Privacy Policy
Last updated: 26 July 2026
1. Who we are and how to contact us
Reffitt Tech Ltd (“Fluir”, “we”, “us”, “our”), a company registered in England and Wales under company number 14506447, registered office Unit 13, Freeland Park, Wareham Road, Poole, United Kingdom, BH16 6FA, is the data controller for the personal data described in this policy.
For any privacy question, or to exercise your rights, contact us at privacy@getfluir.app.
This policy should be read alongside our Terms of Service.
2. Scope
This policy covers personal data we process when you use the Fluir website and progressive web app (the “Service”). We process personal data in line with the UK GDPR and the Data Protection Act 2018, and, where applicable, the EU GDPR.
3. The personal data we collect
You give us:
- Account data — your email address and password (passwords are stored only as a secure hash by our authentication provider), or, if you use Google sign-in, the basic profile information Google returns (email, name, account identifier).
- Profile and settings — your time zone and your notification preferences.
- Learning input — the Spanish words you save while reading, and the text and speech you produce in AI conversations.
We generate as you use the Service:
- Vocabulary graph and learning history — your saved vocabulary and its state (encountered / known / active), reading sessions, and Refresh review history.
- Conversation transcripts — for each AI conversation turn we store the speaker, the text, whether the turn was spoken or typed, and the speech-recognition confidence. Spoken turns are transcribed from your audio.
- Usage metering — daily activity and conversation-airtime counters used to apply your allowance and free-trial limits.
- Subscription data — your subscription status and the platform you bill through (web, iOS, or Android), and identifiers that let us resolve your subscription for support. We do not store your full payment-card details — payments are handled by our payment processors (see section 5).
- Push registration tokens — if you enable notifications, the device token used to send them.
- Technical and analytics data — standard technical data (such as device/browser type and, transiently, IP address for security and delivery) and a curated set of product-analytics events (see section 7).
We do not intentionally collect special-category data. Please don’t include sensitive personal information in conversations or saved notes.
4. Why we use your data, and our legal bases
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and secure your account; authenticate you | Account data | Performance of a contract |
| Provide the Reader, Refresh, and AI conversation features | Learning input, vocabulary graph, transcripts, usage metering | Performance of a contract |
| Convert speech to text and generate spoken/written tutor responses and corrections | Conversation audio and text | Performance of a contract |
| Take payment, run the free trial, and manage your subscription | Subscription data | Performance of a contract |
| Send service and lifecycle emails (e.g. trial-ending, payment issues) | Account data, subscription status | Performance of a contract / legitimate interests |
| Send opt-in retention push notifications | Push token, learning activity | Consent |
| Understand and improve the product (aggregate funnel and retention analytics) | Non-identifying event data | Consent, and/or legitimate interests |
| Keep the Service secure and prevent abuse | Technical data | Legitimate interests |
| Meet legal, tax, and accounting obligations | Subscription and transaction records | Legal obligation |
Where we rely on legitimate interests, we have balanced those interests against your rights. Where we rely on consent, you can withdraw it at any time (see section 9) without affecting processing already carried out.
5. Payments
Payments and subscriptions are processed by RevenueCat and its underlying payment providers: Stripe (via RevenueCat Web Billing on the web), and the Apple App Store or Google Play on mobile. These providers process your payment details as controllers or processors under their own terms, and we receive only the subscription status and limited identifiers we need to give you access and support. We never see or store your full card number.
6. AI, speech, and how learning content is processed
The Service uses AI and speech technology delivered through third-party processors on our behalf:
- Large language models are accessed through OpenRouter (a gateway over model providers) to generate reading content, conversation replies, and corrections.
- Speech-to-text is provided by Deepgram to transcribe your spoken turns.
- Text-to-speech is provided by ElevenLabs to voice the AI tutor.
Your conversation input is sent to these providers only to deliver the feature. We do not use these providers’ zero-data-retention options, so each retains your input for a period under its own standard terms, as summarised below. We keep this content to the minimum needed to run the Service and we do not sell it.
- OpenRouter / the AI model provider. We access AI models through OpenRouter, which by default keeps only operational metadata (model, token counts, timing) and does not store your prompt or completion content. Our default models are provided by Anthropic, which processes API content on a no-training basis and automatically deletes inputs and outputs within about 30 days. Where content is flagged for a policy violation, Anthropic may retain it for up to 2 years(and related trust-and-safety scores for up to 7 years). If we route to a different model provider, that provider’s own retention and, in some cases, model-improvement terms apply.
- Deepgram (speech-to-text).Because we do not opt out of Deepgram’s Model Improvement Partnership Program, Deepgram may retain your audio and use it to improve its speech-recognition models. Under our agreement with Deepgram, this audio is retained for no longer than 12 months, after which it is deleted.
- ElevenLabs (text-to-speech). ElevenLabs may retain your input and use it to develop and improve its models under its standard terms. It does not keep voice data longer than 3 years after your last interaction, except where the law requires otherwise.
Each provider processes this data as our processor or as an independent controller under its own privacy terms. If you would prefer not to have your speech and conversation content processed on these terms, please limit what you share in conversations, or contact us at privacy@getfluir.app.
7. Analytics
We use PostHog (EU Cloud) to understand how the product is used — chiefly our sign-up funnel and retention. To protect your privacy:
- analytics are ingested through a same-origin reverse proxy;
- we send a curated set of custom events only (autocapture is off);
- event properties contain no personal or learning content — no email, no saved Spanish words, no article or transcript text, and no notification tokens; counts and category values only;
- session replay is off; and
- we honour your cookie/consent choice and Do-Not-Track.
If you exercise your right to erasure, we also issue a deletion request to PostHog so your analytics profile is removed.
8. Sharing your data and international transfers
We share personal data only with service providers (“processors”) who process it on our instructions to run the Service, including:
- Supabase — database and authentication;
- Vercel — web application hosting; Railway — our scheduled batch processing;
- OpenRouter, Deepgram, ElevenLabs — AI, speech-to-text, and text-to-speech;
- RevenueCat / Stripe / Apple / Google — payments and subscription management;
- Resend — transactional and lifecycle email;
- Firebase Cloud Messaging (Google) — push notifications;
- PostHog (EU Cloud) — product analytics.
We may also disclose data if required by law, to enforce our Terms, or in connection with a business sale or reorganisation.
Some processors are located outside the UK/EEA (for example, in the United States). Where data is transferred internationally, we rely on appropriate safeguards such as the UK International Data Transfer Agreement / Addendum or the EU Standard Contractual Clauses, plus any additional measures needed. We deliberately keep product analytics in the EU via PostHog EU Cloud. Details of the safeguards used are available on request.
9. Your rights
Subject to conditions and exemptions in the law, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased(“right to be forgotten”);
- restrict or object to certain processing (including profiling for notifications);
- data portability — receive your data in a portable format;
- withdraw consent at any time where we rely on it (e.g. turn off push notifications, or decline analytics cookies); and
- not be subject to solely automated decisionswith legal or similarly significant effects — the Service’s AI features generate learning content and feedback but do not make such decisions about you.
To exercise any right, contact privacy@getfluir.app. We will respond within the statutory time (normally one month). You can also complain to the Information Commissioner’s Office (ICO) at ico.org.uk, or to your local supervisory authority in the EU — though we’d appreciate the chance to resolve concerns first.
You can delete your account at any time from within the Service; see how deletion works in section 10.
10. How long we keep your data
We keep personal data only as long as needed for the purposes above:
- Active accounts — while your account is open, so the Service works and your learning history is preserved.
- After cancellation or a dismissed paywall — you keep read-only access to your vocabulary graph and progress for 30 days. After that window your personal records are archived out of the live service, recoverable if you re-subscribe within a defined grace period, and then permanently deleted.
- On account deletion — deleting your account cascades to your vocabulary graph, reading sessions, conversation sessions (including transcripts), usage metering, and profile, and we also issue an analytics-profile deletion. Shared, non-personal content (such as generated articles and cached audio) is not personal to you and is retained.
- Legal and financial records — we retain the minimum transaction and tax records the law requires, even after account deletion.
- Conversation transcripts contain your speech and are covered by the same retention and erasure rules as the rest of your account.
11. Cookies and similar technologies
We use cookies and similar technologies that are:
- strictly necessary — for sign-in, security, and to make the Service work; and
- analytics — the privacy-protective PostHog setup described in section 7, used in line with your consent.
You can manage non-essential cookies through the in-product consent control and your browser settings. We honour Do-Not-Track for analytics.
12. Security
We use technical and organisational measures to protect your data, including encryption in transit, hashed passwords, access controls, row-level database security isolating each user’s data, and restricted administrative access. No system is perfectly secure, but we work to protect your information and to meet our breach-notification obligations.
13. Children
The Service is not intended for children. You must be at least 16 (or the minimum age of digital consent in your country, if higher) to use it. We do not knowingly collect data from children under that age; if you believe we have, contact us and we will delete it.
14. Changes to this policy
We may update this policy from time to time. If we make material changes, we will give reasonable notice (for example, by email or in the Service). The “Last updated” date above shows the latest revision.
15. Contact
Privacy questions or requests: privacy@getfluir.app, or write to Reffitt Tech Ltd, Unit 13, Freeland Park, Wareham Road, Poole, United Kingdom, BH16 6FA.