Privacy Policy

Last updated: August 7, 2026

1. Who We Are

Smirk ("we," "us," "our") is operated from the Netherlands. If you have questions about this policy, contact us at [email protected].

2. Data We Collect

We collect the minimum data needed to provide and improve Smirk:

Category Examples
AccountEmail address, hashed password, date of birth
ProfilePractice preferences, skill goals, experience level
ConversationsMessages you send and AI responses during practice sessions
Voice input (optional)If you turn on voice and hold the talk button, a short recording of your speech is sent for transcription. We do not store the recording. Only the resulting text is saved, as an ordinary message.
PerformanceQuality scores, streaks, XP, levels, achievements
Usage AnalyticsApp opens, feature usage, session duration (via PostHog)
Purchase DataSubscription status, transaction IDs (via RevenueCat; we never see your payment card)
DevicePush notification token, timezone, platform (iOS/Android)

We do not collect location data, contacts, photos, or health data. Voice input is off by default and can be turned on or off at any time in the app. The microphone is used only while you hold the talk button. We do not record in the background and we do not listen for ambient audio.

3. How We Use Your Data

  • Generate AI responses and score your messages during practice conversations
  • Convert your speech to text when you choose to use voice input, and generate the practice character's spoken lines
  • Track your progress (XP, streaks, levels, performance analytics)
  • Send push notifications you've opted into (streak reminders, daily practice)
  • Process subscriptions and gem purchases
  • Improve the app through anonymized, aggregated usage analytics
  • Respond to support requests

We do not sell your personal data, and we do not share it for cross-context behavioural advertising. We do not use your conversations or your voice to train AI models.

4. AI Processing

AI Processing Disclosure

Smirk uses artificial intelligence to power conversations, coaching, scoring, speech, and imagery. This section explains what happens to your data when you use AI features.

What is sent, and where

Feature What is sent Processed by
Conversation and coachingThe messages you write, plus the practice scenario and character detailsGoogle Gemini models, via OpenRouter
Scoring and feedbackThe same conversation content, to produce a grade and written feedbackGoogle Gemini models, via OpenRouter
Voice input (optional)A short recording of you speaking your turn, sent as audio and returned as textDeepgram speech to text, via OpenRouter
Character speechOnly the character's own line. Nothing you wrote or said is sent here.Qwen speech synthesis models, via OpenRouter

These requests carry the content above and nothing else. Your name, email address and account identifiers are not included in them.

Retention by AI providers

Content is sent to produce a response and is returned in real time. Under the terms on which we access these services, our AI providers do not use content sent through their APIs to train their models, and do not retain it for their own purposes. We do not train any AI model on your conversations or your voice. Voice recordings are transcribed while the request is in flight and are not stored by us.

Model providers may change

We may change AI providers or models as the technology moves. Where a change means a different category of provider receives your content, we will update this policy and ask you to confirm your consent again in the app before continuing.

What AI does not do

  • AI does not access your email, contacts, photos, or any data outside the active practice session
  • AI does not make decisions about your account, billing, or access
  • AI-generated grades and feedback are informational only and do not affect your account standing
  • AI does not create profiles about you that persist across sessions
  • Voice recordings are not used to identify you, and we do not create voiceprints or any other biometric identifier

5. Sub-Processors

We share data with the following service providers, each under their own data processing agreements:

Provider Purpose Data Shared
SupabaseAuthentication, databaseAccount data, conversations, progress
Google CloudBackend hostingServer-side data in transit and in processing
OpenRouterAI request routingConversation content and voice clips, in transit
Google (Gemini)Conversation, coaching and scoring modelsConversation content, in transit
DeepgramSpeech to text, only if you use voice inputA short recording of your speech, in transit
Qwen speech modelsCharacter speech synthesisThe character's own line only. No user content.
CloudflareImage, video and audio deliveryTechnical request data such as IP address
RevenueCatSubscription managementUser ID, purchase events
PostHogProduct analyticsAnonymized usage events
Expo / FirebasePush notificationsDevice push token

This list reflects the providers we use at the date above. We may add, replace or remove a provider, and we will update this list when we do.

6. Data Retention

  • Conversations: Stored while your account is active. Deleted when you delete your account.
  • Voice recordings: Not stored. A clip exists only for the moments it takes to transcribe it, and is then discarded. The transcribed text is kept as an ordinary message.
  • Performance data: Stored while your account is active. Anonymized aggregates may be retained for analytics.
  • Analytics events: Retained for 12 months, then deleted.
  • Account data: Deleted within 30 days of an account deletion request.

Copies may remain in routine encrypted backups for a limited period after deletion, until those backups are overwritten on their normal cycle. We may also retain limited records where we are required to by law, for example transaction records for tax purposes.

7. Your Rights (GDPR)

If you are in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Ask us to correct inaccurate data.
  • Erasure: Request deletion of your data. You can delete your account in the app (Profile → Delete Account) or email us.
  • Portability: Request your data in a machine-readable format.
  • Restriction: Ask us to limit processing in certain circumstances.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw consent: You can stop voice processing at any time by turning voice off in the app. Because AI processing is what the app does, withdrawing consent to it means the practice features stop working. You can withdraw it by contacting us or by deleting your account.

To exercise any of these rights, email [email protected]. We will respond within one month. Where a request is complex or you have made several, we may extend that period by up to two further months and will tell you if we do, as the GDPR allows.

Legal basis for processing: consent (AI processing, marketing), contract performance (account, conversations), legitimate interest (analytics, security).

8. AI Transparency

Smirk is built around AI, and we tell you so at every point where it matters. In line with the transparency expectations of the EU AI Act (Regulation 2024/1689):

  • You are always interacting with an AI system, never with a real person. There is no way to reach another human being through Smirk.
  • The practice characters are fictional. Their faces, scenes and photographs are AI-generated and do not depict, and are not intended to depict, any real person.
  • The voices you hear are synthesised by AI. They are not recordings of a real person speaking.
  • Grades, feedback and coaching suggestions are generated by AI. They are informational only, can be wrong, and are not professional advice of any kind.
  • We do not use AI to make decisions about your account, your billing, or your access to the service.
  • Content safety is handled through instruction-level rules and filtering. These reduce the chance of unexpected output but cannot rule it out.

9. Age Requirement

Smirk is intended for users aged 18 and older. You confirm your age when you create an account, and the app is age-rated in the App Store and Google Play. We rely on that confirmation and on the store rating, and we do not knowingly collect data from anyone under 18. If we learn that we hold data from someone under 18, we will delete it promptly. If you believe a minor is using Smirk, contact us at [email protected].

10. Security

We use technical and organisational measures appropriate to the risk, including:

  • Encryption in transit and at rest
  • Row-level access rules on our database
  • Hashed passwords, never stored in plain text
  • Rate limiting and request validation
  • Access controls and logging

No method of transmission or storage is completely secure, so while we work to protect your data we cannot guarantee absolute security.

11. International Data Transfers

Your data may be processed by sub-processors located in the European Union and the United States. Where data is transferred outside the EEA, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements (DPAs) with each sub-processor
  • EU-US Data Privacy Framework where applicable

Our application servers run in the European Union and our database is hosted in Europe. AI processing, subscription management, push delivery and content delivery involve providers located outside the EEA, including in the United States and elsewhere, and are covered by the safeguards above.

12. Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33
  • Notify affected users without undue delay if the breach is likely to result in a high risk to your rights, as required by GDPR Article 34
  • Document the breach, its effects, and remedial actions taken

13. Cookies

Smirk is a mobile app and does not use browser cookies. This website uses no tracking cookies. Analytics on the website (if any) use privacy-friendly, cookieless methods.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the app. Continued use of Smirk after changes constitutes acceptance.

15. Contact

For privacy-related questions, data requests, or complaints:

Email: [email protected]
Operator: Smirk, Netherlands

If you are unsatisfied with our response, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local supervisory authority.