Privacy Policy
Last updated: August 7, 2026
1. Who We Are
Smirk ("we," "us," "our") is operated from the Netherlands. If you have questions about this policy, contact us at [email protected].
2. Data We Collect
We collect the minimum data needed to provide and improve Smirk:
| Category | Examples |
|---|---|
| Account | Email address, hashed password, date of birth |
| Profile | Practice preferences, skill goals, experience level |
| Conversations | Messages you send and AI responses during practice sessions |
| Voice input (optional) | If you turn on voice and hold the talk button, a short recording of your speech is sent for transcription. We do not store the recording. Only the resulting text is saved, as an ordinary message. |
| Performance | Quality scores, streaks, XP, levels, achievements |
| Usage Analytics | App opens, feature usage, session duration (via PostHog) |
| Purchase Data | Subscription status, transaction IDs (via RevenueCat; we never see your payment card) |
| Device | Push notification token, timezone, platform (iOS/Android) |
We do not collect location data, contacts, photos, or health data. Voice input is off by default and can be turned on or off at any time in the app. The microphone is used only while you hold the talk button. We do not record in the background and we do not listen for ambient audio.
3. How We Use Your Data
- Generate AI responses and score your messages during practice conversations
- Convert your speech to text when you choose to use voice input, and generate the practice character's spoken lines
- Track your progress (XP, streaks, levels, performance analytics)
- Send push notifications you've opted into (streak reminders, daily practice)
- Process subscriptions and gem purchases
- Improve the app through anonymized, aggregated usage analytics
- Respond to support requests
We do not sell your personal data, and we do not share it for cross-context behavioural advertising. We do not use your conversations or your voice to train AI models.
4. AI Processing
AI Processing Disclosure
Smirk uses artificial intelligence to power conversations, coaching, scoring, speech, and imagery. This section explains what happens to your data when you use AI features.
What is sent, and where
| Feature | What is sent | Processed by |
|---|---|---|
| Conversation and coaching | The messages you write, plus the practice scenario and character details | Google Gemini models, via OpenRouter |
| Scoring and feedback | The same conversation content, to produce a grade and written feedback | Google Gemini models, via OpenRouter |
| Voice input (optional) | A short recording of you speaking your turn, sent as audio and returned as text | Deepgram speech to text, via OpenRouter |
| Character speech | Only the character's own line. Nothing you wrote or said is sent here. | Qwen speech synthesis models, via OpenRouter |
These requests carry the content above and nothing else. Your name, email address and account identifiers are not included in them.
Retention by AI providers
Content is sent to produce a response and is returned in real time. Under the terms on which we access these services, our AI providers do not use content sent through their APIs to train their models, and do not retain it for their own purposes. We do not train any AI model on your conversations or your voice. Voice recordings are transcribed while the request is in flight and are not stored by us.
Model providers may change
We may change AI providers or models as the technology moves. Where a change means a different category of provider receives your content, we will update this policy and ask you to confirm your consent again in the app before continuing.
What AI does not do
- AI does not access your email, contacts, photos, or any data outside the active practice session
- AI does not make decisions about your account, billing, or access
- AI-generated grades and feedback are informational only and do not affect your account standing
- AI does not create profiles about you that persist across sessions
- Voice recordings are not used to identify you, and we do not create voiceprints or any other biometric identifier
5. Sub-Processors
We share data with the following service providers, each under their own data processing agreements:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Authentication, database | Account data, conversations, progress |
| Google Cloud | Backend hosting | Server-side data in transit and in processing |
| OpenRouter | AI request routing | Conversation content and voice clips, in transit |
| Google (Gemini) | Conversation, coaching and scoring models | Conversation content, in transit |
| Deepgram | Speech to text, only if you use voice input | A short recording of your speech, in transit |
| Qwen speech models | Character speech synthesis | The character's own line only. No user content. |
| Cloudflare | Image, video and audio delivery | Technical request data such as IP address |
| RevenueCat | Subscription management | User ID, purchase events |
| PostHog | Product analytics | Anonymized usage events |
| Expo / Firebase | Push notifications | Device push token |
This list reflects the providers we use at the date above. We may add, replace or remove a provider, and we will update this list when we do.
6. Data Retention
- Conversations: Stored while your account is active. Deleted when you delete your account.
- Voice recordings: Not stored. A clip exists only for the moments it takes to transcribe it, and is then discarded. The transcribed text is kept as an ordinary message.
- Performance data: Stored while your account is active. Anonymized aggregates may be retained for analytics.
- Analytics events: Retained for 12 months, then deleted.
- Account data: Deleted within 30 days of an account deletion request.
Copies may remain in routine encrypted backups for a limited period after deletion, until those backups are overwritten on their normal cycle. We may also retain limited records where we are required to by law, for example transaction records for tax purposes.
7. Your Rights (GDPR)
If you are in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Ask us to correct inaccurate data.
- Erasure: Request deletion of your data. You can delete your account in the app (Profile → Delete Account) or email us.
- Portability: Request your data in a machine-readable format.
- Restriction: Ask us to limit processing in certain circumstances.
- Objection: Object to processing based on legitimate interests.
- Withdraw consent: You can stop voice processing at any time by turning voice off in the app. Because AI processing is what the app does, withdrawing consent to it means the practice features stop working. You can withdraw it by contacting us or by deleting your account.
To exercise any of these rights, email [email protected]. We will respond within one month. Where a request is complex or you have made several, we may extend that period by up to two further months and will tell you if we do, as the GDPR allows.
Legal basis for processing: consent (AI processing, marketing), contract performance (account, conversations), legitimate interest (analytics, security).
8. AI Transparency
Smirk is built around AI, and we tell you so at every point where it matters. In line with the transparency expectations of the EU AI Act (Regulation 2024/1689):
- You are always interacting with an AI system, never with a real person. There is no way to reach another human being through Smirk.
- The practice characters are fictional. Their faces, scenes and photographs are AI-generated and do not depict, and are not intended to depict, any real person.
- The voices you hear are synthesised by AI. They are not recordings of a real person speaking.
- Grades, feedback and coaching suggestions are generated by AI. They are informational only, can be wrong, and are not professional advice of any kind.
- We do not use AI to make decisions about your account, your billing, or your access to the service.
- Content safety is handled through instruction-level rules and filtering. These reduce the chance of unexpected output but cannot rule it out.
9. Age Requirement
Smirk is intended for users aged 18 and older. You confirm your age when you create an account, and the app is age-rated in the App Store and Google Play. We rely on that confirmation and on the store rating, and we do not knowingly collect data from anyone under 18. If we learn that we hold data from someone under 18, we will delete it promptly. If you believe a minor is using Smirk, contact us at [email protected].
10. Security
We use technical and organisational measures appropriate to the risk, including:
- Encryption in transit and at rest
- Row-level access rules on our database
- Hashed passwords, never stored in plain text
- Rate limiting and request validation
- Access controls and logging
No method of transmission or storage is completely secure, so while we work to protect your data we cannot guarantee absolute security.
11. International Data Transfers
Your data may be processed by sub-processors located in the European Union and the United States. Where data is transferred outside the EEA, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements (DPAs) with each sub-processor
- EU-US Data Privacy Framework where applicable
Our application servers run in the European Union and our database is hosted in Europe. AI processing, subscription management, push delivery and content delivery involve providers located outside the EEA, including in the United States and elsewhere, and are covered by the safeguards above.
12. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33
- Notify affected users without undue delay if the breach is likely to result in a high risk to your rights, as required by GDPR Article 34
- Document the breach, its effects, and remedial actions taken
13. Cookies
Smirk is a mobile app and does not use browser cookies. This website uses no tracking cookies. Analytics on the website (if any) use privacy-friendly, cookieless methods.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the app. Continued use of Smirk after changes constitutes acceptance.
15. Contact
For privacy-related questions, data requests, or complaints:
Email: [email protected]
Operator: Smirk, Netherlands
If you are unsatisfied with our response, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local supervisory authority.