Privacy Policy
What we collect
1. Account data
- Email address (required for registration)
- Google account info if signing in via Google OAuth
- Created at timestamp
2. Audio files
- Uploaded for analysis only
- Stored temporarily in Supabase Storage (EU Frankfurt)
- Deleted immediately after analysis completes
- Never used for training, never shared
3. Analysis data
- Results of each analysis (score, issues, timestamps)
- Stored in Supabase linked to your account
- Retained while account is active
4. Usage data
- Credit balance and transaction history
- Analysis count and file durations (for billing)
5. Payment data
- Handled entirely by lava.top
- We never receive or store card details
- lava.top privacy policy applies to payment processing
How we use data
- To provide the analysis service
- To manage your account and credit balance
- To send transactional emails (analysis results, credit confirmations)
- We do not sell data to third parties
- We do not use data for advertising
Sub-processors (third parties who process data)
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Database and file storage | EU Frankfurt (AWS eu-central-1) |
| Google Gemini API | Audio pronunciation analysis | Google Cloud |
| lava.top | Payment processing | Russia / International |
| Vercel | Hosting and CDN | Global |
| Google OAuth | Optional authentication | Google infrastructure |
Note on Gemini API: audio files are sent to Google Gemini API for analysis. Google does not retain audio data after processing under their API terms.
Legal basis for processing (GDPR Article 6)
- Contract performance: account data and analysis results are necessary to provide the service
- Legitimate interests: usage analytics for service improvement
Data retention
- Audio files: deleted immediately after analysis (within minutes)
- Analysis results: retained while account is active, deleted on account deletion
- Account data: retained while account is active, deleted on account deletion
- Payment records: retained as required by applicable law (typically 7 years)
Your rights (GDPR)
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and all associated data
- Export your data
- Withdraw consent at any time
To exercise any right: email hello@audiolint.com
Data security
- All data encrypted in transit (HTTPS/TLS)
- Supabase Row Level Security (RLS) — users can only access their own data
- Audio files stored with time-limited signed URLs
- No permanent audio storage
Cookies
We use only essential cookies required for authentication (Supabase session). No advertising or tracking cookies.
Contact
Data controller: Audiolint
Email: hello@audiolint.com
Last updated: April 2026