When you speak
Your voice takes a short path.
- 01
You start it
The microphone turns on only after you choose to record. You can type instead.
- 02
Audio is transcribed
The temporary recording passes through Idiolect's backend to OpenAI's speech-to-text service.
- 03
Audio is removed
The raw file is deleted from Idiolect storage when the transcription attempt finishes or fails.
- 04
Text does the work
You review the transcript. Submitted text can guide your profile or become the sentence the AI assesses.
What we collect
Idiolect collects the information needed to run a personal, account-based vocabulary practice. Some details come from you, some are created as you use the app, and some come from the services that keep the app working.
Account and identity
When you create an account or sign in, our authentication provider, Clerk, handles identifiers such as your email address, name if you provide one, sign-in method, and account ID. If you choose Sign in with Apple or Google, that provider also handles the information needed to complete sign-in. Idiolect's application database stores a Clerk user ID rather than another copy of your password. We do not receive your password or one-time sign-in code.
Your direction
We keep the answers you give during onboarding and later profile edits. These can include your goals, the situations where words matter, how you want to sound, tones you want to avoid, your preferred level of challenge, familiarity answers, written notes, and voice transcripts. We also keep the editable profile summary and structured signals produced from those answers.
Your learning activity
We keep the words selected for you, why they were selected, whether you knew them, your progress, words you ask to see, sentences and context you submit, whether you typed or spoke, and the AI's feedback. We also keep technical records about recommendation and evaluation requests, such as model version, timing, token use, cost, and whether a request succeeded.
Reminders, device, and subscription status
If you enable reminders, we keep your selected times, time zone, locale, notification preferences, an installation identifier, device platform, and an Expo push token. If Idiolect offers paid access, we may keep a billing identifier and entitlement status from RevenueCat. Apple handles App Store payment details; Idiolect does not receive your full card number.
Website visits and voluntary discovery answers
The public website stores first-touch attribution in your browser's session storage: the page you entered on, the referring site's origin, and any UTM source, medium, or campaign in the link. If you submit the “How did you find us?” form, we receive the source you choose and any prompt you volunteer. Hosting providers may also create ordinary request, security, and error logs, which can include an IP address, user agent, requested URL, and time.
Crash and error diagnostics
When the app fails, it sends a diagnostic report so the fault can be found and fixed. A report contains the error, where in the app it happened, the app version, and the device model and operating system. It is linked to your account identifier so repeated failures for one person can be recognised.
Diagnostics deliberately exclude what you wrote. Sentences, onboarding answers, voice transcripts, request contents and message bodies are removed on your device before a report is sent, rather than filtered after it arrives. Your email address, name and IP address are not attached.
How we use it
We use this information to:
- Create, secure, and support your account.
- Turn your onboarding conversation into an editable direction for word selection.
- Choose words around your needs, avoid words you already use, and explain each choice.
- Transcribe deliberate voice recordings and assess the meaning, phrasing, naturalness, and tone of sentences you submit.
- Track learning progress, bring words back for later recall, and send reminders at the times you choose.
- Manage access or subscription status, respond to support requests, prevent abuse, diagnose failures, and improve reliability.
- Understand which public pages and recommendations help people find Idiolect, without using that website attribution to personalise their vocabulary profile.
We do not sell personal information. We do not use your account, onboarding answers, voice, transcripts, or learning activity for third-party targeted advertising.
Voice and AI
Idiolect does not listen in the background. Recording starts only after you open a voice answer or check-in and choose to speak. You can review the resulting text before it becomes part of a submitted answer or usage attempt, and typing is available when you would rather not use the microphone.
A raw recording is stored temporarily so it can be transcribed. It is sent to OpenAI's audio transcription API, then deleted from Idiolect storage after the transcription attempt succeeds or fails. The text transcript is different: if you submit or save it, we retain that text as part of your profile or learning history until you remove the relevant record or ask us to delete your data.
We also send the minimum relevant text to OpenAI when the app needs to reflect your onboarding direction, choose or refine a word, or assess a sentence. That request can include your written answers, transcript, profile direction, the selected word, the sentence, and context you provide. The OpenAI API is not used to train OpenAI's models by default. OpenAI publishes endpoint-specific retention rules; many text API requests can appear in abuse-monitoring logs for up to 30 days, while its audio transcription endpoint currently lists no application-state or abuse-monitoring retention. See OpenAI's API data controls.
Idiolect does not use your voice recordings or personal writing to train a general-purpose AI model. AI feedback helps with vocabulary practice; it does not make decisions that determine your employment, education, credit, health, legal rights, or access to essential services.
Who helps us run Idiolect
We use specialist providers for work we cannot sensibly do alone. We require providers processing personal data for Idiolect to protect it consistently with this policy and applicable law, and to use it only for the service they provide. Their own policies also apply to their processing.
- Clerk provides authentication and account identity. See the Clerk privacy policy.
- Convex provides the application database, backend functions, and temporary file storage. See the Convex privacy policy.
- OpenAI provides speech-to-text and the AI processing used for personalisation, word selection, refinement, and sentence feedback. See the OpenAI privacy policy.
- Expo helps deliver notifications when you enable them. See the Expo privacy policy.
- Apple and RevenueCat can process purchases and subscription-entitlement status if paid access is offered. See Apple's privacy policy and the RevenueCat privacy policy.
- Groq can generate reusable pronunciation audio from a word, definition, and pronunciation—not from your recording. See the Groq privacy policy.
- Vercel hosts the public website and can process ordinary request and security logs. See the Vercel privacy policy.
When data is shared
We share personal data with the providers above only when their work is needed to operate Idiolect. We may also disclose information when reasonably necessary to comply with law, respond to a valid legal request, protect a person from harm, investigate abuse, or protect the rights and security of Idiolect and its users.
If Idiolect is reorganised, financed, acquired, or transferred, data may move as part of that transaction. Any successor would remain responsible for the commitments in this policy unless it gives you notice of a change.
Retention and deletion
We keep account details, your direction, and learning history while your account is active and for as long as they are needed to provide the service. Technical usage and security records may be kept for a shorter or longer period where needed for fraud prevention, accounting, dispute handling, or legal compliance.
Raw voice audio is temporary and is deleted from Idiolect storage after the transcription attempt. If you remove a submitted usage attempt, its sentence, optional context, and AI evaluation are cleared from the active record; a minimal record of the removed attempt can remain so the learning sequence stays consistent.
You can delete your account from inside the app, under You. That removes your direction, your words, the sentences you wrote, your reminders and your sign-in account. You can also request deletion through the contact details below, and we may ask you to verify control of the account. We will remove data we are not legally required to keep; limited records may remain in protected backups until those backups cycle out, or where retention is required for security, financial, or legal reasons. Deleting the app from your phone does not by itself delete the account.
Your choices
- Speak or type. You can use typed answers when you do not want to grant microphone access.
- Control reminders. You can change the chosen times, pause reminders, or turn off notification permission in iOS.
- Review your words. You can inspect your profile direction and voice transcripts before submitting them.
- Ask about your data. Depending on where you live, you may have rights to access, correct, export, object to processing, restrict processing, or delete personal data, and to complain to a data-protection authority.
To make a privacy request, use the details on our contact page. We will verify requests before giving access to or deleting account data. We will not discriminate against you for exercising an applicable privacy right.
Security and transfers
We use access controls, authenticated requests, encrypted network transport, signed webhooks, and restricted service credentials to protect Idiolect data. No online service can promise perfect security, so please do not submit secrets or sensitive information that the app does not need.
Idiolect and its providers may process data in countries other than the one where you live. Those countries can have different data laws. Where required, we rely on contractual and other recognised safeguards for international transfers.
Children
Idiolect is designed for people who already use English comfortably and is not directed to children under 13. We do not knowingly collect personal data from a child under 13. If you believe a child has given us personal data, please contact us so we can investigate and remove it. A higher minimum age may apply where local law requires it.
Changes and contact
We may update this policy when Idiolect, its providers, or the law changes. We will change the date at the top and give a more prominent notice when a change materially affects how personal data is handled.
Questions, access requests, corrections, and deletion requests can be sent to me@andylower.com. Please do not email a password, sign-in code, raw voice recording, or private sentence. See the full contact and support page for what to include.