Back

Nativia

Privacy Policy

Last updated: August 2, 2026

1.Controller and privacy contact

Luca Christ, sole proprietor
Haydnweg 24
69234 Dielheim
Germany

Phone: +49 162 7880802
Email: luca@creatare.de

2.Data processed by the app

2.1 Technical user identifier

At the start of onboarding, the app creates a user identifier from the current timestamp. It stores this identifier locally and uses it in Firebase Analytics and as a document identifier in Cloud Firestore. The app does not provide sign-in with an email address, password, or social account.

2.2 Onboarding and profile data

Depending on the information provided and how the app is used, Nativia processes:

  • the entered name and selected gender;
  • the app language, selected learning language or languages, and active learning language;
  • the selected country, city, or region;
  • starting and target level and self-assessments for comprehension, speaking, and grammar;
  • learning-method and story-mode preferences;
  • onboarding progress and a referral code;
  • premium status.

Some of this information is stored locally. The name and app language may also be stored in Cloud Firestore together with activity data. Learning language, country, region, level, self-assessments, and premium status are sent to Firebase Analytics as user properties.

2.3 Learning, progress, and game data

The app stores learning and usage progress locally and/or in Cloud Firestore, including:

  • chats, messages, AI context, help messages, topic, learning language, level, and selected conversation partner;
  • story, chapter, and scene progress, conversation history, scene summaries, and story memories;
  • known characters, story choices, items, and virtual balances;
  • XP, energy, completed chapters, message counts, and hints used;
  • learned, seen, and actively used words and assigned CEFR levels;
  • grammar and pronunciation scores and identified pronunciation errors;
  • timestamps relating to learning and game progress.

Cloud Firestore offline persistence is enabled. Firestore data may therefore also be held in the local app cache on the device.

2.4 Voice recordings and camera

The app requests microphone access for speaking exercises and conversations. Recordings are sent to Microsoft Azure Speech through endpoints in Western Europe to transcribe speech and assess pronunciation. Audio, the requested language/locale, and, for pronunciation assessment, a reference text are processed.

Nativia can use the camera for simulated video calls. The camera image is shown as a local preview. The app does not transmit the camera image to an external video service.

For speech output, the text and selected voice are sent to Microsoft Azure Text to Speech. Generated audio is temporarily cached in memory and in temporary files on the device. In some cases, the device's own text-to-speech service is used instead.

2.5 AI features

To generate replies, assess grammar and naturalness, continue stories, create summaries, and simulate calls, Nativia sends the following to external AI services:

  • typed or transcribed text;
  • extracts from earlier conversations or their summaries;
  • learning and explanation language, level, and regional context;
  • role, character, story, and scene information;
  • results and instructions required for assessment.

Nativia uses OpenAI and the paid Google Gemini API through Google AI Studio. Depending on the feature, content may be sent to these services separately or in parallel. Voluntary prompt and response sharing for Google model improvement is not enabled.

2.6 Translations

When a translation is requested or displayed, the AI-generated text and the source and target languages are sent to DeepL API Pro. The generated text may contain information from the conversation context and therefore personal data.

2.7 Analytics and activity data

Nativia uses Firebase Analytics. Events include session starts, ends and duration, viewed screens, time spent, navigation targets, onboarding steps and selections, the mode used, conversation identifiers, round and message counts, conversation duration, grammar and pronunciation scores, device language and country code, learning language, selected country and region, level, self-assessments, and premium status.

The analytics implementation technically supports logging shortened conversation, correction, or pronunciation text if explicitly enabled. No active use of this text transmission has been identified. The app also stores the latest activity timestamp, active seconds per day, and the most recently used mode in Cloud Firestore.

Firebase Analytics is activated only after express consent. Consent can be withdrawn at any time under “Settings → Privacy” or the corresponding localized label. Event data is retained for two months and user data for 14 months.

2.8 Crash reports

Nativia uses Firebase Crashlytics. Unhandled serious Flutter and asynchronous errors are reported with a stack trace. The SDK may add device and diagnostic information. Crashlytics is activated only after express consent and can be disabled together with Analytics in the app's privacy settings.

2.9 Push and local notifications

After notification permission has been granted, the app uses Firebase Cloud Messaging (FCM). The FCM token is stored in Cloud Firestore under the user identifier and updated when it changes. If no learning activity has taken place on a given day, Nativia may automatically send a reminder personalized using the daily activity status and story progress.

The app also schedules local streak and trial-period reminders. Push and local notifications are controlled through the operating system's notification settings; Nativia does not provide a separate in-app switch.

2.10 Purchases and subscriptions

Nativia uses RevenueCat and Apple's or Google's billing systems for in-app purchases and subscription status. RevenueCat uses an automatically generated anonymous App User ID. The app retrieves customer and entitlement information, restores purchases, and stores the active premium status locally. Payment-card data is not sent directly to a server operated by the controller.

2.11 Feedback

Free-form feedback is stored with its date and time in Firestore without a user identifier. Feedback is deleted three years after receipt. Relevant findings may first be transferred to internal tasks or bug descriptions without a user reference.

2.12 Network and device data

Communications with external services necessarily involve connection data such as IP address, timestamps, protocol information, and device information. Nativia also checks network status to indicate a missing connection. The app does not access location or contacts. The Android configuration removes the advertising-ID permission, and no advertising network is integrated.

3.Purposes and legal bases

Nativia processes data to provide personalized learning chats, stories and simulated calls; transcribe speech; assess pronunciation, grammar and naturalness; provide translations and speech output; store and synchronize progress; process subscriptions; analyze onboarding, usage and stability; send requested reminders; and process feedback.

Core app functions, AI processing, translations, speech processing, progress storage, purchases, and subscriptions are processed for contract performance under Art. 6(1)(b) GDPR. Legal retention obligations are based on Art. 6(1)(c) GDPR.

Firebase Analytics, Crashlytics, and notifications are used on the basis of consent under Art. 6(1)(a) GDPR. Technical security, abuse prevention, and feedback processing are based on legitimate interests under Art. 6(1)(f) GDPR. Support requests are processed for contract performance or on the basis of legitimate interests, depending on their content.

4.Recipients and external services

  • Google Firebase: Firestore, Cloud Messaging, Analytics, Crashlytics, Remote Config, Cloud Functions, and Storage;
  • OpenAI: generation and assessment of learning and conversation content;
  • Google Gemini: generation and assessment of story and conversation content;
  • Microsoft Azure Speech: speech-to-text, pronunciation assessment, and text-to-speech;
  • DeepL: translation;
  • RevenueCat: subscription and entitlement management;
  • Apple App Store / Google Play: purchase and subscription processing.

Cloud Firestore runs in the European multi-region eur3 and Cloud Functions in europe-west1. Firebase Storage runs in us-east1, but stores only general app content such as chapter thumbnails, not user uploads. Technical connection data is nevertheless generated when content is retrieved.

OpenAI is used through a paid API account without a special Zero Data Retention configuration. Gemini is used through paid Google AI Studio access, Azure Speech through a paid Azure subscription with Western European endpoints, and DeepL through API Pro.

Data processing agreements are in place with DeepL and RevenueCat. The relevant data protection terms form part of the contractual terms for Firebase, OpenAI, and Microsoft. Where data is processed outside the EEA, the transfer mechanisms stated in the providers' terms, particularly adequacy decisions or EU Standard Contractual Clauses, apply.

5.Permissions

  • Microphone: spoken answers and pronunciation exercises;
  • Camera: local self-view during simulated video calls;
  • Notifications: push and local reminders;
  • Internet/network status: communication with the listed services and connection status;
  • In-app purchases: subscription purchase and management.

Permissions can be managed in the device settings. A feature may be unavailable without the required permission.

6.Local storage

Nativia stores settings and status in Shared Preferences, including the user identifier, name, gender, languages, region, level, onboarding status, learning preferences, streak information, notification status, and premium status. The device may also contain the Firestore offline cache, temporary audio or TTS files, and small in-memory audio caches.

Acceptance of the Terms and Privacy Policy is stored only as a simple local status, without a timestamp or document version. Shared Preferences is not a dedicated secure-secret store, and no additional app-level encryption of these entries is implemented.

7.Retention and deletion

  • User, learning, chat, and progress data remains stored until deleted in the app or through “Delete Account.”
  • Firebase Analytics event data is retained for two months and user data for 14 months.
  • Feedback is deleted three years after receipt.
  • Support and privacy correspondence is deleted no later than three years after final handling, unless legal retention duties or legal claims require longer storage.
  • Local data generally remains until it is deleted in the app, the account is deleted, or the app is removed from the device.

Individual chats can be deleted from Cloud Firestore. “Delete Account” deletes the Firestore user document, known chat, story-progress, energy, chapter-session and inventory subcollections, and all Shared Preferences data.

The deletion function does not separately remove data held by Firebase Analytics, Crashlytics, RevenueCat, OpenAI, Gemini, Azure, or DeepL. It also does not expressly remove the FCM token from the FCM service, temporary files, or the Firestore offline cache. Provider retention rules additionally apply. RevenueCat data is currently not removed manually when an account is deleted.

8.Automated assessment

Nativia automatically assesses user text and speech to produce grammar, naturalness, and pronunciation scores, corrections, and personalized learning responses. For reminders, it also checks whether learning activity has occurred that day and may use story progress to personalize the notification. No churn score is calculated.

These assessments do not produce legal or similarly significant effects for users.

9.Data subject rights

Subject to the legal requirements, users have rights of access, rectification, erasure, restriction, data portability, and objection. Consent can be withdrawn at any time with effect for the future. Requests can be sent to luca@creatare.de.

Nativia does not use email sign-in, so an incoming email cannot be reliably linked to a pseudonymous app record. The controller will instead help users delete their data in the app. Individual chats and the known Firestore and local profile data can be deleted there. The app currently has no data-export function.

Learning languages, countries, and learning level can be changed in Settings. The name can be changed only by deleting the data and completing onboarding again.

Users may lodge a complaint with a supervisory authority. The competent authority for the controller is generally the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg.

10.Children

Nativia is rated USK 0. The app currently has no technical age check or procedure for verifying parental consent. Users under 16 should use Nativia only together with, or with the consent of, a parent or legal guardian.

11.Changes to this policy

This policy reflects the app and its configuration as of August 2, 2026. Changes to features, configurations, providers, or actual processing may require an update.