AmioraJoin the waitlist

Privacy Policy

Effective 30 July 2026

This policy explains what personal data Amiora collects, why we process it, who we share it with, how long we keep it, and the rights you can exercise. It applies to our mobile app, our website, and the services provided to companies whose team members learn with Amiora.

Who we are

Amiora is the controller of the personal data described below. For any privacy question or to exercise your rights, contact us at [email protected].

Data we collect

  • Identity and account data — your email address, name (where provided), and an authentication identifier from our sign-in provider.
  • Learning content — the conversation text you write during practice, sentences and words you save, and your progress and review history.
  • Voice audio — when you speak in a practice session, your audio is sent to a speech-to-text provider to transcribe what you said. We do not use your voice to identify you.
  • Subscription data — your plan and purchase status, handled through our app-store billing provider. We do not receive or store your full card details.
  • Product analytics and device data — if you consent, we record how the product is used (screens viewed, features used) together with basic device and app identifiers. Analytics is off until you accept.
  • Diagnostics — crash and error reports, with personal data scrubbed before they leave your device or our servers.

Why we process it, and our lawful basis

  • To provide the service (accounts, practice, progress, voice transcription, subscriptions) — performance of our contract with you.
  • To keep the service secure and reliable (diagnostics, abuse prevention) — our legitimate interest in a safe, working product.
  • To understand and improve the product (analytics) — your consent, which you can withdraw at any time.

International transfers

Amiora runs on infrastructure located in the United States, and several of our processors are US-based. Where personal data is transferred outside your country, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses or a valid data-transfer framework — with the processors listed below.

Sub-processors

We rely on the following processors to run Amiora. Each is bound by a data-processing agreement and processes personal data only on our instructions.

  • Google Firebase — authentication and account infrastructure.
  • DigitalOcean — application hosting, database, and file/media storage.
  • OpenAI, Groq, and Google (Gemini) — AI language and speech processing for practice and transcription.
  • PostHog — product analytics (only after you consent).
  • Sentry — crash and error diagnostics.
  • RevenueCat — subscription management.
  • Resend — transactional email.

How long we keep your data

We keep personal data only as long as needed for the purpose it was collected for, to meet legal obligations, and to resolve disputes. When you delete your account we delete or anonymise your personal data on a defined schedule, including copies held by our processors and in routine backups.

Your rights

You can ask us to:

  • access the personal data we hold about you, and receive a copy of it;
  • correct data that is inaccurate or incomplete;
  • delete your account and personal data;
  • restrict or object to certain processing;
  • withdraw analytics consent at any time (use “Cookie settings” in the footer).

To exercise any of these, email [email protected]. You also have the right to lodge a complaint with your local data-protection authority.

Deleting your account

You can delete your account and the data associated with it. See Account deletion for how.

Changes to this policy

If we make material changes we will update this page and, where required, ask for your consent again.