Skip to content

Privacy policy

Last updated 2026-09-06

Léo Etelbert is the controller for the personal data SHAZA collects. For any question, or to exercise your rights: [email protected].

What we collect

Account: your email address, display name, and a bcrypt hash of your password — the password itself is never stored.

Profile: your main goal, biggest challenge, how often you interact with people, how much time you want to spend, your language.

Usage: XP, level, streak, completed lessons, challenges, badges, AI quota consumed.

What you write: journal entries, transcripts of your practice simulations, saved items, quiz answers.

Billing: your Stripe customer id and subscription state. No card data.

Technical: one strictly necessary session cookie, plus the request metadata your host and CDN see.

Why, and on what basis

Performance of the contract: creating and keeping your account, giving you the service, managing your subscription.

Legitimate interest: keeping the service secure, limiting abuse, measuring usage in aggregate.

Consent: non-transactional email — streak reminders and the weekly digest — which you can switch off in Settings at any time.

Legal obligation: retaining accounting records for payments.

Who receives it

We do not sell data and we do not advertise. These processors are involved:

Railway Corporation — hosting and the PostgreSQL database (California, USA (US-West)). Sees everything stored by the service.

Google (Gemini API) — receives the text of a coaching message, a practice turn or a journal entry at the moment you ask for AI help, in order to generate the reply. Processed in the United States.

Resend, and Amazon SES in Ireland (eu-west-1) — your email address and the content of transactional messages: verification, password reset, streak reminders, weekly digest.

Stripe — your email address and subscription state. Card details go straight to Stripe and never reach this service.

Cloudflare — proxies traffic to shaza.app, so it sees request metadata such as your IP address.

Transfers outside the EU: hosting and the database (California, USA (US-West)) process everything stored in the United States, and the Gemini API processes the text concerned there when you trigger an AI feature. These transfers are covered by the European Commission's Standard Contractual Clauses and by a data-processing agreement (DPA) with each processor. Transactional email stays processed in the EU (Ireland).

How long

Account and content: for as long as your account exists.

Deletion: Settings → Delete account. It is immediate and irreversible — profile, progress, journal, transcripts and history go with it, and the Stripe subscription is cancelled.

Session, verification and reset tokens: days at most, then purged.

Accounting records: for as long as the law requires.

Your rights

Access, rectification, erasure, restriction, objection and portability. Write to [email protected].

You may also complain to the supervisory authority where you live.

Cookies

One cookie is set: your session, strictly necessary for the service to work. It is `httpOnly`, `SameSite=Lax`, and is not used for tracking.

No analytics tool is active today. If one is added, this page is updated first, and anything setting a non-essential cookie will ask for consent before it does.

Security

Passwords hashed with bcrypt, 256-bit opaque session tokens, HSTS, a per-request Content-Security-Policy, and a database with no public endpoint.