Privacy Policy
ThaiSpeak (mangothaitutor.com) · Last updated: September 21, 2026
Who we are
ThaiSpeak is a language-learning app operated by Jupitor Team. To reach us, see Support.
Information we collect
- Account information. When you sign in with Google or Apple we receive your name, email address, and profile picture from that provider. We never see or store your password. If you use Sign in with Apple and choose to hide your email, we only ever receive Apple’s private relay address.
- License and device information. If you activate a license, we store the license status and a device identifier to enforce the device limit.
- Subscription information. If you subscribe inside the App Store or Google Play build, Apple or Google processes the payment — we never see or store your card, bank or billing details. What we receive and keep against your account is the plan you bought, the store’s transaction identifier and the date the subscription runs to, which is what lets the app know your subscription is live and restore it when you sign in on another device.
- Usage. We record how many AI credits your account uses — per day for a free account, per week for a license or subscription, and across the whole of a trial — to apply those limits, together with per-feature totals of how much the service costs to run.
- Content you submit to AI features. Text you translate, messages you send to the AI tutor, audio you record for speech recognition, and images you submit for text recognition are sent to Google Cloud to produce the answer and are not kept afterwards. Two things are kept against your account: the words you look up, which guide which lessons we write next, and any answer you report, so we can fix it. None of this content is used for advertising.
- Learning progress. Which lessons and cards you have completed is stored on your device and also on our servers, against your account, so that your progress follows you to a second phone or tablet.
- Your community profile. If you use the community features, other learners can see your display name, your profile picture, the chat level and role you choose, the posts you share with them, and a small “active now” mark when you have used the app recently. Your email address is not shown to other learners.
- Community feed. We store the posts you publish, your comments and reactions, the posts you repost or hide, who you follow, your friend requests, and the notifications you receive. A post is shown to the audience you choose for it — every signed-in learner, or only your friends.
- Community chat. We store the username and display name you pick, the text and voice messages you send, and who you block. A direct message is visible only to the person you send it to. Voice messages are stored privately and can be played only through short-lived links issued to signed-in learners who can see the message.
- Profile picture checks. Before your Google profile picture is shown to other learners, it is sent to Google Cloud Vision to check it for explicit content. We do not store a copy of the picture.
- Notifications. If you allow notifications, we store your device’s push token so we can tell you when someone sends you a friend request or accepts yours.
- Error and performance reports. When something goes wrong in the app, technical details of the error are sent to Sentry so we can fix it, along with timing measurements from a sample of sessions. It is set up not to attach personal identifiers such as your name or email, and it does not record your screen.
How we use your information
- To sign you in and keep your session active (session cookie).
- To provide translation, AI chat, speech, dictionary and community features.
- To apply license terms and usage limits.
- To keep the service secure and diagnose problems.
We do not sell your personal information, and we do not show third-party advertising.
Service providers
We rely on the following providers to run the app:
- Google Cloud — AI answers, translation, text-to-speech, speech-to-text, text recognition in photos, and explicit-content checks on profile pictures.
- Google / Apple — sign-in.
- Firebase Cloud Messaging (Google) — delivering notifications to your device.
- Vercel — hosting.
- Managed PostgreSQL + Realtime (Supabase) — the database, and live chat signals: typing indicators. Messages themselves are never sent this way.
- Cloudflare — storage for lesson audio, chat voice messages, and our database backups.
- GitHub — a second copy of our database backups.
- Sentry — error monitoring.
- Telegram — internal notifications to our team when a purchase or renewal is made, and when a paid account runs out of credits. They identify the account only by its internal id, never by your name or email.
Data retention and deletion
Account data is kept while your account is active. You can delete your account at any time from Profile → Delete account inside the app. When you do, we delete from the live service straight away: your account and sign-ins, devices, usage records, lookups and progress, your community profile, posts, comments, reactions, follows, friend requests and notifications, your chat messages and the voice messages you sent, the voice messages others sent you in direct messages, and your notification tokens. Reports you filed are kept so we can still act on them, with your account and email address removed from them. Reports other learners filed about something you posted keep the text they reported, so we can finish reviewing them.
A few records are kept after deletion, for these reasons:
- A record that your Google or Apple sign-in has already used its free trial — the provider’s account identifier and the email address — so that a new account cannot claim a second trial.
- Purchase records for subscriptions and credit top-ups, kept for renewals, refunds and our accounts.
- Aggregate totals of how much each feature costs to run, under an identifier that no longer links to you.
Copies of the database in our backups are kept for about 90 days and then deleted, so data from a deleted account can remain in a backup for up to that long.
You can also ask us through Support, from the account you signed in with, and we will delete it within 30 days.
Children
ThaiSpeak is not intended for children under 13, and we do not knowingly collect personal information from children under 13.
Changes
If this policy changes, the new version will be posted on this page with an updated date.