Last updated: 9 June 2025
Privacy Policy
NativSpeaker ("we", "our", "us") is committed to protecting your personal data. This policy explains what we collect, how we use it, and your rights under GDPR and applicable data protection laws.
1. Who we are
NativSpeaker is a language-learning web application operated by NativSpeaker Ltd. If you have questions about this policy, contact us at privacy@nativspeaker.com.
2. Data we collect
Account data
When you create an account we collect your email address and (optionally) your full name. This data is stored in Supabase, our database provider.
Usage data
We collect records of your practice sessions including the TikTok video URLs you study, the languages you practice, session duration, and vocabulary words you save. This data is used to power your dashboard and progress tracking.
Payment data
Payments are processed by Stripe. We never store your card number or full payment details. We receive a Stripe Customer ID and subscription status from Stripe's servers.
Email data
If you opt in to progress emails, we store your email address for the purpose of sending those communications via Resend, our email provider.
Technical data
Our servers log IP addresses, browser type, and page visits in standard server logs. These logs are retained for 30 days for security and debugging purposes.
3. TikTok content
When you paste a TikTok video URL, we send that URL to the TikTok Content Posting API to retrieve publicly available caption data. We do not download, store, or redistribute TikTok video files. Captions retrieved are cached temporarily for your session only.
TikTok's own privacy policy governs the data TikTok holds about the content you access. We only receive caption data for publicly available videos.
4. How we use your data
- To provide and improve the NativSpeaker service
- To authenticate your account and manage your session
- To process payments and manage your subscription (via Stripe)
- To send transactional emails (account confirmation, password reset) via Resend
- To send optional weekly progress summaries (only if you opt in)
- To detect and prevent fraud and abuse
- To comply with legal obligations
5. Legal basis (GDPR)
We process your data under the following legal bases:
- Contract performance — providing the service you signed up for.
- Legitimate interests — security logging, fraud prevention, and service improvement.
- Consent — marketing emails (you can withdraw consent at any time).
- Legal obligation — complying with applicable laws and regulations.
6. Third-party processors
SCCs = Standard Contractual Clauses for international data transfers.
7. Data retention
We retain your account data for as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where we are legally required to retain it (e.g., for tax records, which are kept for 7 years).
Server logs are deleted after 30 days. Session cache data is purged after 7 days.
8. Cookies
NativSpeaker uses HttpOnly session cookies set by our authentication provider (Supabase) to manage your login state. We do not use advertising or tracking cookies. We use one first-party security cookie (ns_last_active) to enforce our 24-hour inactivity timeout.
9. Your rights (GDPR)
If you are located in the EEA or UK, you have the following rights:
- Right to access — request a copy of your data
- Right to rectification — correct inaccurate data
- Right to erasure — request deletion of your data
- Right to restriction — restrict how we process your data
- Right to portability — receive your data in a machine-readable format
- Right to object — object to processing based on legitimate interests
- Right to withdraw consent — for marketing emails at any time
To exercise any of these rights, email us at privacy@nativspeaker.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
10. Data deletion
To delete your account and all associated data, go to Settings → Account → Delete Account in the NativSpeaker dashboard, or email us at privacy@nativspeaker.com. Deletion is permanent and irreversible.
11. Children's privacy
NativSpeaker is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
12. Changes to this policy
We may update this policy from time to time. We will notify you of material changes via email or a prominent notice on the site. The "last updated" date at the top reflects the most recent revision.