SPIK

Privacy Policy

Last updated 1 October 2026 · applies to the SPIK mobile app and the SPIK web admin

SPIK is a speaking-practice app for language learners. Learners call a groupmate and play two short games: guessing a word, then discussing a topic. This policy explains what personal data SPIK handles, why, who else processes it, and how to have it removed.

SPIK is operated by Shokhrukh Nasirov, Uzbekistan (“we”, “us”). Questions and requests: contact@spik.uz.

Accounts are created by the educational institute

Nobody signs up on their own. An educational institute enters its teachers, volunteers and students in the SPIK admin, and the person then signs in with their email address and a six-digit code we send to it. The institute decides who gets an account and what is entered about them, and is responsible for having the right to provide that data to us — including, where a learner is a child, the consent of a parent or guardian.

What we collect

DataWhoWhy
Email addressEveryoneSigning in (the six-digit code is emailed to it) and service messages
Name and surnameEveryoneShown to groupmates and staff so people recognise each other
Chosen avatarEveryoneShown next to the name. Avatars are drawings shipped with the app, not uploaded photos
Phone numberManagers, teachersContact between the institute and us
Age, gender, English levelStudentsEntered by the institute to group learners and pick suitable material
Institute and groupStudents, staffDecides whom a learner can call and whose content they see
Role and account statusEveryoneWhat a person may do in the app and the admin
Online or offline statusStudentsShown to groupmates so they know who can talk right now. Kept only while the app is connected
Call records: who called whom, when, how longStudentsRunning a call, and ending calls that were never answered
Sign-in codes and session tokensEveryoneSigning in and keeping you signed in. Codes are stored only as a hash and expire within minutes; tokens are stored only as a hash
IP address and device/browser identification, stored with a sessionEveryoneTelling sessions apart and looking into suspicious sign-ins

We do not ask for a home address, do not collect location, do not read contacts, and do not use the camera. Learners cannot upload photos of themselves.

Voice calls

A call is carried in real time by Agora, a voice-calling service, over servers in the European Union. We do not record calls and neither party can record them in the app. The audio passes through and is gone. The microphone is used only during a call, and the app asks for permission the first time.

While a call is running, Android shows a permanent notification. That is required by the system: it is what allows the call to keep working when the app is in the background.

Learning material

Words, topics and their pictures are entered by the institute's staff in the admin, not by learners. Pictures are stored in Cloudflare R2. Pronunciation audio is produced by Microsoft Azure's text-to-speech from the word itself — only the word is sent, never anything about a person.

Who else processes the data

We use a small number of services, each for one job, and none of them may use the data for their own purposes:

ServiceWhat it handlesWhere
HetznerOur servers and databaseGermany
AgoraLive call audioEuropean Union
Cloudflare R2Pictures and pronunciation audio of wordsEuropean Union
ResendSending the six-digit sign-in code by emailEuropean Union
Microsoft Azure SpeechReading a word aloud (word text only)United States
Cloudflare Workers AISuggesting pictures for words and topics, in the admin only (the word or topic text only)Cloudflare network
Google PlayDistributing the app and its updatesGoogle infrastructure

What we do not do

What the app keeps on your phone

How long we keep it

Account data stays while the institute keeps the account. Sign-in codes expire within minutes and session tokens when the session ends or is replaced. Call records are kept while they are needed to run and support the service.

Deleting an account or its data

Ask your institute first: staff can deactivate an account in the admin. You can also write to contact@spik.uz from the email address of the account and ask for the account and its data to be deleted. We answer within 30 days and tell you what was removed. Records we must keep by law, where any apply, are kept and nothing else.

Your rights

You can ask what we hold about you, have it corrected, have it deleted, or object to how it is used. Write to contact@spik.uz. If a request comes through an institute, we will act on it only for accounts that institute manages.

Children

SPIK is used by learners of any age, including children, through their educational institute. We do not knowingly let a child create an account directly — accounts exist only because an institute created them, and obtaining a parent's or guardian's consent is the institute's responsibility. A parent or guardian may write to contact@spik.uz to see or delete a child's data, and we act on it the same as any other request.

Security

Traffic between the app and our servers is encrypted (HTTPS and WSS). Sign-in codes are stored only as a hash and expire within minutes; a wrong code can be tried a limited number of times. Session tokens are stored only as a hash, expire, and are revoked when you sign out. What each person may see depends on their role, and staff see only the institute they belong to. No measure is perfect: if a breach puts personal data at risk, we will tell the people affected and their institute.

Changes

If this policy changes in a way that matters, we will update the date at the top and, for a significant change, tell account holders by email.