निजता
This notice is written in English only, so that its legal meaning does not drift in translation. Last updated 1 September 2026.
Who is responsible
FluentLab operates fluentlab.online. For anything in this notice, write to fluentlab.learn@gmail.com.
Practising without an account
You do not need an account. If you practise as a guest, your level estimate and topic history are stored in your own browser under a random identifier that we generate. We never see your name, and that identifier is not linked to anything else about you.
The answers themselves — which item, right or wrong, how long it took — are sent to the server against that random identifier. We use them to find questions that are badly calibrated and retire them. They are not used to profile you and are never sold or shared.
With an account
If you create an account we store your email address, a hash of your password (Argon2id — we cannot read your password), an optional display name, your interface language and your level estimate. Your answer history becomes linked to your account so that your progress follows you between devices.
The lawful basis is the contract between us: you asked for an account that remembers your progress, and we cannot provide it without storing these things.
We send email only for things you set in motion: confirming your address, resetting your password, and telling you if your password has been changed. There is no marketing email and no newsletter. Delivery goes through Google’s SMTP service, which necessarily sees the address and the message.
Cookies
Two cookies, both strictly necessary and neither used for advertising. A session cookie once you sign in, so that you stay signed in — HttpOnly, Secure, SameSite=Lax, thirty days. And a language cookie that remembers which language you chose. No analytics cookies, no third-party trackers, no advertising network of any kind.
How long we keep things
Answer records: 24 months. Sessions: 30 days from last use, then deleted automatically. Email confirmation and password-reset links: one hour, and they can only be used once. Failed sign-in records, kept to throttle attacks: 24 hours. Account data: until you delete the account.
Your rights
Under the GDPR you may access, correct, export and delete your data, and object to its processing. Two of these are built in and need no request at all: on your account page you can download everything we hold in one JSON file, and you can delete your account outright. Deletion is immediate and real, not a flag on a row.
If you think we have handled your data badly, you may complain to your national data protection authority.
Children
FluentLab is aimed at adults and older teenagers preparing for exams. If you are under 16 in the EU, ask a parent or guardian before creating an account. We do not knowingly keep accounts for children under 13.
Security
Traffic is served over HTTPS. Passwords are hashed with Argon2id and never stored in a readable form. Session tokens are stored only as hashes, so a database copy cannot be replayed as a login. Sign-in attempts are rate limited per IP address.