Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
This provision enumerates twelve data subject rights including access, deletion, correction, export, opt-out of third-party sharing, objection to processing, and consent withdrawal, and establishes that these rights are not absolute, with refusal permitted on grounds of authentication failure, third-party rights, legal requirements, or service interference. Requests can be submitted through the Duolingo Data Vault or by emailing privacy@duolingo.com.
This analysis describes what Duolingo's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the operational framework for user data subject rights requests, including the enumerated grounds on which Duolingo may decline to fulfill a request. The breadth of disclosed rights reflects GDPR, CCPA, and other applicable framework requirements, and the refusal grounds align with standard exemptions recognized under those frameworks.
The updated policy removes explicit language stating that Android users and website users are not subject to audio collection for product improvement purposes. Previously, the policy authorized audio collection only from iOS users, with an explicit carve-out for Android and web users. The revised language now states that all users may choose not to share audio within app Settings, suggesting audio collection may now occur across all platforms unless the opt-out mechanism is used. The practical operational effect of this change depends on whether Duolingo implements audio collection on Android and web platforms, which the policy change does not explicitly confirm. You can decline audio sharing for product improvement by adjusting the setting within the app.
View change record →Under this provision, users may request access to, deletion, correction, or export of their personal data, and may opt out of third-party sharing or withdraw consent through the Duolingo Data Vault or by emailing privacy@duolingo.com. The policy states that these rights are not absolute and Duolingo may decline requests on specified grounds including authentication failure or service interference.
Cross-platform context
See how other platforms handle Data Subject Rights and Exercise Procedures and similar clauses.
Compare across platforms →Monitoring
Duolingo has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"You also have the following rights in relation to the personal information we hold about you, in addition to any other rights required by applicable law: Know what personal information we have collected about you. Access a copy of the personal information that we hold about you. Know what personal information about you we have shared with third parties. Opt out of the sharing of your personal information with third parties. Object to our processing of your personal information. Request that we limit our use of your sensitive personal information to what is necessary to perform the services you requested. Not be discriminated against for exercising your data subject rights. Request that we delete any personal information we have collected from you. Request that we correct any inaccurate personal information about you. Export the personal information you have provided to Duolingo in a format that can be transferred electronically to a third party. Withdraw any consent you previously gave us to process your personal information. Delete your Duolingo account by following the instructions in the Service. Please note that these rights are not absolute and Duolingo may refuse requests to exercise data subject rights if there is a legitimate reason, such as if we cannot authenticate your identity, if the request could violate the rights of a third party or applicable law, or if the request could interfere with a Duolingo service or prevent us from delivering a service you requested.Excerpt from Duolingo's Privacy Policy
1) REGULATORY LANDSCAPE: The enumerated rights reflect GDPR Articles 15 through 21 (access, erasure, rectification, portability, objection, restriction of processing), CCPA access and deletion rights, and equivalent frameworks in other jurisdictions. The non-discrimination right reflects CCPA Section 1798.125. The 'not absolute' caveat aligns with GDPR Article 12(5) and standard exemptions under applicable data protection law. Supervisory authority complaint rights are separately referenced for GDPR-subject users. 2) GOVERNANCE EXPOSURE: Low to Medium. The policy discloses a comprehensive set of rights and two operational channels for submitting requests (Data Vault and email). The refusal grounds are consistent with those recognized under GDPR and CCPA. Response timelines are not specified in the policy, which may create exposure under GDPR Article 12 (one-month response requirement) and CCPA (45-day response requirement). 3) JURISDICTION FLAGS: EU and EEA users have GDPR-backed rights enforceable with supervisory authorities. UK users have equivalent UK GDPR rights. California users have CCPA rights. The policy does not specify jurisdiction-specific response timelines, which may require evaluation against applicable regulatory requirements in each jurisdiction. 4) CONTRACT AND VENDOR IMPLICATIONS: The right to opt out of sharing personal information with third parties, if exercised, may affect the operational delivery of features that depend on named vendors including AI providers, advertising networks, and analytics providers. Compliance teams should assess the downstream operational impact of a comprehensive opt-out request. 5) COMPLIANCE CONSIDERATIONS: Legal teams should verify that response timelines comply with GDPR Article 12 and CCPA Section 1798.130 requirements. The Data Vault mechanism should be audited to confirm it supports all enumerated rights. Identity authentication procedures for rights requests should be documented and consistent with regulatory guidance to minimize refusal grounds based on authentication failure.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes the operational framework for user data subject rights requests, including the enumerated grounds on which Duolingo may decline to fulfill a request. The breadth of disclosed rights reflects GDPR, CCPA, and other applicable framework requirements, and the refusal grounds align with standard exemptions recognized under those frameworks.
Under this provision, users may request access to, deletion, correction, or export of their personal data, and may opt out of third-party sharing or withdraw consent through the Duolingo Data Vault or by emailing privacy@duolingo.com. The policy states that these rights are not absolute and Duolingo may decline requests on specified grounds including authentication failure or service interference.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Duolingo.