Amiora
Join the waitlist

Privacy Policy

Effective 30 July 2026

This policy explains what personal data Amiora collects, why we process it, who we share it with, how long we keep it, and the rights you can exercise. It applies to our mobile app, our website, and the services provided to companies whose team members learn with Amiora.

Who we are

Amiora is the controller of the personal data described below. For any privacy question or to exercise your rights, contact us at [email protected].

Data we collect

  • Identity and account data — your email address, name (where provided), and an authentication identifier from our sign-in provider.
  • Learning content — the conversation text you write during practice, sentences and words you save, and your progress and review history.
  • Voice audio — when you speak in a practice session, your audio is sent to a third-party speech-to-text provider to transcribe what you said. We do not store your audio: it is held only in memory for the transcription request and is not written to our databases or file storage. How long each provider retains a request on its own systems is governed by that provider’s terms, which we link under Sub-processors below. We do not use your voice to identify you. The app tells you this and asks you to accept it before your first practice session.
  • Subscription data — your plan and purchase status, handled through our app-store billing provider. We do not receive or store your full card details.
  • Product analytics and device data — we record how the product is used (screens viewed, features used) together with basic device and app identifiers. In the mobile app these events are not tied to your account: they carry an anonymous per-installation identifier only. Some usage events recorded by our own servers are still associated with your account. Analytics is on by default and you can turn it off at any time in Settings; the setting is remembered and we stop collecting as soon as you do. Analytics does not record your approximate location.
  • Diagnostics — crash and error reports, with personal data scrubbed before they leave your device or our servers.
  • Video playback data received by YouTube — the Watch tab plays videos through YouTube’s official embedded player, so YouTube and Google receive the information any embedded player receives directly from your device. See Video playback through YouTube below.

Why we process it, and our lawful basis

  • To provide the service (accounts, practice, progress, voice transcription, subscriptions) — performance of our contract with you.
  • To keep the service secure and reliable (diagnostics, abuse prevention) — our legitimate interest in a safe, working product.
  • To understand and improve the product (analytics) — our legitimate interest in knowing how the product is used, which you can object to at any time by turning analytics off in Settings. On the web, analytics runs only if you accept our cookie banner.

International transfers

Amiora runs on infrastructure located in the United States, and several of our processors are US-based. Where personal data is transferred outside your country, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses or a valid data-transfer framework — with the processors listed below.

Sub-processors

We rely on the following processors to run Amiora. Each is bound by a data-processing agreement and processes personal data only on our instructions.

  • Google Firebase — authentication and account infrastructure.
  • DigitalOcean — application hosting, database, and file/media storage.
  • OpenAI, Groq, and Google (Gemini) — AI language and speech processing for practice and transcription. Your conversation text is sent to Google (Gemini) or OpenAI to generate Amiora’s replies; your voice recordings are sent to Groq or OpenAI to be turned into text.
  • xAI — text-to-speech, used to generate Amiora’s spoken voice from the text of its replies.
  • PostHog — product analytics (only after you consent).
  • Sentry — crash and error diagnostics.
  • RevenueCat — subscription management.
  • Mailgun — transactional email.

Video playback through YouTube

Videos in the Watch tab are not hosted by us. The app loads YouTube’s official embedded player (the YouTube IFrame Player API, served from www.youtube.com) inside a web view, and the video streams from YouTube to your device.

Because the player talks to YouTube directly, YouTube and Google receive the ordinary information an embedded player receives, without it passing through us: your IP address, your user agent and device/app information, cookies and other storage that YouTube sets or reads in that web view, and playback context such as which video was loaded and what you did with the player. That processing is described in Google’s Privacy Policy.

The app streams these videos only. It does not download or store video or audio on your device, and it provides no offline playback or export.

How long we keep your data

We keep personal data only as long as needed for the purpose it was collected for, to meet legal obligations, and to resolve disputes. When you delete your account we delete or anonymise your personal data on a defined schedule, including copies held by our processors and in routine backups.

Your rights

You can ask us to:

  • access the personal data we hold about you, and receive a copy of it;
  • correct data that is inaccurate or incomplete;
  • delete your account and personal data;
  • restrict or object to certain processing;
  • withdraw analytics consent at any time (use “Cookie settings” in the footer).

To exercise any of these, email [email protected]. You also have the right to lodge a complaint with your local data-protection authority.

Deleting your account

You can delete your account and the data associated with it. See Account deletion for how.

Changes to this policy

If we make material changes we will update this page and, where required, ask for your consent again.

Privacy Policy — Amiora