Skip to content
Reallang

Legal

Privacy

What is collected when you speak here, why, who else processes it, how long it is kept and what you can require of us.

Last updated September 21, 2026.

Who is responsible

This notice is given under articles 13 and 14 of Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and Ley Orgánica 3/2018 (LOPDGDD). The controller of the personal data described in it is Amiscon Global S.L., NIF B70862099, Valencia, Spain. Contact: [email protected].

For the personal data of students taking part through a teacher's or a school's room, that teacher or school is the controller and we act as processor on their documented instructions. For the account holder's own data — their account, their billing, our security — we remain controller in our own right.

No data protection officer has been appointed, as none is required under article 37 GDPR or article 34 LOPDGDD: there is no large-scale systematic monitoring and no large-scale processing of special categories of data. Requests and questions about data protection are handled at the address above.

Your voice

Audio passes directly between your device and the provider of the speech models and back. It is not written to disk, it is not retained after the session, and no setting within the service alters this.

What is retained is the transcript: the text of what was said, with turn numbers and timings. The score and the quotations supporting it are attached to that transcript. It is what is shown to you, what you can export and what you can delete.

Voice is not used to identify or authenticate anyone. No voiceprint or other biometric template is created, so no biometric data within the meaning of article 4(14) GDPR is produced and no special category of data under article 9(1) is processed.

What is collected

Account data: an email address, or an anonymous device identifier if you have not registered; the language of the interface, the language of your feedback, and a balance of minutes.

Session data: the character and scenario chosen, the version of the criteria applied, the start and end times recorded by the server, the transcript, the score, and the internal cost of running the session.

Payment data: handled by the payment service provider. Card numbers do not reach our servers; we retain the fact, the amount and the date of a transaction.

Technical data: the records needed to operate the service securely — request logs, rate limits and error reports.

Cookies and similar technologies, in three groups: those strictly necessary to keep you signed in and to carry your settings between pages, which cannot be switched off; those used to measure how the site is performing; and those used for advertising. The second and third groups are described in the next section and are set only with your consent.

Personal data is not sold. Beyond the measurement and advertising described in the next section, it is not disclosed for advertising or for profiling by anyone else. If the business or a part of it is transferred, data may pass to the acquirer for the purposes set out here and on the same terms; you would be informed before that takes effect.

Measurement and advertising

Tags on this site are delivered through Google Tag Manager, which is a container and does not itself collect anything. Two tags run inside it.

Google Analytics 4 measures how the site is used: pages viewed, approximate location derived from a truncated IP address, the type of device and browser, and how you arrived. It is provided by Google Ireland Limited, which acts as our processor, with Google LLC in the United States as a sub-processor.

The Meta pixel measures what happens after an advertisement and builds audiences for further advertising. It is provided by Meta Platforms Ireland Limited. For the collection of your data on this site and its transmission to Meta, we and Meta are joint controllers within the meaning of article 26 GDPR, under Meta's controller addendum; everything Meta does with the data afterwards, Meta does as controller in its own right and under its own policy. You may exercise your rights against either of us, and against Meta directly.

Both involve a transfer of personal data to the United States. Both transfers rest on the European Commission's adequacy decision of 10 July 2023 for the EU–US Data Privacy Framework, to which Google LLC and Meta Platforms, Inc. are both certified.

Neither tag loads and no cookie in these two groups is set before you have consented, as article 6(1)(a) GDPR and article 22.2 of Ley 34/2002 require. Consent is asked for on your first visit and may be given for one group and refused for the other.

Consent may be withdrawn at any time through the preferences link in the footer, as easily as it was given. Withdrawal takes effect immediately and changes nothing about your use of the service: no feature is withheld and no session behaves differently.

Nothing said inside a session — no audio, no transcript, no score — is sent to either of them. These tags see pages and clicks on the public site, and nothing from the product itself.

Neither tag is loaded at all on a teacher's room, on a school's pages, or anywhere inside a session or its result. Not blocked there, not denied by default there — not present. That is also why no cookie banner appears on those pages: there is nothing on them to consent to.

Purposes and legal bases

Providing the service you bought — running a session, producing and explaining a score, keeping your balance and your history — is performance of the contract between us (article 6(1)(b)).

Issuing invoices and retaining accounting records is compliance with a legal obligation (article 6(1)(c)).

Keeping the service secure and available — rate limiting, preventing abuse, investigating failures — rests on our legitimate interest in operating it, which we have weighed against your interests and which does not extend to the content of your conversations (article 6(1)(f)).

Measurement and advertising rest on your consent (article 6(1)(a) and article 22.2 of Ley 34/2002), which you may withdraw at any time without affecting the lawfulness of processing carried out before withdrawal, and without any effect on your use of the service. How long the data they collect is kept is governed by Google's and Meta's own retention periods.

As required by article 13(2)(e) GDPR: an email address is a contractual requirement for holding an account and for recovering access to it, and without it the service cannot be provided to a registered user. The remaining data arises from use of the service and is not separately requested.

Automated scoring

Scores and feedback are produced by automated processing of your transcript against criteria published in advance. The logic is the published criteria and the version of them applied to your session, and every statement in a score is linked to the sentence of yours it was drawn from.

That processing is disclosed under articles 13(2)(f) and 15(1)(h) GDPR. A score produces no legal effect concerning you and does not similarly significantly affect you: it is not a qualification, it is not disclosed to any employer, institution or authority, and no decision about you is taken on the basis of it. Article 22(1) GDPR is therefore not engaged.

You may nonetheless ask for a score to be reviewed by a person, and for an explanation of how it was reached, by writing to [email protected].

Who else processes it

Categories of recipient are given here rather than names, as article 13(1)(e) GDPR permits. A provider of speech models established in the United States processes the audio and the transcript of a conversation in order to conduct it and to score it, as a processor under article 28 GDPR, acting on our documented instructions under a contract which prohibits use of that material to train models.

That involves a transfer of personal data to a third country under chapter V GDPR. The transfer is made on the basis of the standard contractual clauses adopted by the European Commission (article 46(2)(c) GDPR), together with supplementary technical and contractual measures. As article 13(1)(f) requires, a copy of those safeguards may be obtained by writing to [email protected]; the identity of that provider and of every other processor is supplied on the same request.

Payment service providers process what is necessary to take and to reconcile a payment, as controllers in their own right for that purpose.

A hosting provider within the European Union holds the database and the application servers. A transactional email provider sends messages such as password resets.

Google and Meta receive data from the public pages of this site where you have consented to measurement or to advertising. They are named, and the terms on which they receive it are set out, in the section on measurement and advertising above.

Personal data may also be disclosed where we are required to do so by law or by a competent authority.

How long it is kept

Retention periods are given under article 13(2)(a) GDPR and follow the storage limitation principle in article 5(1)(e). Account data, transcripts and scores are kept while the account remains open, and are deleted when the account is closed.

Accounting records relating to payments already made are kept for 6 years, as required by article 30 of the Código de Comercio and by tax legislation, with identifying data removed.

Technical logs are kept for as long as is necessary to secure and to operate the service, and for no longer than twelve months.

Where a claim, a complaint or a legal obligation requires it, the data concerned is kept, blocked from ordinary use, until the matter is closed.

Your rights

Access (article 15 GDPR): a copy of everything held about you can be exported as a file from your account page, or requested in writing.

Rectification of inaccurate data (article 16), erasure (article 17), restriction of processing (article 18), and portability of the data you provided, in a machine-readable format (article 20).

Objection (article 21) to processing carried out on the basis of our legitimate interest, and withdrawal of consent at any time (article 7(3)), which does not affect the lawfulness of processing carried out before the withdrawal.

A right is exercised by writing to [email protected]. In accordance with article 12(3) GDPR we reply without undue delay and in any event within one month of receipt, extendable by two further months where a request is complex or numerous; where it is extended you are told within the first month and given the reason. Our own target is to reply within 24 hours and to complete within 2 working days. Exercising a right is free of charge (article 12(5)).

You have the right to lodge a complaint with a supervisory authority (article 77 GDPR): the Agencia Española de Protección de Datos, C/ Jorge Juan 6, 28001 Madrid, aepd.es, or the authority of the Member State of your residence, of your place of work, or of the place where you believe the infringement occurred.

Security

Technical and organisational measures appropriate to the risk are applied, as article 32 GDPR requires. Data is encrypted in transit and at rest, access to production systems is restricted to those who need it, and the instructions behind a character are never sent to a browser.

A personal data breach likely to result in a risk to your rights is notified to the supervisory authority within seventy-two hours (article 33 GDPR) and, where the risk is high, communicated to you without undue delay (article 34).

Minors

An account is for people aged 18 or over, which is the age of capacity to enter into the contract rather than the age of consent to processing under article 8 GDPR and article 7 LOPDGDD.

A person aged 13 or over may take part without an account, through a room set up by their teacher or school. The school is then the controller and we are its processor, and the lawful basis is the school's own — its contract with the family, or the task it performs. It is deliberately not the child's consent: the age at which a child can consent under article 8 GDPR differs by member state, fourteen in Spain and sixteen in Germany among them, so a product resting on it would have to know both a student's age and their country. Those are exactly the two things this design refuses to collect.

Nothing asks a student their age and nothing stores one. An age gate would collect a new piece of personal data about a child in order to protect them, and would hand us knowledge we are better off not having. The school knows who is in its class.

In such a room no score is produced, nothing is inferred about the student, and no measurement or advertising tag runs on any page they open.

If it comes to our knowledge that an account has been opened by a person below 18, the account is closed and the personal data attached to it is deleted. A parent or guardian with a question about a child's use of the service may write to [email protected], and we answer — and where the room belongs to a school, we say which school holds the record.

Changes to this notice

This notice may be updated. The date above changes with it, and a change that affects how your personal data is processed is notified in the product or by email before it takes effect.