Privacy Policy (Datenschutzerklärung) for spralingua.com
Last updated: 21 August 2026
This Privacy Policy explains what personal data spralingua.com ("Spralingua," "we," "us") collects when you use our website and app, why we collect it, who we share it with, and what rights you have. Spralingua teaches German through real-time voice conversations with AI conversation partners and AI-graded written and spoken exercises. We are based in Germany, and this policy is written to comply with the EU General Data Protection Regulation (GDPR).
1. Who is responsible for your data (the controller)
The controller responsible for the personal data described in this policy is:
Spralingua
Berlin, Germany
Spralingua is operated as a sole proprietorship. Given the current size and nature of our processing, we are not required to appoint a Data Protection Officer under Art. 37 GDPR, and we have not appointed one. For any privacy question or request, please contact us via the contact details published in our Impressum.
2. What personal data we collect
We collect only the data needed to run the service. Here is exactly what that is.
2.1 Account and sign-in data
You sign in with Google. We receive and store your Google account ID (the "sub" claim), your email address, your name, and your profile picture URL. We check whether Google has verified your email address at sign-in, but we do not store that verification flag. This data is stored together with your account, streak, and level data.
2.2 Voice conversations: recordings and transcripts
When you have a voice conversation with an AI partner, we record and keep the full audio of that session as an MP3 file. This applies to every voice conversation on Spralingua, including:
- the unauthenticated homepage demo, which is recorded under a shared, anonymous "demo" identity and capped at roughly three minutes; and
- conversations with our AI teacher persona ("Clara"), who explains German grammar in English.
We also generate and store a full text transcript of every voice session in our database.
2.3 Written and spoken exercises and your personal error record
When you complete a written or spoken exercise, your answer is processed by an AI system to grade it. We store the graded outcome (pass/fail and the grammar pattern involved).
To personalize your practice, we also keep a learning-error record: for each grammar pattern you tend to get wrong, we store up to five verbatim example sentences of your own mistakes, together with the corrected version. In plain terms: we store examples of your actual mistakes so we can tailor future practice to you.
2.4 Vocabulary, progress and streak data
We store your vocabulary deck and card progress, your drill history, your daily streak and daily-completion data, and the CEFR level you have told us you are at (self-declared, not independently verified).
2.5 What we store in your browser — and what we don't
We use your browser's localStorage (not cookies) to store two things: your session token and a local copy of your profile (together, spralingua_auth), and a small set of non-personal UI preferences (such as display settings).
We do not use cookies. We do not use any analytics, tracking, or advertising technology of any kind — not our own, and not from any third party.
Because the only thing stored locally is a login token that is strictly necessary to keep you signed in, this falls under the "strictly necessary" exemption in § 25(2) of the German Telecommunications-Digital-Services-Data-Protection Act (TDDDG). That is why you do not see a cookie/consent banner on Spralingua: nothing non-essential is being stored without your knowledge, and there is nothing non-essential to ask consent for.
2.6 IP addresses
Our application itself does not store your IP address. It is used only transiently, in memory, to apply rate limits (for example, to stop abuse of the free homepage demo), and is not written to any database or log we control. Our hosting provider, Railway, necessarily processes connection-level data (such as IP addresses) as part of operating the servers, in the same way any web host does.
3. Why we process your data, and our legal basis
GDPR requires us to have a specific legal basis for each purpose we process data for. We do not rely on one blanket basis — here is the basis for each activity:
| What we do | Legal basis |
|---|---|
| Creating and maintaining your account, signing you in | Art. 6(1)(b) GDPR — necessary to perform our contract with you |
| Running the voice conversation service (speech-to-text, generating the AI's reply, speech synthesis) | Art. 6(1)(b) GDPR — necessary to provide the service you signed up for |
| AI grading of exercises, maintaining your personal error ledger, and personalizing your practice | Art. 6(1)(b) GDPR — this personalization is the core of what you sign up for |
| Storing session recordings and transcripts, so you can review your own history and so we can maintain service quality | Art. 6(1)(b) and Art. 6(1)(f) GDPR — contract performance, and our legitimate interest in maintaining and improving service quality |
| Observability and tracing of our systems (via Langfuse), for reliability and cost monitoring | Art. 6(1)(f) GDPR — our legitimate interest in keeping the service reliable and financially sustainable. Note: these technical traces include the content of your conversations and the prompts used to generate replies |
What happens if you don't provide this data: an email address and a Google account are required to create a Spralingua account. Without one, you can still use the free, unauthenticated homepage demo, but you cannot access the full service (saved progress, personalized practice, tandem partners, and so on).
4. Who else sees your data
We use a small number of outside service providers ("processors") to run Spralingua. None of them are allowed to use your data for their own purposes. The table below lists each one, what it receives, and the legal mechanism that allows us to send data there if it leaves the EU/EEA.
| Service | Company | Country | What it receives | Transfer mechanism |
|---|---|---|---|---|
| Speech-to-text | Deepgram Inc. | United States | Your voice audio — both live conversation streams and recorded spoken-exercise clips — for transcription | EU Standard Contractual Clauses (SCCs) |
| Text-to-speech (AI tutor's voice) | MiniMax | China | Only the text of the AI tutor's own reply, so it can be spoken aloud. MiniMax never receives your voice audio, anything you wrote or said, or any identifier that could identify you. | EU Standard Contractual Clauses (SCCs) |
| AI conversation and grading (primary) | Cerebras Systems Inc. | United States | The text of your conversation and your exercise answers, to generate the AI's replies and to grade your work | EU Standard Contractual Clauses (SCCs) |
| AI conversation and grading (routing / fallback) | OpenRouter Inc. | United States | The same conversation/exercise text, used as a routing layer and as a fallback if our primary provider is unavailable | EU Standard Contractual Clauses (SCCs) |
| Observability and tracing | Langfuse | European Union (cloud.langfuse.com is EU-hosted) | Conversation content, exercise data and technical performance data, to monitor reliability and cost | Not applicable — this data stays within the EU |
| Sign-in | Google LLC | United States | Your Google account ID, email, name and profile picture, to authenticate you | EU-U.S. Data Privacy Framework |
| Pronunciation assessment (when active) | Microsoft Corporation (Azure Speech) | Processed in the EU (West Europe/Amsterdam region); Microsoft is a US-headquartered company | Your voice audio, to assess your pronunciation, when this feature is active. This feature is not currently active, but remains built into the service and may be re-enabled. | Processing occurs within the EU; EU-U.S. Data Privacy Framework applies to any incidental US-based administrative or support access |
| Hosting (servers, database, file storage) | Railway Corporation | Servers, database and audio files all run in Railway's EU-West (Amsterdam) region; Railway is a US-headquartered company | All application data at rest — your account, database records and audio recordings — plus ordinary connection/hosting data | Application data at rest is stored in the EU; EU-U.S. Data Privacy Framework applies to any US-based administrative or support access |
In plain terms: all of your application data at rest — your account, your database records, your audio recordings — is stored on servers in the EU.
We do not currently process any payment data. Spralingua is free today; paid plans are planned. Before any paid plan launches, this policy will be updated to name our payment processor and describe that processing.
5. How long we keep your data
- Account and learning data (profile, vocabulary deck, drill history, streak, error ledger): kept for as long as your account exists, and deleted when you ask us to delete your account.
- Session audio recordings: kept on our server infrastructure. Recordings are routinely cleared during infrastructure updates. We are in the process of introducing a fixed retention period for audio; until that is in place, we cannot give you a specific number of days, but recordings do not persist indefinitely as a matter of course.
- Transcripts and other learning records: kept for as long as your account exists.
- Observability traces (Langfuse): kept according to our observability provider's project-level retention settings.
6. Your rights
Under the GDPR, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict how we process your data
- Object to processing based on our legitimate interest (Art. 6(1)(f))
- Data portability — receive your data in a structured, machine-readable format
- Withdraw consent at any time, for any processing that is based on consent. Note: none of the processing described in this policy is currently based on your consent (Art. 6(1)(a)) — see Section 3 for the actual bases we rely on.
How to exercise these rights: Spralingua does not yet have a self-service way to export or delete your data in the app. To exercise any of the rights above, please contact us via the contact details published in our Impressum. We will respond within one month, as required by Art. 12(3) GDPR (this can be extended by two further months for complex requests, in which case we will tell you why).
Right to complain: You also have the right to lodge a complaint with a data protection supervisory authority. You may complain to any supervisory authority in the EU, including the authority for the German federal state (Land) where we are established.
7. Automated evaluation of your practice
Your written and spoken exercises, and your voice conversations, are evaluated automatically by AI systems — for example, to grade an answer, judge pronunciation, or detect a grammar error. These automated evaluations only affect practice recommendations and in-app feedback — for example, which grammar patterns we focus on with you next, or what your AI tutor brings up in conversation. They do not produce any legal effect or similarly significant effect on you, so they do not fall under Art. 22 GDPR.
8. AI transparency — you are always talking to an AI
In line with Art. 50 of the EU AI Act, we tell you plainly: every conversation partner and tutor on Spralingua is an AI system, and all of their speech is synthetically generated — none of it is a real person. You are informed of this in-product before every session, not just here.
9. Age requirement
Spralingua is intended for users aged 16 or over, consistent with the age of consent for information-society services under Art. 8 GDPR and German law. We do not knowingly collect data from users under 16.
10. Changes to this policy
We may update this policy as the service changes — for example, when we introduce paid plans, or if we re-enable pronunciation feedback. We will update the "Last updated" date at the top when we do.
We do not use analytics, tracking, or advertising today. If that ever changes, we will update this policy and put a proper consent mechanism in place first, before any such technology goes live — not after.