Legal · Shining Apps LLC

Privacy Policy & Terms of Service

This policy explains how Shining Apps LLC collects, uses, stores and protects your personal data across all of our Cambridge English websites and apps — and sets out the terms on which we provide them. It applies to every product we operate, not to any single app.

Last updated July 2026 GDPR compliant

1. Introduction & Data Controller

Shining Apps LLC is a limited liability company incorporated in the State of New Mexico, United States, with its registered place of business at 530-B Harkle Road, STE 100, Santa Fe, NM 87505, United States (“the Company”, “we”, “us”, or “our”). We design, build and operate top-tier Cambridge English learning software across web, iOS and Android for levels B1, B2, C1 and C2.

The Company acts as the data controller for all personal data processed in connection with our websites and apps, as defined under Regulation (EU) 2016/679 (the “General Data Protection Regulation” or “GDPR”) and applicable national implementing legislation.

This policy applies to everyone who creates an account, purchases a subscription or credits, interacts with our features, browses our sites without registering, or otherwise communicates with us. By accessing or using any of our services, you acknowledge that you have read and understood this policy. If you do not agree, please discontinue use of our services.

2. Personal Data We Collect

We collect only the data necessary for the purposes described below. We do not collect Special Category Data (Art. 9 GDPR) such as health, biometric, or racial or ethnic origin data.

We do not store sensitive data. We never store payment card numbers, CVV codes, bank details, government-issued identification, passport or national ID numbers, or any comparable sensitive identifiers on our servers. Payment details are handled entirely by our certified payment processors (see Section 5). The limited personal data we do collect — such as your name and email address — is used exclusively to operate and provide the application's functionality (creating your account, delivering features, and communicating service information with you) and is never used for unrelated purposes.

2.1 Account & Profile

Your name, email address, optional profile photo, and username. This data creates and maintains your account and identifies you across sessions.

2.2 Authentication

Sign-in is provided through third-party identity providers — currently Apple Sign-In and Google Sign-In. We receive an authentication token and, where available, your name and email. We never receive, store, or have access to your provider password.

2.3 Learning, Usage & Diagnostics

Exercises attempted, scores, progress and streaks, features and pages visited, actions taken, performance metrics, timestamps, crash logs and general analytics. This powers your in-app statistics and helps us improve reliability across our products.

2.4 Payment & Billing

Payments are handled by Stripe, Inc. and by the Apple App Store / Google Play. We never store your full card number or CVV. From Stripe we receive only a tokenised customer identifier, subscription status, the last four digits of a card (for display), billing country and transaction history.

2.5 Device & Technical

Your IP address, browser or device type, operating system, screen resolution, preferred language and time zone — used for security, fraud prevention and rendering across devices.

2.6 Communications

When you contact support (in-app, email, or messaging channels) we collect the content of your messages and any attachments, retained to resolve your enquiry.

2.7 Cookies & Similar Technologies

We use cookies, local storage and similar technologies as described in Section 8 below.

3. Purposes & Legal Bases

We process your personal data only where a lawful basis under Article 6 GDPR (or equivalent applicable law) exists:

Contractual necessity — Art. 6(1)(b)

Creating and managing your account, delivering exercises and features, processing subscriptions and one-off purchases, maintaining entitlements and credits, and authenticating you on each session.

Legitimate interests — Art. 6(1)(f)

Security and fraud prevention, content moderation, product analytics and service improvement, and maintaining the integrity of our systems. We have assessed that these interests are not overridden by your rights and freedoms.

Legal obligation — Art. 6(1)(c)

Retaining financial records for statutory periods, responding to lawful requests from competent authorities, and meeting tax and accounting obligations.

Consent — Art. 6(1)(a)

For non-essential cookies and marketing communications. You may withdraw consent at any time without affecting the lawfulness of prior processing or your access to core services.

4. AI-Powered Features

Some of our applications — such as Use of English AI — use third-party large language model (LLM) infrastructure to generate practice content and feedback in real time. Where a product offers such a feature, only the parameters needed to fulfil your request (for example, a topic prompt, level and selected options) are transmitted to our AI provider.

No personally identifiable information — such as your name, email or account identifier — is sent alongside your prompt. Prompts are processed in isolation under a strict content policy designed to prevent harmful, violent, explicit or otherwise prohibited output, and are subject to automated content moderation.

No training on your data: prompts and AI-generated output associated with your account are not used to train or fine-tune any model. Data sent to our AI providers is governed by a data processing agreement that prohibits use of API-submitted data for model training.

Generated content and your responses may be stored on our servers to power history, statistics and review features, associated with your account and retained per Section 7.

5. Payments, Subscriptions & Refunds

Direct payments are processed exclusively by Stripe, Inc. (510 Townsend Street, San Francisco, CA 94103, USA), a PCI-DSS Level 1 certified processor. Stripe independently collects and processes your card data, billing name, address and IP at the time of transaction under Stripe's Privacy Policy. We never have access to your full card number or CVV.

Subscription management: subscribers can update billing, change plan, or cancel through the provider's customer portal. Cancellation takes effect at the end of the current billing period; no partial refunds are issued for unused time within a cycle unless required by applicable consumer protection law.

Account deletion is separate from cancellation: as is standard across all apps and websites, deleting your account and cancelling a subscription are two distinct actions, and deleting your account does not automatically cancel, pause or refund an active subscription. You remain responsible for cancelling any recurring subscription through the channel where it was purchased. Subscriptions taken out directly with us must be cancelled from within the relevant website before deleting your account, as access to the cancellation controls is lost once the account is removed. Subscriptions purchased through the Apple App Store or Google Play are billed and managed by those platforms and can be cancelled through your store account either before or after deleting your Shining Apps account.

App store purchases: subscriptions bought through the Apple App Store or Google Play are subject to those platforms' billing and refund policies and must be managed directly through them.

Returns: unless otherwise required by law, lifetime licenses and in-term subscriptions are non-refundable. Where a refund is approved and processed, any associated entitlements or credits are revoked and the account may be subject to suspension.

6. Data Sharing & Recipients

We do not sell, rent or trade your personal data. We share it only with the following categories of processors, and only to the extent necessary to operate our services:

  • Authentication — Apple Inc. / Google LLC: we receive sign-in tokens governed by each provider's privacy policy.
  • Payments — Stripe, Inc. / Apple / Google: we share only your email (for receipts) and a user-level identifier to associate payments with your account.
  • AI infrastructure providers: prompts stripped of identifying data, under a DPA prohibiting secondary use.
  • Analytics — Google Analytics / Firebase: pseudonymous or aggregated usage and crash data; IP anonymised where feasible.
  • Hosting & infrastructure: cloud providers under contractual confidentiality and security obligations.
  • Email delivery: transactional email services for confirmations, receipts and notifications.
  • Legal & regulatory authorities: where required by law, court order, or to protect the rights, property or safety of the Company, our users or the public.

All processors are bound to act solely on our instructions and in compliance with applicable data protection law.

7. Data Retention

We retain personal data only as long as necessary for the purposes above, unless a longer period is required by law:

  • Account data: for the life of your account, plus up to six (6) years after closure to satisfy legal and contractual obligations.
  • Usage & content data: for the life of your account; anonymised or deleted within ninety (90) days of closure.
  • Purchase & billing records: up to six (6) years for tax and accounting.
  • Support communications: up to twenty-four (24) months after resolution.
  • AI prompt logs (moderation): up to twelve (12) months, then deleted or anonymised.
  • Analytics & logs: typically twelve (12) to twenty-four (24) months.

After expiry, data is securely deleted or irreversibly anonymised. Where deletion is temporarily infeasible (e.g. encrypted backups), data is isolated from active processing until it can be removed.

8. Cookies & Tracking Technologies

We use cookies and analogous technologies (including local and session storage) for the following purposes:

  • Strictly necessary: session authentication, security and load-balancing. These cannot be disabled and require no consent.
  • Preference: remembering language, display and notification settings, on the basis of implied consent.
  • Analytics: pseudonymous usage measurement via Google Analytics and Firebase, placed only with consent where required.
  • Marketing & attribution: measuring advertising effectiveness, placed only with your explicit prior consent.

You can manage or withdraw consent to non-essential cookies through your browser settings or, where available, our cookie preference centre. This does not affect your ability to use the core service.

9. Your Rights Under GDPR

Subject to applicable law and certain conditions, you have the right to:

  • Access (Art. 15): confirm whether we process your data and obtain a copy.
  • Rectification (Art. 16): correct inaccurate or incomplete data — basic profile fields can be edited in-app.
  • Erasure (Art. 17): request deletion where data is no longer necessary, subject to legal retention obligations.
  • Restriction (Art. 18): limit processing in certain circumstances.
  • Portability (Art. 20): receive your data in a structured, machine-readable format.
  • Objection (Art. 21): object to processing based on legitimate interests.
  • Withdraw consent at any time where processing relies on it.

To exercise any right, contact us via the details in Section 14. We respond to verified requests within thirty (30) days and may request proof of identity first. You also have the right to lodge a complaint with a supervisory authority in your habitual residence, place of work or place of the alleged infringement.

10. Children's Privacy

Our services are not directed at, and are not intended for, individuals under the age of sixteen (16). We do not knowingly collect personal data from children under 16. If you are under 16, please do not use our services or provide personal data.

If we learn we have inadvertently collected data from a child under 16 without verifiable parental consent, we will delete it promptly. If you believe this may have occurred, contact us at info@shiningapps.com.

11. International Data Transfers

Given the international nature of our operations, your data may be transferred to and processed in countries outside the European Economic Area (EEA) — in particular the United States. Such transfers are conducted under Chapter V of GDPR, using one or more of the following safeguards:

  • Adequacy decisions of the European Commission, where applicable.
  • Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) for transfers where no adequacy decision applies.
  • Supplementary measures such as data minimisation, pseudonymisation and encryption in transit and at rest.

You may request details of the mechanism applicable to a specific recipient at gdpr@tckrlabs.com.

12. Security & Automated Decisions

We implement appropriate technical and organisational measures to protect your data, including:

  • Encryption in transit via TLS 1.2 or higher.
  • Encryption at rest of sensitive fields such as authentication tokens.
  • Access controls restricting data to authorised personnel under least-privilege.
  • Infrastructure security including firewalls, intrusion detection and vulnerability assessments.
  • Breach response: we notify the competent supervisory authority within seventy-two (72) hours where a breach is likely to risk your rights and freedoms, and affected users where required.

No method of transmission or storage is completely secure; while we strive to protect your data we cannot guarantee absolute security. We do not engage in automated decision-making, including profiling, that produces legal or similarly significant effects on you.

13. Terms of Service

By accessing or using our websites and apps you agree to be bound by these terms and this Privacy Policy.

  • Content is provided for general information and use and may be updated without prior notice.
  • We do not warrant that information is accurate, complete or fit for a particular purpose, and exclude liability to the fullest extent permitted by law.
  • Use of any information or materials is at your own risk; ensuring products, services or information meet your needs is your responsibility.
  • Our sites and apps contain material owned by or licensed to us (design, layout, look and graphics). Reproduction is prohibited except under the applicable license or prior written consent.
  • All trademarks not owned by us are acknowledged. Unauthorised use may give rise to a claim for damages and/or be a criminal offence.
  • Links to third-party sites are provided for convenience only; we do not endorse and are not responsible for their content.
  • These terms are governed by the laws of Spain. If you access our services from another jurisdiction, you are responsible for local compliance.

We reserve the right to amend this policy at any time to reflect changes in law, our practices or our products. Material changes will be notified by email or a prominent in-product notice no less than thirty (30) days before taking effect. Continued use after the effective date constitutes acceptance.

14. Contact & Data Protection Enquiries

For any data protection enquiry, to exercise your rights, or to report a potential breach, contact us using the details below. We aim to respond within thirty (30) calendar days.

Data Controller

Shining Apps LLC

530-B Harkle Road, STE 100

Santa Fe, NM 87505

United States

info@shiningapps.com+1 (505) 381-8112

EU Representative · Art. 27 GDPR

Paula Klein

Balmes 241, 4th Floor

08006 Barcelona, Spain

gdpr@tckrlabs.com
WhatsApp