Privacy Policy
Last Updated: March 11, 2026
This privacy policy applies to the Dictio mobile application (herein referred to as "Application") developed by Mikhail Pontus ("we", "us", or "our"). Mikhail Pontus is the data controller responsible for your personal data.
Data Safety Disclosure
In accordance with Google Play's Data Safety requirements and Apple's App Privacy guidelines, we disclose the following:
- Data Types Collected: Speech-derived features (MFCC coefficients, required for pronunciation analysis), Device Identifiers (optional, Advertising ID), app interaction events, crash logs, device model, OS version, and IP address. We do not collect or transmit raw audio recordings.
- Data Usage: Speech features are used for app functionality (pronunciation feedback). Identifiers are used for advertising. Device information and interaction events are used for analytics and app stability monitoring.
- Data Sharing: We share device identifiers and device information with third-party providers (Google AdMob, Firebase Analytics, Firebase Crashlytics) for advertising, analytics, and stability monitoring purposes. We do not sell your personal data.
- Data Retention: Speech features are processed in real time and discarded immediately after analysis. They are not stored on our servers. Device identifiers are retained for the duration of app usage and deleted within 30 days of a deletion request. See Section 2 for third-party retention periods.
- Accounts: The Application does not require or support user accounts. All data is associated with device identifiers only.
- Security: All data is encrypted in transit using secure protocols (HTTPS/WSS).
1. Information Collection and Use
Speech Features (Microphone Access)
The Application requires access to your device's microphone to provide its core functionality: real-time pronunciation analysis and scoring.
- Collection: When you use the recording features, the Application captures audio from your microphone and extracts speech features (MFCC coefficients) on your device. Only these numerical features are transmitted to our servers — raw audio recordings never leave your device.
- Purpose: App Functionality (Pronunciation Feedback).
- Legal Basis (GDPR): Performance of a contract — providing the core service you requested (Art. 6(1)(b)).
- Handling: Speech features are processed in real time on our servers and discarded immediately after analysis. No speech data is stored on our servers.
- Consent: You are prompted for microphone permission before any audio is captured. You may revoke this permission at any time in your device settings, though this will prevent the app from providing pronunciation feedback.
Advertising ID and Device Identifiers
The Application uses the Google Advertising ID (AD_ID) and Apple Identifier for Advertisers (IDFA).
- Purpose: These identifiers are used to serve personalized advertisements and to analyze the effectiveness of our marketing efforts.
- Legal Basis (GDPR): Consent (Art. 6(1)(a)). You are asked for consent before personalized advertising identifiers are collected.
- Apple App Tracking Transparency: On iOS 14.5 and later, the Application will present Apple's App Tracking Transparency (ATT) prompt before accessing IDFA. If you decline tracking, no IDFA is collected, and only non-personalized ads are served.
- User Control: You can reset or opt out of personalized advertising through your device settings at any time. On Android, go to Settings > Google > Ads. On iOS, go to Settings > Privacy & Security > Tracking.
2. Third-Party Services
We use third-party SDKs that may collect information used to identify you. These third parties process data as independent data controllers under their own privacy policies:
- Google AdMob: Used for displaying advertisements. AdMob collects device information and identifiers to serve relevant ads. Data collected includes device type, OS version, IP address, and advertising identifiers. Data retention: up to 7 years for ads activity reports, 90 days for user activity reports. View Policy
- Firebase Crashlytics: Used to monitor app stability. Collects crash logs, installation identifiers, device model, OS version, and app state at time of crash. Data retention: 90 days. View Policy
- Firebase Analytics: Used to understand app usage patterns. Collects app interaction events, session duration, device information, and installation identifiers. Event-level data retention: 2 months (default). Aggregated reports are retained indefinitely. View Policy
- Expo: Built using the Expo platform, which may collect basic hardware and software diagnostic data such as device model and OS version. View Policy
Third-party data retention periods listed above are based on each provider's current defaults and may change. We encourage you to review their privacy policies linked above for the most up-to-date information.
3. Data Deletion
How to delete your data:
- In-App: Navigate to Settings > Clear local data to delete all local application data, cached audio, and preferences. This is the recommended method.
- Email: Contact us at m.pontus.admob@gmail.com with the subject line "Data Deletion Request".
Server-side data will be deleted within 30 days of receiving a valid deletion request. We will confirm deletion by email when applicable. Note that anonymized, aggregated data that cannot be linked back to you may be retained for analytics purposes.
4. Your Privacy Rights
European Economic Area (GDPR)
If you are located in the EEA, you have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate personal data.
- Erasure: Request deletion of your personal data (see Section 3).
- Restriction: Request that we restrict processing of your personal data.
- Portability: Request a machine-readable copy of your personal data.
- Objection: Object to processing based on legitimate interest.
- Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise these rights, contact us at m.pontus.admob@gmail.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
California (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know: Request disclosure of the categories and specific pieces of personal information we have collected.
- Delete: Request deletion of your personal information.
- Opt-Out of Sale/Sharing: We do not sell your personal information. We share advertising identifiers with ad networks (Google AdMob) for personalized advertising, which may constitute "sharing" under the CPRA. To opt out, disable ad personalization in your device settings (Android: Settings > Google > Ads; iOS: Settings > Privacy & Security > Tracking), or contact us at m.pontus.admob@gmail.com.
- Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
5. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence, including the United States, where our third-party service providers (Google, Firebase) operate. These transfers are necessary to provide the Application's functionality. For transfers from the EEA, we rely on the safeguards provided by our service providers, including the European Commission's Standard Contractual Clauses (SCCs) and adequacy decisions where applicable. Google's data transfer framework is described in their privacy frameworks documentation.
6. Data Security
The security of your personal information is a priority. We use industry-standard encryption (TLS/SSL) for all data in transit between the Application and our servers. Speech features are processed in memory and not persisted to storage. Raw audio is processed entirely on-device and never transmitted.
7. Children's Privacy
The Application does not knowingly collect personally identifiable information from children under 13 (or under 16 in the EEA). We do not target our services to children. If we learn that we have inadvertently collected personal data from a child, we will delete it promptly. If you believe a child has provided us with personal data, please contact us at m.pontus.admob@gmail.com.
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the "Last Updated" date at the top of this page and, where practicable, through an in-app notification. We encourage you to review this page periodically. Continued use of the Application after changes constitutes acceptance of the updated policy.
9. Contact Information
If you have any questions regarding this Privacy Policy, our data practices, or wish to exercise your privacy rights, please contact us:
Mikhail Pontus
Email: m.pontus.admob@gmail.com