2) Scope

This Policy covers data processed through:

  • The NuVoka mobile and web apps.

  • AR features (e.g., live captions, translations, environmental tagging).

  • The contributor portal and the Partner‑Generated Content (PGC) program.

  • Our public hashtag discovery (Instagram PCA) and any similar integrations (e.g., YouTube, Bilibili) you choose to link.

3) Data we collect

We collect the following categories of data:

A. Account & Profile

  • Name/handle, email, password (hashed), avatar, interface language, learning language(s), proficiency level(s).

  • Optional: country/region, time zone.

B. AR & Learning Activity

  • On‑device audio/text/video processing for live captions/translation. By default, streams are processed ephemerally; we only store transcripts or screenshots if you explicitly save them.

  • Vocabulary/grammar interactions, topic progression, in‑app ratings and feedback.

C. Social & Integrations (opt‑in)

  • Linked accounts and identifiers (e.g., Instagram Business/Creator account ID, YouTube channel ID, Bilibili UID).

  • For learning integrations you connect (e.g., Duolingo, Preply, Speak), we ingest progress metadata where permitted (e.g., lesson IDs, completion timestamps, scores)—never your payment data on those services.

D. PGC Contributor Data

  • Contributor profile (name/handle), social handles you provide, submission metadata, licensing selections, payout information (processed by our payment processor), contribution metrics.

E. Instagram Public Hashtag Data (PCA)

  • For approved hashtags (e.g., #nuvoka), we ingest only the fields Instagram allows for hashtag media, such as: media ID, caption, media type, media URL, permalink, timestamp, and public engagement counts (e.g., comments_count, like_count). We do not collect private content.

F. Device & Usage

  • Device type, OS, app version, diagnostics/crash logs, coarse location (from IP), cookies/SDK identifiers, and event telemetry (e.g., feature usage, latency) used to improve stability and UX.

Sensitive data: We do not seek to collect sensitive categories. Please do not submit health, political, or other sensitive information. If AR capture picks up such content incidentally, we process it ephemerally and do not store it unless you explicitly save a transcript/screenshot.

4) Sources of data

  • You (account creation, settings, contributions, opted‑in integrations).

  • Your device (AR live processing, telemetry).

  • Third parties at your direction (e.g., Instagram Graph API for public hashtag posts; other platforms you connect).

5) How we use data (purposes & legal bases)

We process data to:

  1. Provide the Service (create accounts; deliver AR subtitles/translations; enable PGC contributions) — contract.

  2. Personalize learning (identify gaps/ZPD; recommend content; maintain vocab/grammar progress) — legitimate interests / consent where required.

  3. Discover public hashtag content relevant to learning scenarios — legitimate interests and to fulfill PCA‑approved use cases.

  4. Safety & integrity (abuse prevention, fraud, IP enforcement) — legitimate interests / legal obligation.

  5. Analytics & product improvementlegitimate interests / consent where required (e.g., cookies).

  6. Payments & tax for PGCcontract / legal obligation.

  7. AI/ML training (see §7) — consent (opt‑in) or legitimate interests with opt‑out controls, depending on jurisdiction.

6) Instagram Public Content Access (PCA)

For Instagram PCA we:

  • Access public media for approved hashtags (like #nuvoka) via the Instagram Graph API.

  • Store only permitted fields (e.g., id, caption, media_type, media_url, permalink, timestamp, comments_count, like_count). We do not collect private content or authentication data of users who didn’t connect their accounts.

  • Use the data solely to surface relevant learning scenarios, to run aggregate analytics, and to measure hashtag campaign effectiveness.

  • Respect deletions/changes: we periodically refresh and remove/stop showing media that has been deleted, made private, or altered to remove the hashtag.

  • Do not build profiles about Instagram users beyond what is necessary for the permitted use.

  • Do not resurface full content in ways that replicate Instagram’s core experience.

If you connected your Instagram Business/Creator account, we may store your account ID to perform hashtag searches, per your consent.

7) AI/ML model training & governance

  • We operate a contributor‑aligned model program. By default, your personal content and interactions are not used to train models unless you opt in. You can change this at any time in Settings.

  • PGC creators can choose training permissions per contribution under the PGC License (separate document). We honor revocation on a go‑forward basis.

  • When we train models on aggregated/anonymized data, we use privacy‑protective techniques (e.g., minimization, hashing, prompt filtering). If you request deletion, we stop using your data for new training runs; previously trained model weights are not individually reversible, but we will retrain/refresh models over time.

8) Sharing & disclosure

We do not sell your personal data. We share data with:

  • Service providers (hosting/storage and databases, analytics, crash reporting, payment processors, email providers, content moderation). These processors act under contract and only per our instructions.

  • Integration partners you connect (e.g., Meta/Instagram; language‑learning platforms you authorize).

  • Legal & safety — if required by law or to protect rights, safety, and security.

  • Business transfers — if we undergo a merger, acquisition, or asset sale, under appropriate safeguards.

Current core vendors (update as needed): Supabase (infrastructure/database), cloud hosting/CDN, analytics (e.g., Plausible/GA), crash reporting (e.g., Sentry), payment processor (e.g., Stripe), task automation (e.g., GitHub Actions). Vendor list and sub‑processors will be published at nuvoka.app/subprocessors.

9) International transfers

We may transfer data to countries with different data protection laws. Where required, we use appropriate safeguards (e.g., EU Standard Contractual Clauses, UK IDTA/Addendum, PDPA transfer mechanisms). You can request copies of SCCs via info@ironlioninternational.com.

10) Retention

  • Account data: for the life of your account; deleted within 30–90 days after closure (unless legally required to retain longer).

  • AR transcripts/screenshots: only if you save them; you can delete at any time.

  • PGC assets & contributor records: retained as required for licensing and payouts; you can remove or relicense future use consistent with contributor terms.

  • Instagram hashtag media metadata: refreshed regularly; we attempt to remove items no later than 30 days after the source post is deleted, made private, or loses the hashtag.

  • Analytics/telemetry: typically 12–24 months in aggregate form.

11) Security

We use industry‑standard safeguards (encryption in transit and at rest, access controls, monitoring, backups). No system is 100% secure; if we detect a breach affecting you, we will notify you and regulators as required.

12) Your rights & choices

Depending on your location, you may have the right to:

  • Access, correct, delete your data.

  • Portability of certain data.

  • Object or restrict processing (including personalization and analytics).

  • Opt out of training uses of your data.

  • Opt out of “sale”/“sharing” (CPRA) and targeted advertising.

  • Withdraw consent (where processing is based on consent).

Submit requests in‑app or email info@ironlioninternational.com. For California residents, we honor CPRA rights and provide a “Do Not Sell or Share My Personal Information” link where required. For EU/UK residents, we identify legal bases and will respond within statutory timeframes.

13) Children

NuVoka is not directed to children under 13. If you are 13–17, you must use NuVoka only with parental/guardian consent where required. If we learn we collected personal data from a child under 13, we will delete it.

14) Cookies & similar technologies

We use strictly necessary cookies and, with consent where required, functional and analytics cookies/SDKs to understand usage and improve the Service. Manage preferences in Settings or your browser/OS.

15) Data deletion & appeals

16) Changes to this Policy

We may update this Policy from time to time. Significant changes will be notified in‑app or by email. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.

17) Instagram PCA statement for reviewers (non‑contractual summary)

  • We use Instagram Graph API only to discover and analyze public media tagged with approved hashtags (e.g., #nuvoka).

  • We store and display only the permitted fields and do not replicate Instagram’s core user experience.

  • We respect content changes and removals and refresh our index accordingly.

  • We do not use PCA data to build profiles of Instagram users; we apply aggregate analytics and scenario matching for language learning.

Contact Us
Questions or requests: info@ironlioninternational.com.