Privacy Policy
Effective: October 4, 2026
Data handled by English Now
English Now stores settings, AI-processing consent, practice history, and estimated scores in local SQLite storage. A cryptographically random app user ID and a 256-bit install secret are stored in the iOS Keychain. Apple and RevenueCat process purchase and entitlement records. RevenueCat returns the subscription ID used for the server voice-time meter. The meter stores the plan and verified subscription dates to reset the 300-minute monthly allowance: on the original purchase date's monthly anniversary for annual access, and each billing period for monthly access. Included minutes do not roll over; purchased add-on minutes remain until used.
When a learner submits a voice answer, English Now sends the audio, practice prompt, anonymous app user ID, and a signed session token over encrypted HTTPS to a Cloudflare Worker. The Worker verifies the paid RevenueCat entitlement, applies per-IP and per-account rate limits, and meters voice time. It sends the audio and prompt to OpenAI for transcription, evaluation, and speech generation.
The Worker keeps completed feedback, its transcript, and generated coach speech for up to 15 minutes so a connection failure can recover the same result without another charge. It does not retain uploaded learner audio after processing. Result content is removed by a scheduled storage alarm; a content-free turn fingerprint remains to prevent duplicate charges. The Worker also stores the voice-time balance, entitlement cache, hashed install binding, rate-limit counters, and purchase-event records. Purchased add-on time belongs to the verified original RevenueCat customer so it can survive restore, plan changes, and resubscription. The app saves recordings, recognized and edited transcripts, task context, corrections, and model answers locally on the device. Conversation requests include up to six prior user/coach messages.
Analytics is off unless a PostHog key is configured. When enabled, PostHog receives named product events, the anonymous app user ID, acquisition source/campaign, turn IDs, and technical metadata. Content-free Worker diagnostics record audio seconds, tokens, retries, generated-audio size, latency, and refunds. English Now does not put audio, transcripts, exam dates, or answer text in analytics events. Cloudflare, OpenAI, RevenueCat, Apple, and PostHog can process network and device metadata needed to provide and protect their services.
OpenAI retention
OpenAI processes voice and text as our AI provider. API data is not used for training by default; abuse-monitoring logs may be retained for up to 30 days. See https://developers.openai.com/api/docs/guides/your-data.
Purpose and retention
English Now uses this data to provide speaking feedback, confirm paid access, meter voice time, keep local progress, prevent misuse, deliver add-on purchases once, reverse refunds, and diagnose failures. Local learning data remains until the learner deletes it or removes the app. Server meter, purchase-event, security, and entitlement-cache records remain only as needed to operate paid access, prevent fraud, and meet accounting duties.
Choices and transfers
The learner can use the prerecorded sample without voice consent. Live voice feedback requires consent before the first upload. The learner can delete local history, settings, consent, drafts, recordings, identity keys, and caches in Settings. Deletion restarts onboarding and does not cancel the Apple subscription, which can be restored. Purchases are managed through Apple. Processing can occur in Japan, the United States, and other countries where the listed providers operate.
Providers
English Now uses Apple for purchases, RevenueCat for entitlements and purchase events, Cloudflare for the Worker and abuse controls, OpenAI for AI voice processing, and optional PostHog analytics.
Controller and contact
Questions? See Support.