Privacy Policy
nawana is a language-learning app that clones your voice — once, with your explicit consent — so you can practice speaking with a fluent version of yourself. Your voice is the most personal data there is, and this policy explains exactly what we do and don't do with it.
The short version
- You must be 16 or older. Building a voice model means processing biometric data, so you confirm your age before recording — we keep the confirmation, never a birth date.
- One 60-second recording at setup. The app never records you outside a conversation or exercise you started yourself.
- Your learning data stays on your iPhone. Sessions, transcripts, drill cards, vocabulary, and progress are stored on your device, not on our servers.
- No ads, no cross-app tracking. We don't sell or share your data for advertising. The app measures its own usage (which screens people reach, whether a talk finished) through PostHog — see below — and nothing else.
- Delete anytime. Re-recording your voice permanently deletes the old clone. Deleting your account removes your voice clone and account data.
What we collect and why
| Data | Why | Where it lives |
|---|---|---|
| Apple ID sign-in (user identifier, email) | Your account, subscription entitlement, invite credits | Our backend (Supabase) |
| 60-second voice recording | Creating your personal voice clone | Processed by ElevenLabs; the app keeps only a reference to your voice |
| Speech during conversations and shadowing | Transcription, fluent rewrites, and pronunciation scoring — the core features | Recognised on-device first; the recording of that turn is also sent for a more accurate transcription, processed per request and not retained. The resulting text stays on your iPhone |
| Subscription and credit balance | Powering conversations, voice generation, and shadowing | Apple (purchase) + our backend (balance) |
| Product usage events (e.g. "a talk ended", "a scene played") | Understanding which parts of the app work, and fixing the parts that don't | PostHog, on EU servers, keyed to a random account identifier |
The usage events carry no advertising identifier, no screen recording, and no automatic screen tracking — only events we wrote by hand, tagged with the random UUID of your account. They never contain what you said or what your fluent self replied.
What other learners can see
Find people lets you practise with someone you haven't met. So that others can find you the same way, four fields from your profile are listed for learners studying your language: your display name, occupation, location, and interests. Nothing else.
- Your intro paragraph is never shown to another person. It reaches only the model that plays your character, so details you wrote there — who you live with, your situation — stay unread by other users.
- Talking with "you" does not reach you. The other learner is talking to an AI portrayal. You get no notification, and no record of it is kept or shared.
- Your voice is never used. A persona always speaks in a preset voice, never in your clone.
- Turn it off or edit it in Settings → Find people. Taking your listing down removes it for everyone, and after an edit we never publish over your changes again.
Your voice is biometric data
A model built from a recording of your voice can identify you, so we treat it as what the law calls it: special-category biometric data under GDPR Art. 9, a "voiceprint" under the Illinois Biometric Information Privacy Act, and sensitive information under Korea's PIPA. Every one of those regimes requires a consent that is separate from the general terms, informed, and recorded — so it is its own screen with its own toggle, shown before the microphone is ever requested, and the date you gave it is stored and shown back to you in Settings → Privacy.
- Voice cloning happens only after you deliberately record the 60-second setup sample. There is no passive listening.
- Your clone reproduces only your own voice. nawana cannot be used to clone anyone else.
- The model is used for exactly one purpose: speaking your practice lines back in your own voice. It is never sold, shared, or used to train any model.
- Re-record anytime — creating a new clone permanently deletes the previous one.
- Withdraw your consent at any time in the app (Settings → Privacy → Withdraw consent & delete my voice). Withdrawal deletes the model here and at ElevenLabs. You can also delete your entire account.
Who processes data on our behalf
The app never talks to AI providers directly — every request routes through our own backend, so no provider API keys ever live on your phone.
- Supabase — authentication, subscriptions, and secure relay of AI requests.
- ElevenLabs — voice cloning and speech synthesis of your fluent lines.
- Google (Gemini) — conversation replies, fluent rewrites, session analysis, and transcribing what you just said. The recording of a single spoken turn is sent for that transcription and is not retained after the request; nothing is used to train Google's models.
- Apple — Sign in with Apple, subscriptions, and on-device speech recognition.
- PostHog — product usage events, hosted in the EU. No advertising identifiers, no session replay, no automatic screen tracking.
These processors act under contract for us and may not use your data for their own purposes.
What we don't do
- No advertising, no data sales, no cross-app tracking. Nothing is shared with data brokers, and the app never asks for tracking permission because it does not track you across other companies' apps or sites.
- No session replay, no screen recording, no advertising identifier.
- No recording outside an activity you started.
- No use of your voice or conversations to train our own or third-party AI models.
Retention and deletion
- Learning data (sessions, drills, progress) lives on your device and disappears when you delete the app.
- Your voice clone exists until you replace it, delete it, or delete your account. We do not keep it on any other schedule and we do not archive superseded clones.
- The record of your consent — the date you gave it, and the fact that you confirmed your age — is kept while your account exists, because we are required to be able to show that consent was given. It is deleted with your account.
- Account deletion (in the app: Me → Account → Delete account) removes your voice clone, account record, and credit balance. Purchase records are retained by Apple per their policy.
Your rights (GDPR)
Dear RoRo (Munich, Germany) is the data controller. You have the right to access, correct, export, restrict, or delete your personal data, and to lodge a complaint with a supervisory authority. Voice data is processed on the basis of your explicit consent (Art. 9(2)(a)), which you can withdraw at any time — in the app under Settings → Privacy, or by deleting your account. Withdrawal is as easy as consent was, and does not affect processing that already happened.
Age
nawana is for people aged 16 and over. Before your voice is recorded, setup asks you to confirm you are 16 or older, on the same screen that explains what happens to your voice. We store that confirmation and nothing else — we never ask for or keep your date of birth, because the only fact the app needs is "old enough". We do not knowingly collect data from anyone below that age; if you believe we have, write to us and we will delete it.
Sixteen is not an arbitrary number. It is the age of digital consent under GDPR Art. 8 in Germany, where we are established; and ElevenLabs, which builds the voice model, does not permit its service to be made available to anyone under 13, or to 13–17-year-olds without a parent or guardian's consent, which we have no way to verify.
Changes and contact
If this policy changes materially, we'll note it in the app or on this page. Questions or requests: hello.dearroroapp@gmail.com