Skip to content

Privacy policy

Version 2026-09-21. This policy is available in English and Norwegian with the same content; if you spot a difference, tell us at privacy@hellomolo.com.

Molo is made by Hardmax AS. This policy says what we store about you, why, who receives it, where it is processed, and how to get it or delete it.

Controller: Hardmax AS, org. nr. 936 143 202, Brinken 19A, 0654 Oslo, Norway. privacy@hellomolo.com. We have no data protection officer.

What we store

  • Account: name, email address, the sign-in method you use and, if you sign in with Apple or Google, the identifier we receive from them (see "Signing in"). Passwords are stored as hashes we cannot read. You must give a name and an email address to have an account; without them we cannot provide Molo. At registration we check your birth year and country of residence and, when needed, whether you have reached the minimum age this year. We keep a yes/no record that you meet the age requirement and your country selection (Norway, South Africa or another country) to determine whether web purchases are available. The birth year and birthday confirmation are discarded. You can optionally choose a league display name and opt out of leagues in Settings.
  • Learning: which exercises you did, your answers' correctness and time, review schedules, XP, streaks, hearts, league membership and rank, and your settings (language, daily goal, listening and speaking modes, preferred voice, reduced motion). Your league display name and rank are visible to the other learners in your weekly league (up to 20 people). The display name defaults to your first name; you can change it in Settings. You can also opt out of leagues there, which removes you from the current league immediately without losing learning progress.
  • Reminders: if you turn on streak reminders we store a push-notification token for your device, its platform and app version, and send reminders through Expo's push service to Apple or Google. Turn reminders off in Settings and we delete the token.
  • Recordings you make: speaking exercises are scored on your device; the audio is discarded and never leaves your phone. Only the result is stored with your learning data. Editors and speakers who record for the course work under a written agreement with us and receive their own privacy notice.
  • Reports you send us: if you report an exercise, we store your report text with your account id.
  • Purchases: if you buy Molo Plus, the seller (Apple, Google or, on the web, Hardmax AS through RevenueCat and Stripe) handles payment; we receive the subscription status, the store, and a subscription identifier assigned by RevenueCat, which we store with your account — never card details. We use RevenueCat's dashboards to see aggregate subscription statistics. We also retain your express-start request, purchase details, any withdrawal notice and refund reference for the accounting and refund period described below; abandoned checkout requests are removed after 30 days.
  • Technical: error and crash reports (Sentry, hosted in the EU) containing the device model, operating system and app version, and the app's state at the time of the error. The IP address of the request is discarded on receipt and never stored. They are not linked to your name or email. We do not use advertising or tracking SDKs and we do not sell or share your data for advertising.

Signing in

You can sign in with an email address and password, with Sign in with Apple, or with Google. When you use Apple or Google, we receive only your name, your email address and a provider identifier that lets us recognise your account; we do not receive your Apple or Google password, and we do not post to or read anything in those accounts. If you choose Apple's "Hide My Email", Apple gives us a relay address ending in privaterelay.appleid.com that forwards to you. We use it only to send you our own account and receipt emails; Apple lets you stop forwarding at any time in your Apple Account settings, in which case our emails will not reach you until you give us another address. Accounts are matched by verified email address or by the provider identifier; if you sign in with a different method that uses a different address, a second account may be created. When you delete your account we also revoke the Sign in with Apple authorisation held for it.

Who receives your data

Our processors, who act only on our instructions under data-processing agreements: Cloudflare (hosting and edge network — US company, servers worldwide including South Africa), PlanetScale (database in London; US company), Sentry (error reports, EU region; account metadata in the US), Resend (email — US company; sent from an EU region, records stored in the US), Expo (push delivery, US) and RevenueCat (subscription status, US). Acting on their own behalf under their own privacy policies: Apple, Google and Stripe when you buy Molo Plus or sign in with Apple or Google. Other learners in your weekly league see your league display name and rank. The current list of providers, where each processes data and the safeguard we rely on is at hellomolo.com/privacy/providers.

Why we use your data, and our legal basis (behandlingsgrunnlag)

  • To run the course you signed up for — your account (including name and email, or Apple's relay address, from Apple or Google sign-in), your password hash, your exercise attempts, review schedule, XP, streaks, hearts, settings and, if you subscribe, your Molo Plus status: this is necessary to perform our contract with you (GDPR Art. 6(1)(b)).
  • To run weekly leagues. If you take part, your league display name and rank are visible to other learners in your league. This is part of the service you have chosen (Art. 6(1)(b)); you can opt out at any time in Settings.
  • To send streak reminders as push notifications, only if you turn them on in Settings: your consent (Art. 6(1)(a)). Turn them off there to withdraw it. Allowing notifications in your phone's settings alone does not start reminders. We do not use reminders to sell you anything.
  • To find and fix errors and keep Molo secure and fair — error reports and abuse checks such as rate limiting and detecting cheating or harassment in leagues: our legitimate interest in a working, secure service and in protecting other learners (Art. 6(1)(f)). You can object (see Your rights).
  • To handle reports you send about an exercise and improve the course: our legitimate interest in accurate content (Art. 6(1)(f)). Please do not put personal information in the report text.
  • To keep purchase records after you delete your account, for five years after the end of the financial year, because Norwegian bookkeeping law requires it (bokføringsloven § 13; Art. 6(1)(c)). These are the transaction records our payment providers and our accounts hold, not your learning data.
  • Editors and speakers: we process editors' and speakers' names under our agreement with them (Art. 6(1)(b)); they receive their own privacy notice.

You may object to processing based on our legitimate interests, and to any direct marketing, at any time.

Where your data is processed

We are based in Norway. Your account and learning data are stored in a database hosted in the United Kingdom (PlanetScale on AWS, London). The United Kingdom is covered by a European Commission adequacy decision (Decision (EU) 2025/2574, valid to 27 December 2031), so no additional safeguard is needed for storage there.

Some of our providers are established in the United States or run global networks. When we transfer personal data to them we rely on (a) the EU–US Data Privacy Framework, where the provider is certified (you can check the list at dataprivacyframework.gov), and/or (b) the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), together with our assessment of the laws of the destination country. Our app runs on Cloudflare's global network, so requests are processed in the Cloudflare data centre nearest to you — for users in southern Africa that includes South Africa — under the Standard Contractual Clauses in our agreement with Cloudflare. Error reports (Sentry) are stored in the EU, except account metadata held in the US; transactional emails (Resend) and subscription records (RevenueCat) are stored in the US; push notifications are delivered through Expo (US) to Apple and Google.

The current list of our providers, the country each processes data in, and the safeguard we rely on for each is at hellomolo.com/privacy/providers. You can ask for a copy of the Standard Contractual Clauses we have signed by emailing privacy@hellomolo.com.

How long

Account and learning data: until you delete your account. When you delete your account we remove your data from our live database immediately and from backups within 30 days; the offline copy on your device is wiped when you delete the account in the app. Error reports: 90 days. Push tokens: until you turn reminders off or delete the account. Reports you send us: until handled, and at the latest 12 months after. Purchase records: five years after the end of the financial year in which you bought, because Norwegian bookkeeping law requires it (bokføringsloven § 13).

Cookies and storage on your device

Molo sets no advertising or analytics cookies and no third-party cookies, so we do not show a cookie banner. We store on your device only what is needed to run the service you asked for, which the Norwegian Electronic Communications Act (ekomloven § 3-15) allows without consent:

  • Web: a session cookie that keeps you signed in; browser storage (localStorage) holding your interface language and reduced-motion setting; and a cache of published lessons and audio so pages load quickly and work offline.
  • iOS and Android apps: an encrypted local database with your lessons and review queue for offline use, and — only if you turn reminders on — a push-notification token.

Nothing here is used to track you across other sites or apps. If we ever add analytics, we will ask for your consent first and you can say no without losing any feature.

How we protect your data

We protect your data with encryption in transit (TLS), passwords stored only as salted hashes, an encrypted offline cache on your phone (SQLCipher), a database hosted in London (UK) with automatic backups, application code that runs on Cloudflare's network in the data centre nearest you, access limited to named accounts, and error monitoring hosted in the EU. No system is perfectly secure; if a breach is likely to put you at high risk we will tell you and notify the regulator (Datatilsynet, and the Information Regulator for South African users) as the law requires.

Your rights

You can ask us to: see the personal data we hold about you (access); correct it (rectification); delete it (erasure); limit how we use it while a question is resolved (restriction); and receive the data you gave us in a machine-readable file or have it sent to another service where technically feasible (portability). You can object at any time to processing based on our legitimate interests, and to any direct marketing, and you can withdraw a consent (for example to reminders) at any time in Settings without affecting the lawfulness of what we did before. We do not make decisions about you based solely on automated processing that have legal or similarly significant effects; review scheduling and league placement are automated but only change what you see in the course. In Settings you can download everything we hold in JSON and delete your account yourself; you can also request deletion at hellomolo.com/delete-account without installing the app. For anything else write to privacy@hellomolo.com and we answer within one month. If you think we handle your data unlawfully you can complain to Datatilsynet (datatilsynet.no) or, if you live in another EU/EEA country, to the supervisory authority where you live.

If you are in South Africa

The Protection of Personal Information Act (POPIA) applies to how we handle your personal information. Hardmax AS is the responsible party; our Information Officer is Jakob Malmo, reachable at privacy@hellomolo.com or by post at Hardmax AS, Brinken 19A, 0654 Oslo, Norway. Our PAIA manual is available on request at the same address. Giving us your name, email and password is required to have an account; learning data is required to run the course; reminder notifications are optional. Your data is stored in the United Kingdom and processed by providers in the EU and the United States; the UK and EU have laws giving protection substantially similar to POPIA, and our US providers are bound by written agreements requiring equivalent protection. Other learners see your league display name in weekly leagues; you can change it or opt out in Settings. You may object to processing based on our legitimate interests and to any direct marketing at any time, and you may ask us to correct or delete your information. Reminder notifications are service messages about your own progress; we do not send marketing by push, SMS or email to South African users unless you separately opt in, and every marketing message will tell you how to stop it. In South Africa, anyone under 18 is a child under POPIA; Molo is for adults (18+) in South Africa because we do not yet collect the parent's or guardian's consent that POPIA requires. You may lodge a complaint with the Information Regulator (South Africa): Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191; POPIAComplaints@inforegulator.org.za; 010 023 5200.

Children

Molo is for learners aged 13 and over, and 18 and over in South Africa, where anyone under 18 is a child under POPIA and we do not yet collect the parent's or guardian's consent POPIA requires. If you believe a child below the minimum age has an account, email privacy@hellomolo.com and we will delete it.

Changes

We will announce material changes in the app and by email before they take effect.