Privacy Policy

Privacy Policy

SayMelo by DaelVista — how we collect, use, and protect your information.

Last Updated: August 2, 2026  ·  Effective: August 2, 2026

1. Introduction

Welcome to SayMelo ("we," "our," or "us"). This Privacy Policy explains how DaelVista LLC collects, uses, shares, and protects your information when you use the SayMelo mobile application (the "App").

Company Information:
Age Requirement: SayMelo is intended for users 13 years of age or older. We do not knowingly collect personal information from children under 13. If we discover a user is under 13, we will delete their data immediately. SayMelo is a general-audience education app and is not directed to children; we do not opt into Google Play's Designed for Families programme.

2. Information We Collect

2.1 Information Stored Locally (No Account Required)

The following data is stored on your device using AsyncStorage. It does not leave your device unless you sign in:

2.2 Information You Provide Optionally (Sign-In)

You can sign in to sync your progress and make your credit balance portable across devices. We offer two sign-in methods:

Whichever method you use, the following are also stored server-side against your account:

Signing in is optional. Most of the App works without it, but credits, the Pro subscription, and AI features require a signed-in account because they are enforced server-side. If you sign up with email, we send a confirmation email (and password-reset emails on request) via our email provider — see Section 5.

2.3 Information Collected Automatically

3. How We Use Your Information

  1. Deliver the learning experience: Track your progress, unlock circles, calculate XP and streaks.
  2. Operate the Credits system: Maintain your credit balance, grant welcome / ad / purchase / subscription credits, and debit credits when you use paid AI tools — all enforced server-side.
  3. Power AI tools: Route your inputs to DeepSeek to run the AI-powered tools (SlangDecoder, SlangRoleplay, ToneMaster, AIReview, ScenarioChat, Write & Polish) and AI Custom Practice, and to OpenAI Whisper for the transcription used by Pronunciation Check and by "Answer in your own words". Four practice tools (FillTheGap, WordSnap, SentenceBuilder, FixMySentence) run entirely on your device from a built-in content library and send nothing to any AI provider. These four also give you 2 free practice sessions every day without spending credits.
  4. AI personalization: Analyze your mistake patterns locally and send an anonymised weak-area profile to DeepSeek to generate custom practice and AI Coach insights.
  5. Insights dashboard: Process your locally stored activity data on-device to display performance trends, accuracy rates, and learning momentum.
  6. Review Box & spaced repetition: Use SM-2 data stored on your device to schedule flashcard reviews.
  7. Streak Restore: Allow you to spend 1 credit to restore a broken learning streak. The credit debit is processed server-side; no additional personal data is collected for this action beyond the standard credit ledger entry.
  8. Free daily practice and speaking: Give free users 2 practice sessions every day on the four on-device tools, and 2 speaking attempts every day across Pronunciation Check and "Answer in your own words", without spending credits. The speaking allowance is counted on our server (see the retention entry in Section 4.7), because unlike the on-device tools each speaking attempt is a real request to a provider. (Optional rewarded ads to earn credits are planned but not active — see Section 4.5.)
  9. Process subscriptions and purchases: Verify Pro subscription status and credit-pack purchases through RevenueCat & Google Play, and grant the corresponding entitlements / credits server-side.
  10. Sync progress (optional): Back up your data to the cloud when you sign in (with Google or email).
  11. Prevent fraud and abuse: Use the device ID and server-side logs to enforce daily ad-credit caps, prevent welcome-credit farming via reinstalls or new accounts, and prevent shared-account abuse.
  12. Send push notifications (optional): Daily on-device reminders — a morning nudge, the daily situation, a slang phrase lesson, a practice nudge targeted to your weak areas, a streak-at-risk alert, and a weekly summary — only if you grant permission. These are scheduled entirely on your device.
  13. Improve the app: Analyze aggregate, non-identifying usage patterns to improve features.

4. Data Storage and Security

4.1 Local Storage

Learning progress is stored locally on your device. It does not leave your device unless you sign in.

4.2 Cloud Storage (Optional — after sign-in)

If signed in, your progress, credit balance, and credit ledger are stored in Supabase (hosted on AWS). Data in transit is encrypted with TLS 1.3. Data at rest is encrypted by Supabase. Sensitive operations (credit spending, purchase grants, welcome grants) are gated by Supabase Row-Level Security (RLS) and service_role-only RPCs that the client cannot call directly.

4.3 AI Practice Tool Data

When you use one of the AI-powered practice tools (SlangDecoder, SlangRoleplay, ToneMaster, AIReview, ScenarioChat, Write & Polish) or AI Custom Practice, your text input is sent to our Supabase Edge Function proxy and forwarded to DeepSeek. For the two speaking features — Pronunciation Check and Answer in your own words — the short audio clip is forwarded to OpenAI Whisper for transcription, and the resulting transcript then goes to DeepSeek for the written feedback. The four on-device tools (FillTheGap, WordSnap, SentenceBuilder, FixMySentence) send no input to any AI provider. We do not log or store your AI conversation content or audio on our servers, but the proxy does log per-call metadata (user ID, device ID, tool ID, timestamp, token usage, estimated cost) for billing accuracy, cap enforcement, and fraud prevention. Each provider processes requests per its own policy — DeepSeek and OpenAI.

Speech feedback is transcription-based matching plus a written tip. It is educational and may be inaccurate; it is not a clinical or phoneme-level pronunciation assessment.

4.4 AI-Generated Content Cache

When you use AI Custom Practice or the AI Coach insight, the AI-generated output is cached in Supabase to avoid repeated API calls for the same anonymised weak-area fingerprint. This cache:

4.5 Advertising — currently none

SayMelo shows no advertising at all. Rewarded ads are disabled in the shipped app, no advertisement is requested or displayed anywhere, and no advertising network receives any data about you. The Android manifest actively removes the AD_ID permission and the related advertising-services permissions.

There are no ads in the lessons either: the situations and Slang Hub content are free, unlimited, and ad-free for everyone.

Optional rewarded ads — which you would choose to watch in the Credits screen to earn credits — are planned but not active. If they are enabled in a future release, we will update this policy and our Google Play Data Safety declaration before the release goes live, and we will name the advertising network here along with the data it processes.

4.6 Push Notifications

If you grant notification permission, your device generates a local push token used by Google Firebase Cloud Messaging (FCM) on Android. All notification scheduling — a morning practice reminder, the daily situation, a daily slang phrase lesson, a personalized practice nudge based on your weak areas, a streak-at-risk reminder, and a weekly summary built from your activity — is handled entirely on your device via expo-notifications. A gentle default notification sound may play. We do not send server-side push notifications and do not store your push token on our servers.

4.7 Data Retention

5. Third-Party Service Providers

We do not sell your personal information. No advertising network is in this list, because SayMelo currently shows no advertising (Section 4.5).

ServicePurposeData Shared
Google Play BillingPayment processing (credit packs & Pro subscription)Purchase transaction info
RevenueCat, Inc.Subscription & purchase verification, webhook-driven credit grantsDevice ID, anonymous user ID, purchase & subscription status, transaction IDs
Supabase (hosted on AWS)Auth, cloud backup, credit ledger, AI proxy, AI content cache, security logsAccount ID, device ID, progress data, credit ledger, AI inputs (forwarded, not retained as content), AI-generated cache (anonymised)
DeepSeekGenerates feedback for the AI text tools and AI personalizationText inputs to AI tools, speech transcripts, and anonymised weak-area profiles
OpenAI, LLC (Whisper)Transcribes the recordings from Pronunciation Check and "Answer in your own words" — transcription only, no other useShort audio clip plus the reference sentence or the situation prompt, sent only after you press submit
DeepL & MyMemoryTranslate eligible on-screen learning text when you use the translation featureThe specific text selected for translation
SentryCrash and performance diagnosticsApp version, OS, screen route, crash stack, timings, categorical error codes — no screenshots, request bodies, or account identity
Supabase Auth (Google or Email sign-in)Sign-in — optional but required for credits & subscriptionName, email, Google ID (Google), or email + hashed password (email sign-up) — only if you sign in
Resend (resend.com)Delivers transactional emails (account confirmation & password reset) for email sign-inYour email address and the email content (only if you sign up with email)
Google Firebase Cloud Messaging (FCM)Local push notifications — AndroidDevice push token (handled on-device; not stored by us)

6. Credits, Ads, and Subscription — Privacy Implications

6.1 The Credits System

The App uses a credits-based monetization model. Every credit grant (welcome, ad-reward, in-app purchase, monthly subscription allowance) and every spend (per AI tool use) is recorded in a server-side ledger tied to your account. This ledger is the source of truth for your balance and is what allows credits to follow you across devices when you are signed in.

6.2 Rewarded Ads (Earn Credits)

Rewarded ads are not active in the current release (Section 4.5). The mechanism below is documented because the code is present and disabled, so you know exactly what would happen if it is ever switched on.

If you chose to watch a rewarded ad in the Credits screen, our server would first issue a single-use, short-lived security token (a "nonce") bound to your account before the ad was shown. When the ad completed, that server-issued token would be sent back and consumed to grant the corresponding credit. This design means the reward is decided by our server, never by the ad network — so a faulty or hostile ad SDK cannot mint credits. The data an advertising network would collect during the ad would be governed by that network's own policies, and we would name it in Section 4.5 before enabling anything.

6.3 No Ads in Lessons

The lessons — all situations and Slang Hub content — are free, unlimited, and contain no advertising for everyone. In the current release there is no advertising anywhere in the App.

6.4 Pro Subscription

The Pro subscription ($9.99 / month) grants 700 monthly credits and removes all advertising. Subscription state is verified by RevenueCat against Google Play, and the monthly credit allowance is granted server-side via a RevenueCat webhook at each renewal (idempotent on the transaction ID). This means a Pro subscriber on a clean device does not need to share any extra data — the entitlement and grants happen through the existing RevenueCat/Supabase pipeline.

6.5 Anti-Abuse Measures

To prevent abuse of the welcome credits and the ad reward system, the App uses a stable device identifier (see Section 2.3). This identifier is used to: (a) enforce the one-time welcome grant per physical device, regardless of how many accounts sign in on it, (b) enforce the daily ad-credit cap, and (c) detect a single account being shared across many devices. It is not used for advertising or for tracking you across other apps.

7. Account Deletion and Data Removal

How to delete your account and data:
  1. Open SayMelo → go to Settings
  2. Scroll down to Delete Account & All Data
  3. Confirm deletion — all cloud data (progress, credit balance, credit ledger, AI cache, subscription record) is deleted immediately

Full instructions: https://apps.daelvista.com/contextly/delete-account-en

If you never signed in, your data exists only on your device. Uninstall the App to remove it.

If you cannot access the App, email support@saymelo.com and we will delete your data within 7 business days.

Note: Purchase and subscription transaction records are retained by Google Play and RevenueCat as required by financial law, even after account deletion. The device welcome-grant record is also retained on a device-only, anonymous basis to prevent welcome-credit farming.

8. Your Rights

Contact: privacy@saymelo.com. We respond within 30 days.

9. Children's Privacy

SayMelo is intended for users 13 years of age or older and is a general-audience education app, not directed to children. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has used the App, contact us at privacy@saymelo.com and we will delete all associated data immediately.

10. International Data Transfers

DaelVista LLC is based in the United States. If you use the App from outside the US, your data may be transferred to and processed in the United States and other countries where our service providers operate. By using the App, you consent to this transfer in accordance with applicable data protection laws.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via in-app notification. The "Last Updated" date reflects the most recent revision. Continued use of the App after changes constitutes acceptance.

12. Contact Us

Email: support@saymelo.com  ·  privacy requests: privacy@saymelo.com

Address:
DaelVista LLC
30 N Gould St Ste N
Sheridan, WY 82801-6317
United States

We aim to respond within 3 business days.

13. Governing Law

This Privacy Policy is governed by the laws of the State of Wyoming, United States.