Talkling – Privacy Policy
Quick summary
- Controller: Talkling (contact: support@talkling.app)
- What we collect: Account details (email, name), messages/audio you send, learning progress, limited technical and security logs.
- Why: To run Talkling, improve quality and safety, support you, and meet legal obligations.
- Analytics & ads measurement: In production, we load Google Analytics 4 (GA4) and Google Ads tags via the Google tag (gtag.js) only if you opt in through our cookie banner (separate Analytics and Marketing choices).
- AI processing: Transcription and AI replies use OpenAI. API data is not used to train OpenAI models by default. We don't sell personal data.
- Payments: Handled by Dodo; they process your billing data and taxes/VAT.
- Reasonable-use safeguards: Paid plans include “unlimited” messaging/AI help, but we keep soft limits (~3k messages & ~10k AI calls/day) to stop abuse—normal learners never hit them.
- Your rights: Access, rectify, delete, export, restrict/ object. EU/UK users can complain to a data authority.
1) What data we process
You provide:
- Account info: email, display name, languages, settings
- Content: messages, audio, attachments
We generate:
- Transcriptions, translations, learning progress
- Usage metrics (features used, timestamps)
- Security/abuse signals (e.g., rate limits, IP in logs)
- Daily usage counters to enforce reasonable-use safeguards (message count, translation/AI call count)
Technical:
- Device/browser type, IP‑derived region, crash logs
- Essential cookies or tokens for authentication only
- Diagnostic signals from rate-limit systems (e.g., whether you hit the soft cap that day)
We do not intentionally collect special‑category data. Please avoid sharing sensitive information.
2) Why we use your data (legal bases)
- Provide the service and support (contract)
- Keep Talkling safe & reliable (legitimate interests)
- Improve features using aggregated/de‑identified data (legitimate interests)
- Communications like important service updates (legitimate interests / legal obligation)
- Consent‑based features (e.g., notifications) when required
- Advertising measurement (Google Ads conversion/measurement) when required by law (consent)
- Prevent abuse & enforce reasonable-use limits so “unlimited” perks remain sustainable for everyone (legitimate interests)
3) AI features (OpenAI)
We send text/audio you choose to process to OpenAI to generate transcripts and AI replies. According to OpenAI, API data is not used to train their models by default. We keep only what we need to provide Talkling and to prevent abuse. See Your Controls below for export and deletion.
4) Payments (Dodo)
We use Dodo as our Merchant of Record. Dodo processes payment methods, invoices, and taxes/VAT and shares with us only what we need (e.g., plan status, country/tax info). Your payment data is handled under Dodo's terms and privacy policy.
5) Analytics
We may use Google Analytics 4 (GA4) and Google Ads via the Google tag (gtag.js) for analytics, conversion, and performance measurement (for example: to understand whether an ad click led to a signup or subscription).
We use Google Consent Mode and set all storage to denied by default. In production, we load Google tags only after you opt in through the cookie banner:
- If you accept Analytics, we load GA4 and Google may store/read analytics cookies or similar identifiers (and process related event data) to measure and improve performance.
- If you accept Marketing, we load the Google Ads tag and Google may store/read advertising cookies or similar identifiers to measure ad effectiveness and (if enabled) personalize ads.
- If you decline, we do not load GA4 or Google Ads tags and we do not send analytics/ads measurement events to Google.
You can change your choice anytime via the cookie banner preferences or the Cookie settings link in the footer. You can also review Google’s policies at https://policies.google.com/privacy and https://policies.google.com/technologies/partner-sites.
6) Data sharing
We share data with service providers under contracts that limit their use to our instructions—e.g., hosting, authentication, analytics and advertising measurement (Google Ads/Google tag), billing (Dodo), AI processing (OpenAI), and customer support. We don't sell personal data.
Rate-limit counters are stored with the same providers that host our databases (Supabase/Prisma Postgres) and automatically reset daily.
When enabled by your consent choice, Google may receive conversion/measurement event data (and potentially cookie identifiers) via the Google tag. Google’s use of information is described in Google’s policies (see https://policies.google.com/privacy and https://policies.google.com/technologies/partner-sites).
7) International transfers
If data leaves your region (for example, to our providers), we rely on approved safeguards such as Standard Contractual Clauses and vendor certifications.
8) Retention
- Account data: kept while your account is active
- Content (messages/audio): kept so the app works; deleted on account deletion
- After deletion: remove active data within 30 days; backups may persist up to 90 days
- Legal/transaction records may be kept longer where required
- Rate-limit counters reset every 24 hours and are kept only in aggregate logs for abuse investigations (typically under 30 days unless part of an active security review)
9) Your controls & rights
In Settings or via support@talkling.app, you can:
- access/export your data,
- correct or delete information,
- delete your account,
- object to or restrict certain processing,
- withdraw consent (where applicable).
EU/UK/Swiss users can also complain to their local data authority.
10) Children
Talkling is not for children under 13 (or the higher minimum age in your country).
11) Security
We use HTTPS, access controls, and industry‑standard safeguards. No method is 100% secure.
12) Changes
We'll post updates here and, for material changes, notify you in‑app or by email.
13) Contact
Email: support@talkling.app
Website: https://talkling.app
For GDPR-related inquiries, please include "GDPR Request" in your subject line.
Last Revised: January 8, 2026