Legal

Privacy Policy

Last updated: October 5, 2026

Glosso Studio builds a small number of applications. This page explains what each one does with your data. It covers the Glosso pronunciation app, this website, and points to the separate TransitOS policy.

The data controller is Glosso Studio (an independent software project). For any privacy or data-protection request, contact [email protected].


Glosso (pronunciation app)

Glosso records you speaking and scores how you pronounced each sound. What happens to that recording depends on how the app is set up, and we describe both paths plainly below.

Audio and how your attempt is scored

There are two ways an attempt is scored, and the difference matters for your voice:

  1. Cloud scoring (the default). On a normal install, when you finish an attempt the app sends the recording over HTTPS to our own server (api.glossostudio.com) to be scored. The audio is processed in memory to produce your result and discarded as soon as the request finishes. It is never written to disk, never logged, never sold, and never used to train models. Along with the recording, the request contains the practice text, the reference pronunciation, the target language and the interface language, an aggregate summary of your pronunciation profile (per-sound accuracy statistics, no audio) and the app’s random installation id (see below). No name, email or other personal identity is attached.
  2. On-device scoring (optional). In Settings you can download an optional acoustic model (about 342 MB) once. With it installed, scoring runs entirely on your phone: your recordings never leave the device, and scoring also works offline. You can delete the model at any time, after which scoring returns to the cloud.

So, in short: your voice leaves your device unless you have installed the optional on-device model. Cloud scoring is what a fresh install uses, because the model is a large, optional download rather than something bundled with the app.

The pronunciation profile summary is also sent when the app asks our server to plan your drills. In both cases it is processed in memory to answer that request.

The installation id

On first launch the app creates a random identifier (a UUID) and stores it on your device. It is sent with the app’s requests to api.glossostudio.com: product configuration, account status, scoring, purchase verification and usage statistics. Our server stores it with the usage and score events described below, and uses it as the key for your device’s plan, Pro access and Beta Founder status.

  • It is not a hardware identifier or the advertising ID, and it is not derived from anything that identifies you or your device.
  • The app does not reset it, because it is how your device keeps its plan and Beta Founder status.
  • What we hold under it is pseudonymous: it is linked to a random installation id, not to your name or email.

Usage statistics

From app version 2.5.2, the app sends first-party usage statistics so we know whether the course is working. They go only to our own server and are stored in our own database. They are never shared, there is no analytics or advertising SDK in the app, and the app shows no ads.

  • On by default, easy to turn off. The first onboarding page says so in one line. You can turn them off at any time in Settings > Usage statistics, and the app works exactly the same.
  • What is recorded: app opened; session length; onboarding started and finished (and whether it was skipped); lesson started, finished or left early (lesson id and CEFR level); exercise finished (exercise type, a 10-point score band, mastered or not); pronunciation attempt scored on the device (score band, mastered or not, ids of the sound-error rules); microphone permission denied; paywall seen; Pro button tapped; purchase started or failed (product and plan ids, error code).
  • Also recorded from app version 2.5.4:
    • Context when the app opens: the Android version number, phone or tablet, dark mode on or off, whether the optional on-device model is installed, the app’s interface language and the accent you chose. Never the device model, the brand or any hardware identifier.
    • Scoring speed: how long an attempt took to score, in milliseconds, and whether it was scored on your phone.
    • How the app is used: screens viewed (from a fixed list of the app’s screens); lesson steps reached; audio played (which kind of audio, normal or slow speed, and replaying your own recording, never the recording itself); “Your turn” and review results (recalled, partial, not that phrase, revealed); stories opened (story id and level) and how much of each was read, as a percentage; daily streak length.
    • Settings changed: which setting and its new value, for target language, accent, interface language, phonetic transcription, translations, daily reminder and Wi-Fi-only downloads.
    • Downloads: lesson or model download started, finished or failed (lesson id, size in MB, short error code); on-device model deleted.
    • Errors and crash reports: visible errors by type (scoring failed, offline, not evaluated, microphone, content, audio) and the screen where they appeared; crash reports, sent on the next launch, with only the type of error, the place in the app’s own code where it happened and whether the app closed. Never the error message, what was on screen or anything you typed.
    • Permissions and sign-in: notification permission granted or not; result of signing in with Google (success, cancelled, no account, failed).
  • What each event carries: the installation id, a random session id, the app version, the platform, the language you are learning and the time.
  • What is never included: our server only accepts yes/no values, small numbers and content ids as event details. No audio, no free text, and your IP address is not stored with the events. No advertising ID, IMEI, MAC address, hardware identifier, device model or brand, location, contacts or messages.

Score events. For each attempt scored in the cloud, our server also writes a score event: the score, the level, whether the attempt was mastered, whether audio was used, the number of sounds, the ids of the sound-error rules, the language and the accent, linked to the installation id. When usage statistics are turned off, the app tells our server so with each request and the server does not write these score events either.

Delete my usage data. The button in Settings > Usage statistics immediately erases, on our server, all usage and score events of your installation, including crash reports (see Delete your data).

Usage and score events are kept for a limited period (180 days by default) and are never shared with third parties.

These statistics are also shown in the same self-hosted Umami dashboard as the website analytics, on our own server. There they are linked only to the random installation id, never to your IP address, they are kept for the same 180 days, and Delete my usage data erases them there too.

Accounts and purchases

  • There is no mandatory account. You can use Glosso without signing up, your progress is kept on your device, and the app works fully without signing in.
  • Sign in with Google (optional). It lets you take your account and Beta Founder status to a new phone. When you sign in, our server verifies Google’s ID token and stores only Google’s opaque account identifier (called “sub”), linked to your installation id. We do not store your email, name or photo: the ID token that contains them is used only to verify the sign-in and is not stored. Your email is shown only on your phone.
  • Subscriptions are sold and charged by Google Play. Payment details are handled by Google; Glosso never sees your card details. Our server verifies each purchase with Google and stores the resulting access (plan, status and expiry date) and a hash of the purchase token, linked to your installation id.

Data collection summary

Data type Handled by Glosso Shared with third parties
Audio (voice) Cloud scoring by default: processed in memory, then discarded. Stays on device if the optional on-device model is installed. No
App activity (usage events) Yes: first-party usage and score events (such as lessons, exercises, screens viewed and settings changed), linked to the installation id. Can be turned off in Settings. No
App info and performance (crash logs and diagnostics) From app version 2.5.4: crash reports (only the type of error and the place in the app’s code, never the message) and diagnostics (scoring speed, Android version, phone or tablet), linked to the installation id. Can be turned off in Settings. No
Device or other IDs Yes: a random installation id created by the app. No advertising or hardware ID. No
Location (approximate or precise) No No
Personal info (name, email, address, phone) Only Google’s account identifier, if you choose to sign in with Google. Your email and name are processed only to verify the sign-in and are not stored. No
Financial info Purchase status verified with Google Play (plan, status, expiry). No card data. No
Health and fitness No No
Messages (email, SMS, in-app) No No
Photos and videos No No
Files and documents No No
Calendar No No
Contacts No No
Web browsing history No No
Advertising ID No No

Why we process it, and on what basis

  • Scoring your pronunciation and delivering the course and any Pro features, including the installation id that keeps your plan, Pro access and Beta Founder status, purchase verification and, if you choose it, Google sign-in: to perform the service you asked for (performance of a contract), and our legitimate interest in running and securing the service.
  • Usage statistics, crash reports and score events: our legitimate interest in knowing whether the course works, finding and fixing errors and crashes, and improving it. They are pseudonymous, are not used for advertising and are never shared. You can object at any time: turn them off in Settings > Usage statistics, or contact us.
  • Website analytics: our legitimate interest in knowing which pages are read and where visitors come from, so we can improve the site. It is cookieless and aggregate, stores no IP address and does not track you across sites, so no consent banner is needed; you can block it with any content blocker.

Retention

  • Cloud audio: not retained at all. It is discarded when the scoring request finishes (0 seconds).
  • Usage and score events, including crash reports: purged after the retention window (180 days by default), or immediately when you use Delete my usage data.
  • Installation id records (plan, Pro access and Beta Founder status, the linked Google account identifier and purchase records): kept while they are needed to provide your plan and access, or until you ask us to delete them.
  • Uninstalling the app stops all collection from the app.

Delete your data

  • Usage data, from the app. In Settings > Usage statistics, Delete my usage data erases, on our server, all usage and score events of your installation, immediately. You can also turn usage statistics off there so that nothing new is recorded.
  • Everything else, by email. To delete the rest (the records kept under your installation id: your plan, Pro access and Beta Founder status, the linked Google account identifier and purchase records), write to [email protected] from any address. Tell us roughly when you installed the app and, if you signed in with Google, which Google account you used. We delete the data within 30 days and confirm it to you.
  • Deleting the plan record removes Pro access and Beta Founder status for that device.
  • Google Play keeps its own purchase records under Google’s privacy policy.

Your rights

Under the GDPR and the UK GDPR you can ask to access, correct, delete, restrict or object to the processing of your personal data, and to receive it in a portable form. Write to [email protected]. Cloud audio is not stored, and what we do hold is linked to a random installation id rather than to your name or email, so we may ask you for the details above to find it; if we cannot link a request to any data we hold, we will tell you honestly.

You also have the right to lodge a complaint with a supervisory authority. In Spain this is the Agencia Española de Protección de Datos (AEPD), www.aepd.es, or the authority in your country of residence.

International transfers

Google Play and our hosting provider may process connection or purchase data outside the European Economic Area, including in the United States, under appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

Children

Glosso is not directed at children, and we do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we will remove it.

Security

Scoring traffic uses HTTPS/TLS. We collect as little as possible, store no audio and no email or name, and enforce size and rate limits on the scoring endpoint.


This website

glossostudio.com is a static website. It sets no cookies of its own and does not profile visitors.

  • Analytics. We use Umami, self-hosted on our own server (umami.glossostudio.com), to see aggregate page views and referrers, plus coarse browser, device and country counts and a few interface events such as switching the colour theme. It sets no cookies and stores no IP address: it counts visitors with a hashed identifier that rotates periodically, and it does not track you across sites. The data stays on our server and is never shared. Because it uses no cookies and stores nothing on your device, there is no consent banner. If you would rather not be counted, any content blocker can block it and the site works exactly the same.
  • Fonts and assets are served from this domain. The only script not served from this domain is the Umami tracker, from our own server. There are no third-party advertising or tracking scripts.
  • Hosting. The site is served through Cloudflare Pages. Cloudflare processes connection data, including IP addresses, to deliver the site and protect it from abuse, under its own terms.
  • Interactive demo. The recording demo on the home page is currently disabled. When it is enabled, the single phrase you record is sent to our server only to be scored and is then discarded, exactly like cloud scoring in the app; the demo is capped, needs no account and stores no audio.

TransitOS

TransitOS has its own privacy policy: TransitOS Privacy Policy.

In short: TransitOS has no analytics, no telemetry and no advertising SDKs. It fetches real-time transit data directly from the operator’s public API, and location is used only for the map and never leaves your device.


Changes to this policy

We may update this policy when the product changes. The date at the top shows the latest revision.

Contact

Questions about any of these policies? Write to [email protected] or reach out via github.com/IgnacioLD.