Security & privacy
Your security, safety, and privacy are built into Talkey from the start – from encrypted UK-hosted infrastructure to row-level access row-level access controls, passwordless auth, and transparent AI practices.
Security infrastructure
Your learning data is stored on our servers in the United Kingdom (London). Data is encrypted in transit over HTTPS/TLS and encrypted at rest on our infrastructure.

PostgreSQL databases
Accounts, flashcards, courses, progress, and media files are stored in isolated databases on our UK servers with automated backups and point-in-time recovery (PITR).
Encryption in transit
All connections between the Talkey app, website, and our servers use HTTPS with modern TLS configurations.
Encryption at rest
Database volumes and object storage are encrypted at rest on our UK-hosted infrastructure.
Backup & recovery
Database backups rotate on a standard schedule (30–90 days). If something goes wrong, PITR lets us restore to a specific point in time.

Product security & access
Access controls are enforced as close to your data as possible. PostgreSQL row-level security (RLS) policies filter queries by your signed-in account, and authentication is handled entirely through passwordless methods.
Row Level Security (RLS)
Many database tables use RLS policies tied to your account ID, so each query is scoped to your account – reducing the risk that an application bug exposes another learner's data.
Passwordless authentication
Sign in via email OTP (magic link), Apple Sign In, or Google OAuth. We do not collect, process, or store user-chosen passwords.
Secure session storage
On iOS, session tokens are stored in the device secure container. On web, session cookies are used only for essential login state.
Least-privilege operations
Production database and storage access is restricted to authorized personnel. We use database security rules, audit logging, and dependency management as part of our operational safeguards.
Privacy
Remelith (Talkey) is committed to transparency about how we collect, use, and protect personal data. Our practices are mapped to GDPR, UK GDPR, CCPA, and other global privacy standards.

Data minimization
We collect only what is needed to run the service – account details, learning progress, and optional profile information. We do not sell personal information or share it for cross-context behavioral advertising.
No targeted ads
Talkey does not run targeted advertising or behavioral profiling. Optional usage analytics, where collected, support product improvement – not ad targeting.
Your rights
Request access, correction, portability, or deletion at any time by emailing support@remelith.com. We verify identity before fulfilling requests, as described in our Privacy Policy.
Children's protections
Users under 16 may not create accounts. Users aged 16–17 receive high-privacy defaults, and AI features are disabled for accounts identified as belonging to users under 18.
Artificial intelligence (AI)
Talkey uses a pre-trained AI model to generate flashcard translations, pronunciation guidance, and example sentences. AI runs only when you explicitly request it – never in the background on your private decks.

On-demand, user-initiated
AI features require an explicit action – such as generating a translation or example sentence. We do not automatically scan or process your entire library.
Minimal data transfer
Only the words, phrases, or sentences you submit are sent to our AI inference provider over an encrypted connection. Account IDs, email addresses, device tokens, and profile names are not included.
No training on your decks
We do not use your private study decks to train Talkey models. The pre-trained model is not fine-tuned on your content. Never enter sensitive or confidential information into AI fields.
Disabled for minors
AI features are turned off entirely for accounts identified as belonging to users under 18. No minor data is sent for AI processing.

Infrastructure & partners
Talkey is built on managed cloud services we evaluate for security and privacy. We disclose every subprocessor that handles personal data in our Privacy Policy.
Cloud hosting
UK data centresAuthentication, PostgreSQL databases, encrypted object storage, and automated backups. Production systems run in London, United Kingdom on SOC 2 Type II certified infrastructure.
Learn more →Apple & Google
AuthenticationSign in with Apple and Google OAuth. We receive authentication tokens and basic profile fields – never your Apple or Google passwords.
Learn more →Paddle
Website billingMerchant of Record for web purchases. Paddle processes payment and billing data under its own privacy terms. We never receive or store credit card numbers.
Learn more →Pre-trained AI
Flashcard generationOn-demand translations, examples, and pronunciation hints using a third-party pre-trained language model. Only words and phrases you submit are sent – no account IDs or emails. See our Privacy Policy for full disclosures.
Learn more →Reliability & incident response
We maintain an internal incident response plan for detecting, containing, and assessing security events. Where required by law, we notify regulators and affected users without undue delay.

Account deletion
Delete your account anytime from Settings → Account → Delete Account (app) or through the website. Live production data is purged promptly; residual encrypted backup copies rotate out within 30–90 days.
Security logging
Server and security logs are retained for 180 days to support fraud prevention and incident investigation, then overwritten.
Breach notification
Where a qualifying breach is likely to affect your rights, we notify the competent supervisory authority within 72 hours (GDPR) and inform affected individuals when the risk is high.
Report a concern
If you discover a security vulnerability or suspect unauthorized access to your account, contact support@remelith.com. We investigate all good-faith reports.
