Filomou

Privacy Policy

Last updated and effective: 2 August 2026

This policy explains what personal data Filomou (“Filomou”, “we”, “us”) collects when you use the Filomou mobile app and this website, why we collect it, who we share it with, and the rights you have over it.

The short version. Filomou is designed for adult language learners aged 18 and over. An AI character with an AI-generated voice calls you. Live audio is processed by Google’s Gemini service. Placement-call audio may be held temporarily until assessment finishes; other raw call audio is not persistently stored. Full text transcripts are temporary: we use them to keep a live session connected and build its review, then delete them. We keep the smaller derived feedback, progress, vocabulary and selected buddy memory. Optional PostHog analytics is off until you opt in. We do not sell personal data or use advertising trackers. Account deletion is irreversible.

1. Who is responsible for your data

The controller of your personal data is:

Dev.Enkrio is operated by one person. We have not appointed a formal Data Protection Officer because we currently do not consider the statutory appointment thresholds met. The proprietor is the privacy contact and periodically reassesses this as the service grows.

2. Data we collect

2.1 Account data

When you create an account we receive, from you or from your chosen sign-in provider (Apple, Google, or email and password): your email address, whether that email is verified, the sign-in provider you used, and a display name if your provider supplies one. We generate an internal account identifier for you. We never receive or store your provider password.

If you use Sign in with Apple and choose to hide your email, we only ever see Apple’s private relay address.

2.2 Learning profile

What you tell us during onboarding and in settings: the language you are learning, your native language, your goals, your interests, your self-assessed level, and anything you write in the free-text “about you” step. We also store what we infer from your use of the app: your placement result and CEFR level, lesson and scenario progress, saved vocabulary, streaks and activity dates, and the times of day you have asked your buddy to call.

2.3 Call and conversation content

This is the core of the product, so we describe it precisely:

2.4 Device and notification data

To ring your phone we store push notification tokens for your device (Firebase Cloud Messaging on Android, Apple Push Notification service and PushKit/VoIP on iOS), plus the platform and app version. Tokens are removed when you sign out or delete your account.

2.5 Diagnostics and product analytics

We use Sentry for essential crash and error diagnostics, configured not to send transcript text, vocabulary, email addresses or default personal identifiers. With your optional consent, we use PostHog for product-usage events such as a call starting or a lesson completing, together with app/device information and an account identifier. PostHog is disabled before consent and can be disabled again under You → Privacy & legal. Neither service is used for advertising.

2.6 Purchase data

If you subscribe, the payment itself is handled entirely by Apple or Google. We never receive your card number or billing address. We receive from RevenueCat and the stores a purchase record: which product you bought, whether the subscription is active, trial and renewal dates, and cancellations or refunds.

2.7 Website data

This website does not set advertising or analytics cookies. Hostinger records standard server logs such as IP address, request time and user agent for security and reliability.

The waitlist is for people aged 18 or over, and the first Filomou call is free. By joining, you agree to receive waitlist emails and acknowledge this Privacy Policy. Dev.Enkrio stores your email address, the source you arrived from and the wording you agreed to in Google Cloud Firestore, and uses Resend to send your confirmation and launch invitation. We do not store your IP address with your waitlist entry, and we do not use the list for any other marketing. We keep the list for up to 30 days after early access ends, and delete it after that. You can opt out and ask us to delete your waitlist entry at any time by emailing privacy@filomou.com or support@filomou.com; every waitlist email also carries that link.

3. Why we use your data, and our legal basis

PurposeData usedLegal basis (GDPR Art. 6)
Create and secure your account; sign you inAccount dataPerformance of a contract
Deliver calls, lessons and scenarios; personalise them to your level and interestsLearning profile, conversation contentPerformance of a contract
Let your buddy remember you between callsBuddy memory, transcriptsPerformance of a contract
Ring your phone at the times you chose; send follow-up messagesPush tokens, call schedulePerformance of a contract; consent where required for notifications
Take payment and manage your subscriptionPurchase dataPerformance of a contract
Fix crashes, prevent fraud or abuse, and keep the service reliableMinimal diagnostics and security logsLegitimate interests (operating a secure, reliable service)
Understand which features work and improve the productOptional PostHog usage eventsConsent; withdrawable in the app
Comply with tax, accounting and legal obligationsPurchase recordsLegal obligation
Send product or marketing email, if you ask for itEmail addressConsent (withdrawable at any time)

4. Artificial intelligence and your conversations

Filomou’s characters are AI, not people. To generate their speech and replies we send Google’s Gemini API the following: your live call audio, the running transcript of the conversation, your learning profile (language, level, interests, goals), and your buddy’s memory summary. Text features — translations, lesson content, debriefs, placement assessment — are sent to the same provider as text.

We use paid Gemini API/Vertex AI services. Under the applicable paid-service terms, prompts and responses are not used to improve Google’s general models. Google may nevertheless retain limited content and technical information for security, abuse detection, billing and legal compliance under its terms, and processing can occur outside the EEA.

Our memory prompt instructs the AI not to save or infer health, disability, sexuality, religion, politics, ethnicity, union membership, precise location, government identifiers, financial credentials, passwords or criminal history, and to remove such items from prior generated memory. No automated safeguard is perfect. Please do not share sensitive or confidential information. AI corrections and explanations are practice material, not professional advice or a certified assessment.

5. Who we share data with

We do not sell personal data or share it for cross-context behavioural advertising. Some recipients act as our processors; others, particularly app stores and sign-in providers, act as independent controllers for their own activities.

RecipientRole and purposeData involvedLocation
Google Cloud / FirebaseProcessor: Cloud Run hosting, authentication, Firestore, Storage, App Check and Android pushAccount, profile, transcript, temporary placement audio and device-token dataCore configured services in the EU/Netherlands; some global support and transfer processing
Google Gemini API / Vertex AIProcessor for paid AI services; independent controller for limited account, usage, security and abuse dataLive audio, transcripts, prompts, learning context, outputs and technical usageGlobal Google infrastructure
AppleProcessor for requested push delivery; independent controller for Sign in with Apple and App Store activityPush tokens, sign-in and purchase informationGlobal
Google Play / Google Sign-InIndependent controller for store and sign-in activityAccount and purchase informationGlobal
RevenueCatProcessor: subscription status and receipt validationAccount identifier and purchase recordsUnited States
SentryProcessor: essential crash and error diagnosticsMinimised diagnostic and technical dataEU region when production configuration is enabled
PostHogProcessor: optional consent-based product analyticsUsage events and account identifier; no conversation contentEU region
HostingerProcessor: public website hosting, security logs and the support and privacy mailboxesIP address, request time and user agent; email correspondenceServers in the Netherlands and backups in Lithuania, both inside the EEA. A content delivery network and email-delivery providers may process data in transit outside the EEA under Standard Contractual Clauses

We may also disclose data where we are legally required to (a valid court order or lawful request), to establish or defend legal claims, or to a buyer in connection with a merger or sale of the business — in which case we will tell you first.

6. International transfers

Our intended core storage and backend region is the European Union. Some recipients process data elsewhere, including the United States. Depending on the recipient and destination, we rely on an adequacy decision (including an active EU–US Data Privacy Framework certification where applicable), the European Commission’s Standard Contractual Clauses plus supplementary measures, or another lawful mechanism. You may request information about the relevant mechanism or a copy of applicable safeguards at privacy@filomou.com; confidential commercial terms may be redacted.

7. How long we keep data

DataRetention
Ordinary call audioNot persistently stored by us; discarded from server memory after call processing
Placement-call audioTemporarily until assessment succeeds or the retry is no longer needed; also removed during account deletion. An automatic storage lifecycle rule provides a one-day backstop for any orphaned copy.
Account, profile, progress, vocabularyUntil you delete your account
Full call/chat transcriptWhile the session is active and until its assessment/review and final derived updates complete; failed, incomplete or orphaned copies have an automatic 48-hour deletion backstop. Encrypted soft-delete/recovery copies may then remain up to 7 days, isolated from product use.
Debriefs, corrections, vocabulary and buddy-memory summaryUntil you delete your account (or delete individual items in the app, where offered)
Deleted accountsAuthentication and access end immediately; active application data is normally purged within 30 minutes. Disaster-recovery copies may remain up to 7 days and ordinary application security logs up to 30 days. Google-mandated administrator/system audit records may remain in a locked audit bucket for 400 days. They are not ordinary conversation content. Deletion cannot be undone.
Push tokensRemoved at sign-out or account deletion
Diagnostics and analytics eventsUp to 12 months, per provider retention settings
Purchase and tax recordsAs required by law (typically 7 years in the Netherlands)

8. Your rights

If you are in the EEA or the UK, you have the right to: access your data; correct it; erase it; restrict or object to processing (including profiling used to personalise lessons); receive a portable copy; and withdraw consent at any time without affecting processing already carried out. You also have the right to lodge a complaint with your supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens.

If you are in California, you have the right to know, delete, and correct your personal information, and to be free from discrimination for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA/CPRA.

Most of these you can exercise directly in the app: edit your profile on the You tab, or delete your account there. For anything else, write to privacy@filomou.com. We answer within 30 days.

9. Deleting your account

Open the app, go to the You tab, and choose to delete your account. Authentication and access end immediately and deletion cannot be undone. Full timing and exceptions are on the account deletion page.

Deleting your Filomou account does not cancel a subscription bought through Apple or Google. Cancel that in your App Store or Google Play subscription settings first.

10. Security

All traffic between the app and our servers is encrypted in transit (TLS). Data at rest is encrypted by our cloud provider. Access to production data is limited to the people who need it, protected by two-factor authentication. Requests to our backend are authenticated per user, and database rules deny direct client access by default. No system is perfectly secure; if a breach affects your data we will notify you and the relevant regulator as the law requires.

11. Children

Only people aged 18 or older may use Filomou. The app is not offered to children, even with parental permission, and requires an age confirmation before AI-backed features are enabled. We record that confirmation on the account, configure both app stores for an adult audience, keep our listings and marketing adult-directed, and act on app-store age signals where they are available to us. We do not knowingly collect personal data from anyone under 18.

If you believe a minor has created an account or provided data, write to privacy@filomou.com. We will investigate, and where we confirm the account belongs to someone under 18 we will disable it and delete the associated personal data within 30 days. Our reasoning and our safety protocol are on the Safety page.

12. Changes to this policy

We will update this page when our practices change and revise the “last updated” date. If a change is material we will tell you in the app or by email before it takes effect.

13. Contact

Adam Daghmah, trading as Dev.Enkrio (KVK 42061187; VAT ID NL005465302B85)
Brouwhuis 52, 1695 JS Blokker, the Netherlands
privacy@filomou.com