Legal
Privacy Notice
Last updated: 6 August 2026
This Privacy Notice explains how Xpect S.P., Banović Strahinje 28, 78000 Banja Luka, Bosnia and Herzegovina ("we", "us", "our"), the operator of Konzul (the "Service"), collects, uses, shares, and protects personal data. We are the data controller for the personal data described below. A plain-language companion to this notice is available on our Security & data handling page.
1. Privacy by design
Konzul is built around data minimisation. We ask only for what a spoken language rehearsal needs, we do not store voice recordings at all, we delete practice text on a fixed schedule, and we remove identifiers from text before it is stored or sent to an AI provider.
2. Personal data we collect
- Account data — your email address and authentication identifiers (for example a Google sign-in identifier, or a securely hashed password).
- Profile and preparation data — the display name you choose, the level you select, and the content of your simulated interviews.
- Interview conversation text — the transcribed text of your spoken answers and the consul's replies, retained for a limited period (see Retention).
- Assessment data — scores, estimated CEFR level, readiness and pass estimates, topic coverage and written feedback.
- Önéletrajz (life story) data — text you write or that is read from page photos you upload, and the resulting coverage analysis.
- Support and communications — the content of messages you send us.
- Operational and security data — coarse usage counters used for abuse prevention and rate limiting, and error status codes.
- Payment data — handled by our Merchant of Record, Creem. We receive limited billing metadata (subscription status, plan, period, currency, country for tax) and never full card numbers.
3. What we deliberately do not collect
The simulated consul is instructed never to ask for a passport or ID number, personal identification or TAJ number, tax number, bank or card details, a full postal address, a phone number or a password. If you mention something like that anyway, it is detected and replaced with a neutral placeholder (for example [ID_NUMBER_1]) before the text is stored or sent for processing.
4. How we use personal data
- to create and secure your account, and to provide the Service;
- to transcribe, translate, evaluate and simulate consular interviews using AI models;
- to show your interview history, reports and readiness dashboard;
- to process purchases, subscriptions, invoices and refunds through Creem;
- to prevent fraud and abuse, including per-account rate limits;
- to respond to support requests and to meet legal or regulatory obligations.
5. Legal bases
- Performance of a contract — providing the Service you signed up for.
- Legitimate interests — securing the Service, preventing abuse, and communicating operationally with users.
- Consent — for optional features that require it. You may withdraw consent at any time.
- Legal obligation — retention of billing and tax records and responding to lawful requests.
6. Voice recordings
Your audio is streamed for transcription, used, and discarded. Recordings are never stored: nothing is written to a recording archive and no recording is ever attached to your account. Only the resulting text is retained, for the limited period described below.
7. AI processing
Konzul uses OpenAI models to play the consul, transcribe speech, generate the spoken voice and assess answers. Requests are sent as stateless calls with provider-side retention for model training and dashboard history switched off, and identifiers are redacted before any text leaves our servers. Your practice content is not used to train AI models. Prompts, model responses and transcripts are never written to our application logs; errors record a status code only.
8. Who we share personal data with
- Creem — Merchant of Record for subscription sales, payment processing, tax compliance, invoicing and refunds.
- Lovable Cloud — hosting, database, authentication and file storage.
- OpenAI — transcription, language generation, speech synthesis and assessment.
- Authentication providers where you choose to sign in with Google.
- Professional advisers and authorities, where reasonably necessary or required by law.
We do not sell your personal data and we do not use it for advertising.
9. International transfers
Personal data may be processed outside your country of residence, including outside the UK/EEA. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.
10. Retention
- Voice recordings — not kept at all.
- Interview conversation text — automatically deleted 30 days after the session ends.
- Scores, level estimate and progress — kept while your account exists, so your Journal and readiness view keep working after the text is gone.
- Önéletrajz page photos — deleted as soon as the read-through finishes.
- Önéletrajz text — deleted after 90 days.
- Account data — kept until you delete your account.
- Billing records — retained by Creem as required by tax and accounting law.
11. Your rights and controls
Subject to applicable law, you have the right to access, rectify, erase, restrict, port and object to the processing of your personal data, and to withdraw consent where processing relies on it. Where the GDPR applies you may also lodge a complaint with your local supervisory authority. We aim to respond to verified requests within one month.
Three of these rights are self-service, on your Readiness page under "Your data":
- Download my data — a machine-readable JSON copy of everything stored about your account.
- Erase my content — removes conversation text, written feedback and önéletrajz reviews while keeping your account.
- Delete account — permanently removes the account and everything attached to it.
12. Security
- All traffic is served over HTTPS with a strict set of browser security headers.
- Every practice record is bound to your account at the database level, so one account can never read another's interviews, reports or önéletrajz.
- New and changed passwords are checked against known breached-password lists.
- You are signed out automatically after 30 minutes of inactivity.
- Per-account rate limits protect against abuse and runaway processing.
No online service is completely secure. You are responsible for keeping your credentials confidential, for the device you practise on, and for choosing what you disclose during practice.
13. Cookies and browser storage
We use a small number of cookies and equivalent browser storage for essential functionality, such as keeping you signed in and remembering your preferences. We do not use third-party advertising cookies. Where non-essential cookies are introduced, we will ask for consent as required.
14. Children
The Service is not directed at children under the age required to consent to online services in their country. If you believe a child has provided us with personal data, please contact us so we can remove it.
15. Changes
We may update this Privacy Notice from time to time. Material changes will be communicated through the Service or by email where appropriate.
16. Contact
For privacy questions or to exercise your rights, contact us through the in-app support channel. Billing-related privacy questions can also be raised with Creem via the link in your receipt email. Suspected security issues should be reported to us before public disclosure.