Privacy Policy
Last updated and effective: 2 August 2026
This policy explains what personal data Filomou (“Filomou”, “we”, “us”) collects when you use the Filomou mobile app and this website, why we collect it, who we share it with, and the rights you have over it.
1. Who is responsible for your data
The controller of your personal data is:
- Adam Daghmah, trading as Dev.Enkrio, a Dutch sole proprietorship (eenmanszaak), at Brouwhuis 52, 1695 JS Blokker, the Netherlands
- Chamber of Commerce (KVK) number: 42061187
- VAT identification number: NL005465302B85
- Privacy contact: privacy@filomou.com
Dev.Enkrio is operated by one person. We have not appointed a formal Data Protection Officer because we currently do not consider the statutory appointment thresholds met. The proprietor is the privacy contact and periodically reassesses this as the service grows.
2. Data we collect
2.1 Account data
When you create an account we receive, from you or from your chosen sign-in provider (Apple, Google, or email and password): your email address, whether that email is verified, the sign-in provider you used, and a display name if your provider supplies one. We generate an internal account identifier for you. We never receive or store your provider password.
If you use Sign in with Apple and choose to hide your email, we only ever see Apple’s private relay address.
2.2 Learning profile
What you tell us during onboarding and in settings: the language you are learning, your native language, your goals, your interests, your self-assessed level, and anything you write in the free-text “about you” step. We also store what we infer from your use of the app: your placement result and CEFR level, lesson and scenario progress, saved vocabulary, streaks and activity dates, and the times of day you have asked your buddy to call.
2.3 Call and conversation content
This is the core of the product, so we describe it precisely:
- Audio. During a voice call your microphone audio is streamed to our server and Google’s Gemini AI service. Ordinary-call audio is processed in transit and memory and is not persistently stored by us. For a placement assessment, encrypted raw PCM may be stored temporarily in Google Cloud Storage so assessment can finish or retry across server instances. It is deleted after a successful assessment, when no longer needed for the retry, or during account deletion.
- Transcripts. We temporarily store the text transcript of calls and chats (what you said and what the character said) so a dropped or server-moved session can resume and so we can produce its assessment, debrief, vocabulary and constrained buddy-memory update. After those results are saved successfully, the full transcript is deleted. A failed, incomplete or orphaned transcript may remain for retry, with an automatic 48-hour deletion backstop.
- Buddy memory. We store a short, generated summary of things you have told your character — the things a friend would remember — so later calls feel continuous.
- Feedback and debriefs. The AI-generated summaries, corrections and suggestions produced after a session.
2.4 Device and notification data
To ring your phone we store push notification tokens for your device (Firebase Cloud Messaging on Android, Apple Push Notification service and PushKit/VoIP on iOS), plus the platform and app version. Tokens are removed when you sign out or delete your account.
2.5 Diagnostics and product analytics
We use Sentry for essential crash and error diagnostics, configured not to send transcript text, vocabulary, email addresses or default personal identifiers. With your optional consent, we use PostHog for product-usage events such as a call starting or a lesson completing, together with app/device information and an account identifier. PostHog is disabled before consent and can be disabled again under You → Privacy & legal. Neither service is used for advertising.
2.6 Purchase data
If you subscribe, the payment itself is handled entirely by Apple or Google. We never receive your card number or billing address. We receive from RevenueCat and the stores a purchase record: which product you bought, whether the subscription is active, trial and renewal dates, and cancellations or refunds.
2.7 Website data
This website does not set advertising or analytics cookies. Hostinger records standard server logs such as IP address, request time and user agent for security and reliability.
The waitlist is for people aged 18 or over, and the first Filomou call is free. By joining, you agree to receive waitlist emails and acknowledge this Privacy Policy. Dev.Enkrio stores your email address, the source you arrived from and the wording you agreed to in Google Cloud Firestore, and uses Resend to send your confirmation and launch invitation. We do not store your IP address with your waitlist entry, and we do not use the list for any other marketing. We keep the list for up to 30 days after early access ends, and delete it after that. You can opt out and ask us to delete your waitlist entry at any time by emailing privacy@filomou.com or support@filomou.com; every waitlist email also carries that link.
3. Why we use your data, and our legal basis
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and secure your account; sign you in | Account data | Performance of a contract |
| Deliver calls, lessons and scenarios; personalise them to your level and interests | Learning profile, conversation content | Performance of a contract |
| Let your buddy remember you between calls | Buddy memory, transcripts | Performance of a contract |
| Ring your phone at the times you chose; send follow-up messages | Push tokens, call schedule | Performance of a contract; consent where required for notifications |
| Take payment and manage your subscription | Purchase data | Performance of a contract |
| Fix crashes, prevent fraud or abuse, and keep the service reliable | Minimal diagnostics and security logs | Legitimate interests (operating a secure, reliable service) |
| Understand which features work and improve the product | Optional PostHog usage events | Consent; withdrawable in the app |
| Comply with tax, accounting and legal obligations | Purchase records | Legal obligation |
| Send product or marketing email, if you ask for it | Email address | Consent (withdrawable at any time) |
4. Artificial intelligence and your conversations
Filomou’s characters are AI, not people. To generate their speech and replies we send Google’s Gemini API the following: your live call audio, the running transcript of the conversation, your learning profile (language, level, interests, goals), and your buddy’s memory summary. Text features — translations, lesson content, debriefs, placement assessment — are sent to the same provider as text.
We use paid Gemini API/Vertex AI services. Under the applicable paid-service terms, prompts and responses are not used to improve Google’s general models. Google may nevertheless retain limited content and technical information for security, abuse detection, billing and legal compliance under its terms, and processing can occur outside the EEA.
Our memory prompt instructs the AI not to save or infer health, disability, sexuality, religion, politics, ethnicity, union membership, precise location, government identifiers, financial credentials, passwords or criminal history, and to remove such items from prior generated memory. No automated safeguard is perfect. Please do not share sensitive or confidential information. AI corrections and explanations are practice material, not professional advice or a certified assessment.
5. Who we share data with
We do not sell personal data or share it for cross-context behavioural advertising. Some recipients act as our processors; others, particularly app stores and sign-in providers, act as independent controllers for their own activities.
| Recipient | Role and purpose | Data involved | Location |
|---|---|---|---|
| Google Cloud / Firebase | Processor: Cloud Run hosting, authentication, Firestore, Storage, App Check and Android push | Account, profile, transcript, temporary placement audio and device-token data | Core configured services in the EU/Netherlands; some global support and transfer processing |
| Google Gemini API / Vertex AI | Processor for paid AI services; independent controller for limited account, usage, security and abuse data | Live audio, transcripts, prompts, learning context, outputs and technical usage | Global Google infrastructure |
| Apple | Processor for requested push delivery; independent controller for Sign in with Apple and App Store activity | Push tokens, sign-in and purchase information | Global |
| Google Play / Google Sign-In | Independent controller for store and sign-in activity | Account and purchase information | Global |
| RevenueCat | Processor: subscription status and receipt validation | Account identifier and purchase records | United States |
| Sentry | Processor: essential crash and error diagnostics | Minimised diagnostic and technical data | EU region when production configuration is enabled |
| PostHog | Processor: optional consent-based product analytics | Usage events and account identifier; no conversation content | EU region |
| Hostinger | Processor: public website hosting, security logs and the support and privacy mailboxes | IP address, request time and user agent; email correspondence | Servers in the Netherlands and backups in Lithuania, both inside the EEA. A content delivery network and email-delivery providers may process data in transit outside the EEA under Standard Contractual Clauses |
We may also disclose data where we are legally required to (a valid court order or lawful request), to establish or defend legal claims, or to a buyer in connection with a merger or sale of the business — in which case we will tell you first.
6. International transfers
Our intended core storage and backend region is the European Union. Some recipients process data elsewhere, including the United States. Depending on the recipient and destination, we rely on an adequacy decision (including an active EU–US Data Privacy Framework certification where applicable), the European Commission’s Standard Contractual Clauses plus supplementary measures, or another lawful mechanism. You may request information about the relevant mechanism or a copy of applicable safeguards at privacy@filomou.com; confidential commercial terms may be redacted.
7. How long we keep data
| Data | Retention |
|---|---|
| Ordinary call audio | Not persistently stored by us; discarded from server memory after call processing |
| Placement-call audio | Temporarily until assessment succeeds or the retry is no longer needed; also removed during account deletion. An automatic storage lifecycle rule provides a one-day backstop for any orphaned copy. |
| Account, profile, progress, vocabulary | Until you delete your account |
| Full call/chat transcript | While the session is active and until its assessment/review and final derived updates complete; failed, incomplete or orphaned copies have an automatic 48-hour deletion backstop. Encrypted soft-delete/recovery copies may then remain up to 7 days, isolated from product use. |
| Debriefs, corrections, vocabulary and buddy-memory summary | Until you delete your account (or delete individual items in the app, where offered) |
| Deleted accounts | Authentication and access end immediately; active application data is normally purged within 30 minutes. Disaster-recovery copies may remain up to 7 days and ordinary application security logs up to 30 days. Google-mandated administrator/system audit records may remain in a locked audit bucket for 400 days. They are not ordinary conversation content. Deletion cannot be undone. |
| Push tokens | Removed at sign-out or account deletion |
| Diagnostics and analytics events | Up to 12 months, per provider retention settings |
| Purchase and tax records | As required by law (typically 7 years in the Netherlands) |
8. Your rights
If you are in the EEA or the UK, you have the right to: access your data; correct it; erase it; restrict or object to processing (including profiling used to personalise lessons); receive a portable copy; and withdraw consent at any time without affecting processing already carried out. You also have the right to lodge a complaint with your supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens.
If you are in California, you have the right to know, delete, and correct your personal information, and to be free from discrimination for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA/CPRA.
Most of these you can exercise directly in the app: edit your profile on the You tab, or delete your account there. For anything else, write to privacy@filomou.com. We answer within 30 days.
9. Deleting your account
Open the app, go to the You tab, and choose to delete your account. Authentication and access end immediately and deletion cannot be undone. Full timing and exceptions are on the account deletion page.
Deleting your Filomou account does not cancel a subscription bought through Apple or Google. Cancel that in your App Store or Google Play subscription settings first.
10. Security
All traffic between the app and our servers is encrypted in transit (TLS). Data at rest is encrypted by our cloud provider. Access to production data is limited to the people who need it, protected by two-factor authentication. Requests to our backend are authenticated per user, and database rules deny direct client access by default. No system is perfectly secure; if a breach affects your data we will notify you and the relevant regulator as the law requires.
11. Children
Only people aged 18 or older may use Filomou. The app is not offered to children, even with parental permission, and requires an age confirmation before AI-backed features are enabled. We record that confirmation on the account, configure both app stores for an adult audience, keep our listings and marketing adult-directed, and act on app-store age signals where they are available to us. We do not knowingly collect personal data from anyone under 18.
If you believe a minor has created an account or provided data, write to privacy@filomou.com. We will investigate, and where we confirm the account belongs to someone under 18 we will disable it and delete the associated personal data within 30 days. Our reasoning and our safety protocol are on the Safety page.
12. Changes to this policy
We will update this page when our practices change and revise the “last updated” date. If a change is material we will tell you in the app or by email before it takes effect.
13. Contact
Adam Daghmah, trading as Dev.Enkrio (KVK 42061187; VAT ID NL005465302B85)
Brouwhuis 52, 1695 JS Blokker, the Netherlands
privacy@filomou.com