On this page
Privacy policy
What we do with your data
This page explains what personal data Agnetia processes, what for, for how long and who it is shared with. It is written to be read in full: if something is unclear, that is a defect of this page and we would like to hear about it.
Version of 20 September 2026
The controller's identifying details are not published yet. Agnetia is operated by a company registered in Spain; its legal name, tax number, address and contact email will be published here as soon as they are completed. In the meantime, the rights described on this page are exercised from Support, inside your account, and are handled within the same statutory deadline.
01 / 11
Who processes your data
- Controller
- Not published yet
- Tax number
- Not published yet
- Address
- Not published yet
- Contact
- Not published yet
The controller is the company registered in Spain that operates Agnetia. No data protection officer has been appointed: the processing meets none of the cases that require one under article 37 of Regulation (EU) 2016/679 (GDPR) or article 34 of Spanish Organic Law 3/2018 (LOPDGDD).
The supervisory authority is the Spanish Data Protection Agency, the AEPD (www.aepd.es).
02 / 11
What data we process
The full list. If a piece of data is not here, it is not processed.
| Data | Where it comes from |
|---|---|
| Email address | You provide it when you sign up. It is your username |
| Name | You provide it when you sign up |
| Password | You choose it. It is stored hashed with no way back: nobody can read it |
| Google identifier and profile picture | Only if you sign in with Google, and only what Google returns when verifying your identity |
| Native language, language studied and level | You choose the languages; the level is calculated by the platform from your conversations |
| Learning progress | Generated as you use the platform: what you got right, what you are reviewing, which phase you are on |
| Transcript of what you say in each turn | Generated as you speak. The audio is not kept; the transcript is, for thirty days |
| Wallet balance and usage | Generated as you use the platform and as you pay |
| Card brand and last four digits | Returned by the payment provider. The full number never reaches our systems |
| Billing address and tax number | You provide them on the payment provider's screen and they stay on your record there; this database does not copy them |
| IP address, browser and date of access | Logged by the system in a security history when you sign in, change your password or delete your account |
| The tickets you open in Support | Whatever you write and the files you attach |
No special categories of data are processed — health, beliefs, ethnic origin, biometrics — no profiling with legal effects is carried out, and there are no automated decisions that significantly affect you. The level the platform estimates is an indicative teaching assessment that only you see.
No data is bought or enriched from outside sources: everything above comes from you or from your own use of the service.
03 / 11
What we use it for, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Creating and maintaining your account, verifying your email and giving you access | Performance of the contract (art. 6(1)(b) GDPR) |
| Providing the service: asking, listening, correcting and saving your progress | Performance of the contract |
| Charging the fee and top-ups, and issuing invoices | Performance of the contract, and legal obligation for invoicing (art. 6(1)(c)) |
| Sending you service emails: verification, password reset, deletion confirmation and payment notices | Performance of the contract |
| Handling the tickets you open | Performance of the contract |
| Keeping a history of sign-ins and sensitive operations to detect fraud and abuse | Legitimate interest in the security of the service and of accounts (art. 6(1)(f)) |
| Keeping turn transcripts for thirty days so a disputed correction can be reviewed and the agent's quality measured | Legitimate interest in service quality and traceability (art. 6(1)(f)) |
| Keeping invoices and accounting records | Legal obligation (art. 6(1)(c)) |
No purpose relies on your consent, because none needs it: no marketing messages are sent, no data is shared for advertising, and there are no analytics or advertising cookies. If anything of that kind were ever added, consent would be asked for beforehand and separately.
Where the basis is legitimate interest you can object to the processing, and the objection will be upheld unless compelling grounds override it. For the security history such grounds usually exist: it is what makes it possible to show who got into an account.
04 / 11
Your voice and your conversations
It is the most sensitive data that passes through here, so it gets its own section and the detail it deserves.
- The audio of what you say is not stored. It is sent to the transcription service, turned into text and discarded. There is no recording of your voice kept anywhere, not even briefly once the turn ends.
- The model that decides what to say back never receives the audio: it receives the transcribed text. That is what keeps your voice from travelling beyond the transcription step.
- Each turn's transcript is kept in an audit log that is deleted after thirty days. It exists so a correction you dispute can be reviewed, and so the agent's teaching can be measured.
- The agent reads from your record only what the turn needs — your name, the two languages, the chosen voice and what you have demonstrated so far — and it cannot delete your progress or your history.
- What you say is always treated as data, never as instructions: asking the agent to change your progress or ignore its rules changes nothing.
- The level the platform estimates from your conversations is never said out loud and never returns to the conversation. You look it up in your profile, and nobody else does.
05 / 11
Who it is shared with
Nobody buys your data, and none is handed to third parties for their own purposes. What there is are providers who process data on Agnetia's behalf so the service can work, each under a data processing agreement.
| Provider | What for | What it receives |
|---|---|---|
| Stripe | Payment, invoicing and tax calculation | Your email, your billing details and your payment method details, which you type directly on its page |
| OpenAI | Voice transcription, the text model that decides the reply, and speech synthesis | The turn's audio in order to transcribe it, and the turn's text with the minimum context of the exercise |
| Resend | Sending service emails | Your email address and the content of the message |
| Railway | Hosting the platform and the voice agent | The infrastructure everything above runs on |
| Managed database provider | Database storage | The data in the table above, except what only exists at Stripe |
| Only if you use Sign in with Google, to verify your identity | The sign-in request. Google receives nothing about your activity in Agnetia |
The artificial intelligence models are configurable and the provider can change without the agent's behaviour changing. If it changes, this table changes with it and the date above reflects that.
Beyond these providers, data may be disclosed to public authorities, courts or law enforcement where a legal rule requires it.
06 / 11
Transfers outside the European Economic Area
Some of the providers above are companies headquartered outside the European Economic Area, or may process data on servers located outside it.
Where that happens, the transfer relies on one of the mechanisms in chapter V of the GDPR: an adequacy decision of the European Commission — such as the EU-US Data Privacy Framework for certified providers — or the standard contractual clauses approved by the Commission, together with whatever supplementary measures are appropriate.
You can ask us, through the contact channels, which specific mechanism covers each provider.
07 / 11
How long it is kept
| Data | Retention |
|---|---|
| Your account and your progress | For as long as the account exists. Deleting it removes them along with your vocabulary, exercise profiles and open sessions |
| Audio of your turns | Never kept, at any point |
| Turn transcripts | Thirty days |
| History of sign-ins and sensitive operations | Kept so that what happened in an account can be shown. Deleting the account unlinks it from you: the entry survives without a user identifier |
| Open sessions | The session token lasts thirty days and rotates on every use. They are removed on sign-out, on password change and on account deletion |
| Invoices and accounting records | The statutory retention period for commercial and tax records, which in Spain reaches six years. They are held by the payment provider |
| Support tickets | For as long as the account exists, and afterwards for as long as needed to handle a claim |
08 / 11
Your rights
- Access: to know what data about you is processed and get a copy.
- Rectification: to correct anything inaccurate. You can correct your profile details yourself at any time.
- Erasure: to ask for your data to be deleted. You can do it yourself from the platform, without asking permission: deletion is confirmed with a link sent to your email and cancels your subscription first.
- Restriction: to ask for data to be kept but not used, while a disagreement is resolved.
- Portability: to receive the data you gave us and the data you generated, in a structured, commonly used format.
- Objection: to object to processing based on legitimate interest.
- Withdrawing consent: today no processing relies on it, but if any ever did, you could withdraw it at any time without affecting what came before.
Rights are exercised through the contact channels in the first section, or from Support inside your account. We answer within one month, extendable to two if the request is complex, and it is free unless requests are manifestly unfounded or excessive.
To stop someone exercising your rights in your name, an additional identity check may be requested when a request does not come from the account concerned.
If you believe the processing does not comply with the rules, you can complain to the Spanish Data Protection Agency (www.aepd.es). We would appreciate the chance to sort it out first, but it is not a requirement.
09 / 11
How it is protected
- All traffic travels encrypted, and the server declares that it may only be spoken to that way.
- Passwords are stored hashed with no way back: nobody inside Agnetia can read them.
- The browser session is stored in a way the page's own code cannot read, and it does not travel anywhere else.
- Your card number is not in these systems, so it cannot leak from them. The full detail is on Payment security.
- Database access uses a role limited to the application's own tables, not an administrator account.
- There are attempt limits on sign-in, sign-up and password recovery, and a history of sensitive operations.
10 / 11
Minors
The service is not aimed at children under fourteen and should not be used by them.
Subscribing requires legal capacity to do so: if you are under the age of majority, you need authorisation from whoever holds parental responsibility or guardianship, and that person takes on the contract.
The platform does not verify age at sign-up. If we find out, or are told, that an account belongs to a child under fourteen, it will be deleted along with its data.
11 / 11
Changes to this policy
This policy may be updated when the service, a provider or the rules change. The version in force is always the one published here, with the date shown above.
If a change substantially affects how your data is handled, you will be told by email before it takes effect.