Privacy Policy隐私政策
Effective / 生效日期: 2026-08-12
This Privacy Policy explains how SayVeda (“we”, “us”) collects, uses, shares, retains, and protects information when you use https://sayveda.com and related services (the “Service”).
The Service is a language-learning tool that generates scenario-specific vocabulary plans, matches you with YouTube practice videos, transcribes your shadowing recordings, and maintains your learning history. To do this we process a limited set of personal data as described below.
1. Data we collect
1.1 Data you provide
- Account information. If you sign in with Google, we receive your Google account ID, email, name, and profile picture. If you sign in with email + one-time code (OTP), we receive only your email address.
- Scenario descriptions and multimodal inputs. Text you type into the scenario input, plus any links, images, audio, or video you attach for interpretation.
- Shadowing recordings. Audio captured by your browser when you practice along with a video.
- Reading articles and notes. URLs you save, and highlights or notes you add.
- Payment information. When you purchase session credits, our payment partner Paddle collects your billing details directly — we never see or store your card number.
1.2 Data collected automatically
- Authentication cookies. A signed session cookie issued by NextAuth so you stay logged in.
- Basic technical logs. Request timestamps and error traces used for debugging and abuse mitigation. We do not use analytics or advertising cookies.
2. How we use your data
- To authenticate you and keep you signed in.
- To generate your scenario vocabulary plan, transcribe your recordings, and score your practice.
- To process purchases, deliver session credits, and honor refunds.
- To detect and prevent abuse (rate-limiting, fraud checks on payments).
- To comply with legal obligations and enforce our Terms of Service.
We do not sell your personal information. We do not use it for advertising or profiling unrelated to the Service.
3. Third-party subprocessors
We rely on a small set of vetted third-party services to operate. Each processes data only under our instructions and their own published privacy commitments:
- Google (OAuth). Identity verification when you sign in with Google.
- Paddle.com Market Ltd. (payments). Merchant of Record for all purchases; collects billing details, computes tax, issues invoices. Paddle privacy policy.
- Resend (email). Delivery of transactional email such as sign-in codes.
- Moonshot AI / Kimi (LLM). Generates the scenario vocabulary plan and, when you attach an image or URL, interprets it into a scenario intent. Inputs are sent per request and not retained by us beyond the immediate response.
- OpenAI (Whisper) or Groq (Whisper large-v3). Transcribes audio you upload (shadowing recordings, scenario voice memos, audio/video attachments) into text.
- Amazon Web Services (hosting). Compute, object storage (S3) for long-lived recordings, and shared filesystem (EFS) for account data.
4. Data retention
- Account and credit ledger: retained for the life of your account. Deleted within 7 days of account deletion.
- Practice recordings: stored under your account until you delete them or delete your account.
- Whisper transcripts: cached for up to 30 days after their last use to avoid re-charging for the same audio; automatically pruned thereafter.
- Temporary upload audio: deleted 7 days after upload via automated lifecycle rules.
- Payment records: Paddle retains transaction records as required by applicable financial regulations (typically 7 years).
- Webhook audit log: retained for at least 90 days for reconciliation; no plaintext user identifiers are stored.
5. Security
- All traffic is encrypted in transit (HTTPS/TLS 1.2+).
- User identifiers are hashed (SHA-256) before being used as on-disk filenames.
- Session tokens can be revoked server-side; deleting your account invalidates every device.
- Per-user data is isolated to per-user files/objects — cross-user reads are structurally impossible.
- Access to production systems is restricted to authorized personnel and audit-logged.
6. Your rights
You have the right to access, correct, export, or delete your personal data. From your account page you can delete your account at any time; this removes credits, scenarios, articles, and practice recordings within 7 days and revokes every issued session.
If you are in the EU/UK (GDPR): you additionally have the right to withdraw consent, restrict processing, port your data, and lodge a complaint with your local supervisory authority.
If you are in California (CCPA/CPRA): you additionally have the right to know, delete, correct, and opt out of any “sale” or “sharing” of personal information — we do neither, so no opt-out is required.
To exercise any right or ask a question, email admin@sayveda.com. We respond within 30 days.
7. Children
The Service is not directed to children under 13 (or under 16 where the GDPR applies). We do not knowingly collect data from children. If you believe a child has provided us with personal information, contact us and we will delete the account.
8. International transfers
Data may be processed in the United States and other countries where our subprocessors operate. Where transfers occur from the EU/UK to the United States, we rely on the subprocessor's Standard Contractual Clauses or equivalent safeguards.
9. Changes to this policy
We may update this policy from time to time. Substantive changes will be reflected in the “Effective” date at the top of this page. Continued use of the Service after a change constitutes acceptance of the revised policy.
10. Contact
SayVeda · [Registered business address to be confirmed] · Governing law: Delaware, United States
Privacy inquiries: admin@sayveda.com
本《隐私政策》说明 SayVeda(以下称“我们”)在你使用 https://sayveda.com 及相关服务(以下称“服务”)时,如何收集、使用、共享、保留与保护你的信息。
本服务是一款语言学习工具:生成场景化的词汇计划、匹配 YouTube 练习视频、转写你的跟读录音、 并保存你的学习历史。为此我们会处理下述有限的个人数据。
1. 我们收集的数据
1.1 你主动提供
- 账户信息。用 Google 登录时会获取 Google 账号 ID、邮箱、昵称、头像; 用邮箱验证码登录时仅获取邮箱地址。
- 场景描述与多模态输入。你在场景输入框中键入的文字,以及为解读上传的链接、图片、音频、视频。
- 跟读录音。你在浏览器中练习跟读时录制的音频。
- 阅读文章与笔记。你保存的 URL、以及做的高亮和笔记。
- 支付信息。购买 session 额度时,我们的支付合作方 Paddle 会直接收取你的账单信息 —— 我们不接触、不存储你的银行卡号。
1.2 自动收集
- 身份认证 Cookie。NextAuth 签发的会话 Cookie,用于保持登录状态。
- 基础技术日志。请求时间戳与错误堆栈,仅用于调试和滥用防护。 我们不使用任何分析类或广告类 Cookie。
2. 数据的使用
- 验证你的身份、保持登录状态;
- 生成场景词汇计划、转写跟读音频、评估练习效果;
- 处理购买、发放 session 额度、执行退款;
- 检测和防止滥用(限频、支付防欺诈);
- 遵守法律法规、执行使用条款。
我们不出售你的个人信息,也不会将其用于与服务无关的广告或用户画像。
3. 第三方子处理商
我们依赖少量经过筛选的第三方服务运行系统。它们仅按我们的指令并遵循其公开的隐私承诺处理数据:
- Google(OAuth) —— 你使用 Google 登录时的身份验证。
- Paddle.com Market Ltd.(支付) —— 所有购买的商户结算方 (Merchant of Record), 收取账单信息、计算税费、开具发票。见 Paddle 隐私政策。
- Resend(邮件) —— 送达登录验证码等事务性邮件。
- Moonshot AI / Kimi(大语言模型) —— 生成场景词汇计划; 当你附上图片或链接时,解读为场景意图。输入按次发送,我们不长期保留。
- OpenAI Whisper 或 Groq Whisper large-v3 —— 将你上传的音频 (跟读、语音便签、音视频附件)转写为文本。
- Amazon Web Services(托管) —— 计算资源、对象存储 (S3) 用于长留录音、 共享文件系统 (EFS) 用于账户数据。
4. 数据保留期
- 账户与额度账本:保留至账户注销;注销后 7 天内删除。
- 练习录音:存储在你的账户下,你可自行删除或随账号注销一并删除。
- Whisper 转写:最后使用后最长缓存 30 天(避免重复计费),此后自动清理。
- 临时上传音频:通过生命周期规则在上传后 7 天自动删除。
- 支付记录:Paddle 按适用金融法规保留(通常 7 年)。
- Webhook 审计日志:至少保留 90 天用于对账;不存储明文用户标识符。
5. 安全措施
- 全部传输经 HTTPS/TLS 1.2+ 加密;
- 用户标识符经 SHA-256 哈希后才作为磁盘文件名;
- 会话令牌可服务端撤销;注销账户会使所有设备的登录立即失效;
- 用户数据按账号隔离存储于独立文件/对象,跨用户读取在结构上不可能;
- 生产系统访问仅限授权人员,并有审计日志。
6. 你的权利
你有权访问、更正、导出或删除属于你的个人数据。在账户页可随时注销账户, 额度、场景、文章和练习录音会在 7 天内清除,所有活跃会话会立即失效。
欧盟 / 英国用户(GDPR):另享有撤回同意、限制处理、数据可携、 向本国监管机构投诉的权利。
加州用户(CCPA/CPRA):另享有知情、删除、更正以及拒绝“出售” 或“共享”个人信息的权利 —— 我们两者皆不进行,故无需提供 opt-out。
如需行使权利或咨询,请邮件联系 admin@sayveda.com。我们将在 30 天内回复。
7. 未成年人
本服务不面向 13 岁以下(或适用 GDPR 时 16 岁以下)的儿童,我们不会有意收集儿童数据。 如你认为某未成年人向我们提供了信息,请联系我们,我们将删除相应账户。
8. 跨境传输
数据可能在美国及其他子处理商所在国家/地区被处理。当数据自欧盟/英国跨境传输至美国时, 我们依赖子处理商签订的《标准合同条款》(SCC) 或同等保障。
9. 政策变更
我们会不时更新本政策。实质性修改将反映在页首的“生效日期”上。 修改后继续使用服务即视为你接受新版政策。
10. 联系方式
SayVeda · [Registered business address to be confirmed] · 管辖法律:Delaware, United States
隐私事务:admin@sayveda.com