This Privacy Policy explains how Aurelion Labs LLC, a California limited liability company doing business as Conversa (“Conversa”, “we”, “us”), collects, uses, and shares personal information when you use the Conversa mobile application and the heyconversa.com website (together, the “Service”). Aurelion Labs LLC, 2108 N St, Ste N, Sacramento, CA 95816, United States, is the data controller for that information. Conversa is an AI-powered language-learning app that helps you practice a new language through spoken conversation with AI tutors. Sections 1.1 to 1.5 describe the app; §1.6 describes the website, which you can use without installing the app.
By using the Service, you agree to the practices described here. If you do not agree, please do not use the Service.
1. Information we collect
1.1 Information you provide directly
- Account information. When you create an account, we collect your email address and a display name. If you sign up with Google or Apple, we receive your name and email from that provider; we do not receive or store your Google/Apple password.
- Voice recordings. When you speak during a lesson or conversation, the app records short audio clips of your speech. These are sent to our servers so they can be transcribed into text and used to generate a response from your AI tutor.
- Conversation content. The text transcripts of your conversations, any written messages you send, and the AI tutor’s responses are stored on our servers so you can review your history and track progress.
- Learning profile. The target language you’re studying, your level, your learning goals, streaks, and similar preferences you set in the app.
- Feedback. If you submit in-app feedback, we collect what you write and, for a limited time, a recording of the session you are reporting on (see Session replay in §1.3).
1.2 Information collected automatically
- Device and app information. Device model, operating system and version, app version, locale/language settings, a generated device identifier, and diagnostic information (crash logs, error traces, performance metrics).
- Usage information. Which screens you visit, which buttons you tap, lesson completions, conversation length, and similar product-analytics events used to understand feature engagement.
- Push-notification token. If you allow notifications, we store the push token issued by Apple or Google so we can send practice reminders and other messages you’ve opted into.
1.3 Session replay in the app (off by default)
The Conversa app integrates a session-replay feature from our analytics provider. It is disabled by default and does not record your screen under normal use. It only activates in two narrow cases:
- You open the in-app feedback panel. Recording starts so that if you submit feedback, the engineer reviewing it can see what you saw.
- A specific remote feature flag is enabled for your account for a product-research purpose, which we would only use in a targeted, time-limited way.
Session-replay data never captures system-level content outside the Conversa app and is retained for a limited window (see §4).
1.4 Information from third-party sign-in providers
If you sign in with Google or Apple, those providers send us a stable user identifier, your email address, and (depending on your choices and their platform) your name. We do not receive your contacts, photos, or any other data from those accounts.
1.5 What we do not collect
- We do not collect your precise location.
- We do not access your contacts, photos, camera, or files.
- We access the microphone only while you are in a conversation or a flashcard and pronunciation practice screen, and only to record your speech.
- We do not ask for health, financial, or government-ID data. If you mention such things to a tutor, they are stored as part of your conversation content.
1.6 Information we collect on our website
You can visit heyconversa.com, read the blog, and join the waitlist without creating an account or installing the app. When you do, we collect:
- Waitlist sign-up. If you join the waitlist, we collect your email address and a note of which part of the site you signed up from. We store it in our database and pass it to our email-delivery provider so we can send you one welcome email and one notification when Conversa launches. We also use it to link your visit to your sign-up, as described under Website analytics below. Every email we send you tells you how to leave the waitlist.
- IP address and request data. Like any website, our servers and hosting provider see your IP address, browser type, the pages you request, and the time of each request. We use your IP address to limit how many times a form can be submitted per minute (it is held in memory for one minute and not written to our database) and to keep the site secure. Our analytics provider stores your IP address with each website event for the period in §4 and may infer an approximate country or city from it. We do not collect precise location.
- Cookies. We set a small number of first-party cookies, listed one by one under Cookies we set below. None of them is used for advertising, and the site works without them.
- Website analytics and session replay. We use a product-analytics provider to record page views, how far you scroll, where you click, which sections and links you interact with, whether you started or completed the waitlist form, which version of a page you saw, errors the page encounters, browser console output, and page-load performance. If you join the waitlist, these events and any replay of your visit are linked to your email address so we can see which pages lead people to sign up. Unlike the app (§1.3), the same provider records a replay of your visit to the website: the page content you saw and your mouse movement, scrolling, and clicks. Anything you type into a form field is masked in the recording. Replays are used to find layout and usability problems, are retained for up to 30 days (§4), and are not used for advertising. We do not run third-party advertising trackers on the site.
Cookies we set
If you visit from the European Economic Area, the United Kingdom, or Switzerland, we ask before setting any cookie that is not strictly necessary: analytics, page-version testing, and session replay stay off until you choose Accept in the cookie banner, and you can decline with one click. Everywhere else, these run on the basis of our legitimate interest described in §6, and you can turn them off at any time. In both cases the Cookie settings link in the footer of every page lets you change your choice. We also honour the Global Privacy Control and Do Not Track signals your browser can send: if either is on, we treat it as a refusal.
| Cookie | Purpose | Set by | Lasts | Legal basis |
|---|---|---|---|---|
cookie_consent | Remembers whether you accepted or declined analytics cookies. Until you choose, it only records whether we need to ask you (visitors from the EEA, UK, and Switzerland) or not. | Conversa (first party) | 12 months after a choice; the “do we need to ask” marker lasts until you close your browser | Strictly necessary (stores your choice) |
landing_variant | Which version of the home page and blog you were shown while we test a redesign. | Conversa (first party) | Up to 24 hours | Consent in the EEA, UK, and Switzerland; legitimate interest elsewhere |
landing_did | A random identifier so that our server and our analytics provider agree on which page version you saw. | Conversa (first party) | 12 months | Consent in the EEA, UK, and Switzerland; legitimate interest elsewhere |
ph_…_posthog (cookie and browser storage) | Our analytics provider’s identifier for your browser, your current session, and the page-version assignment. Removed when you decline. | Analytics provider, served through our own domain (first party) | 12 months | Consent in the EEA, UK, and Switzerland; legitimate interest elsewhere |
__ph_opt_in_out_… (browser storage) | Our analytics provider’s own record that you declined, so it stays off. | Analytics provider, in your browser’s local storage | Until you clear your browser storage | Strictly necessary (stores your choice) |
2. How we use your information
We use the information above to:
- Provide the core Service: run conversations, transcribe your speech, generate AI tutor responses, show your progress, and keep you signed in.
- Personalize your experience: pick lessons and difficulty based on your goals and past performance.
- Send account and service communications: password resets, important service notices, and (if you opted in) push notifications with practice reminders.
- Keep the app reliable and secure: detect crashes, investigate bugs, prevent abuse, and enforce our Terms.
- Improve the product: understand which features help users learn, in aggregate or anonymized form where practical.
We do not use your voice recordings or conversation content to train third-party AI models. See §3 for how we work with AI subprocessors.
3. Third-party service providers (subprocessors)
We share the minimum personal information needed with a small number of service providers who help us operate Conversa. These providers are contractually bound to process your data only for the purposes we specify. If you would like the names of the providers we currently use, email privacy@heyconversa.com and we will send you the list.
| Type of provider | What we share | Why |
|---|---|---|
| AI speech and language providers (speech-to-text, language model, text-to-speech) | Voice recordings (for speech-to-text) and conversation text (prompts and responses) | Transcribe your speech, generate AI tutor responses, and turn them into speech. These providers process data under their API terms, which prohibit using our inputs or outputs to train their models. |
| Pronunciation-assessment provider | Short voice clips from conversations and flashcard practice | Score your pronunciation. The provider’s terms prohibit using this data to train its models. |
| Authentication and push-notification providers | Email, password hash, auth tokens, push-notification token | Account sign-in and push-notification delivery. |
| Google or Apple sign-in (only if you choose it) | The identifiers they send us back | Federated sign-in you chose. |
| Product analytics and crash-reporting provider | Device identifier, app events, crash logs, website analytics events, and session-replay data (in the app only in the narrow cases described in §1.3; on the website as described in §1.6) | Product analytics, crash reporting, and targeted feedback review. |
| Cloud hosting and performance-monitoring providers | Server-side copies of the data above; the monitoring provider receives only user and session identifiers, target language, and request timing and size (never audio or transcripts) | Run the Service and find slow or failing requests. |
| Website hosting, database, and email-delivery providers (website only, see §1.6) | IP address and request logs (hosting); waitlist email address and sign-up source (database and email delivery) | Serve heyconversa.com, store the waitlist, send the welcome and launch emails, and understand how the site is used. |
We do not sell your personal information. We do not share it with advertising networks, and Conversa does not display third-party ads.
We may also disclose information when legally required (court order, subpoena, regulatory request), to protect our rights or users’ safety, or in connection with a corporate transaction (merger, acquisition), in which case we will notify you and this Policy will continue to apply until updated.
4. How long we keep your information
- Account data (email, profile, learning progress): for as long as your account exists.
- Voice recordings: retained only as long as needed to produce the transcript and deliver your tutor’s response, after which the audio is deleted from our systems. Transcripts are retained as part of your conversation history.
- Conversation transcripts: retained for as long as your account exists so you can review your history.
- Diagnostics and analytics: retained on a rolling 13-month window by default.
- Session-replay data (app, when recorded; website visits): retained for up to 30 days and then deleted, unless needed to investigate a specific support ticket.
- Waitlist email (website): kept until we have sent the launch notification and for up to 90 days afterwards, or until you unsubscribe or ask us to delete it, whichever comes first. If you then create an account with the same email, it becomes account data.
- Website IP address and request logs: the rate-limit record is held in memory for one minute. Our hosting provider’s request logs are kept for a short period, currently no more than a few days, for security and troubleshooting.
- Website cookies and analytics: cookie lifetimes are in the table in §1.6 (
landing_variantwithin 24 hours;cookie_consent,landing_did, and the analytics cookie within 12 months); website analytics events and replays follow the Diagnostics and analytics and Session-replay data windows above.
When you delete your account (see §7), your account and the personal information tied to it are deleted from our production systems immediately. Copies held by our service providers (such as analytics) and in backups are deleted or anonymized within 30 days, except where a longer retention period is required by law or for security and fraud-prevention reasons.
5. International data transfers
Our servers and many of our service providers are located in the United States. If you are outside the United States, your information will be transferred to, stored, and processed in the United States and potentially in other countries where our providers operate.
For transfers from the European Economic Area (EEA), the United Kingdom, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum) to provide appropriate safeguards for your data.
6. Security
We use industry-standard safeguards to protect your information:
- All data in transit between the app and our servers is encrypted with TLS (HTTPS).
- Passwords are salted and hashed by our authentication provider; we never see your plaintext password.
- Access to production systems is limited to a small number of authorized engineers, with role-based access controls and audit logging.
No system is perfectly secure. If we become aware of a security incident affecting your personal information, we will notify you as required by applicable law.
7. Your choices and rights
You have control over your data:
- Access and correction. You can view and edit your profile and learning preferences in the app’s Settings screen.
- Delete your account. You can delete your account at any time in the app from Settings → Account → Delete account, or by following the steps at heyconversa.com/delete-account. Deletion is permanent and takes effect in our live systems right away (see §4 for backups). If you can no longer sign in, email privacy@heyconversa.com from the address on your account and we will complete deletion within 30 days.
- Notifications. You can turn push notifications on or off in Settings at any time; you can also revoke the OS-level microphone or notifications permission from your device settings.
- Marketing email. Any marketing email we send will include an unsubscribe link.
- Leave the waitlist. Reply to any waitlist email, or email privacy@heyconversa.com from the address you signed up with. We will stop emailing you right away and delete your record from our database and our email-delivery provider within 30 days.
- Website cookies. Use the Cookie settings link in the footer of any page to accept or decline analytics cookies, or change an earlier choice; declining also removes the cookies listed in §1.6. You can also delete or block them in your browser settings. The site keeps working; the version of a page you see may simply vary between visits while we are testing a redesign.
Every right in this section is available to you whether you use the app, the website, or both. If you have only joined the waitlist and never created an account, email privacy@heyconversa.com and we will verify the request against that address.
7.1 If you are in California (CCPA/CPRA)
California residents have the right to (1) know what personal information we collect, use, and share; (2) request deletion of their personal information; (3) request correction of inaccurate personal information; (4) opt out of “sale” or “sharing” of personal information; and (5) not be discriminated against for exercising these rights.
We do not sell or share personal information as those terms are defined under the CCPA/CPRA. To exercise any of the above rights, email privacy@heyconversa.com with “CCPA Request” in the subject. We will verify your request against the email on file and respond within 45 days.
7.2 If you are in the EEA, UK, or Switzerland (GDPR/UK GDPR)
You have the right to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interests, and to withdraw consent where processing is based on consent. You can exercise these rights by emailing privacy@heyconversa.com. You also have the right to complain to your local data-protection authority.
The legal bases we rely on are: performance of a contract (to deliver the Service you signed up for), legitimate interests (to keep the Service secure, reliable, and improving), consent (for push notifications and any optional data-collection toggles), and legal obligation (where required by law).
For the website (§1.6): we send waitlist emails on the basis of your consent, which you give by submitting the form and can withdraw by unsubscribing; we process IP addresses and request logs on the basis of our legitimate interest in keeping the site secure and available; and we run website analytics, session replay, and the page-version cookies on the basis of your consent, given in the cookie banner, if you visit from the European Economic Area, the United Kingdom, or Switzerland, and otherwise on the basis of our legitimate interest in understanding how the site is used and improving it. You can withdraw consent or object to the legitimate-interest processing at any time through the Cookie settings link in the footer, or by emailing privacy@heyconversa.com.
8. Children’s privacy
Conversa is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please email privacy@heyconversa.com and we will delete it.
In the EEA and UK, the Service is not directed at children under 16. If you are under the age of digital consent in your jurisdiction, please do not use the Service without your parent or guardian’s involvement.
9. Changes to this Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you in the app or by email before the change takes effect. The “Effective date” at the top of this Policy indicates when it was last revised. Your continued use of the Service after an update means you accept the updated Policy.
10. Contact us
If you have questions about this Policy or your personal information, contact:
- Email: privacy@heyconversa.com