Privacy Policy
Last updated: 2026-06-17
What this app does
Lilt helps you practice a foreign language by speaking with an AI tutor named Mira. To do that, the app records your voice, converts it to text, sends the text to a language model that generates Mira’s reply, and plays the reply back as audio.
What we collect
- Account data: your display name and email address. When you sign in with Google or Apple, we receive your email, your name (on first sign-in), and a stable provider account identifier — we never receive your Google or Apple password. Accounts created with a phone number instead store the phone number and a hashed password. Stored in our database.
- Audio of your voice during a tutor call: recorded on your device, sent to our backend for transcription, and discarded after the text is returned. We do not retain audio recordings.
- Transcripts of your conversations: when you save a session, the text of what you and Mira said is stored on your account so you can review it later. You can delete your account to remove this data permanently.
- Vocabulary you save during conversations, and your review history (the Hard / Good / Easy rating you give each card).
- Push notification tokens: if you grant notification permission, your device’s push token (issued by Apple, Google, or Expo’s push service) is stored against your account so we can send daily streak nudges. We delete the token when you sign out, uninstall, or delete your account.
- Usage diagnostics: sign-in events, session duration, error rate, rate-limit triggers. Used only to keep the service reliable.
- Device-level basics: OS version, app version, and the IP address the request comes from (used for rate limiting and abuse detection, not stored long-term).
What we don’t collect
- We do not record video or take photos.
- We do not collect contacts, calendar, location, or device identifiers for advertising.
- We do not include third-party analytics or ad SDKs.
- We do not sell or share your voice or transcripts with anyone.
Third-party services we use
To run Lilt we share specific data with these providers:
- DeepSeek (LLM) — we send your conversation text for Mira’s replies
- Cloudflare Workers AI — Whisper transcription of your voice; MeloTTS speech synthesis of the tutor’s replies
- Google Sign-In — if you sign in with Google, it verifies your identity and returns your email, name, and an account identifier so we can create and recognize your account. We never receive your Google password.
- Apple Sign-In — if you sign in with Apple, it verifies your identity and returns your email (or a private relay address), name on first sign-in, and an account identifier. We never receive your Apple password.
- Payme — if you buy a Premium subscription on the web, Payme (Paycom) processes the payment. You enter your payment details with Payme directly; we receive only the order and its transaction status to unlock Premium. We never see or store your card number.
- Eskiz — if you use phone-number sign-in, we send your phone number to Eskiz to deliver the one-time SMS verification code.
- Resend — for any verification or password-reset emails (legacy email/phone accounts).
- RevenueCat — only if/when in-app purchases ship on the mobile app; if you purchase a Premium subscription through the app store, RevenueCat receives your Lilt user ID and your App Store / Play Store purchase receipt to track entitlement state. No transcripts, no audio, no personal content — only the opaque account ID and the receipt the store itself issues. RevenueCat passes the receipt back to Apple / Google for validation; we use the result to unlock Premium features.
These providers process the text only long enough to return their output, and per their terms do not retain it for training. If you’d prefer not to use them, the only path today is to not use the app.
How long we keep your data
- Account, transcripts, vocabulary: until you delete your account, or for 24 months after your last sign-in (whichever is sooner).
- Recorded audio: not retained — deleted within seconds of transcription.
- Diagnostic logs: 90 days.
Your choices
- Sign out of all devices: Settings → Account → Sign out of all devices.
- Delete your account, which removes everything tied to your account on our side, including transcripts and vocabulary: Settings → Account → Delete account. You can also delete your account from outside the app at https://lilt-cu8.pages.dev/delete-account — useful if you’ve uninstalled the app or don’t want to download it just to delete. This is irreversible.
Children
Lilt is rated 4+/Everyone but is not directed at children under 13. We don’t knowingly collect data from children under 13. If you believe a child has signed up, email us (below) and we’ll remove the account.
Changes to this policy
If we materially change what we collect or how we use it, we’ll update this page and increment the date at the top. For substantive changes we’ll also email you.
Contact
Questions, requests for data export, or to report a privacy concern: hello@lilt.app