Privacy and transparency
This notice explains what the Englevo learning platform records, why it is used, and how students and teachers can exercise their data rights.
Effective September 4, 2026 · Last updated September 18, 2026 · Version 2026-09-18-v6Englevo is a learning service operated in Brazil by Jonathan Ouellet-Labrie, who is responsible for Englevo's platform operations and the personal-data handling that Englevo determines. Privacy requests can be sent to labriejonathan0@gmail.com.
A teacher may also have responsibilities for records used in an independent teaching relationship. Englevo will coordinate a request when more than one responsible party is involved.
A teacher's record that this Privacy Notice was made available is an acknowledgement, not blanket privacy consent. The platform does not store plain-text passwords or payment-card details.
Information is used to provide classes and practice, authenticate accounts, save progress, assign and review homework, keep private teaching records, prevent misuse, diagnose failures, and respond to support or data-rights requests.
Cloudflare provides the Worker, database, delivery, security, and recovery infrastructure. Google may process account information when optional Google teacher sign-in is used, exercise text for configured speech synthesis, and microphone audio plus live input and output transcripts during an enabled Gemini speaking exercise. The Englevo application uses that audio and transcript during the live exercise and does not intentionally save the raw audio or full live transcript in its application database after the session.
Google's Gmail service processes messages sent to the public support or data-rights address. If a student chooses homework email and delivery is enabled, Resend processes the recipient address and assignment message for delivery. When student email verification is enabled, Resend also delivers the requested security code independently of homework-email preferences. Verification uses a necessary ten-minute browser cookie and hashed challenges; the code expires after ten minutes. Expired challenge records are removed by daily maintenance after one day, normally within two days of expiry. WhatsApp processes a message only when the user chooses that external link. Discord receives fixed operational reliability alerts that exclude student and tenant details.
These providers may process information in countries where they operate. The applicable provider, purpose, and safeguards depend on the feature used. Contact labriejonathan0@gmail.com to request current information about a relevant provider or international transfer.
Active teaching records are kept while they are needed for the learning relationship and legitimate record-keeping. A verified request can lead to correction, export, restriction, or deletion where the law permits. Limited recovery copies may remain temporarily in Cloudflare's backup systems.
In-app notifications expire after 90 days. Technical delivery logs and private problem reports, including optional screenshots, are retained for no more than 365 days unless they must be kept longer for a legal or active dispute reason.
Teacher agreement and access-audit records may be retained after access ends when needed to demonstrate the agreement, protect users, investigate misuse, resolve a dispute, or meet a legal accountability duty. They do not contain the raw setup code or password.
To protect a long placement test from a phone interruption, the browser may keep a same-device recovery copy in local storage. It can include answers, position, audio-play counts, a technical attempt identifier, and save timestamps. The copy becomes unusable after 30 days and is removed when safely reconciled, explicitly discarded, or the app next performs its expired-copy cleanup.
The platform uses encrypted transport, signed sessions, hardened password hashing, access controls, rate limits, security headers, monitoring, and recoverable database history.
The public Reading library and two-minute demo can remember favourites, attempt counts, completion dates, and scores in this browser's local storage. This information stays on the device, is not treated as an account record, and is not sent to Englevo's teaching database.
Clearing site data or using another browser or device removes or hides that local history. Future account syncing will require a separate, explicit choice and will not silently import anonymous browser data.
The initial controlled launch is limited to adults aged 18 or older. New public access requests and teacher-created student setups require an explicit adult confirmation and remain subject to manual approval. Englevo does not currently offer accounts for minors. Access for a child or adolescent requires separately implemented and reviewed age, guardian, privacy, and best-interest safeguards in Brazil.
Students and teachers can request confirmation, access, correction, information about use and sharing, portability where applicable, or deletion where legally available. See the Data Rights page for the request process.