Skip to main content

Privacy Policy

Last updated: August 10, 2026

This policy explains what data we collect, how we use it, and your rights regarding your information. We have tried to write it so that it describes what the product actually does, including the parts that are least flattering to us. If you only read two sections, read section 3, on the AI-generated profile we keep about you, and section 4, on what your teacher can see.

1. Information We Collect

Account Information

You can sign in with Google, or with an email address (password or emailed sign-in link). Depending on the method, we hold:

  • Your email address
  • Your name (as you enter it, or as provided by Google)
  • Profile picture (if your sign-in provider supplies one)
  • Your school, classroom, and teacher, if you joined through a classroom
  • Your phone number and time zone, only if you turn on the optional "Morning Brief" practice phone call

Learning Data

To provide personalized tutoring, we store:

  • Conversation transcripts from your tutoring sessions
  • Learning progress and statistics (XP, streaks, session duration)
  • Error patterns and corrections (to help you improve)
  • Spaced repetition data (review schedules for your learning items)
  • Language preferences and proficiency level
  • A written "learner profile" about you, generated by AI from your conversations — see section 3 below

Voice Data

Your voice is processed in real time and we do not store recordings. Audio from your microphone is streamed through our session infrastructure to our speech-recognition provider, converted to text, and discarded. We keep the text transcript, not the audio. In the self-paced "Speak" exercise, one short audio clip is uploaded for transcription and is likewise not stored by us.

Our speech-recognition, language-model and text-to-speech providers each receive the data needed to do their job — audio, or the text of the conversation — and handle it under their own retention terms. We use these services under terms that do not permit our data to be used to train their models.

Payment Information

Payment processing is handled entirely by Stripe. We do not store your credit card numbers or banking details. We only receive confirmation of your subscription status.

Usage and Analytics Data

To understand how Cadentia is used and to diagnose problems, we collect product analytics through PostHog: the pages and features you visit, clicks and other interface interactions, and basic device and browser information. These events are tied to a pseudonymous account identifier (your user ID) along with non-identifying attributes such as your target language and account type. We do not send your email address or name to our analytics provider.

We also use session replay, and it is currently switched on for every session. Session replay records a visual playback of your interactions with the interface — navigation, clicks, and on-screen content — to help us diagnose issues and improve usability. Two things are deliberately hidden from it: everything you type into a form field, and every screen area that displays what a learner said — the live transcript, corrections, suggestions, the "did we mishear you" card, and review cards are masked in the browser before anything is sent. There is currently no per-school switch to turn session replay off.

We also send application error reports to Sentry, and traces of our AI calls to PostHog with the prompt and response content redacted. This analytics data is processed in the United States, is used only to operate and improve Cadentia, and is never sold or used for advertising. You can request its deletion at any time (see Your Rights below).

2. How We Use Your Data

We use your information to:

  • Provide and personalize your language learning experience
  • Track your progress and schedule optimal review times
  • Identify patterns in your errors to help you improve
  • Maintain your account and subscription
  • Send important service updates (we don't send marketing emails)
  • Show your teacher your progress, if you are in a classroom
  • Diagnose faults and improve how the product works

We do not train AI models on your conversations, we do not sell your data, and we do not use it for advertising.

3. The AI-Generated Learner Profile

This is the part people are most often surprised by, so we want to be direct about it.

At the end of each tutoring session, the full text transcript of that session is sent to OpenAI, and an AI model reads it and writes down personal facts about you. Those facts are saved to your account as a "learner profile": a short third-person description of you, plus a list of individual notes. The categories the model is asked to look for are: who you are (including things like your name and age), why you are learning, your job or studies, your family, your interests, how you feel about speaking, and dates or deadlines that matter for your lessons.

We do this so the tutor remembers you between sessions and can talk to you about your actual life instead of starting from zero every time. The profile is fed back into the tutor's instructions at the start of your next session, and is also used to personalise features such as the Morning Brief.

Things worth knowing: the profile is written by an AI and can be wrong. It is rewritten and trimmed after each session rather than growing forever. It contains whatever you happened to say out loud, which may include information you would not have chosen to type into a form. You can ask us to show it to you, correct it, or delete it — email us at the address at the bottom of this page. Deleting your account deletes it.

4. School and Classroom Use

If you joined Cadentia through a classroom join code or a school invitation, some of your data is visible to staff at that school. In plain terms:

Your teacher can read the word-for-word transcript of your tutoring sessions, along with your corrections, vocabulary items, assignment submissions and progress statistics. This is not a summary — it is what you actually said, as transcribed. Co-teachers on the classroom, and administrators of the school or district that owns the classroom, have the same read access.

That access is scoped in three ways:

  • By date. By default a teacher only sees sessions from on or after the date you joined their classroom — not your earlier practice. A teacher can switch this on to include your history from before you joined; if they do, that change is recorded in our internal access log.
  • By language. A teacher only sees sessions in the language their classroom is for. Practice you do in another language is not shown to them.
  • By session. Each session carries a flag controlling whether it is visible to teachers, and every teacher-facing screen respects it. To be honest about the current state: there is no button in the app today that lets a student switch that flag off. Sessions you start outside a classroom context are not shared with a classroom.

Access logging. When a member of staff opens an individual student's transcript, exports student error data, changes the history setting, or signs in as a student for support, we write a record to an internal access audit log (who, what, when). We do not currently log every listing screen — only the actions above. This log is not self-serve; schools can request extracts from it.

Age and consent for schools. Cadentia asks for a minimum age of 13 for people who sign up on their own, but we do not collect a date of birth and we do not technically verify anyone's age. For schools, the control is provisioning: students get accounts because a teacher or administrator enrols them or gives them a join code, and the institution is responsible for deciding which students may use Cadentia and for obtaining any consent the law requires of it. A join code only works if the teacher's account has been verified by us and is permitted to invite students.

Guardians. A learner can link a parent or guardian's existing Cadentia account to their own. Only the learner can create that link, and they can revoke it. While it is active, the guardian can read that learner's session transcripts, corrections and progress. Guardian access is not limited by classroom, date, or language.

Platform administrators. A small number of Cadentia staff accounts can access user data to operate and support the service.

5. Subprocessors — Who Else Touches Your Data

These are the companies that process personal data on our behalf in order to make Cadentia work. Each has its own privacy policy and handles data under its own terms.

ProviderWhat it receivesWhyWhere
Supabase (on AWS)Account details, transcripts, learning items, learner profileOur database and sign-inUnited States (AWS us-east-2, Ohio)
VercelWeb requests you make to the siteHosts the website and its APIsUnited States
HetznerLive session audio and text in transitRuns our voice tutoring agentUnited States (Ashburn, Virginia)
LiveKitLive session audioReal-time voice connection; transit only, no storage by usUnited States
SonioxYour speech audioSpeech-to-text — our primary providerUnited States
DeepgramYour speech audioBackup speech-to-text, used when Soniox is unavailable or does not support your languageUnited States
OpenAIConversation text, including full session transcriptsThe tutor itself, error analysis, and the learner profile in section 3United States
Microsoft AzureTutor text; speech audio for a few languagesThe tutor's voice (primary), and speech-to-text where Soniox has no supportUnited States (East US)
GoogleYour email and name, only if you choose Google sign-inSign-in. (A Google text-to-speech fallback is wired but no language currently uses it)United States
PostHogProduct events, session replays, AI call traces with content redacted. Learner speech and form inputs are masked before sendingProduct analytics and troubleshootingUnited States
SentryError reports and technical diagnosticsDetecting and fixing crashesUnited States
StripeBilling contact and payment details (we never see card numbers)Payments for paid plansUnited States
ResendYour name and email addressTransactional email — sign-in links, invitations, remindersUnited States
LiveKit SIP and its telephony carrierYour phone number and the call audioThe optional "Morning Brief" practice phone call onlyUnited States

We will update this list when it changes. If you are evaluating Cadentia for a school and need vendor detail beyond this table, write to us and we will provide it.

6. Where Your Data Is Stored

All of it is in the United States today. Our database sits in AWS us-east-2 (Ohio) via Supabase; our website runs on Vercel in the US; the voice tutoring agent runs on a server in Ashburn, Virginia; our analytics are on PostHog's US cloud; and our speech and language providers process in the US.

We do not currently offer a Canadian, EU, UK, or Australian data region. If you are outside the United States, using Cadentia means your data is transferred to and processed in the United States, where it may be subject to US law. We would rather say this plainly than let you discover it later.

7. Data Retention

While your account is open, we keep your data indefinitely. There is no automatic expiry and no background job that deletes old transcripts, corrections or profile notes. Your transcripts from a year ago are still there. We keep them because your review schedule and progress history are built on them — but we would rather state it than imply a clean-up that does not happen.

When you delete your account, deletion happens immediately. You can do it yourself from your account settings. Removing your account removes the records that hang off it — transcripts, learning items, learner profile, classroom memberships — and we send a deletion request to our analytics provider to remove your events, person record and session replays. Backups and system logs roll off on their own cycles, and we may retain the minimum needed for legal, tax or fraud-prevention purposes.

There is also a "reset" option that wipes your learning data while keeping your account. Where a school holds the relationship, we will return and delete district data on request or on termination.

8. Your Rights

You can ask us to:

  • Show you your data — including your AI-generated learner profile
  • Correct it — if something we hold about you is wrong
  • Delete it — your account and the data attached to it
  • Give you a copy — your learning history and progress

Two honest caveats about how these work in practice. Deletion is self-serve — you can do it yourself from your account settings, right now. Export is not. There is no download button in the app today; you email us and we assemble your data by hand and send it to you. We are working on making that self-serve. Everything else on this list is handled by email at the address below.

If your account was created by a school, some of these requests may need to go through the school, since it decides what happens to its students' records. We will help either way.

9. Security

Data is encrypted in transit (HTTPS/TLS) and at rest by our hosting providers. Our database uses row-level security so that, by default, a user's records are only readable by that user; identity is established server-side, so a browser can never claim to be a different user. Teacher and school access runs through a separate, explicitly checked permission layer, described in section 4. Access to production data is limited to a small number of staff accounts.

What we do not claim. We are a small company. We do not hold SOC 2, ISO 27001, or any other security certification, and we are not going to describe ourselves as "GDPR compliant" or "FERPA certified" on a marketing page. Our infrastructure providers hold their own certifications and we can share what they publish. If you are assessing us for a school or district, ask us and we will answer specifics honestly, including the things we have not built yet.

10. Children's Privacy

Cadentia is not intended for children under 13 signing up on their own. We do not knowingly collect personal information from them. To be precise about the mechanism: we do not ask for a date of birth and we do not verify age, so this is a rule we state and enforce on report, not a technical gate.

Where a school or district provisions Cadentia, the institution decides which students may use it and is responsible for any consent required of it. If you believe a child has given us personal data, contact us and we will delete it.

11. Changes to This Policy

We may update this privacy policy from time to time. We'll notify you of significant changes by email or through the app. Continued use after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this privacy policy or want to exercise your data rights, contact us at:

Email: privacy@cadentialearning.com