Last updated: 13 July 2026
Colloquial ("we," "us," "Colloquial") is a language-learning app built and operated by ELLIS, Felix Adrian Raymond, an individual based in Hong Kong ("the developer"). Colloquial is not currently operated by an incorporated company. This policy explains what data the app collects, why, and what control you have over it.
If anything here is unclear, email [email protected] — a real person reads it.
Colloquial exists to help you practise a language by voice. To do that, it stores the audio flashcards you record, remembers when you've practised, and rings your phone at times you've scheduled. It does not show ads, does not have an ad network or advertising ID in it anywhere, does not sell your data to anyone, and never uses your voice recordings to train any AI model — yours or anyone else's. Your audio is played back to you and nobody else.
Account information. Your email address, collected when you sign up. Authentication (including OAuth sign-in and password handling) is managed by our authentication provider, Supabase — we never see or store your password directly.
Your audio recordings. The question and answer audio you record for each flashcard. This is the most sensitive data this app handles, so to be explicit: this audio is used for exactly one purpose — playing it back to you during your own practice sessions. It is never transcribed for training purposes, never listened to as a matter of course, never shared with any third party, and never used to improve any product, ours or anyone else's.
Flashcard text (optional). Short text labels you optionally attach to a card, in addition to its audio.
Review and scheduling history. Which cards you've rated "got it" or "needs work," when, and your resulting spaced-repetition schedule. Used only to decide which cards are due for your next practice session — this data isn't shared or compared across users.
Scheduled session data. When you've asked to be called for practice, your timezone, and the outcome of each call (answered, declined, completed) — needed to actually ring your phone at the right time and to show you your own practice history.
Device and push tokens. A token identifying your device, used solely to trigger the incoming-call notification (via Apple's VoIP push service or Firebase Cloud Messaging) at your scheduled time. This is not used for tracking, advertising, or any purpose beyond delivering that one notification.
Product usage analytics. We use PostHog (hosted on PostHog's EU infrastructure) to understand how the app is used in aggregate — e.g., whether a practice call was answered, whether a session was completed. These events do not include your audio or flashcard content, and are tied to your account only to help us fix problems and understand real usage, not to build an advertising profile.
Crash and error reports. We use Sentry to catch and fix bugs and crashes, on both the app and our backend. Error reports may include technical details about what the app was doing when something went wrong; we do not log audio content, full push tokens, or raw audio URLs in these reports.
Transactional email. If you request a data export (see "Your rights," below), we send you one email, via our provider Resend, containing a link to download it. We do not send marketing email and do not maintain a mailing list from your account email.
We use a small number of infrastructure providers to run the app — none of them are advertising or data-broker companies, and none of them are permitted to use your data for their own purposes:
| Provider | What they handle |
|---|---|
| Supabase | Account authentication and our primary database |
| Cloudflare (R2) | Storage for your audio recordings |
| Fly.io | Hosts our backend application (Amsterdam, EU region) |
| PostHog | Product usage analytics (EU-hosted instance) |
| Sentry | Error and crash monitoring |
| Resend | Delivery of the one transactional email described above (EU-region sending) |
We do not sell personal data to anyone, for any reason. We do not work with advertising networks, data brokers, or analytics-for-advertising services. There is no advertising identifier, ad SDK, or third-party tracking pixel anywhere in this app.
Some of these providers process data in the United States as well as the EU. Where that happens, the transfer is covered by the provider's own certification under the EU-US Data Privacy Framework, Standard Contractual Clauses, or both.
Your account data, audio, and review history are kept for as long as your account exists. If you delete a specific card or deck, its audio is permanently removed from our storage, not just hidden — usually within a short cleanup window, not instantly, but it is genuinely deleted, not retained indefinitely with a "deleted" flag. If you delete your account entirely (see below), everything is removed.
Wherever you're located, you have meaningful control over your data, not just a legal entitlement on paper:
If you use hands-free call rating, the app uses your device's own built-in speech recognition to detect what you said — this recognition happens entirely on your device. Nothing is sent to any server for this feature, and we never receive a transcript or recording from it.
Colloquial is not directed at children. During sign-up, you're asked to confirm you're 13 or older; we don't collect a date of birth or otherwise independently verify age. If we become aware that someone under 13 has provided us personal information, we will delete it. Parents who believe their child has done so can contact us at [email protected].
We use industry-standard measures to protect your data: audio files are never exposed via a permanent public URL — every playback link is a time-limited, cryptographically signed link generated on request. Data in transit is encrypted. Access to raw infrastructure (databases, storage) is restricted to the developer. No system is perfectly secure, and we can't guarantee absolute security, but we treat your recordings the way we'd want our own treated.
If we make a material change to how we handle your data, we'll update the date at the top of this page and, for significant changes, notify you in the app.
Questions, data requests, or concerns about this policy: [email protected].
This policy is governed by the laws of Hong Kong SAR. If you live in the EU, EEA, or UK, nothing in this policy limits the rights you're entitled to under the GDPR or UK GDPR, and if you live somewhere else whose law gives you data-protection rights that can't be signed away by agreement, those rights apply too, regardless of this governing-law clause.