1. Account and Google sign-in
You can register with an email address and password or sign in with Google. Email registration uses verification codes; passwords are stored as hashes rather than readable passwords.
If you choose Google, we receive your Google account identifier, email address and verification status, name and profile picture URL through the openid, email and profile permissions. We use these to authenticate you, maintain your account and safely associate a verified existing account. A Google account identifier links future sign-ins to the same account and membership.
We store account and provider-link information in our server database. The authentication library may store OAuth tokens and token metadata. OAuth access and refresh tokens are encrypted; password hashes, identity tokens and session records use their respective authentication storage formats. Google credentials are kept on the server.
Google sign-in is optional. We do not request access to Gmail messages, Drive files, contacts or calendars. We do not sell Google account data, use it for advertising, or use it to train AI models. Account information may be processed by our hosting and database providers, and the account email may be used for transactional email or billing as described below.
2. Sessions, security and technical data
Signing in creates a server-side session and a browser cookie. Session information includes the account identifier, session timestamps, IP address and browser user agent. Infrastructure providers may also process connection details and request logs.
Cloudflare Turnstile processes browser and network signals to protect email registration, sign-in and verification-code requests. Our server checks its verification result. We use persistent request limits to reduce automated abuse and unwanted email sends. Limit counters use keyed hashes of identifiers, while login sessions and infrastructure logs can still contain IP addresses.
Security and billing checks can automatically reject or limit requests. Contact us if you think a restriction is incorrect. We do not use Google account data to make credit, employment or similarly significant eligibility decisions.
3. Lesson audio and text
When you start a live web lesson and grant the required browser permission, your browser sends selected audio directly to Soniox for transcription and translation. This audio does not pass through the Nelora application API. Nelora does not implement audio recording storage on its servers. Soniox processes the audio and text under its service policies; this policy does not promise that Soniox has no retention or training use.
If you enable lesson-text saving, confirmed text, translations and timing information are saved in the current account partition of this browser. Web saving is on by default for each new lesson and can be turned off before starting. Nelora does not upload saved transcript bodies to its own database or automatically sync them between browsers.
Our servers do store operational lesson data: account and browser identifiers, language and audio-source settings, start/end and connection times, status, provider connection references and usage/credit records. These are separate from transcript bodies.
You control what you capture. Only send audio that you are entitled to process, and inform or obtain permission from other speakers where required. Revoking microphone or sharing permission stops the corresponding browser capture.
4. Payments and membership
Stripe hosts payment collection and the customer portal. Nelora sends account/customer references and the details needed to create checkout or manage a subscription. Stripe may collect payment, billing and fraud-prevention information directly. Our application does not receive or store full card numbers or card security codes.
We store Stripe customer, checkout, subscription, invoice and payment references, amounts and currency, status, timestamps and related refund or dispute information. Membership grants, usage, reservations and audit records are held on the server to apply purchased credits, prevent duplicate grants and reconcile payments.
5. Service providers and disclosure
Providers receive the data needed for their role: Vercel for application hosting, Neon for the PostgreSQL database, Cloudflare for domain/security infrastructure and Turnstile, Resend for transactional email and delivery information, Google for optional Google sign-in, Stripe for payments and fraud controls, and Soniox for audio transcription and translation. Each provider also handles information under its own applicable terms and privacy notices.
Authorised operational access may be used to support you, investigate abuse, correct errors and manage billing. We may disclose information when required by law or to protect legal rights. We do not sell your personal data or use lesson text for targeted advertising.
Providers can process information outside France or the European Economic Area depending on their infrastructure. Applicable transfer terms and safeguards depend on the provider and service arrangement. Contact the privacy address for information about the processing locations and safeguards relevant to your data.
6. Why we process data
Account access, requested lessons, transactional messages and purchased membership are processed to provide the service you request and perform our agreement with you. Security, abuse prevention and service reliability rely on our legitimate interest in protecting users and the service. Relevant billing records may also be processed to meet legal obligations.
Google authorisation and browser audio permissions give you control over optional features; they do not authorise unrelated use of your information. Required account and payment information is needed to provide those features. You can read the public website without creating an account.
7. Cookies and browser storage
We use authentication, OAuth-state and locale cookies and browser storage needed for sessions, preferences and local lesson records. Signing out ends the current session, but it does not automatically erase saved lesson records in the browser.
You can delete individual local records or clear them in the records page, export supported text formats, and clear browser site data. Clearing site data can permanently remove local records and preferences. Nelora cannot restore a transcript that exists only in your browser. Blocking necessary cookies can prevent sign-in.
8. Retention
Account and provider-link data remains while the account exists. Authentication codes and sessions have expiry times; expiry prevents their use but does not itself guarantee immediate deletion of every database or infrastructure record.
Operational, security, usage and billing records are kept according to their continuing purpose, dispute and fraud-prevention needs, and applicable legal obligations. Current service operation does not include automatic age-based deletion of all account and billing records. Payment and lifetime eligibility history may need to remain after a subscription ends to prevent duplicate grants and preserve the audit trail.
Local lesson text remains until you delete it or the browser removes site data. Provider logs, backups and processing records are subject to the relevant provider arrangements. To request removal of server-side account data, contact us; deletion requests are reviewed with any records that must be retained by law or for a valid legal purpose.
9. Your choices and rights
Depending on the applicable law, you can request access, correction, deletion, restriction or portability of your personal data, and object to processing based on legitimate interests. You can withdraw optional authorisations for future use. Removing Nelora access in Google does not automatically delete the Nelora account, end every Nelora session or remove legal billing records.
Send requests to yusupturak@gmail.com from your account email where possible. We may ask for proportionate information to verify identity and protect the account. We respond within the applicable legal timeframe, normally one month; legally permitted extensions or refusal reasons will be explained. You may also complain to the French data protection authority, CNIL.
10. Updates and contact
The update date is shown on this page. Material changes to the use of Google account data will be disclosed before the new use and, where required, presented for renewed authorisation. For privacy questions, account-data requests or concerns about this policy, contact yusupturak@gmail.com.