Privacy Policy
SpeakNatif
Effective date: 15 August 2026 Last updated: 8 September 2026 Version: 1.6
This policy is published in Russian and English. The Russian text is the primary version; this English version is provided for convenience and, in case of discrepancy, is read in accordance with the Russian text.
1. Who we are
SpeakNatif is an online course for learning spoken Italian, operated by Jevgenija Sidlovska, a sole trader registered in the United Kingdom, trading as SpeakNatif ("SpeakNatif", "we", "us", "our").
Data controller: Jevgenija Sidlovska trading as SpeakNatif Postal address: 3 Brownlee Place, NN4 6GA, Northampton, UK Contact for privacy matters: info@speaknatif.com
We are established in the United Kingdom and are therefore outside the European Union. We process personal data of learners who are resident in the EU, the UK and other countries, and we apply the UK GDPR and, where it applies to us, the EU GDPR.
We have not appointed a Data Protection Officer. We are not required to do so: we do not carry out large-scale processing of special category data and we do not carry out large-scale systematic monitoring. Privacy questions go to the address above and are handled by the controller personally.
2. Scope
This policy covers the SpeakNatif website and web application at speaknatif.com, including the installable (PWA) version of the app.
It does not cover third-party websites that we may link to.
3. What we collect
We deliberately collect as little as possible. There are only three categories of data.
3.1. Your email address
We ask for one thing at sign-up: an email address. There is no password, no name, no date of birth, no payment card details held by us, and no profile.
An email address is required because it is the only way to sign in: we send a sign-in link and a six-digit code to that address. You may optionally add a second, recovery email address; this is offered, never required.
If you ask us for marketing email (a checkbox at sign-up or a switch on your Account page — never pre-ticked), we also store the date you asked and the exact wording you agreed to, so that both you and we can see what was actually agreed. If you never tick it, there is nothing to store.
At sign-up each account is also given a random student number (shown on your Account page, e.g. SN-7K3M2Q). It contains no personal information; its purpose is support — because addresses are stored encrypted (see below), the number lets us find your account when you write to us from a different mailbox.
How it is stored. Your email address is never stored in readable form in our database. It is stored twice over, in two derived forms:
- encrypted with AES-256-GCM, using a key held outside the database; and
- as a keyed hash (HMAC-SHA-256), which is what allows us to recognise a returning address without being able to read it.
The consequence of this design is that a leaked copy of our database does not reveal a single email address.
3.2. Your learning progress
The substance of the service. For each learner we store:
- which phrases you have seen and how you rated each one ("again" / "hard" / "good" / "easy");
- the spaced-repetition state for each phrase: repetition count, current interval, ease factor, next due date, whether it is marked learned;
- your favourites;
- your settings: level, number of new phrases per day, interface language, time zone, reminder settings;
- which days you studied.
This data is tied to your account so that your progress follows you between devices. If you use the app without signing in, this data stays in your browser's local storage and never reaches us.
3.3. Technical and usage records
- Learning events. When you use the app it records events such as "lesson started", "phrase shown", "phrase rated", "audio played", "hint used", "lesson completed". These are linked to your account. They contain no IP address and no user-agent string. They exist so that we can tell which phrases are too hard, where lessons are abandoned, and whether the course works.
- How you found us. If you arrive through a partner's link or an advertising campaign, the link carries a short tag — a partner code or campaign labels. If you then create an account, we attach that tag to it: the source, the campaign labels from the link, the website you came from and the date of your first visit. This tells us which partners and campaigns actually bring learners, and it is what a partner is paid for. It contains no browsing history and nothing about what you did anywhere else; if you sign up without following such a link, it simply records that you arrived on your own.
- Sign-in log. Sign-in attempts (requested, confirmed, failed code, rate-limited, registration closed, sign-in address changed, account-recovery form submitted) are logged with the IP address and a coarse browser family ("Chrome on Windows"). This is the only place where we store an IP address in the clear: our abuse limiter keeps a one-way keyed hash of the address for up to 24 hours (the address itself cannot be recovered from it), and the back office keeps the administrator's own IP with administrator sessions and actions. The sign-in log is kept for 30 days and exists for security only: detecting and limiting abuse of the sign-in form and investigating security incidents.
- Devices. For each active session we store a short device label ("Chrome on Windows"), the creation time and last-seen time, so that you can review and sign out your devices. A maximum of five devices can be signed in at once.
- Email delivery records. For each message we send you, we store which message it was, when it was sent and whether it was delivered, bounced or complained. We do not store the body of the messages.
- Error reports. If something breaks, an error report is sent to our error tracking provider. Personal data is stripped from these reports: request bodies, cookies, authorisation headers and query parameters are removed before sending, and the "send default personally identifiable information" option is switched off.
3.4. Feedback: pilot testers and reviews
If you take part in the pilot, we will ask you by email to complete a short survey and, later, to write a review. We store your answers and the text of your review, linked to your account. We also store the yes/no answers you gave to the pilot conditions when you registered with your invitation — the record that the conditions were confirmed.
Any signed-in learner (not only a tester) may leave a review from the Account page; it is stored the same way, linked to the account.
Responding is a condition of the free pilot access, as set out in the Pilot Participation Agreement provided with your invitation and available at speaknatif.com/pilot: by default the survey must be completed by day 35 of your access and the review by day 66 (your invitation may set different days, and the Account page always shows the dates that apply to you), and we warn you by email three days before each deadline. If a deadline passes without a response, your free pilot access ends automatically; your account and your learning progress are not deleted and remain available if you later subscribe.
Publishing a review is a separate decision: we publish it only if you allow it in the review form — the publication box is separate from the review itself and can be left unticked — we store the exact wording of the permission you gave and when you gave it, and you can withdraw it at any time from the Account page ("Публикация отзыва" → withdraw) or by writing to us, after which the review is taken down.
3.5. Payment data — what we do not hold
We do not process payments ourselves and we never see or store your card details. Payments are handled by Lemon Squeezy, which acts as Merchant of Record — legally, the seller of the product to you is Lemon Squeezy, not us.
From a completed payment we store only: the order and subscription identifier at the provider, the plan, the amount, the currency, the dates and the receipt number. We deliberately do not store the billing name, billing address or billing country that the provider sends us.
3.6. What we never collect
- No third-party analytics, advertising or tracking scripts of any kind.
- No third-party cookies of any kind. We set two first-party cookies — one keeps you signed in, one remembers which link brought you here — and nothing else (see section 8).
- No audio or video recording of you. Pronunciation is played to you; nothing is recorded from your microphone.
- No special category data (health, religion, ethnicity, political opinion, biometrics), and we never ask for any.
- No data of children. The service is for adults only — see section 11.
4. Why we process it, and on what legal basis
| What | Why | Legal basis (UK/EU GDPR Art. 6) |
|---|---|---|
| Email address | To create your account, sign you in, and send service messages | Performance of a contract (Art. 6(1)(b)) |
| Recovery email address (optional) | To let you recover access if you lose your main address | Consent (Art. 6(1)(a)) — you choose to add it |
| Learning progress | To deliver the course: to schedule repetitions and keep progress in sync across your devices | Performance of a contract (Art. 6(1)(b)) |
| Learning events linked to your account | To understand how the course performs and improve it | Legitimate interests (Art. 6(1)(f)) — improving a product our users pay for; no external sharing, no profiling that affects you |
| Sign-in log with IP address | To detect and limit abuse of the sign-in form and to investigate security incidents | Legitimate interests (Art. 6(1)(f)) — security of the service and of your account |
| Acquisition source (which link or campaign brought you) | To see which partners and campaigns bring learners, and to pay partners fairly for real learners rather than sign-ups | Legitimate interests (Art. 6(1)(f)) — measuring our own marketing; no profiling, no external sharing |
| Email delivery records | To know whether service email reaches you and to honour bounces and complaints | Legitimate interests (Art. 6(1)(f)) |
| Payment records | To manage your subscription, handle refunds, and meet accounting and tax obligations | Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Optional service emails (tester survey and review requests and their reminders) | To ask pilot participants for the feedback their free access depends on | Performance of a contract (Art. 6(1)(b)) — Pilot Participation Agreement. You can switch these off at any time with the one-click unsubscribe in any such email; for testers this also stops the checkpoint reminders, while the deadlines, the final warning and the notice that access has ended still apply |
| Marketing emails (news about the course, offers) | To tell you what is new in the course and what we offer | Consent (Art. 6(1)(a)) — we send these only if you ticked the box asking for them, and you can withdraw at any time from your account page or any such email |
| Survey and review responses (incl. pilot-condition answers at sign-up) | To learn from the pilot and from learners generally and improve the course; a review is published only with your separate, explicit consent | Performance of a contract (Art. 6(1)(b)) — for testers, feedback is a condition of the free pilot access (Pilot Participation Agreement); a review volunteered by any learner rests on our legitimate interest in collecting feedback (Art. 6(1)(f)); publishing a review rests on separate consent (Art. 6(1)(a)) |
| Anonymous phrase statistics | To see which phrases are too hard, without reference to any person | Not personal data — see section 5 |
Service email that is necessary to operate your account — sign-in links, security notices, notice before data deletion, subscription and payment notices — is sent on the contractual basis above and cannot be switched off while your account exists.
Marketing email is different: we send it only if you asked for it. The request is a checkbox, never pre-ticked, shown on the sign-in page and in your account. We store the date you ticked it together with the exact wording you agreed to, and both appear in the data you can export. A box ticked on the sign-in page counts only when you confirm the sign-in in the same browser: the sign-in form is open to anyone, and we will not record consent on your behalf because someone else typed your address — if you confirm from another device, switch marketing on in your account instead. You can withdraw at any time — the switch in your account, or the unsubscribe link in any such email — and withdrawing is as easy as giving it. Withdrawing does not affect anything we sent before, and it never affects the service email above.
Study reminders are not emails: if you switch them on, they are notifications shown by your own browser on your own device at the time you chose. Nothing about them leaves the device, and the browser asks your permission before showing any.
5. Anonymous statistics
Once a day we roll learning events up into per-phrase statistics: how many times a phrase was shown, how it was rated, how often the hint was used. These aggregates contain no reference to any individual — no account identifier, no device, nothing that could be traced back to a person. The same is true of the click counters on partner links: we count how many times a link was followed, with no record of who followed it.
We also count visits to our public pages the same way. When a public page (the front page, the sign-in page or these legal pages) is opened, our own server adds one to a daily counter: which page, which day, the class of the referring site (for example "instagram" or "google"; for other sites, the site's hostname; or the link tag from section 3.3), and the country the request came from. That is the whole record — a set of daily totals. It uses no cookies, no scripts from anyone else, and no identifier of any kind; the IP address is used only to derive the country and to limit abuse (the limiter keeps a one-way keyed hash of it for up to 24 hours), and is not stored with the counters. The trial lesson on the front page has two counters of its own — how many times it was started and how many times it was finished — recorded with the same anonymity. Because these counters cannot single out a person, they cannot tell a returning visitor from a new one, and that is by design.
Because these aggregates are anonymous, they are kept indefinitely and are not affected by deletion of your account. This is stated plainly here because it is the one place where something survives account deletion, and we would rather say so than have it discovered.
6. How long we keep it
These retention periods are enforced automatically by a scheduled nightly job.
| Data | Retention |
|---|---|
| Sign-in requests (pending links and codes) | 24 hours |
| Sessions | 30 days after expiry |
| Rate-limiting counters (keyed by a one-way hash of the IP address, never the address itself) | 24 hours |
| Sign-in log (the only data with an IP address in the clear) | 30 days |
| Administrator sessions (with IP address) | 30 days after expiry |
| Account recovery requests | 90 days after the request is closed |
| Email delivery records | 12 months |
| Learning events linked to your account | 24 months |
| Delivery records of our payment and email providers' webhooks (no personal data) | 90 days |
| Do-not-email list: a keyed hash of an address that bounced, complained or unsubscribed — not the address itself | Indefinitely; it survives account deletion so that we never write to that address again |
| Subscription records and their history | Together with the payment records they belong to |
| Acquisition source attached to your account | For as long as your account exists |
| Anonymous per-phrase statistics | Indefinitely (anonymous — see section 5) |
| Administrator action log | At least 24 months |
| Payment records | As required by accounting and tax law (currently taken as 10 years) |
| Account with no active access (expired trial or subscription, not renewed) | 12 months, after which the account and its progress are deleted; we email you 30 days before |
| Your learning progress | For as long as your account exists |
| Survey and review responses (including the pilot-condition answers given at sign-up) | For as long as your account exists; a review you allowed us to publish is kept until you withdraw that consent |
An expired subscription does not delete your progress. Your account becomes "expired", the data lives for a further 12 months, and if you subscribe again you continue from exactly where you stopped.
7. Who we share it with
We do not sell personal data, we do not share it for advertising, and we do not disclose it to anyone except the service providers below, each of which processes it only on our instructions under a data processing agreement.
| Provider | Role | Where | Transfer safeguard |
|---|---|---|---|
| Vercel Inc. | Application hosting | USA (served from EU edge) | DPA with Standard Contractual Clauses / EU-U.S. Data Privacy Framework |
| Neon Inc. | Database | EU (Frankfurt) | DPA; data stored in the EU |
| Resend (Plus Five Five, Inc.) | Sending service email | USA | DPA with Standard Contractual Clauses |
| Lemon Squeezy LLC | Payments, Merchant of Record | USA | Own controller for billing data; DPA / Standard Contractual Clauses |
| Cloudflare, Inc. | Encrypted database backups (R2), DNS and routing of our support mailbox | EU (backups); global network for DNS and email routing | DPA with Standard Contractual Clauses |
| GitHub, Inc. | Runs the weekly backup job: the database dump is produced on a GitHub-hosted runner and encrypted there before upload (section 10) | USA | DPA with Standard Contractual Clauses |
| Functional Software, Inc. (Sentry) | Error reports (personal data stripped) | EU (Germany) | DPA; data stored in the EU |
If we later add an AI conversation mode or recorded audio narration, the AI and text-to-speech providers will be added to this table before the feature is released, and this policy will be updated.
International transfers. We are established in the United Kingdom, which the European Commission has recognised as providing an adequate level of protection. Some of our providers are established in the United States; transfers to them are covered by the safeguards named in the table above — for transfers from the UK, the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses and, where the provider is certified, the UK Extension to the EU-U.S. Data Privacy Framework; for transfers of EU residents' data, the EU Standard Contractual Clauses and the Data Privacy Framework. You may request a copy of the relevant safeguards from the contact address in section 1.
We may also disclose data where we are legally required to do so — for example, in response to a valid legal order.
8. Cookies
We set two cookies. Both are our own; neither is a third-party cookie.
- Signing in. A session cookie keeps you signed in. It is
HttpOnly,SecureandSameSite=Lax, it contains a random token and nothing about you, and it lasts up to 30 days from your last use — and never more than 180 days in total, after which you are asked to sign in again. It is strictly necessary: without it you could not stay signed in. - Which link brought you here. If you arrive through a partner's link or an advertising campaign (section 3.3), a cookie remembers the tag carried by that link — the partner code or campaign labels, the hostname of the site that referred you (if any) and the date — so that if you come back and sign up a few days later, the sign-up is still credited to the right source. It contains no identifier and nothing about you, it lasts at most 90 days, and once you sign up (or the time passes) it has done its job. If you never followed such a link, this cookie is not set at all.
- Sign-in page only. If you tick the marketing box on the sign-in page, a short-lived cookie (15 minutes, visible only to the sign-in endpoints) records that the box was ticked in this browser, so that the consent is attributed to you only when you confirm the sign-in from the same browser (section 4). It contains no identifier.
We set no analytics, advertising or third-party cookies, and no tracking scripts of any kind. The anonymous visit counters described in section 5 work without any cookie or identifier at all — your browser only remembers, for the duration of the tab session, that the visit has already been counted, so that reloading a page is not counted twice.
Your browser also stores your learning progress locally so that lessons work offline, and — if you install the app — a cached copy of the app's pages for offline use. That is local storage on your own device, not a cookie, and the progress is cleared when you sign out. Study reminders, if you switch them on, use your browser's notification permission and are shown by your own device (section 4).
9. Your rights
Under the UK GDPR and the EU GDPR you have the right to:
- access your personal data and receive a copy of it;
- portability — receive it in a structured, machine-readable format;
- rectification of inaccurate data;
- erasure of your data;
- restriction of processing, and to object to processing based on legitimate interests;
- withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of what was done before;
- complain to a supervisory authority.
How to exercise them. Two of these are built into the product and do not require you to write to anyone:
- Export — Account → Export my data. You receive a machine-readable file containing your email address, your student number, settings, every progress card, your favourites, your learning events, your access history, how you found us (your acquisition source, if any), your payment records, your active devices, the record of emails sent to you, any survey answers or review you submitted and, for pilot testers, the invitation record with the answers you gave at sign-up.
- Deletion — Account → Delete my account. Your email address and recovery address are irreversibly erased; your progress, cards, favourites and events are deleted; all your devices are signed out and the session records are removed within 30 days. If a subscription is still running, you are asked to cancel it first (Account → "Управление подпиской"), so that nothing keeps being charged for an account that no longer exists.
Both require a fresh confirmation of your identity: you will be asked to confirm by email even if you are already signed in, so that a laptop left open cannot be used to export or destroy your data.
For anything else, or if the in-product route does not work for you, write to info@speaknatif.com. We respond within one month.
What survives deletion, and why. After deletion a stub of your account row remains, containing no personal data — no email address, no student number, no time zone, no consent records, nothing identifying — and marked as deleted. It exists because payment records, which we must keep for accounting purposes, and the administrator action log, which must remain provable, refer to it. Your email address cannot be recovered from it. Three further things remain for a limited time or by design: sign-in log entries linked to the account (with IP address) are kept for their normal 30-day period and then deleted; if your address had bounced, complained or unsubscribed, a keyed hash of it stays on our do-not-email list so that we never write to it again (the address itself cannot be recovered from the hash); and anonymous per-phrase statistics (section 5) are unaffected because they never referred to you in the first place.
Backups. Deletion is applied immediately to the live database. Once a week a backup job running on GitHub's infrastructure produces a database dump, encrypts it there with a public key and uploads it to storage in the EU; the private key is held offline, never together with the backups. Encrypted backup copies are kept for up to three months and then destroyed, so a deleted account can persist inside a backup for at most that long. Backups exist only to restore the service after a failure; a deleted account is not restored from them. The sign-in log, pending sign-in requests, sessions and rate-limit counters are excluded from these backup copies entirely.
One more thing survives deletion, by your own choice: a review you allowed us to publish (section 3.4) remains published, under the signature you chose, until you withdraw that permission. Deleting your account does not by itself withdraw it — withdraw it on the Account page before deleting, or write to us and we will take the review down.
Complaints. If you believe we have handled your data incorrectly, please tell us first — we would rather fix it. You also have the right to complain to the UK Information Commissioner's Office (ICO, ico.org.uk) or, if you are in the EU, to the supervisory authority of the country where you live or work.
10. Security
The measures we actually take, rather than a general assurance:
- Email addresses are encrypted at rest and searchable only through a keyed hash; the keys are held outside the database.
- There are no passwords to steal: sign-in is by emailed link or six-digit code, valid for 15 minutes, with a limited number of attempts and rate limiting.
- The database is reached through two separate roles; the application's role cannot alter the database structure.
- The administrative back office is reachable only with a hardware-backed passkey. It has no password, which is what makes it resistant to phishing. Every administrative action is written to an append-only audit log.
- Access to a learner's email address by an administrator is shown masked by default; revealing it is time-limited and is itself recorded in the audit log.
- Logs are passed through a strict allow-list of fields: email addresses, tokens and message contents cannot reach them. Error reports are passed through the same mask before they leave the browser or the server.
- Rate-limit counters are keyed by a one-way keyed hash of the IP address, never by the address itself.
- Backups are encrypted with a public key before they are uploaded to storage in the EU, and the private key is never held together with the backups.
- Traffic is served over TLS with a strict Content Security Policy.
No system is perfectly secure, and we do not claim otherwise. We do have a written procedure for handling a personal data breach, including notifying the supervisory authority within 72 hours where the breach is notifiable and notifying affected learners directly where the risk to them is high.
11. Age
SpeakNatif is for adults. You must be 18 or over to create an account. We do not knowingly collect data from children. If we learn that an account belongs to someone under 18 we will delete it. If you believe a child has created an account, write to info@speaknatif.com.
12. Automated decision-making
The order in which phrases are shown to you is calculated automatically from your own ratings — that is what a spaced-repetition course is. This produces no legal effect and no similarly significant effect on you within the meaning of Article 22. We carry out no profiling for advertising, credit, pricing or any other purpose.
13. Changes to this policy
If we change this policy we will update the date at the top. If a change materially affects your rights or how we use your data, we will tell you by email before it takes effect.
14. Contact
Jevgenija Sidlovska trading as SpeakNatif 3 Brownlee Place, NN4 6GA, Northampton, UK info@speaknatif.com