Privacy Policy
Last updated: June 26, 2026
Dylen ("we," "us," or "our") respects your privacy. This Privacy Policy describes how we collect, use, store, and protect your information when you use our Services. We are committed to transparency about our data practices and to minimising the data we hold.
1. Who We Are
The Services are operated by Dylen. For privacy-related inquiries, contact us at support@dylen.app.
2. Who Can Use Dylen
Dylen is intended for users aged 13 and older. We do not knowingly collect personal information from anyone under 13. If we become aware that a user under 13 has provided personal information, we will promptly delete it. Users must be at least 13 years old to create an account, and by completing onboarding you represent that you meet this requirement.
For users aged 13–17, Dylen maintains strict automated content generation filters that prevent the creation of sexual, graphic, politically inflammatory, or war-glorifying content. These filters remain active regardless of the topic requested, except where the subject matter is explicitly educational in nature — for example, history curriculum, civics education, or academic study of conflict and politics.
3. Information We Collect
We collect the following categories of information:
- Account Information: Name, email address, and authentication tokens necessary to provide and secure access to your account.
- Customer Content: Inputs, text, files, and prompts you submit to the Services for processing, including documents and web page content captured via the browser extension.
- Usage Data: Activity logs, timestamped events, IP addresses, and device identifiers used to monitor system performance, detect abuse, and improve the Services.
- Authentication Data: If you sign in via Google or another OAuth provider, we receive only the information you authorise at sign-in (typically your email address and display name).
- Source Library Content: Documents, PDFs, images, and web pages you choose to upload or import into your Source Library. This content is used solely to generate and enrich your learning experiences and is retained as described in §7.
We do not collect payment information directly. Payments, if applicable, are processed by third-party payment providers subject to their own privacy policies.
4. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Services.
- Process your content generation requests and return results to you.
- Monitor for security incidents, abuse, and policy violations.
- Communicate with you about your account, approvals, and service updates.
- Improve the reliability and quality of the Services.
- Comply with applicable legal obligations.
We do not use your Customer Content or generated lessons to train AI models.
5. AI Processing and Third-Party Models
To generate lesson content, your instructional inputs — the text prompts, topics, and files you submit for lesson generation — are processed by third-party AI providers. "Customer Content" in this context refers to this instructional material only. We do not include personal identifiers such as your name, email address, or account details in any prompts sent to AI providers.
Depending on the features you use, your instructional inputs may be processed by third-party infrastructure providers in the following ways:
- Content generation: Your topic, prompts, and source materials are processed by AI model providers to generate lesson and exercise content.
- Audio narration: Lesson text is transmitted to speech synthesis providers to generate audio narration. No personal identifiers are included.
- Illustration generation: Your topic and lesson context are transmitted to image generation providers to produce lesson illustrations.
- Document parsing: When you upload a PDF or document, its contents may be processed by a document extraction service to extract readable text.
- Web content enrichment: Your lesson topic or query may be transmitted to a web search service to retrieve publicly available content used to enrich lesson material. No personal identifiers are included.
By using the Services, you explicitly consent to the transmission of your instructional inputs to these external systems for the sole purpose of generating content on your behalf.
The AI providers we use have committed in their terms of service that customer API data is not used to train their models. Dylen itself does not use your content or generated lessons to train any AI model.
6. Live Conversation Practice
Certain lessons include a real-time conversational practice feature ("Live Call") in which you speak or type with an AI model in a defined scenario. During a Live Call session, the following data is collected and retained:
- Transcript: A text transcript of the conversation is generated and stored in your account for review after the session.
- Audio: Audio from the session may be recorded and stored in our cloud storage infrastructure for the duration permitted by your plan tier.
- Session metadata: Start time, duration, and the lesson scenario are recorded for quota management and account history.
Live Call sessions are capped at 30 minutes. Your voice and conversation content are processed by our AI infrastructure providers solely to conduct the session. This data is not used to train AI models.
You may review your session transcript from within the app. Audio and transcript data are deleted when your account is closed or when retention limits under your plan are reached.
7. Content Generation Filters
We employ automated and manual content moderation to enforce our Acceptable Use Policy. Content generation filters actively screen for and block prohibited content categories, including sexual, graphic, military, and political content. Detection of prohibited content may result in request blocking, content deletion, and account review.
These filters apply to all users. The scope of permitted educational content may vary by account tier and workspace configuration.
8. Data Retention
We enforce strict data lifecycle management:
- Uploaded Files (Temporary Processing): Files uploaded solely for a single lesson generation request are retained temporarily — approximately 24 hours — to perform the requested processing. After this period, they are automatically purged from our active processing storage.
- Source Library Content: Documents, PDFs, images, and web pages you explicitly save to your Source Library for indexing and reuse are retained for the duration of your active account or until you remove them. These are indexed and stored to enable retrieval across future lesson generation sessions.
- Generated Outputs and Lessons: Structured lesson content, JSON outputs, and associated metadata are retained to enable persistent access within your account. Retention rights and duration may vary by plan tier as described in our Terms of Service.
- Account Data: Retained for the duration of your active account. Upon account closure, we retain only what is required by law or for legitimate operational purposes.
9. Cookies and Local Storage
We use browser local storage and session storage to maintain your authentication state and user preferences. These are not advertising cookies and do not track you across third-party websites.
Our authentication system uses local storage tokens to keep you signed in between sessions. Clearing your browser's local storage will sign you out.
We do not use third-party advertising or analytics cookies.
10. Monitoring and Abuse Prevention
We employ automated scanning and may conduct manual review of activity to detect violations of our Acceptable Use Policy, including attempts to generate prohibited content or circumvent access controls. Detected violations may result in content removal, account restriction, or termination.
We maintain records of enforcement actions as required for operational and compliance purposes.
11. How We Share Information
We do not sell your personal information. We disclose information only in the following circumstances:
- Third-Party AI Providers: Customer Content is transmitted to AI model providers strictly for the purpose of generating content in response to your request.
- Infrastructure Providers: Cloud hosting and infrastructure providers who process data on our behalf under confidentiality obligations.
- Legal Compliance: If required by law, regulation, valid legal process, or to enforce our Terms of Service and protect the rights, property, or safety of Dylen, our users, or the public.
- Business Transfers: In connection with a merger, acquisition, or sale of all or substantially all of our assets, subject to standard confidentiality protections.
12. Security
We implement technical and organisational security measures appropriate to the nature of the data we hold, including encrypted data transmission (TLS/HTTPS), access controls, and authentication requirements.
However, no method of transmission over the internet is completely secure. We cannot guarantee the absolute security of information transmitted to or from the Services. You acknowledge that you provide Customer Content at your own risk and should not submit sensitive personal information (such as financial data, health records, government identifiers, or passwords) unless a specific feature requires it and you have a lawful basis for doing so.
13. Security Breach Notification
In the event of a data security breach that affects your personal information, we will notify affected users without undue delay and, where required by applicable law, within 72 hours of becoming aware of the breach. Notification will be provided via the email address associated with your account and/or through a prominent notice on the Services.
We will include in such notification: the nature of the breach, the categories of data affected, the steps we are taking to address it, and any recommended actions you can take to protect yourself.
14. International Data Transfers
The Services are hosted on distributed cloud infrastructure. Your information may be transferred to, stored, and processed in jurisdictions other than your own — including the United States and other countries — which may have different data protection laws than your jurisdiction. By using the Services, you consent to such transfers.
Any legal disputes related to privacy matters are subject to the jurisdiction described in our Terms of Service.
15. Third-Party Links
The Services may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before submitting any personal information to them.
16. Your Rights
You may have rights to access, correct, or request deletion of your personal data. To make a data request, contact us at support@dylen.app or use the feedback option within the app.
Account deletion is available on request — submit a deletion request via the in-app feedback option and we will process it within a reasonable timeframe. We may retain certain information as required by law or for legitimate operational purposes as described in this Policy.
17. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, the Services, or applicable law. Material changes will be communicated by updating the "Last updated" date at the top of this page. We will provide at least 30 days' notice before material changes take effect where reasonably practicable. Your continued use of the Services after changes become effective constitutes acceptance of the revised Policy.
18. Contact Us
For privacy-related inquiries: support@dylen.app