Sayni

Privacy policy

Updated 10 October 2026

This policy covers the Sayni iOS and Android apps and sayni.ai. Cubo World Inc. operates Sayni. For privacy questions or requests, contact Support@sayni.ai.

Conversations and learning records

Supported builds cache transcripts, saved words, learning evidence, progress, meanings and topic references on your device and back them up to your Sayni account when you sign in. These account records sync across supported iOS, Android and Web clients. Preferences are cached locally; supported builds sync the account settings described below when you sign in. Sayni does not save raw conversation audio in the learning archive or its application database. Device backups and any exports you create can contain local learning data.

Conversation features require AI processing. With Sayni-provided time, audio travels between the app and OpenAI; Sayni's service handles session setup, relevant conversation context and text needed for teaching features such as meanings, word explanations and learning review. Prompts, replies and transcripts are processed for those requests. Learning records are also stored in the private account backup described above; ordinary conversation text is not written to application logs. Current-topic requests may use provider web search.

If your build supports your own OpenAI API key, requests use your provider account. The key is stored using iOS Keychain or Android Keystore protection and is excluded from learning exports. It is not sent to Sayni's account service. Provider processing and retention depend on the provider account and settings. Disabling optional request storage does not eliminate all provider retention.

Sayni Web

The Web app caches learning records in browser storage, including IndexedDB, and syncs them with your private account backup when signed in on a supported build. Account settings are cached locally and sync as described below. Clearing browser storage can remove local records and settings changes that have not yet synced. The Web app uses the same hosted AI, account and usage services described in this policy. Microphone access requires your browser permission. Browser sign-in uses a secure, HttpOnly session cookie; temporary sign-in cookies bind the authentication response to the sign-in you started.

Accounts and sign-in

Sign-in options depend on your build. We store a random account ID, creation date, the sign-in provider and its account identifier, and a verified email when supplied. We do not receive your Google or Apple password. Identity proof is used to verify sign-in; Sayni sessions are stored separately from your AI API key. Server session tokens are hashed. Email registration also stores the email address you enter and a salted password hash; we do not store your plain-text password. Email addresses are not currently verified, and signing up does not require a verification email. If you already use a Google account, you can add an email password while signed in to keep the same Sayni account. Matching email addresses alone do not merge accounts.

When you sign in on a supported Web or native build, Sayni stores your learning language, meaning language, meaning subtitle preference, session limit and interests with your account so these settings can sync across devices. Changes made offline stay on that device until a successful sync. Conversation archives, saved words, hidden words, learning evidence and meaning/topic caches sync through the separate private learning-data service. API keys, sign-in credentials, microphone permissions, raw audio and device AI consent are excluded from learning backups.

Guest access, where offered, uses a random installation credential and guest identifier, allowance and eligibility records. It does not require an email address. Eligible transfers to an account are recorded to prevent duplicate grants. On supported builds, first sign-in backs up existing local learning records when their ownership matches the account or no previous account owner exists. Subsequent sync uses account-specific caches.

Usage, minutes and payments

Hosted conversations and teaching requests generate operational records: session and request IDs, language, time, duration, usage totals, cost and rate snapshots, balance reservations and settlements, and completion or error status. These support limits, balance accounting, delivery and troubleshooting without storing ordinary conversation content.

Purchases are available only when enabled. The payment provider handles checkout and its own payment information. Sayni retains account-linked orders, products, quantity, currency, quoted value, verified transaction references, delivery, refund and reconciliation status. Sensitive receipt references are encrypted at rest. We do not receive full card numbers or card security codes from store purchases.

When direct web payments are enabled, Stripe processes the payment details entered in checkout. Sayni uses the associated transaction and subscription references to provide access, maintain balances, handle refunds and resolve billing questions; we do not receive full card numbers or card security codes from Stripe checkout. See Billing & cancellation and our Refund policy for purchase rules.

Reports and support

If you submit an in-app AI report, the excerpt you review, reason, language, report ID, consent version and submission date can be saved for review. Reports are optional and do not automatically include your full conversation or audio. Support receives your email and the message or attachments you choose to send.

Website measurements and security

The public website uses first-party measurements for page views, download clicks and scene selections. Events include a random browser-tab session ID, page path and limited campaign tags. They do not include your email, conversation text, device fingerprint, full query string or advertising click identifiers. The event payload does not contain an IP address; network and hosting providers still receive technical request information. Measurements respect the browser's Do Not Track setting, and event records are removed after 90 days.

Cloudflare also provides website traffic and performance measurements through a browser beacon, including page-load timing. This is separate from Sayni's first-party events. The beacon does not use cookies or browser local storage to identify visitors.

Cloudflare delivers and protects the site and hosted service. Service security uses rate limits and technical identifiers to prevent abuse. Administrative access and changes generate access-control and audit records. The browser stores temporary session and campaign values; protected sign-in uses secure cookies where applicable.

Purpose, providers and international processing

We process information to deliver requested features, authenticate accounts, manage allowances and payments, investigate support requests and reports, secure the service and meet legal obligations. Applicable legal bases include performing the service you request, consent where required, legitimate interests in service security and support, and legal obligations.

Infrastructure, AI, sign-in, email and enabled payment providers receive information needed for their roles. They may process it in countries different from yours. The current hosted service runs on Cloudflare infrastructure; it is not the independently operated Mural service. We do not sell your personal information or share it for cross-context behavioural advertising. Information may be disclosed where legally required or necessary to protect rights and service security.

Retention and your choices

Local learning data remains until you delete or replace it. Account identifiers remain while the account is active. Account settings and the private learning backup are removed when your Sayni account is deleted. Learning deletions propagate to other devices on their next successful sync; deletion markers prevent offline old copies from returning. After account deletion, limited billing, usage, anti-abuse and audit records may remain where needed for obligations, disputes or security. Support and submitted reports are retained as needed to handle the request and service safety. Website event retention is described above.

You can export learning data and check backup status in Settings. On supported signed-in builds, deleting learning data also deletes its cloud copy and propagates to synced devices. Offline changes and deletions are queued until the next successful sync. Signing out clears the visible account data; an account-specific offline cache may remain on that device so you can resume after signing in. For account deletion, access, correction or other privacy rights available under your local law, use our support page or contact Support@sayni.ai. We may verify ownership before acting. Deletion from Sayni does not remove records independently held by a provider.

Security and changes

We use access controls and protected credentials, but no system is perfectly secure. Do not include sensitive personal information in practice conversations. Sayni is intended for language practice and does not knowingly offer account services to children under 13. Contact support if a child has provided personal information. We will update this page when practices change and give additional notice where required.