Privacy Policy
Last updated: 3 August 2026
1. Who is the data controller
The controller of personal data processed through Speak·Meet·Travel (the “App”) is Norbert Czarnek, conducting business activity in Poland under the firm APQART NORBERT CZARNEK (NIP 6772275303, REGON 383714501), with registered place of business at ul. Morelowa 4A/5, 30-222 Kraków, Poland (“we”, “us”, or “our”). Privacy questions can be sent to contact [at] apqart.com.
2. What we collect and why
The exact data depends on the modules and optional features you use.
2.1 Account and identity data
- Account identifier. Firebase Authentication assigns a stable user ID, including for an initial anonymous session, so App data can be associated with the correct account.
- Sign-in information. Depending on the method you choose, this can include your email address, Apple user identifier, and an Apple private relay email address. We do not receive your Apple ID password or payment-card details.
- Name and phone number. A display name is used for your profile. A phone number is collected only when you choose to enable Meet and complete its phone-verification step.
- Date of birth and gender. Date of birth is used to enforce Meet's 18+ gate and display age. Gender can be used in the Meet profile and to adapt grammatical lesson variants. These values are linked to your account.
- Language and interface preferences, including your selected app language and notification preferences.
2.2 Speak — learning data
- Languages and proficiency levels you select.
- Lesson and word progress, answers, scores, review state, streaks, and completion history.
- Short pronunciation recordings used by Apple speech recognition as described in section 5.
2.3 Meet — profile, location, verification, and communication data
- Meet profile. Profile photos, first name, age, gender, city, biography, interests, languages, prompt answers, and verification status. The public-safe part of this profile is shown to eligible signed-in Meet users.
- Location. When you grant permission and use Meet, the App requests a one-time location update while open and stores latitude, longitude, a geohash, and update time. Apple treats these coordinates as precise location for privacy disclosure. Eligible Meet users receive the protected profile location needed for their device to calculate distance; the App displays distance rather than your coordinates. We do not collect location in the background.
- Social activity. Swipes, likes, matches, blocks, reports, online/presence state, and related timestamps used to provide matching, safety, and notifications.
- Profile verification. If you choose verification, the App records a short, silent front-camera video while asking you to turn your head left and right. On-device face detection checks framing and movement; the video is then uploaded to a private Firebase Storage location and compared with your profile photo by an authorised reviewer. This is a moderation aid, not certified anti-spoofing, legal-identity verification, or proof of age. Other users see only the verification result, never the video.
- Chats. Text messages, replies, reactions, sent photos, voice messages, message timestamps, read state, and technical waveform/duration information. Chat content is available to the two chat participants and, where necessary, authorised administrators handling safety or support matters. Sent chat photos are checked by Google Cloud Vision SafeSearch before they are published to the other participant.
- Safety reports. The reporting user, reported user, selected reason, optional explanation, status, moderation timestamps, and a bounded copy of the newest chat context are stored so we can investigate abuse, prevent repeated harm, and enforce our Terms. The evidence copy contains at most 50 recent messages and five recent media files.
2.4 Travel — trips, contacts, and searches
- Saved trips. Destination, dates, title, notes, budget, mobility preferences, phrasebook progress, and other planning details you enter.
- Trip companions. If you grant Contacts access, the App reads names, phone numbers, and email addresses on-device to display the picker. Unselected contacts are not uploaded. When you select a contact as a trip companion and save the trip, that contact's name and available phone number or email are stored with your trip. Do not add another person's details unless you are entitled to do so.
- Travel searches. Flight or accommodation search parameters such as origin, destination, dates, and number of travellers/rooms are sent to the relevant travel provider to return results. We do not add your Firebase user ID to these provider requests. If you continue to an external booking flow, the provider processes information you enter there under its own privacy policy.
- Destination interactions. Destination views can be counted in aggregate to rank popular content. The ranking record does not store your user ID.
2.5 Subscription and purchase data
- Product identifier, entitlement status, purchase/renewal/expiry timestamps, store, country, price/currency information, and cancellation or refund state supplied by Apple through RevenueCat.
- Apple processes payment credentials. We do not receive your full card or bank-account details.
2.6 Device, notification, diagnostics, and usage data
- A device-scoped identifier, APNs/FCM notification token, app version, iOS version, device model, locale, and short-lived presence state used to deliver and suppress notifications correctly.
- Crash reports, error logs, stack traces, and related diagnostic information used to operate, secure, and improve the App.
- Feature interactions linked to your account where they are part of saved progress or service operation. We do not use this information for advertising or cross-app tracking.
2.7 Data kept only on your device
Some interface preferences, filters, downloaded lesson audio, and caches are stored locally using iOS storage. Local data is not “collected” by us unless another feature explicitly sends it to our service. You can remove local data by using the relevant in-app control or deleting the App from the device.
3. Legal bases (GDPR)
- Contract (Art. 6(1)(b)) — to create and operate your account, synchronise learning, save trips, provide Meet, deliver chats and notifications, and manage subscriptions.
- Consent (Art. 6(1)(a)) — for optional access and processing such as location sharing, contact-book access, camera/photos, microphone/speech recognition, and notifications where consent is the applicable basis. You can withdraw consent as described below.
- Legitimate interests (Art. 6(1)(f)) — service security, fraud and abuse prevention, moderation, crash diagnosis, reliability, and aggregated product improvement. We balance these interests against your rights.
- Legal obligation (Art. 6(1)(c)) — for tax, accounting, consumer protection, lawful requests, and other mandatory records.
4. Device permissions and your choices
- Location: requested when you enter the Meet location flow. Turn off sharing in the App to remove the stored profile location, or revoke Location access in iOS Settings. Meet distance features will be unavailable.
- Contacts: requested only after you choose to synchronise contacts in the companion picker. Revoking access stops future reads. Contacts already selected and saved with a trip remain until you remove them, delete the trip, or delete your account.
- Camera and Photos: used only when you choose a profile/chat image, take a chat photo, or deliberately record a verification video. Selected or captured media is uploaded only after your action.
- Microphone and Speech Recognition: used for pronunciation exercises or when you deliberately record a voice message. You can deny or revoke access; non-voice features remain available.
- Notifications: optional. You can change permission in iOS Settings and change supported notification preferences in the App.
iOS permissions can be changed under Settings → Apps → SpeakMeetTravel. Account-linked data can also be removed through the controls described in sections 10 and 11.
5. Voice and speech recognition
5.1 Speak pronunciation exercises
The App records a short pronunciation sample and passes it to Apple's Speech framework to produce a transcript. When the selected language and device support on-device recognition, the App requires that mode. Otherwise Apple may process the audio on its servers under Apple's Speech & Dictation policy.
- Pronunciation recordings are not uploaded to our Firebase Storage or retained by us.
- The recording is released after the exercise finishes or is cancelled.
5.2 Chat voice messages
Chat voice messages are different: after you deliberately record and send one, the audio file is uploaded to Firebase Storage and made available to the other chat participant. It remains until the chat is removed through unmatching/reporting, the account is deleted, or retention is otherwise required for a legal or safety matter.
6. How data is shared
- Other users: eligible Meet users can see your public-safe Meet profile and the distance calculated from profile location data. A matched chat partner can see the content you send. Exact coordinates and verification videos are not displayed in the interface.
- People you add to trips: companion details are stored privately with your trip and are not published as a Meet profile.
- Authorised staff: limited access may be used to compare verification videos with profile photos, handle safety reports and support, prevent fraud, and operate the service.
- Service providers: providers listed below receive only the information needed for their function.
- Legal and safety disclosures: information may be disclosed when required by law or when reasonably necessary to protect users, rights, safety, or the service.
We do not sell or rent personal data.
7. Service providers
Providers are required by their applicable terms and data-protection arrangements to protect information and process it only for the relevant service. Not every provider receives every data category.
- Google LLC (Firebase and Google Cloud) — Authentication, Firestore, Cloud Storage (including SpeakMeetTravel-owned destination imagery), Cloud Functions, push messaging, Crashlytics diagnostics, and SafeSearch screening of sent chat photos. Privacy information.
- Apple Inc. — Sign in with Apple, Speech, StoreKit/App Store payments, APNs notifications, and platform permissions. Privacy Policy.
- RevenueCat, Inc. — receipt validation, entitlement management, subscription lifecycle webhooks, and customer subscription tools. Privacy Policy.
- Twilio SendGrid — transactional emails such as a subscription cancellation confirmation, using the destination email address and message content. Privacy Notice.
- Duffel Ltd — flight search results and an external flight booking flow. Privacy Policy.
- Stay22 Technologies Inc. — accommodation search results, affiliate attribution, and redirects to external booking partners. Privacy Policy.
- ElevenLabs, Inc. — generation of developer-authored lesson audio. We send lesson text, not your voice, profile, chats, or contact book. Privacy Policy.
8. International data transfers
Some providers process data outside Poland or the European Economic Area. Where a transfer requires safeguards, we rely on an adequacy decision, an applicable EU–US Data Privacy Framework certification, Standard Contractual Clauses, or another lawful transfer mechanism. Provider documentation linked above contains additional details.
9. Retention
- Account, profile, learning, and trip data: retained while the account exists or until you remove the relevant content.
- Location: replaced by a newer update and removed when you turn off Meet location sharing or delete the account.
- Selected companion details: retained with the saved trip until the companion or trip is removed, or the account is deleted.
- Chats and media: retained while the chat exists and removed when the relationship/chat is torn down through unmatching or account deletion. When a user files a safety report, a private copy of up to 50 recent messages and five recent media files is retained for authorised review for up to 180 days.
- Verification video: retained in a restricted location while needed to document and resolve the verification request, until replaced by a later submission, earlier deletion on request where possible, or account deletion.
- Safety reports and moderation records: the report audit record may be retained for as long as reasonably necessary to investigate, prevent repeat abuse, resolve disputes, and establish or defend legal claims. The copied chat evidence attached to it is automatically purged after 180 days.
- Purchase and transaction records: retained for the period required by tax, accounting, chargeback, and consumer-protection law, commonly five years under applicable Polish record-keeping rules.
- Crash and diagnostic data: retained under our processor settings and normally deleted or aggregated when no longer needed; Crashlytics records are typically kept for up to 90 days.
- Deletion feedback and aggregate statistics: a selected deletion reason and optional text can be retained without the Firebase user ID for product improvement. Aggregated destination/revenue metrics that no longer identify a user can be retained.
- Backups and processor copies: residual copies can remain for a limited backup cycle, normally no longer than 30 days after deletion, unless a longer period is legally required.
10. Your rights
Subject to applicable law, you can:
- Access your personal data and receive a portable copy.
- Correct inaccurate or incomplete data.
- Request deletion or restriction of processing.
- Object to processing based on legitimate interests.
- Withdraw consent without affecting processing that occurred before withdrawal.
- Lodge a complaint with the Polish Personal Data Protection Office (UODO) at uodo.gov.pl, or another competent supervisory authority.
Send requests to contact [at] apqart.com. We normally respond within one month.
11. Deleting your account
Delete the account inside the App under Settings → Account → Delete account, or contact us. If an active subscription exists, the App lets you delete immediately or schedule deletion for the end of the paid period. You can cancel a scheduled deletion before it runs.
Account deletion removes or schedules removal of:
- the Firebase Authentication account and account/profile documents;
- learning progress, saved trips, selected companion data, push tokens, presence state, swipes, likes, matches, and blocks;
- Meet profile and verification records, profile photos, and verification videos;
- active chats, message documents, chat photos, and chat voice files; and
- the linked RevenueCat subscriber record where the provider operation succeeds.
Deleting the account does not automatically cancel an App Store subscription, which is controlled by your Apple ID. Manage it in iOS Settings → your Apple ID → Subscriptions. When Sign in with Apple is used, the App also attempts to revoke its Apple authorisation token.
We can retain limited transaction, safety, legal, security, de-linked feedback, and aggregated records described in section 9. If an automated deletion step fails, the account identity is kept long enough to retry safely rather than leaving private files with no recovery path.
12. Age requirements
12.1 Speak and Travel (13+)
Speak and Travel are intended for people aged 13 and older. If you are below the digital-consent age in your country (for example, 16 in Poland), use the App only with a parent or guardian's involvement where required by law.
12.2 Meet (18+ only)
Meet is an adult social matching feature and is available only to users aged 18 or older. The App requires a date of birth and blocks Meet when the age requirement is not met. By enabling Meet, you confirm that your date of birth is accurate.
12.3 Children under 13
We do not knowingly permit children under 13 to create an account or provide personal data. If you believe a child under 13 has done so, contact us and we will investigate and delete the information without undue delay.
13. Security
We use safeguards including TLS in transit, Firebase access rules, restricted administrator roles, short-lived authentication tokens, server-side validation, private immutable storage paths for verification videos, and password hashing managed by authentication providers. No method of storage or transmission is perfectly secure, so absolute security cannot be guaranteed.
14. Advertising and tracking
The App does not contain third-party advertising, does not sell personal data, does not access the advertising identifier for behavioural advertising, and does not track you across apps or websites owned by other companies. Data is used for App functionality, safety, diagnostics, personalisation you request, and aggregated service improvement.
15. Changes to this policy
We may update this policy when the App, providers, or legal requirements change. The date at the top identifies the latest version. Material changes will be communicated in the App or by another appropriate channel before they take effect where required.
16. Contact
Privacy questions and data-subject requests:
contact [at] apqart.com
App support: support@speakmeettravel.com
Norbert Czarnek
trading as APQART NORBERT CZARNEK
ul. Morelowa 4A/5, 30-222 Kraków, Poland
NIP 6772275303 · REGON 383714501