Legal

Privacy Policy

LAST UPDATED · 10 SEPTEMBER 2026 · EFFECTIVE 10 SEPTEMBER 2026 · GDPR · LOPDGDD · LSSI

We collect the minimum needed to run Suelto. No ads, no data brokerage. We name every processor below and state what each one may do with your content. Alicante, Spain is our legal base — EU law applies to all users.

1. Controller

The data controller (responsable del tratamiento) is:

Elevate Studio
Legal Iuris La Zenia, C. Salzillo, S/n, 03189 Orihuela, Alicante, Spain
Email (privacy & rights): hola@suelto.es — subject: “Privacy”
Contact: Umut Gokbayrak
Website: suelto.es

For data-protection enquiries we respond within one month (extendable by two months for complex requests). There is no appointed Data Protection Officer — hola@suelto.es handles all privacy requests directly. If a DPO is appointed later, this section will be updated.

If you are a consumer in the EU, you remain protected by the mandatory rules of your habitual residence in addition to Spanish law.

2. Scope

This policy covers suelto.es (including the marketing site and the sign-in page at suelto.es/signin), the Suelto web app at suelto.es/app (or /app/), and the associated backend on Cloudflare. It does not cover third-party sites linked from Suelto. Processing is governed by Regulation (EU) 2016/679 (GDPR / RGPD), Organic Law 3/2018 (LOPDGDD) and Law 34/2002 (LSSI-CE).

3. What we collect

CategoryExamplesSource
AccountEmail (account identifier for passwordless magic-link authentication — no password is stored), display name, level (A1–C1), target variety, settingsYou
Learning contentAnswers, corrections, error events, lesson progress, story continuations and scenes, notes/captures, session transcripts, prompt historyYou + generated
Voice dataAudio recordings and Whisper transcriptions for Speak / conversation practice. Voice is biometric data in the broad sense, but we process it only to transcribe and give feedback — not to identify you.You
BillingStripe customer ID, plan, subscription status, invoice metadata. We never see or store card numbers.You via Stripe
TechnicalMagic-link tokens (SHA-256 hashed, single-use, 15-minute expiry), login session token (cookie), IP address, request logs for rate-limiting/abuse prevention, error logs. No fingerprinting.Automatic
Support chatMessages you send through the live chat widget (Crisp), plus any name or email address you type there. Crisp also processes the technical data strictly needed to run the chat: a session identifier, IP address and device/browser type.You via Crisp
Analytics (opt-in)Page views, referrer, country, device/browser/OS type and page performance metrics via Cloudflare Web Analytics (cookieless — see §12), plus first-party product events (e.g. "lesson completed", "checkout started") stored in our own database. No reading content, answers or free text — only counts, ids and levels.Automatic, only if you allow Analytics

We do not intentionally collect special-category data (Art. 9 RGPD). Please avoid entering health, political or other sensitive data in free-text fields.

4. Purposes and legal bases (Art. 6 RGPD)

PurposeLegal basis
Provide the Suelto service: accounts, lessons, conversation, spaced repetition, progressArt. 6(1)(b) — performance of the contract you accept at signup
AI processing to generate lessons, replies, story scenes, corrections, transcription and TTS (see §5)Art. 6(1)(b) — strictly necessary core of the service; without it Suelto cannot function
Billing, subscription management, fraud preventionArt. 6(1)(b) + Art. 6(1)(c) where tax/accounting law requires it
Security, rate-limiting (5 magic-link requests/hour per IP; 3/hour per email), abuse prevention, debugging, service integrityArt. 6(1)(f) — legitimate interest in securing and operating the service; balanced against your rights
Support replies and rights handling (access, deletion)Art. 6(1)(b) and 6(1)(c)
Support and sales enquiries via the live chat (Crisp), including chat quality and abuse preventionArt. 6(1)(b) — pre-contractual enquiries and performance of your contract; Art. 6(1)(f) — legitimate interest in operating a working support channel
Legal retention of invoices and accounting recordsArt. 6(1)(c) — Código de Comercio & Ley General Tributaria
Optional product updates / newsletter, if you opt inArt. 6(1)(a) — consent, withdrawable at any time
Product analytics — understanding how the marketing site and app are used (page views, feature usage, funnel events) to improve the productArt. 6(1)(a) — consent, given via the cookie preferences and withdrawable at any time (§12)

Where we rely on legitimate interest you may object at any time (see §10). Where we rely on consent you may withdraw it without affecting prior processing.

Automated decisions: Suelto adapts lessons based on your gaps and errors. This is not a decision producing legal or similarly significant effects under Art. 22 RGPD, and always involves logic you can understand and override (e.g., level settings, pause, retake placement).

5. AI processing

Suelto’s core depends on AI. Portions of your learning data — prompts, answers, story continuations, notes, transcripts — are sent to:

  • Anthropic PBC (US) via Cloudflare AI Gateway for language generation, conversation replies and corrections (model family: Claude).
  • Meta Platforms, Inc. (US) for Writing Lab story scenes (model: Muse Spark, contributor tier). The contributor tier is what keeps this feature inexpensive, and its terms permit Meta to use submitted prompts and generated content to improve its own models. We state that plainly rather than burying it: write your stories freely, but do not put personal or sensitive details into them.
  • Cloudflare Workers AI for transcription (Whisper) and speech synthesis.
  • ElevenLabs, Inc. (US) for text-to-speech voices in listening and speaking practice.

What each processor may do with submitted content is governed by that processor’s own terms, which we state here rather than as a blanket promise. Anthropic’s commercial terms exclude Customer Content from training. Cloudflare acts as processor under its DPA. Where we use a provider whose terms permit it to use submitted content to improve its own models, that is stated here and in the processor table in §6 — today that provider is Meta.

This processing occurs on servers in the EU and the US (see §7). Without it, lessons, tutoring and speaking feedback cannot be produced — you consent to it by creating an account, and it is simultaneously necessary for contract performance.

6. Recipients and processors (Art. 28 RGPD)

ProcessorRoleLocation
Cloudflare, Inc.Hosting (Workers), D1 database, R2 object storage, AI Gateway, Workers AI (transcription; speech synthesis incl. Deepgram Aura models), Turnstile / security, CDN, Web Analytics (opt-in, cookieless traffic and performance measurement)EU + US
Anthropic PBCLarge-language-model inference (via AI Gateway)US
Meta Platforms, Inc.Large-language-model inference for Writing Lab story scenes (Muse Spark contributor tier — Meta’s terms permit use of submitted prompts and generated content to improve its models)US
ElevenLabs, Inc.Text-to-speech voices for listening and speaking practiceUS
Stripe, Inc. / Stripe Payments Europe Ltd.Payment processing, subscription management, invoicingEU + US
Crisp IM SARLLive chat / support messaging widget on suelto.es and in the app (chat delivery and storage on our behalf)EU (France)

We disclose data only to those processors, and — if required — to tax authorities, courts or law enforcement under Spanish/EU law. We do not sell or rent personal data. No advertising network receives your data.

7. International transfers (Chapter V RGPD)

Some processors are US-based. We transfer data only with a valid safeguard:

  • Cloudflare — certified under the EU-US Data Privacy Framework (DPF) and bound by Standard Contractual Clauses (SCCs) as fallback.
  • Anthropic — transfers under SCCs endorsed by the European Commission, with supplementary technical measures (encryption in transit, gateway pseudonymisation).
  • Meta — certified under the EU-US Data Privacy Framework (DPF), with SCCs as fallback.
  • ElevenLabs — certified under the EU-US Data Privacy Framework (DPF), with SCCs as fallback.
  • Stripe — certified under the DPF; EU payments are handled by Stripe Payments Europe Ltd. (Ireland).

Copies of the relevant SCCs / DPF certification can be requested at hola@suelto.es. Crisp IM SARL (support chat) is established in France and stores chat conversations on servers in the EU, so no transfer outside the EEA is required for chat data.

8. Retention

  • Magic-link tokens: single-use, expire in 15 minutes, stored as SHA-256 hashes and deleted shortly after expiry or on first use. No password is ever stored.
  • Learning & voice data: kept while your account is active. On deletion, primary data is erased within 30 days; encrypted backups expire within 90 days.
  • Account record (email, deletion log): minimal log of deletion kept for 12 months to prove compliance, then erased.
  • Invoices & accounting: retained 6 years per Art. 30 Código de Comercio and up to 4 years for tax per Ley General Tributaria — Stripe retains invoices per its own obligations; we retain only metadata needed to prove the transaction.
  • Security logs (IP, rate-limit): rolling 30–90 days, then aggregated or deleted.
  • Support chats (Crisp): kept while your enquiry is open and for up to 12 months afterwards for quality and abuse-prevention purposes, then deleted from our Crisp inbox.
  • Web Analytics (opt-in): held by Cloudflare in aggregate form under its own retention terms; we do not retain raw visitor data on our own systems.
  • First-party product events (opt-in): events tied to your account are erased with the account (30-day window as above); anonymous events are purged after 12 months.

9. Security (Art. 32 RGPD)

We apply appropriate technical and organisational measures: TLS 1.2+ in transit, encryption at rest via Cloudflare D1/R2, passwordless authentication via single-use magic links (15-minute expiry, SHA-256-hashed tokens at rest, consumed on first use; no passwords are stored), 90-day session cookies with HttpOnly + Secure + SameSite=Lax, least-privilege access, and rate-limiting. No method is 100% secure; if a breach risks your rights we will notify you and the AEPD within 72 hours where required.

10. Your rights

Under Arts. 15–22 RGPD and Arts. 12–18 LOPDGDD you have the right to access, rectification, erasure, restriction, objection, portability, and to withdraw consent, plus the right not to be subject to a decision based solely on automated processing with legal effect.

How to exercise: email hola@suelto.es from your account address with subject “Data rights — [your request]”. We may ask for proof of identity (e.g., confirmation from the account email) and will reply within one month (extendable by two months for complexity, with notice).

  • Export: we provide your learning history, notes and transcripts in a common machine-readable format (JSON/CSV).
  • Deletion: we erase learning data, recordings and the account within 30 days, except where retention is legally required (see §8).
  • Objection to legitimate-interest logging: you may object; we will assess overriding grounds and, where possible, limit processing.

Complaint: if you consider processing unlawful, you may lodge a claim with the Spanish Supervisory Authority:

Agencia Española de Protección de Datos (AEPD)
C/ Jorge Juan 6, 28001 Madrid — aepd.es — Tel. 900 293 183

You may also complain to the authority in your EU country of residence. Under LOPDGDD you may additionally contact us first for an amicable resolution.

11. Minors

Suelto is designed for adults. You must be at least 18 to create an account. For users under 14, Spanish law (Art. 7 LOPDGDD) requires parental consent, which we do not provide a flow for — do not create an account if you are under 18. If we learn a minor has registered, we will delete the account.

12. Cookies and similar technologies (Art. 22 LSSI)

Suelto sets no advertising cookies and carries out no cross-site tracking. What can run on your device, and when, is governed by the cookie preferences (banner, or Settings → Cookie preferences in the app). Until you decide, only the strictly necessary session cookie below is used.

The app sets one strictly necessary cookiesession — to keep you logged in (90-day expiry, HttpOnly, Secure, SameSite=Lax). This cookie is exempt from consent under Art. 22.2 LSSI and the ePrivacy guidance because it is essential to provide the service you requested.

Analytics is opt-in. Only if you allow Analytics in the cookie preferences do we load:

  • Cloudflare Web Analytics — a cookieless measurement beacon. It sets no cookies and stores nothing on your device; the source IP of the measurement request is discarded at Cloudflare's network edge and is not kept in the analytics stores. It measures page views, referrers, country, device/browser type and page-load performance for our domains only — it does not profile you, does not follow you to other sites, and is not used for advertising.
  • First-party product events — funnel and usage events (e.g. "lesson completed", "checkout started") sent to our own servers and stored in our own database, linked where applicable to a pseudonymous account id. They never contain the content of what you read, write or answer — only counts, ids, levels and scores.

Withdrawing the Analytics preference stops both from loading and from collecting on future visits; deleting the preference re-shows the banner. The support chat below remains governed by its own, separate switch.

The live support chat widget (Crisp) is also opt-in. It does not load and stores nothing on your device until you allow Support chat in the cookie preferences. Once enabled, it stores a functional session identifier (cookie / local storage) on both the marketing site and in the app so a conversation can continue across pages, and the page you are on is shared with the support inbox so an agent can see where you need help. It carries no advertising or analytics identifiers and is not used for profiling. Withdrawing consent stops the widget from loading on future visits; deleting the stored identifier simply starts your next chat as a new conversation.

13. Marketing communications

We send transactional emails (receipts, security notices, service updates) on the basis of contract / legitimate interest. Any newsletter or product marketing is sent only with your prior consent (Art. 21 LSSI) and includes an unsubscribe link in every message. You may opt out at any time without charge.

14. Changes to this policy

Material changes will be announced in-app and, where appropriate, by email at least 14 days before taking effect. Non-material clarifications take effect on publication. The “Last updated” date reflects the current version.

15. Contact

Questions about this policy or to exercise your rights: hola@suelto.es — please include “Privacy” in the subject. Postal contact: Legal Iuris La Zenia, C. Salzillo, S/n, 03189 Orihuela, Alicante, Spain.

For disputes you may also use the EU Online Dispute Resolution platform: ec.europa.eu/consumers/odr, and the out-of-court mechanisms under Art. 25 LOPDGDD.

This policy is provided in English for convenience. Spanish law governs its interpretation. Where a Spanish translation is published, the Spanish version prevails in case of discrepancy. The controller will provide a Spanish copy on request.