Privacy Policy

Effective April 19, 2026 · Last updated April 19, 2026

This Privacy Policy explains how Conversa (“Conversa”, “we”, “us”) collects, uses, and shares personal information when you use the Conversa mobile application (the “Service”). Conversa is an AI-powered language-learning app that helps you practice a new language through spoken conversation with AI tutors.

By using the Service, you agree to the practices described here. If you do not agree, please do not use the Service.


1. Information we collect

1.1 Information you provide directly

1.2 Information collected automatically

1.3 Session replay (off by default)

Conversa integrates a session-replay feature from our analytics provider (PostHog). It is disabled by default and does not record your screen under normal use. It only activates in two narrow cases:

  1. You open the in-app feedback panel. Recording starts so that if you submit feedback, the engineer reviewing it can see what you saw.
  2. A specific remote feature flag is enabled for your account for a product-research purpose, which we would only use in a targeted, time-limited way.

Session-replay data never captures system-level content outside the Conversa app and is retained for a limited window (see §5).

1.4 Information from third-party sign-in providers

If you sign in with Google or Apple, those providers send us a stable user identifier, your email address, and (depending on your choices and their platform) your name. We do not receive your contacts, photos, or any other data from those accounts.

1.5 What we do not collect


2. How we use your information

We use the information above to:

We do not use your voice recordings or conversation content to train third-party AI models on an opt-out basis. See §3 for how we work with AI subprocessors.


3. Third-party service providers (subprocessors)

We share the minimum personal information needed with a small number of service providers who help us operate Conversa. These providers are contractually bound to process your data only for the purposes we specify.

ProviderWhat we shareWhy
OpenAIVoice recordings (for speech-to-text) and conversation text (prompts/responses)Transcribe your speech and generate AI tutor responses. OpenAI processes this data under its API data-processing terms and does not use API inputs or outputs to train its models.
Google Firebase (Authentication, Cloud Messaging)Email, password hash, auth tokens, push-notification tokenAccount authentication and push-notification delivery.
Google Sign-In / Apple Sign-InThe identifiers they send us backFederated sign-in you chose.
PostHogDevice identifier, app events, crash logs, and — only in the narrow cases described in §1.3 — session-replay dataProduct analytics, crash reporting, and targeted feedback review.
Cloud hosting (our backend servers)All of the above that is stored server-sideRun the Service itself.

We do not sell your personal information. We do not share it with advertising networks, and Conversa does not display third-party ads.

We may also disclose information when legally required (court order, subpoena, regulatory request), to protect our rights or users’ safety, or in connection with a corporate transaction (merger, acquisition), in which case we will notify you and this Policy will continue to apply until updated.


4. How long we keep your information

When you delete your account (see §7), we delete or anonymize the personal information tied to your account within 30 days, except where a longer retention period is required by law or for security and fraud-prevention reasons.


5. International data transfers

Our servers and many of our service providers are located in the United States. If you are outside the United States, your information will be transferred to, stored, and processed in the United States and potentially in other countries where our providers operate.

For transfers from the European Economic Area (EEA), the United Kingdom, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework, to provide appropriate safeguards for your data.


6. Security

We use industry-standard safeguards to protect your information:

No system is perfectly secure. If we become aware of a security incident affecting your personal information, we will notify you as required by applicable law.


7. Your choices and rights

You have control over your data:

7.1 If you are in California (CCPA/CPRA)

California residents have the right to (1) know what personal information we collect, use, and share; (2) request deletion of their personal information; (3) request correction of inaccurate personal information; (4) opt out of “sale” or “sharing” of personal information; and (5) not be discriminated against for exercising these rights.

We do not sell or share personal information as those terms are defined under the CCPA/CPRA. To exercise any of the above rights, email privacy@heyconversa.com with “CCPA Request” in the subject. We will verify your request against the email on file and respond within 45 days.

7.2 If you are in the EEA, UK, or Switzerland (GDPR/UK GDPR)

You have the right to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interests, and to withdraw consent where processing is based on consent. You can exercise these rights by emailing privacy@heyconversa.com. You also have the right to complain to your local data-protection authority.

The legal bases we rely on are: performance of a contract (to deliver the Service you signed up for), legitimate interests (to keep the Service secure, reliable, and improving), consent (for push notifications and any optional data-collection toggles), and legal obligation (where required by law).


8. Children’s privacy

Conversa is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please email privacy@heyconversa.com and we will delete it.

In the EEA and UK, the Service is not directed at children under 16. If you are under the age of digital consent in your jurisdiction, please do not use the Service without your parent or guardian’s involvement.


9. Changes to this Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you in the app or by email before the change takes effect. The “Effective date” at the top of this Policy indicates when it was last revised. Your continued use of the Service after an update means you accept the updated Policy.


10. Contact us

If you have questions about this Policy or your personal information, contact: