Last Updated: August 10, 2026

Effective Date: August 10, 2026 | Supersedes: Mar 2026

NOTICE FOR ENTERPRISE CUSTOMERS: Enterprise customers and their Authorized Users are also subject to the Immerse Enterprise Terms of Service and, where applicable, the Data Processing Addendum (the “DPA”) and, for smart-glasses use, the Glasses & Biometric Data Addendum. The DPA governs how Immerse processes personal data on behalf of enterprise customers and supersedes this Privacy Policy with respect to enterprise data-processing obligations. To the extent of any conflict between this Privacy Policy and the DPA in connection with enterprise data processing, the DPA controls.

Your privacy is important to us. This Privacy Policy (“Policy”) applies to services provided by Immerse Inc. (“we”, “us”, or “Company”) and our website, product pages, mobile or web applications, or other digital products that link to or reference this Policy (collectively, the “Services”). This Policy explains what information we collect from users (“you”), including Personal Information, and how we collect, use, disclose, retain, and protect it. It applies to any visitor to or user of our Services.

We may change this Policy at any time by posting a new version to our website and/or notifying the primary email address on your account. Changes are effective upon posting, and your continued use of the Services signifies your acceptance of the revised Policy. For any new category of sensitive-data or biometric collection (including Smart Glasses Capture Data described below), we will obtain your affirmative opt-in consent before such collection occurs. We encourage you to review this Policy periodically to stay informed about how we protect your information.

What Information Do We Collect?

In the course of providing the Services, we collect the following categories of information, which may include Personal Information:

Identifiers

First and last name, email address, username, postal address, phone number, IP address, country, time zone, and display name.

Commercial Information

Records of products or services purchased or subscribed to, including sales history and subscription history for the Services.

Voice Data

Voice data received through your device microphone. How your voice data is processed, stored, and shared depends on the context in which it is captured:

  • Public-room moderation. In certain public room instances we may perform limited processing of voice data for content-moderation and safety purposes. Any such recordings are anonymized and retained for no more than thirty (30) days, after which they are deleted. Voice data in private instances is not processed, stored, or sent to third parties except as expressly provided in this Policy.
  • Asynchronous lessons. When you complete asynchronous (non-real-time) lessons, your voice is transcribed and the resulting transcript is retained to deliver and personalize your learning. This processing includes the use of Langfuse observability tooling, which is processed in the European Union (Germany).
  • Pronunciation. Audio you submit for pronunciation assessment is processed by Microsoft Azure Speech and is not retained by default.
  • Capture (smart glasses). Voice captured through the Capture feature is handled as described in the "Captured Moments (Capture)" section below.

Captured Still Images

Still images created by the Capture feature. For each moment you capture, the Services create a single still image together with a transcript; no video is stored. Captured still images are stored locally on your device by default, and are stored on Immerse servers only if you enable cross-device sync or when a captured moment is turned into a lesson. See the "Captured Moments (Capture)" section below.

Sensory Data

Animation data derived from head movement and facial expressions, used to animate your avatar and facilitate immersive interaction. Any such sensory data is anonymized and retained for no more than thirty (30) days.

Neural and Biometric Data

Where you access the Services via VR hardware, we may process eye-tracking data, haptic response data, and spatial-intent data solely to facilitate immersive interaction within the platform. We do not sell this data and do not use it to profile you. This data is retained only for the duration of your session unless you provide explicit research consent.

Smart Glasses Capture Data

Where you use Immerse on smart glasses or similar wearable devices, the device camera and microphone provide camera imagery and audio to the application in order to power real-time, camera- and voice-aware coaching. No video is ever stored. For moments you choose to capture, what we keep is a still image and a transcript, handled as described in the "Captured Moments (Capture)" section and the "Captured Still Images" and "Transcription Data" categories. We use Smart Glasses Capture Data solely to provide and personalize your learning; we do not use it for advertising, and we do not sell it. Capture is off until you turn it on, and you can turn it off at any time in Settings.

Recordings

Instructor-initiated session recordings, which may include the video feed of your VR avatar, your first name, your voice data, and audio. Recordings are enabled with notice to participants and are used for internal training and academic research purposes.

Transcription Data

Data contained in transcriptions of your AI conversations and chat sessions, including the interaction content derived from asynchronous lessons and from Smart Glasses Capture Data.

Internet or Other Network Activity

Activity history collected through cache, cookies, and REST API calls during use of the Services, including search terms, pages viewed, and usage behavior.

Other Categories

Content you create and share publicly, survey responses, and any information you voluntarily provide to us.

Captured Moments (Capture)

Capture is an optional smart-glasses feature that lets you save real-world "moments" to power your language learning. Capture is user-initiated only: there is no background listening, and no video is ever stored. When you capture a moment, the Services create a single still image together with a transcript of the associated audio.

Captured moments are stored locally on your device by default. They are stored on Immerse servers only if you turn on cross-device sync, or when you turn a captured moment into a lesson. Real-time transcription for Capture is provided by Google (Gemini), which may retain inputs for up to fifty-five (55) days for abuse-monitoring purposes; your inputs are not used to train AI models. We do not sell Capture data, and we do not use it to train AI models.

Capture is not intended for sensitive or explicit content; we do not knowingly retain sensitive content; you can delete captured moments at any time. You agree not to use Capture to record sensitive, explicit, unlawful, or otherwise prohibited content, or to capture in any location where recording is not permitted.

You can review and delete your captured moments at any time.

Bystanders. You are responsible for the privacy of other people who may appear in captured content and for obtaining any consent required by the recording, wiretap, or privacy laws that apply where you are. Immerse does not run facial recognition and does not generate biometric identifiers from captured content.

Capture Involving Other People (Bystanders)

Smart-glasses capture may incidentally include people who are not Immerse users ("Third-Party Individuals"). Because Capture stores only a still image and a transcript of the moments you choose to save — and no video — incidental capture is minimized. Where any derived content references non-users, we minimize and de-identify that content, and we do not use it to identify anyone. Immerse does not run facial recognition and does not generate biometric identifiers from captured content.

You are responsible for using capture features lawfully. This includes obtaining any consent required by the recording, wiretap, or privacy laws that apply where you are, and not capturing in private or prohibited locations. Please use these features considerately and with respect for the privacy of those around you.

Artificial Intelligence, Biometric Data & Facial Recognition

Our platform uses artificial intelligence services provided by OpenAI, Google (Gemini), Deepgram, and Microsoft Azure Speech, among other providers. Asynchronous generation, evaluation, and text-to-speech tasks are routed through our own backend to the applicable provider. Before external processing, we exclude direct account identifiers (name, email, account ID) from text prompts. This applies to text only; visual content from Capture and audio processed for transcription or pronunciation cannot be filtered the same way.

None of our AI providers train on our data by default; your inputs are not used to train AI models. Retention of inputs for abuse-monitoring purposes differs by vendor: OpenAI retains inputs for up to thirty (30) days; Google (Gemini) retains inputs for up to fifty-five (55) days; and Deepgram and Microsoft Azure Speech do not retain inputs by default.

Real-time coaching is provided using Google (Gemini), and real-time speech-to-text is provided using Deepgram; these connect using short-lived tokens.

We do not perform facial recognition, and we do not use Capture Data to identify, verify, or profile any person. Where processing of voice or facial characteristics would constitute biometric data under applicable law, we process it only with your affirmative opt-in consent, only for the stated learning purpose, and only subject to the retention limits set out below.

The AI component of the Services is a machine-learning model and not a human operator. AI-generated content may be inaccurate and is provided for educational purposes only; it should not be relied upon as professional, legal, or medical advice.

From What Sources Do We Collect Personal Information?

Directly from You

  • At account registration, including your email, first and last name, and password, and including Meta-account login information if you choose to sign in with Meta.
  • Through contact records and correspondence with us.
  • Through instructor-initiated recordings, with notice when enabled.
  • Through crash reports, which may include DLLs, username, and memory-dump data.
  • Through your device microphone during voice chat.
  • Through your survey responses.

Device Permissions on VR Headsets

On Meta Quest and other VR headsets, the Services may access the following, where supported by your hardware:

  • Microphone, for voice chat (optional and able to be disabled).
  • Camera, to animate your avatar.
  • Eye-tracking and spatial sensors.

Device Permissions on Smart Glasses

On Meta AI glasses and similar wearables, using the device platform's wearables toolkit, the Services access the glasses camera and microphone to provide capture-based coaching. Capture is optional, off by default, and can be disabled at any time; the Services otherwise continue to function when capture is disabled.

Automatically

Information collected automatically through cache, cookies, and REST API calls during your use of the Services.

From Third Parties

We may receive information from third parties, including:

  • App-store platforms, including the Meta Quest / Horizon Store, Apple App Store, and Google Play Store.
  • Cloud-computing providers.
  • Payment platform providers.
  • Data-analytics providers.

A current list of sub-processors is available at immerse.com/legal/subprocessors.

How Do We Use the Information We Collect?

We use the information we collect for the following purposes:

  • To deliver, operate, maintain, and improve the Services and your user experience.
  • To protect against fraudulent, unauthorized, or illegal activity, and to maintain the security and integrity of the Services.
  • To analyze usage of the Services and to understand how the Services are used.
  • To communicate with you, including to send confirmations, invoices, notices, updates, and security alerts, and to respond to your comments and questions.
  • To provide customer and technical support.
  • In connection with a merger, acquisition, reorganization, or similar transaction.
  • To comply with legal obligations and to respond to legal process.
  • With your consent, or at your direction, for any other purpose disclosed to you at the time.

Smart Glasses Capture Data and Captured Moments are used solely to generate and personalize your learning content and to operate the capture features you enable. They are not used for advertising.

Legal Bases for Processing (GDPR Article 6)

If you are located in the European Economic Area or the United Kingdom, we process your Personal Information on one or more of the following legal bases, depending on the purpose:

  • Performance of a contract (Article 6(1)(b)). To create and administer your account, provide and maintain the Services, deliver lessons, and operate the Capture and other features you enable.
  • Consent (Article 6(1)(a); and Article 9(2)(a) for special categories). To process sensitive-data or biometric categories, to enable Capture, to use session recordings for research, and for other purposes for which we ask for your opt-in consent. You may withdraw consent at any time.
  • Legitimate interests (Article 6(1)(f)). To secure the Services and prevent fraud and abuse, to analyze and improve the Services, and to conduct analysis on aggregate or de-identified data, where such interests are not overridden by your rights.
  • Compliance with legal obligations (Article 6(1)(c)). To meet our legal, regulatory, tax, and record-keeping obligations and to respond to lawful requests.

Do We Share Your Personal Information?

We may disclose Personal Information in the following circumstances:

  • With our corporate affiliates and subsidiaries.
  • With third-party service providers and sub-processors, including database administrators, cloud-computing services, payment processors, and application providers.
  • To support audit, compliance, and corporate-governance functions.
  • In connection with a change of ownership, merger, acquisition, reorganization, or bankruptcy.
  • To detect, prevent, or protect against fraud or security issues.
  • To comply with legal obligations, respond to law-enforcement requests, protect our rights, protect user safety, or enforce our Terms of Service.
  • With your consent or at your direction.

We do not sell Personal Information, Capture Data, or biometric data. A current sub-processor list is available at immerse.com/legal/subprocessors.

How Do We Use Tracking Technologies?

Required Cookies

These cookies enable navigation and core service features. No opt-out option is available for these cookies.

Performance Cookies

These cookies collect usage information about which pages are visited most often, and are used only to improve the function and performance of the Services.

Functionality Cookies

These cookies allow the Services to remember information you have entered and choices you have made, providing enhanced and personalized features.

Targeting or Advertising Cookies

These cookies track usage and statistical information. Third-party cookies may track advertisement performance. For information about interest-based advertising and your choices, visit the Digital Advertising Alliance website at http://www.aboutads.info/.

How Do We Secure Your Personal Information?

We take reasonable steps to protect your Personal Information against unauthorized access, alteration, disclosure, misuse, or destruction, including through encryption, access controls, firewalls, and secure socket layer (SSL) technology. However, no method of data transmission or storage is guaranteed to be 100% secure. You should help protect your information by using a strong password, not sharing your password, and logging out after each session.

Data Retention

We retain Personal Information for as long as necessary to fulfill the purposes described in this Policy, subject to the following:

  • Identifiers and account data: retained for the duration of your account plus a reasonable period thereafter for legal and business purposes.
  • Voice and sensory moderation data: retained for no more than thirty (30) days.
  • VR neural and biometric data: retained for the session only, unless explicit research consent is provided.
  • Session recordings: retained for the duration of the course or program.
  • Transcription data (including interaction content from asynchronous lessons and from glasses capture): retained for the duration of your account unless deletion is requested.
  • Captured Moments (still images and transcripts): stored locally on your device by default, and on Immerse servers only if you enable cross-device sync or convert a moment into a lesson. Real-time transcription for Capture is provided by Google (Gemini), which may retain inputs for up to fifty-five (55) days for abuse-monitoring purposes. You can review and delete captured moments at any time.
  • Asynchronous lesson transcripts and observability (Langfuse): retained for the duration of your account unless deletion is requested; processed using Langfuse observability tooling in the European Union (Germany).
  • Pronunciation audio (Microsoft Azure Speech): not retained by default.
  • Aggregate and de-identified data: may be retained indefinitely, as it no longer constitutes Personal Information.

Enterprise retention is governed by the applicable Order Form and the DPA, which provide for deletion or return of Personal Data within thirty (30) days of termination.

Managing Your Privacy

You may review, update, correct, or delete the Personal Information in your account by contacting us at support@immerse.online or by accessing your user account. You may also delete derived Capture content, or withdraw your capture consent, at any time in Settings.

To cancel your account, contact support@immerse.online, and your personally identifiable information will be deleted or anonymized in a timely manner or as required by law. To stop receiving promotional communications, follow the opt-out instructions in those communications or contact support@immerse.online.

Your Rights Under Applicable Law

GDPR (EEA and UK Users)

If you are located in the European Economic Area or the United Kingdom, you have the following rights:

  • Right of access: to request a copy of the Personal Information we hold about you.
  • Right to rectification: to request correction of inaccurate information.
  • Right to erasure: to request deletion in certain circumstances.
  • Right to restriction: to request that we restrict processing.
  • Right to portability: to request a copy in a structured, machine-readable format.
  • Right to object: to object to direct marketing or to processing based on legitimate interests.

To exercise these rights, contact support@immerse.online. You may also lodge a complaint with your national data-protection authority.

LGPD (Brazilian Users)

If you are located in Brazil, you have the following rights under the Lei Geral de Proteção de Dados Pessoais:

  • Confirm the existence of processing of your Personal Information.
  • Access your Personal Information.
  • Correct incomplete, inaccurate, or outdated information.
  • Request anonymization, blocking, or deletion of unnecessary or excessive information.
  • Request portability to another service provider.
  • Request deletion of information processed on the basis of consent.
  • Obtain information about third parties with whom we share information.
  • Obtain information about the possibility of denying consent and the consequences of doing so.
  • Revoke consent at any time.

To exercise these rights, contact support@immerse.online. You may also lodge a complaint with Brazil's Autoridade Nacional de Proteção de Dados (ANPD).

CCPA / CPRA (California Users)

If you are a California resident, you have the following rights:

  • To know what Personal Information is collected, used, disclosed, and sold.
  • To delete Personal Information we have collected, subject to exceptions.
  • To correct inaccurate Personal Information.
  • To opt out of the sale or sharing of Personal Information (Immerse does not sell Personal Information).
  • To limit the use and disclosure of Sensitive Personal Information (the enterprise dashboard includes a link where applicable).
  • To not be discriminated against for exercising your privacy rights.

To exercise these rights, contact support@immerse.online or write to Immerse Inc., 2175 Tustin Ave, Costa Mesa, CA 92627.

Children Under 16

The Services are not directed to individuals under the age of sixteen (16), and we do not solicit or knowingly collect Personal Information from children under the age of sixteen (16). Because smart-glasses capture may incidentally include apparent minors, we minimize and promptly delete or de-identify such incidental content. If you believe we have unknowingly collected information from a child under 16, please contact support@immerse.online immediately so we can delete it.

Links to Third-Party Websites

The Services may contain links to other websites. We do not control these websites, which are subject to their own terms and privacy policies. We do not endorse and are not responsible for the availability, content, advertising, products, or materials on any third-party website.

How We Respond to Do-Not-Track Signals

We do not alter our practices when we receive a Do-Not-Track signal from your browser, because we do not track visitors across third-party websites for targeted-advertising purposes. For more information about Do-Not-Track signals, visit http://www.allaboutdnt.com.

International Users

The Services are controlled and offered from facilities in the United States, and data is stored and processed in the United States. Where we transfer Personal Information from the European Economic Area, the United Kingdom, or Switzerland to the United States or to another country that has not received an adequacy decision, we rely on an appropriate transfer mechanism under Article 46 of the GDPR (and equivalent UK and Swiss law), including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, or on an applicable adequacy decision. This is the same transfer basis we apply to enterprise processing. For enterprise customers subject to GDPR, LGPD, or other international data-protection regulations, international data transfers are governed by the DPA at immerse.com/legal/dpa, which implements appropriate transfer mechanisms including the Standard Contractual Clauses or the UK IDTA where required.

Contact Us

For general privacy questions: support@immerse.online

For data-protection requests, GDPR/LGPD inquiries, or to contact our data-protection team: support@immerse.online

For enterprise DPA inquiries: support@immerse.online