Phonimo privacy notice

Effective date: July 28, 2026

Phonimo is operated by Guilherme Passero. Questions and privacy requests can be sent to support@phonimo.app. Do not include recordings, credentials, account identifiers, or other sensitive information in your message. This notice is publicly available at phonimo.app/privacy.

This notice applies only to the invited Phonimo closed beta. Phonimo's internal and public production versions are not available yet. This notice will be updated before any other version is distributed.

Information we process

The closed beta requires an invited Firebase Authentication identity. Phonimo receives a verified identity token and stores only a SHA-256 digest of its subject with an opaque internal actor ID. It does not store the raw Firebase subject, profile, password, or credential in ordinary product records. Google processes account information needed to provide Firebase Authentication.

When an invited tester starts a recording, the app sends the recording, selected exercise, and identity token to the Phonimo backend. The backend verifies the identity, forwards the audio to Microsoft Azure Speech in West Europe for pronunciation assessment, and returns a technical result. Phonimo does not write audio to its database, logs, or app storage. Assessment sessions and technical results remain in server memory for no more than five minutes.

The beta stores the pronunciation-practice focus and daily time goal selected by the tester, plus local lesson-completion, activity-duration, and derived practice-progress data, in the app's private storage on the tester's device. Changing setup does not remove local learning progress.

Phonimo uses Google Cloud to run the beta backend and database, Firebase Authentication to verify invited identities, Firebase Crashlytics to investigate reliability problems, and Microsoft Azure Speech to assess recordings. Crashlytics receives crash, application-not-responding, and limited device and app-version diagnostic data. It does not receive audio, transcripts, identity tokens, assessment content, or assessment results. These providers process information only to provide their services. Their processing and any international transfers are governed by their applicable terms and data-processing commitments.

The legal basis for beta identity verification and assessment is performance of the features an invited tester chooses to use. The beta does not sell personal information, show advertising, or use analytics.

Retention, deletion, and your rights

Local learning data remains on the tester's device until the app is uninstalled. The opaque actor and subject digest remain until account deletion. Use the in-app account-deletion action to remove beta server data associated with that actor. Firebase account deletion may require a recent sign-in. Assessment audio is not retained by Phonimo, and assessment-session data is removed from memory within five minutes.

If you cannot access the beta app, visit phonimo.app/delete-data and enter the email address used for the invited beta account. Phonimo checks the address with Firebase Authentication in memory and, if it matches an eligible beta account, sends a one-time confirmation link through Resend. Phonimo does not store the email address or link token. A pending request retains only protected, opaque request material and an encrypted Firebase subject for up to 30 minutes. A one-hour SHA-256 email hash is retained only to apply a request limit. Confirming the link permanently deletes the associated Phonimo server data and Firebase account. The same neutral confirmation is shown for every submitted email address.

You may contact us about your privacy rights or lodge a complaint with the Dutch Autoriteit Persoonsgegevens.