NowLanguage Privacy Policy
Last Updated: October 13, 2025
NowLanguage LLC ("we," "our," or "us") is committed to protecting your privacy.
This Privacy Policy explains how we collect, use, disclose, and safeguard your
information when you use our mobile application and services.
This policy complies with US privacy laws including the California Consumer Privacy Act (CCPA)
and other applicable US privacy laws. It outlines our data processing practices, your rights, and how we protect your information.
1. Information We Collect
We collect information you provide directly to us, such as when you create an account, update your profile, or communicate with us. This includes:
- Personal identification information (name, email, phone number)
- Professional credentials and certifications
- Payment and billing information
- Session recordings and transcripts (when applicable)
- Communication preferences and settings
Bank Account Information (Stripe Financial Connections)
When you choose to pay via ACH (Automated Clearing House) or connect your bank account for payment purposes, we use Stripe Financial Connections, a secure third-party service, to access the following financial information:
- Bank account and routing numbers - Used to process ACH payments and direct deposits
- Account balances - Verified before transactions to ensure sufficient funds and reduce payment failures
- Transaction history - Used for payment reconciliation, revenue tracking, and matching deposits to invoices
- Account ownership details - Including account holder name and mailing address to verify ownership, prevent fraud, and accurately match payments to customer accounts
How We Protect Your Financial Data
Your financial account data is handled with the highest level of security:
- Processed securely through Stripe - All bank account data is encrypted and processed through Stripe's PCI-DSS compliant infrastructure
- Limited use - Financial data is used exclusively for payment processing, fraud prevention, and payment reconciliation
- Never sold or shared - We do not sell or share your bank account information with third parties for marketing or unrelated purposes
- Secure storage - Bank credentials are tokenized and stored according to banking industry security standards
- Compliance - We comply with all applicable financial data protection regulations including PCI-DSS, NACHA rules, and banking privacy laws
- You control access - You can disconnect your bank account at any time through your account settings
Important: When you connect your bank account through Stripe Financial Connections, Stripe acts as a service provider on our behalf. Your use of Stripe Financial Connections is also subject to Stripe's Privacy Policy.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process transactions and send related information
- Send technical notices and support messages
- Communicate about services, features, and policy changes
- Monitor and analyze usage patterns
- Detect and prevent fraud and abuse
3. Information Sharing
We do not sell, trade, or rent your personal information to third parties. We may share your information only in these limited circumstances:
- With your explicit consent
- To comply with legal obligations
- To protect our rights and prevent fraud
- With service providers who assist our operations
- In connection with a business transfer or acquisition
4. Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. This includes:
- Encryption of sensitive data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication measures
- Secure data centers and infrastructure
- Employee training on data protection
5. Session Confidentiality and Healthcare Information
We take special care to protect the confidentiality of interpretation sessions:
- Session content is encrypted and access is strictly limited
- Recordings are automatically deleted after specified retention periods
- Interpreters are bound by confidentiality agreements
- We comply with professional interpretation standards
- Client-interpreter privilege is respected and protected
HIPAA Compliance
For medical and healthcare interpretation services, we adhere to the Health Insurance Portability and Accountability Act (HIPAA) requirements:
- Protected Health Information (PHI) - We implement administrative, physical, and technical safeguards to protect PHI
- Business Associate Agreements - We enter into Business Associate Agreements with covered entities when required
- Minimum Necessary Standard - We limit access to PHI to the minimum necessary to provide our services
- Breach Notification - We have procedures in place to notify affected individuals and covered entities in the event of a data breach involving PHI
- Security Measures - We implement enhanced security measures for healthcare-related interpretation services
- Training - Our interpreters and staff receive HIPAA compliance training
6. Your Rights and Choices
Under US privacy laws, including the California Consumer Privacy Act (CCPA), you have the following rights:
- Right to know - You can request information about the personal data we collect about you
- Right to access - You can request a copy of the personal data we hold about you
- Right to deletion - You can request deletion of your personal data in certain circumstances
- Right to opt-out of sales - You can opt out of the sale of your personal information
- Right to non-discrimination - We will not discriminate against you for exercising your privacy rights
- Right to correct inaccurate information - You can request correction of inaccurate data
To exercise these rights, please contact us at privacy@nowlanguage.com. We will respond to your request within 45 days.
7. Data Retention
We retain your information for as long as necessary to provide services and comply with legal obligations:
- Account information: Until account deletion plus 7 years
- Session records: 30 days to 3 years depending on type
- Payment records: 7 years for tax and legal compliance
- Communication logs: 2 years for quality assurance
- Marketing data: Until you opt out or 5 years of inactivity
8. Data Storage and Processing
Your information is primarily stored and processed in the United States. We implement the following safeguards to protect your data:
- Encryption - We use industry-standard encryption for data at rest and in transit
- Access Controls - Strict access controls limit who can access your data
- Data Minimization - We only collect and retain data necessary for our services
- Regular Security Audits - We conduct regular security reviews of our systems
- Vendor Assessment - We evaluate third-party service providers for security practices
9. Children's Privacy
Our services are not intended for children under 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take steps to delete it promptly.
10. App Store Data Collection
In compliance with Apple App Store requirements, we disclose that our app may collect the following types of data:
- Contact Information (name, email address, phone number)
- User Content (audio/video recordings during interpretation sessions)
- Identifiers (user ID, device ID)
- Usage Data
- Diagnostics
- Location (with user consent)
- Payment Information (processed securely by payment providers)
This data is used to provide and improve our services, process payments, and ensure security. Data is not used to track users across apps and websites owned by other companies unless required for our specific service functionality.
11. AI Services and Data Processing
We use artificial intelligence (AI) technologies both for direct service delivery and for improving our translation and interpretation services. This includes:
- AI interpreters that may directly provide interpretation services alongside human interpreters
- AI-assisted human interpretation where AI tools support and enhance human interpreters
- Video analysis technology that processes video content to improve interpretation quality and accuracy
- Machine learning models to enhance translation accuracy and quality
- Voice recognition systems to improve speech-to-text capabilities
- Natural language processing for better language understanding
AI Processing and Service Delivery
We process data for both direct AI service provision and AI training in the following ways:
- Direct AI service provision - Your data is processed by our AI systems in real-time to deliver interpretation and translation services
- AI-assisted services - AI models may interact with your data to support human interpreters during service delivery
- Service improvement - We use data to improve the quality and accuracy of our AI services
- User consent - We obtain appropriate consent where required for using your data for AI interactions
How We Use Your Data for AI Services and Training:
- Real-time processing - Your conversations and content may be processed by AI models in real-time when using our AI interpretation services
- Video analysis - AI technology may analyze video content during interpretation sessions to improve accuracy and context understanding
- Service provision - AI models interact with your data to provide language interpretation and translation during active sessions
- Training and improvement - We use anonymized and pseudonymized data from interpretation sessions to improve our AI systems
- Data security - Personal identifiers are removed or encrypted before data is used for AI training
- Risk assessment - We conduct data protection impact assessments for AI processing that may pose high risks
- Security protocols - All data used in AI services or training is secured with strict access controls and encryption
- Third-party limitations - We do not share your raw session data with third-party AI providers without consent
- Quality assurance - Human review of selected anonymized samples may occur for quality assurance
- Data minimization - We only process what is necessary for each purpose
- Record keeping - We maintain records of all AI processing activities
Your Rights and Choices:
- You can withdraw consent at any time for processing based on consent
- You can opt out of having your data used for AI training by contacting us at privacy@nowlanguage.com
- Opting out will not affect the quality of services you receive
- You can request information about how your data has been used for AI purposes
- You can request deletion of your personal data in accordance with applicable US laws, though previously trained models may retain anonymized learnings
Automated Decision-Making and Profiling:
Our services may involve limited automated decision-making through AI to provide translation recommendations or match you with appropriate interpreters. These processes:
- Are necessary for service delivery but do not have significant legal or similar effects
- Can be overridden with human intervention upon request
- Are regularly tested for bias and accuracy
- Use only the minimum data necessary
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on our website and through the app. Your continued use of our services after such changes constitutes acceptance of the updated policy.