Skip to main content

Privacy Policy

Last updated: August 21, 2026

1. Data We Collect

Account Information

  • Email address (required for login)
  • Full name
  • Password (stored only as a hash, never in readable form)
  • Profile photo (optional)
  • Learning preferences (languages, levels)

Usage Data

  • Course progress and completion
  • Quiz scores and results
  • Daily mission submissions
  • Placement test answers and the level they produce
  • Time spent on platform
  • Device information (browser, OS)
  • IP address and location data

Payment Information

  • Billing address
  • Payment method details (processed securely by Stripe)
  • Transaction history

Communication Data

  • Messages sent to tutors
  • Community posts and comments
  • Event registrations
  • Customer support inquiries

Platform Activity Data

To run, protect, and improve NewWave Fluent, we process data about how you use the platform, including posts, comments, likes, follows and replies; tutor availability, bookings, completed sessions and events, reviews and ratings, cancellations and no-shows; reports about content or accounts and related moderation history; and technical data associated with your activity, such as IP address, browser/user-agent, device and operating-system information. Section 7 describes the separate, structured activity records we keep about how you move through the product.

Records of Agreement

When you accept our terms, policies, or tutor agreements, we may keep a record of which version you accepted and when, including the document version or identifier, a technical fingerprint or hash where used, the time of acceptance, and technical details such as your IP address and browser/user-agent. We keep these records for audit, legal-compliance, and dispute-resolution purposes.

2. How We Use Your Data

  • Provide and improve our language learning services
  • Process payments and administer paid services
  • Match you with appropriate tutors
  • Track your learning progress
  • Send you study reminders (if opted in)
  • Notify you about events and updates
  • Respond to customer support requests
  • Analyze platform usage to improve features
  • Comply with legal obligations

We use platform activity signals to operate discovery and ranking features, surface or restrict tutors, profiles, posts, sessions and events, protect learners and tutors, detect abuse or manipulation, moderate content and accounts, review tutor payout eligibility, and keep audit/compliance records.

  • Ranking, discovery and surfacing of tutors, profiles, posts, sessions and events
  • Reducing visibility of, or restricting, content that breaks our platform rules
  • Safety and moderation, and preventing abuse, fraud and manipulation
  • Reviewing tutor payout eligibility and protecting platform integrity
  • Keeping records of policy acceptance for audit and compliance

3. Data Storage, Security and Retention

Where your data is stored

Your account and platform data are held in a database hosted in the European Union (the Frankfurt region), operated for us by Supabase. The website itself is delivered through a content delivery network with servers in many countries, so the server that hands your browser a page receives your IP address. Section 10 explains what this means for international transfers.

Security Measures

  • Passwords are stored only as a salted hash by our authentication provider, never in readable form
  • Data transmitted via SSL/TLS encryption
  • Access controls limiting who can view your data
  • You stay signed in until you sign out; a stored session is not restored into a new browser session that did not establish it

Retention Period

  • Active account data: Retained while your account is active
  • Deleted account data: Permanently deleted within 30 days of account deletion
  • Payment records: Retained for 7 years per EU tax law requirements

We keep different categories of data for different periods, depending on why we need them. Account, booking, payment, payout, tax, legal-acceptance, moderation, audit and dispute records may be retained where necessary to provide the service, comply with legal obligations, resolve disputes, enforce our terms, and meet tax or accounting requirements. Where Dutch law requires a specific retention period, we follow that requirement.

4. Browser and Device Storage

NewWave Fluent keeps a small amount of information in your browser. Most of it is not a cookie: we use the browser storage areas called localStorage and sessionStorage. NewWave Fluent itself does not set any cookies. Third parties whose code runs in your browser may set their own cookies or storage — see sections 5 and 9.

We separate two kinds of storage. Necessary storage is what the service you asked for needs in order to work: keeping you signed in, protecting your sign-in against session-restore problems, recording the privacy choice you made, sending you back to the page you came from after signing in, and making sure you are served an up-to-date version of the site. Functional storage remembers a setting you deliberately chose, such as light or dark mode, reduced motion, high contrast, or your active learning language. Neither is presented to you as an optional tracking category, because neither is used for advertising or for profiling you across other websites. The optional categories are the two the banner asks about: External media, in section 5, and Visitor analytics, in section 7a.

One session-only record does not fit either description: when you tap through from a community post to the author’s profile, we store the identifiers of that post and author for up to 30 minutes so that the activity record described in section 7 can note where the visit came from. It contains identifiers only, never the text of the post.

Our Cookie Policy lists every item we currently store in your browser, with its exact name, what it is for, and how long it stays.

5. External Media

Some pages can show video and social media posts that are hosted by another company rather than by us. We call this External Media, and it is the one optional privacy choice on NewWave Fluent.

  • External Media is off by default. Nothing loads from a platform until you allow it.
  • It covers five platforms: YouTube, Vimeo, Instagram, TikTok and X. Each item is requested from that platform’s own embed address — YouTube from youtube-nocookie.com, Vimeo from player.vimeo.com, Instagram from www.instagram.com, TikTok from www.tiktok.com and X from platform.twitter.com.
  • One choice covers all five. There is no separate switch per platform, and no platform is contacted before you answer.
  • You can allow External Media once, for a single item, without saving anything; or allow it globally, which is stored as your choice until you change it.

When an embed does load, your browser connects to that platform directly. The platform can receive your IP address, information about your browser and device, the NewWave Fluent page the item is on, and how you interact with it. It may place its own storage on your device under its own privacy terms, which we do not control. We do not know what each platform stores or for how long, and we are not going to state figures they have not published.

Requesting YouTube video from youtube-nocookie.com uses what Google calls privacy-enhanced mode. Google states that a view in this mode is not used to personalise the viewer’s YouTube experience or advertising elsewhere. It does not mean that no data is transmitted to Google.

Refusing External Media costs you nothing. Every other part of NewWave Fluent works normally, the original link stays available so you can open the content on the platform’s own site, and refusing has no effect on your account, your lessons, or how you appear anywhere on the platform. If an embed you allowed fails to load, we show a short message and keep that original link, rather than leaving an empty space.

We asked everyone again in August 2026. An earlier version of this choice covered only YouTube and Vimeo, and said in as many words that Instagram, TikTok and X would not be embedded. Extending External Media to those three widens who receives your data, so a permission given under the old description is not carried over. Everyone who had answered before is asked once more, against the description on this page, and nothing loads from any of the five until that new answer exists. The stored record is versioned for exactly this purpose; it is currently at version 3.

You can change your mind. The banner asks the question once; after that, the single place the answer lives is Settings → Privacy, under “Privacy & external media”. That page requires a NewWave Fluent account, so a signed-out visitor who has already answered has to sign in to change it, or clear this site’s stored data in their browser, which makes the banner ask again. There is no cookie or privacy control in any footer, menu or page corner. One control does write the same setting: when External Media is off, a blocked embed offers Always allow external media, which turns it on globally in one press. That button only ever grants — it can never withdraw, and it is reachable only when you are signed in, because embeds only appear on signed-in pages. Turning External Media back off is Settings → Privacy, and nowhere else. Turning External Media off stops any new embed loading and removes embeds that are currently on screen. It cannot undo information a platform has already received from content you loaded earlier — for that you would need to contact the platform directly.

6. Where Embedded Content Comes From

Embedded and linked media on NewWave Fluent has three sources:

  • A public link shared by a community member. A member pastes a public URL into a post; we store the URL, not the video.
  • Content curated by a Language Lead or administrator. The same mechanism, used inside lessons and course material.
  • Media hosted by NewWave Fluent. Images and video uploaded to our own storage. These load from our own systems, involve no third-party provider, and are unaffected by the External Media choice.

In the first two cases the media stays hosted by the original provider. We embed or link to it; we do not copy it onto our own systems. The provider, or the person who published it there, can change, restrict or remove it at any time, independently of NewWave Fluent.

7. Activity Records We Keep

This section is about the records we keep, in our own database. We do not send them to an advertising network, and no third party receives them. There is exactly one third-party analytics service on this site — Apollo — it is off unless you turn it on, it receives nothing described in this section, and it has a section of its own: 7a.

These first-party records are not anonymous: each one is stored against your user account. Your answer to the Visitor analytics question does not affect them, because they never leave our systems; the section below says what does govern them.

These records are only written while you are signed in. If you are signed out, browsing the public site produces no such record.

The event families we currently record are:

  • Account and session events, such as sign-up and sign-in
  • Learning events, such as starting or completing a lesson, quiz or flashcard session
  • Navigation events, such as moving between the main areas of the platform
  • Community and discovery events, such as a post appearing in your feed, opening a profile from a post, or clicking a booking or event entry point on a profile
  • Booking and checkout events, such as choosing a lesson time, reaching the review step, or a payment step opening and completing
  • Tutor workspace events, such as opening a section of Tutor Studio, messaging a learner, or using a lesson, pricing or payout-setup control

Each record holds your user account identifier, the event name, the time, and a small set of fields. Those fields are identifiers, counts and short labels — for example a post identifier, an author or tutor identifier, a language name, a lesson count, or which route you arrived by. They do not contain the text of posts, comments or messages, your email address, your name, payment or card details, Stripe identifiers, or booking links.

We use these records to operate and debug the product, understand which parts of the service work, protect the platform against abuse and manipulation, and support the discovery and ranking features described in section 2.

7a. Visitor Analytics (Apollo)

This is off unless you switch it on. It is one of the two optional choices in the privacy banner, and it is off for everyone who has not answered, everyone who chose “Reject all”, and everyone who left it off in “Manage options”. While it is off, no script is loaded and no request is made.

Who receives what. Apollo.io, Inc., a business intelligence company in the United States, receives your IP address, the address of the page you opened, the site you arrived from, any campaign tags in the link you followed, and a random identifier stored in your browser. It does not receive your name, email address, account, lessons, messages, or anything you write here.

Why. To learn which organisations — schools, universities, employers — are looking at NewWave Fluent, so we can decide where to put our effort. Apollo does this by matching the IP address against its own records of which business uses which network. We are not trying to identify you personally, and we do not use it to build a profile of an individual learner.

One thing we block on purpose. Apollo’s script tries to load a second company’s script — LiveIntent — which resolves a hashed version of your email address from your activity on other websites and attaches it to what Apollo is told. We do not permit it. The address is excluded from this site’s content security policy, so your browser refuses the request and those fields are empty on every event. This is enforced by our configuration rather than by a setting on Apollo’s side.

Legal basis. Your consent, under Article 6(1)(a) GDPR, given through the banner or the Settings switch. It is the only basis we rely on for this, so withdrawing it stops the processing.

Transfer outside the EEA. Apollo is in the United States, so allowing this sends the information above there. We rely on your explicit consent for the transfer; you can withdraw it at any time, and doing so is what stops the transfer.

Withdrawing. Signed in, Settings → Privacy, under “Visitor analytics”. Turning it off stops any further information leaving the page and deletes the identifier Apollo stored in your browser. It cannot recall what Apollo has already received. Our Cookie Policy lists exactly what Apollo keeps in your browser and what a reload does.

Signed-out visitors. The Settings page needs an account. A signed-out visitor who has already answered the banner can withdraw by clearing this site’s stored data in their browser, which also deletes Apollo’s identifier and makes the banner ask again.

8. Legal Bases

Under the GDPR we rely on the following legal bases:

  • Performance of a contract. Creating and running your account, delivering lessons and courses, arranging and delivering booked sessions and events, taking payment, and providing support.
  • Legal obligation. Accounting and tax records, platform reporting duties, and responding to lawful requests.
  • Consent. Loading External Media from a third-party provider. This is the choice described in section 5, and you can withdraw it at any time.
  • Legitimate interests. Keeping the platform secure, preventing fraud, abuse and manipulation, moderating content, keeping the service working, and understanding how the product is used so we can improve it. We balance these against your rights, and you can object — see section 11.

Necessary browser storage is used because the service you requested cannot be delivered without it. Functional storage is written only when you actively choose the setting it records. We do not treat this as an absolute legal exemption for every item; the Cookie Policy states exactly what each item does so you can judge it for yourself.

9. Who Receives Your Data

We do not sell your personal data, and we do not share it with advertising networks.

One recipient in the list below is a marketing-data company, so that sentence deserves its limits stated rather than left to be assumed. Apollo is a sales-intelligence provider, not an advertising network: it receives no money from us for your data and we receive none for it, nothing goes to an ad exchange, and none of it is used to target advertising at you anywhere. It is also the only recipient here that needs your permission before it receives anything at all. Section 7a says what it gets and what we block it from getting.

Some providers receive data because our servers send it to them. Others receive data because your own browser connects to them while a page is loading. Both are listed below.

Providers our servers send data to

  • Supabase — database, file storage, authentication and server functions. Holds the account and platform data described in section 1.
  • Stripe — payment processing. Receives what is needed to take and reconcile a payment, including your email address and the amount.
  • Calendly — scheduling for tutor sessions. When you book, we send your name, email address, time zone and the time you selected.
  • Resend — sending transactional email. Receives the recipient address and the content of the message.

Providers your browser connects to

  • Vercel — hosting and delivery of the website itself. Receives your IP address and request details as part of serving you a page.
  • Supabase — the app talks to the database directly from your browser, so the same applies there.
  • Stripe — Stripe’s payment library is loaded from js.stripe.com, and only when you enter a payment flow: opening checkout or a payment screen. Browsing the site, reading these policies or looking at prices does not load it. Once it loads it sets two cookies of its own; the Cookie Policy names them.
  • YouTube (Google), Vimeo, Instagram (Meta), TikTok and X — only when you have allowed External Media, and only for the item being loaded. Each of the five is a conditional recipient in exactly the same way: nothing reaches any of them unless you allowed that load. See section 5.
  • Apollo — only when you have allowed Visitor analytics. Its script loads from assets.apollo.io and sends page visits to aplo-evnt.com, both Apollo’s. It receives your IP address, the page address, where you came from and a random identifier; never your account or anything you write. See section 7a.
  • LiveIntent — blocked, and listed so you can check. Apollo’s script attempts to load a further script from d-code.liadm.com to attach a hashed version of your email address to what Apollo is told. We do not allow that address to load, so LiveIntent receives nothing and is not a recipient. It is named here because you cannot verify a refusal you were never told about.

Our typefaces are served by us, from this website. Your browser does not request them from Google Fonts or any other font service, so no IP address is sent to a third party in order to display text on NewWave Fluent.

Google Meet

Tutor sessions are held on Google Meet. The meeting is created through Calendly using the tutor’s own connected calendar; NewWave Fluent does not send your data to Google for this. When you join a meeting, that is a direct connection between you and Google under Google’s own terms.

How the embeds actually work

For all five platforms we request the platform’s own embed page inside a frame. We do not load any of their scripts into NewWave Fluent pages, so nothing of theirs runs alongside our code, and closing the embed removes their frame entirely. What happens inside that frame is theirs, under their terms: they may store data on your device and we cannot read or delete it. Withdrawing consent stops further loading and removes what is on screen; it cannot reach back into what has already been sent.

We put a written data processing agreement in place with providers that process personal data on our instructions. We are reviewing the exact contractual status of each provider named above and will state it here once that review is complete; until then we do not claim a specific arrangement we have not verified.

10. International Transfers

Our database is hosted in the European Union. However, several of the providers listed in section 9 are established outside the European Economic Area or operate global infrastructure, so your personal data may be processed outside the EEA — for example when a content delivery network serves you a page, when a payment is processed, or when you load External Media.

Where that happens, the transfer must rest on a mechanism recognised under Chapter V of the GDPR, such as an adequacy decision or standard contractual clauses. We are verifying, provider by provider, which mechanism applies and where each one processes data. We will name the specific mechanism for each provider here once that verification is complete. We would rather say less than claim a safeguard we have not confirmed.

If you want to know the current position for a particular provider before then, email us at team@newwavefluent.com and we will tell you what we know.

11. Your Rights (GDPR)

Under GDPR, you have the right to:

  • ✓ Access: Request a copy of all data we hold about you
  • ✓ Rectification: Correct inaccurate personal data
  • ✓ Erasure: Request deletion of your account and data ("right to be forgotten")
  • ✓ Portability: Receive your data in a machine-readable format
  • ✓ Restriction: Limit how we process your data
  • ✓ Objection: Object to processing we base on legitimate interests
  • ✓ Withdraw consent: Turn External Media off again, and opt out of email communications, at any time

Withdrawing your External Media consent

  • Signed in: Settings → Privacy, under “Privacy & external media”. One switch, saved as you set it. This is the only place in the product that can turn External Media off.
  • Signed out: the answer you gave the banner stays in your own browser and cannot be edited from a public page. Sign in to change it, or clear this site’s stored data in your browser and the banner will ask again.
  • Turning it back on is easier than turning it off, and we would rather say so than not: signed in, any blocked embed offers Always allow external media in one press, while turning it off means opening Settings. Withdrawal is never more than one page away, but it is not one press.
  • Withdrawal stops future automatic loading and removes embeds currently on screen. It does not reverse processing a platform has already carried out.

To exercise any of these rights, email team@newwavefluent.com. We will respond within 30 days. You also have the right to lodge a complaint with a supervisory authority — for the Netherlands, the Autoriteit Persoonsgegevens.

12. Tax Reporting

Where legally required — for example under EU platform-reporting rules such as DAC7 — NewWave Fluent B.V. may collect, verify, retain, and report information about providers, such as tutors, and relevant transactions to the competent tax authorities. We only report where legally required.

13. Children and Young People

Paid tutoring and paid tutor events are for adults (18+). Free platform access is available from age 14; if you are under 18, you must have parental or guardian consent. Where Dutch data-protection law (AVG/GDPR) requires consent from a holder of parental responsibility for users under 16, we rely on that consent, and a parent or guardian may exercise the young person's data-protection rights where applicable.

14. Contact

Data Controller: NewWave Fluent B.V. (KvK 42030454, RSIN 869385501)

Email: tijnklinkhamer@newwavefluent.com

Business address: Suikersilo-West 9, 1165MP Halfweg, the Netherlands

Postal address: Derde Helmersstraat 53, 1054BD Amsterdam, the Netherlands

Supervisory Authority: Autoriteit Persoonsgegevens (AP), the Netherlands

Website: https://www.autoriteitpersoonsgegevens.nl