Spokit Privacy Policy

Effective date: September 28, 2026

This Privacy Policy explains how PodFlyy LLC ("PodFlyy," "Spokit," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use the Spokit mobile application for iOS (the "App") and related services, and when you contact us or visit spokit.app (together, the "Service"). This policy is published at spokit.app/privacy.

Spokit is a language-learning application. It turns typed or spoken practice prompts into phrase cards, translations, word-by-word ("token") analysis, optional audio pronunciation, and spaced-repetition review. With Speak, you can practice a spoken conversation with an AI conversation partner. With Catch, you can also photograph an everyday object and turn it into a phrase card.

If you have questions about this policy or your personal information, contact us at [email protected].


1. Who We Are (Data Controller)

The controller responsible for your personal information is:

PodFlyy LLC Email: [email protected] Website: spokit.app

For users in the European Economic Area ("EEA"), the United Kingdom ("UK"), and other regions with similar laws, PodFlyy LLC is the "controller" of your personal information. Our third-party service providers described in Section 6 act as our "processors" or independent controllers as noted.


2. Scope

This policy applies to personal information we process through the Spokit iOS App and the Service. It does not apply to third-party services that operate under their own privacy policies, including the Apple App Store, Apple ID, and any third-party website you reach through a link. We encourage you to review those third parties' privacy notices.


3. Information We Collect

We collect only the information we need to operate Spokit's language-learning features, manage your account and subscription, keep the Service secure and reliable, and provide support. We describe each category below, including its source and the purposes for which we use it.

3.1 Account and Authentication Data

Source: you and your chosen sign-in provider (Apple or Google). Purpose: create and secure your account, authenticate you, and enable subscription restore and cross-device continuity.

3.2 Profile and Learning-Preference Data

Source: you, during onboarding and in settings. Purpose: personalize your learning experience, generate relevant practice content, and deliver reminders you enable.

Spokit's current version does not ask for your age range, date of birth, or free-text location.

3.3 Learning Content and User-Generated Content

Source: you, and content generated for you by the Service in response to your input. Purpose: provide, store, and synchronize your learning content and progress.

3.4 Voice Recordings and Audio Data

Source: you (microphone), and audio generated for you. Purpose: transcribe your speech into practice text and provide audio pronunciation. See Section 7 for audio-specific handling and retention.

3.5 Purchase and Subscription Data

Source: Apple's App Store and our subscription processor (RevenueCat). Purpose: activate and manage your Spokit Pro subscription, enforce your credit allowance, send subscription-related notices, and support billing questions. We do not receive or store your full payment-card number; Apple processes all payments.

3.6 Product-Interaction and Usage Data

Source: your use of the App. Purpose: operate credit and rate-limit systems, prevent abuse, diagnose failures, and improve reliability.

3.7 Device and Technical Data

Source: your device and our backend. Purpose: keep the Service secure, functional, and reliable.

3.8 Camera Photos and Catch

Catch is available only when you are signed in with a permanent account. It is not available to guest users. The Catch preview shown during onboarding uses sample photos included in the App; it does not use your camera and does not upload or save anything.

Source: you (camera), and content generated for you from the photo. Purpose: identify the object you photographed, show you a proposed phrase card, and save the Catch to your Shelf and your deck if you tap Keep.

Please photograph everyday objects. Do not use Catch to photograph people, faces, documents, screens, or other private or sensitive material.

3.9 Speak Conversations and Conversation Memory

Source: you (microphone and your conversation), and content generated for you. Purpose: hold the conversation, give you feedback on your speaking, and personalize later conversations.

3.10 Advertising Measurement (Meta and TikTok SDKs)

We advertise Spokit on Meta (Facebook and Instagram) and TikTok. To measure whether those ads lead to app installs and subscriptions, the iOS App includes the Meta SDK and the TikTok Business SDK. These SDKs automatically send app events to Meta and TikTok: the App being installed and opened, whether you open it again the next day (TikTok), and App Store purchase and subscription events. The events include technical information about your device and the App, such as device model, operating-system version, app version, language, time zone, and identifiers that the SDKs create or read for this purpose.

We do not pass your name, email address, Spokit account identifier, learning content, voice recordings, transcripts, conversation memory, or photos to these SDKs. Spokit does not ask for App Tracking Transparency permission, so the SDKs cannot access your device's advertising identifier (IDFA), and IDFA collection is turned off in the Meta SDK. Meta and TikTok process this information under their own terms and privacy policies, including for their own purposes.

Source: your device and your use of the App. Purpose: measure the effectiveness of our own advertising campaigns.

3.11 Website Waitlist

If you join the waitlist on spokit.app, we collect your email address, the page you signed up from, any campaign tags in the link you followed (UTM parameters), and the time you agreed to receive emails. We use them to send you early-access and occasional product emails. You can unsubscribe or ask us to remove you at any time. To prevent abuse, we rate-limit sign-ups using a shortened one-way hash of your IP address.

Spokit does not show third-party advertising in the App, and we do not sell your personal information. Apart from the advertising-measurement SDKs described in Section 3.10, we do not share information about your use of Spokit with advertising companies.


4. How We Use Your Information

We use personal information to:

  1. Create, authenticate, and manage your account and sessions.
  2. Generate language-learning phrases, translations, token analysis, speech transcription, and optional pronunciation audio; hold Speak conversations and give feedback on your speaking; and identify objects in photos you take with Catch.
  3. Store and synchronize your learning content and progress across sessions and devices, and, if conversation memory is on, remember details from your Speak conversations to personalize later ones.
  4. Operate the credit allowance, subscriptions, rate limits, abuse prevention, and security controls.
  5. Send you service and transactional messages (for example, password-reset, welcome, trial, and subscription-lifecycle emails), and, if you join our website waitlist, early-access and product emails.
  6. Provide customer support and respond to your requests, including account deletion and data-access requests.
  7. Maintain, secure, and improve the reliability of the Service, diagnose failures, and measure the effectiveness of our own advertising campaigns (see Section 3.10).
  8. Comply with legal, tax, billing, App Store, and security obligations, and enforce our Terms of Use.

We do not use your learning content, voice recordings, transcripts, conversation memory, or Catch photos to serve advertising, and we do not sell them.


If you are in the EEA or UK, we rely on the following legal bases under the GDPR and UK GDPR:

Purpose Legal basis
Creating and operating your account; providing the core learning features you request; processing your subscription Performance of a contract (Art. 6(1)(b))
Security, abuse prevention, rate limiting, reliability, diagnostics, and service improvement Legitimate interests (Art. 6(1)(f))
Sending service/transactional emails; managing subscription lifecycle notices Performance of a contract and/or legitimate interests
Remembering details from Speak conversations to personalize later conversations Legitimate interests (Art. 6(1)(f)); you can turn conversation memory off and delete it at any time
Measuring the effectiveness of our advertising campaigns (Meta and TikTok SDKs) Legitimate interests (Art. 6(1)(f))
Local reminders and optional preferences you enable Consent (Art. 6(1)(a)), which you can withdraw at any time in settings
Website waitlist emails Consent (Art. 6(1)(a)), which you can withdraw at any time by unsubscribing
Retaining billing and tax records; responding to lawful requests Compliance with a legal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have balanced those interests against your rights. You may object to processing based on legitimate interests as described in Section 10.


6. Third-Party Service Providers (Processors)

We share personal information with a limited set of service providers who process it on our behalf to operate specific features. We do not sell this information. Except for Meta and TikTok as described in Section 3.10, providers are permitted to use it only to provide their service to us. Spokit uses the following third-party providers in this version:

Provider Role / purpose Data shared
Convex Backend host, application database, server functions, and file storage; stores your account, learning content, Speak conversation history and conversation memory, generated audio, Catch photos, and usage data Account and profile data, learning content, Speak conversation history and conversation memory, voice recordings awaiting transcription, generated audio, Catch photos and object cut-outs, identifiers, usage data
Apple Sign in with Apple; App Store payment processing, billing, renewals, cancellations, and refunds Authentication identifiers, name/email you share, purchase and subscription data
Google Google sign-in (OAuth) Authentication identifiers, and name/email you share
RevenueCat Subscription-entitlement management and processing of App Store purchase-lifecycle events Subscription/purchase identifiers and lifecycle data, app user identifier
ElevenLabs Speech-to-text transcription of your voice recordings, and text-to-speech generation of pronunciation audio and Speak replies Voice recordings you submit for transcription; text submitted for audio generation (phrases, Spokit's Speak replies, and corrections)
OpenRouter AI model gateway used to generate phrases, translations, and token/grammar analysis; Speak replies, corrections, feedback, and conversation summaries; and checks of answers you speak during review. OpenRouter forwards each request to a provider of the model we choose: currently Google Gemini models for most features, and DeepSeek models for Speak conversations, which OpenRouter routes to inference providers such as Baidu The text you submit (typed prompts and transcripts of your speech) and your language pair and level; for Speak, also recent conversation turns and your conversation memory
OpenRouter (Catch) AI model gateway used for Catch. OpenRouter forwards each Catch request to Google's Gemini models, which identify the object, propose the phrase card, and outline the object in the photo The processed Catch photo and your selected language pair; if you edit a proposed card, the edited card text; if the object is already on your Shelf, up to 20 of your existing phrases for it
Cloudflare Hosting of the spokit.app website, and delivery of transactional and service emails (for example, password-reset and subscription notices) Your email address and the contents of the message; for website visitors, technical request data such as IP address
Expo (EAS Update) Delivery of App updates; the App checks for an update when it starts Technical request data such as IP address, app and runtime version, platform, and a random installation identifier
Meta Advertising measurement through the Meta SDK (see Section 3.10) App install, launch, and App Store purchase and subscription events; device and app information; identifiers created by the SDK
TikTok Advertising measurement through the TikTok Business SDK (see Section 3.10) App install, launch, next-day return, and App Store purchase and subscription events; device and app information; identifiers created or read by the SDK

For Catch, we send the processed photo inside the request itself; we do not store it in a separate file service at OpenRouter or Google. We configure Catch requests so that OpenRouter uses only provider endpoints that it lists as not retaining request data (zero data retention) and not using it for training. Providers still process each request to return a result. For our other AI features, OpenRouter and the model providers process the request content under their own terms, which may allow them to keep it for a limited period (for example, to monitor abuse) and, depending on the provider, to use it to improve their services. These providers may be located outside your country (see Section 9).

We may also disclose personal information (a) to comply with law, legal process, or lawful government requests; (b) to enforce our Terms or protect the rights, safety, and security of our users, the public, or PodFlyy; and (c) in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honor this policy or notify you of any material change.


7. Microphone and Audio Handling

Audio is handled carefully and only when you choose to use a speech feature:

Please do not record sensitive, confidential, or regulated information as practice content.


8. Data Retention

We keep personal information only as long as needed for the purposes described in this policy, then delete or de-identify it. Specific practices include:

Data Retention
Account, profile, and learning content (phrases, tokens, reviews, journal, decks) While your account is active; deleted when you delete your account (see Section 10)
Voice recordings submitted for transcription Deleted immediately after transcription; unused uploads expire and are purged within a short window
Generated audio (pronunciation and Speak replies) Audio not attached to saved content: deleted after 14 days. Audio for a saved phrase: kept while the phrase exists. On account deletion, deleted, except audio of phrase text that other learners also use, which is kept without any link to you
Speak conversation history and feedback Deleted 90 days after each turn, or earlier when you clear your history or delete your account; the retry copy of the latest turn is deleted after about 15 minutes
Conversation memory notes and summaries Kept until you delete them, clear them, or delete your account; limited to 30 notes per language, with the least important removed first
Transcripts of answers you speak during review Deleted after 7 days
Original Catch camera photo Stays on your device and is deleted after the processed copy is made; never uploaded
Processed Catch photo on your device Kept in the App's private cache while the Catch is processed or waiting for a connection, for up to about 72 hours (an expired photo is removed the next time the App runs); deleted earlier when you finish with the result, sign out, or delete your account
Uploaded Catch photo and object cut-out you do not keep The photo is deleted automatically within about 24 hours of upload, and sooner if you cancel, no object is identified, or you reach your daily limit; the object cut-out is deleted within about 24 hours after it is made
Kept Catch photo and object cut-out Stored while the object remains on your Shelf; deleted when you delete the object or your account
Catch request records (without the photo) Kept with your account until you delete your account
Guest (no-account) data If you use Spokit without an account, your onboarding answers, name, and preview phrase are deleted 7 days after your last activity; if you create an account, they move to your account and the guest record is deleted within about a day
Purchase and subscription records Retained as needed to operate your subscription and to meet billing, tax, and legal obligations; records may also persist with Apple and RevenueCat under their policies
Transactional email records Personal data in email delivery records is scrubbed about 30 days after sending
Website waitlist sign-ups Kept until you unsubscribe or ask us to remove you
Usage and reliability events Deleted after 90 days, and on account deletion, except where retained for security or legal reasons
Information received by Meta and TikTok through their SDKs Retained by Meta and TikTok under their own policies
Backups and system logs Kept for a limited period for security and disaster recovery, then overwritten or deleted

We may retain limited information longer where required to comply with legal obligations, resolve disputes, prevent fraud, or enforce our agreements.


9. International Data Transfers

We are based in the United States, and our service providers may process and store personal information in the United States and other countries that may have data-protection laws different from those in your country. Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), or another lawful transfer mechanism. You may contact us at [email protected] for more information about these safeguards.


10. Your Rights and Choices

Depending on where you live, you may have some or all of the following rights regarding your personal information:

How to exercise your rights

We will not discriminate against you for exercising your privacy rights.

EEA/UK residents may lodge a complaint with their local data-protection authority (in the UK, the Information Commissioner's Office). We would appreciate the chance to address your concerns first.


11. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, provides the rights described below.

Categories of personal information we collect (as defined by California law):

Statutory category Examples in Spokit
Identifiers Email, name, account/session/provider identifiers, RevenueCat app user ID, identifiers created or read by the Meta and TikTok SDKs
Customer records / commercial information Subscription and purchase history
Audio, electronic, visual, or similar information Voice recordings you submit for transcription; generated audio; Catch photos and object cut-outs
Internet or other electronic network activity Product-interaction and usage events; app install, launch, and purchase events sent to Meta and TikTok
Other information you provide (user content) Typed prompts, phrases, token analysis, journal/review entries, Speak conversation history, conversation memory

Sources, purposes, and disclosures. We collect these categories from the sources and for the business purposes described in Sections 3–7. We disclose personal information to the service providers listed in Section 6 for those business purposes only, and to Meta and TikTok for advertising measurement as described in Section 3.10.

Selling and sharing. We do not sell your personal information for money. The app events that the Meta and TikTok SDKs send for advertising measurement (Section 3.10) may count as "sharing" for cross-context behavioral advertising under California law. Apart from those events, we do not sell or share personal information.

Do Not Sell or Share My Personal Information. These events are not linked to your name, email address or Spokit account, so we cannot match them to you after they are sent. To stop them, delete the App from your device. You can also email [email protected] with the subject "Do Not Sell or Share", and we will handle your request as California law requires.

Sensitive personal information. We do not use or disclose sensitive personal information for purposes that would require offering a right to limit under the CPRA.

Your California rights include the right to know, the right to delete, the right to correct, and the right to non-discrimination for exercising your rights. To exercise them, delete your account in the App or contact [email protected]. We will verify your request as required by law. Authorized agents may submit requests with proof of authorization.

Residents of other U.S. states with comprehensive privacy laws may have similar rights and can exercise them the same way.


12. Children's Privacy

Spokit is intended for a general audience and is not directed to children. You must be at least 13 years old (and at least 16 in the EEA, or the minimum age of digital consent in your country) to use Spokit, or older where required by local law and the App Store.

We do not knowingly collect personal information from children under 13 (or under the applicable minimum age in your region). If you believe a child has provided us personal information, contact [email protected] and we will delete it. Spokit is not part of the Apple Kids Category and does not use content directed to children.


13. Security

We use managed, industry-standard providers for our backend, authentication, storage, and email delivery, and we apply access controls, encryption in transit, short-lived upload credentials, and rate limiting to protect personal information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please keep your device and sign-in credentials secure, and avoid submitting sensitive or confidential information as practice content.


14. Apple App Store Privacy ("Nutrition Label") Mapping

Spokit's App Store privacy details describe the data the App collects. The data Spokit collects to provide its features is linked to your identity and used for App Functionality:

App Store data type What it covers in Spokit
Email Address Account contact and authentication
Name Optional display name you type or share through Apple/Google sign-in
Audio Data Voice recordings and generated audio
Photos or Videos Catch photos and object cut-outs
Other User Content Phrases, saved cards, token analysis, journal/review entries, transcripts, Speak conversation history, conversation memory
User ID Spokit and RevenueCat identifiers
Product Interaction App usage and reliability events
Purchase History App Store / RevenueCat purchase-lifecycle data

The Meta and TikTok SDKs described in Section 3.10 also collect identifiers created or read by those SDKs, app install and launch events, and purchase events, which are used to measure our advertising. The App Store listing shows our current declarations, including how Apple's definition of tracking applies.


15. Advertising and Tracking

Spokit does not display third-party advertising in the App. It does not ask for App Tracking Transparency permission and does not collect your device's advertising identifier (IDFA). The Meta and TikTok SDKs described in Section 3.10 send app install, launch, and purchase events and device information to Meta and TikTok so that we can measure our own advertising campaigns. We do not sell your personal information.


16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our features, service providers, or legal requirements. When we make material changes, we will update the "Effective date" above and, where appropriate, provide additional notice in the App or by email. Your continued use of Spokit after an update takes effect means you accept the revised policy.


17. Contact Us

For any privacy question or request, contact:

PodFlyy LLC Email: [email protected] Website: spokit.app