Privacy Policy
LAST UPDATED · 10 SEPTEMBER 2026 · EFFECTIVE 10 SEPTEMBER 2026 · GDPR · LOPDGDD · LSSI
We collect the minimum needed to run Suelto. No ads, no data brokerage. We name every processor below and state what each one may do with your content. Alicante, Spain is our legal base — EU law applies to all users.
1. Controller
The data controller (responsable del tratamiento) is:
Elevate Studio
Legal Iuris La Zenia, C. Salzillo, S/n, 03189 Orihuela, Alicante, Spain
Email (privacy & rights): hola@suelto.es — subject: “Privacy”
Contact: Umut Gokbayrak
Website: suelto.es
For data-protection enquiries we respond within one month (extendable by two months for complex requests). There is no appointed Data Protection Officer — hola@suelto.es handles all privacy requests directly. If a DPO is appointed later, this section will be updated.
If you are a consumer in the EU, you remain protected by the mandatory rules of your habitual residence in addition to Spanish law.
2. Scope
This policy covers suelto.es (including the marketing site and the sign-in page at suelto.es/signin), the Suelto web app at suelto.es/app (or /app/), and the associated backend on Cloudflare. It does not cover third-party sites linked from Suelto. Processing is governed by Regulation (EU) 2016/679 (GDPR / RGPD), Organic Law 3/2018 (LOPDGDD) and Law 34/2002 (LSSI-CE).
3. What we collect
| Category | Examples | Source |
|---|---|---|
| Account | Email (account identifier for passwordless magic-link authentication — no password is stored), display name, level (A1–C1), target variety, settings | You |
| Learning content | Answers, corrections, error events, lesson progress, story continuations and scenes, notes/captures, session transcripts, prompt history | You + generated |
| Voice data | Audio recordings and Whisper transcriptions for Speak / conversation practice. Voice is biometric data in the broad sense, but we process it only to transcribe and give feedback — not to identify you. | You |
| Billing | Stripe customer ID, plan, subscription status, invoice metadata. We never see or store card numbers. | You via Stripe |
| Technical | Magic-link tokens (SHA-256 hashed, single-use, 15-minute expiry), login session token (cookie), IP address, request logs for rate-limiting/abuse prevention, error logs. No fingerprinting. | Automatic |
| Support chat | Messages you send through the live chat widget (Crisp), plus any name or email address you type there. Crisp also processes the technical data strictly needed to run the chat: a session identifier, IP address and device/browser type. | You via Crisp |
| Analytics (opt-in) | Page views, referrer, country, device/browser/OS type and page performance metrics via Cloudflare Web Analytics (cookieless — see §12), plus first-party product events (e.g. "lesson completed", "checkout started") stored in our own database. No reading content, answers or free text — only counts, ids and levels. | Automatic, only if you allow Analytics |
We do not intentionally collect special-category data (Art. 9 RGPD). Please avoid entering health, political or other sensitive data in free-text fields.
4. Purposes and legal bases (Art. 6 RGPD)
| Purpose | Legal basis |
|---|---|
| Provide the Suelto service: accounts, lessons, conversation, spaced repetition, progress | Art. 6(1)(b) — performance of the contract you accept at signup |
| AI processing to generate lessons, replies, story scenes, corrections, transcription and TTS (see §5) | Art. 6(1)(b) — strictly necessary core of the service; without it Suelto cannot function |
| Billing, subscription management, fraud prevention | Art. 6(1)(b) + Art. 6(1)(c) where tax/accounting law requires it |
| Security, rate-limiting (5 magic-link requests/hour per IP; 3/hour per email), abuse prevention, debugging, service integrity | Art. 6(1)(f) — legitimate interest in securing and operating the service; balanced against your rights |
| Support replies and rights handling (access, deletion) | Art. 6(1)(b) and 6(1)(c) |
| Support and sales enquiries via the live chat (Crisp), including chat quality and abuse prevention | Art. 6(1)(b) — pre-contractual enquiries and performance of your contract; Art. 6(1)(f) — legitimate interest in operating a working support channel |
| Legal retention of invoices and accounting records | Art. 6(1)(c) — Código de Comercio & Ley General Tributaria |
| Optional product updates / newsletter, if you opt in | Art. 6(1)(a) — consent, withdrawable at any time |
| Product analytics — understanding how the marketing site and app are used (page views, feature usage, funnel events) to improve the product | Art. 6(1)(a) — consent, given via the cookie preferences and withdrawable at any time (§12) |
Where we rely on legitimate interest you may object at any time (see §10). Where we rely on consent you may withdraw it without affecting prior processing.
Automated decisions: Suelto adapts lessons based on your gaps and errors. This is not a decision producing legal or similarly significant effects under Art. 22 RGPD, and always involves logic you can understand and override (e.g., level settings, pause, retake placement).
5. AI processing
Suelto’s core depends on AI. Portions of your learning data — prompts, answers, story continuations, notes, transcripts — are sent to:
- Anthropic PBC (US) via Cloudflare AI Gateway for language generation, conversation replies and corrections (model family: Claude).
- Meta Platforms, Inc. (US) for Writing Lab story scenes (model: Muse Spark, contributor tier). The contributor tier is what keeps this feature inexpensive, and its terms permit Meta to use submitted prompts and generated content to improve its own models. We state that plainly rather than burying it: write your stories freely, but do not put personal or sensitive details into them.
- Cloudflare Workers AI for transcription (Whisper) and speech synthesis.
- ElevenLabs, Inc. (US) for text-to-speech voices in listening and speaking practice.
What each processor may do with submitted content is governed by that processor’s own terms, which we state here rather than as a blanket promise. Anthropic’s commercial terms exclude Customer Content from training. Cloudflare acts as processor under its DPA. Where we use a provider whose terms permit it to use submitted content to improve its own models, that is stated here and in the processor table in §6 — today that provider is Meta.
This processing occurs on servers in the EU and the US (see §7). Without it, lessons, tutoring and speaking feedback cannot be produced — you consent to it by creating an account, and it is simultaneously necessary for contract performance.
6. Recipients and processors (Art. 28 RGPD)
| Processor | Role | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting (Workers), D1 database, R2 object storage, AI Gateway, Workers AI (transcription; speech synthesis incl. Deepgram Aura models), Turnstile / security, CDN, Web Analytics (opt-in, cookieless traffic and performance measurement) | EU + US |
| Anthropic PBC | Large-language-model inference (via AI Gateway) | US |
| Meta Platforms, Inc. | Large-language-model inference for Writing Lab story scenes (Muse Spark contributor tier — Meta’s terms permit use of submitted prompts and generated content to improve its models) | US |
| ElevenLabs, Inc. | Text-to-speech voices for listening and speaking practice | US |
| Stripe, Inc. / Stripe Payments Europe Ltd. | Payment processing, subscription management, invoicing | EU + US |
| Crisp IM SARL | Live chat / support messaging widget on suelto.es and in the app (chat delivery and storage on our behalf) | EU (France) |
We disclose data only to those processors, and — if required — to tax authorities, courts or law enforcement under Spanish/EU law. We do not sell or rent personal data. No advertising network receives your data.
7. International transfers (Chapter V RGPD)
Some processors are US-based. We transfer data only with a valid safeguard:
- Cloudflare — certified under the EU-US Data Privacy Framework (DPF) and bound by Standard Contractual Clauses (SCCs) as fallback.
- Anthropic — transfers under SCCs endorsed by the European Commission, with supplementary technical measures (encryption in transit, gateway pseudonymisation).
- Meta — certified under the EU-US Data Privacy Framework (DPF), with SCCs as fallback.
- ElevenLabs — certified under the EU-US Data Privacy Framework (DPF), with SCCs as fallback.
- Stripe — certified under the DPF; EU payments are handled by Stripe Payments Europe Ltd. (Ireland).
Copies of the relevant SCCs / DPF certification can be requested at hola@suelto.es. Crisp IM SARL (support chat) is established in France and stores chat conversations on servers in the EU, so no transfer outside the EEA is required for chat data.
8. Retention
- Magic-link tokens: single-use, expire in 15 minutes, stored as SHA-256 hashes and deleted shortly after expiry or on first use. No password is ever stored.
- Learning & voice data: kept while your account is active. On deletion, primary data is erased within 30 days; encrypted backups expire within 90 days.
- Account record (email, deletion log): minimal log of deletion kept for 12 months to prove compliance, then erased.
- Invoices & accounting: retained 6 years per Art. 30 Código de Comercio and up to 4 years for tax per Ley General Tributaria — Stripe retains invoices per its own obligations; we retain only metadata needed to prove the transaction.
- Security logs (IP, rate-limit): rolling 30–90 days, then aggregated or deleted.
- Support chats (Crisp): kept while your enquiry is open and for up to 12 months afterwards for quality and abuse-prevention purposes, then deleted from our Crisp inbox.
- Web Analytics (opt-in): held by Cloudflare in aggregate form under its own retention terms; we do not retain raw visitor data on our own systems.
- First-party product events (opt-in): events tied to your account are erased with the account (30-day window as above); anonymous events are purged after 12 months.
9. Security (Art. 32 RGPD)
We apply appropriate technical and organisational measures: TLS 1.2+ in transit, encryption at rest via Cloudflare D1/R2, passwordless authentication via single-use magic links (15-minute expiry, SHA-256-hashed tokens at rest, consumed on first use; no passwords are stored), 90-day session cookies with HttpOnly + Secure + SameSite=Lax, least-privilege access, and rate-limiting. No method is 100% secure; if a breach risks your rights we will notify you and the AEPD within 72 hours where required.
10. Your rights
Under Arts. 15–22 RGPD and Arts. 12–18 LOPDGDD you have the right to access, rectification, erasure, restriction, objection, portability, and to withdraw consent, plus the right not to be subject to a decision based solely on automated processing with legal effect.
How to exercise: email hola@suelto.es from your account address with subject “Data rights — [your request]”. We may ask for proof of identity (e.g., confirmation from the account email) and will reply within one month (extendable by two months for complexity, with notice).
- Export: we provide your learning history, notes and transcripts in a common machine-readable format (JSON/CSV).
- Deletion: we erase learning data, recordings and the account within 30 days, except where retention is legally required (see §8).
- Objection to legitimate-interest logging: you may object; we will assess overriding grounds and, where possible, limit processing.
Complaint: if you consider processing unlawful, you may lodge a claim with the Spanish Supervisory Authority:
Agencia Española de Protección de Datos (AEPD)
C/ Jorge Juan 6, 28001 Madrid — aepd.es — Tel. 900 293 183
You may also complain to the authority in your EU country of residence. Under LOPDGDD you may additionally contact us first for an amicable resolution.
11. Minors
Suelto is designed for adults. You must be at least 18 to create an account. For users under 14, Spanish law (Art. 7 LOPDGDD) requires parental consent, which we do not provide a flow for — do not create an account if you are under 18. If we learn a minor has registered, we will delete the account.
12. Cookies and similar technologies (Art. 22 LSSI)
Suelto sets no advertising cookies and carries out no cross-site tracking. What can run on your device, and when, is governed by the cookie preferences (banner, or Settings → Cookie preferences in the app). Until you decide, only the strictly necessary session cookie below is used.
The app sets one strictly necessary cookie — session — to keep you logged in (90-day expiry, HttpOnly, Secure, SameSite=Lax). This cookie is exempt from consent under Art. 22.2 LSSI and the ePrivacy guidance because it is essential to provide the service you requested.
Analytics is opt-in. Only if you allow Analytics in the cookie preferences do we load:
- Cloudflare Web Analytics — a cookieless measurement beacon. It sets no cookies and stores nothing on your device; the source IP of the measurement request is discarded at Cloudflare's network edge and is not kept in the analytics stores. It measures page views, referrers, country, device/browser type and page-load performance for our domains only — it does not profile you, does not follow you to other sites, and is not used for advertising.
- First-party product events — funnel and usage events (e.g. "lesson completed", "checkout started") sent to our own servers and stored in our own database, linked where applicable to a pseudonymous account id. They never contain the content of what you read, write or answer — only counts, ids, levels and scores.
Withdrawing the Analytics preference stops both from loading and from collecting on future visits; deleting the preference re-shows the banner. The support chat below remains governed by its own, separate switch.
The live support chat widget (Crisp) is also opt-in. It does not load and stores nothing on your device until you allow Support chat in the cookie preferences. Once enabled, it stores a functional session identifier (cookie / local storage) on both the marketing site and in the app so a conversation can continue across pages, and the page you are on is shared with the support inbox so an agent can see where you need help. It carries no advertising or analytics identifiers and is not used for profiling. Withdrawing consent stops the widget from loading on future visits; deleting the stored identifier simply starts your next chat as a new conversation.
13. Marketing communications
We send transactional emails (receipts, security notices, service updates) on the basis of contract / legitimate interest. Any newsletter or product marketing is sent only with your prior consent (Art. 21 LSSI) and includes an unsubscribe link in every message. You may opt out at any time without charge.
14. Changes to this policy
Material changes will be announced in-app and, where appropriate, by email at least 14 days before taking effect. Non-material clarifications take effect on publication. The “Last updated” date reflects the current version.
15. Contact
Questions about this policy or to exercise your rights: hola@suelto.es — please include “Privacy” in the subject. Postal contact: Legal Iuris La Zenia, C. Salzillo, S/n, 03189 Orihuela, Alicante, Spain.
For disputes you may also use the EU Online Dispute Resolution platform: ec.europa.eu/consumers/odr, and the out-of-court mechanisms under Art. 25 LOPDGDD.
This policy is provided in English for convenience. Spanish law governs its interpretation. Where a Spanish translation is published, the Spanish version prevails in case of discrepancy. The controller will provide a Spanish copy on request.