Privacy Policy for Podo Speak
Effective date: August 10, 2026 Last updated: August 10, 2026
1. Overview
Podo Speak (“the App”, “we”, “us”) is a Korean speaking-practice application published by Awesome Korean. The App listens to you speak Korean sentences, transcribes what you said, and scores how closely it matches the target sentence.
This Privacy Policy explains what data we collect, why we collect it, who we share it with, and how you can access or delete it. It applies to the Podo Speak mobile app.
By using the App you agree to the practices described in this policy. If you do not agree, please do not use the App.
2. Data We Collect
2.1 Account data
| Data | When collected | Why |
|---|---|---|
| Anonymous account identifier (Firebase UID) | Automatically, the first time you open the App | To save your learning progress and restore it across sessions |
| Email address, display name, sign-in provider (Apple or Google) | Only if you choose to sign in with Apple or Google | To let you keep your progress after reinstalling or changing devices, and to reply to you if you ask us for something (for example, to tell you when new lessons you requested are ready) |
| Account timestamps | Automatically | Account maintenance and abuse prevention |
| Push notification token | Only if you have allowed notifications | To deliver service messages, such as letting you know when new lessons are published |
You can use the App without providing an email address. In that case your account is anonymous — it is tied to your device installation only, and we have no way to identify you personally.
If you sign in with Apple, you may choose Apple’s “Hide My Email” option. We only ever receive the relay address Apple provides.
We only email you about something you asked us for. We do not send marketing or promotional email, and we do not share your address with anyone else.
2.2 Voice recordings and transcripts
This is the most sensitive data the App handles, so we describe it in detail.
What happens when you speak:
- The App records only while it is your turn to speak on a practice card. Each recording is short (at most about 15 seconds) and ends as soon as you finish speaking. The card shows clearly when recording is in progress.
- The recording is saved as a temporary audio file on your device.
- The audio is sent, over an encrypted connection, to our server function (Google Cloud Functions,
us-central1region), which forwards it to a third-party speech-recognition provider for transcription. Our current provider is named in section 4. - The transcribed text is returned to the App and compared against the target sentence.
- The temporary audio file on your device is deleted after evaluation.
What we do not do:
- We do not store your voice recordings on our servers or in our database. Audio is processed in memory and discarded once transcription completes.
- We do not record in the background, when the App is not in the foreground, or at any time other than during an active practice prompt in a learning session. Recording is confined to the practice cards described above; leaving the learning screen ends it.
- We do not use your voice to build voice profiles, biometric identifiers, or voiceprints, and we do not attempt to identify you from your voice.
Transcripts: When an attempt is scored as incorrect, we log the transcribed text with the target sentence and the error score to our analytics service, so we can find and fix cases where correct speech was marked wrong. These transcripts are your spoken attempts at the practice sentences the App shows you, and are linked to your account identifier.
Microphone permission is required for the App to function. You can revoke it at any time in your device settings; the App will then be unable to evaluate speech.
2.3 Learning data
To show your progress, streaks and daily goal, we store:
- Per-sentence records: whether a sentence is learned, best and latest accuracy score, attempt and success counts, first-learned and last-reviewed timestamps
- Session summaries: session ID, chunk studied, sentence counts, duration, completion status
- Daily statistics: practice time, sentences spoken, sessions completed, per calendar day
- Aggregate summary: total practice time, total sentences, current and longest streak
This data is stored on your device first and synchronized to our database (Google Cloud Firestore) under your account identifier.
2.4 App settings
Playback speed, romanization display on/off, and daily reminder on/off and time are stored locally on your device, and reminder preferences are used to schedule notifications.
2.5 Notifications
The App sends two kinds of notifications.
Daily reminders are local notifications scheduled on your device. Deciding when to send them and what they say happens entirely on your device; no reminder content is sent to or from our servers.
Service messages (for example, when new lessons are published) are sent from our servers through Google Firebase Cloud Messaging. To deliver them, Firebase issues a device push token, which we store with your account ID so we can send a message to your device. The token identifies a device installation, not you personally; it changes when you reinstall the App, and it is deleted along with the rest of your data when you delete your account.
Whether a notification was tapped, and whether a session followed, is recorded as an analytics event (without message content tied to any personal identifier beyond your account ID).
Notification permission is optional, and we request a push token only if you have already allowed notifications. The App works fully without it.
2.6 Analytics and diagnostics
We use Google Firebase Analytics and Firebase Crashlytics to understand how the App performs and to diagnose failures. These collect:
- App usage events (session started/completed/abandoned, errors shown, paywall viewed, purchase attempted, reminder opened, recognition timing measurements)
- Crash reports and non-fatal error reports, including stack traces
- Device and environment information collected automatically by Firebase: device model, operating system version, app version, language, country/region derived from IP address, and Firebase-generated installation identifiers
Your anonymous account identifier is attached to these reports so that we can trace a specific problem report back to a specific account’s history.
2.7 Device integrity
We use Firebase App Check (Apple App Attest on iOS, Google Play Integrity on Android) to verify that requests to our speech-recognition function come from a genuine, unmodified copy of the App. This produces a device attestation token; it does not identify you.
2.8 Subscription and payment data
Subscriptions are sold through the Apple App Store or Google Play Store and managed through RevenueCat, a subscription-management service.
- We never receive or store your payment card details. Payment is handled entirely by Apple or Google.
- RevenueCat receives your Firebase account identifier (used as the subscription user ID), purchase and receipt information, subscription status, and device/platform information, so that your subscription follows your account across devices.
2.9 Data we do not collect
We do not collect your name (unless supplied by Apple/Google sign-in), phone number, precise location, contacts, photos, calendar, health data, or advertising identifiers. The App contains no third-party advertising and no advertising trackers.
3. Legal Bases for Processing (EEA / UK users)
| Purpose | Legal basis |
|---|---|
| Creating an account and saving learning progress | Performance of a contract (Art. 6(1)(b) GDPR) |
| Processing voice recordings to score your speech | Performance of a contract; the core feature you requested |
| Sending daily reminders | Consent (Art. 6(1)(a)), which you may withdraw at any time |
| Analytics, crash reporting, service improvement | Legitimate interests (Art. 6(1)(f)) — operating and improving the App |
| Fraud/abuse prevention (App Check) | Legitimate interests |
| Processing subscriptions | Performance of a contract; legal obligation for tax/accounting records |
We do not process special-category data. We treat voice recordings as sensitive and process them only transiently, as described in section 2.2, and never for biometric identification.
4. Who We Share Data With
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share data only with the service providers required to run the App:
| Provider | Data shared | Purpose | Location |
|---|---|---|---|
| Google (Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Analytics, Crashlytics, App Check, Cloud Messaging, Remote Config) | Account ID, learning data, settings, analytics events, crash reports, push token, audio in transit | Hosting, authentication, database, analytics, crash reporting, service notifications, remote configuration | United States and other Google regions |
| Speech-recognition provider (currently OpenAI) | Recorded audio for the current prompt only | Speech-to-text transcription | United States |
| RevenueCat | Account ID, purchase/receipt and subscription status | Subscription management and restore | United States |
| Apple / Google | Purchase and billing data; sign-in identity if you use their sign-in | Payment processing, authentication | Per their own policies |
We may change these providers as the service evolves. The table above reflects our current providers and will be updated here whenever it changes; if a change materially affects how your data is handled, we will notify you as described in section 10.
We may also disclose information if required by law, valid legal process, or to protect the rights, safety or property of our users or of Awesome Korean.
Privacy policies of our current providers:
- Google/Firebase — https://firebase.google.com/support/privacy and https://policies.google.com/privacy
- OpenAI — https://openai.com/policies/privacy-policy
- RevenueCat — https://www.revenuecat.com/privacy
- Apple — https://www.apple.com/legal/privacy
5. International Data Transfers
Our servers and the services listed above are located primarily in the United States. If you use the App from the European Economic Area, the United Kingdom, Korea or elsewhere, your data will be transferred to and processed in the United States. Where required, these transfers rely on the European Commission’s Standard Contractual Clauses or an equivalent approved transfer mechanism operated by the relevant provider.
6. How Long We Keep Data
| Data | Retention |
|---|---|
| Voice recordings | Not retained. Processed transiently and deleted; local temp file deleted after evaluation |
| Account and learning data | Until you delete your account |
| Analytics events (in Firebase Analytics) | Per Firebase Analytics retention settings, up to 14 months |
| Analytics events (copied to our BigQuery data warehouse) | Kept for as long as they remain useful for understanding how the App is used and improving it. These records are keyed to your account identifier, not to your name or email, and we delete an individual’s records on request (section 7.2) |
| Crash reports | Up to 90 days |
| Purchase/subscription records | As long as required by tax and accounting law (typically 5 years) |
7. Your Rights and Choices
7.1 Delete your account and data
In the App: Settings → Delete account. This performs a two-step confirmation and then deletes, in order:
- Your learning data in our database (sentence records, session logs, daily statistics, summary, and profile document)
- All learning data stored locally on your device
- Your authentication account
Deletion is permanent and cannot be undone. Note that an active subscription is not cancelled by deleting your account — subscriptions must be cancelled through the App Store or Google Play (see the Terms of Use).
7.2 Other rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to withdraw consent, to receive a copy of your data in a portable format, and to lodge a complaint with a supervisory authority. California residents have the rights to know, delete, correct, and opt out of sale/sharing (we do not sell or share personal information as defined by the CCPA/CPRA), and will not be discriminated against for exercising them.
To exercise any of these rights, email contact@podokorean.com with your User ID (Settings → Account → copy User ID). We respond as soon as we can, and within the time limits required by applicable law.
7.3 Permission controls
- Microphone: revoke in your device settings at any time. Speech evaluation will stop working.
- Notifications: turn reminders off in Settings → Reminders, or revoke notification permission in your device settings.
- Analytics: the App does not currently offer an in-app analytics opt-out. You may request that we delete your analytics data by emailing us, or stop collection by uninstalling the App.
8. Security
We protect your data with:
- Encrypted transport (HTTPS/TLS) for all network communication
- Server-side secrets: the transcription provider’s API key exists only in server-side secret storage and is never included in the App
- Firebase App Check enforcement on the speech-recognition endpoint, so only genuine app instances can call it
- Database security rules restricting each account’s data to that account
- Encryption at rest for data stored by our infrastructure providers
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Children’s Privacy
Podo Speak is not directed to children. You must be at least 13 years old to use the App (16 in the European Economic Area and the United Kingdom, 14 in the Republic of Korea, or the minimum age of digital consent in your jurisdiction, whichever is higher). We do not knowingly collect personal information from children below that age. If you believe a child has provided us with personal information, contact contact@podokorean.com and we will delete the account and its data.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will change the “Last updated” date at the top and post the revised policy at https://podokorean.com/podospeak/privacy-policy. If the changes materially affect how we handle your data, we will post the revised policy at least 30 days before it takes effect, and will use reasonable efforts to highlight the change — for example, in a notice shown in a new version of the App. Continued use of the App after the effective date constitutes acceptance of the revised policy.
11. Contact Us
Podo Speak is operated by Awesome Korean.
Personal Information Protection Officer: Jeongwoo Park
Email: contact@podokorean.com
For privacy questions, data access requests, or complaints, please contact us at the email address above. This email is the single point of contact for all privacy matters, including requests to access or delete your data.