We are committed to protecting your privacy. This policy explains how we collect, use, and safeguard your information.
Talkey ("we," "our," or "us") is committed to protecting your privacy.
This Privacy Policy explains how we process personal data when you use Talkey. Where we rely on your consent, we will request it separately through an appropriate consent screen.
Entity: Remelith
Registered Address: Matbuat Ave. 12b, Baku, Azerbaijan
Registration Number / VÖEN: 1309694561
Email: privacy@talkey.app
Remelith is a company registered under the laws of the Republic of Azerbaijan. We are committed to protecting your privacy and ensuring transparency about how we handle your personal information.
EU & UK Representation: We periodically assess whether the appointment of an EU or UK representative is required. Where such an appointment is legally required, representative details will be published in this Policy.
Data Protection Officer (DPO): We have not appointed a DPO as our core activities do not consist of processing operations that require systematic monitoring of users on a large scale. All data protection inquiries are managed directly by our privacy team.
Privacy Inquiries
privacy@talkey.app
General Support
support@talkey.app
We collect information that you provide directly to us when using the App:
We automatically collect certain information when you interact with our services:
We integrate with specific third-party partners to support authentication, content, and transactions:
We process your personal data under defined legal bases in accordance with GDPR, UK GDPR, and local regulations. Below is a detailed mapping of our processing activities:
| Processing Activity | Data Category | Lawful Basis (GDPR / UK GDPR) |
|---|---|---|
| Account Creation & Authentication | Email, name, OAuth/account identifiers | Performance of a contract (Art. 6(1)(b)) |
| Syncing Learning Data | Flashcards, custom decks, logs, preferences | Performance of a contract (Art. 6(1)(b)) |
| Subscription Verification | StoreKit transactions, product ID, expiry date, Paddle subscription references | Performance of a contract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c)) |
| Security & Fraud Prevention | IP address, server logs, device IDs | Legitimate interests (Art. 6(1)(f)) to keep the app secure; Legal obligation (Art. 6(1)(c)) |
| Customer Support | Emails, messages, attachments, diagnostics | Performance of a contract (Art. 6(1)(b)); Legitimate interests (Art. 6(1)(f)) |
| Optional Analytics | Usage statistics, crash details, performance profiles | Consent (Art. 6(1)(a)) where requested by the platform, otherwise Legitimate interests (Art. 6(1)(f)) |
| AI Flashcard Generation | Submitted words, translation prompts, sentence requests | Performance of a contract (Art. 6(1)(b)) with privacy-preserving filters |
| Marketing Communications | Email, name, campaign interaction data | Consent (Art. 6(1)(a)) |
| Compliance & Legal Claims | Account records, payment timestamps, audit logs | Legal obligation (Art. 6(1)(c)); Legitimate interests (Art. 6(1)(f)) |
We disclose information to the following specific service providers to enable the functionality of Talkey:
We may disclose your information if required to do so by Azerbaijani law, EU/UK regulations, court orders, or requests by competent public authorities, or where we believe in good faith that disclosure is necessary to protect our legal rights, address fraud, or prevent physical harm.
In the event of a merger, corporate restructuring, acquisition, or asset sale, your personal data may be transferred to the acquiring entity. We will notify you in advance of any such change in data controller status.
We use technical and organisational safeguards designed to protect personal data, including encrypted network transmission, access controls, authentication controls, database security rules, logging, backups, dependency management, and restricted administrative access. The safeguards used depend on the nature and sensitivity of the information.
We maintain an internal incident response plan for detecting, containing, and assessing security breaches. Where required by applicable law, we will notify the competent supervisory authority without undue delay and, where applicable, within 72 hours after becoming aware of a qualifying breach (where likely to result in a risk to rights and freedoms). Where a breach is likely to result in a high risk to affected individuals' rights and freedoms, we will also notify those individuals without undue delay.
We do not retain personal data longer than necessary for the purposes for which it is processed. We adhere to the following retention schedule:
| Data Category | Retention Period / Rule |
|---|---|
| Active Account Profile | Until account deletion is requested. Deleted immediately from active servers. |
| Learning Content & Progress | Until deleted by the user in-app, or until account deletion. |
| Deleted Database Records | Purged immediately from live production database tables. |
| Storage Buckets & Media Files | Purged immediately from our cloud storage. |
| Database Backups | Overwritten through standard backup rotation within 30 to 90 days. |
| Security & Server Logs | Retained for 180 days, then overwritten. |
| Support Correspondence | Retained for up to 2 years after closure of the request. |
| Subscription Records | Transaction and subscription records are retained for the period required by applicable accounting, tax, fraud-prevention, and legal-obligation rules. |
| AI feature inputs | Subject to our AI provider's retention policies, based on processing requirements and business obligations rather than a fixed universal period. |
| Consent Records | Retained for the duration needed to prove consent validity. |
You can initiate account deletion manually inside the App at any time via Settings → Account → Delete Account or directly through the Talkey website interface.
Account data is removed from active production systems promptly after deletion is initiated. Residual copies may remain in encrypted backups until normal backup rotation completes. Certain transaction, security, fraud-prevention, or legal records may be retained where required or permitted by law.
Note: Active subscriptions must be cancelled separately through Apple or Paddle. Google authentication is unrelated to subscription cancellation.
Individuals residing in the EU, EEA, or UK have specific statutory rights under the GDPR and UK GDPR:
To the extent the California Consumer Privacy Act (CCPA) as amended by the CPRA applies to Talkey, California residents have the following rights:
We recognize Global Privacy Control (GPC) signals sent by browsers. We do not sell or share data, so no opt-out links are required. You may submit requests via authorized agents meeting California regulatory standards.
Submit your request to privacy@talkey.app. To protect your data, we verify your identity by sending a confirmation code to the email address registered with your account.
All standard privacy rights requests are processed free of charge. We may refuse requests that are manifestly unfounded, excessive, or repetitive.
We implement comprehensive technical safeguards and data restrictions to ensure minor safety in accordance with the GDPR, COPPA, and the UK Children's Code (Age-Appropriate Design Code):
Parental involvement is required only where applicable law requires it. If we discover we have inadvertently collected data from a child under 16, we will delete that information immediately.
We and our service providers (including our UK cloud infrastructure provider, AI inference provider, Apple, Google, and Paddle) may process personal data outside your country of residence (including transfers to the United States and other jurisdictions). Where the EU GDPR or UK GDPR applies, we use an applicable adequacy decision or approved contractual safeguards, such as the European Commission’s Standard Contractual Clauses (SCCs) and, where relevant, the UK International Data Transfer Addendum or other lawful transfer mechanism.
We assess applicable transfer risks and implement supplementary technical and organizational safeguards where required to protect data against unauthorized foreign access. You may contact us at privacy@talkey.app to request further information about the safeguards used.
The App may request specific system permissions on your mobile device to enable interactive language features:
Our mobile app does not utilize web browser cookies. However, we use equivalent sandbox tracking technologies to maintain app states:
Our payment processing and billing setups depend on where you purchase your subscription:
For questions about payments, cancellations, or refunds, please manage your subscription through your Apple Account Settings (for iOS purchases) or via the Paddle Buyer Portal / confirmation receipts (for web purchases).
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
The "Last Updated" date at the top of this policy indicates when it was last revised. Changes become effective when they are posted.
If you do not agree to the changes, you must stop using the App and may delete your account immediately.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: privacy@talkey.app
For questions about privacy, data requests, or exercising your privacy rights
Email: support@talkey.app
For general app support and technical questions
We are committed to protecting your privacy and being transparent about how we handle your data. If you have any questions, please don't hesitate to contact us.