Pausa — Privacy Policy
Last updated: 2026-08-06
This Privacy Policy explains what information Infinitespot Services OÜ (“we”, “us”, “our”) collects when you use the Pausa iOS app (“the app”), how we use it, who we share it with, and the choices you have. We’ve tried to write this in plain language; if anything is unclear, email us at support@infinitespot.co.
1. Who we are
The app is published by Infinitespot Services OÜ. We’re the data controller for the personal data described in this Policy.
Contact for privacy questions, data-access requests, or anything else: support@infinitespot.co
2. What we collect and why
2.1 Information you give us directly
| What | When | Why we collect it | Where it’s stored |
|---|---|---|---|
| Apple Sign In identifier | When you sign in with Apple at first launch | Scopes your library + saved words to your account on this device | iOS Keychain on your device |
| Your name (optional) | If you type it into the Profile editor | Greets you in the app | Locally on your device only |
| Your email (optional) | If you type it into the Profile editor | (a) Lets us contact you about your account, and (b) sends you product updates / offers / discounts only if you also toggle on “Offers and discounts” in the Profile editor | Locally on your device. If — and only if — you opt in to marketing, also shared with PostHog (see §3.4) so we can send you the campaigns you opted into. |
| Audio recordings | When you tap the orb to record a session or press-and-hold to dictate a word in “Dictate Words” | To transcribe what you said into text | Session transcription defaults to Cloud: session audio is uploaded to our speech-recognition processor (Speechmatics, see §3.1) for transcription; the processing job — including the uploaded audio — is deleted automatically by the provider at the end of its standard retention period. An on-device engine (“On this device” — WhisperKit + a diarizer, entirely on-device) is also selectable in Settings and never uploads audio; it’s a deliberate opt-in upgrade requiring a one-time model download over Wi-Fi. Dictated words (“Dictate Words”) are transcribed on-device whenever that model is downloaded, and via Cloud otherwise. Recordings are stored locally; if “Back up recordings to iCloud” is on (the default), session audio is also stored in your private iCloud database, which only your Apple account can access — we cannot read it. Turn the backup off in Settings to keep audio strictly local. |
| Transcripts + saved words | Generated when you analyze a session or dictate a word | The core feature — your vocabulary library | Locally on your device. Word enrichment, session analysis, and every other text-generation feature default to Cloud (OpenAI, see §3.5) unless you switch to On this device in Settings, which runs entirely on your iPhone once you’ve downloaded the on-device language model (an optional one-time download over Wi-Fi). Exception when On this device is selected: if a session’s transcript is too long for the on-device model’s processing window, or the on-device model isn’t downloaded yet, that one request is sent to OpenAI instead so it can still complete — see §3.5. |
| Marketing consent state | When you toggle “Offers and discounts” in the Profile editor | To know whether we’re allowed to email you | Locally on your device. Mirrored to PostHog as a person property so our campaign tooling can filter to consented users only. |
You can edit or delete any of this from inside the app:
- Edit your name / email / consent → Settings → tap the profile card
- Delete your account + all local data → Settings → Delete account
- Delete a single word → swipe on it in Library
- Delete all words → Settings → Library → Delete all words
2.2 Information we collect automatically
| What | Why | Where it goes | Linked to your identity? |
|---|---|---|---|
| Product analytics events (taps, screen views, session starts, word saves, etc.) | Understanding which features get used so we can prioritize improvements | PostHog (§3.4) | Yes — tagged with your pseudonymous account identifier |
| Crash reports, non-fatal exceptions, and performance diagnostics (stack traces, device model, iOS/app version, error strings, speech-to-text latency) | Identifying and fixing crashes and recoverable errors; spotting slow paths | PostHog Error Tracking (§3.4) — automatic crash capture plus exceptions we report manually, alongside performance diagnostics. Apple — aggregate OS metrics through MetricKit and, depending on Apple’s privacy and consent settings, detailed crash reports and logs through Xcode Organizer (a separate pipeline under Apple’s terms). | PostHog: linked only to your pseudonymous account identifier, never your name or email. Apple: aggregate MetricKit metrics are de-identified; detailed Organizer crash reports and logs are governed by Apple’s privacy and consent terms. |
| Structured logs (debug breadcrumbs for the same events as analytics) | Cross-referencing analytics with diagnostic timelines | PostHog (§3.4) | Tagged with your pseudonymous account identifier |
We do not collect your precise location, your IP address (beyond the standard network-level metadata our service providers see), your contacts, your photos, or any data from other apps. We do not use third-party advertising SDKs.
3. Third parties we share data with
We use a small number of trusted third parties to run the app. None of them sell your data to anyone else, and the data they receive is scoped to what each one specifically needs.
3.1 Speech recognition — Cloud by default, On-device available as an upgrade
Session transcription defaults to Cloud — this works immediately, with no download required before your first session. You can switch to On this device in Settings → Transcription at any time; speech-to-text then runs entirely on your iPhone and no audio is sent to any third-party speech provider, once you’ve downloaded the on-device speech model (a one-time download over Wi-Fi). Speaker labeling is available on both engines. Word dictation runs on-device whenever the on-device speech model is installed, and via Cloud otherwise.
Cloud transcription (Speechmatics). What’s shared (only while Cloud is selected): the session’s audio recording and the language you’re learning, sent to Speechmatics Ltd for transcription and speaker labeling. Deletion & retention: transcription jobs — including the uploaded audio — are deleted automatically by Speechmatics at the end of their standard retention period; processing is governed by the Speechmatics Privacy Policy and their data processing terms. Word dictation (“Dictate Words”) runs on-device whenever the on-device speech model is installed — regardless of this setting. When that model is not installed (for example, you removed it in Settings to free storage) and the Cloud engine is selected, dictation clips are transcribed by the same Speechmatics service under the same deletion & retention terms as session audio. With “On this device” selected, dictation audio is never uploaded — the app instead asks you to download the on-device model (over Wi-Fi). Switching back to “On this device” stops all audio uploads immediately.
3.2 Apple diagnostics (MetricKit / Xcode Organizer)
What’s shared: nothing directly by us. Apple collects diagnostics on-device. MetricKit provides aggregate, de-identified crash and performance metrics such as launch time, hang rate, and energy use. Depending on your Apple privacy and diagnostic-sharing settings, Apple may also provide us with detailed crash reports and logs through Xcode Organizer under Apple’s terms. This pipeline is separate from PostHog Error Tracking (§3.3). Why: so we can identify and fix crashes and performance regressions through Apple-managed diagnostics. Retention: governed by Apple’s Privacy Policy. Region: handled by Apple under its own terms.
3.3 PostHog
What’s shared: product analytics events (tap names, screen names, custom properties — no raw user content), structured log lines, automatic crash reports and manually reported non-fatal exceptions (including stack traces and error strings, but never your transcripts, words, or definitions), performance diagnostics (speech-to-text latency), the pseudonymous account identifier we use to identify your account, and — only when you opt in via the “Offers and discounts” toggle — your email address as the $email person property. The identifier we send is your stable Apple Sign In identifier only; we never send your name, email (except the opt-in marketing case above), or IP address. We do not record session replays of your screen.
Why: product analytics + structured logs, crash, non-fatal error, and performance diagnostics + email-campaign cohort targeting when you opt in.
Retention: governed by PostHog’s Privacy Policy.
Region: European Union (Frankfurt).
3.4 Apple
What’s shared: the standard data Apple receives from any iOS app — your Apple ID identifier for Sign In with Apple, App Store transaction state, push-notification token, and crash reports Apple’s own systems collect. For paid features: when you tap a plan on the paywall, Apple’s In-App Purchase system handles the entire payment — we never see your card number, billing address, or full Apple ID. Apple sends back only a cryptographically signed receipt confirming the purchase plus the product identifier (e.g. com.app.pausa.pro.monthly), which is what our app uses to grant access.
Why: authentication + app delivery + processing your in-app purchases.
Retention: governed by Apple’s Privacy Policy and the Apple Media Services Terms.
3.5 OpenAI (cloud text generation)
Text generation — word enrichment, session analysis, exercises, practice lessons, and the rest — defaults to Cloud, processed by OpenAI. You can switch to On this device in Settings → “Text generation” at any time; this then runs entirely on your iPhone, once you’ve downloaded the on-device language model (a one-time download over Wi-Fi) — nothing is sent to a third party for this. Two situations send that one request to OpenAI even while On this device is selected, so the feature still completes rather than simply failing: the on-device model’s processing window is too small for that particular session’s transcript, or the on-device model hasn’t finished downloading yet.
What’s shared (while Cloud is selected, or in either fallback case above): the session transcript or word being processed, the language you’re learning, and — for session analysis — a list of words you already know (so the analysis doesn’t re-suggest them). What’s NOT shared: your name, email, Apple Sign In identifier, or any other session’s content — each request is scoped to the one operation being run. Why: to generate word details, session analysis, exercises, and practice content — by default, or to complete that generation when the on-device path can’t (window too small, or the model isn’t downloaded yet), instead of refusing it outright. Deletion & retention: governed by OpenAI’s Privacy Policy and their API data-usage policy; OpenAI does not use API content to train its models by default. Region: United States.
If you’d rather no transcript content ever leave your device under any circumstance, switch to On this device in Settings and download the on-device model — you can also delete any affected session locally at any time.
4. Your rights (and how to exercise them)
Because we operate in the European Union, the EU General Data Protection Regulation (GDPR) applies. You have the following rights regardless of where you live:
- Right to access — ask us what data we have about you. Email support@infinitespot.co; we’ll respond within 30 days.
- Right to erasure (“be forgotten”) — tap Settings → Delete account in the app. This permanently removes your library, sessions, recordings, and settings from this device, clears the PostHog
$emailperson property if it was set, and resets your pseudonymous PostHog identifier. If you also want us to purge the third-party-side copies that may persist beyond their normal retention windows (Speechmatics receives your session audio while Cloud transcription is selected, which is the default; OpenAI receives text-generation requests while Cloud text generation is selected, which is also the default, or — when On this device is selected — only when the on-device model’s processing window can’t hold the request or the model isn’t downloaded yet, per §3.5), email us with your Apple Sign In identifier and we’ll request deletion on your behalf. - Right to rectification — edit your name, email, and consent from Settings → Profile.
- Right to portability — email us. We’ll export your saved words as a CSV.
- Right to object — toggle off “Offers and discounts” in the Profile editor to immediately stop the marketing-email pipeline. Other processing (analytics, diagnostics) supports core app functionality and runs under our legitimate interest; you can object by deleting your account.
- Right to lodge a complaint — you can complain to your local EU data-protection authority. The Estonian Data Protection Inspectorate (aki.ee) is the lead supervisory authority for Infinitespot Services OÜ.
5. Data retention
| Data | How long we keep it |
|---|---|
| Local library, sessions, recordings, settings | Until you delete the app or tap Settings → Delete account |
| Pseudonymous account identifier (Sign In with Apple identifier) | Until account deletion |
Marketing email (PostHog $email person property) | Until you revoke consent or delete your account |
| Analytics + diagnostics data | Per the relevant service provider’s retention policy (typically 90 days for events, up to 12 months for error issues). Apple-side crash diagnostics are retained by Apple under its own terms. |
| Text-generation requests sent to OpenAI (default Cloud path, or the On-device fallback, §3.5) | Governed by OpenAI’s API data-retention policy; not used to train models by default |
We don’t keep historical backups of personal data after deletion.
6. Children
Pausa is intended for users aged 13 and over. We don’t knowingly collect data from children under 13. If you believe a child has used the app and provided personal data, contact us and we’ll delete the account.
7. International data transfers
By using the app, you accept that personal data may be transferred to and processed in:
- The European Union (PostHog)
- The United States (Apple; OpenAI — the default text-generation path, and the On-device fallback, §3.5)
- The United Kingdom (Speechmatics — the default transcription path, unless you switch to On this device)
For transfers outside the EU/EEA, our processors operate under Standard Contractual Clauses or equivalent safeguards.
8. Security
- Audio recordings are encrypted in transit (HTTPS / WSS).
- The Apple Sign In identifier is stored in your iOS Keychain.
- Sensitive secrets (API keys) are bundled into the app build only and never logged.
- The only identifier we send to PostHog is your pseudonymous Apple Sign In identifier — never your name, email (except the opt-in marketing case), or IP address. We do not record session replays of your screen.
- We use Sign In with Apple, so we never see your Apple ID password.
We can’t promise zero-incident security — no one truthfully can — but if a breach affects your data we’ll notify you within 72 hours of becoming aware of it, as required by GDPR Article 33–34.
9. Changes to this Policy
If we change this Policy in a way that affects what data we collect or how we use it, we’ll:
- Update the “Last updated” date at the top
- Surface a notice the next time you open the app
- If the change requires it, ask for fresh consent before continuing
The current version is always available at this URL (and inside the app via the link in Settings → Privacy).
10. Contact
Infinitespot Services OÜ Registry code: 16678626 Registered address: Harju maakond, Tallinn, Lasnamäe linnaosa, Sepapaja tn 6, 15551, Estonia Email: support@infinitespot.co
You can also write to us using the in-app Settings → Contact support path, which automatically attaches diagnostic info we use to answer faster.