HablaYa Privacy Policy
Version: 1.1 Effective date: 20 May 2026 Last updated: 22 May 2026
This document is written in plain language while complying with GDPR (General Data Protection Regulation, EU). Our goal: every user should understand what data we process, why, for how long, and what rights they can exercise.
Legal precedence: This English version is the authoritative one. In case of conflict between language versions, this English text prevails.
1. Who we are and who this document is for
HablaYa is an AI-powered language practice service. This document describes the processing of personal data of people who use the service via Telegram bot, Telegram Mini App, web application, or admin panel.
Data controller:
- Name: Aleksei Skopkarev
- Legal status: autónomo (self-employed individual, registered in Spain)
- NIE: Z0174306V
- Registered address: Las Palmas de Gran Canaria, calle Palmar 80, piso 2
- Privacy contact:
privacy@hablaya.work
Under GDPR terminology, the "data controller" determines what data to collect and for what purposes. Technical contractors (hosting, AI providers) act as processors — they process data on our instructions.
2. Territorial scope
The service is available globally via Telegram. Our primary compliance framework is the European Union / EEA (GDPR applies).
Important for residents of the Russian Federation: The service is not intended for residents of the Russian Federation. We do not comply with Federal Law No. 152-FZ "On Personal Data" and do not localize data storage within the Russian Federation. If you are a resident of the Russian Federation and continue to use the service, you do so at your own discretion, and your data is processed according to the rules in this document (GDPR standard).
For users in the United States: As of this version, no specific provisions for CCPA/CPRA (California) are implemented. Data subject requests from California residents will be handled under the GDPR standard, which is generally broader than California requirements.
3. What data we process
| Category | What it includes | Source |
|---|---|---|
| Account and profile | Telegram ID, name, selected languages, proficiency level, voice settings, subscription status | From you during onboarding and in Settings |
| Dialog history | Text of messages in dialog, turn metadata (role, time, context) | From you during use |
| Voice data | Audio messages you send, and their transcripts (STT) | From you when using voice mode |
| Help functions | Translation requests and "What to reply" prompts | From you when using these features |
| Usage and technical logs | Usage events, quotas, idempotency keys, diagnostic logs, security events | Technical, during service operation |
| Payment data | Customer email, billing address, tax-relevant location, customer ID at the payment provider, transaction and subscription status. Payment instruments (card number, bank details) are processed by our payment provider Paddle through its hosted checkout — HablaYa does not receive or store these instruments. On HablaYa's side, we only see the Paddle customer ID and subscription status | From you when subscribing to a paid plan through Paddle |
We do not collect: precise geolocation, contacts from your address book, messages outside the HablaYa dialog, data about your other Telegram chats.
4. Purposes of processing and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the core function (voice-first dialog, text dialog) | Performance of contract (Art. 6(1)(b)) |
| Personalization (remembering level, topic, voice) | Performance of contract (Art. 6(1)(b)) |
| Help functions (Translate / What to reply) | Performance of contract (Art. 6(1)(b)) |
| Processing of voice (STT, TTS) | Explicit consent (Art. 6(1)(a)) — separate voice consent collected at onboarding |
| Security, fraud prevention, abuse protection | Legitimate interest (Art. 6(1)(f)) |
| Diagnostics and incident investigation | Legitimate interest (Art. 6(1)(f)) |
| Compliance with legal obligations (accounting, regulator responses) | Legal obligation (Art. 6(1)(c)) |
On voice specifically: We treat user audio messages as a sensitive data category (close to biometrics, although we do not use voice for identification). Therefore, voice processing requires explicit separate consent via voice consent at onboarding. You may withdraw this consent at any time via Settings → Privacy → "Withdraw voice consent", after which the service will continue to work in text-only mode.
5. Retention periods
Core principle: we store data only as long as needed for a specific purpose, and no longer.
| Data category | Retention period | What happens at expiry |
|---|---|---|
| Account profile | While account is active + 30 days grace after deletion | Deletion |
| Dialog history (text + metadata) | 12 months rolling | Deletion or anonymization |
| Voice messages (raw audio) | 30 days | Irreversible deletion |
| Provider audit logs (prompt/completion texts) | 90 days | PII fields nulled; technical metadata retained (model, cost) |
| Help requests (Translate / What to reply) | 90 days | Deletion |
| Usage / quotas | 24 months | Aggregation or deletion |
| Idempotency cache | 24 hours | Automatic TTL expiry |
| TTS cache (generated audio responses) | 90 days LRU | LRU eviction |
| Payment events | 6 years | Archive per Spanish tax and financial law |
| Security / incident logs | 180 days | Deletion or aggregation |
When an account is deleted, a cascade procedure applies: profile, dialog history, help requests, and associated audit payloads are deleted or anonymized. Technical metadata required for financial and legal reporting (where applicable) may be retained within the periods listed above.
6. Who we share data with
To operate the service, we use the following processors and sub-processors:
| Provider | Role | Location | Data shared |
|---|---|---|---|
| OpenAI Ireland Ltd. | Large language models (LLM), speech recognition (STT), speech synthesis (TTS) | USA (model serving), Ireland (EU data routing) | Dialog texts, prompts, audio messages |
| Google LLC / Google Ireland Ltd. | Alternative LLM (Gemini API), used in canary/multi-provider mode | USA / Ireland | Dialog texts, prompts |
| Telegram FZ-LLC | Authentication, message and voice file delivery, Mini App transport | UAE (Dubai, legal address) | Telegram ID, name, voice message file IDs |
| Paddle.com Market Limited / Paddle, Inc. | Merchant of Record and authorized reseller of paid subscriptions (charges the customer, processes refunds, calculates and remits sales tax) via hosted checkout | United Kingdom (Paddle.com Market Limited) / USA (Paddle, Inc.) | Email (collected by Paddle at checkout), payment instruments (card/bank — via Paddle hosted checkout, HablaYa does not see or store them), billing address, tax-relevant location, customer ID, transaction and subscription status |
| Contabo GmbH | VPS hosting (origin server) | Germany | All service data on the VPS |
| BunnyWay d.o.o. (Bunny CDN) | Edge cache, CDN | Slovenia + global points of presence | Cached HTTP responses (no user data in cached content) |
| Cloudflare, Inc. | DNS-only | USA | DNS queries (no user data) |
We do not sell your data to third parties. Sharing occurs only to the extent necessary for service operation, governed by standard data processing agreements (DPAs) with each processor.
Data may be disclosed pursuant to a lawful request by a public authority where required under applicable law.
7. International transfers
Since the service uses processors outside the EEA (primarily in the USA), the following safeguards apply:
- Standard Contractual Clauses (SCC) of the European Commission, incorporated into each processor's DPA;
- Additional technical measures: TLS encryption in transit, access control on the processor side, minimization of data transferred.
Where applicable for a given processor, we rely on additional grounds (EU-US Data Privacy Framework for certified companies).
8. Your rights
Under GDPR, you have the right to:
- Access your data (Art. 15);
- Rectify inaccurate data (Art. 16);
- Erase your data ("right to be forgotten", Art. 17);
- Restrict processing in certain cases (Art. 18);
- Receive a copy of your data in a machine-readable format (right to data portability, Art. 20);
- Object to processing based on legitimate interest (Art. 21);
- Withdraw consent for consent-based processing (e.g., voice consent) — Art. 7(3);
- Lodge a complaint with a supervisory authority. For Spain, this is the AEPD (Agencia Española de Protección de Datos).
How to exercise your rights:
- Via Mini App: Settings → Privacy
- "Export data" — receive a JSON with all your data;
- "Delete account and data" — full deletion;
- "Withdraw voice consent" — disable voice mode.
- By email:
privacy@hablaya.work— for any other requests.
SLA: We acknowledge receipt of a request within 72 hours and respond substantively within 30 days. In complex cases, this period may be extended up to 90 days (Art. 12(3) GDPR) with prior notice.
Verification: To protect against requests submitted on behalf of someone else, we may ask you to confirm ownership of the Telegram account or email tied to the request.
9. Age policy
The service is intended for users aged 16 and older (globally, with no regional exceptions). The Mini App onboarding includes an age gate where you confirm compliance with this requirement.
If we become aware that an account is registered by a user under 16 without proper consent from a parent or legal guardian, we reserve the right to suspend access and delete the data after notice.
Parents and legal guardians may contact us at privacy@hablaya.work to request deletion of a minor's data.
10. Security
We implement technical and organizational measures:
- TLS encryption for all data transmission channels;
- Access control to the VPS via SSH keys, root access disabled;
- Secret segmentation — production secrets stored outside the repository, with restricted filesystem permissions;
- Logging of administrator actions and system events;
- Regular database backups with 14-day rotation;
- Data minimization — voice message content and dialog texts are not logged;
- Incident response procedures with notification to affected users for significant events (per Art. 33–34 GDPR).
Despite these measures, no system can guarantee absolute security. If you notice an issue, report it to privacy@hablaya.work.
11. Cookies and trackers
The current version of the Mini App uses only strictly necessary technical cookies/storage for authentication session purposes. Analytical or marketing trackers are not used, so no separate consent banner is shown.
If we add analytics or marketing in the future, this will be accompanied by a separate consent banner in accordance with the ePrivacy Directive and GDPR.
12. Changes to this policy
We may update this policy when service functionality, providers, or legal requirements change. Material changes are communicated to users via:
- a banner in the Mini App on next sign-in;
- email notification (if you have provided a contact address).
The last update date is shown at the top of this document. Archived previous versions are available on request at privacy@hablaya.work.
13. Contacts
| Purpose | Contact |
|---|---|
| Data subject requests (DSAR), consent withdrawal, general privacy questions | privacy@hablaya.work |
| Complaint to a supervisory authority (for EEA residents) | AEPD — Spain, or any competent authority in your place of residence |
14. Change history
| Version | Date | Changes |
|---|---|---|
| 1.0 | 11 May 2026 | Initial version. |
| 1.1 | 22 May 2026 | Onboarded Paddle as Merchant of Record for paid subscriptions: §3 "Payment data" — real flow; §6 — added Paddle (Paddle.com Market Limited / Paddle, Inc.) to the processor list; in the same revision, §5 was aligned (the "when enabled" qualifier removed from the retention row for payment events — the section is now consistent with §3 and §6). |
Language versions:
- English (this document) — legally authoritative
- Russian —
docs/legal/PRIVACY_POLICY.md— for Russian-speaking users - Spanish —
docs/legal/es/PRIVACY_POLICY.md
In case of any conflict between language versions, the English version prevails.
Author: Claude | Model: Claude Opus 4.7 (1M context) | Mode: implementation (Paddle migration Phase 6 prep — legal-docs fix after quality review) | Reasoning: not reported by system | Timestamp: 23 May 2026, 00:00 (Europe/Madrid) [2026-05-23T00:00:53+0200]