Privacy Policy
Last updated: 25 July 2026
This policy explains what InputDojo collects, why, who it is shared with, and what you can do about it. InputDojo is operated by Ken Ryrbo (Sweden), who is the data controller for the purposes of the UK/EU GDPR. Questions go to support@inputdojo.com.
What we collect
Account and profile data you give us:
- Email address and password (passwords are hashed by our authentication provider — we never see them)
- Display name, chosen target language, learning goal, and whether you registered as a learner or a teacher
- Optional profile details: bio, avatar emoji, username, and whether your profile is public (off by default)
Learning data generated as you use the service:
- Content you import (text, URLs, uploaded PDFs and images, YouTube/Bilibili links) and the lessons created from it
- Saved vocabulary, highlights, notes, spaced-repetition review history, and which items you have marked as known
- Quiz answers, writing submissions, teacher grades and feedback, study plans, streaks and daily activity counts
- Usage counts for AI features and voice sessions, so we can apply plan limits
Technical data:
- Error reports (message, page, browser) when something breaks
- Product analytics events — which features are used, and session recordings and heatmaps via Microsoft Clarity (see “Analytics” below)
- Your IP address, used transiently for rate limiting on public endpoints
Student data in teacher-managed courses
This section matters most to schools, and we want it to be unambiguous.
When a student joins a course using a teacher's join code, that teacher can see that student's learning progress within the platform: vocabulary and characters marked as known, assignment and quiz results, writing submissions, reading activity, and engagement history. Teachers cannot see the student's password, and cannot see activity belonging to other teachers' courses.
Teachers can generate a read-only progress report link to share with a parent or guardian. That link contains a random token, shows only aggregate progress for that one student, and can be revoked by the teacher.
We do not sell student data. We do not use student data to train AI models. We do not serve advertising anywhere in InputDojo.
If your school requires a data processing agreement, or needs students onboarded without individual email addresses, contact support@inputdojo.com.
Children and age requirements
InputDojo is designed for independent learners aged 16 and over, and for younger students using it under the direction of a teacher or school. If you are under 16 and not using InputDojo through a school or teacher, please do not create an account without a parent or guardian's involvement.
Where a school or teacher enrols students, the school is responsible for obtaining any parental consent its jurisdiction requires. We will delete a student's data on request from the student, their teacher, or their parent or guardian.
Who we share data with
We use the following processors. Each receives only what it needs to do its job:
- Supabase — database, authentication and file storage. Holds essentially all account and learning data.
- Stripe — payments. Stripe handles your card details directly; we never receive or store them.
- Lovable AI Gateway (routing to Google Gemini models) — receives the text you ask us to process: lesson content for generation, grammar questions, writing you submit for feedback, words you look up.
- ElevenLabs and Simli — power AI conversation practice. They receive your microphone audio during a voice session.
- Supadata — fetches transcripts for YouTube links you import.
- Microsoft Clarity — product analytics, including session recordings.
- Lovable email — sends transactional email such as course invitations and assignment notifications.
Content you import from YouTube or Bilibili is loaded from those services, which apply their own privacy policies and may set their own cookies when a video is embedded.
Analytics and session recording
We use Microsoft Clarity to understand how people move through the app, which includes recordings of interactions with pages and heatmaps of clicks and scrolling. Clarity masks input field contents by default. We use this to find broken flows, not to monitor individuals.
If you would prefer not to be recorded, email support@inputdojo.com and we will exclude your account, and you can also enable Do Not Track or block clarity.ms in your browser.
How long we keep data
We keep your account and learning data for as long as your account exists. Delete your account and we remove your personal data and learning history; anonymised, aggregate counts may remain. Error logs and analytics events are retained for a limited period for debugging and then discarded.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your data, to object to or restrict processing, and to complain to a data protection authority. Exercise any of these by emailing support@inputdojo.com. We aim to respond within 30 days.
Security
Data is stored in Supabase with row-level security policies so that accounts can only read their own records, plus the specific teacher-to-student visibility described above. Payments run through Stripe and never touch our servers. No system is perfectly secure, but if we discover a breach affecting your data we will tell you.
Changes
If this policy changes materially we will update the date at the top and, for significant changes affecting how we use your data, notify account holders by email.

