Privacy Policy — Fluento
Effective Date: 17 August 2026
Last Updated: 17 August 2026
Developer: NanoSmartX Technologies Pvt Ltd
Contact: contactus@nanosmartx.com
Website: https://nanosmartx.com
1. Introduction
NanoSmartX Technologies Pvt Ltd (“we”, “us”, “our”) operates the Fluento mobile application (the “App”) available on Android and iOS. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and your rights under applicable law — including the Digital Personal Data Protection Act, 2023 (DPDP Act) of India.
By installing or using the App, you agree to the practices described in this policy. If you do not agree, please uninstall the App and contact us to request deletion of any data already collected.
2. Data We Collect
2.1 Account & Identity Data
| Data | How Collected | Purpose |
|---|---|---|
| Mobile phone number or email address | Entered by you during OTP login | Account identification and authentication |
| One-Time Password (OTP) | Generated and verified by our backend | Verify your identity at sign-in |
| User ID (system-generated) | Created on first login | Link all your data records internally |
2.2 Voice & Conversation Data
| Data | How Collected | Purpose |
|---|---|---|
| Voice / audio input | Microphone (only while a session is active and you have pressed Start) | Processed in real-time by Azure AI for English speaking practice |
| AI conversation transcripts | Generated during each session | Display chat history, save session logs, enable assessment |
| Session metadata (start time, end time, duration, chat session ID) | Logged automatically per session | Billing, usage tracking, dispute resolution |
2.3 Subscription & Purchase Data
| Data | How Collected | Purpose |
|---|---|---|
| Google Play purchase token, product ID, transaction ID | Provided by Google Play in-app purchase flow | Verify subscription, activate plan, detect fraud |
| Subscription status, plan type, expiry date | Stored by us after verification | Grant or restrict access to features |
| Talk-time balance and credits remaining | Calculated and stored by us | Enforce usage limits per subscription |
2.4 Usage & Performance Data
| Data | How Collected | Purpose |
|---|---|---|
| Assessment scores, fluency grades | Generated by AI after each session | Show your progress in the app |
| App feature usage patterns | Azure Application Insights (anonymous telemetry) | Improve app performance and UX |
| Error logs and crash reports | Azure Application Insights | Debug and fix issues |
| Heartbeat timestamps | Sent every 15 seconds during an active session | Detect connectivity loss, protect your usage credits |
2.5 Device & Network Data
| Data | How Collected | Purpose |
|---|---|---|
| Device ID, device name | Read from device on login | Identify your device for security and support |
| IP address | Captured at OTP request time | Rate-limit abuse, security audit trail |
| Firebase Cloud Messaging (FCM) token | Generated by Firebase on device | Send you push notifications |
| Platform (Android / iOS) and app version | Read from device | Version-specific support and update prompts |
2.6 Support & Feedback Data
| Data | How Collected | Purpose |
|---|---|---|
| Help and feedback tickets you submit | Entered by you in the Help / Feedback screens | Respond to your support requests |
3. Data We Do NOT Collect
- We do not collect your full name unless you provide it voluntarily in support tickets.
- We do not collect location / GPS data.
- We do not collect contacts, photos, or any files from your device.
- We do not record audio outside of an active AI conversation session.
- We do not sell your personal data to third parties.
- We do not use your data for advertising profiling.
4. Legal Basis for Processing (DPDP Act 2023 & IT Act 2000)
Under the Digital Personal Data Protection Act, 2023 (India), we process your data on the following bases:
| Processing Activity | Legal Basis |
|---|---|
| OTP login, account creation | Consent — given when you sign up |
| Voice processing during session | Consent — given when you press Start and grant microphone permission |
| Subscription verification | Contract — necessary to deliver the service you purchased |
| Usage logging, heartbeat, session tracking | Legitimate interest — protecting your purchased credits from fraudulent loss |
| Push notifications | Consent — you are prompted to grant notification permission |
| Crash / error reporting | Legitimate interest — maintaining service reliability |
You may withdraw consent at any time by contacting us at contactus@nanosmartx.com. Withdrawal will not affect processing already carried out.
5. How We Use Your Data
- Provide the service — authenticate you, run AI conversation sessions, enforce subscription limits.
- Process payments — verify Google Play purchases and activate your subscription plan.
- Protect your credits — detect session interruptions (app backgrounded, connectivity lost) and stop billing accurately.
- Show your progress — display assessment scores and session history within the app.
- Send notifications — inform you about session results, promotions, or important service updates (only with your permission).
- Improve the app — use anonymised telemetry to identify bugs and performance issues.
- Security and fraud prevention — rate-limit OTP abuse using IP and device signals.
- Support — respond to help and feedback tickets you raise.
6. Data Sharing & Third-Party Services
We share your data only with the following trusted processors to operate the service. All are bound by data processing agreements.
| Third Party | Purpose | Data Shared | Location |
|---|---|---|---|
| Microsoft Azure (Azure Table Storage, Azure App Service, Azure SignalR, Azure OpenAI, Azure Notification Hubs, Application Insights) | App hosting, AI processing, push delivery, analytics | Voice audio, transcripts, user ID, session data, device token | India (Central India region) |
| Google Firebase (Firebase Cloud Messaging) | Push notification delivery | FCM device token | Global (Google infrastructure) |
| Google Play (Google LLC) | In-app purchase verification | Purchase token, product ID, transaction ID | Global (Google infrastructure) |
We do not share your data with any other third party, advertiser, or data broker.
7. Data Retention
| Data Type | Retention Period |
|---|---|
| Account (phone / email, user ID) | Until you request deletion |
| Voice audio | Not stored — processed in real-time and discarded |
| AI conversation transcripts | 12 months from session date |
| Session usage logs | 12 months from session date |
| Assessment scores | 12 months from assessment date |
| Subscription records | 7 years (required for financial record-keeping under Indian law) |
| Support / feedback tickets | 2 years from ticket date |
| Push notification tokens | Until you log out or uninstall |
| IP address / OTP logs | 90 days |
| Crash / telemetry logs | 90 days |
After the retention period, data is permanently deleted from all storage systems.
8. Data Security
- Encryption in transit — all API communication uses HTTPS / TLS 1.2+.
- Encryption at rest — Azure Storage encryption (AES-256) is enabled by default.
- Authentication — short-lived JWT access tokens (renewed automatically) protect all authenticated API calls.
- Access control — backend APIs require valid JWT or internal API key; no anonymous access to user data.
- Rate limiting — OTP requests are rate-limited by email, IP address, and device ID to prevent brute-force abuse.
- Minimal data principle — voice audio is streamed and processed in real-time; it is never written to disk or stored.
No system is 100% secure. In the event of a data breach that poses a risk to you, we will notify you and the relevant authority as required under applicable law.
9. Microphone Permission
The App requests microphone access only for AI conversation sessions. The microphone is activated only when you explicitly start a session and is deactivated when you stop the session, navigate away, or background the app. We do not record or store raw audio.
You can revoke microphone permission at any time in your device settings. Doing so will prevent AI conversation sessions from functioning.
10. Push Notifications
We use Firebase Cloud Messaging (FCM) to send push notifications. You will be asked to grant notification permission when you first use the App. You can disable notifications at any time in your device settings or by contacting us.
11. Children’s Privacy
The App is intended for users aged 13 and above. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us personal data, please contact us at contactus@nanosmartx.com and we will delete it promptly.
12. Your Rights
Under the DPDP Act, 2023 and applicable Indian law, you have the right to:
| Right | What it means |
|---|---|
| Access | Request a summary of the personal data we hold about you |
| Correction | Ask us to correct inaccurate or incomplete data |
| Erasure | Request deletion of your account and associated personal data |
| Withdraw consent | Withdraw consent for any processing based on consent (e.g. notifications) |
| Grievance redressal | Lodge a complaint with our Data Protection Officer |
| Nomination | Nominate another person to exercise your rights in the event of your death or incapacity (as provided under DPDP Act) |
To exercise any of these rights, email us at contactus@nanosmartx.com with the subject line “Privacy Request”. We will respond within 30 days.
13. Data Protection Officer / Grievance Officer
In accordance with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the DPDP Act, 2023:
Grievance Officer
NanoSmartX Technologies Pvt Ltd
Email: contactus@nanosmartx.com
Website: https://nanosmartx.com
Response time: within 30 days of receipt of complaint
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we do:
- The “Last Updated” date at the top will be revised.
- If the changes are material, we will notify you via a push notification or an in-app alert.
- Continued use of the App after the updated policy is posted constitutes acceptance of the new terms.
15. Contact Us
For any privacy-related questions, requests, or complaints:
NanoSmartX Technologies Pvt Ltd
Email: contactus@nanosmartx.com
Website: https://nanosmartx.com
This Privacy Policy was prepared in accordance with the Digital Personal Data Protection Act, 2023 (India), the Information Technology Act, 2000, and the IT (Amendment) Act, 2008.
