Speakroom is operated by Code Bakery BV, incorporated in Belgium ("Speakroom," "we," "us," or "our").
This Privacy Policy explains how we collect, use, store, share, and protect personal data when you use Speakroom, including our website, web application, AI language tutoring features, voice features, billing features, and related services (the "Service").
If you have questions, contact us at:
1. Summary
Speakroom is a voice-first AI language practice app. To provide the Service, we process account information, language settings, tutoring sessions, transcripts, replay audio, AI-generated tutor responses, coach notes, credit balances, and billing records.
Key points:
- Speakroom uses artificial intelligence to generate tutor responses, translations, transcripts, and feedback.
- You are interacting with AI software, not a human tutor.
- We store replayable audio files from tutoring sessions, including your spoken audio and AI tutor response audio, so you can replay conversations later.
- Speakroom itself does not use your audio, transcripts, messages, or tutoring sessions to train or fine-tune AI models.
- Google Gemini and OpenAI may process your content on our behalf to provide AI features, depending on the feature and provider configuration.
- We do not sell your personal data.
- You can delete ended or abandoned tutoring sessions, or delete your account.
- Speakroom is intended for users aged 18 and older.
2. Who controls your data
For purposes of the GDPR and other applicable privacy laws, the data controller is:
Code Bakery BV Belgium Email: [email protected]
We have not appointed a Data Protection Officer. You can contact us at the email above for privacy requests.
3. Data we collect
Account data
When you sign in, we collect or receive:
- email address
- first and last name, if provided by the authentication provider
- display name
- WorkOS user identifier
- internal Speakroom user ID
- account creation and update timestamps
- account deletion/tombstone status, if applicable
- onboarding/legal acknowledgement evidence, including acknowledgement version, Terms/Privacy versions, checkbox/copy version or hash, timestamp, language/path shown, request ID, source IP address, and user-agent metadata
Authentication is provided by WorkOS. Speakroom stores only an opaque app-session cookie in your browser. WorkOS session material is stored server-side in encrypted form.
Preferences and settings
We store settings used to personalize your practice, such as:
- app/review language
- target language
- tutor style
- speech pace
- language mix
- selected tutor voice
- microphone mode
- preferred session length
- last selected scenario
Tutoring session data
When you use Converse, Translate, Review, or related tutoring features, we may collect and store:
- tutoring session records
- selected language and scenario
- settings snapshot for the session
- text you type
- audio you speak
- transcripts of what you said
- AI tutor transcripts
- translations
- AI-generated feedback and coach notes
- pronunciation, grammar, and general feedback
- evaluation status and error state
- session timestamps and exchange/turn metadata
Audio data
Speakroom stores replay audio for tutoring sessions as replayable audio files, including:
- your spoken audio
- tutor response audio
- audio duration
- audio file size
- sample rate
- audio creation timestamp
- private storage object key
We store this audio so you can replay your conversation later in Review.
Microphone audio may include background sounds or voices of people near you. Please do not submit another person's voice, conversation, or confidential information unless you have the required rights and consents. Speakroom is designed for your own language practice, not for recording third parties.
We process speech characteristics such as pronunciation, pace, fluency, grammar, vocabulary, and intelligibility to provide language-learning feedback. We do not use your voice to identify you, create a voiceprint for identification, infer sensitive traits, infer emotions, or perform biometric identification.
Billing and credit data
If you buy credits, we store:
- selected credit pack
- number of credits/interactions purchased
- amount and currency
- Stripe Checkout session ID
- Stripe payment status
- local fulfillment status
- credit grants
- remaining credit balance
- usage ledger entries
- refund/debit records where applicable
- Stripe webhook audit records
- checkout consent evidence, including consent version, statement versions, copy hash, timestamp, page path, request ID, source IP address, and user-agent metadata
We do not store full card numbers or payment card security codes. Payments are processed by Stripe.
Technical, security, and log data
We may collect:
- IP address
- request metadata
- browser/device metadata
- authentication/session metadata
- error codes
- timestamps
- security and abuse-prevention logs
- WebSocket connection metadata
- provider status/error metadata
We do not intentionally log raw audio, full transcripts, app-session tokens, CSRF tokens, provider API keys, or raw AI provider payloads.
Support data
If you contact us for support, we may collect:
- your email address
- support message content
- information you choose to provide
- relevant account/session identifiers
- limited diagnostic information needed to investigate your request
If you ask us to investigate a specific tutoring issue, authorized personnel may access relevant session data, transcripts, audio, or AI feedback only as reasonably needed to respond to your request, debug the issue, maintain security, or comply with law. We restrict this access to people who need it for those purposes. We do not use support access to train AI models.
4. How we use your data
We use personal data for the following purposes:
| Purpose | Data used | Legal basis under GDPR |
|---|---|---|
| Create and manage your account | account data, WorkOS identity, session data | performance of contract |
| Authenticate you and keep sessions secure | auth/session data, CSRF data, security logs | performance of contract; legitimate interests |
| Provide tutoring, translation, review, and replay | text, audio, transcripts, settings, session records, AI outputs | performance of contract |
| Generate AI tutor responses and feedback | messages, audio, transcripts, context, settings | performance of contract |
| Store replay audio | user audio, tutor audio, audio metadata | performance of contract |
| Manage credits and usage | credit grants, ledger entries, session/exchange metadata | performance of contract |
| Process payments | billing metadata, Stripe session data | performance of contract; legal obligation |
| Prevent fraud, abuse, and security incidents | logs, account/session metadata, billing audit records | legitimate interests; legal obligation |
| Respond to support requests | support messages, relevant account/session data | legitimate interests; performance of contract |
| Comply with legal, tax, and accounting obligations | billing records, audit records, account tombstone data | legal obligation |
| Improve reliability and product quality | aggregated or de-identified usage and performance data | legitimate interests |
Speakroom does not use your tutoring content, transcripts, or audio to train AI models.
Where we rely on legitimate interests, those interests are: keeping Speakroom secure and reliable; preventing fraud, abuse, and unauthorized access; debugging errors; responding to support requests; enforcing our terms; protecting billing and payment integrity; and understanding aggregated or de-identified product reliability and usage patterns. We balance these interests against your privacy rights and do not use identifiable tutoring content for advertising or model training.
5. Data needed to provide the Service
Some data is necessary to use Speakroom. For example, account and authentication data are needed to sign in; tutoring settings, text, audio, transcripts, and AI outputs are needed to provide tutoring, translation, Review, and replay; and billing data is needed if you buy credits. If you do not provide required data, we may not be able to provide the relevant feature. Support messages are optional, but we may not be able to respond to a support request without enough information to investigate it.
6. AI processing
Speakroom uses AI providers to power tutoring features.
Depending on configuration and feature, your text, audio, transcripts, recent conversation context, settings, and related metadata may be sent to:
- Google Gemini / Google AI
- OpenAI
These providers process data on our behalf to provide:
- AI tutor responses
- speech transcription
- tutor audio
- translation
- review feedback
- pronunciation/grammar/general coach notes
We do not permit Google or OpenAI to use your Speakroom audio, transcripts, or messages to train their general AI models under our API/provider terms and settings.
Provider systems may temporarily retain API data for abuse monitoring, security, reliability, debugging, or legal compliance according to their own API terms. We do not control every technical retention period applied by those providers, but we choose provider configurations and terms intended to prevent model training on your data.
For coach notes and Review feedback, Speakroom may retrieve stored user audio and transcripts after a session and send them to the configured AI provider for evaluation. The provider returns structured feedback, which Speakroom stores as app-owned coach notes.
AI-generated content may be inaccurate, incomplete, or inappropriate. You should not rely on Speakroom as a source of professional, legal, medical, immigration, employment, educational certification, or exam advice.
7. Model training and product improvement
We do not:
- train AI models on your session audio
- train AI models on your transcripts
- fine-tune models on your conversations
- sell conversation data
- share your content for third-party AI training
We may use aggregated or de-identified operational information to understand product performance, such as error rates, feature usage, or average session counts. We do not use identifiable conversation content for model training.
If we ever want to use identifiable session content for research, evaluation, or model improvement, we will ask for separate permission first.
8. Where your data is stored and processed
At launch, Speakroom uses or may use the following providers:
| Provider | Purpose | Role / notes |
|---|---|---|
| Hetzner | application and database hosting | infrastructure provider for the production application and database |
| Cloudflare R2 or equivalent S3-compatible object storage | private replay audio storage | private storage for replay audio; production launch assumes an EU-pinned private bucket or equivalent private EU storage |
| WorkOS | authentication and hosted sign-in | authentication provider |
| Stripe | payment processing, tax/payment records, checkout | payment processor; card data is handled by Stripe |
| Google Gemini / Google AI | AI tutoring, transcription, feedback, translation, or evaluation features | AI provider under applicable API terms and settings |
| OpenAI | AI tutoring, transcription, feedback, translation, or evaluation features | AI provider under applicable API terms and settings |
| Mailbox.org | support email service | email provider for [email protected]; operated by Heinlein Support GmbH (Germany, EU) |
We try to keep core application hosting in the EU/EEA where our infrastructure configuration allows it. Some providers that help us operate Speakroom are based in, or may process data in, countries outside the EEA, including the United States. This may include WorkOS, Stripe, Cloudflare, Google, OpenAI, and their subprocessors. Where required, we rely on appropriate safeguards such as Data Processing Agreements, the European Commission's Standard Contractual Clauses, the EU-U.S. Data Privacy Framework where applicable, transfer impact assessments, and provider technical and organizational measures. You can contact us at [email protected] to request more information about the safeguards relevant to your data.
9. Cookies and local storage
Speakroom uses necessary cookies for:
- authentication
- session security
- CSRF protection
- login state
These cookies are required for the Service to work.
| Cookie or browser item | Purpose | Type | Approximate lifetime |
|---|---|---|---|
| App session cookie | keeps you signed in to Speakroom | necessary | until expiry, logout, revocation, or account deletion |
| CSRF token cookie | helps protect authenticated unsafe requests | necessary security | short-lived/session-bound |
| OAuth/login state cookies | supports WorkOS hosted sign-in and return flow | necessary authentication | short-lived |
At launch, Speakroom does not use advertising cookies, retargeting pixels, or third-party analytics cookies. If we add non-essential analytics or marketing cookies later, we will update this policy and provide any required consent controls.
Speakroom does not use browser IndexedDB or durable browser storage as the source of truth for tutoring sessions, transcripts, audio, billing, or account data.
10. How long we keep data
We keep personal data only as long as needed for the purposes described in this Privacy Policy.
| Data type | Current retention |
|---|---|
| Account data | while your account is active; if you delete your account, direct identity fields are anonymized/tombstoned where possible, while limited internal identifiers may be retained for billing, fraud-prevention, reconciliation, and legal records |
| Authentication sessions | until logout, expiry, revocation, account deletion, or operational cleanup; expired or revoked sessions are rejected even if database cleanup has not yet run |
| User preferences and tutoring settings | until you update them or delete your account |
| Tutoring sessions, transcripts, translations, evaluations, and coach notes | until you delete the session or account, or until age-based maintenance deletes terminal sessions under the configured retention window; ended sessions are currently retained for up to 24 months after session end unless we must retain limited information for legal, security, billing, or dispute reasons |
| Replay audio | retained with the tutoring session so Review replay works; deleted when you delete the session/account or when age-based maintenance deletes the owning session, unless deletion is delayed by backup rotation or a temporary operational issue |
| Abandoned/incomplete sessions | stale active sessions may be marked abandoned; abandoned sessions remain deletable from Review and are deleted on account deletion or after a shorter configured maintenance window, currently 30 days after abandonment |
| Credit grants and usage ledger | retained while your account is active and as needed for billing, fraud prevention, tax, accounting, reconciliation, and dispute handling |
| Stripe checkout and webhook audit records | retained as needed for tax, accounting, dispute, fraud-prevention, and reconciliation purposes, generally up to the applicable statutory retention period |
| Security logs | kept for a limited operational period unless needed longer for security investigation, abuse prevention, legal compliance, or dispute handling |
| Support messages | generally kept only as long as needed to handle the support request and any related legal, security, or dispute issue |
| Backups | deleted data may remain in encrypted production backups until normal backup rotation, currently planned for up to 30 days unless the production provider configuration is updated before launch; after a restore, we run deletion reconciliation before returning restored data to production service |
When you delete a tutoring session, we delete the transcript, AI feedback, evaluation records, and replay audio for that session.
When you delete your account, we delete product data such as sessions, transcripts, evaluations, settings, preferences, app sessions, and replay audio. We retain billing, tax, fraud-prevention, and audit records where required or permitted by law, but we remove or anonymize direct account identity fields where possible.
11. How we share data
We share personal data only when needed to provide, secure, or operate the Service.
We may share data with:
- authentication providers
- AI processing providers
- hosting and storage providers
- payment processors
- support and email providers
- professional advisers
- authorities or courts when legally required
- parties involved in a merger, acquisition, financing, or sale of assets, subject to appropriate protections
We do not sell your personal data.
12. Your rights
Depending on where you live, you may have rights to:
- access your personal data
- correct inaccurate personal data
- delete personal data
- restrict processing
- object to processing
- receive a portable copy of your data
- withdraw consent where processing is based on consent
- lodge a complaint with a data protection authority
To exercise rights, contact:
We may need to verify your identity before responding to a rights request. We generally respond within one month, unless applicable law allows an extension for complex or multiple requests. If we cannot fulfill a request fully, we will explain why, subject to legal limits.
If you are in the EEA, you may also complain to your local data protection authority. Because Code Bakery BV is incorporated in Belgium, the Belgian Data Protection Authority may be relevant: https://www.dataprotectionauthority.be/citizen/form-complaint.
13. Account and session deletion
You can delete ended or abandoned tutoring sessions from Review. Active sessions must be ended before they can be deleted.
You can delete your account from Settings. Account deletion:
- deletes tutoring sessions
- deletes transcripts
- deletes coach notes and evaluations
- deletes replay audio
- deletes preferences and tutoring settings
- deletes local app sessions
- attempts to delete the upstream WorkOS user
Some records may be retained or anonymized where needed for billing, tax, accounting, fraud prevention, legal compliance, or dispute handling. Retained records may remain linked to a tombstoned internal user ID rather than your direct identity fields. Upstream WorkOS deletion is attempted during account deletion but may depend on provider availability and legal/operational constraints.
14. Children
Speakroom is intended for users aged 18 or older.
Do not use Speakroom if you are under 18. We do not knowingly collect personal data from children. If you believe a child has provided personal data to Speakroom, contact us at [email protected].
15. Security
We use technical and organizational measures designed to protect personal data, including:
- HTTPS in production
- secure, HttpOnly session cookies
- CSRF protection for unsafe authenticated actions
- encrypted server-side WorkOS session material
- restricted backend access to AI provider secrets
- authenticated access checks for replay audio
- private no-store headers for account, billing, tutoring, and audio responses
- production security headers
- restricted service-worker caching of public assets only
No internet service can be guaranteed completely secure. If you believe you found a security issue, contact us at [email protected].
16. Automated decision-making
Speakroom generates AI feedback, translations, transcripts, and coach notes. These outputs are for informal language practice only.
Speakroom does not use AI to make decisions with legal or similarly significant effects about you, such as admission, employment, credit, immigration, certification, or formal educational assessment decisions.
17. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice, such as by updating the date above, showing an in-app notice, or emailing you where appropriate.
18. Contact
For privacy questions or requests:
Code Bakery BV Belgium [email protected]