Privacy Policy
Last updated: 2026-08-13
What this app does
iSpeak helps you practice a foreign language by speaking with an AI tutor. To do that, the app records your voice, converts it to text, sends the text and lesson context to a language model that generates your tutor’s reply, and plays the reply back as audio.
What we collect
- Account data: your display name and email address. When you sign in with Google or Apple, we receive your email, your name (on first sign-in), and a stable provider account identifier — we never receive your Google or Apple password. Accounts created with a phone number instead store the phone number and a hashed password. Stored in our database.
- Audio of your voice during a tutor call: recorded on your device and converted to text. In the web app, audio is sent to our backend and to the configured transcription provider. In the native iOS / Android app, speech recognition uses the operating system speech service; iSpeak sends the resulting transcript, not the native recording, to our backend. There is no native-to-cloud audio fallback: if the operating system cannot recognize speech, the app reports the error and asks you to try again. We do not retain web audio after transcription.
- Transcripts and lesson context: the text of what you said, what the tutor said, your selected learning language, level, and current lesson context are sent to our backend and to DeepSeek so the AI tutor can generate a relevant reply. When you save a session, transcript text is stored on your account so you can review it later. You can delete your account to remove this data permanently.
- Vocabulary you save during conversations, and your review history (the Hard / Good / Easy rating you give each card).
- Push notification tokens: if you grant notification permission, your device’s push token (issued by Apple, Google, or Expo’s push service) is stored against your account so we can send daily streak nudges. The app requests removal of its current token when you sign out; signing out everywhere or deleting your account removes all of your stored token rows. Tokens reported invalid by the push provider, including after an uninstall, are also removed.
- Usage diagnostics: sign-in events, session duration, error rate, rate-limit triggers, and a random anonymous browser identifier stored in localStorage before sign-in so we can understand signup funnel reliability. Used only to keep the service reliable.
- Device-level basics: OS version, app version, and the IP address the request comes from (used for rate limiting and abuse detection, not stored long-term).
What we don’t collect
- We do not record video or take photos.
- We do not collect contacts, calendar, location, or device identifiers for advertising.
- We do not include third-party analytics or ad SDKs.
- We do not sell your voice, transcripts, or account data.
- We do not share voice or transcript data for advertising.
Third-party services we use
To run iSpeak we share specific data with these providers:
- DeepSeek (LLM) — we send your transcript text, tutor text, selected learning language, level, and lesson context so the tutor can generate replies.
- Cloudflare Workers AI — in the web app when configured, Whisper transcription of your voice and MeloTTS speech synthesis of tutor replies. Native iOS / Android recordings are not sent to Cloudflare as a fallback.
- Apple / Android system speech services — in the native app, speech recognition and text-to-speech are handled by the device operating system. Depending on your device, language, and OS settings, speech recognition may be processed on-device or by the OS provider’s speech service.
- OpenAI — only when OpenAI is explicitly configured as the web voice provider, we may send web-call audio for transcription or tutor reply text for speech synthesis. Native iOS / Android recordings are not sent to OpenAI as a fallback.
- Google Sign-In — if you sign in with Google, it verifies your identity and returns your email, name, and an account identifier so we can create and recognize your account. We never receive your Google password.
- Apple Sign-In — if you sign in with Apple, it verifies your identity and returns your email (or a private relay address), name on first sign-in, and an account identifier. We never receive your Apple password.
- Payme — if you buy a Premium subscription on the web, Payme (Paycom) processes the payment. You enter your payment details with Payme directly; we receive only the order and its transaction status to unlock Premium. We never see or store your card number.
- Eskiz — if you use phone-number sign-in, we send your phone number to Eskiz to deliver the one-time SMS verification code.
- Resend — for any verification or password-reset emails (legacy email/phone accounts).
- RevenueCat — when the app loads, purchases, restores, renews, or checks Premium, RevenueCat receives your opaque iSpeak user ID and the App Store purchase receipt to validate entitlement state. It does not receive transcripts, audio, or lesson content. Our backend stores the verified product, billing source, status, and entitlement end date so paid APIs cannot be unlocked by a client-side flag.
These providers process voice or text only to return transcription, tutor replies, or speech output for iSpeak. We do not permit providers to use your voice or transcripts for advertising or model training. The app asks for microphone permission and explains this AI processing before a tutor call uses your voice. If you’d prefer not to use these AI providers, the only path today is to not use voice tutor calls.
How long we keep your data
- Account, transcripts, vocabulary: until you delete your account, or for 24 months after your last sign-in (whichever is sooner).
- Recorded audio: not retained after transcription.
- Diagnostic logs: 90 days.
Your choices
- Sign out of all devices: Settings → Account → Sign out of all devices.
- Delete your account, which removes everything tied to your account on our side, including transcripts and vocabulary: Settings → Account → Delete account. You can also delete your account from outside the app at https://lilt-cu8.pages.dev/delete-account — useful if you’ve uninstalled the app or don’t want to download it just to delete. This is irreversible.
Children
iSpeak is rated 4+/Everyone but is not directed at children under 13. We don’t knowingly collect data from children under 13. If you believe a child has signed up, email us (below) and we’ll remove the account.
Changes to this policy
If we materially change what we collect or how we use it, we’ll update this page and increment the date at the top. For substantive changes we’ll also email you.
Contact
Questions, requests for data export, or to report a privacy concern: hello@lilt.app