Legal

Privacy Policy

Last updated: September 16, 2026

Introduction

TraceSpark ("we," "us," or "our") is an independent language learning application built in Wellington, New Zealand. We are committed to protecting your privacy. This policy explains what data we collect, our legal basis for processing it, how we use it, and your statutory rights regarding that data under international frameworks like the GDPR and CCPA.

1. Data Stored on Your Device

TraceSpark is designed with a local-first architecture. Your captured vocabulary, generated story and audiobook content, spaced repetition scheduling data, and app preferences are stored primarily in a local database on your device, and that remains the primary copy of your data. We do not maintain a centralized backup or archive of your full library.

We do hold two small records about you on our own servers. The first is your account, described in Section 4. The second is an audio usage record: each time you generate audio, our servers store the time that generation started, the number of bytes of text sent for synthesis, and a one-way hash of each block of that text. We use it to apply a weekly audio limit and to avoid charging your allowance twice when a block is retried. It holds no story text, no vocabulary and no audio.

Some of this data is also transmitted off-device as part of how the app works: to generate your stories and audio (see Section 2) and to help us understand app usage and diagnose problems (see Section 3). Section 2 and Section 3 describe exactly what leaves your device, to whom, and why.

It is your responsibility to secure your device and use your operating system's backup mechanisms. If you lose your device without a backup, your local library cannot be recovered from us.

2. Third-Party Services & International Transfers

The app transmits data to a small number of third-party services to do its job and to help us run the business. Because we are based in New Zealand and these providers are based in the United States, this involves the international transfer of data, which is governed by Standard Contractual Clauses (SCCs).

  • Google Vertex AI (Gemini models): The words, phrases and context you capture, your selected narrative preferences, and the messages you send to the in-app Companion are sent to Google's Vertex AI to generate story and podcast content and to translate and explain what you capture. If you share a photo or screenshot into TraceSpark to capture a word from it, that image is sent to Vertex AI as well, directly from your device. We do not store the image and it does not pass through any server of ours.
  • Our audio service, running on Google Cloud: When you generate audio, the story text goes first to a service we operate ourselves on Google Cloud, and that service calls Google's Vertex AI to synthesise the speech. It does not store your text. It writes the audio usage record described in Section 1, and returns the audio to your device.
  • Firebase (Google): We use Firebase Authentication for Google Sign-In (Section 4), Cloud Firestore for the audio usage record in Section 1, Firebase Remote Config for settings we can change without shipping an app update, and Firebase Crashlytics for crash reports. A crash report carries the error, where in the app it happened, and your device model and app version. We do not tell Crashlytics who you are, so crash reports are not linked to your account.
  • Supabase (Database): Your email address and user ID are stored in a database hosted by Supabase, alongside your legacy waitlist entry if you joined our pre-launch waitlist. See Section 4.
  • PostHog (Product Analytics): We use PostHog to understand how the app is used and to diagnose generation failures. This shares structured usage data (which features you use, whether a generation succeeded, your selected language and level, and similar events) with PostHog. See Section 3 for exactly what is and is not included in that data.

We do not sell your data to any of these providers, and none of them are permitted to use it for their own purposes. The processing is strictly necessary to provide the core functionality of the app (Performance of a Contract) or to understand and improve it (Legitimate Interest).

3. Analytics & Usage Data

We use PostHog for analytics, and how it is configured differs between our marketing website and the app, because the two work differently.

On this website, PostHog runs in Cookieless Mode (‘persistence: memory’). We do not store cookies or other tracking technology in your browser, and we do not connect your visits to one another. Each browsing session is anonymous. What PostHog records is which pages you open, when you leave a page and how far down it you scrolled, and clicks on links and buttons.

When you tap a Google Play button on this website, we add a short note to the Play Store link: which page and campaign you came from, and a random code made for that one click. We record the same code with the click. If you then install the app, Google Play passes the note to the app, which records it once with your install. This shows us which pages lead to installs. The code is random, is not stored in your browser, and does not identify you.

One exception, for browsers that opt in. Opening a link ending in ?internal=1 marks that one browser as ours and switches it to localStorage, so its visits are recognised across sessions and can be excluded from our figures. We use it on our own browsers so that our testing does not distort them. Opening ?internal=0 turns it off again and clears what was stored. Nothing marks a browser this way except opening that link in it.

In the app, this is different: once you sign in, your activity is associated with your account so that we can understand your usage over time and diagnose problems specific to your account if you report one. This includes which features you use, whether a story or audio generation succeeded or failed and why, your selected language and proficiency level, and similar structured events. Errors that crash the app are captured here too, against your account. Our analytics provider also automatically attaches your device type. It does not attach your location: we have switched off its location lookup, so your network address is not turned into a city, region or country, and no location is stored against your activity. The app also records, once, how it was installed: through a link on our website (with that link's code), directly from the Play Store, or unknown.

What we do not send to analytics: the actual words, phrases, or definitions you capture, the text of your generated stories or audiobook chapters, and any image you share into the app. That content is handled as described in Section 1 and Section 2 only.

What you write to us does go to analytics. Two things are sent to PostHog with your account attached, and both are optional: the text you type into the app's feedback box, and your answers to in-app surveys. Reporting a piece of generated content sends the reason you picked and the identifier of the item, without any of its text.

Our legal basis for this processing is Legitimate Interest in operating and improving the app, balanced against the scope of what we collect as described above.

4. Your Account, Email & Pre-Launch Waitlist (Data Retention)

Your account. TraceSpark requires an account, and signing in with Google is the only way to create one. There is no guest mode. When you sign in, Firebase Authentication holds your email address, your Google display name and a user ID for you, and the app sends your email address and user ID to our own database at Supabase so that we can recognise you and match you to your legacy waitlist entry if you have one. Our legal basis is Performance of a Contract: without an account the app cannot generate anything for you. Account data is kept for as long as the account exists, and Section 5 explains how to delete it.

Our pre-launch waitlist. TraceSpark has been publicly available on Google Play since September 10, 2026. Before that, we ran a waitlist and collected email addresses, based on your explicit Consent, from people who wanted to hear from us before the public launch. That waitlist is closed: the app is not gated behind it, there is no signup form for it anywhere on this site, and you cannot join it today.

Data Retention & Erasure: We still hold a small number of email addresses from people who joined the waitlist before launch. We keep those addresses only until you ask us to delete them or withdraw your consent, whichever comes first. You may request removal at any time by replying to our emails or contacting us directly using the details in Section 7, at which point your data will be permanently deleted.

5. Your Statutory Rights (GDPR & CCPA)

Depending on your location, you may have specific rights regarding your personal data:

  • Right to Access: You can request a copy of the personal data we hold about you.
  • Right to Rectification: You can request that we correct inaccurate data.
  • Right to Erasure ("Right to be Forgotten"): You can request that we delete your data.
  • Right to Restrict Processing: You can ask us to limit how we use your data.
  • Right to Data Portability: You can request your data in a structured, machine-readable format.

How to Exercise These Rights: for your local library (captured vocabulary, generated stories and audio, and scheduling data) you can access, edit, export and permanently erase it in the app, since that data lives on your device. For your account and the audio usage record in Section 1, use Delete Account, described below. For anything else, including a copy of the data we hold and removal of your analytics history, email us at the address in Section 7.

Deleting your account: in the app, open Settings, then Account, then Delete Account. From a browser, with or without the app installed, go to tracespark.app/account/delete. Either route removes your Firebase Authentication record, your row in our Supabase database, your legacy waitlist entry and your audio usage record, and it cannot be undone. The in-app route also erases the library on that device. Deleting from the web cannot reach a phone that still has the app installed, and neither route removes your analytics history, so write to us if you want that deleted too.

6. Governing Law & Updates

This Privacy Policy and our data practices are governed by the laws of New Zealand, without regard to its conflict of law provisions.

We may update this policy periodically. Changes will be posted on this page with an updated "Last updated" date. We encourage you to review this policy periodically.

7. Contact Us

If you have any questions about this privacy policy, wish to exercise your statutory rights, or want your legacy waitlist entry removed, please contact our Data Protection Officer at: hello@tracespark.app