This Privacy Policy explains how Conversa (“Conversa”, “we”, “us”) collects, uses, and shares personal information when you use the Conversa mobile application (the “Service”). Conversa is an AI-powered language-learning app that helps you practice a new language through spoken conversation with AI tutors.
By using the Service, you agree to the practices described here. If you do not agree, please do not use the Service.
1. Information we collect
1.1 Information you provide directly
- Account information. When you create an account, we collect your email address and a display name. If you sign up with Google or Apple, we receive your name and email from that provider; we do not receive or store your Google/Apple password.
- Voice recordings. When you speak during a lesson or conversation, the app records short audio clips of your speech. These are sent to our servers so they can be transcribed into text and used to generate a response from your AI tutor.
- Conversation content. The text transcripts of your conversations, any written messages you send, and the AI tutor’s responses are stored on our servers so you can review your history and track progress.
- Learning profile. The target language you’re studying, your level, your learning goals, streaks, and similar preferences you set in the app.
- Feedback. If you submit in-app feedback, we collect what you write and, for a limited time, a recording of the session you are reporting on (see Session replay in §1.3).
1.2 Information collected automatically
- Device and app information. Device model, operating system and version, app version, locale/language settings, a generated device identifier, and diagnostic information (crash logs, error traces, performance metrics).
- Usage information. Which screens you visit, which buttons you tap, lesson completions, conversation length, and similar product-analytics events used to understand feature engagement.
- Push-notification token. If you allow notifications, we store the push token issued by Apple or Google so we can send practice reminders and other messages you’ve opted into.
1.3 Session replay (off by default)
Conversa integrates a session-replay feature from our analytics provider (PostHog). It is disabled by default and does not record your screen under normal use. It only activates in two narrow cases:
- You open the in-app feedback panel. Recording starts so that if you submit feedback, the engineer reviewing it can see what you saw.
- A specific remote feature flag is enabled for your account for a product-research purpose, which we would only use in a targeted, time-limited way.
Session-replay data never captures system-level content outside the Conversa app and is retained for a limited window (see §5).
1.4 Information from third-party sign-in providers
If you sign in with Google or Apple, those providers send us a stable user identifier, your email address, and (depending on your choices and their platform) your name. We do not receive your contacts, photos, or any other data from those accounts.
1.5 What we do not collect
- We do not collect your precise location.
- We do not access your contacts, photos, camera, or files.
- We access the microphone only while you are actively in a conversation screen, and only to record your speech for that turn of the conversation.
- We do not collect health, financial, or government-ID data.
2. How we use your information
We use the information above to:
- Provide the core Service — run conversations, transcribe your speech, generate AI tutor responses, show your progress, and keep you signed in.
- Personalize your experience — pick lessons and difficulty based on your goals and past performance.
- Send account and service communications — password resets, important service notices, and (if you opted in) push notifications with practice reminders.
- Keep the app reliable and secure — detect crashes, investigate bugs, prevent abuse, and enforce our Terms.
- Improve the product — understand which features help users learn, in aggregate or anonymized form where practical.
We do not use your voice recordings or conversation content to train third-party AI models on an opt-out basis. See §3 for how we work with AI subprocessors.
3. Third-party service providers (subprocessors)
We share the minimum personal information needed with a small number of service providers who help us operate Conversa. These providers are contractually bound to process your data only for the purposes we specify.
| Provider | What we share | Why |
|---|---|---|
| OpenAI | Voice recordings (for speech-to-text) and conversation text (prompts/responses) | Transcribe your speech and generate AI tutor responses. OpenAI processes this data under its API data-processing terms and does not use API inputs or outputs to train its models. |
| Google Firebase (Authentication, Cloud Messaging) | Email, password hash, auth tokens, push-notification token | Account authentication and push-notification delivery. |
| Google Sign-In / Apple Sign-In | The identifiers they send us back | Federated sign-in you chose. |
| PostHog | Device identifier, app events, crash logs, and — only in the narrow cases described in §1.3 — session-replay data | Product analytics, crash reporting, and targeted feedback review. |
| Cloud hosting (our backend servers) | All of the above that is stored server-side | Run the Service itself. |
We do not sell your personal information. We do not share it with advertising networks, and Conversa does not display third-party ads.
We may also disclose information when legally required (court order, subpoena, regulatory request), to protect our rights or users’ safety, or in connection with a corporate transaction (merger, acquisition), in which case we will notify you and this Policy will continue to apply until updated.
4. How long we keep your information
- Account data (email, profile, learning progress): for as long as your account exists, plus a short window to allow recovery from accidental deletion.
- Voice recordings: retained only as long as needed to produce the transcript and deliver your tutor’s response, after which the audio is deleted from our systems. Transcripts are retained as part of your conversation history.
- Conversation transcripts: retained for as long as your account exists so you can review your history.
- Diagnostics and analytics: retained on a rolling 13-month window by default.
- Session-replay data (when recorded): retained for up to 30 days and then deleted, unless needed to investigate a specific support ticket.
When you delete your account (see §7), we delete or anonymize the personal information tied to your account within 30 days, except where a longer retention period is required by law or for security and fraud-prevention reasons.
5. International data transfers
Our servers and many of our service providers are located in the United States. If you are outside the United States, your information will be transferred to, stored, and processed in the United States and potentially in other countries where our providers operate.
For transfers from the European Economic Area (EEA), the United Kingdom, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework, to provide appropriate safeguards for your data.
6. Security
We use industry-standard safeguards to protect your information:
- All data in transit between the app and our servers is encrypted with TLS (HTTPS).
- Passwords are salted and hashed using Firebase Authentication’s standard practices; we never see your plaintext password.
- Access to production systems is limited to a small number of authorized engineers, with role-based access controls and audit logging.
No system is perfectly secure. If we become aware of a security incident affecting your personal information, we will notify you as required by applicable law.
7. Your choices and rights
You have control over your data:
- Access and correction. You can view and edit your profile and learning preferences in the app’s Settings screen.
- Delete your account. You can request account deletion by emailing privacy@heyconversa.com from the address on your account. We will confirm the request and complete deletion within 30 days.
- Notifications. You can turn push notifications on or off in Settings at any time; you can also revoke the OS-level microphone or notifications permission from your device settings.
- Marketing email. Any marketing email we send will include an unsubscribe link.
7.1 If you are in California (CCPA/CPRA)
California residents have the right to (1) know what personal information we collect, use, and share; (2) request deletion of their personal information; (3) request correction of inaccurate personal information; (4) opt out of “sale” or “sharing” of personal information; and (5) not be discriminated against for exercising these rights.
We do not sell or share personal information as those terms are defined under the CCPA/CPRA. To exercise any of the above rights, email privacy@heyconversa.com with “CCPA Request” in the subject. We will verify your request against the email on file and respond within 45 days.
7.2 If you are in the EEA, UK, or Switzerland (GDPR/UK GDPR)
You have the right to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interests, and to withdraw consent where processing is based on consent. You can exercise these rights by emailing privacy@heyconversa.com. You also have the right to complain to your local data-protection authority.
The legal bases we rely on are: performance of a contract (to deliver the Service you signed up for), legitimate interests (to keep the Service secure, reliable, and improving), consent (for push notifications and any optional data-collection toggles), and legal obligation (where required by law).
8. Children’s privacy
Conversa is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please email privacy@heyconversa.com and we will delete it.
In the EEA and UK, the Service is not directed at children under 16. If you are under the age of digital consent in your jurisdiction, please do not use the Service without your parent or guardian’s involvement.
9. Changes to this Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you in the app or by email before the change takes effect. The “Effective date” at the top of this Policy indicates when it was last revised. Your continued use of the Service after an update means you accept the updated Policy.
10. Contact us
If you have questions about this Policy or your personal information, contact:
- Email: privacy@heyconversa.com