Privacy policy
Effective October 10, 2026. Contact by email only, at the address in section 32.
Summary. We never record your calls. We don't ask for your name, email, phone number, photos, contacts or precise location, we don't keep your date of birth, and we don't sell your personal information. There is no sign-in: your account is a random ID made on your phone, and we also receive a scrambled form of your phone's Android ID so that suspensions and the under-18 hold stay with the phone. The people you talk to see your country and whether your account is less than a week old, and in a direct call they could technically see your IP address. Friends see when you were last connected. Ads come from Google AdMob. You can delete your account in the app at any time, under Settings, then Account. The numbered sections below set out our practices in full.
1. Introduction and scope
1.1 This Privacy Policy (the "Policy") explains how we collect, use, disclose, retain and dispose of personal information in connection with Talkoa, a voice service that matches adults for live conversations and lets them keep in touch as Friends.
1.2 This Policy applies to (a) the Talkoa application for Android; (b) the servers and systems that operate it; and (c) the website at talkoa.com (together, the "Service"), and to every individual who uses the App, visits the Website or writes to us.
1.3 This Policy forms part of the Agreement described in section 1.2 of our Terms of service. Our Cookies and device storage policy forms part of this Policy. Where this Policy and the Terms differ on the handling of personal information, this Policy prevails.
1.4 Services operated by others, such as Google's advertising services and Google Play, are also governed by their providers' own policies. Section 14 explains what those providers receive.
2. Interpretation
2.1 Capitalised terms have the meanings given in section 3, or, if not defined there, in the Terms.
2.2 The summary at the top of this Policy is accurate but not complete, and does not limit the numbered sections.
2.3 Headings do not affect interpretation. "Including" means including without limitation. A reference to a law includes that law as amended or replaced and any regulation made under it. A reference to a section is to a section of this Policy.
2.4 A period described as "up to" a stated length is a maximum, and the record concerned may be removed sooner.
2.5 Where this Policy states that we do not do something, it describes our practice and our commitment not to begin doing it without first amending this Policy as section 31 describes and, where the law requires it, obtaining your consent.
2.6 Sections 22 to 28 give further rights to residents of particular places. They apply in addition to the rest of this Policy and do not reduce any protection given elsewhere in it.
2.7 If any part of this Policy is unclear to you, write to us and we will explain it.
3. Definitions
3.1 In this Policy:
- "Account" means the account the App creates for your phone when you first open it, and "Account ID" means the random identifier, generated by the App at that time, which is your Account.
- "App" means the Talkoa application for Android, and "Website" means talkoa.com.
- "Applicable Law" means every law on the protection of personal information that applies to us in respect of you.
- "Backups" means copies of our database kept so that it can be restored after a failure.
- "Call" means a live voice conversation through the App, whether with someone you were matched with at random or with a Friend.
- "Country" means the country from which you connect, as worked out from your IP address by Cloudflare.
- "Device Hash" means the one-way scrambled form of your phone's Android ID, produced with the SHA-256 algorithm, that the App sends to us. It cannot be turned back into the Android ID.
- "Friend" means someone you and they have both chosen to add after a Call, and "Friend Name" means the name made from your Public ID that your Friends see, such as Blue Heron.
- "Gender Answer" means your optional answer to the App's question whether you are a woman.
- "GDPR" means Regulation (EU) 2016/679; "UK GDPR" means that regulation as it forms part of the law of the United Kingdom; "PIPEDA" means the Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5; "Quebec Private Sector Act" means the Act respecting the protection of personal information in the private sector, CQLR c. P-39.1, as amended by the law commonly called Law 25; "DPDP Act" means India's Digital Personal Data Protection Act, 2023; and "LGPD" means Brazil's Law No. 13,709/2018 (Lei Geral de Proteção de Dados Pessoais).
- "Personal Information" means information about an identifiable individual, and includes "personal data" and "personal information" as defined by Applicable Law.
- "Plus" means the Talkoa Plus subscription, and "Purchase Token" means the token Google Play issues for a purchase of Plus.
- "Privacy Officer" means the individual we have designated as accountable for our compliance with this Policy and Applicable Law, who is also the person in charge of the protection of personal information under the Quebec Private Sector Act.
- "Process" means any operation on Personal Information, including collection, use, storage, disclosure and deletion.
- "Public ID" means the separate random identifier that other users see in place of your Account ID.
- "Relay" means the relay run by Cloudflare through which audio passes when a Call cannot travel directly between the two phones.
- "Safety Records" means the reports, blocks, suspensions and Under-18 Holds described in section 6.15.
- "Talkoa ID" means the identifier shown in the App under Settings, then Account, which you quote when you write to us.
- "Under-18 Hold" means the record kept when the App's age screen finds that the person using the phone is under 18, consisting of the date that person turns 18 and the Device Hash of the phone.
- "we", "us" and "Talkoa" mean the company identified in section 4, and "you" means the individual to whom the Personal Information relates.
4. The accountable organisation and the Privacy Officer
4.1 Inayah Tech Solutions Inc., a corporation incorporated under the laws of Ontario, Canada, operates Talkoa and is accountable for the Personal Information this Policy describes. Where the relevant law applies to us, we are also the "controller" under the GDPR and the UK GDPR, the "business" or "controller" under United States state privacy laws, the "Data Fiduciary" under the DPDP Act, and the "controller" (controlador) under the LGPD.
4.2 We are accountable for Personal Information under our control, including information we pass to the providers in section 14 to Process for us, and we use contractual means to require a comparable level of protection from them.
4.3 The Privacy Officer can be reached at [email protected], and mail to that address about privacy is treated as notice to the Privacy Officer, who is the point of contact for questions, requests, grievances and complaints under every Applicable Law. We correspond by email only and keep no postal address for notices.
5. What we do not collect, and what we do not do
5.1 We state these limits first because they matter as much as what we do collect:
- (a) we do not record, listen to or transcribe Calls;
- (b) we do not ask for your name, email, phone number, photos, contacts or precise location;
- (c) we do not keep your date of birth;
- (d) we do not sell Personal Information, or share it for cross-context advertising, apart from what Google's ad services collect as section 14 describes;
- (e) we do not use your information to train AI models;
- (f) we never see your card or payment details;
- (g) we do not write your IP address to our database or logs; and
- (h) we never show your Account ID to anyone, and never show anything more precise about your location than your Country.
5.2 The App does not ask for an email address. If you choose to write to us, we receive the address you write from, as section 6.19 describes.
6. Categories of Personal Information
6.1 The table lists each category of Personal Information we Process, its source, our purposes, the legal basis we rely on where the GDPR or the UK GDPR applies (section 12), and how long we keep it (section 17). Sections 6.2 to 6.21 describe each category.
| Category | Source | Purposes | Legal basis (EU and UK) | Retention |
|---|---|---|---|---|
| Account ID | Generated by the App | Running your Account; connecting you; enforcing blocks and suspensions; rejoining a dropped Call | Contract; legitimate interests (safety) | Until you delete your Account |
| Public ID and Friend Name | Generated for your Account | Identifying you to others without revealing your Account ID | Contract | Until you delete your Account, or while a Safety Record containing it is kept |
| Device Hash | Computed by the App from the Android ID | Keeping suspensions and the under-18 hold with the phone | Legitimate interests (safety, protecting children) | With your Account; after deletion only alongside a suspension (up to 2 years) or an Under-18 Hold (until that 18th birthday) |
| Gender Answer | You, if you choose to answer | Matching with Plus users who filter by gender | Consent | Until you delete your Account |
| Date of turning 18 | Worked out on your phone; your date of birth is not kept | Keeping the App closed until that date | Legitimate interests (protecting children); legal obligation where one applies | Until that 18th birthday |
| Languages, Friends, friend requests, blocks, Plus filters | You | Providing the features you choose | Contract; legitimate interests (safety) for blocks | Until you delete your Account; unanswered friend requests 1 day |
| Language test results | You | Unlocking Calls in a language | Contract | Passes until you delete your Account; attempts 2 days |
| Language answers after Calls | You and other users | Keeping language matching honest | Legitimate interests (reliable matching) | Up to 2 years, or longer where the law requires; removed when the Account is deleted |
| Daily count of Calls in languages other than English | Your use | Applying the daily limit | Contract | 2 days |
| Ad counts | Your use | Applying the ad rules in the Terms | Contract | Until you delete your Account |
| Days you use Talkoa | Your use | Counting daily and returning users | Legitimate interests (understanding use) | About 13 months |
| When you were last connected | Your use | Showing your Friends | Contract | Until you delete your Account |
| How you found us | Google Play | Learning which ads work | Legitimate interests (understanding which ads work) | Until you delete your Account |
| Country; whether your Account is less than a week old | Cloudflare, from your IP address; our records | Showing the people you talk to; Plus country filters | Contract; legitimate interests (safety) | Latest Country only, until you delete your Account |
| Purchase Token and Plus end date | Google Play | Checking purchases, renewals and refunds; preventing reuse of a purchase | Contract; legitimate interests (preventing misuse) | End date until you delete your Account; token kept after deletion, no longer linked to you |
| Safety Records | You, other users, and us | Acting on reports; enforcing blocks, suspensions and the under-18 hold | Legitimate interests (safety); legal obligation | Reports and suspensions up to 2 years, or longer where the law requires |
| IP address | Your connection | Running the Service; limiting abuse such as automated connections | Contract; legitimate interests (preventing abuse) | Held in memory only while you are connected; not written to our database or logs |
| Your voice | You | Carrying the Call live | Contract | Never recorded or stored |
| Advertising information collected by Google | Google AdMob, in the App | Showing, limiting and measuring ads | Consent where the law requires it, through Google's consent form | Under Google's own policy |
| Correspondence | You | Answering you; handling requests, appeals and complaints | Legitimate interests; legal obligation | As long as needed to deal with the matter |
Your Account
6.2 Account ID. When you first open the App, it makes a random ID for your phone. It is your Account: there is no sign-in, password or username. We use it to connect you, enforce blocks and suspensions, and let you rejoin a Call if your connection drops. It is never shown to anyone.
6.3 Public ID and Friend Name. Other people see only a separate random Public ID, and Friends see a Friend Name made from it, such as Blue Heron.
6.4 Device Hash. The App also sends a one-way scrambled form (a SHA-256 hash) of your phone's Android ID. It cannot be turned back into the ID and is not shown to anyone. We use it only so that a suspension stays with the phone instead of ending at a reinstall, and so that Talkoa stays closed on a phone whose owner told us they are under 18.
Information about you
6.5 Gender Answer. Answering is optional. If you answer, we keep it so that people with Plus who choose to talk only with women, or only with men, can be matched with you. It is never shown, but someone using that filter can tell which answer you gave from being matched with you. Once given, it cannot be changed in the App. Section 7 explains how we treat it.
6.6 Date of birth. Your date of birth is checked on your phone and not kept. If it shows you are under 18, the phone keeps only the date you turn 18 and sends us that date, nothing else (section 29).
Your use of the App
6.7 Choices. The languages you want to talk in, your Friends and friend requests, the people you block, and your filters if you have Plus.
6.8 Language tests and answers. Calls in languages other than English unlock with a short listening test. We keep whether you passed each language's test and when you last tried it. After a Call you can say whether the other person spoke the chosen language; we keep those answers, and a pass can be taken back if several people say no.
6.9 Usage counts. Your daily number of Calls in languages other than English. The Calls you have had since a full-screen ad last showed, and when it showed, to apply the ad rules in section 9 of the Terms. The days you use Talkoa, to count daily users and how many come back. When you were last connected, which your Friends see.
6.10 How you found us. If you installed Talkoa through one of our links or ads, Google Play tells the App which one, and we keep that to learn which ads work.
6.11 Country. Cloudflare works out the country you connect from, from your IP address, and we keep the latest one. Section 8 explains who sees it.
6.12 Plus. If you buy Plus, Google Play takes the payment. We receive a Purchase Token, check it with Google, and keep it with the date your Plus ends, so that we can check renewals and refunds and so that one purchase cannot be used on another Account. We never see your card or payment details.
Connection data and your voice
6.13 IP address. While you are connected, our servers hold your IP address in memory to run the Service and to limit abuse such as automated connections. It is not written to our database or logs. Our logs record Public IDs and call IDs only.
6.14 Your voice, live only. Calls are carried live and never recorded or stored, as section 9 explains.
Safety Records
6.15 Reports and blocks you make or that involve you, with the reason chosen, the time, and which Call it was about. Suspensions, and Under-18 Holds.
Information collected by Google
6.16 Google AdMob may collect your phone's advertising ID, your IP address and information about the ads you see and tap. Google Play handles Plus payments and tells the App how it was installed. Section 14 describes both.
Other information
6.17 Hourly counts of the number of people online are kept for 8 days. They are not linked to anyone and are not Personal Information.
6.18 Any other category of Personal Information will be added to this section before we begin to collect it.
6.19 Correspondence. If you write to us, we receive your email address, your message, and anything you include, such as your Talkoa ID or a Google Play order number, and use it to answer you and to handle any request, appeal or complaint.
7. Sensitive information and inferences
7.1 Sensitivity depends on the nature of information and the context of its use. We treat as sensitive the Gender Answer; the Under-18 Hold, which concerns a person under 18; and Safety Records.
7.2 The Gender Answer. We collect it only if you choose to answer, and answering is your express consent to the use section 6.5 describes. You can use Talkoa without answering. The answer is never shown, but a Plus user who chooses to talk only with women, or only with men, and is matched with you can infer which answer you gave. Answer only if you are content for people using that filter to draw that inference.
7.3 The Gender Answer cannot be changed in the App. You may withdraw your consent to it by deleting your Account, or by asking us under section 21 to erase it.
7.4 We do not ask for information about racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation, or genetic or biometric data. People may talk about such things in a Call, but Calls are not recorded, so we hold nothing that was said.
7.5 Other inferences. Your Country is visible to the people you talk to. A language pass suggests you speak that language. Your last-connected time tells Friends when you were last active. In a direct Call, your IP address can show a rough location (section 8.4).
7.6 Age. We never keep a date of birth. The only age information we keep is, for a person under 18, the date they turn 18.
8. Information disclosed to other users
8.1 People you talk to see your Country and whether your Account is less than a week old. Nothing more precise than the Country is ever shown. Plus users can filter whom they are matched with by Country and by gender.
8.2 Friends see your Friend Name and when you were last connected.
8.3 Identifiers. Your Account ID is never sent to other users, who see only your Public ID. Your Device Hash is never shown to anyone.
8.4 Direct Calls. To connect a Call directly, each phone needs the other's IP address. The person you talk to could therefore technically see your IP address, which can show a rough location such as your city or internet provider. It does not show your name, phone number or exact address.
8.5 What you say reaches the person you are talking to, and we do not control what they do with it. The Terms forbid recording a Call without the clear permission of everyone in it, but we cannot technically stop another person from breaking that rule. Never share your address, money, passwords, intimate images or anything you would regret.
8.6 The gender filter lets a Plus user infer your Gender Answer, as section 7.2 explains.
8.7 Reports and blocks. Nobody is told who reported or blocked them, and blocked people are not told.
9. How Calls work
9.1 Matching. Our server matches you with another user who chose the same language, applying blocks, suspensions, daily limits and, for Plus users, their filters.
9.2 Connection. Calls travel directly between the two phones where possible, which requires each phone to have the other's IP address (section 8.4). When that is not possible, audio passes through the Relay run by Cloudflare.
9.3 Encryption. Audio is encrypted in transit, whether it travels directly or through the Relay.
9.4 No recording. Calls are never recorded or stored by us or by Cloudflare, and we do not listen to or transcribe them. We therefore hold no recording or transcript of any Call, and none can be disclosed, deleted or provided on request.
9.5 What we keep about a Call. Each Call has a call ID. Our logs record it with the Public IDs of the people in it, and a report records which Call it concerns.
9.6 Length and afterwards. Calls are capped at 15 minutes, or 60 minutes with Plus. After a Call you may be asked whether the other person spoke the chosen language, and you can report or block them during the Call or for 30 minutes after it.
10. Identified purposes
10.1 We identify our purposes at or before collection, through this Policy and in the App. We Process Personal Information:
- to run your Account, match you, connect Calls, and let you rejoin a dropped Call;
- to provide the features you choose, including languages, Friends and Plus filters;
- to keep Talkoa safe: acting on reports, enforcing blocks, suspensions and the under-18 hold, and stopping spam and abuse such as automated connections;
- to keep language matching honest, through tests and the answers people give after Calls;
- to apply daily limits and the ad rules;
- to show ads that pay for the Service;
- to check Plus purchases, renewals and refunds, and stop a purchase being used on another Account;
- to understand how many people use Talkoa, how many come back, and which ads work;
- to answer correspondence and handle requests, appeals and complaints; and
- to meet our legal obligations.
10.2 We collect only what these purposes need, and do not use or disclose Personal Information for any other purpose except with your consent or as the law requires or permits. Before using it for a new purpose, we will identify that purpose and, where the law requires it, obtain your consent.
11. Consent
11.1 We rely on your consent, in a form suited to the sensitivity of the information and your reasonable expectations, except where the law permits or requires Processing without it.
11.2 Information the Service needs. By continuing past the App's welcome screen, you consent to the Processing this Policy describes that is needed to provide the Service: your Account ID, Public ID, Device Hash, Country, IP address while connected, your choices, language results, usage counts and Safety Records. The Service cannot be provided without it.
11.3 Express consent. You give express consent to the Gender Answer by choosing to answer. Where the law requires it, Google's consent form asks you before personalised ads are shown.
11.4 Ad choices. Where the law gives you the choice, you can change your ad privacy choices in the App under Settings, then Ad privacy choices. You can also reset your advertising ID or turn off ad personalisation in your phone's Google settings.
11.5 Withdrawal. You may withdraw a consent at any time, subject to legal or contractual restrictions and reasonable notice. Withdrawal does not affect earlier Processing. Withdrawing consent to information the Service needs means we can no longer provide it to you, and we will tell you the consequences before acting.
11.6 Without consent. The law permits or requires some Processing without consent, such as the disclosures in section 15.
11.7 We do not seek consent from anyone under 18 (section 29).
12. Legal bases under EU and UK law
12.1 Where the GDPR or the UK GDPR applies, we rely on:
- (a) performing our agreement with you (Article 6(1)(b)), to run your Account and Calls and provide the features and limits the Terms describe;
- (b) our legitimate interests (Article 6(1)(f)) in user safety, preventing abuse, keeping children off the Service, reliable language matching, preventing misuse of Plus purchases, and understanding use and which ads work, balanced against your interests and fundamental rights;
- (c) your consent (Article 6(1)(a)) for the Gender Answer and personalised ads; and
- (d) legal obligation (Article 6(1)(c)), including answering requests under this Policy, recording breaches, and disclosures the law requires.
12.2 You may object to Processing based on legitimate interests (section 24) and ask us about the balancing we carried out. Where we rely on our agreement and you do not provide the information, we cannot provide the Service.
12.3 We do not seek to Process the special categories of data in Article 9. We nonetheless treat the Gender Answer as sensitive and collect it only with consent.
12.4 Storage of and access to information on your phone is also governed by the rules on device storage. The Cookies and device storage policy explains which items are strictly necessary and how consent is obtained for the others.
13. Automated decision-making
13.1 Much of the Service runs automatically, such as finding a match and applying your filters and blocks. The following decisions restrict what you can do and are made without a person deciding each time:
- Pause after reports. When several different people report an Account within a day, it is paused until our team reviews it. The information used is the number of different people who reported it and when.
- Phone-level holds. An Account on a suspended phone is suspended too, and a phone held as under 18 stays closed until that birthday. The information used is the Device Hash, compared with those held with suspensions and Under-18 Holds, and the date of turning 18.
- Pause for skipped ads. If Calls keep ending before the ad between them can show, new random Calls pause for a couple of minutes. The information used is the pattern of Calls ending before the ad. Calls with Friends are not affected, and watching a short ad ends the pause at once.
- Language passes. A language unlocks with a test score and can be taken back if several people say it wasn't spoken. The information used is your score and the answers people gave after Calls with you.
13.2 You can ask for any of these to be reviewed by a person, and tell us why you think it is wrong, by writing to the address in section 32 with your Talkoa ID or, for a paused Account, by tapping Appeal on the Paused screen. A person reviews every appeal. On request, we will tell you the information used and the reasons and principal factors behind the decision. This applies whether or not the decision has a legal or similarly significant effect on you.
14. Service providers
14.1 We share Personal Information only with the providers that run Talkoa for us, under terms that limit how they may use it, and as section 15 describes. Each receives only what its function requires.
| Provider | Function | Information | Location |
|---|---|---|---|
| Oracle Cloud | Hosts our server and database | The information in our database | United Kingdom (London) |
| Cloudflare | Carries connections to our server, runs the Relay, works out your Country, hosts the Website | IP address and connection data; encrypted audio through the Relay; Website requests | Worldwide |
| Google AdMob | Shows ads | Advertising ID, IP address, ads seen and tapped | Worldwide |
| Google Play | Handles Plus payments; tells the App how it was installed | Your purchase and payment, which Google holds; install source | Worldwide |
14.2 Google AdMob may collect your phone's advertising ID, IP address and information about the ads you see and tap, to show and measure ads, under its own policy at policies.google.com/technologies/ads. Where the law requires it, Google's consent form asks you before personalised ads are shown, and you can change your choice in Settings. Talkoa Plus has no ads.
14.3 Google Play takes the payment for Plus and holds your payment details under Google Play's terms. We receive only the Purchase Token, which we check with Google.
14.4 Information Google collects through AdMob and Google Play is also governed by Google's own privacy policy, and Google is responsible for its own use of it.
15. Disclosures required by law and for safety
15.1 We disclose Personal Information when the law requires it, such as under a court order or other legal process that binds us, or when someone's safety is at risk. We disclose only what the requirement or the situation calls for.
15.2 When we find or are told about child sexual abuse material or exploitation, we suspend the Account, keep the records the law requires, and report it to the National Center for Missing and Exploited Children (NCMEC) and, for Canada, to Cybertip.ca, and to law enforcement where required. We cooperate with lawful requests from police and child protection agencies, as our Child safety standards describe.
15.3 We can disclose only what we hold. We hold no recording or transcript of any Call and no stored record of your IP address.
16. Where information is held, and transfers across borders
16.1 Our server and database are in the United Kingdom, at Oracle Cloud's London region, and backup copies are kept in Canada. Cloudflare and Google operate worldwide.
16.2 While information is held or Processed in another country, it is subject to that country's laws and may be accessible to its courts, law enforcement agencies and national security authorities. We rely on contractual protections from each provider.
16.3 Where the GDPR or the UK GDPR applies, transfers to the United Kingdom and Canada are made to countries recognised as providing adequate protection, and transfers elsewhere rely on safeguards in each provider's terms, such as standard data protection clauses, or another mechanism that law recognises. You may ask us about these safeguards.
16.4 Sections 23 and 26 to 28 add provisions for Quebec, Australia, India and Brazil.
17. Retention and disposal
17.1 We keep Personal Information only as long as the purposes in section 10 need it, or longer where the law requires.
| Record | Retention |
|---|---|
| Account, Public ID, Country, Friends, settings, Gender Answer, language passes, ad counts, Plus end date, last-connected time, how you found us, blocks you made | Until you delete your Account |
| Reports and suspensions | Up to 2 years, or longer where the law requires |
| Language answers | Up to 2 years, or longer where the law requires; removed when the Account is deleted |
| Device Hash | With your Account; after deletion only alongside a suspension (up to 2 years) or an Under-18 Hold (until that 18th birthday) |
| Under-18 Hold | Until that 18th birthday |
| Purchase Token | Kept after deletion, no longer linked to you, so it cannot be used again on a new Account |
| Test attempts and daily Call counts | 2 days |
| Unanswered friend requests | 1 day |
| Days you used Talkoa | About 13 months |
| Hourly counts of people online, not linked to anyone | 8 days |
| Records the law requires, such as reports of child exploitation to the authorities | As long as the law requires |
| IP address | In memory only while you are connected |
| Call audio | Never recorded or stored |
| Backups of the database | Up to 30 days |
17.2 Deleting your Account. In the App, under Settings, then Account, then Delete account, your Account is deleted straight away. If you ask by email, we confirm by reply and delete it within 30 days. Deletion removes your Account and its ID, your Country, your Gender Answer, your Friends list and friend requests, your language settings and test results, your daily Call counts, the blocks you made, and the language answers you gave or that others gave about you.
17.3 What remains. To keep other people safe, we keep reports made about your Account, and any suspension along with the Device Hash it applies to, for up to 2 years after deletion, so that someone suspended for abuse cannot simply start again. Records we must keep by law are kept as long as the law requires. If the App was told its owner is under 18, the Device Hash and that 18th birthday stay until then. The Purchase Token is kept, unlinked from you. Everything else is removed within 30 days, including from Backups.
17.4 Backups and disposal. Backups are kept for up to 30 days, so deleted information may remain in a Backup until it expires. Scheduled jobs, not manual action, remove what is past these points.
17.5 Deleting your Account does not cancel Plus. Cancel it in Google Play, under Payments and subscriptions, or it keeps renewing. See how to delete your account.
18. Safeguards
18.1 Our safeguards are proportionate to the sensitivity of the information. Stated as what exists, rather than as an aspiration:
- every connection to our server is encrypted, and Call audio is encrypted in transit;
- your Account ID is never sent to other users, who see only a separate Public ID;
- the Android ID reaches us only as a one-way SHA-256 hash, and your date of birth is checked on your phone and not sent;
- our server accepts connections only through Cloudflare, and our test tools are not reachable from the internet;
- your IP address is held in memory only, and our logs record Public IDs and call IDs, never Account IDs or IP addresses;
- card and payment details stay with Google Play; and
- old records are removed by scheduled jobs, not by hand.
18.2 No system is completely secure, and we cannot promise that ours can never be compromised.
18.3 Your Account lives on your phone. Keep the phone secure, because anyone who can use the App on it can use your Account.
19. Breaches of security safeguards
19.1 If a breach of our safeguards affects Personal Information, we will assess whether it creates a real risk of significant harm, considering the sensitivity of the information and the probability of its misuse.
19.2 Where it does, we will report it to the Office of the Privacy Commissioner of Canada, tell the people affected as soon as we can, and notify any other organisation or government institution that may be able to reduce the risk. A notice to you will describe what happened, the information involved, what we have done, what you can do, and how to reach us.
19.3 We keep a record of every breach, reportable or not, for at least 24 months.
19.4 Where another law applies, we will also report and notify as it requires, including reporting a confidentiality incident presenting a risk of serious injury to the Commission d'accès à l'information du Québec, and, under the GDPR or the UK GDPR, notifying the competent supervisory authority within 72 hours unless the breach is unlikely to result in a risk to people's rights and freedoms.
20. Your rights
20.1 Subject to section 21 and Applicable Law, you may ask to see the Personal Information we hold about you, have it corrected, have it deleted, withdraw a consent, and ask how it has been used and to whom it was disclosed. Sections 22 to 28 add rights for particular places, and section 13 gives the right to human review of automated decisions.
20.2 The quickest way to delete everything is in the App, under Settings, then Account. You can change your languages, Friends, blocks, Plus filters and ad choices in the App at any time.
21. How to exercise your rights
21.1 Requests. For anything you cannot do in the App, email [email protected] with your Talkoa ID, shown in Settings, then Account, and say what you are asking for.
21.2 Verification. Because there is no sign-in, we may ask you to confirm details only your phone has, so nobody else can get, change or delete your information. We will ask for no more than that purpose needs and use it only to verify the request. If we cannot verify a request, we may decline it and will say why.
21.3 Agents. Where the law allows, someone may make a request for you. We may ask for proof of their authority and may still ask you to confirm details only your phone has.
21.4 Time limits. We answer within 30 days, and will tell you before then if we need longer and why. Any extension will not exceed what the law allows, and where a shorter period applies to you, we will meet it.
21.5 Fees. Requests are free unless they are clearly unfounded or repetitive, in which case we may decline them or, where the law allows, charge a reasonable fee, and will explain why.
21.6 Refusals. Where the law lets or requires us to refuse part of a request, we will say so in writing, give the reason, and explain how to complain. Grounds include that answering would reveal someone else's information, such as who reported or blocked you; that the information is legally privileged; or that disclosure would prejudice the investigation of a breach of the Agreement or the law. We will provide whatever part can be provided.
21.7 Limits. We cannot provide what we do not hold, such as Call recordings or a history of your IP address, and after an Account is deleted we may be unable to find information connected with it.
21.8 Review. If you are not satisfied with how we handled a request, ask for a review and we will reply in writing with the outcome.
22. Canada
22.1 Our handling of Personal Information is governed by PIPEDA and, where it applies, by provincial law recognised as substantially similar, including the Quebec Private Sector Act (section 23).
22.2 This Policy gives effect to the ten principles in Schedule 1 to PIPEDA: accountability (section 4), identifying purposes (10), consent (11), limiting collection (5 and 10), limiting use, disclosure and retention (14, 15 and 17), accuracy (20), safeguards (18), openness (this Policy), individual access (20 and 21) and challenging compliance (32).
22.3 We answer access requests within 30 days. We may extend that by up to a further 30 days, or longer where needed to convert information into an alternative format, and will tell you of the extension, the reasons, and your right to complain to the Privacy Commissioner of Canada.
23. Quebec
23.1 Where the Quebec Private Sector Act applies, you may also:
- (a) ask for computerised Personal Information you provided to be communicated to you, or to a person or body you designate, in a structured, commonly used technological format;
- (b) where a decision is based exclusively on automated Processing (section 13), be told the Personal Information used, the reasons and principal factors and parameters that led to it, and your right to have the information corrected, and submit observations to a member of our staff who can review it; and
- (c) where the law so provides, ask us to stop disseminating Personal Information about you, or to de-index a hyperlink attached to your name that gives access to it.
23.2 The person in charge of the protection of personal information is the Privacy Officer, at [email protected].
23.3 We obtain express consent for sensitive Personal Information, including the Gender Answer.
23.4 Before Personal Information is communicated outside Quebec, including to our database in the United Kingdom, we conduct an assessment of privacy-related factors where the law requires one.
23.5 The Service works out your Country from your IP address (section 6.11), and Google AdMob may use your advertising ID to personalise ads, which you can control as section 11.4 describes.
23.6 We keep a register of confidentiality incidents and report any that presents a risk of serious injury to the Commission d'accès à l'information and the people concerned.
23.7 We respond to written requests within 30 days. You may complain to the Commission d'accès à l'information du Québec.
24. European Union and United Kingdom
24.1 Where the GDPR or the UK GDPR applies, we are the controller, and section 12 sets out our legal bases. In addition to the rights in section 20, you may:
- (a) object, on grounds relating to your situation, to Processing based on our legitimate interests;
- (b) restrict Processing, for example while accuracy is checked or an objection is considered;
- (c) receive data you provided, Processed on the basis of consent or our agreement, in a structured, commonly used and machine-readable format, and have it sent to another controller where technically feasible;
- (d) withdraw a consent at any time, without affecting earlier Processing;
- (e) not be subject to a decision based solely on automated Processing that has legal or similarly significant effects, and obtain human intervention, express your view and contest it (section 13); and
- (f) complain to the supervisory authority where you live or work or where an alleged infringement occurred, which in the United Kingdom is the Information Commissioner's Office.
24.2 We respond within one month. Where requests are complex or numerous, we may extend this by up to two further months, and will tell you within the first month, with reasons.
24.3 Section 16.3 explains how we protect data transferred out of the European Economic Area and the United Kingdom.
25. United States
25.1 Where a United States state privacy law applies to us, including the California Consumer Privacy Act as amended, the following also applies.
25.2 Categories collected in the past 12 months, as those laws describe them: (a) identifiers: Account ID, Public ID, Device Hash, IP address while connected, the email address of anyone who writes to us, and the advertising ID collected by Google AdMob; (b) characteristics of protected classifications: the Gender Answer, if given; (c) commercial information: the Purchase Token and Plus end date; (d) internet or other network activity: usage counts, days of use, last-connected time, install source, and ads seen and tapped, collected by Google AdMob; (e) geolocation limited to Country, which is not precise geolocation; (f) audio, carried live and never recorded or stored; and (g) inferences, limited to language passes and the inference about the Gender Answer in section 7.2.
25.3 Sources, purposes and retention for each category are in sections 6, 10 and 17. We disclose personal information for business purposes to the providers in section 14, and as section 15 describes.
25.4 Sale and sharing. We do not sell personal information. Apart from what Google's ad services collect as section 14 describes, we do not share it for cross-context behavioural advertising. You can turn off ad personalisation or reset your advertising ID in your phone's Google settings and, where the law gives you the choice, change your choices in the App under Settings, then Ad privacy choices.
25.5 We do not use sensitive personal information in a way that gives a right to limit it, do not disclose personal information to third parties for their own direct marketing, and do not offer any financial incentive in exchange for personal information.
25.6 Your rights. Subject to your state's law, you may ask to know the categories and specific pieces of personal information we collected about you, its sources and purposes, and the categories of recipients; have it corrected or deleted; obtain a portable copy; and opt out of targeted advertising as section 25.4 describes. Requests are made as section 21 describes, including through an authorised agent, subject to verification.
25.7 Appeals. If we decline a request, you may appeal by replying and asking us to reconsider. We will answer in writing within the time your state's law requires. If the appeal is denied, you may contact your state attorney general.
25.8 We won't treat you differently for using these rights. Talkoa is only for adults, and we do not sell the personal information of anyone, including anyone under 16.
26. Australia
26.1 Where the Privacy Act 1988 (Cth) and the Australian Privacy Principles apply to us, the following also applies.
26.2 Talkoa does not ask for your name; you deal with us and other users under random identifiers.
26.3 Personal Information is held in the United Kingdom, with Backups in Canada, and Processed by Cloudflare and Google wherever they operate (section 16).
26.4 We respond to access and correction requests within a reasonable period, and in any case within 30 days. Section 13 describes our automated decisions and how to have them reviewed.
26.5 Please complain to us first, and we will respond within 30 days. If you are not satisfied, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
27. India
27.1 Where the DPDP Act and its rules apply to us, we are the Data Fiduciary, and we Process your personal data on the basis of your consent or a legitimate use the Act recognises.
27.2 You may ask for a summary of the personal data we Process about you and the Processing activities, and the identities of others with whom it has been shared; have it corrected, completed, updated or erased; withdraw consent; and nominate someone to exercise your rights if you die or become incapable.
27.3 The Privacy Officer, at [email protected], handles questions and grievances, which we answer within the period the rules prescribe. After using this process, you may complain to the Data Protection Board of India.
27.4 Personal data may be transferred to the countries in section 16, except any to which the Government of India has restricted transfers. Talkoa is only for people 18 and over (section 29).
28. Brazil
28.1 Where the LGPD applies, we rely on the legal bases it recognises that correspond to section 12: performance of our agreement, legitimate interests, consent, compliance with a legal or regulatory obligation, and the regular exercise of rights.
28.2 You may ask for confirmation that we Process your data; access to it; correction of incomplete, inaccurate or out-of-date data; anonymisation, blocking or deletion of unnecessary or excessive data or data Processed unlawfully; portability; deletion of data Processed on consent; information about those with whom we shared it and about the possibility and consequences of not consenting; withdrawal of consent; and review of decisions made solely by automated Processing (section 13).
28.3 Data is transferred to the countries in section 16 under mechanisms the LGPD recognises. The Privacy Officer, at [email protected], is our channel for communication about your data. You may complain to the National Data Protection Authority (ANPD).
29. Children and the under-18 hold
29.1 Talkoa is only for people 18 and over. We don't knowingly collect information from anyone younger, and we delete it when we find it, keeping only the Under-18 Hold.
29.2 The App asks for your date of birth before your first Call. It is checked on your phone and not kept. If it shows you are under 18, the phone keeps only the date you turn 18 and sends us that date, nothing else.
29.3 We keep that date with the Device Hash, so that Talkoa stays closed on that phone until the 18th birthday, including after a reinstall. When the birthday arrives, the hold ends and is removed.
29.4 Anyone can report a person who seems under 18 by tapping Report and choosing They seem under 18, during a Call or for 30 minutes after it. Reports about minors are reviewed first, and if we learn that someone under 18 is using Talkoa, we close their access.
29.5 If you believe a person under 18 is using Talkoa, tell us at [email protected]. If a child is in immediate danger, contact your local police first. See our Child safety standards.
30. Do Not Track and Global Privacy Control
30.1 Because we don't track you across apps or websites, a Do Not Track or Global Privacy Control signal changes nothing further for us: what it asks for already applies. The Website sets no cookies of its own and runs no analytics, tracking pixels or advertising scripts. Ad choices in the App are controlled as section 11.4 describes.
31. Changes to this Policy
31.1 If we change this Policy in a way that matters, we'll show a notice in the App before the change takes effect, and update the date at the top. We will not use information already collected for a new purpose without identifying it and, where the law requires, obtaining your consent. The version in force is the one on this page.
32. Contact, complaints and challenging compliance
32.1 This Policy is issued by the company identified in section 4, which is accountable for the information described here. Questions and requests, including for the Privacy Officer: [email protected]. We correspond by email and keep no postal address for notices.
32.2 If you're not satisfied with how we handled something, tell us and ask for a review. We will reply in writing with the outcome and say what, if anything, we have changed as a result.
32.3 You can complain to the Office of the Privacy Commissioner of Canada at any time, whether or not you have raised the matter with us first, at priv.gc.ca or 1-800-282-1376.
32.4 You also have the right to complain to the data protection authority where you live, including the Commission d'accès à l'information du Québec, a supervisory authority in the European Union, the Information Commissioner's Office in the United Kingdom, your state attorney general in the United States, the Office of the Australian Information Commissioner, the Data Protection Board of India, or Brazil's National Data Protection Authority.
32.5 This Policy supersedes any earlier version.