← Back to home

Privacy Policy

Last updated: 2026-05-07

This policy describes how Francaisia collects, uses, and protects your personal information. It is written for Quebec Bill 25, GDPR (EU), and PIPEDA (Canada) compliance.

1. Data Controller

Francaisia is the data controller for personal information processed via the platform. Contact: legal@francaisia.com.

2. Data We Collect

  • Account data: email address, hashed password (bcrypt), signup timestamp.
  • Progress data: lesson completion, exercise scores, XP, streaks, and gamification milestones, stored as a JSONB blob keyed to your user ID.
  • Subscription data: Stripe customer ID and subscription status (trial / active / cancelled). We do not store credit-card numbers. Stripe handles that directly.
  • Voice recordings: when you complete a speaking exercise, your microphone audio is sent over HTTPS to our server, forwarded to OpenAI for transcription (Whisper) and AI evaluation (GPT), and then deleted immediately. We do not store voice recordings beyond the duration of the evaluation request (a few seconds).
  • Usage analytics: anonymized page views and Core Web Vitals via Vercel Analytics and Vercel Speed Insights: see §6.
  • Cookies: see our Cookie Policy for the full list.

3. Lawful Basis

  • Consent: for optional analytics cookies and any marketing email you opt into.
  • Contractual necessity: to provide the lessons, simulator, and AI feedback you signed up for, and to bill your subscription.
  • Legitimate interests: security, fraud prevention, rate-limit enforcement, and core service operation.

4. How We Use Your Data

We use your data to:

  • deliver lessons, exercises, and AI evaluation;
  • track progress and surface personalized recommendations;
  • process subscription payments via Stripe;
  • secure the platform against abuse;
  • respond to your support requests.

We do not sell your data, share it with data brokers, or use it for behavioural advertising.

5. Data Retention

  • Account & progress data: retained while your account is active. Deleted within 30 days of account closure.
  • Voice recordings: deleted immediately after AI evaluation completes (typical retention: a few seconds; never persisted to long-term storage).
  • AI evaluation transcripts & scores: stored as part of your progress data and deleted with your account on closure.
  • Stripe billing data: retained by Stripe per their policy and applicable tax law (typically 7 years for invoices).
  • Encrypted backups: rolling backups are deleted within 90 days.

6. Sub-processors & International Transfers

We rely on the following sub-processors to operate Francaisia:

Sub-processorPurposeRegion
VercelHosting, edge delivery, Blob storage for TTS audioUSA & Canada regions
SupabasePostgres database (account, progress, XP)[REGION TBD: verify in Supabase dashboard]
StripeSubscription payments & billingUSA (GDPR-compliant; EU-US Data Privacy Framework)
OpenAIWhisper transcription & GPT evaluation of speaking exercisesUSA: voice recordings transcribed and deleted
Google Cloud (Text-to-Speech)Quebec-French voice generation for lesson audioUSA / Global Google infrastructure
Vercel Analytics & Speed InsightsAnonymized page views and Core Web VitalsUSA & Canada

Vercel Analytics disclosure (v1).Vercel Analytics and Speed Insights load on all pages and collect anonymized page-view and web-vitals data per Vercel's privacy policy. We rely on Vercel's privacy-compliance certifications for this v1. Granular consent gating of analytics may be added post-launch based on user feedback. The Francaisia cookie consent banner records your acceptance choice for Quebec Bill 25 evidence-of-consent purposes.

7. Your Rights

Subject to Quebec Bill 25, GDPR, and PIPEDA, you have the following rights:

  • Access: request a copy of your account and progress data.
  • Rectification: correct inaccurate data.
  • Erasure("right to be forgotten"): request deletion within 30 days.
  • Portability: receive your progress data in JSON format.
  • Object: opt out of marketing communications.
  • Restrict processing: limit how we use your data.
  • Lodge a complaint: with the Commission d'accès à l'information du Québec (CAI), the Office of the Privacy Commissioner of Canada (OPC), or your local data-protection authority.

To exercise any right, email legal@francaisia.com. We respond within 30 days.

8. Cross-Border Transfers

Some sub-processors are located in the United States. For Quebec residents, transfers comply with Bill 25 cross-border transfer rules (privacy assessment, contractual safeguards). For EU residents, transfers rely on the Standard Contractual Clauses where applicable.

9. Security

We protect your data with bcrypt password hashing, signed session tokens (JWT), HTTPS everywhere, encrypted backups, and isolation of database service-role keys to server-only code. No system is perfectly secure; we will notify affected users and the relevant authority of any confirmed breach as required by law.

10. Children

Francaisia is not directed at children under 13. Users aged 13–17 must have parental or legal-guardian consent. We do not knowingly collect personal data from children under 13; if you believe we have, contact legal@francaisia.com and we will delete it.

11. Cookies

For the full list of cookies and your choices, see our Cookie Policy.

12. Changes to This Policy

We may update this Privacy Policy. Material changes will be communicated by email at least 30 days before they take effect.

13. Contact & Complaints

Privacy questions, data-subject requests, and complaints: legal@francaisia.com.

You may also contact the Quebec CAI (cai.gouv.qc.ca), the Office of the Privacy Commissioner of Canada (priv.gc.ca), or your local data-protection authority.

This Privacy Policy was prepared with the assistance of AI for an early-stage soft-launch and is not a substitute for legal advice. Francaisia plans to commission review by a Quebec-licensed privacy/SaaS lawyer before scaling beyond a small beta cohort.