Introduction

CiaoSpeak ("the app", "we", "us") is a language-learning app for practicing speaking and vocabulary. This policy explains what information the app handles, how it is used, and the choices you have. Most of the app works entirely on your own device; the AI speaking practice (the Speak tab, or the Chat tab in older versions of the app) is the one exception, described in "AI speaking practice (Speak and Chat)" below.

Information we collect

CiaoSpeak does not require you to create an account, and by default does not collect your name, email address, or other contact details. (Speak can ask what to call you; a name you type there stays on your device and is sent only as described in "AI speaking practice (Speak and Chat)" below. If you choose to turn on the optional cloud backup, the app learns the email address of the Google account you pick — see "Optional cloud backup" below.)

The app stores the following on your device only:

  • Your onboarding choices (target language, learning goal, experience level, daily practice goal)
  • Your lesson and review progress (streak, XP, completed lessons, badges, spaced-repetition mistake queue)
  • Your in-app preferences (sound effects, pinyin visibility, slow-audio playback, reminder setting)
  • Your Speak progress and practice schedule, the sentences saved in "My phrasebook" (My answers and Things I couldn't say), and whether you prefer to answer by voice or by typing
  • In older versions of the app with the Chat tab, your Chat transcript (saved on your device so the chat picks up where you left off after a restart)

None of this on-device data is sent anywhere, with one exception: when you use Speak or Chat, some of what you say or type is sent to a backend service (in Speak, only for answers the app can't check on your device by itself) — see "AI speaking practice (Speak and Chat)" below for exactly what that involves.

Separately, the app generates a random installation identifier (not tied to your name or any personal detail) used for the anonymous once-a-day "active today" record (see "Third-party services" below), and, if you use Speak or Chat, to apply daily limits (see "AI speaking practice (Speak and Chat)" below). You can turn off crash/usage analytics at any time in Settings > Data; Speak and Chat can simply be avoided by not using that tab.

AI speaking practice (Speak and Chat)

Speak is the speaking practice in every course (Chinese for English speakers, English for Taiwan, and English for Japanese adults), and in current versions of the app it takes the place of the Chat tab. A character asks you a question and you answer by speaking or typing. Many answers are checked on your device, and nothing is sent for those. When the app can't check an answer on the device by itself, it sends the following to a backend service CiaoSpeak operates on Cloudflare Workers: the text of your answer (typed, or transcribed by your device's own speech recognition), the recognizer's other guesses for it, which question you were asked (and whether it was a follow-up question or you asking the character back), whether you typed it, which course you are taking, and your random installation identifier. The backend forwards this to Anthropic's Claude API, which decides whether your answer got across, and sends the result back to your device.

If you tap "I can't say it" and type what you want to say in your own language (English, Traditional Chinese or Japanese), that text is sent the same way, together with the list of lessons you've completed, so that the sentence written for you stays at your level.

For Speak, the backend logs which question was checked, the verdict and a mistake category — not the text of your answer. It also keeps daily usage counts per installation to apply daily limits: 15 answer checks and 3 "I can't say it" requests a day for free, and 150 and 25 with CiaoSpeak+ (fair use).

The characters' voices are pre-recorded audio clips the app downloads from CiaoSpeak's audio host (see "Text-to-speech & sound" below); replies the AI writes on the spot are read aloud by your device's own text-to-speech.

In older versions of the app, the Chat tab is a real AI teacher instead, not a fixed script. When you send a message — by typing, tapping a suggested reply, or speaking (see "Microphone & voice input" below) — the app sends that message, your recent conversation history (up to your last 20 messages, so the AI stays coherent turn to turn), which lessons you've completed, and your random installation identifier to the same backend, which forwards your message to Anthropic's Claude API to generate the teacher's reply. For quality and abuse monitoring, each Chat exchange (your message and the AI's reply, keyed to your installation identifier — never your name) is logged by this backend, and the backend limits how many messages one installation can send each day.

These records are used only to apply the limits and to catch bugs, wrong verdicts, off-topic replies, or misuse of the feature — never for advertising or to build a profile of you. See Anthropic's own privacy policy for how they handle data sent to their API. On iPhone, the app asks for your permission before anything from Speak or Chat is sent.

Your Speak progress and "My phrasebook" stay on your device, and in your cloud backup only if you turned that on; a Chat transcript stays on your device only. If you'd rather nothing you say or type in practice ever leave your device, simply don't use the Speak or Chat tab — every other part of the app (Lessons, Progress, Settings) works entirely on-device, as described elsewhere in this policy.

Microphone & voice input

Speak and Chat let you answer by speaking instead of typing. Speech recognition uses the speech recognizer built into your phone (Android or iOS) — CiaoSpeak never records or uploads raw audio. Depending on your device and its settings, that built-in recognizer may process your speech on the device or on its provider's servers (such as Google's or Apple's), under that provider's own privacy policy. The app receives only the resulting text and the recognizer's other guesses, and they leave your device only when they are sent on as described in "AI speaking practice (Speak and Chat)" above. If a future update adds any other microphone-based feature, this policy will be updated first, and the app will ask for microphone permission at that time with a clear explanation before anything is recorded.

Text-to-speech & sound

Words and sentences are read aloud using audio recordings that the app downloads from our audio server (hosted on Cloudflare Pages) and keeps in a cache on your device; story cover pictures are downloaded the same way. These downloads are ordinary file requests that carry no account or personal identifier, although, like any web request, Cloudflare processes standard technical request data such as your IP address to deliver them. If a recording isn't available, and for replies the AI writes on the spot in Speak, the app uses your device's or browser's built-in text-to-speech engine, which runs on your device or through your operating system, not on a CiaoSpeak server. Sound effects (tap, correct answer, incorrect answer) are short audio clips bundled with the app and play locally.

CiaoSpeak+ subscription

CiaoSpeak+ is an optional paid subscription that raises the daily limit on AI answer checks in Speak, unlocks every Speak scene and the full "My phrasebook", and unlocks the full Stories library and unlimited Quick Practice bonus rounds (in older versions of the app, it also raises the daily limit on Chat messages). If you subscribe, the purchase itself is handled entirely by Google Play Billing on Android or by Apple's App Store on iPhone — CiaoSpeak never sees your payment card or billing details.

To know which features to unlock and to let you restore your purchase on a new device, the app uses RevenueCat, a subscription-management service: your random installation identifier and your subscription status (active, expired, which plan) are shared with RevenueCat so it can verify your entitlement. This is used only to run the subscription and prevent fraud (e.g. blocking a modified app from claiming an entitlement it hasn't paid for) — never for advertising.

Optional cloud backup

Settings > Backup (currently available on Android only) lets you sign in with a Google account to keep a copy of your learning progress in the cloud, so it survives a lost phone, a new device, or a reinstall. This is entirely optional — every feature of the app works identically without it, and nothing ever asks you to sign in.

If you turn it on, two things leave your device: the email address of the Google account you choose (used only to identify which backup is yours), and a snapshot of your learning progress (streak, XP, completed lessons and stories, review queue, Speak progress and "My phrasebook", and preferences). A Chat transcript is deliberately not included in the backup. The snapshot is stored with Supabase (see "Third-party services" below), protected so that only your own signed-in account can read or write it.

You stay in control: "Delete backup" in Settings removes the cloud copy immediately; "Sign out" stops backups while leaving everything on your device untouched; and "Reset progress" also deletes the cloud copy, so a deliberate wipe cannot be undone by signing in again.

How we use information

Everything in "Information we collect" above is used only to run the app's own features on your device: tracking your streak and XP, scheduling mistake review, remembering your preferences, and picking up where you left off.

Separately, the app also collects: crash/diagnostic data (device model, OS version, app version, and technical error details, used only to find and fix bugs); anonymous usage analytics (session counts and which tabs/features you use, keyed only to an anonymous random identifier, never to your identity); and lesson/exercise completion data (which lessons and exercises you complete or leave unfinished, used to find where the curriculum is confusing or incomplete). This is used only for internal product decisions — fixing bugs and improving the app — never for advertising, behavioral targeting, or building a profile of you, and we do not sell or share it with third parties beyond the services named below. You can turn all of it off at any time via the "Share crash reports & usage data" toggle in Settings > Data.

Data storage, retention & deletion

Your data lives in the app's local storage on your device. It stays there until you either use "Reset progress" in Settings (clears your streak, XP, badges, completed lessons, review queue, Speak progress and "My phrasebook", and any saved Chat transcript, and restarts onboarding), or uninstall the app (removes everything). Unless you have turned on the optional cloud backup, we keep no copy of it anywhere else — and if you have, "Reset progress" and "Delete backup" both remove the cloud copy too (see "Optional cloud backup" above). The backend behind Speak and Chat keeps only the logs and daily usage counts described in "AI speaking practice (Speak and Chat)" above.

Third-party services

CiaoSpeak uses Sentry for crash reporting and the anonymous usage/completion analytics described in "How we use information" above. No advertising identifiers, precise location data, or behavioral-targeting data are collected — this integration exists solely to find bugs and understand how the app's own features are used, not to build advertising profiles. Sentry uses its own random identifier for each install, never your name, email, or any other personal identifier — signing in for cloud backup does not change what Sentry receives.

For Speak and Chat, CiaoSpeak also uses Cloudflare Workers to run its backend service, and Anthropic's Claude API to check answers, write "I can't say it" sentences, and (in Chat) generate the AI teacher's replies — see "AI speaking practice (Speak and Chat)" above for exactly what's sent to them. Neither receives your email or any other contact detail — only the practice content listed there (your answer and the question it answers, "I can't say it" text, Chat messages and history), your completed-lesson list, and the random installation identifier.

Your device's built-in speech recognition is provided by your phone's platform (such as Google on Android or Apple on iPhone), not by CiaoSpeak — see "Microphone & voice input" above.

If you subscribe to CiaoSpeak+, CiaoSpeak uses RevenueCat to manage the subscription — see "CiaoSpeak+ subscription" above for exactly what's sent to it. Google Play Billing (Android) or Apple's App Store (iPhone) processes the actual payment; neither CiaoSpeak nor RevenueCat ever receives your payment card or billing details.

CiaoSpeak also uses Supabase for two things. First, if the crash/usage analytics toggle is on, the app sends Supabase one anonymous "this install was active today" record per day (the random installation identifier, the date, and the app version — nothing else), plus one record when a Speak session starts or ends (the course, how many questions you answered, the date and the app version — never what you said), used only to measure whether people keep using the app and its speaking practice over time; the same Settings > Data toggle that governs Sentry turns this off too. Second, if you turn on the optional cloud backup, Supabase stores your backup snapshot and handles the Google sign-in (with Google's sign-in service verifying the account you pick) — receiving your Google account's email address and your progress snapshot. Nothing else described in this policy is sent to Supabase.

Fonts & bundled data

CiaoSpeak bundles two open-licensed third-party resources directly in the app, rather than downloading them, so the app works fully offline:

  • The Noto Sans TC typeface (Copyright 2014-2021 Adobe, with Reserved Font Name "Source"), licensed under the SIL Open Font License, Version 1.1.
  • Character stroke-order data, trimmed from the open "Make Me a Hanzi" project, licensed under the Arphic Public License.

Both licenses permit this use and redistribution; neither imposes any obligation on you as a user of the app.

Children's privacy

CiaoSpeak is not directed at children under 13, and we do not knowingly collect personal information from children. Apart from a name you may choose to type in Speak, the only personal detail the app can ever hold is the email address of a Google account voluntarily signed in for the optional cloud backup; everything else works without collecting personal information from any user.

This website

ciaospeak.app itself is a static site hosted on Cloudflare Pages. Two things on it involve your data:

  • Email updates. If you enter your email in the "Stay updated" form, it is collected and stored by Kit (kit.com), our email provider, and used solely to send you CiaoSpeak product updates. Every email includes an unsubscribe link; unsubscribing removes you from the list.
  • Analytics. The site uses Cloudflare Web Analytics, which is cookieless: it sets no cookies, does not fingerprint you, and does not track you across other sites. We see aggregate page-view counts, not individual visitors.

Like any website, the hosting infrastructure (Cloudflare) processes standard technical request data (such as IP addresses) to serve pages and protect against abuse — see Cloudflare's privacy policy.

Changes to this policy

If this policy changes, we'll update the "Last updated" date shown above, the copy in the app's Settings > Privacy Policy screen, and this page.

Contact

Questions about this policy can be sent to [email protected].