Privacy Policy

Last updated: September 3, 2026

The short version: We collect what Tim Budong needs to score your pronunciation and remember your progress. We do not ask for your name, run advertising trackers, or sell your personal information. We may retain recordings to evaluate, develop, and train our own speech and pronunciation models. You can delete your account from the app, but deleting the account does not automatically delete recordings retained for model development.

This Privacy Policy explains how the developer and operator of Tim Budong (“Tim Budong,” “we,” “us,” or “our”) handles information when you use the Tim Budong iOS app, timbudong.com, and the related services (together, the “Service”).

What we collect and why

Our guiding principle is to collect only what we need to provide and maintain the Service.

Pseudonymous account and credentials

When you first use the app, we create random account and device identifiers. We do not ask for your name, email address, phone number, social-media account, or contacts. Credentials that let your device return to the account are stored in Apple’s Keychain; our server stores a one-way hash of the device secret and session records. We use these items to authenticate the app, keep your progress separate from other learners’ progress, and protect the Service.

Voice recordings and pronunciation results

When you choose to complete a speaking exercise, the app uses the microphone to record your voice. We process the recording and related exercise information to assess pronunciation, provide feedback, and personalize your learning experience.

We may store recordings, assessment results, and related technical and contextual information to provide your learning history, operate and improve the Service, investigate problems, and develop new features.

We may also use recordings and related information to evaluate, develop, and train speech and pronunciation models that we own or operate. This use may continue after the account that supplied a recording is deleted. We do not sell recordings or use them to build advertising profiles.

Learning profile and activity

We store choices you make in onboarding and Settings, including your daily goal, preferred practice time and time zone, reminder preference, topic interests, motivation, self-reported level, placement result, onboarding status, practice attempts, mastered readings, progress, and streak. We use this information to personalize exercises, schedule reminders, and show your learning history.

Notifications

If you enable reminders, we store an Apple push-notification token, whether it came from a development or production build, your reminder time and time zone, and delivery status. We send the token and notification contents to Apple Push Notification service (APNs). You can disable reminders in the app or in iOS Settings. Deleting your account removes active push tokens immediately.

Technical and website information

When the app or your browser connects to the Service, our hosting and network providers may process standard request information such as your IP address, request path, date and time, response status, device or browser type, and diagnostic information. We use it to deliver the Service, keep it secure, prevent abuse, and diagnose failures.

Our website does not currently set advertising cookies or include third-party advertising or analytics scripts. The iOS app does not currently include an advertising or third-party analytics SDK.

Messages you send us

If you email us for feedback, support, privacy, or legal questions, we receive your email address and anything you include in the message. We keep correspondence as needed to answer you, maintain support history, and protect our legal rights.

How we use information

We use the information described above to:

We may create aggregate or de-identified statistics that cannot reasonably be linked back to you and use them to understand and improve the Service.

When we share information

We do not sell your personal information. We do not share it for cross-context behavioral advertising or allow third parties to use your recordings to advertise to you.

We limit service providers to using personal information to perform services for us and require them to protect it consistently with this Policy and applicable law.

We share only what is reasonably needed with service providers that support hosting, storage, pronunciation assessment, artificial-intelligence processing, audio generation, app distribution, and notifications. Depending on the function, these providers may process recordings, reference text, assessment data, technical request information, or notification tokens. They do not receive your name or email address from your Tim Budong account because we do not collect those details when creating the account.

We may also disclose information when you ask us to; when reasonably necessary to protect the rights, safety, and security of users, the public, or the Service; or when required by a valid legal process. If the Service is involved in a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to applicable law and this Policy.

When a person may access your data

We limit human access to account information and recordings to circumstances where it is reasonably necessary:

Retention and deletion

We generally keep your account, profile, learning history, scores, technical assessment data, and recordings while your account is active because they power your progress and the Service.

When you delete your account in Settings → Danger zone → Delete account, the account and its learning history become inaccessible immediately, its sessions are revoked, and its push tokens are deleted. We keep the remaining account records for a 30-day recovery and operational window before they are deleted or de-identified, unless we must retain limited information longer for security, fraud prevention, legal compliance, dispute resolution, or enforcement. Residual copies may remain in backups until those backups rotate out.

Account deletion does not automatically delete recordings retained for model evaluation, development, or training, or models and statistical information created from them. We may keep those materials for as long as they remain useful for those purposes. You may email us to request deletion of identifiable source recordings; we will honor requests where required by applicable law.

We keep support email for as long as reasonably useful to respond and maintain a support history. Server and infrastructure logs are retained according to operational and security needs and our providers’ retention settings.

Your choices and rights

Depending on where you live, you may have rights to know about, access, correct, delete, restrict, or object to processing of your personal information, and to receive a portable copy. You may also have a right to complain to your local data-protection authority. We will not discriminate against you for exercising a privacy right.

Legal bases for processing

Where laws such as the UK or EU GDPR apply, we process information as needed to perform our agreement with you by providing the Service; for legitimate interests such as securing, maintaining, and improving the Service; with your consent, such as when iOS grants microphone or notification permission; and when needed to comply with legal obligations. You may withdraw consent through the app or iOS Settings, without affecting earlier processing.

Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has provided information, email us so we can investigate and delete it. A higher minimum age or parental consent requirement may apply where you live.

International data transfers

We operate from the United States, and our providers process information in the United States and other countries. Those countries may have different privacy laws from yours. Where required, we and our providers use recognized safeguards for international transfers.

Security

We use reasonable administrative, technical, and organizational safeguards designed to protect information. Connections to the Service are encrypted in transit with HTTPS; device credentials are stored in Apple’s Keychain; device secrets are stored by our server as one-way hashes; and access is limited to people and providers who need it. No method of storage or transmission is perfectly secure, so we cannot guarantee absolute security.

Changes and questions

We may update this Policy as the Service or law changes. We will post the new version here, update the date above, and provide additional notice when a change materially affects your rights.

For privacy questions or requests, email maria@balloonapps.co.