← Colloquial Terms of Service →

Privacy Policy

Last updated: 11 October 2026

Colloquial ("we," "us," "Colloquial") is an audio flashcard app built and operated by ELLIS, Felix Adrian Raymond, an individual based in Hong Kong ("the developer"). Colloquial is not currently operated by an incorporated company. This policy explains what data the app collects, why, and what control you have over it.

If anything here is unclear, email help@getcolloquial.com — a real person reads it.

The short version

Colloquial exists to help you practise a language by voice. To do that, it stores the audio flashcards you record, remembers when you've practised, and rings your phone at times you've scheduled. It does not show ads, does not have an ad network or advertising ID in it anywhere, does not sell your data to anyone, and never uses your voice recordings to train any AI model — yours or anyone else's. Your audio is played back to you and nobody else.

What we collect

Account information. Your email address, collected when you sign up. Authentication (including OAuth sign-in and password handling) is managed by our authentication provider, Supabase — we never see or store your password directly. If you sign in with Google, the name on your Google account is also stored with your account. Sign in with Apple supplies only your email address.

Your audio recordings. The question and answer audio you record for each flashcard. This is the most sensitive data this app handles, so to be explicit: this audio is used for exactly one purpose — playing it back to you during your own practice sessions. It is never transcribed for training purposes, never listened to as a matter of course, never shared with any third party, and never used to improve any product, ours or anyone else's.

Flashcard text (optional). Short text labels you optionally attach to a card, in addition to its audio.

Review and scheduling history. Which cards you've rated "got it" or "needs work," when, and your resulting spaced-repetition schedule. Used only to decide which cards are due for your next practice session — this data isn't shared or compared across users.

Scheduled session data. When you've asked to be called for practice, your timezone, and the outcome of each call (answered, declined, completed) — needed to actually ring your phone at the right time and to show you your own practice history.

Announcements you've dismissed. Which in-app announcement cards you've dismissed or opened, so that each one is shown to you only once. This is deleted with your account and included in your data export.

Library decks withdrawn from your decks. If we have to withdraw a library deck because we lose the right to offer it, we keep a note of which of your decks it affected and how many cards were removed, so that the app can tell you once. This is deleted with your account and included in your data export.

Changes to your card limit. If we change your card limit, usually because you asked for more cards, we keep a note of the previous and the new limit, when it was changed, and when you saw the notice telling you, so that the app can tell you once. This is deleted with your account and included in your data export.

Device and push tokens. A token identifying your device, used solely to trigger the incoming-call notification (via Apple's VoIP push service or Firebase Cloud Messaging) at your scheduled time. This is not used for tracking, advertising, or any purpose beyond delivering that one notification. The notification also carries the name of the deck you're practising, which your phone shows on the incoming call.

Product usage analytics. We use PostHog (hosted on PostHog's EU infrastructure) to understand how the app is used in aggregate — e.g., whether a practice call was answered, whether a session was completed. These events do not include your audio or flashcard content, and are tied to your account only to help us fix problems and understand real usage, not to build an advertising profile. It is off until you agree. The app asks once, after your first completed practice call, and you can change your answer at any time in Settings. By agreeing, you confirm that you are 16 or over.

Crash and error reports. We use Sentry to catch and fix bugs and crashes, on both the app and our backend. Error reports may include technical details about what the app was doing when something went wrong; we do not log audio content, full push tokens, or raw audio URLs in these reports. Reports identify your account by an internal ID, never by your email address, and don't record your IP address. Sentry deletes them after 30 days.

Transactional email. Our provider Resend delivers the email about your account, such as sign-up confirmation and password reset. If you request a data export (see "Your rights," below), we send you one email, via our provider Resend, containing a link to download it. We do not send marketing email and do not maintain a mailing list from your account email.

Who we share data with

We use a small number of infrastructure providers to run the app — none of them are advertising or data-broker companies, and none of them are permitted to use your data for their own purposes:

ProviderWhat they handle
SupabaseAccount authentication and our primary database
CloudflareHosts this website, and stores your audio recordings (R2)
Fly.ioHosts our backend application (Amsterdam, EU region)
PostHogProduct usage analytics (EU-hosted instance)
SentryError and crash monitoring
GoogleDelivery of practice-call notifications to Android devices (Firebase Cloud Messaging), sign-in if you choose to sign in with Google, and encrypted backups of our database and your audio recordings (Google Cloud Storage, Frankfurt)
AppleDelivery of practice-call notifications to iPhone and iPad (Apple Push Notification service), and sign-in if you choose Sign in with Apple
ResendDelivery of the account email described above: sign-up confirmation, password reset and data-export links (sent from the EU; delivery logs stored in the United States)
KitYour email address, if you sign up with the form on this website (United States)
AnthropicAI-assisted operations tooling (Claude). It sees aggregate statistics only, never your account details, recordings or flashcard content.
MistralAI assistant in our internal operations dashboard, hosted in the EU. It reads service health, error reports and usage statistics, never your recordings or flashcard content. It sees your account details only when we grant access for one investigation, and we record every grant. Mistral does not use your data to train its models.

We do not sell personal data to anyone, for any reason. We do not work with advertising networks, data brokers, or analytics-for-advertising services. There is no advertising identifier, ad SDK, or third-party tracking pixel anywhere in this app.

Some of these providers process data in the United States as well as the EU. Where that happens, the transfer is covered by the provider's own certification under the EU-US Data Privacy Framework, Standard Contractual Clauses, or both.

Cookies and storage

This website sets no cookies and uses no local storage or tracking pixels. Our analytics run in cookieless mode, which means PostHog counts visitors using a privacy-preserving hash calculated on its own servers rather than anything saved in your browser.

If you sign up with the email form on this website, your address goes to Kit, the service that sends our emails. We use it only for what you signed up for, joining the test or hearing when the app reaches your country, and every email has an unsubscribe link. We delete it when you unsubscribe, or after 12 months without engagement.

The app itself stores your settings and login session on your device, which is what lets you stay signed in between sessions.

How long we keep your data

Your account data, audio, and review history are kept for as long as your account exists. If you delete a specific card or deck, its audio is permanently removed from our storage, not just hidden. That happens within 30 days rather than instantly, and the card's text and review history go at the same time. If you delete your account entirely (see below), everything is removed. Data-export files you request are deleted 48 hours after we create them. We also keep encrypted backups of the database and of your audio for up to 30 days, in Frankfurt, so that we can recover from a failure. Only we hold the key that can read them. When you delete your account, your data has left every backup within 40 days.

Your rights

Wherever you're located, you have meaningful control over your data, not just a legal entitlement on paper:

On-device speech recognition

If you use hands-free call rating, the app uses your device's own built-in speech recognition to detect what you said — this recognition happens entirely on your device. Nothing is sent to any server for this feature, and we never receive a transcript or recording from it.

Children's privacy

Colloquial is not directed at children. During sign-up, you're asked to confirm you're 13 or older; we don't collect a date of birth or otherwise independently verify age. If we become aware that someone under 13 has provided us personal information, we will delete it. Parents who believe their child has done so can contact us at help@getcolloquial.com.

Security

We use industry-standard measures to protect your data: audio files are never exposed via a permanent public URL — every playback link is a time-limited, cryptographically signed link generated on request. Data in transit is encrypted. Access to raw infrastructure (databases, storage) is restricted to the developer. No system is perfectly secure, and we can't guarantee absolute security, but we treat your recordings the way we'd want our own treated.

Changes to this policy

If we make a material change to how we handle your data, we'll update the date at the top of this page and, for significant changes, notify you in the app.

EU and UK representatives

We are based in Hong Kong. Under Article 27 of the GDPR and the UK GDPR we have appointed representatives you can contact about how we handle your data:

EU: Rickert Rechtsanwaltsgesellschaft mbH
– Felix Adrian Raymond Ellis / Colloquial –
Colmantstraße 15, 53115 Bonn, Germany
art-27-rep-colloquial@rickert.law

UK: Rickert Services Ltd UK
– Felix Adrian Raymond Ellis / Colloquial –
PO Box 1487, Peterborough PE1 9XX, United Kingdom
art-27-rep-colloquial@rickert-services.uk

To exercise your rights through them, for example to ask for access to your data or its deletion, email them at the address for your region above.

Contact

Questions, data requests, or concerns about this policy: help@getcolloquial.com.

This policy is governed by the laws of Hong Kong SAR. If you live in the EU, EEA, or UK, nothing in this policy limits the rights you're entitled to under the GDPR or UK GDPR, and if you live somewhere else whose law gives you data-protection rights that can't be signed away by agreement, those rights apply too, regardless of this governing-law clause.