The short version.
The app is operated by [Owner to complete: legal entity name and registered address]. Questions about this policy: [Owner to complete: contact e-mail].
The app has no sign-up, no login and no user profile. We do not collect your name, e-mail address, phone number, date of birth, photograph, contacts, calendar, location or advertising identifier. Nothing you enter identifies you to us as a person.
The information you optionally enter during onboarding — a target CLB level and a test date — is stored only on your device and is never sent to us.
| What | When | Why | What happens to it |
|---|---|---|---|
| Your audio recording of a Speaking answer | When you finish a Speaking task and it is scored | It cannot be scored without being heard | Held in memory and in the web server's temporary upload area only for as long as the request runs, sent to the AI scoring provider, and deleted on every exit path — including on error. It is never written into our storage, our database or our logs. |
| Your written answer to a Writing task | When you submit a Writing task for scoring | Same reason | Processed in memory, sent to the AI scoring provider, and discarded when the response is returned. It is never written to disk on our side and never appears in a log. |
| A device identifier | With every scoring request | To count your three free sessions and enforce the daily and monthly limits, and to stop one device from consuming the service without limit | Stored on our server as the key of a small counter file. In our logs only a shortened SHA-256 hash of it is stored, never the raw value. |
| Which task you attempted | With every scoring request | The model has to know which question it is scoring | A task code such as T5 and a question code. Not personal data. |
ANDROID_ID by hashing it with a private namespace on your device.
The raw system value never leaves your phone; only the hash does.Our server writes one line for each scoring request. That line contains measurements only:
No audio, no transcript, no candidate text, no feedback text and no keys are ever written to a log. Log files are kept for 14 days and then deleted automatically.
Scoring is performed by a large language model operated by Google (“Gemini”), called from our server. Your recording or your text is sent to that model to be scored and is subject to that provider's terms for the API tier we use. We do not send your device identifier or any other identifier along with it — the provider receives the answer to be scored and nothing that identifies you.
[Owner to confirm before publishing: the exact provider entity, the API tier, and its data-retention terms, so this section names them correctly.]
We cannot read any of it. Deleting the app deletes all of it — and it is not recoverable, so export or screenshot a report you want to keep.
Subscriptions are sold and managed by Apple and Google. The purchase happens entirely inside their systems. We never see or receive your card number, your billing address or your store account identity. We receive from the store only the fact that a valid subscription exists, which the app uses to unlock paid practice. Cancellation and refunds are handled in your store account, under the store's policy.
The app contains no advertising SDK, no analytics SDK and no tracking SDK. It does not use the advertising identifier, it does not fingerprint your device, and it does not track you across other apps or websites. Nothing is shared with data brokers, and nothing is sold.
Two ordinary network facts, for completeness: the app talks to our scoring server over an encrypted connection, and it talks to the App Store or Google Play to check your subscription. Those are the only two hosts it contacts. Each of those connections discloses your IP address to the server at the other end, as any internet request does. We do not store your IP address in our logs.
The app's typefaces are built into the app itself and are never downloaded, so no font host — Google Fonts included — ever sees a request from your device.
The app is aimed at adults preparing for an English language test and is not directed at children. We do not knowingly collect personal information from children. Because there is no account and no personal data collection, we hold nothing that would identify a child user.
Depending on where you live — for example under Canada's PIPEDA or the EU/UK GDPR — you have rights to access, correct, delete and port your personal data, and to complain to a regulator.
In practice, the only data we hold that could be connected to you is the device counter keyed by the device identifier, and the 14-day metadata log. If you want them removed, contact us at the address in section 1 and tell us roughly when you last used the app and on which platform, so we can locate and delete the matching counter and log entries. Deleting the counter also ends any free sessions still attached to that device. Log entries expire within 14 days on their own.
Our server is hosted in [Owner to complete: hosting country]. The AI scoring provider processes requests on its own infrastructure, which may be outside your country. [Owner to confirm the region before publishing.]
Traffic between the app and our server is encrypted in transit. Counters and logs are stored outside the web root, so they are not reachable from the internet. API keys are held in server configuration and are never shipped in the app. Recordings are deleted on every code path, including error paths.
No system is perfectly secure; we design so that a breach would expose counters and measurements rather than anybody's voice or writing.
If we change what the app collects, we will update this page and its “last updated” date, and update the store privacy declarations to match.