Privacy Policy

Effective August 23, 2026

Sayphon helps you speak a foreign language, so what you write and say passes through the service. Here's a plain, jargon-free account of what data we collect, why we need it, who it reaches, and how you can control it.

Who processes your data

Sayphon is provided by sole proprietor Dmitrii Kondratev, registered in the Republic of Armenia (tax ID 20368125), at Yerevan, 43/2 Pavstos Buzand Street, Apt. 0002. For any questions about your data, write to the support email listed at the bottom of this page.

What data we collect

  • Account data: your email address, name if you provided one, time zone, and registration date.
  • Content you send to the service: conversation turns, text and voice messages, resumes and job descriptions, and your answers in exercises.
  • Usage data: which features you've opened, how many requests you've made, exercise results, and learning progress.
  • Technical data: your connection address, browser type, and error logs kept by the server.
  • Payment data: handled entirely by our payment partner. Card numbers never reach us and we never store them.

Why we need it

To make the service work: recognize speech, translate, suggest responses, score pronunciation, and save your progress and history. To keep your account accessible and respond to support requests. To protect the service from abuse and track usage against your plan. And to improve the product: we look at anonymized usage metrics, not at your conversations out of curiosity.

Our legal basis

We process data to perform our contract with you, meaning to provide the paid or free access you've signed up for. Some processing relies on our legitimate interest: security, preventing abuse, and product development. Where your consent is required, we ask for it separately, and you can withdraw it at any time.

Who we share data with

We don't sell your data or hand it over for someone else's advertising. To keep the service running, some data is processed by contractors, each with a narrow role: speech recognition, voice synthesis, language models for translation and suggestions, email delivery, server hosting, and payment processing. They work under contract, process data only on our instructions, and may not use it for their own purposes. We provide an up-to-date list of contractors on request, by email to support.

We may disclose data if required by law or by an official request from an authorized government body.

Where and how long we keep it

Our servers are located in the European Union, in Finland. Some contractors may process data outside the EU; in that case, transfers rely on standard contractual clauses or other lawful mechanisms.

We keep account data and session history for as long as your account exists. After you delete your account, data is deleted within 30 days, including backups. Certain records required by law, such as payment records, are kept for as long as the law requires.

Technical logs of session dialogues are kept only in debug mode, while we investigate a specific problem, and are deleted no later than 30 days.

Your rights

You can request a copy of your data, correct inaccuracies, delete your account together with your data, restrict or object to processing, and withdraw any consent you've given. Write to our support email from the address your account is registered under, and we'll respond within 30 days. If you're not satisfied with our response, you have the right to contact your data protection supervisory authority.

Model training

We do not train models on your conversations. Your utterances, audio and text are processed only to fulfil your request: recognise speech, translate, suggest a reply, assess pronunciation. We pass data to contractors on terms that prohibit them from using it to train their own models.

To improve the product we look at anonymised usage figures: how many requests were made, which features were opened, where errors occurred. This data cannot be used to reconstruct the content of your conversation.

How we protect your data

The connection to the service is encrypted, passwords are stored as irreversible hashes and cannot be read even by us. Server access is restricted to keys, password login is disabled, and repeated guessing attempts are blocked. Backups are stored encrypted, separately from the server.

No one can guarantee complete protection. If a breach affecting your data occurs, we will notify you and the supervisory authority within the period set by law.

Cookies

We use only essential cookies: they keep you signed in and protect forms against request forgery. We use no advertising or tracking cookies, and no data about you goes to ad networks.

Children

The service is not intended for children under 16. If we learn that an account was created by a child under this age without parental consent, we will delete that account and its associated data.

Changes to this policy

If this policy changes, we'll update the date at the top of the page, and we'll notify you by email or within the service about any material changes before they take effect.

How to reach us

For any questions about your data, write to hello@sayphon.ai. We respond within 5 business days.