1. Introduction
Welcome to SayMelo ("we," "our," or "us"). This Privacy Policy explains how DaelVista LLC collects, uses, shares, and protects your information when you use the SayMelo mobile application (the "App").
- Legal name: DaelVista LLC
- Address: 30 N Gould St Ste N, Sheridan, WY 82801-6317, United States
- Contact: privacy@saymelo.com for privacy matters, support@saymelo.com for everything else. Mail sent to support@daelvista.com still reaches us.
2. Information We Collect
2.1 Information Stored Locally (No Account Required)
The following data is stored on your device using AsyncStorage. It does not leave your device unless you sign in:
- Learning progress — completed situations, correct answers, XP points
- Unlocked circles and levels
- Daily streak and session history
- App preferences (theme, onboarding status, personalization answers)
- Mistake records — situations you answered incorrectly (Mistake Notebook)
- Saved items — phrases and expressions you bookmarked (Review Box)
- Spaced repetition data — SM-2 scheduling intervals for flashcards
- Slang Hub progress — completed phrase lessons and themes
- Push notification preferences and permission status
2.2 Information You Provide Optionally (Sign-In)
You can sign in to sync your progress and make your credit balance portable across devices. We offer two sign-in methods:
- Google Sign-In: your Google account name, email address, and Google unique user ID.
- Email & password: your email address and a password. The password is never stored in readable form — it is handled and stored only as a secure cryptographic hash by our authentication provider (Supabase Auth); we cannot see your plain-text password.
Whichever method you use, the following are also stored server-side against your account:
- Your learning progress data (backed up to Supabase)
- Your credit balance, credit ledger entries, and welcome-grant status (stored server-side so they survive reinstall)
Signing in is optional. Most of the App works without it, but credits, the Pro subscription, and AI features require a signed-in account because they are enforced server-side. If you sign up with email, we send a confirmation email (and password-reset emails on request) via our email provider — see Section 5.
2.3 Information Collected Automatically
- Device identifier: SayMelo is an Android-only app. A stable device ID is stored in encrypted, device-only secure storage so it survives reinstall. It is used for: (a) RevenueCat purchase verification, (b) preventing abuse of the one-time welcome credits across reinstalls and new accounts, and (c) server-side rate limiting and account-device binding to prevent shared-account abuse. It is not the Android Advertising ID and is never used for advertising or cross-app tracking.
- Purchase & subscription status: Collected and verified by RevenueCat and Google Play Billing.
- AI session data: Text you submit to an AI practice tool is routed through a Supabase Edge Function proxy to DeepSeek, which generates the feedback. Short voice recordings from the two speaking features — Pronunciation Check and Answer in your own words — are routed to OpenAI Whisper for transcription only; the resulting transcript is then sent to DeepSeek for text feedback. We do not retain your AI conversation content or audio recordings on our servers beyond temporary processing for the request. Each provider may retain data per its own privacy policy.
- Crash and performance diagnostics: Sentry receives app version, operating system, screen route, crash stack traces, performance timings, and categorical error codes. It is deliberately configured to attach no screenshots, view hierarchy, request bodies, breadcrumbs, or account identity.
- Anonymous activity comparison: Your own weekly practice count may be compared against an anonymous total for all learners active that week, so the app can show you where you stand. The server reads your identity from your own session and returns only your own position — no other learner's data is sent to your device, and yours is never sent to theirs. The comparison stays hidden entirely unless enough learners were active that week for a position to be meaningful and non-identifying.
- AI-generated content cache: When you use AI Custom Practice or the AI Coach (Insights), the AI-generated output is cached in Supabase's
ai_generated_contenttable to avoid redundant API calls. This cache contains generated situations and coaching summaries — not your personal inputs. It is keyed to an anonymous fingerprint of your weak-area profile, not your identity, and is deleted with your account. - Server-side usage & security logs: Each AI call is logged server-side (user ID, device ID, tool ID, timestamp, token usage, estimated cost) in
api_call_logto enforce daily caps and detect abuse. This log is retained for operational and fraud-prevention purposes. - Credit ledger: Every grant (welcome, ad, purchase, subscription) and every spend (per tool, per session) is recorded server-side in a credit ledger that is the source of truth for your balance.
- Push notification token: If you grant notification permission, your device's local push token is used by expo-notifications (via Google FCM on Android) to deliver scheduled reminders. We do not store the token on our servers.
- Voice/audio input (Pronunciation Check): When you use the Pronunciation Check tool, a short audio recording (up to 10 seconds) is captured on your device and forwarded through our Supabase Edge Function proxy to OpenAI Whisper for transcription and scoring. The audio is not stored on our servers — it is processed transiently and discarded immediately after the API response is returned.
- Voice/audio input (Answer in your own words): Some situations offer a second speaking mode in which you reply to the situation in your own words instead of repeating a given line. It works exactly like Pronunciation Check: a short recording is captured on your device, forwarded through our Supabase Edge Function proxy to OpenAI Whisper for transcription, and discarded immediately after the response returns. Because your reply is your own wording rather than a fixed sentence, the resulting transcript is then sent to DeepSeek — together with the situation prompt — so it can comment on meaning, naturalness and tone fit. Neither the audio nor the transcript is stored on our servers. This mode is a limited pilot available on a small set of situations, and it is optional: you can always use the repeat-the-line mode instead, or skip speaking entirely.
- App version enforcement: The App checks a minimum required version against a server-side configuration on launch. If your installed version falls below the minimum, you will see a Force Update screen and the App will not allow further use until updated. This check is performed anonymously (no personal data is transmitted).
- Advertising identifier: Not collected. Rewarded advertising is currently disabled in SayMelo — no advertisement is requested or shown anywhere in the app, and no advertising network receives any data. The app's Android manifest actively removes the
AD_IDpermission. If rewarded advertising is enabled in a future release, this policy and the Google Play Data Safety declaration will be updated first, and the network will be named here.
3. How We Use Your Information
- Deliver the learning experience: Track your progress, unlock circles, calculate XP and streaks.
- Operate the Credits system: Maintain your credit balance, grant welcome / ad / purchase / subscription credits, and debit credits when you use paid AI tools — all enforced server-side.
- Power AI tools: Route your inputs to DeepSeek to run the AI-powered tools (SlangDecoder, SlangRoleplay, ToneMaster, AIReview, ScenarioChat, Write & Polish) and AI Custom Practice, and to OpenAI Whisper for the transcription used by Pronunciation Check and by "Answer in your own words". Four practice tools (FillTheGap, WordSnap, SentenceBuilder, FixMySentence) run entirely on your device from a built-in content library and send nothing to any AI provider. These four also give you 2 free practice sessions every day without spending credits.
- AI personalization: Analyze your mistake patterns locally and send an anonymised weak-area profile to DeepSeek to generate custom practice and AI Coach insights.
- Insights dashboard: Process your locally stored activity data on-device to display performance trends, accuracy rates, and learning momentum.
- Review Box & spaced repetition: Use SM-2 data stored on your device to schedule flashcard reviews.
- Streak Restore: Allow you to spend 1 credit to restore a broken learning streak. The credit debit is processed server-side; no additional personal data is collected for this action beyond the standard credit ledger entry.
- Free daily practice: Give free users 2 practice sessions every day on the four on-device tools without spending credits. (Optional rewarded ads to earn credits are planned but not active — see Section 4.5.)
- Process subscriptions and purchases: Verify Pro subscription status and credit-pack purchases through RevenueCat & Google Play, and grant the corresponding entitlements / credits server-side.
- Sync progress (optional): Back up your data to the cloud when you sign in (with Google or email).
- Prevent fraud and abuse: Use the device ID and server-side logs to enforce daily ad-credit caps, prevent welcome-credit farming via reinstalls or new accounts, and prevent shared-account abuse.
- Send push notifications (optional): Daily on-device reminders — a morning nudge, the daily situation, a slang phrase lesson, a practice nudge targeted to your weak areas, a streak-at-risk alert, and a weekly summary — only if you grant permission. These are scheduled entirely on your device.
- Improve the app: Analyze aggregate, non-identifying usage patterns to improve features.
4. Data Storage and Security
4.1 Local Storage
Learning progress is stored locally on your device. It does not leave your device unless you sign in.
4.2 Cloud Storage (Optional — after sign-in)
If signed in, your progress, credit balance, and credit ledger are stored in Supabase (hosted on AWS). Data in transit is encrypted with TLS 1.3. Data at rest is encrypted by Supabase. Sensitive operations (credit spending, purchase grants, welcome grants) are gated by Supabase Row-Level Security (RLS) and service_role-only RPCs that the client cannot call directly.
4.3 AI Practice Tool Data
When you use one of the AI-powered practice tools (SlangDecoder, SlangRoleplay, ToneMaster, AIReview, ScenarioChat, Write & Polish) or AI Custom Practice, your text input is sent to our Supabase Edge Function proxy and forwarded to DeepSeek. For the two speaking features — Pronunciation Check and Answer in your own words — the short audio clip is forwarded to OpenAI Whisper for transcription, and the resulting transcript then goes to DeepSeek for the written feedback. The four on-device tools (FillTheGap, WordSnap, SentenceBuilder, FixMySentence) send no input to any AI provider. We do not log or store your AI conversation content or audio on our servers, but the proxy does log per-call metadata (user ID, device ID, tool ID, timestamp, token usage, estimated cost) for billing accuracy, cap enforcement, and fraud prevention. Each provider processes requests per its own policy — DeepSeek and OpenAI.
Speech feedback is transcription-based matching plus a written tip. It is educational and may be inaccurate; it is not a clinical or phoneme-level pronunciation assessment.
4.4 AI-Generated Content Cache
When you use AI Custom Practice or the AI Coach insight, the AI-generated output is cached in Supabase to avoid repeated API calls for the same anonymised weak-area fingerprint. This cache:
- Contains only AI-generated content, not your personal messages
- Is keyed to an anonymous hash of your weak-area profile — not your name or email
- Is automatically deleted when you delete your account
- Is encrypted at rest by Supabase and in transit with TLS 1.3
4.5 Advertising — currently none
SayMelo shows no advertising at all. Rewarded ads are disabled in the shipped app, no advertisement is requested or displayed anywhere, and no advertising network receives any data about you. The Android manifest actively removes the AD_ID permission and the related advertising-services permissions.
There are no ads in the lessons either: the situations and Slang Hub content are free, unlimited, and ad-free for everyone.
Optional rewarded ads — which you would choose to watch in the Credits screen to earn credits — are planned but not active. If they are enabled in a future release, we will update this policy and our Google Play Data Safety declaration before the release goes live, and we will name the advertising network here along with the data it processes.
4.6 Push Notifications
If you grant notification permission, your device generates a local push token used by Google Firebase Cloud Messaging (FCM) on Android. All notification scheduling — a morning practice reminder, the daily situation, a daily slang phrase lesson, a personalized practice nudge based on your weak areas, a streak-at-risk reminder, and a weekly summary built from your activity — is handled entirely on your device via expo-notifications. A gentle default notification sound may play. We do not send server-side push notifications and do not store your push token on our servers.
4.7 Data Retention
- Local data: Until you reset progress, delete the App, or request deletion.
- Cloud progress (if signed in): Until you delete your account or request deletion.
- Credit ledger entries: Retained while the account exists; deleted with the account, except where retention is required by law for financial records.
- Server-side API call log: Retained up to 90 days for operational, billing, and fraud-prevention purposes, then deleted or aggregated.
- Device welcome-grant record: Retained for the lifetime of the device record to enforce the one-time welcome bonus across reinstalls and new accounts. Contains only the device ID and the grant timestamp — no personal data.
- AI-generated content cache: Deleted with your account, or within 30 days of last access.
- Purchase records (RevenueCat / Google Play): Retained per financial regulations.
5. Third-Party Service Providers
We do not sell your personal information. No advertising network is in this list, because SayMelo currently shows no advertising (Section 4.5).
| Service | Purpose | Data Shared |
|---|---|---|
| Google Play Billing | Payment processing (credit packs & Pro subscription) | Purchase transaction info |
| RevenueCat, Inc. | Subscription & purchase verification, webhook-driven credit grants | Device ID, anonymous user ID, purchase & subscription status, transaction IDs |
| Supabase (hosted on AWS) | Auth, cloud backup, credit ledger, AI proxy, AI content cache, security logs | Account ID, device ID, progress data, credit ledger, AI inputs (forwarded, not retained as content), AI-generated cache (anonymised) |
| DeepSeek | Generates feedback for the AI text tools and AI personalization | Text inputs to AI tools, speech transcripts, and anonymised weak-area profiles |
| OpenAI, LLC (Whisper) | Transcribes the recordings from Pronunciation Check and "Answer in your own words" — transcription only, no other use | Short audio clip plus the reference sentence or the situation prompt, sent only after you press submit |
| DeepL & MyMemory | Translate eligible on-screen learning text when you use the translation feature | The specific text selected for translation |
| Sentry | Crash and performance diagnostics | App version, OS, screen route, crash stack, timings, categorical error codes — no screenshots, request bodies, or account identity |
| Supabase Auth (Google or Email sign-in) | Sign-in — optional but required for credits & subscription | Name, email, Google ID (Google), or email + hashed password (email sign-up) — only if you sign in |
| Resend (resend.com) | Delivers transactional emails (account confirmation & password reset) for email sign-in | Your email address and the email content (only if you sign up with email) |
| Google Firebase Cloud Messaging (FCM) | Local push notifications — Android | Device push token (handled on-device; not stored by us) |
6. Credits, Ads, and Subscription — Privacy Implications
6.1 The Credits System
The App uses a credits-based monetization model. Every credit grant (welcome, ad-reward, in-app purchase, monthly subscription allowance) and every spend (per AI tool use) is recorded in a server-side ledger tied to your account. This ledger is the source of truth for your balance and is what allows credits to follow you across devices when you are signed in.
6.2 Rewarded Ads (Earn Credits)
Rewarded ads are not active in the current release (Section 4.5). The mechanism below is documented because the code is present and disabled, so you know exactly what would happen if it is ever switched on.
If you chose to watch a rewarded ad in the Credits screen, our server would first issue a single-use, short-lived security token (a "nonce") bound to your account before the ad was shown. When the ad completed, that server-issued token would be sent back and consumed to grant the corresponding credit. This design means the reward is decided by our server, never by the ad network — so a faulty or hostile ad SDK cannot mint credits. The data an advertising network would collect during the ad would be governed by that network's own policies, and we would name it in Section 4.5 before enabling anything.
6.3 No Ads in Lessons
The lessons — all situations and Slang Hub content — are free, unlimited, and contain no advertising for everyone. In the current release there is no advertising anywhere in the App.
6.4 Pro Subscription
The Pro subscription ($9.99 / month) grants 700 monthly credits and removes all advertising. Subscription state is verified by RevenueCat against Google Play, and the monthly credit allowance is granted server-side via a RevenueCat webhook at each renewal (idempotent on the transaction ID). This means a Pro subscriber on a clean device does not need to share any extra data — the entitlement and grants happen through the existing RevenueCat/Supabase pipeline.
6.5 Anti-Abuse Measures
To prevent abuse of the welcome credits and the ad reward system, the App uses a stable device identifier (see Section 2.3). This identifier is used to: (a) enforce the one-time welcome grant per physical device, regardless of how many accounts sign in on it, (b) enforce the daily ad-credit cap, and (c) detect a single account being shared across many devices. It is not used for advertising or for tracking you across other apps.
7. Account Deletion and Data Removal
- Open SayMelo → go to Settings
- Scroll down to Delete Account & All Data
- Confirm deletion — all cloud data (progress, credit balance, credit ledger, AI cache, subscription record) is deleted immediately
Full instructions: https://apps.daelvista.com/contextly/delete-account-en
If you never signed in, your data exists only on your device. Uninstall the App to remove it.
If you cannot access the App, email support@saymelo.com and we will delete your data within 7 business days.
Note: Purchase and subscription transaction records are retained by Google Play and RevenueCat as required by financial law, even after account deletion. The device welcome-grant record is also retained on a device-only, anonymous basis to prevent welcome-credit farming.
8. Your Rights
- Access: Request a copy of data we hold about you
- Deletion: Delete your account and data (see Section 7)
- Correction: Request correction of inaccurate data
- Portability: Request your data in a readable format
- Withdraw consent: Disable notifications at any time via App or device settings; choose not to submit text or audio to the AI tools; continue as a guest instead of creating an account
- GDPR (EU/EEA users): Right to object to processing, restrict processing, and lodge a complaint with your local data protection authority.
- CCPA (California): Right to know, delete, and opt out of "sale" or "share". We do not sell personal information, and we disclose nothing to advertising partners — there are none.
Contact: privacy@saymelo.com. We respond within 30 days.
9. Children's Privacy
10. International Data Transfers
DaelVista LLC is based in the United States. If you use the App from outside the US, your data may be transferred to and processed in the United States and other countries where our service providers operate. By using the App, you consent to this transfer in accordance with applicable data protection laws.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via in-app notification. The "Last Updated" date reflects the most recent revision. Continued use of the App after changes constitutes acceptance.
12. Contact Us
Email: support@saymelo.com · privacy requests: privacy@saymelo.com
Address:
DaelVista LLC
30 N Gould St Ste N
Sheridan, WY 82801-6317
United States
We aim to respond within 3 business days.
13. Governing Law
This Privacy Policy is governed by the laws of the State of Wyoming, United States.
This page is the same document published at apps.daelvista.com/contextly, the address registered with Google Play. Both copies are kept identical. apps.daelvista.com/contextly/privacy-en.html