Duolingo · Duolingo Privacy Policy · View original document ↗

Data Subject Rights and Exercise Procedures

Low severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Duolingo changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Duolingo Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

This provision enumerates twelve data subject rights including access, deletion, correction, export, opt-out of third-party sharing, objection to processing, and consent withdrawal, and establishes that these rights are not absolute, with refusal permitted on grounds of authentication failure, third-party rights, legal requirements, or service interference. Requests can be submitted through the Duolingo Data Vault or by emailing privacy@duolingo.com.

This analysis describes what Duolingo's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the operational framework for user data subject rights requests, including the enumerated grounds on which Duolingo may decline to fulfill a request. The breadth of disclosed rights reflects GDPR, CCPA, and other applicable framework requirements, and the refusal grounds align with standard exemptions recognized under those frameworks.

Recent Activity

This document changed recently

Medium May 27, 2026

The updated policy removes explicit language stating that Android users and website users are not subject to audio collection for product improvement purposes. Previously, the policy authorized audio collection only from iOS users, with an explicit carve-out for Android and web users. The revised language now states that all users may choose not to share audio within app Settings, suggesting audio collection may now occur across all platforms unless the opt-out mechanism is used. The practical operational effect of this change depends on whether Duolingo implements audio collection on Android and web platforms, which the policy change does not explicitly confirm. You can decline audio sharing for product improvement by adjusting the setting within the app.

View change record →

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this provision, users may request access to, deletion, correction, or export of their personal data, and may opt out of third-party sharing or withdraw consent through the Duolingo Data Vault or by emailing privacy@duolingo.com. The policy states that these rights are not absolute and Duolingo may decline requests on specified grounds including authentication failure or service interference.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Navigate to the Duolingo Data Vault to submit a request to access, delete, correct, or export your personal data, or email privacy@duolingo.com for other privacy-related requests.
  • Export Your Data
    Access the Duolingo Data Vault and submit a data portability or export request to receive your personal information in an electronically transferable format.

Cross-platform context

See how other platforms handle Data Subject Rights and Exercise Procedures and similar clauses.

Compare across platforms →

Monitoring

Duolingo has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
You also have the following rights in relation to the personal information we hold about you, in addition to any other rights required by applicable law: Know what personal information we have collected about you. Access a copy of the personal information that we hold about you. Know what personal information about you we have shared with third parties. Opt out of the sharing of your personal information with third parties. Object to our processing of your personal information. Request that we limit our use of your sensitive personal information to what is necessary to perform the services you requested. Not be discriminated against for exercising your data subject rights. Request that we delete any personal information we have collected from you. Request that we correct any inaccurate personal information about you. Export the personal information you have provided to Duolingo in a format that can be transferred electronically to a third party. Withdraw any consent you previously gave us to process your personal information. Delete your Duolingo account by following the instructions in the Service. Please note that these rights are not absolute and Duolingo may refuse requests to exercise data subject rights if there is a legitimate reason, such as if we cannot authenticate your identity, if the request could violate the rights of a third party or applicable law, or if the request could interfere with a Duolingo service or prevent us from delivering a service you requested.

Excerpt from Duolingo's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: The enumerated rights reflect GDPR Articles 15 through 21 (access, erasure, rectification, portability, objection, restriction of processing), CCPA access and deletion rights, and equivalent frameworks in other jurisdictions. The non-discrimination right reflects CCPA Section 1798.125. The 'not absolute' caveat aligns with GDPR Article 12(5) and standard exemptions under applicable data protection law. Supervisory authority complaint rights are separately referenced for GDPR-subject users. 2) GOVERNANCE EXPOSURE: Low to Medium. The policy discloses a comprehensive set of rights and two operational channels for submitting requests (Data Vault and email). The refusal grounds are consistent with those recognized under GDPR and CCPA. Response timelines are not specified in the policy, which may create exposure under GDPR Article 12 (one-month response requirement) and CCPA (45-day response requirement). 3) JURISDICTION FLAGS: EU and EEA users have GDPR-backed rights enforceable with supervisory authorities. UK users have equivalent UK GDPR rights. California users have CCPA rights. The policy does not specify jurisdiction-specific response timelines, which may require evaluation against applicable regulatory requirements in each jurisdiction. 4) CONTRACT AND VENDOR IMPLICATIONS: The right to opt out of sharing personal information with third parties, if exercised, may affect the operational delivery of features that depend on named vendors including AI providers, advertising networks, and analytics providers. Compliance teams should assess the downstream operational impact of a comprehensive opt-out request. 5) COMPLIANCE CONSIDERATIONS: Legal teams should verify that response timelines comply with GDPR Article 12 and CCPA Section 1798.130 requirements. The Data Vault mechanism should be audited to confirm it supports all enumerated rights. Identity authentication procedures for rights requests should be documented and consistent with regulatory guidance to minimize refusal grounds based on authentication failure.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has jurisdiction over the adequacy and implementation of data subject rights mechanisms under the FTC Act's unfair or deceptive practices authority.
    File a complaint →
  • State AG
    State attorneys general have jurisdiction over CCPA data subject rights compliance for California residents and analogous rights in other states with enacted privacy laws.
    File a complaint →

Provision details

Document information
Document
Duolingo Privacy Policy
Entity
Duolingo
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-016023
Document ID
CA-D-00084
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
ffd79e13b1f23d8f50cc63af7c7e06fe3d89fe994f3f6c441c5f01a292a571ad
Analysis generated
July 9, 2026 09:23 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Duolingo
Document: Duolingo Privacy Policy
Record ID: CA-P-016023
Captured: 2026-07-09 09:23:37 UTC
SHA-256: ffd79e13b1f23d8f…
URL: https://conductatlas.com/platform/duolingo/duolingo-privacy-policy/provision/CA-P-016023/data-subject-rights-and-exercise-procedures/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Duolingo's Data Subject Rights and Exercise Procedures clause do?

This provision establishes the operational framework for user data subject rights requests, including the enumerated grounds on which Duolingo may decline to fulfill a request. The breadth of disclosed rights reflects GDPR, CCPA, and other applicable framework requirements, and the refusal grounds align with standard exemptions recognized under those frameworks.

How does this clause affect you?

Under this provision, users may request access to, deletion, correction, or export of their personal data, and may opt out of third-party sharing or withdraw consent through the Duolingo Data Vault or by emailing privacy@duolingo.com. The policy states that these rights are not absolute and Duolingo may decline requests on specified grounds including authentication failure or service interference.

Is ConductAtlas affiliated with Duolingo?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Duolingo.