Privacy Policy
Oosta · Last updated: 20 June 2026
This Privacy Policy explains how Oosta (“Oosta”, “we”, “us”) collects, uses, and protects your information when you use the Oosta language-learning app and website (the “Service”). By using the Service you agree to this policy.
Who we are
The Service is operated by Milad Hajilotfali, an individual sole operator trading as “Oosta”. For any privacy question or request, contact us at support@oosta.app.
Information we collect
- Account information. Your email address and password (passwords are handled by our authentication provider and stored only as secure hashes), and — if you sign in with Google or Apple — the basic profile information that provider shares with us.
- Profile information. Your chosen display name and avatar, and your selected learning language and level.
- Learning data. Your study progress, learned words, streaks, points, decks, exam results, and any personal notes you add to cards.
- Subscription status. Whether you have an active Oosta Plus subscription. The purchase itself is processed by Apple or Google — we store only your membership status, never your card or full payment details.
- Social features. Friend connections and the “hearts”/reactions you send or receive, so the leaderboard and friends features work.
- Preferences. App settings such as sound, haptics, and notification choices (most are stored only on your device).
- Technical data. Basic, non-precise technical information needed to run and debug the app (e.g. app version and error logs). We do not collect your precise location, contacts, photos, or microphone.
How we use your information
- To provide and operate the Service (save your progress, sync across devices, run leaderboards and friends).
- To authenticate you and keep your account secure.
- To send the notifications you opt into (e.g. streak reminders). You can turn these off any time in Settings or your device settings.
- To diagnose problems and improve the app.
How we share information
We do not sell your personal data. We share data only with service providers that help us run the app:
- Supabase — our database, authentication, and hosting provider, which stores your account and learning data on our behalf.
- Apple / Google — for app distribution and, if you make a purchase, payment processing. We do not receive your full payment details.
- Other users see only your public profile information (display name, avatar) and the scores shown on shared leaderboards.
- We may disclose information if required by law.
Data retention & deletion
We keep your data while your account is active. You can permanently delete your account and all associated data at any time from Settings → Account management → Delete account. This is immediate and cannot be undone. You may also email us to request deletion.
Your rights
Depending on where you live (e.g. under GDPR or CCPA), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, use in-app deletion or contact support@oosta.app.
Security
We use industry-standard measures (encrypted transport, hashed passwords, and database row-level security) to protect your data. No method of transmission or storage is 100% secure, but we work to protect your information.
International transfers
Your information may be processed on servers located outside your country. Where required, we rely on appropriate safeguards for such transfers.
Children’s privacy
The Service is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. We will revise the “Last updated” date above and, for significant changes, provide a notice in the app.
Contact
Questions or requests about your data? Email support@oosta.app and we will respond as soon as we can.