Updated September 10, 2026
Privacy Policy
This Privacy Policy explains how Eloquent handles information when you use its apps, website, and support services. The service operator and data controller is Petar Nikolic, based in Serbia (“Eloquent,” “we,” or “us”). Contact us at support@eloquent-app.com.
Who can use Eloquent
Eloquent is a general-audience vocabulary-learning service and does not impose one global minimum account age. Eloquent does not ask for your birth date or country to create an account. If applicable law requires permission from a parent or guardian, you may use Eloquent only with that permission. Store age ratings describe content suitability and support device-level parental controls.
Information we handle
We handle account information such as optional display name, email address, authentication provider identifiers, language and interface preferences; learning content such as saved words, examples, notes, interests, chat messages, generated entries, images, streak and review activity; subscription identifiers, entitlement state, transaction status, and trial-use prevention markers; consent records; support messages, optional diagnostics, and validated image attachments; product-analytics data such as screens visited, navigation, feature interactions, session duration, language, app version, coarse device/platform information, a randomly generated installation identifier, approximate city or country inferred by PostHog from network information, aggregated counters, and AI costs; and limited operational logs needed for security and reliability.
We do not sell personal information or use Eloquent analytics for advertising or tracking across other companies’ apps or websites.
Product analytics and Session Replay
During onboarding, you can approve product analytics and privacy-masked Session Replay together. If you choose the AI-only option, both remain off. When approved, Eloquent sends account-linked, privacy-minimized usage events to PostHog and retains granular first-party usage records in Supabase. PostHog uses the same Eloquent account identifier used by Supabase and RevenueCat so subscription outcomes can be measured without creating separate analytics identities. PostHog acts as our analytics service provider.
A remotely selected sample of eligible mobile sessions may be recorded to understand navigation, diagnose problems, improve the product, and investigate support requests. A replay can capture screen structure, screen changes, navigation, taps or touches, timing, app/platform metadata, and non-content session identifiers. Eloquent configures mobile replay to mask all rendered text and text inputs, images, and embedded platform views. Console-log capture, network-request capture, request and response bodies, and headers are disabled. Native authentication and payment screens are not captured. These protections reduce risk but cannot guarantee that every future interface or third-party component is correctly classified, so we review sensitive screens and keep replay optional.
Passwords, authentication credentials, tokens, payment details, private keys, raw Chat messages, prompts, and other user-authored text are not intentionally sent through Session Replay. Exact Chat feedback content is stored only in restricted Supabase records when needed for the feature and is not included in PostHog analytics events.
How we use information
We use information to authenticate accounts, sync your Library and preferences, provide learning and AI features, process and restore subscriptions, measure and improve product use, diagnose reliability and support issues, prevent fraud and abuse, send reminders you explicitly enable, answer support requests, keep the service secure, and meet legal obligations. Where consent is the applicable legal basis, analytics and Session Replay remain off until consent is recorded.
AI processing
After you give explicit AI-processing permission during onboarding or in Settings, the words, messages, images, and learning context needed for a feature may be sent to OpenRouter for language-model processing and prompt generation, and to ModelsLab for image generation. Chat uses OpenAI’s GPT-5.6 Luna through OpenRouter, with routing restricted to endpoints listed by OpenRouter as zero-data-retention and non-collecting. Chat does not fall back to Meta if that route is unavailable. Other text features use Meta’s Muse Spark Contributor model with OpenAI’s GPT-5.6 Luna as fallback. Meta states that prompts and outputs sent to the Contributor model may be used to improve Meta products. Eloquent sends a request not to store provider responses, does not enable web search, and does not provide tools or plugins to these requests; this does not override a provider’s own data-use terms. These routing restrictions do not delete the chat history you save in Eloquent or operational metadata needed to run the service. We use returned output to provide the feature you requested and to operate abuse, cost, and reliability controls. Eloquent prevents remote AI requests when valid permission is absent. Do not submit secrets or personal information about another person unless you have permission to do so. You can withdraw AI permission in Settings → Privacy. After withdrawal, remote AI generation stops. Your saved Library remains available, and saved content can continue to sync. Withdrawal does not undo processing already completed.
Legal bases
Where the GDPR or similar law applies, we process account, learning, and subscription data to perform our contract with you; security, fraud-prevention, support, and limited operational records for our legitimate interests and those of our users; optional analytics, Session Replay, reminders, and third-party AI sharing based on consent where required; and records we must keep to comply with law. You may withdraw consent at any time without affecting earlier lawful processing.
Service providers and international processing
We use Supabase for authentication, databases, storage, and server functions; PostHog’s EU-hosted service for product analytics and sampled Session Replay; Vercel for the website and web app; RevenueCat and Paddle for subscription and web billing infrastructure; Apple and Google for authentication, app distribution, and mobile purchases; OpenRouter, Meta, OpenAI, and ModelsLab for AI generation; Resend for service and support email; and GitHub for private support issue workflow. These providers may process information in countries outside yours. Where required, we rely on applicable data-processing terms and transfer safeguards, such as adequacy decisions or contractual protections. EU hosting reduces some transfers but does not mean all provider support or subprocessors remain exclusively in the EEA.
Subscriptions
Apple, Google, RevenueCat, and Paddle process payment details. Eloquent receives transaction and entitlement information but does not receive full card details. Deleting Eloquent does not automatically cancel a subscription managed by a store or billing provider.
Retention and deletion
Active account content is retained while your account is active. PostHog Session Replays are configured for up to 30 days. Analytics events are retained while needed for product reporting and reliability and are included in our account-deletion process. Supabase analytics facts are retained as needed for product reporting, cost attribution, security, and recalculation, then deleted or aggregated under our retention process. After an account-deletion request, normal use is blocked and final deletion is scheduled for 30 days, allowing recovery during that period. At the end of the recovery period, Eloquent removes user-owned Supabase Storage objects through the Storage API, deletes the RevenueCat customer record, queues deletion of the PostHog person, events, and recordings, and deletes the Supabase authentication user and cascading account content. Provider deletion jobs and provider-managed backups or archives may complete later under their documented and contractual schedules. Restoring a backup does not authorize renewed use of deleted account data. We retain only a non-reversible marker needed to prevent repeat trial abuse and records required for security, tax, legal claims, or disputes. Store and payment providers may retain transaction records under their own legal obligations. Account deletion does not cancel a subscription.
Your choices and rights
You can enable or decline product analytics and privacy-masked Session Replay together during onboarding. You can later withdraw both in Settings → Privacy; future analytics export and replay collection stop after withdrawal, and locally pending analytics is discarded. Withdrawal does not affect processing already completed before it. You can also withdraw or restore AI permission in Settings → Privacy, access and change many preferences, restore or manage purchases, disable reminders, request a portable copy of your data, and request deletion in the app. Depending on your location, you may also have rights to access, correct, restrict, object, appeal a refusal, or complain to your local data-protection authority. We do not use personal data to make decisions that produce legal or similarly significant effects solely by automated means.
Permissions and device data
Eloquent asks for camera or photo-library access only when you choose to attach an image, and asks for notification permission only when you enable a reminder. Selected attachments are uploaded for the conversation or support request you initiate. Reminder schedules and some preferences are stored locally on your device; synced account content is stored with Supabase. You can change operating-system permissions in device settings.
Policy changes
We may update this policy when the product, providers, or law changes. We will update the effective date and provide additional in-app notice or request renewed consent when a material change requires it.
Security
We use access controls, tenant isolation, private attachment storage, signed links, webhook verification, rate limits, and least-privilege service credentials. No system can guarantee absolute security.
AI-generated content and accuracy
Eloquent uses AI to generate learning content, including definitions, translations, example sentences, related words, fun facts, images, and coaching responses. AI can make mistakes and may produce inaccurate, incomplete, misleading, or outdated content. Generated content is not guaranteed to be correct or individually reviewed by a human. Verify important information with reliable sources, and report errors through Support.
AI permission and optional analytics
Eloquent requires explicit AI-processing permission to complete onboarding and use its AI-powered learning service. You may continue with AI only, leaving optional analytics and Session Replay off. You can withdraw AI permission in Settings; future remote AI requests stop. Existing accounts with saved Library content or recorded app use can access their Library and Word of the Day without an active subscription; AI features require active subscription access and AI permission. Withdrawal does not undo processing already completed by a provider.
Contact
For privacy questions or requests, email support@eloquent-app.com or use Support. Account deletion instructions are available at Account deletion.