Privacy Policy
Last updated: 10 August 2026
This Privacy Policy explains how Abika ("we") collects, uses and protects personal data when you use Abika. We are the data controller for this processing.
1. Data we collect
Account data: your name and email address (provided directly or via Google Sign-In).
Voice data: the voice recordings you record or upload. Voice recordings can be used to identify a person and may constitute biometric data; we process them only with your explicit consent (see section 4).
Content data: story text and audio narrations you create.
Voice-verification data: the text you say is contained in an uploaded recording, an automated speech-to-text transcript, a similarity score, and whether you manually confirmed a recording after an automated check did not pass.
Usage and analytics data: events such as voice uploads and generation of story text or audio, together with the associated account ID and time. These analytics events do not contain story text or audio recordings.
Diagnostic data: crash reports, stack traces, technical error details, performance information, app and operating-system versions, device model, and network information such as an IP address where supplied by the device or diagnostic provider.
Payment data: we do not store your card details. Payments are handled by Creem (Merchant of Record), which processes your billing information under its own privacy policy.
2. How we use data
To provide and operate the Service (including verifying recordings, creating voices and narrations, and managing your account); to process payments; to measure feature usage; to diagnose crashes and performance problems; to maintain security and prevent abuse; to communicate with you about the Service; and to comply with legal obligations.
3. Legal bases
Where the GDPR applies, we rely on: performance of our contract with you (providing the Service); your consent (for processing voice/biometric data); our legitimate interests (security, improving the Service); and compliance with legal obligations.
4. Voice data and consent
We process your voice recordings to generate spoken narrations. Because voice can identify a person, we ask for your explicit consent before you upload or record a voice, and you must confirm you have the right to use that voice. You can withdraw consent at any time by deleting the voice or your account; withdrawal does not affect processing already carried out.
Before a voice is saved, we may send the recording to our speech-to-text provider to check it against the text you expected to be spoken. We record the expected text, resulting transcript, similarity score and any manual override in an access-controlled consent journal.
5. Service providers and sharing
We share data with providers who help us run the Service, under appropriate data-processing terms: Supabase (authentication, database and file storage), Vercel (hosting and privacy-friendly, cookieless web analytics), Google (OAuth sign-in), OpenAI (AI generation of story text), RunPod (voice synthesis and speech-to-text used to process recorded voices and generate narrations), Sentry (mobile-app crash reporting and performance diagnostics), and Creem (payment processing, as Merchant of Record). Some of these providers operate outside your country — see “International transfers” below. We do not sell personal data or use it for targeted advertising.
6. Retention
We keep account data, voices and content while your account is active or as needed to provide the Service. You can delete individual voices and content at any time. Deleting a voice removes its stored audio file and prevents further use.
When a voice or account is deleted, we retain an access-controlled consent record so that we can demonstrate when and on what basis the voice was provided and respond to legal claims. The record may include an internal account identifier, consent date and type, policy version, technical client information, expected text, speech-to-text transcript, similarity score, manual-override status and deletion date. It does not retain the voice recording itself. We retain this record only for as long as reasonably necessary for these legal and compliance purposes.
When you delete your account, other personal data is deleted or anonymised within a reasonable period, except where retention is necessary for legal obligations or claims. Analytics events are retained without the account identifier. We also retain a one-way salted hash derived from your email address for up to 12 months solely to prevent repeated claiming of the free allowance; we cannot use that hash to contact you and it contains no other account information.
Crash and performance diagnostics are retained for a limited period necessary to investigate reliability and security issues, subject to our diagnostic provider’s retention settings.
7. International transfers
Your data may be processed in countries other than where you live. Where required, we use appropriate safeguards for such transfers.
8. Your rights
Subject to applicable law, you may have the right to access, correct, delete or export your data, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, contact us at the address below. You may also complain to your local data-protection authority.
9. Children
The Service is for adults. We do not knowingly create accounts for children. Parents and guardians are responsible for any content created for children to listen to.
10. Cookies and local device storage
We use only strictly necessary cookies: Supabase authentication cookies (prefixed “sb-”) to keep you signed in, and preference cookies that remember your language (“locale”) and display theme (“theme”). To understand and improve usage we use Vercel Web Analytics, which is cookieless and does not set tracking identifiers. We do not use advertising or third-party tracking cookies, so no cookie-consent banner is required.
In the mobile app, authentication credentials are stored in the device’s protected storage. The app also stores preferences locally, including interface and library language, theme, and the child-age library filter. The child-age filter remains on the device and is not sent to our servers. Local preferences can be removed by clearing the app’s data or uninstalling it.
If you choose to share a narration, the mobile app creates a temporary local copy and passes it to the operating system’s sharing interface. Any recipient app you select processes the file under its own privacy terms.
11. Security
We use reasonable technical and organisational measures to protect your data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Changes and contact
We may update this Policy and will revise the "Last updated" date. Contact: Abika, Georgia, support@abika.org.