Parlai Logo

Privacy Policy

Effective date: 19.06.2026

We at "Parlai" take the protection of your personal data very seriously. We process your data in strict compliance with the applicable legal provisions on data protection, data security, and the responsible handling of personal information.

In this privacy policy, we inform you about which personal data we collect and process, the extent of that processing, and the purposes for which the data processing is carried out.

1. Who we are (Data Controller)

Parlai FlexCo ("Parlai")
Wohllebengasse 7/16, 1040 Vienna, Austria
Commercial Register: FN 640088 g (Commercial Court Vienna)
VAT ID: ATU81353606
Privacy contact: hi@parlai.app

Support: WhatsApp customer support channel (see in-app menu or type "support")

Minimum age: You must be 16 years or older to use Parlai. We do not provide parental consent flows and do not knowingly process data of users under 16.

2. Scope and services covered

This Policy applies to the Parlai language-learning service delivered primarily via WhatsApp, our optional real-time practice calls, email features, public website, and backend services. Features include instant corrections, vocabulary practice, mini-games, personalization, reminders, progress reports, voice message transcription, text-to-speech replies, and optional calls.

3. What data we collect and from where

We collect the data needed to provide, secure, personalize, and improve Parlai. Some data is required to use the service; other data is optional or consent-based.

A) Identity & contact (WhatsApp and account)
• WhatsApp display name, profile metadata provided by WhatsApp, and phone number, which is required to deliver the service over WhatsApp.
• First name, when provided. Parlai can proceed without a real first name.
• Email address, when you provide it for reports, support, subscription, vouchers, tandem, or other email features. Email collection is not required during initial onboarding and can be skipped where offered.

B) Learning profile & preferences
• Target language(s), proficiency level, learning goal, pain points, interests, commitment minutes, reminder settings, profile answers, additional context, tutor customization, audio/selfie preferences, and optional gender guidance for languages where it affects wording.

C) Conversation & usage data
• Messages you send and receive, corrections, quiz/game/practice events, learned/requested vocabulary, progress signals, and message metadata such as IDs and timestamps.
• WhatsApp voice notes may be processed for transcription and spoken replies. We do not record or store call audio ourselves. Audio may be sent to ElevenLabs for speech-to-text and text-to-speech, with OpenAI Whisper as a fallback for transcription if needed. Transcripts and generated audio are used to deliver the service.

D) Website analytics & device data
• After analytics consent, we may process page views, events, device/OS, browser/user agent, referrer/UTM, IP-derived country/city, cookies or local storage IDs, and A/B testing events. We do not run Mixpanel session replay or heatmap recording.

E) Voice calls (optional feature)
• Real-time audio is relayed to realtime voice/LLM providers for transcription and response generation. We do not record or store call audio ourselves. We may store call transcripts/turns, call IDs, duration, token/cost metadata, timestamps, end reason, and summaries to provide feedback, manage call minutes, debug, and improve the service.

F) Payments and email delivery
• Payments are processed by Stripe. Stripe may process payment method details, billing identifiers, billing email/phone, receipts, fraud signals, and subscription status.
• Transactional and opted-in emails may be sent through email providers such as Resend and Brevo.

G) Special-category data
• We do not ask for sensitive data. If you voluntarily share sensitive information in chats, it may be stored in our database as part of your conversation history because it is technically inseparable from the message stream.

H) Inference & segmentation
• We may derive high-level engagement segments to understand usage and plan product or advertising strategy. We do not conduct automated decision-making producing legal or similarly significant effects.

4. Why we use your data and our legal bases

We map each purpose to its legal basis under GDPR/UK GDPR/Swiss FADP and note typical data used.

PurposeLegal basisData used (examples)
Provide the core service: chat, corrections, personalization, transport over WhatsApp, reminders, practice calls, speech processing, and email featuresContract necessity (Art. 6(1)(b))Phone number, WhatsApp name, messages, learning profile, preferences, voice/call data, message metadata, email where needed
Run and protect the service: availability, latency, abuse prevention, debugging, security, delivery reliabilityLegitimate interests (Art. 6(1)(f))Message metadata, technical logs, limited diagnostics, delivery status, abuse and error signals
Improve features and product decisions through non-essential website analyticsConsent (Art. 6(1)(a))GA4, Mixpanel, Vercel Analytics, and Ahrefs events after analytics consent only
Advertising measurement and personalization on the website and off-siteConsent (Art. 6(1)(a))Google Ads and Meta tags/events triggered only with Marketing consent
Support and transactional service communications over WhatsApp or emailContract necessity and legitimate interestsPhone number, email, support messages, subscription or delivery context
Payments, invoicing, fraud prevention, tax and accounting dutiesContract necessity and legal obligationBilling identifiers and payment records handled primarily by Stripe
Compliance with law and authority requestsLegal obligationAny data needed to comply

Advertising & measurement: When you consent to Marketing cookies, we send marketing events and limited identifiers to Google Ads and Meta (Pixel and, where enabled, Conversions API) to measure campaign performance, prevent fraud, build/measure audiences, and improve advertising strategy. Data examples include page and campaign parameters, event type, pseudonymous IDs, IP/user agent, and, only when you provide it and we have consent, hashed contact information such as email or phone for matching. You can withdraw consent through the banner or support. We do not sell personal information.

WhatsApp analytics: We rely on contract necessity or legitimate interests for essential service telemetry such as delivery and stability. Behavioral analytics on WhatsApp can be opted out of by contacting support in WhatsApp.

LLMs & prompts: To provide responses and feedback, we send recent conversation context, profile context, facts summaries, and system prompts to LLM providers. We exclude phone numbers, emails, payment references, and Stripe IDs from the LLM context where technically feasible. We do not permit model training on Parlai data. Providers may temporarily retain prompts/outputs under their service terms; we use configuration and contractual controls to minimize retention where available.

Speech and call providers: For voice features, audio and transcripts may be processed by ElevenLabs, OpenAI, Google/Gemini, or other configured speech/realtime providers as needed to provide the feature.

5. WhatsApp

We use the WhatsApp instant messaging service as part of our product. The service provider is WhatsApp Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland (a subsidiary of Meta Platforms Inc., USA).

Using WhatsApp can involve various types of data, including personal data, being processed. This includes account information such as your telephone number, profile picture, username, or other information that you provide to WhatsApp when creating and managing your WhatsApp account. Naturally, WhatsApp also processes the contents of your messages (text messages, photos, videos, voice messages) that you send via the service. Metadata is also generated, e.g. the date and time a message was sent or received. WhatsApp also records the phone numbers of the parties involved and technical information (such as device type, operating system, or possibly location data).

If you use our service via WhatsApp, different parties are responsible for data processing:
Parlai is the controller for all personal data that you provide to us in the context of WhatsApp communication (e.g. telephone number, profile name, chat content, voice messages). We process this data exclusively to provide and improve our language learning service.
WhatsApp Ireland Limited is an independent controller for the data that is collected when using the WhatsApp service itself. This includes in particular metadata (e.g. timestamps of communications, involved phone numbers), technical information about your device (e.g. operating system, app version), as well as data that WhatsApp processes for its own purposes. We have no influence over this processing. The privacy provisions of WhatsApp, which you can find here: WhatsApp Privacy Policy, are authoritative in this regard.

Please note that WhatsApp may also process your data in the USA. WhatsApp is an active participant in the EU–US Data Privacy Framework, which is intended to ensure an adequate level of data protection for the transfer of personal data of EU citizens to the USA. Additionally, WhatsApp relies on so-called Standard Contractual Clauses (SCCs pursuant to Art. 46(2) and (3) GDPR) for international data transfers. You can find more details about the data processed by WhatsApp in WhatsApp's own Privacy Policy at: https://www.whatsapp.com/privacy.

6. Where we store and process data (providers)

We rely on infrastructure and service providers. The table below summarizes purposes, typical data shared, and processing locations. Providers' processing and retention are also governed by their own terms and data protection addenda.

ProviderPurposeData categories sharedRegion(s) noted
SupabasePrimary databaseAccount identifiers; learning profile; preferences; chat content; facts; message IDs/timestamps; progress data; call transcripts/metadataEU (Frankfurt, eu-central-1)
OpenAI APIsLLM inference, Whisper fallback transcription, optional realtime voice/call processingRecent chat/profile context; system prompts; audio/transcripts for speech features; excludes phone, email, payment references where technically feasibleProcessing may include the US
Anthropic APIsLLM inferenceRecent chat/profile context, facts summary, system promptsProcessing may include the US
Google Vertex AI / GeminiLLM inference and optional realtime voice/call processingRecent chat/profile context, prompts, call audio/transcripts where the realtime feature uses Google/GeminiEU for Vertex configuration where used; realtime/Gemini processing may vary by provider terms
Meta / WhatsApp Business APIMessage transport and deliveryMessage content for delivery, phone numbers, message IDs, delivery metadataGlobal processing per Meta policies
VercelHosting, CDN, serverless functions, deployment infrastructureIP addresses in logs, request metadata, technical diagnosticsRegions may include EU and US depending on routing and provider terms
Vercel AnalyticsCookieless website analytics after analytics consentAggregated pageview/session metrics, URL/UTM, device/user agent, request metadata processed transientlyProcessing may include the US
Mixpanel (EU project)Product and website analytics after analytics consentDevice/user agent, IP-derived geo, user/device IDs, usage events. Session replay and heatmap recording are disabled.EU data residency for the configured project
Google Analytics 4Website analytics after analytics consentEvent data, page/campaign data, device/user agent, advertising features when consentedProcessing may include the US
Ahrefs AnalyticsWebsite analytics after analytics consentPageview/referrer/device metadata according to Ahrefs configurationProcessing may include regions listed by Ahrefs
Google AdsAd measurement and personalization after marketing consentMarketing events, pseudonymous IDs, IP/user agent, optional hashed email/phone when provided and consentedProcessing may include the US
Meta Pixel / Conversions APIAd measurement and personalization after marketing consentMarketing events, pseudonymous IDs, IP/user agent, optional hashed email/phone when provided and consentedGlobal processing per Meta policies
SentryError monitoringTechnical logs that may incidentally include identifiersEU project configuration where used
StripePayments, billing, fraud prevention, subscription managementBilling identifiers, payment method details, receipts, billing email/phone, subscription statusGlobal per Stripe policies
ElevenLabsSpeech-to-text and text-to-speechUser voice audio, transcripts, reply text/audio, minimal session metadataProcessing may include the US; provider retention depends on product and plan configuration
ResendTransactional and product email deliveryEmail address, name where provided, email content and delivery metadataProcessing may include the US
BrevoSubscriber/customer email contact management where configuredEmail address, name, subscription/contact metadataProcessing may include the EU and other regions per Brevo terms

We do not authorize providers to use Parlai data for model training. Where a provider offers controls for training or retention, we disable training and use the lowest feasible retention setting available to us.

7. International data transfers

Your data may be processed in countries outside your own, including the United States. We use appropriate safeguards for such transfers, including Standard Contractual Clauses (SCCs) and, where applicable, the UK IDTA/Addendum. For eligible vendors, we rely on their participation in the EU–US Data Privacy Framework (DPF). You can request more information about these safeguards at hi@parlai.app.

Transfers to Google Ads and Meta occur only after Marketing consent and are protected using SCCs and/or vendor participation in recognized transfer frameworks (see each provider's terms).

8. Cookies and tracking (website)

We use a consent banner with Accept all, Reject all, and Manage preferences. Non-essential analytics and marketing scripts are loaded only after the relevant consent is granted.

Analytics (consent-gated): Google Tag Manager/GA4, Mixpanel, Vercel Analytics, and Ahrefs Analytics. Mixpanel session replay and heatmap recording are disabled.
Marketing (consent-gated): Google Ads tags and Meta Pixel/Conversions API, including hashed identifiers only when provided and consented.
A/B testing is consent-gated because it relies on analytics events.
Technically necessary storage: Required for our website and service to function properly, such as display state, session IDs, or saving your cookie preferences. The legal basis is our legitimate interest under Art. 6(1)(f) GDPR in conjunction with § 165(3) TKG. These cannot be disabled because the website or service would otherwise not function correctly.

Signals & frameworks: We honor your consent choices from the banner. Where supported by the provider and browser, we also respect platform-level privacy signals.

Static cookie/storage table (indicative)

Names and durations are typical defaults and may vary by provider.

CategoryProviderCookie/storage name (examples)Typical durationPurpose
AnalyticsGoogle Analytics 4_ga, _ga_*up to 2 yearsVisitor metrics, session and campaign data after analytics consent
AnalyticsMixpanelmp_* / local storage identifiersup to 1 year unless cleared earlierProduct analytics after analytics consent; replay and heatmaps disabled
AnalyticsVercel AnalyticsCookielessaggregatedPrivacy-friendly pageview/session metrics after analytics consent
AnalyticsAhrefs AnalyticsProvider defaultsprovider defaultWebsite analytics after analytics consent
MarketingGoogle Ads_gcl_au and related IDs~3 monthsAd measurement/attribution after marketing consent
MarketingMeta_fbp, _fbc~3 monthsAd measurement/remarketing after marketing consent
NecessaryParlaiparlai-cookie-consent, session storage IDsuntil cleared / sessionStore consent choices, session state, and product handoff context

You can change your choices any time via the banner (Manage preferences in the footer). If you click Reject all, analytics and marketing tags do not run.

9. Retention

We aim to keep personal data only for as long as needed to provide Parlai and as required by law. Depending on the data type and purpose, different periods and criteria apply:

Core account & conversation data (Supabase): Stored for the life of the account. When you request deletion from the WhatsApp menu or via support, we begin a 14-day pending deletion window. After the window, we permanently delete from systems under our control, such as Supabase and Mixpanel deletion where applicable.

LLM prompts/context and speech processing: Used to produce responses or transcriptions; subsequent retention follows provider defaults and the contractual/configuration controls available to us.

Website analytics: Only collected after analytics consent. GA4, Mixpanel, Vercel Analytics, and Ahrefs retention follow their configured/project defaults. Mixpanel session replay and heatmap recording are disabled.

Payments and invoices: Retained as required for financial record-keeping, tax, accounting, fraud prevention, and legal compliance.

Error logs and hosting logs: Retention follows provider defaults and operational needs.

Note on provider systems: We cannot retroactively delete data already processed by telecom, payment, email, LLM, speech, or analytics providers beyond the deletion options they expose in their platforms.

10. Your rights

Subject to law, you can request:

Right of access: You have the right to learn whether we are processing personal data about you. If so, you can request information about this data and additional details of the data processing (Art. 15 GDPR).

Right to rectification: You have the right to request without delay the correction of inaccurate personal data concerning you, or the completion of incomplete personal data we have on file (Art. 16 GDPR).

Right to erasure: You can, under certain conditions, request the deletion of the personal data we have stored about you (the "right to be forgotten", Art. 17 GDPR). This applies, for example, if the purpose of processing no longer applies or if you withdraw a consent you had given.

Right to restriction of processing: You have the right to request that we restrict the processing of your data in certain cases (Art. 18 GDPR), such as a temporary blocking of use. For example, you can request a temporary suspension of the use of your data if you contest the accuracy of the data and we are verifying it.

Right to object: You may object at any time, on grounds relating to your particular situation, to the processing of your personal data, if we are processing your data on the basis of legitimate interests or if you have given your consent and later withdraw it. You can object to processing for direct marketing purposes at any time without giving any reason.

Right to data portability: You have the right to receive the personal data that you have provided to us in a structured, commonly used, and machine-readable format (Art. 20 GDPR). Upon request, and where technically feasible, we will transfer this data directly to another provider.

Right to withdraw consent: If we process data based on your consent, you can withdraw any consent at any time with effect for the future (Art. 7(3) GDPR). The withdrawal does not affect the lawfulness of processing up to the point of withdrawal.

To exercise any of your rights, you can contact us at any time by email at hi@parlai.app. Please, if possible, indicate which right you wish to exercise and to which data your request relates. We will promptly review your request and respond in accordance with the legal requirements.

How to exercise: Email hi@parlai.app or contact us via our WhatsApp support channel. We will acknowledge your request within 5 business days and respond within one month of receipt (extendable by up to two months for complex or numerous requests, as permitted by law). We verify your identity using the phone number that contacted us on WhatsApp or the billing email on your Stripe account.

Self-serve commands:
• "stop" — stops proactive WhatsApp messages from Parlai.
• To delete your account, open the WhatsApp menu and choose "Delete account".
• To opt out of behavioral analytics on WhatsApp, send a message to our support number requesting an opt-out from analytics; we'll confirm in-channel.

11. Disclosures

We share data with the providers listed in Section 6 for the purposes described. We may also share information with professional advisers such as legal or accounting advisers and with public authorities where legally required.

We disclose marketing event data to Google Ads and Meta as independent controllers for advertising measurement and personalization only when you have given Marketing consent. Each provider uses the data according to its own privacy policy. You can withdraw consent at any time via the banner or by contacting support. We do not sell your personal information.

12. International users & complaints

Despite all precautions, a data protection incident (data breach) cannot be completely ruled out. If we become aware of a data breach that is likely to pose a risk to your rights and freedoms, we will inform the competent data protection supervisory authority without delay, and at the latest within 72 hours of discovering the incident. If you are also affected by the incident, we will notify you as well, provided the legal requirements for such notification are met. In doing so, we adhere to the requirements of Art. 33 and 34 GDPR and will take appropriate measures to minimize any possible negative effects.

If you believe that we are processing your data unlawfully or violating your data protection rights, you can lodge a complaint with a data protection supervisory authority at any time. You have the right to contact the supervisory authority in the EU member state of your residence, your workplace, or the place of the alleged infringement.

Parlai is established in Austria. If you have concerns, you can contact the Austrian Data Protection Authority (Österreichische Datenschutzbehörde):

Österreichische Datenschutzbehörde
Barichgasse 40–42, 1030 Vienna, Austria
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at

We invite you to contact us first so we can try to resolve your concern.

13. Changes to this Policy

We may update this Policy to reflect changes to our practices. We will post the updated version with a new effective date. Your continued use of Parlai after the update constitutes acceptance.

Parlai FlexCo
Wohllebengasse 7/16, 1040 Vienna, Austria
Email: hi@parlai.app
Support: WhatsApp customer support channel (in-app menu / type "support")

Privacy Policy - Data Protection & Your Rights | Parlai