Last updated September 13, 2026
Venakhi is the data controller for the personal data processed through this service. We are established in the European Union and our contact details are at the bottom of this page.
Account data: your name, email address, and the language(s) you're learning. Sign-in is handled by our authentication provider (Google sign-in, or email credentials that we never see in plaintext).
Session data: the audio recordings, transcripts, notes, and chat messages from your live sessions, plus the analyses we generate from them.
Consent records: when you consent to recording or make a cookie choice, we keep an auditable record of it.
Contact channels you add for notifications, such as a phone number for SMS or WhatsApp match alerts, and — if you install our mobile app — a push notification token identifying that device.
Practice recordings you choose to make, such as the short voice clips captured for module certificates.
Usage data: pages you visit inside the app, the device and browser you use, and the date/time of your visits. Used to keep the service reliable and to debug.
Technical session telemetry: connection quality, call attempts, and device health during a live session. Used only to diagnose problems, and deleted after 90 days.
How you found us: the referring link and any campaign tags in the URL when you signed up, with an approximate location (country, region, city) derived from your connection. We never store your IP address.
Billing data: handled by our payment processor (Stripe). We store the last four digits of your card and your invoice history, never the full card number.
Contract: to provide the tutoring rooms, materials, matching, and analyses you signed up for. Without this we can't operate the service.
Consent: for any optional features — for example, recording a live session requires explicit consent from every participant, captured on the invite page before they join.
Legitimate interest: to keep the service secure, prevent abuse, and improve the product. We balance this against your privacy rights and minimize what we collect.
Legal obligation: to keep certain financial records, and to respond to lawful requests from authorities.
Account data is kept while your account is active. Deleting your account starts a 30-day grace period — you can sign back in and cancel during that window — after which your account and its content are permanently purged, including your recordings, practice clips, transcripts, analyses, and avatar.
Transcripts, notes, and analyses are kept until you delete the session or delete your account. They are your learning record; nothing ages them out on our side.
Session audio is kept for as long as your account exists, on every plan, and is deleted when you delete the session or your account. Nothing ages it out on our side. The session owner can listen back to their own track of any session; the other participant's track is playable only for sessions recorded on or after September 13, 2026, when guests began consenting to listen-back when they joined.
Files shared on the whiteboard during a session (images and PDFs) follow the same rule: kept for as long as the account exists, deleted with the session or the account, and downloadable by the session owner from the session's recap in the meantime.
A screen shared during a session is shown live to the other participant only. It is never recorded, stored or analysed.
One important point: a session has two participants. A recording of a shared session can contain personal data relating to both people, so an erasure request from either participant removes the session audio entirely. Transcripts and other session records follow the deletion rules described elsewhere in this policy.
Deleted sessions sit in Recently Deleted for 7 days, then are permanently removed.
Technical session telemetry and notification delivery logs are deleted after 90 days. Usage analytics events are deleted after 24 months. Records of staff access to accounts are kept for 12 months.
Session invite links expire 24 hours after the session they were created for.
Billing records are kept for the period required by tax law (typically 7 years in the EU).
Some of our processors are based outside the EU/EEA. Where that's the case we rely on the European Commission's Standard Contractual Clauses (SCCs) and equivalent transfer mechanisms to protect your data.
You can: access your data, correct it, delete it, export it (data portability), restrict our processing of it, object to processing based on legitimate interest, and withdraw consent at any time.
Deleting your account and its data can be done directly from Settings → Account. For access, export, or anything else, email privacy@venakhi.com and we'll respond within one month.
You also have the right to lodge a complaint with your national data protection authority.
Your data is encrypted in transit (TLS) and at rest. Passwords are handled by our authentication provider and stored as salted hashes; we never see the plaintext. We follow the principle of least privilege — only the people who need access to your data have it, and access is logged.
No system is perfectly secure. If a personal data breach occurs, we will notify the appropriate supervisory authority within the time required by law and, where the breach is likely to result in a high risk to you, we will notify you without undue delay.
Data protection questions: privacy@venakhi.com.
General contact: hi@venakhi.com.