This Privacy Policy explains what data Claridad ("we", "us", "the App") collects when you use our Spanish-learning app, why we collect it, who we share it with, and the rights you have over your data. The App is operated by Ilja Niciejewski as an individual developer.

1. Data we collect

Account data

When you sign up we collect your email address. Authentication is handled by Supabase, which assigns each account a unique identifier. We never see or store your password.

Learning data

As you use the App we record your progress: lessons started and completed, answers and scores, vocabulary you have unlocked, XP, streak, and which theory articles you have read. This data is tied to your account so you can pick up where you left off across devices.

Device and analytics data

We use PostHog (EU region) to understand how the App is used in aggregate. Each event is associated with a stable internal user ID (never a provider identifier) and includes: app version, OS version, platform, device language, and which screens or buttons you interacted with. Events are batched and sent over HTTPS.

Crash and error data

We use Sentry to receive automatic reports when the App crashes or encounters an error. These reports include technical information (stack trace, app version, OS version, device model) but no message contents and no recorded audio.

Voice recordings (microphone)

Some lessons include a "Discussion" exercise where you can speak a response in Spanish. When you press record, the App captures audio using the device microphone. The recording is sent over HTTPS to our backend, which:

  1. Forwards the audio to OpenAI Whisper for transcription into text;
  2. Sends the transcript to Anthropic Claude to be scored against the lesson criteria;
  3. Returns the score and feedback to the App.

The raw audio is held in memory only for the duration of the scoring request and is not stored on our servers, in our database, or in any backup. We do not link the audio file to your account record.

A small number of anonymous transcripts (text only, no audio, no user identifier) are sampled to PostHog so we can review the quality of LLM scoring. These samples cannot be tied back to your account.

2. Why we collect each category

3. Who we share data with

We use the following third-party processors. Each is bound to use the data only to provide the service to us, not for their own purposes.

We do not sell or rent your data to anyone. We do not use your data for advertising.

4. How long we keep data

If you request account deletion, we erase your account and learning data within 30 days of the request, and stop sending your identifier to our analytics and error-reporting tools so no new event can be tied to you. Events those tools already hold are retained under their own schedules. Your account remains available until an administrator starts processing the request; access ends at that point.

5. Your rights

You can:

If you are in the EU or UK, you also have the right to lodge a complaint with your local data protection authority.

6. Children

Claridad is not directed at children under 13 (or under 16 in the EU). We do not knowingly collect data from anyone in that age group. If you believe a child has created an account, please contact us and we will delete it.

7. Security

All data in transit is sent over HTTPS/TLS. Passwords are managed by our authentication provider and never reach our servers. Backend access is restricted and logged.

8. Changes to this policy

If we change this policy in a way that affects how we handle your data, we will update the "Last updated" date at the top and, where required, notify you in the App.

9. Contact

For any privacy question, exercise of rights, or to report a concern, email ilja.niciejewski@gmail.com.