Julebu (julebu.ai) Privacy Policy

Last Updated: May 8, 2026

Effective Date: May 8, 2026

Julebu Labs, LLC ("Julebu," "we," "us," or "our") operates the Julebu English learning platform at https://julebu.ai (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Service.

Please read this Privacy Policy carefully. By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.

1. Information We Collect

We collect information in the following categories:

1.1 Information You Provide Directly

Data Category Examples Purpose
Account Information Email address, username, password, avatar image Account creation and authentication
Profile Information Display name, personal signature (bio), profile visibility settings Personalization and social features
Payment Information Billing details processed through Stripe, including payment confirmation, subscription status, customer/subscription identifiers, and billing portal activity where applicable (we do not store card numbers) Membership purchases, recurring subscription billing, cancellation support, refunds, and tax/accounting records
User-Generated Content Study group posts, comments, course reviews, dynamics, error reports, user feedback Community features and service improvement
Audio Data Voice recordings submitted for pronunciation practice (processed in real-time) Real-time speech evaluation via Microsoft Azure (no permanent storage)
AI Chat Messages Messages sent to the AI tutor, exercise context Generating AI-powered learning assistance (via Microsoft Azure)
Communication Data Support emails, feedback submissions Customer support and service improvement

1.2 Information Collected Automatically

Data Category Examples Purpose
Learning Activity Data Practice records, exercise completion, scores, session duration, attempt counts, mistake history, spaced repetition data Tracking learning progress, personalizing the learning experience, and powering the spaced repetition system
Device Information IP address, browser type and version, operating system, device type Security, rate limiting, and technical support
Usage Data Pages visited, features used, time spent, click patterns Service improvement and analytics
Cookie and Storage Data Session identifiers, user preferences, analytics tracking IDs Authentication, preferences, and analytics
Timezone Information IANA timezone string (e.g., "America/New_York") Displaying time-based content correctly

1.3 Information from Third-Party Sources

Source Data Purpose
Google OAuth Google account ID, email address, name, profile picture Account creation via social login
Stripe Payment confirmation, transaction status, subscription status, customer/subscription identifiers Processing payments, recurring billing, subscription management, cancellations, and refunds

2. How We Use Your Information

We use the information we collect for the following purposes:

2.1 Core Service Delivery

  • Providing and maintaining the English learning platform
  • Processing your exercises, tracking learning progress, and calculating spaced repetition schedules
  • Delivering AI-powered tutoring, grammar explanations, and pronunciation assessment (via Microsoft Azure)
  • Managing your account, authentication, and session security
  • Processing payments and managing Membership subscriptions

2.2 Service Improvement

  • Analyzing usage patterns to improve features and user experience
  • Identifying and fixing bugs, errors, and performance issues
  • Developing new features and educational content
  • Generating aggregate, anonymized statistics about platform usage

2.3 Communication

  • Sending service-related notifications (e.g., account security, membership status)
  • Responding to your support requests and feedback
  • Informing you about material changes to our Terms of Service or Privacy Policy

2.4 Safety and Security

  • Detecting and preventing fraud, abuse, and violations of our Terms of Service
  • Rate limiting and automated abuse detection
  • Content moderation to maintain community safety
  • Enforcing our Terms of Service

2.5 Legal Compliance

  • Complying with applicable laws, regulations, and legal processes
  • Responding to lawful requests from public authorities

3. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, we process your personal data based on the following legal grounds:

Legal Basis Examples
Performance of a Contract Providing the Service, managing your account, processing payments, delivering learning features
Legitimate Interests Improving the Service, analytics, fraud prevention, security, customer support
Consent Analytics cookies, marketing communications (where applicable)
Legal Obligation Responding to lawful requests, tax and accounting requirements

You may withdraw your consent at any time where consent is the legal basis for processing (see Section 8).

4. How We Share Your Information

We do not sell your personal information. We share your information only in the following circumstances:

4.1 Third-Party Service Providers

We engage the following categories of third-party service providers who process data on our behalf:

Service Provider Purpose Data Shared Privacy Policy
Stripe Payment processing and recurring subscription billing Email, order details, billing info, subscription/customer identifiers stripe.com/privacy
Google OAuth authentication Authentication tokens policies.google.com/privacy
Microsoft Azure Speech pronunciation assessment and AI chat/tutoring Audio recordings (processed in real-time, not stored), chat messages, exercise context privacy.microsoft.com
Plausible Analytics Privacy-friendly website analytics Anonymized usage events plausible.io/privacy
S3-Compatible Storage File storage (avatars, images) Uploaded files Provider-specific

All service providers are contractually obligated to process your data only as instructed by us and to maintain appropriate security measures.

4.2 Community Features

When you use community features (study groups, dynamics, reviews), your Content and profile information may be visible to other users based on your visibility settings:

  • Public: Visible to all users
  • Followers Only: Visible to users who follow you
  • Mutual Follows: Visible to users you follow who also follow you
  • Private: Visible only to you

4.3 Legal Requirements

We may disclose your information if required to do so by law or if we believe in good faith that such action is necessary to:

  • Comply with a legal obligation or valid legal process
  • Protect and defend our rights or property
  • Prevent or investigate possible wrongdoing in connection with the Service
  • Protect the personal safety of users of the Service or the public
  • Protect against legal liability

4.4 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our Service of any change in ownership or uses of your personal information.

5. Cookies and Tracking Technologies

5.1 Cookies We Use

Cookie Type Purpose Duration Legal Basis
Essential/Session Authentication, session management, security Session Necessary for service delivery
Functional User preferences, timezone, language settings Persistent Legitimate interest
Analytics Privacy-friendly usage analytics (Plausible) Session Legitimate interest (no personal data collected)

5.2 Local Storage

We use browser localStorage and sessionStorage for:

  • Storing user preferences and settings
  • Maintaining application state during your session
  • Analytics session identifiers

5.3 Your Cookie Choices

Most web browsers allow you to control cookies through their settings. You can set your browser to refuse all or some cookies, or to alert you when cookies are being set. Please note that if you disable essential cookies, some parts of the Service may not function properly.

5.4 Browser Extension

Julebu offers an optional browser extension (compatible with Chrome, Edge, and other Chromium-based browsers) to streamline your learning workflow. When installed, the extension accesses the following data, with the scope and purpose described below:

Data Source Purpose Access Trigger Transmission
Julebu authentication cookies (julebu.ai, julebu.co) Detect login state, identify region, maintain session When the extension popup is opened Used only for Julebu authentication. These cookies may be sent to Julebu API endpoints over HTTPS as part of authenticated requests, and are never sent to third parties by the extension
YouTube cookies (.youtube.com) — international users only Authenticate video extraction (via yt-dlp) when you import a YouTube video to a course pack Only when you start a YouTube import from the extension popup or from the official Julebu editor Sent over HTTPS to editor-api.julebu.ai for the current import job; encrypted and temporarily stored in Redis for up to 30 minutes, deleted after the job reads it or when the TTL expires, and never shared with third parties
Active tab URL Determine whether the current tab is a YouTube video page (to decide whether to show the import option) When the extension popup is opened Stays in the browser unless you start an import; the YouTube video URL is then sent to Julebu for the import job
chrome.storage.local Remember your selected region (cn / global) for faster popup loading After login Local to your browser only

YouTube Cookie Access (international users only)

YouTube import is available exclusively to Julebu international users (accounts on julebu.ai). The extension reads cookies for the youtube.com domain only when you start a YouTube import from the extension popup or from the official Julebu editor. The cookies are sent over HTTPS to editor-api.julebu.ai solely to authenticate the yt-dlp video extraction job. They are encrypted and temporarily stored in Redis for up to 30 minutes, deleted after the job reads them or when the TTL expires, never used for any other purpose, and never shared with third parties.

The extension performs no background sync, monitoring, or upload. All sensitive data access is gated by an explicit user action. You may stop this functionality at any time by:

  • Not initiating an import from the extension popup or the official Julebu editor
  • Uninstalling the extension, which immediately revokes its access to all browser data

The extension does not use eval(), does not load remote JavaScript, and does not include any analytics, ads, or tracking scripts.

6. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:

Data Category Retention Period Rationale
Account Information Duration of account + 30 days after deletion Account functionality
Learning Activity Data Duration of account Core service feature
Payment Records 7 years after transaction Legal/tax requirements
AI Chat Messages Duration of account Learning history
Audio Recordings Not stored - processed in real-time for pronunciation assessment only Real-time evaluation, no retention
Rate Limit / Security Logs 90 days Security and abuse prevention
Analytics Data 24 months (aggregated) Service improvement
User-Generated Content Duration of account or until deleted by user Community features

When your account is deleted, we will delete or anonymize your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., resolving disputes, enforcing our agreements).

7. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Transport Encryption: All data is transmitted over HTTPS/TLS
  • Password Security: Passwords are hashed using industry-standard algorithms
  • Access Controls: Role-based access with principle of least privilege
  • Rate Limiting: Tiered rate limiting strategies to prevent abuse and protect against denial-of-service attacks
  • Security Headers: HTTP security headers including HSTS, X-Content-Type-Options, X-Frame-Options
  • Input Validation: Server-side validation using schema-based validation
  • Regular Updates: Dependencies and infrastructure are regularly updated

While we strive to use commercially acceptable means to protect your personal data, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.

8. Your Rights

8.1 Rights for All Users

Regardless of your location, you have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your account and associated personal data
  • Data Portability: Request your data in a structured, commonly used, machine-readable format
  • Withdraw Consent: Withdraw consent at any time where consent is the basis for processing

To exercise these rights, contact us at [email protected]. We will respond within 30 days.

8.2 Additional Rights for EEA/UK Residents (GDPR)

If you are located in the European Economic Area or United Kingdom, you additionally have the right to:

  • Restrict Processing: Request restriction of processing of your personal data under certain circumstances
  • Object to Processing: Object to processing based on legitimate interests
  • Lodge a Complaint: File a complaint with your local data protection authority

Data Protection Authority Contacts:

We will respond to GDPR-related requests within 30 days. In complex cases, this period may be extended by an additional 60 days, and we will inform you of any extension within the initial 30-day period.

8.3 California Residents (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: You have the right to request information about the categories and specific pieces of personal information we have collected, the sources of collection, the purposes for collection, and the categories of third parties with whom we share personal information.
  • Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions.
  • Right to Correct: You have the right to request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.

Categories of Personal Information Collected (past 12 months):

CCPA Category Examples Collected Sold Shared for Advertising
Identifiers Email, username, IP address Yes No No
Personal Information (Cal. Civ. Code § 1798.80) Name, email Yes No No
Internet Activity Usage data, browsing history within the Service Yes No No
Geolocation IP-based approximate location Yes No No
Audio Information Voice recordings for pronunciation (processed in real-time, not stored) Yes No No
Inferences Learning progress, proficiency level Yes No No
Sensitive Personal Information Account login credentials Yes No No

To exercise your CCPA/CPRA rights, contact us at [email protected] or submit a verifiable consumer request. We will verify your identity before processing your request.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States, where our servers and some of our service providers are located. We ensure that appropriate safeguards are in place for such transfers, including Standard Contractual Clauses (SCCs) where required by applicable law.

By using the Service, you acknowledge that your information may be transferred internationally as described in this section.

10. Children's Privacy

10.1 Age Restrictions

The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. Children under 8 years of age are strictly prohibited from using the Service.

10.2 Parental Consent

For users between 13 and 18 years of age, we require parental or guardian consent before account creation. Parents or guardians who provide consent are agreeing to these Terms and this Privacy Policy on behalf of their child.

10.3 Parental Rights

Parents and guardians have the right to:

  • Review the personal information we have collected from their child
  • Request deletion of their child's personal information
  • Refuse further collection or use of their child's personal information

10.4 Our Commitments for Minor Users

For users under 18 years of age:

  • We collect only the minimum information necessary to provide the Service
  • We do not use minor users' data for commercial marketing purposes
  • We apply strict security measures to protect minor users' information
  • We do not share minor users' information with third parties without guardian consent, except as necessary to provide the Service

If you believe we have inadvertently collected information from a child under 13, please contact us immediately at [email protected], and we will promptly delete such information.

11. Do Not Track Signals

Some browsers transmit "Do Not Track" (DNT) signals. The Service currently does not respond to DNT signals. We use Plausible Analytics, which is a privacy-friendly analytics tool that does not track users across websites and does not use cookies for analytics purposes.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by:

  • Posting the updated Privacy Policy on the Service with a revised "Last Updated" date
  • Sending you an email notification at least 30 days before the changes take effect

Your continued use of the Service after the effective date of the revised Privacy Policy constitutes your acceptance of the changes. We encourage you to review this Privacy Policy periodically.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Julebu Labs, LLC

For privacy-specific inquiries, please include "Privacy" in the subject line of your email. We will respond to all inquiries within 30 days.

This Privacy Policy was last updated on May 8, 2026.