Privacy Policy

Privacy Policy — Fluento

Effective Date: 17 August 2026
Last Updated: 17 August 2026
Developer: NanoSmartX Technologies Pvt Ltd
Contact: contactus@nanosmartx.com
Website: https://nanosmartx.com


1. Introduction

NanoSmartX Technologies Pvt Ltd (“we”, “us”, “our”) operates the Fluento mobile application (the “App”) available on Android and iOS. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and your rights under applicable law — including the Digital Personal Data Protection Act, 2023 (DPDP Act) of India.

By installing or using the App, you agree to the practices described in this policy. If you do not agree, please uninstall the App and contact us to request deletion of any data already collected.


2. Data We Collect

2.1 Account & Identity Data

Data How Collected Purpose
Mobile phone number or email address Entered by you during OTP login Account identification and authentication
One-Time Password (OTP) Generated and verified by our backend Verify your identity at sign-in
User ID (system-generated) Created on first login Link all your data records internally

2.2 Voice & Conversation Data

Data How Collected Purpose
Voice / audio input Microphone (only while a session is active and you have pressed Start) Processed in real-time by Azure AI for English speaking practice
AI conversation transcripts Generated during each session Display chat history, save session logs, enable assessment
Session metadata (start time, end time, duration, chat session ID) Logged automatically per session Billing, usage tracking, dispute resolution

2.3 Subscription & Purchase Data

Data How Collected Purpose
Google Play purchase token, product ID, transaction ID Provided by Google Play in-app purchase flow Verify subscription, activate plan, detect fraud
Subscription status, plan type, expiry date Stored by us after verification Grant or restrict access to features
Talk-time balance and credits remaining Calculated and stored by us Enforce usage limits per subscription

2.4 Usage & Performance Data

Data How Collected Purpose
Assessment scores, fluency grades Generated by AI after each session Show your progress in the app
App feature usage patterns Azure Application Insights (anonymous telemetry) Improve app performance and UX
Error logs and crash reports Azure Application Insights Debug and fix issues
Heartbeat timestamps Sent every 15 seconds during an active session Detect connectivity loss, protect your usage credits

2.5 Device & Network Data

Data How Collected Purpose
Device ID, device name Read from device on login Identify your device for security and support
IP address Captured at OTP request time Rate-limit abuse, security audit trail
Firebase Cloud Messaging (FCM) token Generated by Firebase on device Send you push notifications
Platform (Android / iOS) and app version Read from device Version-specific support and update prompts

2.6 Support & Feedback Data

Data How Collected Purpose
Help and feedback tickets you submit Entered by you in the Help / Feedback screens Respond to your support requests

3. Data We Do NOT Collect

  • We do not collect your full name unless you provide it voluntarily in support tickets.
  • We do not collect location / GPS data.
  • We do not collect contacts, photos, or any files from your device.
  • We do not record audio outside of an active AI conversation session.
  • We do not sell your personal data to third parties.
  • We do not use your data for advertising profiling.

4. Legal Basis for Processing (DPDP Act 2023 & IT Act 2000)

Under the Digital Personal Data Protection Act, 2023 (India), we process your data on the following bases:

Processing Activity Legal Basis
OTP login, account creation Consent — given when you sign up
Voice processing during session Consent — given when you press Start and grant microphone permission
Subscription verification Contract — necessary to deliver the service you purchased
Usage logging, heartbeat, session tracking Legitimate interest — protecting your purchased credits from fraudulent loss
Push notifications Consent — you are prompted to grant notification permission
Crash / error reporting Legitimate interest — maintaining service reliability

You may withdraw consent at any time by contacting us at contactus@nanosmartx.com. Withdrawal will not affect processing already carried out.


5. How We Use Your Data

  • Provide the service — authenticate you, run AI conversation sessions, enforce subscription limits.
  • Process payments — verify Google Play purchases and activate your subscription plan.
  • Protect your credits — detect session interruptions (app backgrounded, connectivity lost) and stop billing accurately.
  • Show your progress — display assessment scores and session history within the app.
  • Send notifications — inform you about session results, promotions, or important service updates (only with your permission).
  • Improve the app — use anonymised telemetry to identify bugs and performance issues.
  • Security and fraud prevention — rate-limit OTP abuse using IP and device signals.
  • Support — respond to help and feedback tickets you raise.

6. Data Sharing & Third-Party Services

We share your data only with the following trusted processors to operate the service. All are bound by data processing agreements.

Third Party Purpose Data Shared Location
Microsoft Azure (Azure Table Storage, Azure App Service, Azure SignalR, Azure OpenAI, Azure Notification Hubs, Application Insights) App hosting, AI processing, push delivery, analytics Voice audio, transcripts, user ID, session data, device token India (Central India region)
Google Firebase (Firebase Cloud Messaging) Push notification delivery FCM device token Global (Google infrastructure)
Google Play (Google LLC) In-app purchase verification Purchase token, product ID, transaction ID Global (Google infrastructure)

We do not share your data with any other third party, advertiser, or data broker.


7. Data Retention

Data Type Retention Period
Account (phone / email, user ID) Until you request deletion
Voice audio Not stored — processed in real-time and discarded
AI conversation transcripts 12 months from session date
Session usage logs 12 months from session date
Assessment scores 12 months from assessment date
Subscription records 7 years (required for financial record-keeping under Indian law)
Support / feedback tickets 2 years from ticket date
Push notification tokens Until you log out or uninstall
IP address / OTP logs 90 days
Crash / telemetry logs 90 days

After the retention period, data is permanently deleted from all storage systems.


8. Data Security

  • Encryption in transit — all API communication uses HTTPS / TLS 1.2+.
  • Encryption at rest — Azure Storage encryption (AES-256) is enabled by default.
  • Authentication — short-lived JWT access tokens (renewed automatically) protect all authenticated API calls.
  • Access control — backend APIs require valid JWT or internal API key; no anonymous access to user data.
  • Rate limiting — OTP requests are rate-limited by email, IP address, and device ID to prevent brute-force abuse.
  • Minimal data principle — voice audio is streamed and processed in real-time; it is never written to disk or stored.

No system is 100% secure. In the event of a data breach that poses a risk to you, we will notify you and the relevant authority as required under applicable law.


9. Microphone Permission

The App requests microphone access only for AI conversation sessions. The microphone is activated only when you explicitly start a session and is deactivated when you stop the session, navigate away, or background the app. We do not record or store raw audio.

You can revoke microphone permission at any time in your device settings. Doing so will prevent AI conversation sessions from functioning.


10. Push Notifications

We use Firebase Cloud Messaging (FCM) to send push notifications. You will be asked to grant notification permission when you first use the App. You can disable notifications at any time in your device settings or by contacting us.


11. Children’s Privacy

The App is intended for users aged 13 and above. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us personal data, please contact us at contactus@nanosmartx.com and we will delete it promptly.


12. Your Rights

Under the DPDP Act, 2023 and applicable Indian law, you have the right to:

Right What it means
Access Request a summary of the personal data we hold about you
Correction Ask us to correct inaccurate or incomplete data
Erasure Request deletion of your account and associated personal data
Withdraw consent Withdraw consent for any processing based on consent (e.g. notifications)
Grievance redressal Lodge a complaint with our Data Protection Officer
Nomination Nominate another person to exercise your rights in the event of your death or incapacity (as provided under DPDP Act)

To exercise any of these rights, email us at contactus@nanosmartx.com with the subject line “Privacy Request”. We will respond within 30 days.


13. Data Protection Officer / Grievance Officer

In accordance with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the DPDP Act, 2023:

Grievance Officer
NanoSmartX Technologies Pvt Ltd
Email: contactus@nanosmartx.com
Website: https://nanosmartx.com
Response time: within 30 days of receipt of complaint


14. Changes to This Policy

We may update this Privacy Policy from time to time. When we do:

  • The “Last Updated” date at the top will be revised.
  • If the changes are material, we will notify you via a push notification or an in-app alert.
  • Continued use of the App after the updated policy is posted constitutes acceptance of the new terms.

15. Contact Us

For any privacy-related questions, requests, or complaints:

NanoSmartX Technologies Pvt Ltd
Email: contactus@nanosmartx.com
Website: https://nanosmartx.com


This Privacy Policy was prepared in accordance with the Digital Personal Data Protection Act, 2023 (India), the Information Technology Act, 2000, and the IT (Amendment) Act, 2008.