Security & privacy

Your security, safety, and privacy are built into Talkey from the start – from encrypted UK-hosted infrastructure to row-level access row-level access controls, passwordless auth, and transparent AI practices.

Security infrastructure

Your learning data is stored on our servers in the United Kingdom (London). Data is encrypted in transit over HTTPS/TLS and encrypted at rest on our infrastructure.

Illustration of a lock and key for encryption and infrastructure security

PostgreSQL databases

Accounts, flashcards, courses, progress, and media files are stored in isolated databases on our UK servers with automated backups and point-in-time recovery (PITR).

Encryption in transit

All connections between the Talkey app, website, and our servers use HTTPS with modern TLS configurations.

Encryption at rest

Database volumes and object storage are encrypted at rest on our UK-hosted infrastructure.

Backup & recovery

Database backups rotate on a standard schedule (30–90 days). If something goes wrong, PITR lets us restore to a specific point in time.

Illustration of a shield for access control and product security

Product security & access

Access controls are enforced as close to your data as possible. PostgreSQL row-level security (RLS) policies filter queries by your signed-in account, and authentication is handled entirely through passwordless methods.

Row Level Security (RLS)

Many database tables use RLS policies tied to your account ID, so each query is scoped to your account – reducing the risk that an application bug exposes another learner's data.

Passwordless authentication

Sign in via email OTP (magic link), Apple Sign In, or Google OAuth. We do not collect, process, or store user-chosen passwords.

Secure session storage

On iOS, session tokens are stored in the device secure container. On web, session cookies are used only for essential login state.

Least-privilege operations

Production database and storage access is restricted to authorized personnel. We use database security rules, audit logging, and dependency management as part of our operational safeguards.

Privacy

Remelith (Talkey) is committed to transparency about how we collect, use, and protect personal data. Our practices are mapped to GDPR, UK GDPR, CCPA, and other global privacy standards.

Illustration of an eye for privacy and data protection

Data minimization

We collect only what is needed to run the service – account details, learning progress, and optional profile information. We do not sell personal information or share it for cross-context behavioral advertising.

No targeted ads

Talkey does not run targeted advertising or behavioral profiling. Optional usage analytics, where collected, support product improvement – not ad targeting.

Your rights

Request access, correction, portability, or deletion at any time by emailing support@remelith.com. We verify identity before fulfilling requests, as described in our Privacy Policy.

Children's protections

Users under 16 may not create accounts. Users aged 16–17 receive high-privacy defaults, and AI features are disabled for accounts identified as belonging to users under 18.

Illustration for cookies and local storage

Cookies & on-device storage

The Talkey iOS app does not use browser cookies. Instead, it relies on on-device storage for offline learning. The talkey.app website uses a small set of essential cookies for authentication and checkout.

Mobile local storage

App preferences, deck metadata, and offline study data are cached locally using CoreData and SQLite in the device sandbox.

Web session cookies

The website uses essential security and session cookies to keep you signed in and to operate the support portal. These are not used to build advertising profiles.

Payment cookies (Paddle)

When you purchase on the website, Paddle may set functional cookies for transaction flow and fraud prevention under its own privacy terms.

Authentication tokens

Session access tokens are stored securely on-device (iOS) or in session cookies (web) so you are not asked to re-authenticate on every visit.

Artificial intelligence (AI)

Talkey uses a pre-trained AI model to generate flashcard translations, pronunciation guidance, and example sentences. AI runs only when you explicitly request it – never in the background on your private decks.

Illustration for artificial intelligence governance

On-demand, user-initiated

AI features require an explicit action – such as generating a translation or example sentence. We do not automatically scan or process your entire library.

Minimal data transfer

Only the words, phrases, or sentences you submit are sent to our AI inference provider over an encrypted connection. Account IDs, email addresses, device tokens, and profile names are not included.

No training on your decks

We do not use your private study decks to train Talkey models. The pre-trained model is not fine-tuned on your content. Never enter sensitive or confidential information into AI fields.

Disabled for minors

AI features are turned off entirely for accounts identified as belonging to users under 18. No minor data is sent for AI processing.

Illustration of server infrastructure

Infrastructure & partners

Talkey is built on managed cloud services we evaluate for security and privacy. We disclose every subprocessor that handles personal data in our Privacy Policy.

Cloud hosting

UK data centres

Authentication, PostgreSQL databases, encrypted object storage, and automated backups. Production systems run in London, United Kingdom on SOC 2 Type II certified infrastructure.

Learn more →

Apple & Google

Authentication

Sign in with Apple and Google OAuth. We receive authentication tokens and basic profile fields – never your Apple or Google passwords.

Learn more →

Paddle

Website billing

Merchant of Record for web purchases. Paddle processes payment and billing data under its own privacy terms. We never receive or store credit card numbers.

Learn more →

Pre-trained AI

Flashcard generation

On-demand translations, examples, and pronunciation hints using a third-party pre-trained language model. Only words and phrases you submit are sent – no account IDs or emails. See our Privacy Policy for full disclosures.

Learn more →

Reliability & incident response

We maintain an internal incident response plan for detecting, containing, and assessing security events. Where required by law, we notify regulators and affected users without undue delay.

Wizard at a computer monitoring systems

Account deletion

Delete your account anytime from Settings → Account → Delete Account (app) or through the website. Live production data is purged promptly; residual encrypted backup copies rotate out within 30–90 days.

Security logging

Server and security logs are retained for 180 days to support fraud prevention and incident investigation, then overwritten.

Breach notification

Where a qualifying breach is likely to affect your rights, we notify the competent supervisory authority within 72 hours (GDPR) and inform affected individuals when the risk is high.

Report a concern

If you discover a security vulnerability or suspect unauthorized access to your account, contact support@remelith.com. We investigate all good-faith reports.