Privacy Policy
What we collect
The app stores your account details and learning data.
- Sign-up details: email, username, full name, date of birth, phone number.
- Your settings: the language the app speaks to you in, the language you're learning, and the level you tested into.
- Everything learning produces: your card schedule, your XP, your streak, the Spanish you write, your chat threads.
- Your voice, from four places: the onboarding interview, the reading task, the listening task and bug-report dictation. The spoken onboarding interview and the level exam are one thing rather than two: a single live voice call, once per phone per language.
Where each recording goes
The recordings aren't handled the same way, so here's each one.
Reading and listening: the phone sends the audio to our server, the server passes it to a speech-to-text provider, and the text that comes back is stored with your account. The recording itself isn't kept.
The onboarding interview: LiveKit carries the call. The transcript is written to a row filed under the phone you took it on rather than under your account, because the app on phones today never makes that link. The section on deleting your account says what that means for getting it cleared.
Bug-report dictation: You can dictate a bug report instead of typing it after signing in to a verified account. Guests type their reports, and the mic isn't shown. The recording is stored as a file at Sentry alongside the report, even if transcription fails.
Why we have it
The app is a memory system. It has to know what you got right on Tuesday to decide what to put in front of you on Friday, and it has to see how you actually write Spanish to build tomorrow's episode around your mistakes. Take the learning data away and there's no product left, just a podcast.
The sign-up details do narrower work. Email and password get you back into your account. The phone number is where the verification code goes, and it's a second way back in when you forget a password. The date of birth does two jobs: signup refuses anyone under 13, and it decides whether lessons are allowed to use vulgar slang.
Who else touches it
YapZee runs on other people's software, so your data passes through companies paid to do one specific job each. These are the ones our own code sends it to.
- Supabase: the database your account lives in, and sign-in.
- Cloudflare R2: file storage, including the audio the app generates.
- PostHog: counts what happens in the app.
- Railway: the servers the app talks to.
- Fish Audio: turns text into the voices you hear.
- Groq: turns your speech into text.
- OpenAI: also turns your speech into text.
- OpenRouter: and the model providers behind it, write your lessons.
- LiveKit: carries live voice.
- Twilio: sends the verification text at signup.
- Sentry: catches crashes.
Some of that happens off your phone
Your device doesn't call most of those companies directly. The audio from the reading and listening tasks goes to our server first, and the server sends it on to a speech-to-text provider. The onboarding interview is the exception: your phone joins that call with LiveKit directly. Either way it's your data leaving, so it's listed that way rather than hidden behind the word "infrastructure".
We don't sell any of it. There's no ad network in the app and no tracking SDK beyond the two named above.
What Sentry gets, and what it doesn't
This is the one people assume is anonymous, so it gets said in full rather than summarised.
While you are signed in, Sentry receives your email address and username. A crash can include a screenshot. A manual bug report carries what you wrote and a screenshot captured as the report sheet opens. If voice reporting is available and you use it, the recording is attached. Sentry does not receive your IP address or session headers. Session replay is off. Sentry files reports by bug rather than by person, so deleting your account does not remove those reports.
What we deliberately don't send PostHog
PostHog is told which model ran and what it cost. It is not sent the prompt or the answer. A lesson prompt carries your memory state and every mistake you've made in writing, and handing that to an analytics company is a decision nobody asked us to make.
One exception, and it's the kind that usually goes unmentioned. When a lesson fails to generate, the error report we send carries the strings the pipeline choked on, and those can include phrases from your own review queue. So on a failure, a little of your writing does reach PostHog.
Feedback you choose to send
If you choose Feedback & ideas on this website, your message and whether it is a feature request or general feedback go to PostHog's European servers. The website uses a temporary visitor identity. The form does not submit your message until you press Send.
The website respects Do Not Track, Global Privacy Control, and your saved opt-out.
The form keeps your draft when you close it. Leaving or reloading the page can clear it. The form does not save your message in browser storage.
Feedback is separate from Sentry bug reports. No screenshot, audio recording, or lesson history is included.
The website you're reading this on
Separate thing, and simpler. This site is a pile of static files served from Cloudflare. No cookies, no ad network, nobody buying a look at you.
It counts which course you pick, which sections you read, whether you tap a store badge, and whether the support form opened an email draft or ran into its length limit. Nothing records your screen or follows your mouse.
Those counts and any feedback you choose to submit go to PostHog's European servers. The website uses an in-memory visitor identity that clears on page reload.
Appearance, sound, and the analytics opt-out are the preferences saved in this browser. Feedback drafts are not saved there.
Getting a copy of your data
Not yet. There's no export button in the app, and there's no quiet manual process behind it either. Nobody can run one for you today. When there is one, it'll be described here.
You can still write to privacy@yapzee.ai and ask what we hold on you. What comes back is an answer from a person rather than a file, and the contact note further down is worth reading before you count on the timing.
Deleting your account
Settings, Danger Zone, DELETE ACCOUNT. Seven days to change your mind, and signing back in during that week calls it off.
Day seven is the one deadline the server keeps on its own, and it is narrower than it sounds. Once it passes, signing back in stops calling the deletion off, and the account screens start refusing. Everything else carries on. The lessons, the audio and the writing all keep working for as long as you stay signed in, and the app refreshes that session by itself, so staying signed in is the default rather than something you have to manage. The step that would actually end the session is the scheduled one that has never run.
What has never run is the scheduled job behind the rest: deleting the sign-in itself on day seven, clearing everything else on day thirty, and wiping level-exam recordings after ninety days. Nothing calls that job, so it has never closed or cleared anybody's account. Until something does, finishing a deletion takes a person. If you want yours finished now, write to privacy@yapzee.ai and say so.
Full instructions are on the delete-account page. Seven things outlive a deletion, and five of them can still be traced back to you or to your phone. That page names all seven and says how long each one stays.
The companies a deletion never reaches
The list above has eleven companies on it. A deletion reaches three.
It runs against Supabase, which holds your account and everything you learned; Cloudflare R2, which holds the audio the app made for you; and PostHog, which holds the analytics profile. Inside Cloudflare it leaves two things alone on purpose: the pronunciation audio and the grading notes are shared by everyone who ever tapped the same word, so there is no copy of them that belongs to you, and removing them would take everybody else's with it.
It never calls Railway, Fish Audio, Groq, OpenAI, OpenRouter, LiveKit, Twilio or Sentry. So the verification text, the interview call, the audio posted for transcription and the prompts carrying your writing stay wherever those companies keep them, on their retention schedules rather than on one of ours. We haven't published a period for any of that, because we don't set it.
What a real privacy policy has that this one doesn't
So you know exactly what you aren't reading:
- How long we keep things while you're still using the app. One window is enforced today, and it's the seven days you have to undo a deletion. Two more numbers are set in the code and published on the delete-account page, thirty days until your data is cleared and ninety before a level-exam recording is wiped, and neither has run for anybody yet. Nothing else has a period, so nothing else has a number here.
- Which laws apply and what your rights are under them. Naming a regulation we haven't been checked against would be a claim rather than a fact.
- Where your data physically sits, and what covers it when it crosses a border.
- Anything about children and this app.
- A formal route for complaints.
Reaching a person
Anything about your own data goes to privacy@yapzee.ai. That means a copy of what we hold, a correction, or a deletion. One person reads that mailbox, and it's the person who built the app. Replies arrive from a personal address rather than a yapzee.ai one, which is expected and not someone impersonating support.
Found a security problem instead? security@yapzee.ai. Please write there rather than posting it publicly, and you will get an answer.
Everything else is support@yapzee.ai, and the help page has a form that fills the mail in for you.
When this page changes
It gets replaced. The finished policy is being written by a vendor whose whole job is writing these, and when it lands it goes up here in one piece with a date on it.
If something in the app changes what we collect before then, this page gets updated.