Privacy.
The short version: Vocula keeps your email and what you write — scenarios, memory anchors, the decks built from them — in a database we control, hosted in the EU. You can export everything from inside the app at any time, and delete your account whenever you want — doing so removes the scenarios, decks, cards, and study history you created. To be straight with you, two narrow things can outlive deletion: a deck another learner already added to their own library (kept for them), and anonymised cost logs that hold no text (the "How long we keep it" section spells out exactly what stays). We never sell it, and there are no ads or trackers. One thing leaves the EU: the text you write is sent to our AI provider — both to strip out other people's details and to generate your cards — and that provider may process it outside the EU. The rest of this page is the detail.
Who we are.
Vocula and this website are made by Qatalytic Oy, a Finnish private limited company (business ID 3509976-8) based in Espoo, Finland. For anything in this policy — including any of the rights below — contact us at hello@qatalytic.fi.
For GDPR purposes Qatalytic Oy is the data controller for both the app and the website.
What this covers.
Two things: the Vocula app (the part you sign in to and study in) and the website waitlist (the form on this site). Most of this page is about the app. The waitlist is its own short section near the end.
The app — what we collect, and why.
When you use Vocula, we store:
- Your email address. It's how you sign in (a one-time code or magic link) and how we'd reach you about the alpha. That's the only reason.
- Your language pair. The language you speak and the one you're learning — so the app knows what to generate.
- The scenarios you write. The situations you want to prepare for. These are the seed for your cards. (See the next section — personal names and places are stripped out before anything is saved.)
- Your memory anchors. If you use the memory-palace feature, the places and associations you describe.
- Your decks and cards. The flashcards generated from your scenarios, and any you keep.
- Your review history. Which cards you've reviewed and how you rated them — this is what makes the spaced-repetition schedule work.
- A log of AI requests. A record of each call made to generate your content, kept for cost and debugging. It stores usage and cost only — token counts, model, timing — not the text you wrote, scrubbed or otherwise.
We do not collect: your real name, your location, advertising identifiers, your contacts, or anything from analytics or tracking SDKs. There are none in the app at this stage.
We strip out other people's details before saving.
Your scenarios are about real life, so they often mention real people — "lunch with my boss Mikko at the clinic on Tuesday." Those people haven't signed up for anything, so before any of your text is saved, Vocula runs it through a step that replaces personal names, specific addresses, and named workplaces with generic stand-ins (Mikko becomes a neutral first name; "the clinic on Mannerheimintie" becomes "a clinic"). Only the stripped version is stored.
We want to be precise about how that step works, because it matters: the stripping is performed by our AI provider, the same one that builds your cards. That means your raw text — including any names you typed — is sent once to that provider to perform the strip, and that provider may process it outside the EU (see "The one thing that leaves the EU" below). Your raw text is never written to our database: only the scrubbed version comes back and is stored, and the log we keep of AI requests records usage and cost, not your text. So the people you mention are processed transiently, for one short request, and then erased from everything we keep — but they are processed. This is the honest trade-off behind protecting their privacy.
Legal basis.
Different things we do with your data rest on different legal grounds under GDPR. Here's the honest breakdown:
- Running the service — Article 6(1)(b), performance of a contract. Storing your email so you can log in, storing your scenarios, anchors, decks, cards and review history, and generating cards from them is what you signed up for. We process this data because it's necessary to provide the service you asked us to provide, not because you ticked an extra box.
- The AI-request log — Article 6(1)(f), legitimate interest. We keep a record of each AI call (usage and cost, not your text) to control spend and debug problems. Our legitimate interest in running a sustainable, working service is the basis; it's minimal and doesn't override your rights.
- De-identified accounting rows after you leave — Article 6(1)(c) legal obligation, and 6(1)(f). When you delete your account we sever the link to you, but anonymised cost records remain. We're allowed (and in places required) to keep bookkeeping records, so the basis is our legal obligation plus our legitimate interest in accurate accounts.
- Explicit consent — Article 9(2)(a). Your scenarios can contain sensitive information about you (see the next section). We rely on your explicit consent to process that.
- Plain consent — Article 6(1)(a). Reserved for genuinely optional things (for example, if we ever quote an anonymised sentence in a public changelog). Anything optional is opt-in, and only ever with your consent.
Why this matters for you: withdrawing consent to something optional does not break the core service — the service runs on the contract (6(1)(b)), not on consent. If you want to end that contract and stop all processing, the way to do it is to delete your account (in the app, or by asking us). See Your rights.
Sensitive information in your scenarios.
Vocula asks you to write about "conversations you're dreading" — real situations you want to rehearse. Honestly answered, those can reveal special-category data about you: a health appointment, a conversation tied to your religion, your sex life or sexual orientation, your ethnicity, and so on. Article 9 of GDPR treats this kind of data as especially sensitive.
Two things you should know. First, the name/place stripping described above does not remove this — it replaces other people's names and addresses, but "the conversation with my doctor about my diagnosis" stays, because it's about your situation, not a third party's identity. Second, you are choosing to provide this when you write a scenario; nothing forces you to, and you can keep scenarios as vague as you like.
Because of that, our legal basis for processing any special-category data in your scenarios is your explicit consent under Article 9(2)(a), which you give on the tester consent page. You can withdraw it at any time by deleting your account.
No automated decisions about you.
Vocula does not carry out automated decision-making that produces legal or similarly significant effects about you within the meaning of Article 22 — the AI only generates study content from your text. Nothing here decides anything about your rights, money, access, or status.
Where your data lives.
We use a small number of subprocessors. Here's all of them, and where they sit:
- Supabase — our database and authentication provider: authentication, database, and all your stored content. Hosted in the EU. None of your stored data leaves the EU.
- Google LLC — our AI provider: the AI that generates your cards and hints, and that runs the name/place stripping step. This is the one place your input is processed outside the EU — see the next section.
- Resend — our email-delivery provider: delivers your sign-in emails. EU region (Ireland).
- Vercel — our website host: serves this marketing site and runs the waitlist form's server-side code, which handles your email, a one-way hashed IP, and user-agent before they're stored. EU region (Frankfurt). Not used by the app you sign in to.
Some of these providers are headquartered outside the EU (for example in the US) even though the data they hold for us is hosted in the EU. Where a provider could remotely access EU-hosted data — for support or operations — that access is covered by a data processing agreement with appropriate transfer safeguards.
No marketing partners, no data brokers, no ad networks, no analytics. Your data is never sold, traded, or licensed.
The one thing that leaves the EU.
The text you write for AI generation is processed by our AI provider, Google LLC, which may process it in a data center outside the EU — typically the US. This covers both the name/place stripping step (which runs on your raw text) and the card generation that follows.
- The transfer relies on Standard Contractual Clauses (SCCs) — the legal mechanism GDPR provides for EU-to-non-EU transfers — and additionally on Google LLC's certification under the EU–US Data Privacy Framework, the adequacy decision the European Commission has adopted for certified US recipients. Where the Framework applies it is the basis for the transfer, with the SCCs as a fallback.
- We have assessed this transfer (a Transfer Impact Assessment) and are satisfied the safeguards are adequate for the limited data involved.
- Our provider does not train its models on this input, per its data-use terms.
- Your data at rest still never leaves the EU. This applies only to the live AI request.
How long we keep it.
- While you have an account, we keep your data so the app works.
- This is a closed alpha. When the alpha ends, we delete tester data within 30 days unless you've chosen to continue.
- When you delete your account, we delete it: your sign-in identity, your profile, your memory anchors, and the decks, cards, and study history you created are removed from the database.
-
There are two narrow exceptions, and we want to be upfront about them:
- A deck another learner has added. If you published a deck and someone added it to their own library, that deck is unpublished and unlinked from you, but it is not deleted — their copy, and the shared deck behind it, stay so they keep their study progress. A shared deck like this carries the scenario you wrote: our create-time step removes other people's names and places, but not your own details. So don't publish a deck whose scenario you wouldn't want to outlive your account. (See Sensitive information in your scenarios and Shared decks.)
- The AI-request log. We keep anonymised cost records (token counts and cost, never your text) after deletion, for accounting. The link to you is removed.
Shared decks.
If you publish a deck to the shared library:
- It becomes visible to other learners on the same language pair.
- You stay anonymous unless you choose to publish under a display name.
- The title and description you write for the library are separate fields you fill in yourself — re-read them before publishing, since the privacy scrub doesn't re-run on text you type there.
- A published deck carries the scenario you wrote on the deck and its cards. Other people's names and places were stripped at creation, but your own details were not (see Sensitive information in your scenarios). Don't publish a deck whose scenario you wouldn't be comfortable sharing.
- Unpublishing is not a recall. It removes the deck from the library and stops new people adding it, but anyone who already added a copy keeps it — and their own study progress. Unpublishing does not reach into their account to remove it.
- Deleting your account works the same way. A deck no one else uses is deleted outright. A deck someone had already added is de-listed and unlinked from you, but not clawed back — their copy, and the shared deck behind it, stay with them for their own study. (See How long we keep it.)
- Published content is reviewed when reported, not pre-screened. There's a "report" option on shared decks and cards.
Your rights under GDPR.
You can:
- Access / port — the app has Settings → Your data → Export my data, which gives you a machine-readable copy of everything tied to your account.
- Erase — Settings → Your data → Delete my account deletes your account and the decks, cards, and study history you created. The limits, plainly: a deck another learner had already added is unpublished and kept for them (not deleted), and anonymised cost logs remain. See How long we keep it and Shared decks.
- Rectify — fix anything wrong.
- Restrict / object — pause or say no to specific processing.
- Withdraw consent — any time, for anything you consented to optionally, and for the explicit consent covering sensitive scenario content. Withdrawing optional consent doesn't stop the core service; to end the service entirely, delete your account.
Verifying it's you. Before we act on an access or erasure request, we need to be sure it's really you asking. The simplest way: send the request from — or confirm it via — the email address registered to your account. For sensitive requests we may ask one extra question to confirm, and we won't ask for more than we need.
The export and delete options are in the app. For anything else, contact hello@qatalytic.fi. We respond within one month. For complex or numerous requests we may extend this by up to two further months, and if we need to, we'll tell you why within the first month. If we fall short, you can complain to the Finnish data-protection authority (tietosuoja.fi) or the supervisory authority where you live.
Age.
Vocula is not intended for anyone under 16, and you confirm you're 16 or older when you sign in. To be clear, 16 is our own, more conservative choice, not the legal floor: Finland's digital-consent age under GDPR is 13. We've set the bar higher on purpose. If you believe a younger person has signed up, contact us and we'll remove the account.
Security.
Everything travels over HTTPS. Your data is encrypted at rest in the database, and your sign-in tokens are stored in your phone's hardware- backed secure storage (Android Keystore / iOS Keychain), not in plain text. Access to your data is confined to your own account by row-level security.
If something goes wrong (a data breach).
If your data is exposed in a way that puts you at risk, we'll notify the Finnish data-protection authority within 72 hours and tell you directly without undue delay.
The website waitlist.
This part is only about the form on this site, not the app.
When you join the waitlist, we collect:
- Your email address — so we can write back when there's something to try.
- What you wrote in the "conversation you're dreading" box — it shapes which scenarios we prioritise. A sentence is occasionally quoted on the changelog, but only ever paraphrased and anonymised, never with your email or anything identifying.
- A one-way hash of your IP address — a SHA-256 fingerprint, not your raw IP — and your browser's user-agent, used only to filter spam from real signups.
- The submission timestamp.
Waitlist entries sit in the same EU-hosted database. If you don't respond within six months of our email about the product, we delete the row; if you ask sooner, within 30 days.
The legal basis differs by field. For your email address it's your consent, given when you submit the form — you can withdraw it any time. For the hashed IP address and user-agent, it's our legitimate interest (Article 6(1)(f)) in keeping spam and abuse out of the signup form; we never use them to identify or profile you.
Cookies.
This website sets no cookies and runs no analytics. The app stores only what it needs to keep you signed in. If that ever changes, this page changes first.
Changes to this policy.
If we update this policy, the "Last updated" line at the top changes. Material changes — anything affecting what we do with your data — we'll tell testers about directly.
Contact.
Qatalytic Oy (business ID 3509976-8) · hello@qatalytic.fi · Espoo, Finland.