EN

Privacy Policy

Last updated: October 7, 2026

Noelty is operated by Maksim Filippovskii as an individual. This Privacy Policy explains what data we collect, why we collect it, how it is used, and what rights you may have regarding your data.

1. What we collect

We may collect the following types of information:

  • Account data — your email address, your name and, if you set one, a password, stored only as a hash; your interface language and settings.
  • Google sign-in data — your name and email address if you sign in with Google. Used to create and access your account and to send you a welcome email.
  • Student data — what a teacher enters about a student: a name and, optionally, an email address, notes, the language being learned and the level. Students do not create accounts; they open lessons through a personal link.
  • Lessons, answers and feedback — the lessons and tasks a teacher creates, including uploaded audio; a student's answers and results; and the reaction and comment a student may leave after a lesson.
  • Live lesson signals — during a live lesson, the cursor position and highlighted words are passed between teacher and student. They are not stored.
  • Analytics data — page views and interaction events, collected only after you give cookie consent. Events are linked to a random identifier kept in a first-party lt_cid cookie for 1 year and include your IP address, an approximate country, browser and screen details, the page address and the labels of buttons you click.
  • Activity log — a record of actions in an account, such as signing in, changing or deleting students, lessons and tasks, exports, AI requests, and a student opening their link. Each entry has the time, IP address and browser, and may include a student's name or a lesson's title. Used for security and to investigate problems.
  • Feedback form — your email address and message, if you submit the feedback form. Used to respond to you and to improve the product.
  • Automatically collected technical data — IP address, browser type, device information, timestamps, request paths, and basic diagnostic information collected automatically by the server for security, abuse prevention, and debugging.

2. Why we collect it

We process data for the following purposes:

  • Analytics — to understand product usage and improve features and usability.
  • Authentication — to securely authenticate users and maintain accounts.
  • Service delivery — to provide lesson functionality, maintain active sessions, and synchronize lesson progress.
  • Support — to respond to feedback, support requests, and inquiries.
  • Security — to prevent abuse, investigate suspicious activity, maintain system integrity, and debug technical issues.

3. Legal basis for processing (GDPR)

If you are located in the EEA or UK, we process personal data under the following legal bases:

  • Consent — for analytics cookies and optional analytics tracking.
  • Legitimate interests — for security logs, fraud prevention, debugging, abuse prevention, and customer support.
  • Contractual necessity — when processing data required to provide the Noelty service, including authentication and lesson functionality.

4. Third-party services

We share data with trusted third-party providers only where necessary to operate the service:

  • Google — sign-in with Google, and web fonts, which every page loads from Google's servers. Governed by Google's Privacy Policy.
  • Buy Me a Coffee — optional support platform available through the Support page. Payments are handled entirely by Buy Me a Coffee; we do not see or store payment card details.
  • YouTube — embedded videos may set cookies or collect usage data according to YouTube's policies. We use privacy-enhanced embeds where reasonably possible.
  • OpenAI, Anthropic and Google — AI lesson generation and file import, see section 5.
  • Resend — sends account emails (email confirmation, password reset, welcome). The recipient's address, the subject and the delivery status are recorded.
  • Hosting and infrastructure providers — server and infrastructure providers may process technical and log data necessary to deliver the service securely.

5. AI lesson generation and file import

When you use Build with AI, we send the text you pasted and your settings (level, task types, translation language) to an AI provider: OpenAI, or Anthropic or Google when we switch to one of them. Nothing else is sent — no names, emails or student data. When you import tasks from a file, we read the text out of the file and send that text — not the file — to the same provider. We do not keep the file; its name stays with your account.

  • The providers do not use this data to train their models and keep it for abuse monitoring, under their own policies: OpenAI and Anthropic for up to 30 days, Google for up to 55 days.
  • Noelty keeps a copy of your text, or of the text of your file, for 30 days so a failed attempt can be retried, then deletes that copy. The lesson built from it stays in your account until you delete it. The settings, the number of generations and their token counts stay with your account. Also kept: the lesson's title, the provider and model used, and, for an import, the headings of the file's sections.
  • Generation and import happen only when you ask for them. Do not paste or upload personal data about your students, and upload only materials you have the right to use.

6. International data transfers

Some third-party providers may process or store data outside your country of residence, including in the United States and other jurisdictions. Where applicable, we rely on safeguards provided by those providers for international data transfers.

7. Cookies

Noelty uses a non-essential analytics cookie named lt_cid. It is set only after you accept it in the cookie banner; your choice is remembered in your browser's local storage.

To change your choice, clear this site's data — cookies and local storage — in your browser. The banner will then ask again.

8. Data retention

  • Analytics events — retained for up to 12 months.
  • Activity log — retained for up to 12 months.
  • Server logs and technical diagnostics — kept by our hosting for a limited time.
  • Your account — until you delete it. You can delete it yourself in Settings: it is erased at once, with your students, lessons, tasks, answers, feedback, uploaded audio and the activity log entries about them.
  • Lessons, answers and feedback — until the teacher deletes the lesson, the student or the account. Deleting a student deletes that student's lessons.
  • A student's link — works until the student is deleted.
  • Analytics events and messages sent through the feedback form are not removed when an account is deleted: events are kept for the period above, messages until you ask us to delete them.
  • Copies of texts sent for AI generation or read from an imported file — 30 days in Noelty; at the AI provider up to 30 days (OpenAI, Anthropic) or up to 55 days (Google).

9. Security

We use reasonable technical and organizational measures designed to protect personal data against unauthorized access, disclosure, misuse, or destruction. However, no internet-based service can guarantee absolute security.

10. Children and educational use

Noelty may be used in educational environments by teachers and students. Teachers and lesson creators are responsible for ensuring lawful use of the service, including when lessons involve minors.

The service is not intended for children under 13 without supervision or authorization from a parent, teacher, or educational institution where required by applicable law.

11. User-generated content

Teachers and users are responsible for the legality of any content, lesson material, text, audio, or other data they upload or share through the platform.

12. Your rights (GDPR)

If you are located in the EEA or UK, you may have the right to:

  • Access the personal data we hold about you.
  • Request correction or deletion.
  • Withdraw consent for analytics processing.
  • Object to certain processing activities.
  • Request data portability.
  • Lodge a complaint with your local data protection authority.

You can delete your account and everything in it yourself, in Settings. To exercise your other rights, contact: mafilippovskiy@gmail.com

We will respond within a reasonable period and generally within 30 days where required by law.

13. Contact

Maksim Filippovskii
Email: mafilippovskiy@gmail.com