Privacy Policy
Effective date: April 21, 2026
DaxTech LLC, a Nevada limited liability company, doing business as StreetTongue App (“StreetTongue,” “we,” “us,” “our”) operates the StreetTongue website at streettongueapp.com and the StreetTongue mobile application. Our registered address is 732 S 6th St Ste N, Las Vegas, NV 89101, United States.
This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and what rights you have.
By using our website or app, you agree to the practices described in this policy.
Age Requirement
StreetTongue is rated 16+ in the Apple App Store and Google Play Store and is intended for users who are at least 16 years old. We do not knowingly collect personal information from anyone under 16. If you believe a user under 16 has provided us information, contact us at privacy@streettongueapp.com and we will delete it.
What We Collect
Information You Provide
| Data | Where Collected | Purpose |
|---|---|---|
| Email address | Waitlist form (website), app registration | Notify you of launch, manage your account |
| Phone number (optional) | Waitlist form (website) | SMS notification when the app launches |
| Name | App registration, blog comments (website) | Identify your account, display your comment |
| Password | App registration (email/password sign-up) | Authenticate your account. Stored only as a bcrypt hash by Supabase Auth; never stored or seen in plain text |
| Comment text | Blog comments (website) | Publish your comment |
| Audio recordings | In-app pronunciation practice | Sent in transit to Microsoft Azure for pronunciation scoring (see below) |
| User profile | App (email, name, user ID, tier, progress, goals, target city) | Manage your account and language learning progress |
| Purchase history | App (RevenueCat IAP), website Stripe Checkout | Record your tier, payment provider, and purchase dates |
| AI conversation text | App (Complete and Premium tiers) | Generate AI responses via OpenAI |
Information Collected Automatically
| Data | Where | Purpose |
|---|---|---|
| IP address | Blog comment submission, Cloudflare Turnstile (website), Cloudflare hosting | Rate limiting, spam prevention, abuse detection |
| Visitor fingerprint | Blog engagement system (hashed IP + user agent) | Deduplicate reactions and prevent spam; stored as a one-way SHA-256 hash |
| Aggregated page views | Cloudflare Web Analytics (website) | Understand site traffic in aggregate; no individual visitor tracking, no cookies |
| Device and usage data | Mobile app | App performance, crash reporting, feature usage |
Authentication
StreetTongue supports three ways to sign in:
- Email and password. Passwords are handled by Supabase Auth and stored only as a cryptographic hash (bcrypt). We never store or see your password in plain text.
- Sign in with Apple. We receive an authentication token from Apple. You control what Apple shares with us in your Apple ID settings.
- Sign in with Google. We receive an authentication token from Google. You control what Google shares with us in your Google account settings.
How We Use Your Data
- Provide and operate the website and app
- Assess your pronunciation via Microsoft Azure Speech Services
- Generate AI-powered language content (conversations, grammar explanations, translation) on the Complete and Premium tiers
- Authenticate you and keep your account secure
- Verify you are a human via Cloudflare Turnstile (bot protection)
- Prevent spam and abuse via rate limiting and comment moderation
- Process payments and manage your tier access
- Send transactional and launch notification emails
- Understand aggregate usage via privacy-friendly analytics
- Respond to your support and privacy requests
How Your Audio Data Works
When you practice pronunciation in the app:
- Audio is recorded on your device (typically 3 to 10 seconds of speech).
- The audio is uploaded over HTTPS to our Cloudflare Worker.
- The Worker forwards the audio to Microsoft Azure Speech Services for pronunciation analysis.
- Azure returns word-level accuracy, fluency, and completeness scores. Our Worker returns those scores to the app.
- Your audio recording is not stored. It is held in memory only for the duration of the scoring request and is discarded as soon as the response is returned. It is not written to any database, file system, or cloud storage on our side.
- Azure’s handling of audio is governed by its own enterprise agreement and privacy terms.
- The only audio-derived information we retain is the numeric pronunciation score, stored in Supabase as part of your learning progress.
Your voice recordings are not used to train AI models without your separate, explicit consent.
AI Features and Tiered Access
OpenAI-powered features — including AI conversations, grammar explanations, and translation — are available only on the Complete and Premium tiers. Users on the Free and Starter tiers will not see these features, and no text data from those users is sent to OpenAI.
When AI features are used, the text of your message is transmitted to OpenAI for processing. OpenAI’s handling of that data is governed by its API terms and its own privacy practices. We do not use your AI conversation text to train models without your separate, explicit consent.
Security
All data transmission uses HTTPS/TLS. Passwords are stored only as cryptographic hashes by Supabase Auth. Our Cloudflare Worker validates a signed Supabase JWT on every request before processing audio or AI content. API keys for Azure and OpenAI are held as Cloudflare Worker secrets and are never exposed to the app or the browser.
No method of electronic storage is completely secure, but we use commercially reasonable measures to protect your data.
Third Party Services
We share data with the following third parties to operate our services. We do not sell your personal data to any third party.
| Service | Data Shared | Purpose |
|---|---|---|
| Microsoft Azure Speech Services | Audio recordings (in transit only, not retained by us) | Pronunciation assessment |
| OpenAI | Text (conversations, grammar questions, translation requests) | AI-powered language features (Complete and Premium tiers) |
| Supabase (hosted on AWS) | User profile, progress, purchase history, password hash | Database, backend, authentication |
| Mailchimp (Intuit) | Email, phone, tier intent, city preference | Waitlist email and SMS notifications |
| Apple | Authentication token, in-app purchase receipts | Sign in with Apple, Apple In-App Purchase |
| Authentication token, in-app purchase receipts | Google Sign-In, Google Play Billing | |
| RevenueCat | App user ID, purchase receipts | In-app purchase management across App Store and Play Store |
| Stripe | Payment details (on Stripe’s domain during checkout) | Direct purchases made through the StreetTongue website |
| Cloudflare | IP address, page requests, browser telemetry (Turnstile) | Website hosting (Pages), bot protection (Turnstile), cookie-free analytics (Web Analytics), comment storage (D1), rate limiting (KV) |
| Upstash | User ID, usage counters | Rate limiting and usage tracking for the Cloudflare Worker |
| Resend | Email address | Transactional email delivery (verification, password reset, receipts, comment moderation) |
Each third party operates under its own privacy policy. Links to their policies are available on their respective websites.
Where Your Data Is Stored
| Data | Storage Location |
|---|---|
| User profiles, progress, purchase history | Supabase, hosted on AWS infrastructure |
| Password hashes | Supabase Auth (bcrypt) |
| Blog comments and reactions | Cloudflare D1 (serverless SQL database) |
| Waitlist signups | Mailchimp (Intuit) |
| Rate limit counters | Cloudflare KV and Upstash Redis (expire automatically) |
| TTS audio cache | Cloudflare R2 (synthesized speech only; no user recordings) |
| Theme preference | Your browser’s localStorage (local to your device only) |
| Banner dismissal | Your browser’s sessionStorage (cleared when you close the tab) |
All data transmission uses HTTPS/TLS encryption. No method of electronic storage is completely secure, but we use commercially reasonable measures to protect your data.
Cookies and Tracking
The StreetTongue website sets no cookies.
- Cloudflare Web Analytics is cookie-free by design. It collects only aggregated, anonymized data.
- Fonts are self-hosted. No requests are made to Google Fonts or any font CDN.
- Google Analytics is not enabled.
- We use
localStorageto store your theme preference andsessionStorageto remember whether you dismissed an announcement banner. Neither is personal data and neither leaves your device.
Third-party cookies on their domains: When you submit the waitlist form, a script loads from Mailchimp’s servers (list-manage.com), which may set cookies on Mailchimp’s domain. When you purchase Complete, Premium, or All Cities Lifetime via the website using Stripe Checkout, you are redirected to checkout.stripe.com, where Stripe may set cookies on their domain. We have no control over cookies set by third-party domains.
Data Retention
| Data | Retention Period |
|---|---|
| Account data (app) | Kept while your account is active |
| Audio recordings | Not retained. Held in memory only for the duration of the scoring request |
| Pronunciation scores | Retained with your learning progress until you delete your account |
| AI conversation text | Retained with your account; deleted when you delete your account |
| After deletion request | Deleted within 30 days |
| Blog comments | Retained while published; removed on request |
| IP addresses in comments | Retained for spam prevention; may be purged periodically |
| Waitlist data | Retained in Mailchimp until you unsubscribe or request removal |
| Purchase records | Retained as long as required for tax, accounting, and dispute resolution purposes |
| Cloudflare Web Analytics | Aggregated, not tied to individuals; retained per Cloudflare’s policies |
| Rate limit counters | Expire automatically |
We may retain certain data longer where required by law or to resolve disputes.
Deleting Your Data
To delete your app account and associated data:
- In the app: go to Settings, then Delete Account
- By email: privacy@streettongueapp.com
To remove website data (comments, waitlist):
- Email: privacy@streettongueapp.com
We will complete deletion requests within 30 days. Some data may be retained where we have a legal obligation to do so.
Your Rights Under GDPR (EEA Residents)
StreetTongue targets EU residents, including expats, relocators, digital nomads, medical tourists, and professionals in Barcelona, Madrid, Paris, Berlin, and Lisbon. GDPR applies to your data.
You have the right to:
- Access a copy of your personal data
- Correct inaccurate or incomplete data
- Delete your data (right to erasure)
- Port your data in a structured, machine-readable format
- Restrict processing in certain circumstances
- Object to processing based on legitimate interests
- Withdraw consent at any time where processing is based on consent
Legal bases we rely on:
- Consent (waitlist form, marketing communications, optional analytics)
- Contract performance (providing the app service you purchased, including pronunciation scoring of audio you send us)
- Legitimate interest (spam prevention, security, aggregated analytics)
- Legal obligation (tax, accounting, and legal compliance)
International data transfers: Our providers may process your data in the United States and other countries. Where those transfers involve personal data of EEA, UK, or Swiss users, they are made under appropriate safeguards such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
To exercise any of these rights, email privacy@streettongueapp.com. We will respond within 30 days.
You also have the right to lodge a complaint with your local data protection authority (for example, the AEPD in Spain, the CNIL in France, or the BfDI in Germany).
Your Rights Under CCPA (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:
- Right to Know. You may request disclosure of the personal information we collect, use, disclose, and share, including the sources, the purposes, and the categories of third parties we share it with.
- Right to Delete. You may request deletion of personal information we hold about you, subject to certain exceptions.
- Right to Correct. You may request correction of inaccurate personal information we hold about you.
- Right to Opt Out of Sale or Sharing. StreetTongue does not sell personal information and does not share personal information for cross-context behavioral advertising. There is nothing to opt out of.
- Right to Non-Discrimination. We will not provide you with a different level of service or charge you a different price for exercising your CCPA rights.
To submit a CCPA request, email privacy@streettongueapp.com.
Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated effective date. For material changes, we will notify you via email or a prominent notice on the Service. We encourage you to review this policy periodically.
Contact Us
For privacy-related questions, data requests, and deletion requests:
For general support: support@streettongueapp.com
DaxTech LLC, a Nevada limited liability company, doing business as StreetTongue App 732 S 6th St Ste N Las Vegas, NV 89101 United States