Last Updated: August 10, 2026
Effective Date: August 10, 2026 | Supersedes: March 2026
NOTICE FOR ENTERPRISE CUSTOMERS:Enterprise customers and their Authorized Users are also subject to the Immerse Enterprise Terms of Service and, where applicable, the Data Processing Addendum (the “DPA”). The DPA governs how Immerse processes personal data on behalf of enterprise customers and supersedes this Privacy Policy with respect to enterprise data-processing obligations. To the extent of any conflict between this Privacy Policy and the DPA in connection with enterprise data processing, the DPA controls.
Your privacy is important to us. This Privacy Policy (“Policy”) applies to services provided by Immerse Inc. (“we”, “us”, or “Company”) and our website, product pages, mobile or web applications, or other digital products that link to or reference this Policy (collectively, the “Services”). This Policy explains what information we collect from users (“you”), including Personal Information, and how we collect, use, disclose, retain, and protect it. It applies to any visitor to or user of our Services.
We may change this Policy at any time by posting a new version to our website and/or notifying the primary email address on your account. Changes are effective upon posting, and your continued use of the Services signifies your acceptance of the revised Policy. For any new category of sensitive-data or biometric collection (including Smart Glasses Capture Data described below), we will obtain your affirmative opt-in consent before such collection occurs. We encourage you to review this Policy periodically to stay informed about how we protect your information.
For individuals who subscribe to Immerse directly, Immerse is the data controller of your personal information. For learners who access Immerse through an enterprise or educational customer, that customer is the controller and Immerse acts as its processor under the applicable Data Processing Addendum; those learners should exercise their rights through their organization, and we will assist.
In the course of providing the Services, we collect the following categories of information, which may include Personal Information:
Identifiers
First and last name, email address, username, postal address, phone number, IP address, country, time zone, and display name.
Commercial Information
Records of products or services purchased or subscribed to, including sales history and subscription history for the Services.
Voice Data
Voice data received through your device microphone. How your voice data is processed, stored, and shared depends on the context in which it is captured:
Captured Still Images
Still images created by the Capture feature. For each moment you capture, the Services always create a transcript and may also create a single still image; no video is stored. Any captured still image is stored locally on your device by default, and is stored on Immerse servers only if you enable cross-device sync or when a captured moment is turned into a lesson. Still images, where created, are used only for your own review and are not sent to any AI provider; only the transcript is sent, to generate your lesson. See the “Captured Moments (Capture)” section below.
Sensory Data
Animation data used to animate your avatar and facilitate immersive interaction — namely your headset and controller position and orientation and your avatar’s facial expression, which is derived from your voice. No camera observes your face, and no facial imagery is captured. Any such sensory data is processed in real time to animate your avatar and is retained for no more than thirty (30) days.
VR Interaction Data
Where you access the Services via VR hardware (including Meta Quest 1, 2, and 3), we process your headset and controller position and orientation, and your avatar’s facial expression derived from your voice, solely to render and facilitate immersive interaction within the platform. The VR headsets we support do not perform eye-tracking, and we do not collect neural, brain-activity, or nervous-system data. We do not sell this data and do not use it to profile you. It is used in real time and is retained only for the duration of your session.
Smart Glasses Capture Data
Where you use Immerse on smart glasses or similar wearable devices, the device camera and microphone provide camera imagery and audio to the application in order to power real-time, camera- and voice-aware coaching. No video is ever stored. For moments you choose to capture, what we keep is a transcript and, where created, a single still image, handled as described in the “Captured Moments (Capture)” section and the “Captured Still Images” and “Transcription Data” categories. We use Smart Glasses Capture Data solely to provide and personalize your learning; we do not use it for advertising, and we do not sell it. Capture is off until you turn it on, and you can turn it off at any time in Settings.
Recordings
Instructor-initiated session recordings, which may include the video feed of your VR avatar, your first name, your voice data, and audio. Recordings are enabled with notice to participants and, where a recording will be used for internal training or academic research, only with your explicit opt-in consent (see the “Legal Bases” and “Session Recordings” discussion below).
Transcription Data
Data contained in transcriptions of your AI conversations and chat sessions, including the interaction content derived from asynchronous lessons and from Capture.
Internet or Other Network Activity
Activity history collected through cache, cookies, and REST API calls during use of the Services, including search terms, pages viewed, and usage behavior.
Other Categories
Content you create and share publicly, survey responses, and any information you voluntarily provide to us.
Capture is an optional feature — available across supported devices, including smart glasses — that lets you save real-world “moments” to power your language learning. Capture is user-initiated only: there is no background listening, and no video is ever stored. When you capture a moment, the Services always create a transcript of the associated audio and may also create a single still image.
Captured moments are stored locally on your device by default. They are stored on Immerse servers only if you turn on cross-device sync, or when you turn a captured moment into a lesson. Any still image is used only for your own review and is not sent to any AI provider; only the transcript is sent to the AI providers that generate coaching and lessons. Real-time transcription for Capture is provided by Google (Gemini), which may retain inputs briefly for abuse-monitoring purposes; your inputs are not used to train AI models. We do not sell Capture data, and we do not use it to train AI models.
Capture is not intended for sensitive or explicit content; we do not knowingly retain sensitive content; you can delete captured moments at any time. You agree not to use Capture to record sensitive, explicit, unlawful, or otherwise prohibited content, or to capture in any location where recording is not permitted.
Bystanders. You are responsible for the privacy of other people who may appear in captured content and for obtaining any consent required by the recording, wiretap, or privacy laws that apply where you are. Immerse does not run facial recognition and does not generate biometric identifiers from captured content.
Capture may incidentally include people who are not Immerse users (“Third-Party Individuals”). Because Capture stores only a transcript and, where created, a still image of the moments you choose to save — and no video — incidental capture is minimized. Where any derived content references non-users, we minimize and de-identify that content, and we do not use it to identify anyone. Immerse does not run facial recognition and does not generate biometric identifiers from captured content.
You are responsible for using capture features lawfully. This includes obtaining any consent required by the recording, wiretap, or privacy laws that apply where you are, and not capturing in private or prohibited locations. Please use these features considerately and with respect for the privacy of those around you.
Our platform uses artificial intelligence services provided by OpenAI, Google (Gemini), Deepgram, and Microsoft Azure Speech, among other providers. Asynchronous generation, evaluation, and text-to-speech tasks are routed through our own backend to the applicable provider. Before external processing, we exclude direct account identifiers (name, email, account ID) from text prompts. This is pseudonymization, not anonymization: the content remains linkable to you on our side and remains personal data. This identifier-exclusion applies to text only; visual content from Capture and audio processed for transcription or pronunciation cannot be filtered the same way. Captured still images are not sent to any AI provider; only the transcript is sent, to generate your lesson.
None of our AI providers train on our data by default; your inputs are not used to train AI models. Retention of inputs for abuse-monitoring purposes differs by vendor: OpenAI retains inputs for up to thirty (30) days (or zero retention where agreed); Google (Gemini) may retain inputs briefly for abuse monitoring; and Deepgram and Microsoft Azure Speech do not retain inputs by default.
Real-time coaching is provided using Google (Gemini), and real-time speech-to-text is provided using Deepgram; these connect using short-lived tokens.
We do not perform facial recognition, and we do not use Capture Data to identify, verify, or profile any person. Where processing of voice or facial characteristics would constitute biometric data under applicable law, we process it only with your affirmative opt-in consent, only for the stated learning purpose, and only subject to the retention limits set out below.
The AI component of the Services is a machine-learning model and not a human operator. AI-generated content may be inaccurate and is provided for educational purposes only; it should not be relied upon as professional, legal, or medical advice.
We use AI to evaluate learner responses and generate proficiency and progress insights. We do not use solely automated processing to make decisions about you that produce legal or similarly significant effects. Where an enterprise or educational customer uses proficiency outputs to inform a decision about a learner, that decision involves meaningful human review by the customer, consistent with applicable law, including Article 22 of the GDPR.
Directly from You
Device Permissions on VR Headsets
On Meta Quest and other VR headsets, the Services may access the following, where supported by your hardware:
Device Permissions on Smart Glasses
On Meta AI glasses and similar wearables, using the device platform’s wearables toolkit, the Services access the glasses camera and microphone to provide capture-based coaching. Capture is optional, off by default, and can be disabled at any time; the Services otherwise continue to function when capture is disabled.
Automatically
Information collected automatically through cache, cookies, and REST API calls during your use of the Services.
From Third Parties
We may receive information from third parties, including:
A current list of sub-processors is available at immerse.com/legal/subprocessors.
We use the information we collect for the following purposes:
Smart Glasses Capture Data and Captured Moments are used solely to generate and personalize your learning content and to operate the capture features you enable. They are not used for advertising.
If you are located in the European Economic Area or the United Kingdom, we process your Personal Information on one or more of the following legal bases, depending on the purpose:
We may disclose Personal Information in the following circumstances:
We do not sell Personal Information, Capture Data, or biometric data. A current sub-processor list is available at immerse.com/legal/subprocessors.
Required Cookies
These cookies enable navigation and core service features. No opt-out option is available for these cookies.
Performance Cookies
These cookies collect usage information about which pages are visited most often, and are used only to improve the function and performance of the Services.
Functionality Cookies
These cookies allow the Services to remember information you have entered and choices you have made, providing enhanced and personalized features.
Consent for Non-Essential Cookies.For visitors in the EEA and the UK, non-essential cookies (including performance and functionality cookies) are set only after you opt in through our cookie banner, which is granular by category and lets you withdraw consent as easily as you gave it. We do not use cookies for cross-site targeted advertising, and we do not sell or share personal information for cross-context behavioral advertising.
We take reasonable steps to protect your Personal Information against unauthorized access, alteration, disclosure, misuse, or destruction, including encryption in transit (TLS 1.2 or higher) and at rest (AES-256) across our database, object storage, and analytics environment; network isolation (private subnets with no direct public route, protected by a web application firewall and DDoS protection at the edge); access controls granted on a need-to-know basis, with multi-factor authentication required for administrative and support access; and regular security assessments. However, no method of data transmission or storage is guaranteed to be 100% secure. You should help protect your information by using a strong password, not sharing your password, and logging out after each session.
We retain Personal Information for as long as necessary to fulfill the purposes described in this Policy, subject to the following:
Enterprise retention is governed by the applicable Order Form and the DPA, which provide for deletion or return of Personal Data within thirty (30) days of a request.
You may review, update, correct, or delete the Personal Information in your account by contacting us at support@immerse.online or by accessing your user account. You may also delete derived Capture content, or withdraw your capture consent, at any time in Settings.
To cancel your account, contact support@immerse.online, and your personally identifiable information will be deleted or anonymized in a timely manner or as required by law. To stop receiving promotional communications, follow the opt-out instructions in those communications or contact support@immerse.online.
If you are located in the European Economic Area or the United Kingdom, you have the following rights:
We respond to rights requests within one month, extendable by up to two further months for complex or numerous requests, with notice to you within the first month. To exercise these rights, contact support@immerse.online. You may also lodge a complaint with your national data-protection authority.
If you are located in Brazil, you have the following rights under the Lei Geral de Proteção de Dados Pessoais:
To exercise these rights, contact support@immerse.online. You may also lodge a complaint with Brazil’s Autoridade Nacional de Proteção de Dados (ANPD).
If you are a California resident, you have the following rights:
We confirm receipt within ten (10) business days and complete a deletion request within forty-five (45) days of verifying your identity, extendable by a further forty-five (45) days (up to ninety (90) days total) where reasonably necessary, with notice. To exercise these rights, contact support@immerse.online or write to Immerse Inc., 2175 Tustin Ave, Costa Mesa, CA 92627.
If a personal-data breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, in addition to notifying the relevant supervisory authority as required by law.
The direct-to-consumer Services are not directed to individuals under the age of sixteen (16), and we do not solicit or knowingly collect Personal Information from children under the age of sixteen (16). Because smart-glasses capture may incidentally include apparent minors, we minimize and promptly delete or de-identify such incidental content. Where Immerse is provided to students through a school or district, the school or district is the controller, is responsible for any required notices and for obtaining any parental or institutional consent, and Immerse processes student data only as its processor, consistent with applicable children’s-privacy and student-records laws (including, in the United States, COPPA and FERPA). If you believe we have unknowingly collected information from a child under 16, please contact support@immerse.online immediately so we can delete it.
The Services may contain links to other websites. We do not control these websites, which are subject to their own terms and privacy policies. We do not endorse and are not responsible for the availability, content, advertising, products, or materials on any third-party website.
We do not alter our practices when we receive a Do-Not-Track signal from your browser, because we do not track visitors across third-party websites for targeted-advertising purposes. For more information about Do-Not-Track signals, visit http://www.allaboutdnt.com.
The Services are controlled and offered from facilities in the United States, and data is stored and processed in the United States. Certain processing occurs elsewhere: our AI-quality observability provider processes data in the European Union, and administrative and support access to data is performed by authorized personnel located in the United States and Mexico under multi-factor authentication. Where we transfer Personal Information from the European Economic Area, the United Kingdom, or Switzerland to the United States or to another country that has not received an adequacy decision, we rely on an appropriate transfer mechanism under Article 46 of the GDPR (and equivalent UK and Swiss law), including the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, or on an applicable adequacy decision. This is the same transfer basis we apply to enterprise processing. For enterprise customers subject to GDPR, LGPD, or other international data-protection regulations, international data transfers are governed by the DPA at immerse.com/legal/dpa, which implements appropriate transfer mechanisms including the Standard Contractual Clauses or the UK IDTA where required.
For any privacy question, or to reach the team responsible for data protection at Immerse, contact support@immerse.online, or Immerse Inc., 2175 Tustin Ave, Costa Mesa, CA 92627.