Privacy Policy
Effective 30 August 2026
This policy explains what GoAloud collects when you practise speaking, why we collect it, who else processes it, and how to get it back or have it deleted. We have tried to write it in plain language rather than boilerplate.
1. Who we are
GoAloud is a service operated by GoAloud ("we", "us"). It lets you practise spoken English by holding a conversation with an AI partner that listens, replies out loud, and gives you feedback on how you spoke. We are the data controller for the personal data described below.
If you have any question about this policy, or want to exercise any of the rights in section 8, write to info@goaloud.ai.
2. What we collect
Account information
Your name and email address, and a securely hashed version of your password — we never store the password itself. If you use "Sign in with Google", we receive your Google account identifier, name, email address, and profile picture URL instead of a password. If you turn on two-factor authentication, we store the secret and recovery codes needed to verify your codes.
Voice recordings
When you tap the microphone and speak, your browser records the audio and sends it to us. We store that recording so you can play your own sessions back, and we send it to our speech-to-text provider to be turned into text. Nothing is recorded before you start a recording, and nothing is recorded after it stops.
What you said, and what we made of it
The transcript of each recording, your practice partner's replies, and everything derived from them: grammar, vocabulary, and phrasing corrections; end-of-session summaries; the vocabulary suggestions we collect for you and how many times you have said each one out loud; and your progress figures — minutes practised, sessions completed, day streak, the seconds you have spoken today, the words you have mastered, and the Elo and divisions behind your two ranks.
Technical information
Our servers keep ordinary web logs containing your IP address, browser user agent, the pages requested, and timestamps. We use these to keep the service running securely and to diagnose faults.
Cookies and browser storage
We use a session cookie to keep you signed in, and a CSRF cookie to protect forms against cross-site request forgery. Both are strictly necessary for the service to work. We also remember small preferences — whether your sidebar is open, your light or dark appearance choice, and which practice panel you had open — in cookies and in your browser's local storage. We do not use advertising or cross-site tracking cookies.
The free speaking test
You can take a thirty-second speaking test on our site without an account. Your browser records your answer and sends it to us; we pass the audio to our speech-to-text provider to be transcribed, and then discard it. The recording itself is never stored, never listened to by a person, and never used to train any AI model. What we keep is the transcript, your score, the written feedback, a one-way hash of your IP address (used only to limit how many tests one connection can run) and the time. Your result page is public to anyone who has its link, which is a random identifier nobody can guess, and it is deleted automatically ninety days after the test. If you later create an account from your result, the test is attached to that account as your starting point and is deleted with it.
3. Why we use it
- To provide the service: transcribing what you said, generating a spoken reply, producing corrections and summaries, and tracking your progress and daily goal.
- To maintain your account, authenticate you, and keep the service secure against abuse.
- To fix problems and improve how the product works, using aggregate and diagnostic information.
- To contact you about your account, such as verifying your email address or resetting your password.
Under the UK and EU GDPR, our legal bases are: performance of our contract with you, for everything needed to deliver the service; our legitimate interests in keeping the service secure and working well; and your consent, which your browser asks for separately before any microphone access and which you can withdraw at any time in your browser settings.
4. Who else processes your data
Delivering a spoken conversation needs specialist providers. Each one receives only what it needs, only when you use the feature it powers, and is bound by its own agreement with us to process that data solely on our instructions.
- Deepgram — Speech-to-text. Receives the audio of your recordings to transcribe what you said. Privacy policy.
- Anthropic — Conversation, corrections, session summaries, and vocabulary suggestions. Receives the text of your transcripts, never your audio. Privacy policy.
- ElevenLabs — Text-to-speech. Receives the text of your practice partner's replies to synthesise the spoken voice. Privacy policy.
- Google — Optional "Sign in with Google" authentication. Only used if you choose that sign-in method. Privacy policy.
We also use conventional infrastructure providers for hosting, storage, and email delivery. We do not sell your personal data, we do not share it with advertisers, and we do not use your recordings or transcripts to train our own AI models.
5. International transfers
Some of the providers listed above process data outside the United Kingdom and the European Economic Area, principally in the United States. Where that happens, the transfer is covered by the safeguards those providers offer, such as the European Commission's Standard Contractual Clauses.
6. How long we keep it
Your account data, recordings, transcripts, corrections, vocabulary, and progress are kept for as long as your account is open, because the point of them is that you can go back and review them. Delete your account and we delete all of it, along with the audio files behind it. Server logs are kept for a short period for security and debugging, and are then discarded. Backups may retain data briefly after deletion before they too expire.
7. Security
Traffic between your browser and our servers is encrypted in transit. Passwords are stored only as salted hashes, and two-factor authentication is available on every account from your security settings. Access to production systems is restricted to the people who need it. No service can promise perfect security, but we take this seriously and will tell you without undue delay if a breach affects your data.
8. Your rights
Depending on where you live, you have the right to access the personal data we hold about you, to have it corrected, to have it erased, to receive a copy in a portable format, to restrict or object to certain processing, and to withdraw consent where we rely on it.
You can delete your account and everything attached to it yourself, at any time, from your profile settings — no request needed. For anything else, email info@goaloud.ai and we will respond within 30 days. If you are unhappy with our response, you may complain to your local data protection authority.
9. Children
GoAloud is not intended for children. You must be at least 16 years old to create an account. If we learn that we hold data from a child below that age, we will delete it.
10. Changes to this policy
If we change this policy in a way that materially affects you, we will update the effective date at the top and let you know in the app or by email before the change takes effect. Continuing to use the service after that means you accept the updated policy.
11. Contact
Privacy questions and data requests: info@goaloud.ai. Everything else: info@goaloud.ai. See also our Terms of Service.