speakingmonkey

privacy

Last updated 14 September 2026.

practice on your device

Practice history, preferences, a temporary daily-limit notice, and your analytics choice are stored in your browser. Guest history stays there. Signed-in practice history is also synchronised to Supabase so it can follow the account between devices. Preferences and analytics consent remain device-only.

custom-text practice

Pro members can submit their own practice text. SpeakingMonkey sends that text to Azure Speech to generate and measure a matching reference, then stores the exact text, native measurement, and generated WAV in private Supabase storage for up to 30 days. Access requires the same signed-in account and a currently verified Pro subscription. The browser receives only an opaque reference identifier; generated audio is served through a fresh server-side access check.

Expired references and references detached by account deletion are removed by daily maintenance. Do not submit text you do not have the right to process or text containing sensitive personal information.

payments

Paddle is the merchant of record for Pro subscriptions. Paddle processes payment details, tax, receipts, refunds, and billing support. SpeakingMonkey stores Paddle customer and subscription identifiers, price, status, and billing-period dates, but does not receive or store full card details. This processing is necessary to provide and manage the subscription you request.

optional accounts

The core practice loop remains available without an account. If you create one, Supabase Auth stores your email address, login identities, account metadata, and security/session records. Google sign-in also shares the basic profile information shown in its consent screen. Essential session cookies keep you signed in. This processing is necessary to provide and secure the account you requested.

On the first sign-in in a browser, existing guest history is assigned to that account and removed from the guest profile. Each browser then stores a separate statistics shard containing aggregate counts, practice time, sentence IDs, scores, score components, and timestamps. Recordings and sentence text are not included. Account deletion removes your synced practice history.

Account progression is stored separately: your optional username, fixed home timezone, practice dates, XP, and sentence bests. Keyed one-way identifiers prevent the same recording earning rewards repeatedly; this ledger contains no recordings or custom sentence text. Progression stays until account deletion. Guest history does not earn retrospective XP. A pending reward may leave a signed recovery receipt in this browser; it expires after 24 hours and is removed when recovery completes or expiry is checked.

If you upload a profile picture, we crop and resize it, remove its embedded metadata, and store the processed picture in Supabase. The original upload is not retained. Your picture is visible only within your signed-in account. You can replace it or restore the default icon from your account page; account deletion removes it.

pronunciation scoring

When you ask for a score, SpeakingMonkey sends the reference text, locale, and a speech-trimmed recording through a Vercel function in Dublin to Azure Speech in Microsoft's North Europe region. The returned pronunciation measurements are shown to you and written to your browser history.

SpeakingMonkey does not save scoring recordings. Microsoft states that real-time speech-to-text and pronunciation-assessment input is not retained. The legal basis is performing the service you requested.

To avoid paying to score an identical retry twice, SpeakingMonkey can temporarily cache the returned score in Supabase. The cache key is a keyed, one-way value derived from the exact recording and scoring inputs; the recording itself is not stored. The cached result contains no account identifier or detailed scoring-provider response, expires after 15 minutes, and is removed by daily maintenance after expiry.

SpeakingMonkey also adds completed scoring activity to anonymous daily operational counters in Supabase. These counters contain only the UTC day, practice locale, broad attempt type, cache status, provider request totals, submitted-audio duration totals, and success or error counts. Separate counters record how many practice limit responses are returned for each account tier. They contain no account, browser, sentence, score, transcript, recording, or request identifier. This aggregate history helps prioritise language support and control provider costs under Moltu Digital's legitimate interest in operating and improving the service.

friend challenges and score cards

After a library sentence is scored, you can create a public challenge link and shareable score card. The link contains a signed snapshot of the exact sentence, locale, CEFR level, overall and word scores, and the scoring-model and reference-measurement versions needed to decide whether a later score is comparable. It contains no account identifier, username, email address, recording, transcript, or detailed provider response.

Challenge links are not encrypted: anyone who receives one can see and reshare its sentence and scores. The server verifies the signature before displaying it. SpeakingMonkey does not create a database row for a challenge. Rotating the challenge-signing secret invalidates old links; a library or scoring change can also turn a challenge into ordinary practice without a score comparison.

Vercel Web Analytics receives only the /challenge path, because query parameters are removed. With optional PostHog analytics enabled, SpeakingMonkey can record that a challenge was opened, attempted, or shared, along with its locale, level, scores, comparison outcome, and sharing method. PostHog does not receive the signed token, full challenge URL, sentence text, or recording.

limits and security

Guest scoring uses a random, signed identifier stored in an essential HttpOnly cookie, with a recovery copy in browser storage. Signed-in scoring uses a keyed, one-way form of the verified account email, or the account identifier when no email is available. Known Gmail dot and plus-tag aliases are treated as one mailbox and share an allowance; the email itself is not stored in the usage table. The app also hashes a small set of coarse browser and device properties before sending them; it does not inspect canvas, installed fonts, or WebGL. SpeakingMonkey applies another keyed one-way hash before storing that signal. Only opaque identifiers and replenishing usage counters are stored in Supabase in Ireland; idle rows are deleted after two days.

Cloudflare Turnstile checks email-code requests for automated abuse. Cloudflare receives the verification request, including network and browser signals, and returns a short-lived token that Supabase verifies before sending the email.

Vercel supplies the request IP address to the server for scoring and feedback abuse protection. SpeakingMonkey immediately converts it to a keyed, one-way identifier; raw IP addresses are not stored in usage counters. This processing protects the service and controls paid scoring costs. The legal basis is Moltu Digital's legitimate interest in security, preventing abuse, and controlling service costs.

feedback, classroom inquiries, waitlist, and email

Feedback sent through the app can include your selected reason, message, optional email address, score context including the detailed scoring-provider response, and—only when you choose it—the attempt recording. Supabase stores feedback in Ireland. Optional audio is deleted after 30 days; the remaining submission is deleted after one year. This is processed to handle your request and for the legitimate interest of improving the service.

A classroom inquiry includes the teacher's name, email address, school or organisation, approximate student count, the languages their students will use, and a message. Supabase stores it for up to one year so Moltu Digital can respond with a setup plan and quote. It is not used to create student accounts. Please do not include student names or recordings in the inquiry.

If you join the release waitlist, Resend stores your email address in a dedicated waitlist segment so SpeakingMonkey can notify you when the full version is ready. This is based on your consent. The address is kept until you unsubscribe or ask for deletion.

Email sent to hello@speakingmonkey.com is routed by Cloudflare to a Google mailbox. It is kept only as needed to answer and handle the request, normally no longer than one year.

traffic and optional product analytics

Vercel Web Analytics runs on each page to provide aggregate page-view and daily-visitor counts. SpeakingMonkey removes query parameters and fragments before a page view is sent. Vercel can receive the remaining page path, referrer, country, browser, operating system, and device type. It does not use cookies or a persistent visitor identifier. Vercel derives a one-day visitor hash from the incoming request and discards it after 24 hours, so the same person cannot be recognised across different days.

Vercel Web Analytics receives no recordings, replayed audio, sentence text, written feedback, account identifier, email address, or campaign query values. This aggregate measurement helps Moltu Digital understand whether the site is being reached and which broad browser and device combinations need support. The legal basis is Moltu Digital's legitimate interest in operating and improving the service.

PostHog runs only after you choose “allow”. It receives deliberate product events such as locale and level choices, sentence identifiers, score components, timings, feature use, technical error categories, and sanitized campaign tags on started, scored, and failed attempts. It never receives recordings, played audio, sentence text, transcripts, raw error messages, feedback text, or your feedback email address.

Campaign tags stay only in page memory before consent and are removed from the address bar. If you allow analytics, first-touch and latest-touch tags are kept in this browser for up to 30 days. Denying or withdrawing consent deletes them.

PostHog uses a random browser identifier without a person profile, anonymises IP addresses, and stores events in its EU cloud in Frankfurt for 12 months. The legal basis is your consent. Session replay, autocapture, heatmaps, console collection, and performance capture are disabled. Consent can be withdrawn at any time in settings; withdrawal stops future collection. You can allow analytics again there at any time.

providers and transfers

SpeakingMonkey uses Vercel for hosting and anonymous traffic analytics, Microsoft Azure for speech scoring and custom reference speech, Supabase for authentication, private custom references, feedback and rate-limit counters, Paddle as merchant of record, Resend for authentication email, the release waitlist and feedback notifications, PostHog for consent-only analytics, Cloudflare for DNS, email routing and email-code bot checks, and Google for optional sign-in and the contact mailbox. Personal data is not sold. These providers may use approved subprocessors or permit limited support access outside the EEA under applicable transfer safeguards such as adequacy decisions or standard contractual clauses.

your rights

Depending on the circumstances, you can ask for access, correction, deletion, restriction, or portability, and object to processing based on legitimate interests. You can withdraw waitlist or PostHog analytics consent without affecting earlier lawful processing. Contact Moltu Digital at the contact details below. You may also complain to the Norwegian Data Protection Authority.

changes

Material changes will be highlighted in the app before they take effect, with enough time for you to understand the change and use your rights. Minor corrections may only update the date above.

who is responsible

Moltu Digital is the data controller for SpeakingMonkey. Questions and privacy requests can be sent to the address below.

Moltu Digital
Organisation number 937 795 920
Registered in the Norwegian Central Coordinating Register for Legal Entities (Enhetsregisteret).
Snorres gate 9, 7030 Trondheim, Norway
hello@speakingmonkey.com