Privacy Policy — Eloqo
Last updated: 8 August 2026
This Privacy Policy explains how Ilia Gordeev (“Eloqo”, “we”, “us”) collects, uses, and protects your information when you use the Eloqo mobile application (the “App”). We act as the data controller for the personal data described below.
Contact: support@eloqo.org
1. Who this policy applies to (age)
The App is intended for users aged 13 and over (and 16 and over in the European Economic Area, the United Kingdom, and other regions where 16 is the digital-consent age). The App is not directed to children below these ages, and we do not knowingly collect their personal data. If you believe a child has provided us personal data, contact us and we will delete it.
2. What data we collect
2.1 Account data (Google Sign-In)
Signing in is optional and used to sync your data across devices. When you sign in with Google, we receive from your Google account:
- Email address
- Display name
- Profile photo URL
- A unique user identifier (Firebase UID)
We request only the basic email, profile, and openid scopes. We do
not access your Gmail, contacts, Google Drive, or any other Google data.
2.2 Voice recordings and practice data
When you complete a speaking exercise, the App records your voice and generates practice data, including:
- Audio recordings of your speech (
.m4a) - Speech-to-text transcripts
- Speech metrics (e.g. words per minute, filler-word count, pauses, vocabulary diversity, fluency score) and AI feedback
- Exercise progress and your practice streak
- Your in-app settings (language, recognizer choice, preferences)
Audio is recorded and transcribed, and metrics are calculated, on your device. Your recording and transcript are sent to our AI provider only when you request AI feedback, which requires signing in. If you do not sign in, your recordings and practice data stay on your device and are not uploaded to our servers.
We use your voice to analyze and improve your speaking and to give you feedback — and, only if you separately agree, to improve the analysis itself (section 2.3). We do not use your voice to identify you, and we do not create voiceprints. We do not treat your voice as biometric identification data.
2.3 Improving the speech analysis (only if you agree)
We ask you once, during setup, whether we may use your recordings to improve Eloqo’s speech analysis. The default is no: unless you explicitly agree, your recordings are never used for this, and nothing about the app changes either way — not the analysis you receive, and not your usage limits.
If you do agree, a member of Eloqo staff may listen to individual recordings and compare them against what the AI produced, so we can find where the analysis gets it wrong. In that case:
- Recordings used this way are de-identified — no name, email, or profile content accompanies them.
- Access is limited to Eloqo staff under a confidentiality agreement, not contractors.
- We do not hand recordings over for training third-party models.
- You can change your answer at any time in Settings → Privacy & data, and ask us to delete any recordings already shared.
Withdrawing applies going forward and to any shared copies we still hold; it does not undo work already completed. If we ever change the scope of this use materially, we will ask you again rather than relying on your earlier answer.
Legal basis: consent (Art. 6(1)(a)), which you may withdraw at any time.
2.4 Optional diagnostics (off by default)
Analytics and crash reporting (Firebase Analytics / Crashlytics) are disabled by default. They are collected only if you explicitly turn them on (Settings → Firebase data collection). When enabled, we collect aggregated product-usage events (e.g. which exercises are used, AI-analysis events) and crash/performance diagnostics. We do not collect advertising identifiers and we do not track you across other apps or websites.
3. How we use your data
- To provide the core service: record, transcribe, and analyze your speech and show your progress.
- To sync your recordings, settings, and progress across your devices (only when you are signed in).
- To maintain security and prevent abuse (Firebase App Check).
- With your consent: to understand product usage and fix crashes.
- With your separate consent: to check where the speech analysis gets it wrong and improve it (section 2.3).
4. Legal bases (GDPR / UK GDPR)
- Performance of a contract (Art. 6(1)(b)) — providing the speaking-coach features you request, including recording and AI analysis of your speech.
- Consent (Art. 6(1)(a)) — optional analytics and crash reporting, and the separate permission to use your recordings to improve the analysis (section 2.3); you may withdraw either at any time in Settings.
- Legitimate interests (Art. 6(1)(f)) — security, abuse prevention, and keeping the service working.
5. Service providers (processors) and international transfers
We use Google Firebase (Google Ireland Ltd / Google LLC) as our processor for authentication, cloud storage of recordings, the database (Firestore), AI speech analysis (Firebase AI / Vertex AI), and optional analytics/crash reporting. Your data is stored on Google’s infrastructure and may be processed outside your country, including outside the EEA. Such transfers are covered by Google’s Standard Contractual Clauses and the Google Cloud / Firebase Data Processing Terms. We do not sell your personal data and do not share it with data brokers.
6. Our access to your data (support, safety, service integrity)
Your recordings and practice data are stored in a private, per-account area, and running the service does not involve us reading your content. Automated systems (speech recognition, AI analysis) process your speech to produce your feedback; that is described in sections 2.2 and 5.
Separately, in a small number of narrowly defined cases, an administrator of Eloqo may access specific data in your account through an internal support console:
- Resolving a support request or billing dispute you have raised — for example, checking why an AI analysis was charged but not delivered, or repairing a subscription where Google Play and our records disagree.
- Investigating a technical fault — for example, a session that was scored incorrectly, where the transcript is the only way to see what went wrong.
- Security, abuse prevention, and compliance with legal obligations.
What this can include: your account details (email, sign-up date, last activity), your AI-usage counters and subscription state, and — for one specific recording at a time — its speech-to-text transcript and the calculated speech metrics.
What it never includes: no one listens to your recordings through the support console. It has no audio playback and no download link, by design. The only circumstance in which a person may listen to a recording is the one you can agree to or refuse in section 2.3, which is a separate decision, separately recorded, and unrelated to support.
Every access to a transcript is individually logged, recording who accessed it, which recording, when, and a written justification. Changes an administrator makes to your account — such as adjusting an AI-usage allowance or granting or revoking a subscription — are logged the same way. These logs are retained for 24 months and then deleted.
Legal basis: performance of our contract with you (Art. 6(1)(b)) where the access is necessary to deliver support you asked for, and our legitimate interests (Art. 6(1)(f)) in resolving disputes, correcting faults and keeping the service secure.
7. Data storage and retention
- Recordings and metadata are stored locally on your device and, if you are signed in, in your private area of Firebase (isolated per user account).
- We keep your data while your account exists. When you delete your account or a recording, the data is removed from your device and queued for deletion from the cloud (Storage and Firestore) by an automated backend process.
- Administrator access and action logs (section 6) are kept for 24 months and then deleted. They are retained separately from your account data so that a record of who accessed what survives the deletion of the data itself.
8. Your rights
Subject to applicable law (GDPR, UK GDPR, CCPA/CPRA, and others), you may:
- Access / export your data — use Settings → Privacy & data → Export my data to download a copy of your account profile and recordings.
- Delete your data — use Settings → Delete account, or the public account-deletion page at https://eloqo.org/delete-account.
- Withdraw consent for analytics/crash reporting, or for research use of your recordings (section 2.3), at any time in Settings → Privacy & data.
- Object / restrict / lodge a complaint with your local supervisory authority.
California (CCPA/CPRA): we do not sell or “share” your personal information as those terms are defined by California law. You have the right to know, delete, and not be discriminated against for exercising your rights.
9. Security
Data is encrypted in transit (HTTPS/TLS). Cloud data is access-controlled so that only your authenticated account can read or write your recordings and profile; the single exception is the audited administrator access described in section 6, which happens through a separate, logged path and never through an ordinary account. Local files are protected by your device’s OS-level encryption.
10. Changes to this policy
We may update this policy. Material changes will be communicated in-app, and where required we will ask for your consent again.
11. Contact
Questions or requests: support@eloqo.org, Ilia Gordeev, Padilla 216, 3-1, 08013 Barcelona, Spain.