The short version: your practice data — progress, notes, saved phrases and voice recordings — is stored on your device. There are no ads, and nothing you do is sold, profiled or used to build an advertising identity. Some features do need the internet to work, and those send specific things off your device: your recordings go to a speech service to be transcribed and scored, and text you enter into Executive Polish goes to an AI service to be rewritten. Every one of them is listed in section 4. The camera, when you enable the Posture Coach, never leaves your device at all.
1. Data we store — on your device
The app stores the following locally in your browser/app storage (localStorage and IndexedDB) on your device:
- Your profile (first name, role, goal, practice slot) as entered by you
- Practice progress: completed sessions, scores, notes, saved phrases, vocabulary, clips
- Voice recordings you make, and the text transcripts generated from them
- Practice conversations: the text of what you and the practice character said, kept so you can pick a conversation up again
- Anything you type into the Résumé & LinkedIn coach in the Career Center
This is the only copy unless you turn on cloud sign-in (section 5) or the optional GitHub backup (section 6), or a feature in section 4 sends something out to do its job. Deleting the app or using Account → Reset everything permanently erases the local copy.
2. Microphone and your recordings
The microphone is used only when you tap record or start a speaking exercise. The recording itself is saved on your device — we never keep a copy.
However, to give you word-by-word feedback the app has to send the clip somewhere that can listen to it. When you are online, a recording is sent to our Cloudflare Worker, which passes it to OpenAI and returns the result:
- Transcription and word timings (OpenAI Whisper) — so the app knows which words you said and exactly when
- Pronunciation grading (an OpenAI audio model) — which listens to the clip to score how you said it
This happens automatically as part of speaking feedback and role-play; it is not a separate opt-in. Our Worker stores nothing: it holds no database and writes no logs of your audio or text — it forwards the request and returns the answer.
Workplace practice conversations work differently. There, the app uses the speech recognition built into your browser to turn what you say into text. On Chrome and on Android this is a Google service: your browser sends the audio to Google to be transcribed, under Google's privacy policy, not ours. We never receive that audio. The resulting text is then sent to our Worker and on to OpenAI so the character can reply. The same browser speech recognition is also what the app falls back to elsewhere when the Worker cannot be reached.
OpenAI does not use data sent through its API to train its models, and we have not opted in to any data-sharing programme. We also do not enable OpenAI's optional call logging, so your recordings and text are not kept in our OpenAI account. OpenAI retains API requests for up to 30 days for abuse monitoring and then deletes them.
3. Camera — Posture Coach (zero-capture)
The camera activates only when you enable the Posture Coach, and follows a strict zero-capture, local-loop design:
- Frames are analyzed on-device (Google MediaPipe running locally) and discarded immediately
- No video, image, or facial data is ever recorded, cached, stored, or transmitted
- Only ephemeral numeric posture coordinates exist while the coach runs; they are mathematically irreversible and cannot reconstruct your face
- Turning the coach off releases the camera completely
Unlike the microphone, the camera feed never leaves your device under any circumstances.
4. When data leaves your device
These are every case, and what is sent:
- Speaking feedback and role-play: your voice recording, to our Worker and on to OpenAI (see section 2)
- Workplace practice conversations: the audio of your turn, to your browser's speech recognition service — Google, on Chrome and Android (see section 2). The resulting text, together with the recent turns of that conversation, then goes to our Worker and on to OpenAI so the character can answer you. Because you are describing your own working life, this text will often contain things like your name, your experience and where you have worked
- Executive Polish, and the Résumé & LinkedIn coach: the text you type or dictate, to our Worker and on to OpenAI, which returns the rewritten versions. In the Résumé coach that text is your professional summary
- Natural voices: the text to be spoken, to our Worker and on to OpenAI. Choosing the device voice in Settings keeps this on your device instead
- YouTube: videos in the Shadowing Studio play via YouTube's embedded player, subject to YouTube's privacy policy
- Dictionary definitions: individual words you tap, looked up anonymously via the free Dictionary API
- Fonts and the on-device vision model: fetched from public CDNs
- Analytics: anonymous page counts only — see section 7
- Daily reminders, if you switch them on: your browser's push address and the time of day you chose — see section 8
None of these requests carry your account. Analytics, dictionary look-ups, fonts and reminders carry nothing about you at all. The three AI features above are the exception, and only because they cannot work otherwise: they carry whatever you chose to say or type, which in a practice conversation or a résumé summary may include your name and your work history. We do not sell data, and there are no advertising or social-media trackers in the app.
5. Optional cloud sign-in
Sign-in is optional and off unless you choose it. If you create an account with an email address and password, we use Google Firebase to authenticate you and to store a copy of your progress so it follows you between devices.
What syncs: completed sessions, scores, notes, saved phrases, vocabulary, streak and activity dates, competency and achievement records, and a record of each practice conversation — when it happened, which scenario it was, and the scores it produced.
What does not: your voice recordings, the text of what you said in a practice conversation, anything the app extracted from that text, and whatever you typed into the Résumé coach. Those stay on this device. The cloud copy is filtered before it is sent, so your spoken words are not in it even though the app keeps them locally for you.
You can clear the stored text of your conversations at any time without losing your progress: Account → Delete saved conversations. You can delete the whole account and its stored copy at any time; see Delete your account.
6. Optional GitHub backup
If you choose to connect your own private GitHub repository for backup, your progress and recordings are transmitted directly from your device to your repository using your own access token. Unlike the cloud copy in section 5, this is a full backup: it includes the conversation text that sync leaves behind, because the destination is your own private repository rather than ours. We never see this data or your token; the token is stored only on your device and is never included in exports.
7. Analytics
We use Cloudflare Web Analytics to count page views and see which sites link to us. It is privacy-first by design: it sets no cookies, does not fingerprint your device, and cannot follow you to other websites. We receive aggregate counts only — never an individual profile, and never anything you type, say, record or save. There is nothing here to opt out of because nothing identifies you.
We also count a short list of anonymous actions so we can tell which parts of the app are worth improving: the app being opened, onboarding being finished, a day being marked complete and which week of the programme it was, the reminder being switched on or off, and the share, invite and rate buttons being tapped. These go to our own server, not to an analytics company, and they set no cookies either.
What is recorded is the name of the action, the week or day number where that applies, and the country our network already sees from your connection. There is no device ID and no account link, so these counts cannot be joined together into a picture of one person — which also means we genuinely cannot tell you how many individual people are behind them. Nothing you type, say, record or save is ever included, and the server refuses any event that is not on that fixed list.
8. Daily reminders
Reminders are off unless you turn them on in Settings. If you do, and you allow notifications, your browser creates an anonymous push address for this app and we store it, together with the time of day you picked and a random device ID we generate. That is everything we hold. There is no name, no email, no account link and no practice history attached to it, and the reminder itself is sent empty — the wording you see is composed on your own device, which is also why it appears in your own language.
The one thing your device does tell us is that you have finished a session today, so that the evening reminder is not sent at all. We store the date and nothing else about what you did. Switching reminders off in Settings deletes the push address and the stored time immediately; so does revoking notification permission or uninstalling the app.
9. Children
The app is intended for professionals and learners aged 13 and over.
10. Your rights & data deletion
Your local data is always yours to take or destroy: export it (Account → Export JSON), or erase it entirely (Account → Reset everything, or uninstall the app). If you want to remove only the text of your practice conversations and keep your progress, use Account → Delete saved conversations. The app also clears a practice conversation by itself once it is a week old. If you signed in, deleting your account also removes the synced copy — see Delete your account. If you never signed in, we hold nothing about you to begin with. For anything else, write to us at the address below.
11. Changes & contact
If this policy changes, the "Last updated" date above will change. Questions: contact@lomonec.com