Lemmesa

Lemmesa Privacy Policy

Effective date: 26 August 2026. Last updated: 26 August 2026. Every statement below was checked against the Lemmesa code and our providers' published terms on 25–26 August 2026.

Lemmesa is a Spanish-reading app made by Montiel Systems LLC, a Florida limited liability company at 3612 W Granada St, Tampa, FL 33629, USA. Montiel Systems LLC is the data controller for everything described here. Questions, requests, and complaints: privacy@lemmesa.com.

This policy covers the Lemmesa website and app at lemmesa.com, the Lemmesa Chrome extension, and the waitlist.


1. The short version

  • We collect what you give us (your email, texts you upload or clip, questions you ask) and what the app records as you learn (which words you know, what you read, review results).
  • We do not sell your data. We do not share it for advertising. There are no ad trackers or session-recording tools in Lemmesa.
  • Text you read, upload, clip, or type into AI features is sent to Anthropic, our AI provider, to produce translations, explanations, and stories. Anthropic does not train on it and deletes it within 30 days. It never receives your name, email, or account ID.
  • The Chrome extension only works on YouTube, Netflix, Prime Video, HBO Max, Disney+, and pages where you press "Save". It never reads your streaming-service account, and it only captures a video frame or audio clip when you save a sentence.
  • Delete your account from Settings at any time. Deletion is immediate. Copies in backups and logs are gone within 30 days.

2. What we collect

Your account

  • Email address. Used to sign you in (we email you a sign-in link) and to reach you about your account.
  • Name and Google profile. If you sign in with Google, Google sends us your email and name. We store the name as your display name. We do not store your profile photo.
  • Settings. Reading and review preferences, your daily goals, and your time zone (read from your browser so that "today" means your day, not ours).
  • Level. The Spanish level you told us or that onboarding estimated.

We never store a password. Sign-in is by emailed link or Google.

What you read, import, and upload

  • Files you upload (.txt, .pdf, .epub). We extract the text and keep it as a private book on your shelf. We do not keep the original file; it is processed in memory and discarded. We keep the file name.
  • Web articles you clip with the extension. We keep the page URL, title, author, site name, and the full article text.
  • YouTube videos you save. We keep the video ID, title, channel, and the full caption transcript.
  • Podcast episodes you transcribe. We keep a private copy of the transcript.
  • Stories we write for you and texts we simplify for you, including the prompt you typed.
  • Interests you typed for the daily stories.

Everything in this section is private to you. Other users cannot see it.

Your learning activity

  • Which words you know, are learning, or looked up, and when.
  • Review results (ratings, timing, and the scheduling numbers that drive spaced repetition).
  • Reading and listening progress: what you read, how far, how many words, how long, and per-day totals.
  • Bookmarks, your reading queue, and decks you make.
  • Immersion log entries you add, including any note or link you type.

From the Chrome extension, while you watch

When you watch on Netflix, Prime Video, HBO Max, or Disney+ with the extension connected:

  • The subtitle track of what you are watching (the text and timing of every line), plus the title and episode label and the platform's ID for the title. This is sent to us so we can show you a dual-subtitle overlay and translations. See section 6 for exactly what leaves your device and what does not.
  • Watch activity (Netflix and Prime Video only): which subtitle lines were shown while you watched and how many seconds you watched, so words you saw count toward your knowledge and your immersion log.
  • Word taps in the subtitle overlay: the word and the line it appeared in.
  • Saved sentences ("mined cards"): the line, its translation, the word you chose, the title and episode, and — if capture succeeds — a cropped image of the video frame and a short audio clip (up to 15 seconds) of that moment. These are stored privately for you alone.

AI features

  • Questions you ask the tutor and the sentence you asked about, with the answer.
  • The sentences you asked to see in context, the stories you asked for, and the texts you asked to simplify.

Support and feedback

  • Messages you send through Settings → Help & feedback, with your email, the page you were on, and the app version.
  • Anything you email to hello@ or privacy@lemmesa.com.

Waitlist

  • Your email, your position, an optional answer to "What are you trying to read or watch in Spanish?", and — if you used "Find my level" — your estimated level.

Automatically, from your browser

  • Cookies that keep you signed in and remember your light/dark setting. See section 15.
  • Server logs. Like any website, our hosting provider records requests (IP address, browser type, the page or API address requested, time). We use these to keep the service running and detect abuse. Kept 1 day. See section 9.
  • Analytics. We use Vercel Web Analytics, which is cookie-free. It records page views with the page address, referrer, browser and device type, and approximate location (country, region, city). Visitors are counted using a hash that resets every day; Vercel states the data is anonymized and not tied to any individual or IP address. See section 7.
  • We do not use precise location, contacts, your microphone, or your camera.
  • Payments. Lemmesa is a paid subscription (US $15/month after a 7-day free trial; a card is required to start the trial). Payments are handled by Stripe. You enter your card details on Stripe's form; we never see your full card number. We receive and keep what we need to run your subscription: a Stripe customer ID, the card brand and last four digits, expiry, billing country and postal code, subscription status, and invoice history.

3. How we use your data, and why we're allowed to

If you are in the EU, UK, or another place with GDPR-style law, each use needs a legal basis. Here they are.

What we do Data involved Legal basis
Run your account and sign you in Email, name, settings, session cookies Performing our contract with you
Show you texts, track what you know, schedule reviews, compute how much of a text you'll understand Learning activity, imports, uploads Performing our contract with you
Store and show your imports, clips, uploads, and mined cards Content you added, captured frame and audio Performing our contract with you
Translate, explain, simplify, and write texts with AI Text you read or typed (see section 5) Performing our contract with you — these are features you turn on or invoke
Write your three daily stories each morning Your interests, due words, time zone Performing our contract with you
Run the extension's dual subtitles and sentence mining Subtitle track, watch activity, taps Performing our contract with you
Email you sign-in links, account notices, and replies to your messages Email Performing our contract with you
Bill and manage your subscription Stripe customer ID, subscription status, invoices Performing our contract with you; keeping invoices as long as tax and accounting law requires is a legal obligation
Keep you on the waitlist and email you about it Waitlist email and answers Your consent (double opt-in). Withdraw any time via the unsubscribe link in every waitlist email
Send marketing email (none today) Email Your consent, which you can withdraw with the unsubscribe link in every such email
Keep the service secure, rate-limit abuse, debug errors Server logs, feedback reports Our legitimate interest in running a safe, working service
Understand which pages are used Cookie-free, anonymized analytics Our legitimate interest in improving Lemmesa
Comply with law and respond to lawful requests Whatever is required Legal obligation

We do not make automated decisions about you with legal or similarly significant effects. The app does estimate your vocabulary level and schedule reviews; that only changes what it shows you.

4. What we don't do

  • We don't sell personal data.
  • We don't share it with advertisers or data brokers.
  • We don't use ad trackers, pixels, fingerprinting, or session recording.
  • We don't read your Netflix, Amazon, Disney+, HBO Max, YouTube, or Google account details.
  • We don't record you. The only audio we ever handle is the tab audio of a video you chose to save a sentence from, and public podcast episodes.
  • We don't let AI providers train on your data.

5. AI processing (Anthropic)

Lemmesa's translations, explanations, simplifications, and generated stories are produced by AI models from Anthropic, PBC (Claude models). To do that, we send text to Anthropic's API.

What is sent, by feature:

Feature What goes to Anthropic
Tutor ("Ask" on a word) Your question, the sentence you tapped, the word, up to four earlier questions and answers in the same conversation, the title of the text, and whether you already know the word
Context (sentence translation in the word popup) The sentence and the word you tapped
Word gloss when our dictionary has no entry The dictionary form of the word only
Create (stories) The brief you typed, the words you are currently reviewing, and, on retries, words the draft used that you likely don't know
Daily stories Your chosen interests, the words you are reviewing, and titles of recent stories written for you
Simplify The full text being simplified, in chunks — including a book you uploaded or an article you clipped
Extension: subtitle translation Every subtitle line of the episode or film, in batches
Extension: word gloss The subtitle line and the word you tapped

The sentences and texts above can come from books you uploaded, articles you clipped, videos you saved, podcast transcripts, and streaming subtitles — so private content you added does go to Anthropic when you use these features on it.

What is never sent: your name, email, account ID, IP address, or any captured image or audio. Requests are made from our servers with no user identifier attached.

Anthropic's handling. Under Anthropic's commercial terms, Anthropic may not train models on this content, and Anthropic deletes API inputs and outputs from its systems within 30 days, except where retention is required by law or the content is flagged for trust-and-safety review. Anthropic is a processor for us under a Data Processing Addendum. Links: Anthropic privacy policy, commercial terms, retention details.

What we keep. We keep tutor questions and answers, generated stories, and simplified texts in your account. Translations of individual sentences and of streaming subtitle tracks are cached so the same content is not translated twice. Sentence-level cache rows are tied to the account that first requested them and are deleted with that account. Subtitle-track translations are keyed to the subtitle content itself, contain no link to any user, and are not readable by users directly.

Some AI features run without a tap: the daily stories run each morning for accounts that use them, and subtitle translation starts when the extension loads a subtitle track. Turn off the extension's dual subtitles, or don't open the daily stories, and those calls don't happen.

6. The Chrome extension

This section is written to describe the extension completely, including for Chrome Web Store review.

What it is for. Saving YouTube videos and web articles to your Lemmesa shelf, and showing dual-language subtitles with sentence mining on Netflix, Prime Video, HBO Max, and Disney+.

Permissions and why:

Permission Why
storage Keeps your Lemmesa sign-in and your subtitle settings on your device (chrome.storage.local)
activeTab and scripting When you open the extension on an article page and press Save, it reads that page's text once. It does not run on pages you don't save
tabs Finds the video tab you are working in, and takes the frame screenshot when you save a sentence
tabCapture and offscreen Records the short audio clip of a sentence you saved (see below)
Host access: lemmesa.com, our Supabase database address Talks to your Lemmesa account. Nothing else
Runs on: www.youtube.com, www.netflix.com, www.primevideo.com, play.hbomax.com, www.disneyplus.com The five supported sites. The extension does not run anywhere else unless you open it and press Save

What it reads from those sites:

  • YouTube: the video's ID, title, channel, length, and its Spanish caption track, taken from the page and YouTube's caption service. Requests to YouTube are made from your own browser session, as if you loaded the captions yourself.
  • Netflix, Prime Video, HBO Max, Disney+: the subtitle track of the title you are watching, the title and episode label, the platform's ID for the title, and the playback position of the video. To get the subtitle track it watches the player's own network requests for subtitle files and fetches them the same way the player does. On Netflix it also adjusts the player's subtitle request so a text format is included.
  • It never reads your account name, profile, email, watch history, payment details, or cookies on any of these sites, and it never sends your platform login to us.

What leaves your device, and where it goes:

When What is sent To
You press Save on a YouTube video Video ID, title, channel, length, and the full caption transcript Your Lemmesa account
You press Save on an article The page URL, title, author, site name, and the article text Your Lemmesa account
A subtitle track loads on a streaming site (automatic) The full subtitle track, the title, episode label, and platform title ID, and your chosen translation language Lemmesa, which tokenizes it and sends the lines to Anthropic for translation (section 5)
While you watch on Netflix or Prime Video (every 60 seconds, automatic) Which subtitle lines were shown, and seconds watched Your Lemmesa account (word encounters and immersion log)
You tap a word in the overlay The word and its subtitle line Lemmesa, which asks Anthropic for a gloss
You press Add on a word The line, translation, word, title, episode, and timing Your Lemmesa account (mined cards)
After you press Add One cropped image of the video frame (JPEG) Your private media storage
After you press Add and press play yourself One audio clip of the line, up to 15 seconds Your private media storage

About the frame and audio capture. Capture happens only after you save a sentence. The frame is taken with Chrome's tab screenshot, cropped to the video area before it is uploaded; the full-tab screenshot never leaves the extension. The audio clip is Chrome's tab audio, recorded from just before to just after the saved line, capped at 15 seconds, and only while the video is playing that line. There is no microphone access, no screen recording, and no capture at any other time. Black or silent captures (DRM-protected playback) are discarded. Captured media is stored in a private bucket that only your account can read, served through short-lived links, and is never sent to Anthropic or any other AI provider.

What is read but never sent to us: the streaming service's internal device and session identifiers, subtitle and video file URLs, YouTube's API keys and page HTML, video playback state and page URLs, the on-screen captions Disney+ renders (used only to keep the overlay in sync), and article pages you don't save.

What it stores on your device: your Lemmesa session token, your subtitle settings, and the title of your last import, all in chrome.storage.local. Nothing else. It sets no cookies.

No remote code, no tracking. The extension contains all of its code. It loads nothing from the network at run time and includes no analytics or telemetry.

Signing in and out. You connect the extension from lemmesa.com, which hands it a one-time sign-in token. "Disconnect" in the extension popup signs it out. Deleting your Lemmesa account invalidates it.

Streaming subtitle text is shared content. Subtitle tracks and their translations are stored once per title, keyed to the subtitle text itself, not to you. That shared record contains the title and episode label and is readable only by our servers, never by other users. Which titles you watched is stored only in your own account data and deleted with it.

Google API Services. Lemmesa's use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.

7. Who we share data with (subprocessors)

We use these companies to run Lemmesa. Each is bound by a data-processing agreement and may use the data only to provide its service to us.

Provider What it does for us What it receives Their policy
Supabase, Inc. (US) Database, sign-in, and file storage. Our data lives in Supabase's US East (Virginia) region Everything in section 2, including your email, sign-in tokens, and captured frames and audio. Supabase's sign-in system also records IP address and browser type in its own audit log Privacy · DPA
Vercel Inc. (US) Hosts the website, the app's servers, our text-analysis service, and the daily story job; provides cookie-free analytics. US East (Virginia) region Every request to lemmesa.com: IP address, browser type, the address requested, and the request body (which is how uploads and typed text reach us). Analytics: anonymized page views (section 2) Privacy · Analytics privacy · DPA
Anthropic, PBC (US) AI models for translation, explanation, stories, and simplification The text described in section 5. No identifiers Privacy · Commercial terms · DPA
Resend (Plus Five Five, Inc., US) Sends our email Your email address and the content of emails we send you, including sign-in links (our sign-in system sends them through Resend). For feedback you send us: your email, message, page, and app version, which Resend delivers to our support inbox. Transactional emails carry no open or click tracking. Marketing emails, if we send them, use click tracking so we can see which links are used Privacy · DPA
Stripe (Stripe, Inc. / Stripe, LLC, US) Payment processing Your card details (entered on Stripe's form, never stored by us), name, email, billing address, the amount and date of each payment, and the device and IP information Stripe uses for fraud prevention. We receive back the customer ID, card brand, last four digits, expiry, and subscription status Privacy · DPA
Deepgram, Inc. (US) Speech-to-text for podcast episodes The public audio of podcast episodes you ask to transcribe — never your voice, your captures, or any identifier. Deepgram does not store the transcripts it returns Privacy
Google LLC (US) (1) "Sign in with Google"; (2) Google Workspace hosts our hello@ and privacy@ mailboxes; (3) YouTube video thumbnails (1) Google tells us your email and name when you sign in; (2) emails you send us and the feedback and waitlist notifications above sit in our Workspace inbox; (3) your browser loads thumbnails for saved videos directly from Google's servers, which see your IP address and the video ID, as when browsing YouTube Google privacy · Workspace DPA
Webshare Software (US) Network proxy our servers use to fetch YouTube captions when you save a video from the website (not the extension) The YouTube video ID being fetched. No user identifier, no cookies Privacy

Not our processors. When the extension fetches subtitles or captions on YouTube, Netflix, Prime Video, HBO Max, or Disney+, it does so inside your own browser session with that service, the same way the player does. Those services see the request as coming from you, under their own privacy policies. We receive nothing from those services about your account.

We may also disclose data if the law requires it, to protect Lemmesa or its users from harm, or to a successor if Montiel Systems LLC is sold or merged (we would tell you first, and this policy would still apply).

8. Where your data goes (international transfers)

Lemmesa runs in the United States. All providers above process data in the US (Supabase and Vercel in the US East, Virginia, region). If you use Lemmesa from the EU, UK, Switzerland, or elsewhere, your data is transferred to the US.

Transfers to our US processors rely on the European Commission's Standard Contractual Clauses (2021/914) with the UK Addendum or IDTA where applicable, or on the EU-U.S. Data Privacy Framework where the processor is certified. As of 26 August 2026, Vercel and Google are DPF-certified (EU, UK, and Swiss), and Stripe states in its privacy notice that Stripe, LLC complies with all three frameworks; Resend is certified for the EU and UK (re-certification under review); Supabase, Anthropic, Deepgram, and Webshare are not certified and are covered by Standard Contractual Clauses in their data-processing agreements. You can ask privacy@lemmesa.com for a copy of the relevant clauses.

9. How long we keep things

Data Kept
Your account and everything in it (section 2) Until you delete your account. There is no automatic expiry. Deletion is immediate; copies in database backups are gone within 7 days and everything is gone within 30 days
Waitlist signup Until you unsubscribe, delete a Lemmesa account with that email, or ask us to remove you
Support and feedback emails in our Workspace inbox Until no longer needed to handle your request
Invoices and payment records As long as tax and accounting law requires, even after you delete your account. Stripe keeps its own records under its policy
Server request logs (Vercel) 1 day
Database and sign-in logs (Supabase) 7 days
Database backups (Supabase) Daily backups kept 7 days
Email delivery logs (Resend) 30 days
AI inputs and outputs at Anthropic Deleted within 30 days
Analytics (Vercel Web Analytics, anonymized) 12 months
Shared caches: subtitle-track translations, dictionary glosses, single unrecognized words from tokenization Indefinitely. These are keyed to the content, hold no link to any user, and are not personal data

The Supabase and Vercel windows above are for the Pro plans we run on.

10. Deleting your data

Delete your account: Settings → Delete account, type DELETE, confirm. This runs immediately and cannot be undone. It removes:

  • your account, email, name, and settings;
  • your vocabulary, review history, reading and listening activity, and immersion log;
  • every text you uploaded, article you clipped, video you saved, transcript, story, and simplified text;
  • your mined cards and every captured frame and audio clip;
  • your tutor questions and cached sentence translations you were the first to request;
  • your feedback reports;
  • your waitlist signup for the same email.

It does not remove: the shared library; shared subtitle-track translations and dictionary glosses (not linked to you); copies of emails you sent us in our support inbox; invoices and payment records we must keep for tax law; and copies in provider logs and backups, which expire on the schedule in section 9. If you want support emails deleted too, say so at privacy@lemmesa.com.

Leave the waitlist: every waitlist email has an "Unsubscribe" link that deletes your signup — email, position, and answers — on one click. Mail apps that support one-click unsubscribe show their own button for it. If you no longer have the email, write to privacy@lemmesa.com from the address you signed up with.

Delete single items: you can remove individual mined cards (and their media), texts, imports, transcripts, decks, and log entries inside the app.

11. Your rights (GDPR and similar laws)

Wherever you live, you can:

  • Access your data. Settings → Export gives you a CSV of your vocabulary and mined cards (media and scheduling data are not included). For a complete copy of everything we hold, email privacy@lemmesa.com from your account email; we will send it to that address only, within one month.
  • Correct it. Your display name and settings are editable in the app. To change your email, contact us — self-service email change is not available yet.
  • Delete it. Section 10.
  • Take it with you (portability). The export above, or the full copy on request, in a machine-readable format.
  • Restrict or object to processing based on our legitimate interests (logs and analytics). Email us; note that we cannot run the service without basic request logs.
  • Withdraw consent for the waitlist or marketing at any time via the unsubscribe link. Withdrawing doesn't affect what was done before.
  • Complain to a data-protection authority. In Spain, that is the Agencia Española de Protección de Datos (aepd.es). In the EU, your local authority; in the UK, the ICO. We'd appreciate the chance to fix things first at privacy@lemmesa.com.

We answer requests within one month. We may ask you to confirm you control the account email. We will never ask for a password — we don't have them.

12. California residents (CCPA/CPRA)

Whether or not the CCPA applies to a company our size, we extend these rights to everyone in California.

Categories of personal information we collect (in the last 12 months): identifiers (email, name, account ID, IP address in logs); internet or network activity (pages requested, what you read and watched within Lemmesa, extension activity); audio and visual information (frames and audio clips you chose to capture); approximate location (country/region/city from cookie-free analytics — no precise geolocation); commercial information (subscription status and payment history — card numbers are held by Stripe, not us); inferences (your estimated Spanish level and which words you know); and the content you provide (uploads, clips, questions, feedback, waitlist answers). Sources: you, your browser, the extension, Google when you sign in with it, and Stripe when you pay. Purposes: section 3. Recipients: section 7.

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months. We do not sell or share the personal information of anyone under 16. We collect no sensitive personal information as defined by the CPRA beyond the account sign-in credential, which we use only to sign you in.

Your rights: to know what we collect and why; to delete it (section 10); to correct it (section 11); to opt out of sale or sharing (not applicable — we don't); and not to be discriminated against for exercising these rights. To exercise them, use the in-app tools or email privacy@lemmesa.com from your account email. An authorized agent may submit a request with your written permission; we will still verify with you.

13. Security

Data is encrypted in transit (TLS) and at rest by our providers. Database access is restricted per user by row-level security: the app's database policies only let your account read your own rows, and your captured media is in a private bucket keyed to your account. Sign-in uses one-time emailed links or Google; we hold no passwords. Our servers never log your email or content on purpose. No system is perfectly secure; if we learn of a breach affecting you, we will tell you and any regulator the law requires, without undue delay.

14. Children

Lemmesa is for people aged 16 and over. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has an account or waitlist signup, email privacy@lemmesa.com and we will delete it.

15. Cookies and local storage

Lemmesa sets no advertising or tracking cookies, and there is no cookie banner because none is needed.

Name What for Lasts
sb-…-auth-token (Supabase) Keeps you signed in Up to 400 days, or until you sign out
kissa-theme Remembers light or dark mode 1 year

The app also uses your browser's local storage for small, non-personal state (your Discover session plan, the Simplify queue, which tab is driving a job, and where you navigated from). The extension stores its session and settings in chrome.storage.local (section 6). Vercel Web Analytics uses no cookies.

16. Changes to this policy

When we change this policy we will post the new version at lemmesa.com/privacy and update the date at the top. If a change affects your rights or how we use your data in a material way, we will email account holders before it takes effect. Older versions are available on request.

17. Contact

Montiel Systems LLC 3612 W Granada St, Tampa, FL 33629, USA privacy@lemmesa.com


See also: Terms of service