Privacy Policy

Your privacy is fundamental to our mission

Last updated: January 15, 2025

V2.1

Overview

Vernato (the "Service") is a comprehensive pronunciation improvement platform that helps users enhance their language skills through AI-powered feedback and practice sessions. This privacy policy explains how we collect, use, store, and protect your information when you use our service.

We believe in privacy by design and have implemented robust security measures to protect your data. Whether you're using our service anonymously or with a registered account, we are committed to transparency and giving you control over your personal information.

Information We Collect

We collect different types of information depending on how you use our service. We are committed to data minimization and only collect what is necessary to provide and improve our service.

Account Data

When you create an account, we collect:

  • Email address - for account authentication and communication
  • Display name - for personalization and social features
  • Chosen language - to provide relevant practice content
  • Profile picture/avatar - optional, for personalization
  • Account preferences - including notification settings and learning preferences

Practice Data

To provide pronunciation feedback and track your progress, we collect:

  • Audio recordings - your pronunciation practice sessions
  • Pronunciation feedback - AI-generated analysis and scores
  • Progress metrics - practice frequency, improvement trends, and achievements
  • Practice history - sentences practiced, scores achieved, and learning patterns
  • Certificates - achievement certificates and progress milestones

Usage Data

To improve our service and provide a better user experience, we collect:

  • Browser information - device type, browser version, and screen resolution
  • Usage patterns - features used, time spent, and interaction patterns
  • Performance data - page load times, error rates, and system health metrics
  • Analytics data - anonymized usage statistics and feature adoption rates

Anonymous Usage Tracking

Our anonymous tracking system includes:

  • Hashed identifiers - created from IP address and browser information using SHA-256
  • Daily usage count - tracks practice sessions per day (limited to 3 for anonymous users)
  • Automatic cleanup - all anonymous data is deleted after 30 days
  • No personal information - we never collect names, emails, or personal details
  • Explicit consent - we ask for your permission before implementing tracking

You can decline this tracking and create a free account instead, which provides more practice sessions and better features.

How We Use Information

We use your information for the following purposes:

  • Service Provision: To provide and improve the pronunciation improvement service, including AI-powered feedback and personalized learning experiences
  • Progress Tracking: To store your progress and settings so you can access them across devices and continue your learning journey
  • Social Features: To enable optional sharing of practice sessions when you mark them as public
  • Abuse Prevention: To prevent abuse of our free service by enforcing daily usage limits for anonymous users
  • Fair Access: To ensure fair access to our service for all users through appropriate usage limits
  • Service Improvement: To analyze usage patterns and improve our features, performance, and user experience
  • Communication: To send important service updates, security notifications, and respond to your inquiries
  • Legal Compliance: To comply with legal obligations and protect our rights and the rights of our users

Data Storage & Security

We implement industry-standard security measures to protect your data and ensure it is stored securely.

Cookies & Local Storage

We use cookies and local storage for the following purposes:

  • Authentication: To maintain your Firebase authentication session
  • Preferences: To remember interface preferences such as sidebar state and theme settings
  • Learning Settings: To persist settings like selected language and practice cooldown timers
  • Analytics: To store analytics parameters and track user interactions
  • Performance: To cache frequently used data and improve loading speeds

You can clear these at any time through your browser settings. Note that clearing cookies will log you out of your account.

Third-Party Services

Our service relies on the following third-party providers:

  • Firebase (Google): For authentication, database storage, and hosting
  • Vercel Blob: For secure file uploads and avatar storage
  • Google AI Services: For pronunciation analysis and speech recognition
  • Azure Cognitive Services: For additional pronunciation validation
  • FlagCDN: For flag images used in language selection
  • reCAPTCHA: For bot protection and security

These providers may process data according to their own privacy policies. We ensure all providers meet our security and privacy standards.

Security Measures

We implement comprehensive security measures to protect your data:

  • Encryption: All data is encrypted in transit (TLS 1.3) and at rest
  • Access Control: Strict access controls and authentication requirements
  • Input Validation: Comprehensive validation and sanitization of all user inputs
  • Security Headers: Implementation of security headers including CSP, HSTS, and XSS protection
  • Regular Audits: Regular security audits and vulnerability assessments
  • Monitoring: Continuous monitoring for suspicious activities and potential threats

Your Rights & Control

You have comprehensive rights and control over your personal data. We are committed to making it easy for you to exercise these rights.

Data Management

You can manage your data through your account settings:

  • Review Data: View all personal information we have stored about you
  • Update Information: Modify your profile, preferences, and account settings
  • Delete Specific Data: Remove individual practice sessions, recordings, or uploaded files
  • Manage Sessions: View and terminate active sessions across devices
  • Privacy Settings: Control what information is shared publicly

Visit the Privacy & Data section of your account settings to manage your data.

Data Retention

We retain your information for as long as your account is active and as needed to provide our services:

  • Account Data: Retained until account deletion
  • Practice Data: Retained until account deletion or manual removal
  • Usage Analytics: Retained for up to 2 years for service improvement
  • Anonymous Tracking: Automatically deleted after 30 days
  • Backup Data: Securely deleted within 90 days of account deletion

Account Deletion: When you delete your account, we will remove your personal data and uploaded files from our systems within 30 days.

Data Export

You have the right to request a copy of all your personal data:

  • Complete Export: Download all your data in a structured format
  • Specific Data: Request specific categories of data
  • Format Options: Receive data in JSON, CSV, or other formats
  • Processing Time: Exports are typically processed within 7 days

Contact us at support@vernato.org to request a data export.

Analytics & Tracking

We use analytics and tracking systems to improve our service while respecting your privacy.

URL Cleanup System

Our URL cleanup system automatically processes analytics parameters:

  • Automatic Detection: Identifies analytics parameters in URLs
  • Data Extraction: Stores analytics data for tracking purposes
  • URL Cleaning: Removes analytics parameters for a clean user experience
  • Privacy Protection: IP addresses are hashed and not stored in plain text
  • User Control: Analytics data can be cleared through browser settings

This system helps us understand how users discover our service while maintaining a clean browsing experience.

Performance Monitoring

We monitor service performance to ensure optimal user experience:

  • Core Web Vitals: Track loading performance and user experience metrics
  • Error Tracking: Monitor and resolve technical issues quickly
  • Resource Timing: Optimize page load times and resource delivery
  • User Interactions: Understand how users interact with our features
  • System Health: Monitor overall service health and availability

All performance data is anonymized and used solely for service improvement.

Legal Compliance

We are committed to complying with applicable privacy laws and regulations:

  • GDPR Compliance: We comply with the General Data Protection Regulation (GDPR) for users in the European Union
  • CCPA Compliance: We respect the California Consumer Privacy Act (CCPA) for California residents
  • COPPA Compliance: We do not knowingly collect personal information from children under 13
  • Data Protection Principles: We follow data minimization, purpose limitation, and security by design principles
  • User Rights: We respect your rights to access, rectify, erase, and port your personal data
  • Breach Notification: We will notify you of any data breaches affecting your personal information

If you believe we have not properly addressed your privacy concerns, you have the right to contact your local data protection authority.

Contact Information

If you have any questions about this privacy policy or our data practices, please contact us:

Data Protection Officer: privacy@vernato.org
Security Issues: security@vernato.org

We typically respond to privacy inquiries within 48 hours. For urgent matters, please include "URGENT" in the subject line.

This privacy policy is effective as of January 15, 2025. We may update this policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.