Un momento…
Privacy Policy
Effective date: June 21, 2026
This Privacy Policy explains how Diego (“we”, “our”, or “us”) collects, uses, and protects your personal information when you use our Service. We are committed to protecting your privacy and handling your data in an open and transparent manner.
1. Who We Are (Data Controller)
Diego operates an AI-powered Spanish voice conversation tutor — a live, spoken practice session with an on-screen tutor. Diego (operated at hablacondiego.com) is a trade name (“doing business as” / DBA) wholly owned and operated by Salty Apparel LLC, a company based in the United States, and we store and process your data primarily in the United States.
For the purposes of the EU General Data Protection Regulation (“GDPR”), the UK GDPR, and similar laws, Salty Apparel LLC (operating as Diego) is the data controller of the personal data described in this policy. For any privacy questions, or to exercise your rights, contact us at [email protected].
2. Data We Collect
2.1 Information you provide
- Account data: email address, password (stored as a hashed credential via Supabase Auth), and optional display name.
- Profile data: your chosen Spanish level, learning goals, interests, location (optional), and preferred speech pace.
- Invitation code: the code used when you signed up (to verify eligibility).
2.2 Data generated during use
- Conversation content: the spoken and/or typed exchanges between you and Diego during practice sessions.
- Learning data: vocabulary items, error patterns, grammar areas requiring practice, session history, and spaced-repetition review records — used to personalise Diego's tutoring.
- Usage data: minutes of practice consumed, session durations, and service usage for billing and capacity planning.
2.3 Technical data
- Log data: server-side structured logs including session identifiers, timestamps, and error codes (no full conversation content in logs).
- Error monitoring: we use Sentry to capture diagnostic error reports. It is configured conservatively — no Session Replay and no intentional collection of personal data.
- Cookies: a session cookie set by Supabase Auth to keep you logged in, a cookie-consent preference cookie, and first-party analytics cookies (a visitor and a session identifier) used to understand how the Service is used in aggregate. We do not use advertising cookies.
- Product analytics: we run our own first-party analytics — usage events (e.g. pages visited, features used) are sent to and stored on our own servers, with no third-party analytics provider. The data is pseudonymous, not linked to your name, and used only to improve the Service.
- Payment data: billing and transaction records managed by Stripe. We do not store your card details; Stripe does.
3. How We Use Your Data
- To provide the Service: authenticate you, stream voice sessions, generate AI responses, and store your learning progress.
- To personalise tutoring: feed your error patterns, vocabulary, and profile into Diego's AI system prompt so sessions adapt to your needs.
- To manage your subscription: track credit consumption, enforce usage limits, and process payments.
- To operate and improve the Service: monitor performance, diagnose errors, and develop new features. We process aggregate usage metrics; we do not use individual conversation content to train AI models without your explicit consent.
- To communicate with you: send transactional emails (email verification, billing receipts, important service notices). We do not send marketing emails without your consent.
- To comply with legal obligations: retain records as required by applicable law.
4. Legal Bases for Processing (EEA & UK)
If you are in the European Economic Area (“EEA”), the United Kingdom, or another jurisdiction with comparable law, we rely on the following legal bases to process your personal data:
- Performance of a contract (GDPR Art. 6(1)(b)) — to create and operate your account and provide the tutoring service you sign up for.
- Legitimate interests (Art. 6(1)(f)) — to secure the Service, prevent abuse, debug errors, and understand aggregate usage so we can improve the product. We balance these interests against your rights.
- Consent (Art. 6(1)(a)) — for non-essential analytics cookies and any optional marketing. You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)) — to keep tax, accounting, and other records the law requires.
5. California Privacy Rights
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the “CCPA”), gives you specific rights regarding your personal information:
- Right to know: request the categories and specific pieces of personal information we have collected about you, and how we use and disclose it.
- Right to delete: request deletion of the personal information we have collected from you, subject to certain exceptions.
- Right to correct: request correction of inaccurate personal information we maintain about you.
- Right to opt out: opt out of the “sale” or “sharing” of personal information. We do not sell your personal information and we do not share it for cross-context behavioral advertising.
- Right to non-discrimination: we will not discriminate against you for exercising any of your privacy rights.
To exercise any of these rights, contact us at [email protected]. We will verify your request using the email address registered on your account before acting on it.
6. Data Sharing & Sub-processors
We share your data only as necessary to operate the Service. Our sub-processors are:
- Supabase (authentication and database hosting — US region)
- Anthropic (AI language model — your anonymised conversation context is sent to generate Diego's responses)
- Deepgram (speech-to-text — your audio is streamed for real-time transcription during a session)
- Cartesia (text-to-speech — Diego's spoken replies are generated from their text)
- Stripe (payment processing — billing data only)
- Sentry (error monitoring — diagnostic reports, configured with no Session Replay and no intentional personal data)
- DigitalOcean (cloud hosting infrastructure)
Each sub-processor acts as our processor, is bound by contractual data-protection obligations (including GDPR Art. 28 terms where applicable), and may use your data only to provide services to us. We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
7. Data Retention
- Account data is retained for as long as your account is active or until you request deletion.
- Conversation and learning data is retained for as long as your account is active to support your ongoing learning journey, then deleted within 30 days of account closure.
- Server logs are retained for up to 90 days.
- Billing records are retained for as long as tax and accounting law requires, even after account closure.
8. Your Rights
Regardless of where you live, we offer all users the following rights regarding your personal data (these mirror the rights granted under the GDPR and UK GDPR):
- Access: request a copy of the personal data we hold about you.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion of your data (“right to be forgotten”), subject to legal retention obligations. To request deletion, email [email protected] from the email address registered on your account, stating what you would like deleted (e.g. all account data, conversation history only). Requests sent from a different address cannot be actioned for security reasons.
- Restriction: request that we limit how we process your data.
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to certain processing of your data.
- Withdraw consent: where processing is based on consent, withdraw it at any time, without affecting processing already carried out.
- Automated decisions: we do not make decisions that produce legal or similarly significant effects about you based solely on automated processing.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days (one month for GDPR/UK GDPR requests, extendable by two further months for complex requests, in which case we will tell you). We may verify your request using the email address registered on your account before acting on it.
Right to complain. If you are in the EEA or the UK and believe we have mishandled your data, you may lodge a complaint with your local data protection authority — for example, the UK Information Commissioner's Office (ICO), or the lead supervisory authority in your EU member state. You can find your authority via the European Data Protection Board. We would, of course, appreciate the chance to address your concern first.
9. Cookies
We use a minimal set of cookies:
- Authentication cookie (essential): set by Supabase Auth to keep you logged in. Required for the Service to function.
- Cookie-consent preference (functional): remembers your cookie consent choice.
- First-party analytics cookies (a visitor identifier and a session identifier): set by us (not a third party) to count visitors and sessions and understand in aggregate how the Service is used and where to improve it. They contain only random identifiers, are never shared with an external analytics provider, and are not used for advertising.
We do not use advertising cookies or cookies that identify you individually for marketing purposes.
10. Data Security
We implement technical and organisational measures to protect your data, including:
- All data in transit encrypted with TLS 1.2+.
- Passwords hashed by Supabase Auth (bcrypt); we never store plaintext passwords.
- Row-Level Security (RLS) on all database tables so each user can only access their own data.
- Provider API keys (Anthropic, Deepgram, Cartesia) held only on the server and never exposed to the browser.
- Regular security reviews and monitoring.
No method of transmission over the internet or electronic storage is 100% secure. If we become aware of a personal-data breach that is likely to affect your rights, we will notify the relevant supervisory authority within 72 hours where the GDPR/UK GDPR requires it, and notify you without undue delay where the breach is likely to result in a high risk to your rights.
11. Children's Privacy
The Service is not directed to children. We do not knowingly collect personal information from children below the minimum age of digital consent that applies to them. In the EEA that age is 16 (or a lower age, down to 13, set by your member state); in the United States and the United Kingdom it is 13. If you believe a child below the applicable age has provided us with personal data, please contact us so we can delete it.
12. International Data Transfers
Salty Apparel LLC (operating as Diego) is based in the United States, and we (and our sub-processors) store and process your personal data primarily in the United States. If you access the Service from the EEA, the UK, or another region, your personal data will be transferred to and processed in countries whose data-protection laws may differ from those in your country.
Where we transfer personal data out of the EEA or the UK, we rely on an appropriate safeguard recognised under the GDPR/UK GDPR — typically the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), an adequacy decision, or another lawful transfer mechanism. You can request a copy of the safeguard we use by emailing [email protected].
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will post the revised policy here with a new effective date and notify you by email or in-app notice where required. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
Contact
For any privacy-related enquiries or to exercise your rights, contact us at [email protected].
See also: Terms of Service