Service operator: SpeakCoachLab, operated by Min Xiong
Contact: support@speakcoachlab.com
This Privacy Policy explains how the Service operator identified above ("we," "us," or "our") collects, uses, shares, and retains personal information when you use SpeakCoachLab (the "Service").
The Service is intended for users age 13 and older. We do not knowingly permit accounts for children under 13. If we learn that we collected personal information from a child under 13 without legally sufficient parental authorization, we will take reasonable steps to delete it. A parent or guardian who believes a child under 13 has provided information may contact us using the email above.
Depending on how you use the Service, we may process:
The application backend does not intentionally store raw microphone audio. Public Speaking can use browser speech recognition to produce a transcript and browser-observable delivery measurements such as speaking time, pace, pauses, filler-word count, and volume consistency. Debate can likewise use browser-produced text from speech input. Browser or operating-system speech-recognition providers may process microphone audio under their own terms and privacy practices.
For a successfully completed AI evaluation, the Service clears the stored transcript from its application database after the evaluation is generated. If final AI feedback fails, a completed-session transcript may be retained for up to 7 days so feedback can be retried. Content from incomplete or abandoned sessions and other detailed practice content may be retained for up to 365 days under the Service's general content-retention schedule. After that period, detailed practice content such as topics, scores, delivery details, and narrative reports may be redacted while minimal session/accounting records are retained where needed.
We use personal information to provide and personalize debate and public-speaking practice; generate AI responses, moderation, scores, and coaching; maintain practice history and progress; authenticate and secure accounts; prevent fraud, abuse, and unauthorized access; provide customer support; process one-time purchases and refunds; administer practice credits; diagnose service problems; comply with law; and enforce our Terms.
We send practice content and related instructions to OpenAI's API for functions such as safety moderation, debate responses, and coaching/scoring. Our current Responses API requests are configured with persistent response storage disabled. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer opts in to data sharing; under OpenAI's standard API data controls, certain customer content may still be retained in abuse-monitoring logs for a limited period (currently up to 30 days), subject to OpenAI's data controls and legal obligations. Our own application-database retention described above is separate from a service provider's retention. You can review OpenAI's API data controls.
Stripe processes payment-card information and one-time payment transactions. We receive transaction identifiers and payment status information needed to provide purchased access, maintain purchase history, and process refunds, but we do not store full card numbers. We also use hosting, database/cache, security, and other infrastructure providers that process information on our behalf to operate the Service. We currently use Brevo to deliver transactional messages such as email verification, password reset, account-security, refund/payment-status, and account-deletion notices. You can review Stripe's Privacy Policy.
We may disclose information to service providers that help us operate the Service; when reasonably necessary to protect users, the Service, or others; to investigate fraud, abuse, or security incidents; to comply with lawful requests or legal obligations; or as part of a merger, acquisition, financing, or sale of substantially all relevant business assets, subject to applicable law. We do not sell personal information, and the current Service does not share personal information for cross-context behavioral or targeted advertising.
The Service uses cookies and similar browser storage that are necessary for authentication, session continuity, CSRF/security protections, and core application functions. The current Service does not use third-party behavioral-advertising cookies.
We retain account information while an account is active and as reasonably necessary afterward for security, dispute resolution, accounting, fraud prevention, and legal obligations. Practice-content retention follows the transcript and 365-day rules described above. Purchase, credit-usage, consent, security, refund, and audit records may be kept longer when reasonably necessary for accounting, fraud prevention, enforcing agreements, resolving disputes, or meeting legal requirements. We delete or de-identify information when it is no longer reasonably needed, subject to technical backup cycles and legal obligations.
You may request account deletion from the Account & Plan page. An administrator reviews the request and, when approved, disables account access, removes practice content, and removes or replaces identifying account information. Minimal billing, refund, fraud-prevention, consent, and audit records may be retained when reasonably necessary or legally required.
Depending on where you live, you may have rights to request access to, correction of, deletion of, or a copy of certain personal information, and to appeal certain privacy decisions. You may submit a request through available account controls or by contacting the email above. We may need to verify your identity before completing a request, and applicable law may permit or require us to retain certain information.
We use measures designed to protect information, including encryption in transit, access controls, password hashing, secure authentication cookies, rate limits, moderation and abuse controls, audit records, and service-provider security controls. No online service can guarantee absolute security.
The Service and its providers may process information in the United States and other countries where they operate. Those locations may have privacy laws that differ from the laws where you live. We use service providers and safeguards appropriate to the nature of the Service and applicable requirements.
We may update this Privacy Policy as the Service, vendors, or legal requirements change. The version date at the top identifies the current policy. For material changes, we will provide notice or request renewed consent when required by applicable law.
Questions or privacy requests may be sent to the contact email shown at the top of this page.