Privacy Policy
Last updated: 1 October 2026
1. TL;DR
We only collect what we need to run TalkSibi. We don't sell your data. We don't run advertising trackers. If you delete your account, your data is gone within 30 days. If you ever want to know what we hold about you, email us and we'll send it.
2. Who we are
TalkSibi is an independent language-exchange service and a trading name of Sibghat Ullah, a sole trader in the United Kingdom. The data controller is Sibghat Ullah, 266 John Street, Cannock, Staffordshire WS11 0AG, United Kingdom — that is the person legally responsible for the personal data described in this policy. "We", "us" and "our" refer to the controller; "you" refers to anyone who uses TalkSibi. You can reach us at contact@talksibi.com.
3. What we collect and why
Account data
- Email address — to let you sign in, recover an account, and receive critical notices. Used for nothing else.
- Display name, native language, learning language, country — you enter these during signup so other users can find a language match.
- Date of birth (optional) — we do not ask for it when you sign up, and you never have to give it. Signing up asks you to confirm you are 18 or over instead. If you choose to add a date later from your profile, we keep the full date and never show it to anyone: other users see only your age, and only for as long as you leave “show my age” switched on. A date that shows you are under 18 is refused.
- Profile photo — uploaded by you, shown next to your messages and on your profile page. Face-detection software on our own server checks that it shows one real face; the measurements it takes for that check are used for that upload only and are not stored. See Face data.
- Selfie check (optional) — if you choose to get the verified tick, you take three quick photos of your face. Everything about this, including the face template we keep, is explained in Face data below.
Content you create
- Direct messages, wall posts, comments, voice notes, reactions — stored so the recipient can read them and so you can see your own history.
- Safety review — to keep members safe from scams, harassment and sexual messages, our moderators can review an account when there is a reason to (a report, being blocked, or a pattern such as writing to many people who never reply): who it has chatted with, how many messages each side sent, and the messages that account sent. When it is needed to judge a case, a moderator can open one of those conversations in full, including the other person's messages; every such opening is logged (who opened it, which conversation, when). Reviews are used only to protect members, never for advertising or anything else.
- Device identifier — the app sends an identifier for your device (on iPhone the vendor identifier Apple gives our apps, on Android the Android ID; in a browser a cookie we set). It is used only for security: if an account is suspended for breaking our rules, the devices it used cannot be used to create or sign in to another account. It is never used for advertising or tracking, and never the advertising identifier.
- Call and party voice audio — streamed live through Agora (and Cloudflare Realtime as a fallback); never recorded to our servers. On 1:1 calls, live captions are produced by Agora's speech-to-text while the call runs; the caption text is shown to the two of you and not stored.
- Game state (rooms, scores, moves) — stored in-memory only, cleared when the game ends.
Technical data
- IP address — used for abuse detection and rate limiting; not linked to your account in analytics.
- Browser + device type — collected only in error logs, to fix bugs.
- Push notification tokens (if you opt in) — used only to deliver notifications you've asked for.
Analytics and ads: our public pages (home, blog, guides) use Google Analytics and Google AdSense only after you accept cookies — if you reject, neither loads. There are no ads and no analytics trackers inside the app: not in chats, calls, parties or profiles.
What we do NOT do: no Facebook Pixel, no device fingerprinting, and we never sell or share your data with data brokers.
3a. AI services and your permission
Some TalkSibi features are powered by outside AI services. The app asks your permission before anything is sent to them (the “AI features” screen after you sign in), and you can change your answer at any time in Settings › AI features. This is exactly what is sent, to whom, and why:
- Anthropic (Claude), USA —
- Translation, corrections and writing help: the text you ask to translate, correct or improve (and, if you turn on auto-translate, the messages you receive); a photo you ask to translate.
- AI practice partners: your recent messages in that conversation, your first name and your languages, and any photo you send in that conversation.
- Opening-line ideas: the other person's public profile details (place, languages, “about”) and your conversation with them, when you tap the ideas button.
- Lesson plans and practice games: your languages, level and the goals you type, and words you missed in a game.
- Safety checks: every photo you share (in a chat, on your profile, in your gallery or in a party) is checked for nudity and sexual content before it is shown; and when you finish signing up, your profile (name, photo, bio, interests, stated age, country and languages) is reviewed to keep fake and under-age accounts out.
- Reports: when someone is reported, a moderator may ask Claude to summarise the reported messages and photos.
- Anthropic processes this only to return the result to us and does not use it to train its models.
- ElevenLabs — the text of an AI reply or lesson phrase you ask to hear read aloud, and a voice note you ask to turn into text. Used only to produce that audio or text.
- Agora — during a 1:1 voice or video call, the call audio, to show live captions to the two of you. Captions are not stored, and they are not started if either person has turned AI features off.
If you don't allow AI features, nothing about you is sent to these services: translation, AI partners, voice features, lesson plans and photo sharing are turned off, call captions are not started, and a person (not AI) reviews your profile photo and sign-up instead.
Each of these providers processes the data on our behalf under its own terms and data-processing commitments, which protect it at least as well as this policy does. We never sell your data, and none of it is used for advertising.
3b. Face data
What face data we collect. Two things, and nothing else: (1) when you upload a profile photo, face-detection software measures the face in it to check that the photo shows one real person; (2) only if you choose the optional selfie check for the verified tick, we take three photos of your face (straight on, turned left, turned right) and create a face template — a list of 128 numbers derived from your face. A face template is not a picture and a face cannot be rebuilt from it.
How it is collected and used. The selfie photos are taken with your camera inside the app, only when you start the selfie check. They are used to confirm that a real, live person is taking them (the head turns) and that it is the same person as in your profile photo. The face template is kept only to check that a later profile photo is still you, so the verified tick stays honest: if you change to a photo of a different face, the tick is removed and the template is deleted. Face data is never used for advertising, never used to identify you to anyone, and never used for any other purpose.
Where it is processed and stored. All face processing runs on TalkSibi's own server (DigitalOcean, London, UK) using open-source face-detection software. The three selfie photos are held in memory only for the few seconds of the check and are never saved. The profile-photo measurements are used for that upload only and never saved. The face template, if you passed the selfie check, is stored with your account record on our server.
Sharing. Face data — the selfie photos, the measurements and the face template — is never shared with, sold to or sent to any third party, including AI services. (Your profile photo itself, which everyone can see, is checked for nudity by Anthropic if you allow AI features; see 3a. The selfie photos are not.)
How long we keep it. The selfie photos and profile-photo measurements are not kept at all. The face template is kept until the first of: you change your profile photo to a different face, you delete your account, or you ask us to delete it at contact@talksibi.com. Deleting your account deletes it immediately, and it is gone from backups within 30 days.
4. Third-party processors
To run TalkSibi we send limited data to trusted providers, each covered by their own privacy policy:
- DigitalOcean (server hosting, London region) — receives every request to talksibi.com.
- Cloudflare (voice party routing + CDN) — receives IP + WebRTC signalling; never sees message content.
- Anthropic Claude (AI) — with your permission, receives the text you ask to translate or correct, your conversations with the AI partners, photos you share (for the nudity check) or ask to translate, a new member's profile when the sign-up is reviewed, and, when someone is reported, the reported messages and photos so a moderator can decide. Full detail in 3a. Anthropic does not train on this data.
- ElevenLabs (voice-note transcription + AI voice) — receives the audio clip you're translating or the text an AI is speaking. Clips are not stored on ElevenLabs' side.
- Agora (voice and video calls, parties, live captions) — carries the live audio/video and produces call captions; nothing is recorded.
- Brevo (email) — receives your email address to send sign-in codes and account notices.
- ipwho.is (IP location) — receives your IP address to estimate your country and city at sign-up.
- Google — Sign in with Google (if you use it), Analytics and AdSense on public pages after cookie consent, and Firebase/Play Services for Android push, which receives a push token.
- Apple — Sign in with Apple (if you use it) and push delivery to iPhones.
5. How long we keep it
- Account + profile — until you delete your account, or after 24 months of inactivity (warned first).
- Messages, posts, comments — until you delete them, or until account deletion.
- Voice notes + uploaded images — until you delete them or account deletion.
- Safety exception — if an account has been reported by another member, its conversations are kept privately for 90 days after it is deleted, so a report can still be investigated (or passed to the police) and deleting an account cannot erase evidence of abuse. Only moderators can see them; they are then deleted.
- Server logs — 30 days, then rotated.
- Moderation records (blocks, reports) — 12 months after case close, for repeat-offender detection.
6. Your rights
Under the UK GDPR, EU GDPR, and California CCPA, you have the right to:
- Ask what data we hold about you (data access request)
- Correct data that's wrong
- Delete your data (right to erasure)
- Export your data (data portability)
- Object to processing
- Withdraw consent for optional processing (push notifications, translation)
Email us using the contact below and we'll action any request within 30 days.
7. Deleting your account
You can delete your TalkSibi account at any time:
- In the app: open your profile → Settings → Delete account.
- By email: write to the address below from your registered email. We confirm and delete within 7 days.
Deletion removes: your profile, all messages you've sent, wall posts, comments, voice notes, uploaded images, follow relationships and reactions. Some anonymous audit records (report cases, moderation actions) are retained for 12 months for safety compliance.
8. Children
TalkSibi is intended for users aged 18 and over. Signing up requires you to confirm you are 18 or over; we do not ask for your date of birth, and giving one is optional. If we learn that anyone under 18 has created an account, we remove it immediately and delete all associated data. Parents or guardians who believe an under-18 has registered should contact us using the details below — we act within 48 hours.
For full detail on our under-18 protections and CSAM policy, see our Child Safety policy.
9. Security
Every request to talksibi.com uses HTTPS. Passwords are stored as one-way hashes (never in plain text). Message content and profile data are stored in Redis on our own server; only the operator has SSH access.
Voice calls in parties are routed peer-to-peer through Cloudflare's WebRTC infrastructure; the audio never touches our storage.
If you spot a security issue, please report it privately using the contact below — we appreciate responsible disclosure.
10. Changes to this policy
We'll update this page whenever we materially change how we handle data. If the change is significant, we'll show a banner in the app. The "Last updated" date at the top always reflects the current version.
11. Contact
Questions, deletion requests, data access requests, or safety concerns:
Email: hello@talksibi.com
We respond within 3 working days and action requests within the deadlines set out above.