Privacy Policy
Effective July 27, 2026
This policy describes the information Parrot Passport handles, including feed-usage and Stripe billing records, why we use it, and the choices and rights available to you.
1. Scope and who we are
This Privacy Policy applies to parrotpassport.com and the Parrot Passport language-learning service (the “Service”). Boost Open LLC, a Delaware limited liability company that operates Parrot Passport, is the controller of personal information described in this policy unless we say otherwise.
This policy does not cover third-party websites or services that we do not control. Contact us at privacy@parrotpassport.com with privacy questions or requests.
2. Information we collect
We collect the following categories of information:
- Account information: name, email address, password hash, account role, session records, password-reset records, and passkey public credentials and device metadata if passkeys are used. We do not store your plaintext password or private passkey.
- Learning activity: chosen language, level, goals, word lists, saved vocabulary, placement answers, story activity, practice responses, correctness, feedback, review schedules, progress, and time spent in learning activities.
- Free-allowance and billing records: the date of Feed use, seconds counted toward the daily allowance, the last usage heartbeat time, Stripe customer, Checkout Session, and subscription identifiers, subscription status, current paid-period end, cancellation-at-period-end status, and Stripe webhook event identifiers and types.
- Payment information handled by Stripe: when you open Stripe Checkout or the Stripe billing portal, Stripe may collect your name, email, billing details, payment-method information, transaction details, IP address, browser or device signals, and cookies or similar technologies. Parrot Passport does not receive or store your full card number or card security code.
- Content you provide: typed word lists, written responses, speech submitted for transcription, and YouTube URLs or other source information you ask us to import.
- Device and usage information: IP address or a one-way representation used for rate limiting, request identifiers, browser and device information, timestamps, security events, and diagnostic logs generated when you interact with the Service.
- Local device data: necessary session cookies and browser storage used for language, theme, onboarding, privacy choices, and similar preferences.
- Advertising information: if you opt in to optional advertising technology, Google and its partners may collect cookies, device identifiers, IP address, browser information, ad interactions, and related usage data.
3. Sources of information
We receive information directly from you, automatically from your browser or device, from your activity in the Service, and from providers involved in features you request. Stripe sends us subscription and payment-status updates through signed webhooks. If you import a YouTube video, we receive public video metadata and captions from YouTube or its delivery services.
4. How we use information
- provide accounts, authentication, password resets, learning content, imports, translations, speech transcription, feedback, review scheduling, and progress tracking;
- personalize the order and difficulty of learning activities;
- measure the five-minute daily Feed allowance, determine whether access is free or paid, create Stripe Checkout and billing-portal sessions, reconcile subscription status, and prevent duplicate webhook processing;
- operate, troubleshoot, secure, monitor, and improve the Service;
- detect abuse, enforce limits and policies, and protect users and our rights;
- send transactional messages such as password-reset emails;
- measure Service performance and understand feature usage in aggregated or de-identified form;
- show advertising only after the required privacy choice has been made; and
- comply with law, respond to valid legal process, and establish or defend legal claims.
5. Legal bases for processing
Where the European Economic Area, United Kingdom, or similar law applies, we rely on: performance of our contract to provide requested Service features; our legitimate interests in securing, maintaining, and improving the Service; consent for optional advertising technologies and where otherwise requested; and compliance with legal obligations. You may withdraw consent at any time without affecting earlier processing.
6. How we disclose information
We may disclose information to:
- infrastructure and delivery providers, including cloud hosting, database, object-storage, logging, and Amazon Simple Email Service providers;
- Stripe, which provides hosted Checkout, recurring billing, the customer billing portal, payment authentication, fraud prevention, and payment analytics. Stripe processes payment and device information under its own privacy policy at https://stripe.com/privacy; we send Stripe your account email and an internal user identifier when creating Checkout;
- feature providers when needed for a feature you request, such as YouTube for imports, configured translation providers, and AI or speech providers for transcription, response evaluation, translation, or content generation;
- Google and advertising partners only when optional advertising technology is enabled through your privacy choice;
- professional advisers, auditors, insurers, and authorities where reasonably necessary for legal, security, or compliance purposes; and
- a successor or participant in a proposed merger, financing, acquisition, reorganization, bankruptcy, or transfer of assets, subject to appropriate confidentiality protections.
We do not sell personal information for money. Optional advertising may involve disclosures that some privacy laws define as “sharing” for cross-context behavioral advertising. You can opt out at any time through “Privacy choices,” and we honor supported Global Privacy Control signals.
7. Data retention
We retain account, learning, daily Feed-usage, and subscription-status information while your account is active and as reasonably needed to provide the Service. Daily usage is stored by account and calendar date so we can enforce the allowance. Session and reset-token records expire according to their security settings. Import jobs, Stripe webhook event identifiers, security events, logs, and backups are retained for periods reasonably necessary to operate the feature, prevent duplicate processing or abuse, investigate incidents, meet legal obligations, resolve billing disputes, and maintain reliable backups.
When information is no longer needed, we delete, de-identify, or isolate it from active use. A deletion request may not remove information we must retain for security, legal compliance, fraud prevention, dispute resolution, or enforcing agreements. Backup copies may remain until overwritten through normal cycles.
Stripe keeps payment and transaction information under its own retention and legal obligations. Deleting Parrot Passport data does not automatically delete information controlled by Stripe; you may exercise applicable rights directly with Stripe as described in its privacy policy.
8. Your privacy rights
Depending on where you live, you may have rights to know or access personal information, correct it, delete it, receive a portable copy, restrict or object to processing, withdraw consent, and appeal or complain to a data-protection authority. You will not be discriminated against for exercising a privacy right.
You can permanently delete your account and active learning data from Account settings after confirming your password, but any non-terminal Stripe subscription must first be canceled or otherwise resolved and reach a canceled or expired state. Account deletion removes account-linked daily usage and subscription-status records from our active database. It may not remove Stripe-controlled payment records, webhook audit records that no longer identify your account, backups awaiting normal overwrite, or information we must retain by law. For other privacy requests, email privacy@parrotpassport.com from the address associated with your account and state the right you want to exercise. You may use an authorized agent where permitted. We may request information needed to verify identity and authority. We will respond within the period required by applicable law.
9. California privacy notice
In the preceding 12 months, we may have collected the categories described above: identifiers; commercial information such as subscription and transaction status; internet or electronic-network activity; account credentials; user-provided content; approximate location inferred from IP address; and inferences about learning level and preferences. We use and disclose these categories for the business purposes described in Sections 4 and 6.
We do not knowingly sell personal information for money. If optional ad technology is enabled, related disclosure of identifiers and network activity may be considered “sharing” under California law. Select “Use necessary only,” reopen “Privacy choices” to opt out, or enable Global Privacy Control. We do not knowingly sell or share personal information of consumers under 16.
California residents may request access, correction, deletion, or information about collection and disclosure, and may opt out of sale or sharing. Submit a request through privacy@parrotpassport.com. An online-only business may use this designated email method. We may verify access, correction, and deletion requests, but do not require identity verification for an opt-out.
10. International transfers
Boost Open LLC operates Parrot Passport from the United States. Information may be processed in the United States and other countries where our providers, including Stripe, operate. Where required, we use recognized transfer safeguards or another lawful transfer mechanism. Privacy protections in those countries may differ from those where you live.
11. Security
We use administrative, technical, and organizational safeguards designed to protect information, including hashed passwords and reset tokens, secure cookies in production, access controls, request validation, rate limiting, and security logging. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
12. Children
The Service is not directed to children under 13, and they may not create accounts or provide personal information. If you believe a child under 13 provided personal information, contact privacy@parrotpassport.com so we can investigate and delete it as appropriate. Users under the age of majority should use the Service only with a parent or guardian’s involvement.
13. Automated processing
The Service automatically recommends learning activities and estimates progress from learning interactions. These features affect lesson presentation, not legal or similarly significant decisions. You may contact us with questions about automated recommendations.
14. Changes to this policy
We may update this policy as the Service or law changes. We will post the new version, update the effective date, and provide additional notice when required. Material changes apply prospectively unless law permits otherwise.
15. Contact and complaints
Contact Boost Open LLC, operator of Parrot Passport, at privacy@parrotpassport.com. If European data-protection law applies, you may also lodge a complaint with the supervisory authority where you live, work, or believe a violation occurred.
