Privacy Policy
SPIK is a speaking-practice app for language learners. Learners call a groupmate and play two short games: guessing a word, then discussing a topic. This policy explains what personal data SPIK handles, why, who else processes it, and how to have it removed.
SPIK is operated by Shokhrukh Nasirov, Uzbekistan (“we”, “us”). Questions and requests: contact@spik.uz.
Accounts are created by the educational institute
Nobody signs up on their own. An educational institute enters its teachers, volunteers and students in the SPIK admin, and the person then signs in with their email address and a six-digit code we send to it. The institute decides who gets an account and what is entered about them, and is responsible for having the right to provide that data to us — including, where a learner is a child, the consent of a parent or guardian.
What we collect
| Data | Who | Why |
|---|---|---|
| Email address | Everyone | Signing in (the six-digit code is emailed to it) and service messages |
| Name and surname | Everyone | Shown to groupmates and staff so people recognise each other |
| Chosen avatar | Everyone | Shown next to the name. Avatars are drawings shipped with the app, not uploaded photos |
| Phone number | Managers, teachers | Contact between the institute and us |
| Age, gender, English level | Students | Entered by the institute to group learners and pick suitable material |
| Institute and group | Students, staff | Decides whom a learner can call and whose content they see |
| Role and account status | Everyone | What a person may do in the app and the admin |
| Online or offline status | Students | Shown to groupmates so they know who can talk right now. Kept only while the app is connected |
| Call records: who called whom, when, how long | Students | Running a call, and ending calls that were never answered |
| Sign-in codes and session tokens | Everyone | Signing in and keeping you signed in. Codes are stored only as a hash and expire within minutes; tokens are stored only as a hash |
| IP address and device/browser identification, stored with a session | Everyone | Telling sessions apart and looking into suspicious sign-ins |
We do not ask for a home address, do not collect location, do not read contacts, and do not use the camera. Learners cannot upload photos of themselves.
Voice calls
A call is carried in real time by Agora, a voice-calling service, over servers in the European Union. We do not record calls and neither party can record them in the app. The audio passes through and is gone. The microphone is used only during a call, and the app asks for permission the first time.
While a call is running, Android shows a permanent notification. That is required by the system: it is what allows the call to keep working when the app is in the background.
Learning material
Words, topics and their pictures are entered by the institute's staff in the admin, not by learners. Pictures are stored in Cloudflare R2. Pronunciation audio is produced by Microsoft Azure's text-to-speech from the word itself — only the word is sent, never anything about a person.
Who else processes the data
We use a small number of services, each for one job, and none of them may use the data for their own purposes:
| Service | What it handles | Where |
|---|---|---|
| Hetzner | Our servers and database | Germany |
| Agora | Live call audio | European Union |
| Cloudflare R2 | Pictures and pronunciation audio of words | European Union |
| Resend | Sending the six-digit sign-in code by email | European Union |
| Microsoft Azure Speech | Reading a word aloud (word text only) | United States |
| Cloudflare Workers AI | Suggesting pictures for words and topics, in the admin only (the word or topic text only) | Cloudflare network |
| Google Play | Distributing the app and its updates | Google infrastructure |
What we do not do
- No advertising, and no advertising or tracking SDKs in the app.
- No analytics about how you use the app.
- We never sell personal data or share it for anyone else's marketing.
- No automated decisions about a person and no profiling.
What the app keeps on your phone
- Sign-in tokens, in the operating system's encrypted storage.
- Your app settings.
- Pronunciation audio of recent words, cached in temporary storage so a word plays instantly. Clearing the app's storage removes it.
How long we keep it
Account data stays while the institute keeps the account. Sign-in codes expire within minutes and session tokens when the session ends or is replaced. Call records are kept while they are needed to run and support the service.
Deleting an account or its data
Ask your institute first: staff can deactivate an account in the admin. You can also write to contact@spik.uz from the email address of the account and ask for the account and its data to be deleted. We answer within 30 days and tell you what was removed. Records we must keep by law, where any apply, are kept and nothing else.
Your rights
You can ask what we hold about you, have it corrected, have it deleted, or object to how it is used. Write to contact@spik.uz. If a request comes through an institute, we will act on it only for accounts that institute manages.
Children
SPIK is used by learners of any age, including children, through their educational institute. We do not knowingly let a child create an account directly — accounts exist only because an institute created them, and obtaining a parent's or guardian's consent is the institute's responsibility. A parent or guardian may write to contact@spik.uz to see or delete a child's data, and we act on it the same as any other request.
Security
Traffic between the app and our servers is encrypted (HTTPS and WSS). Sign-in codes are stored only as a hash and expire within minutes; a wrong code can be tried a limited number of times. Session tokens are stored only as a hash, expire, and are revoked when you sign out. What each person may see depends on their role, and staff see only the institute they belong to. No measure is perfect: if a breach puts personal data at risk, we will tell the people affected and their institute.
Changes
If this policy changes in a way that matters, we will update the date at the top and, for a significant change, tell account holders by email.