Skip to content
DRAFT PREVIEW — Not published legal text
pabo.
HomePrivacyTerms

PABO / LEGAL

Privacy Policy

Effective date: [EFFECTIVE DATE]

ON THIS PAGE1. Information we handle 2. Where information is stored and sent 3. How we use information 4. Retention and deletion 5. Your choices and rights 6. International processing and security 7. Children 8. Changes and contact

Pabo is a language-learning app operated by MarkDid, LLC ("Pabo," "we," "us"). This policy explains what information we collect, how we use and share it, and the choices available to you. It applies to the Pabo app and related services. Contact us at support+pabo@markdid.dev or 2855 N. Canyon Rd., Provo, UT 84604, United States.

1. Information we handle

CategoryWhat it includesWhen and why we handle it
Account and sign-inA guest account ID; if you choose to sign in, your account ID, email address, and sign-in provider. For email accounts in development builds, authentication credentials are handled by our authentication provider. The app also stores your 18-or-older confirmation on your device.To check eligibility before you enter the app, create and secure accounts, let you sign in, and connect your learning progress and purchases to your account. A guest account is created when you start features that need the backend, even if you have not chosen a permanent sign-in method. We do not ask for your birth date or upload the age confirmation as a separate record.
Voice and conversation contentMicrophone audio during a live conversation, speech transcripts and typed messages, conversation context sent to OpenAI, and AI responses.To run and continue conversations, generate replies, captions, translations, and learning feedback. Audio is sent to OpenAI while a live session is active.
Learning dataSelected learning language and level, saved words, lookups, pronunciation or speech assessments, practice history, and learning progress.To personalize lessons and show your progress. Saved words and progress are kept on your device and synced to our backend after you sign in.
Local conversation historyConversation text, character, language, and time.To let you revisit and continue conversations. The app saves this history on your device. It does not sync the full conversation-history collection to our database. Conversation text may still be sent to an AI provider to generate a reply or to our backend when you submit feedback, as described here.
FeedbackYour positive or negative rating, character, language, app version, conversation ID, and a short excerpt of captions when you submit a rating.To review and improve the experience. The app currently includes up to the first eight conversation turns in a feedback submission, subject to a 2,000-character limit.
Purchases and usageSubscription product, purchase and renewal status, store transaction information made available through our purchase processor, promotion or invite redemption, live-session timestamps, character and language, and seconds used.To grant paid access, meter included minutes, prevent duplicate redemptions, and resolve billing issues. Apple or another app store handles payment credentials; we do not receive your full card number.
App activity and technical dataA random install ID, account ID, onboarding and purchase-funnel events, event properties such as selected language, level, character and session length, app version, and request or security data such as IP address.To understand where the experience fails, improve the app, protect the service, and enforce usage limits. We hash IP addresses for a daily guest-session rate limit; service providers may also process network logs.
Support requestsInformation you send us when you contact support.To answer and resolve your request.

We do not ask for precise location, contacts, camera access, or a device advertising ID in the app code reviewed for this policy. We do not use an advertising network or sell personal information for advertising. If these practices change, we will update this policy and any required notices.

2. Where information is stored and sent

On your device. The app stores conversation history, selected languages and preferences, saved words and learning data, your age confirmation, an install ID, trial state, and a small buffer of analytics events locally. Removing the app or clearing its data generally removes locally stored history and settings; device backups may behave according to your device settings.

On our backend. Supabase hosts accounts, synced words and progress, subscription entitlements, usage records, feedback, promotions, and app-activity events. Your local conversation history is not automatically uploaded as a history collection. When you sign in, saved words and learning progress can be synced to your account.

With OpenAI. The live voice service sends session instructions and live audio to OpenAI to produce the conversation and transcripts. Typed replies, word explanations, translation, and speech assessment can also send relevant text or conversation context to OpenAI. The app's production provider wiring uses our OpenAI service connection. OpenAI may retain API content and metadata for safety and abuse monitoring under its published data controls. We do not control information already sent to OpenAI by deleting local history.

With purchase and platform providers. RevenueCat processes account identifiers and purchase history to validate subscriptions and provide entitlements. Apple (and Google Play if an Android version is offered) processes store purchases under its own terms. Apple or Google may provide sign-in information when you use their sign-in option. Dictionary lookups send the queried word to Free Dictionary API and, when needed, Wiktionary; those services also receive normal network information such as IP address.

Our providers include Supabase, OpenAI, Google for optional sign-in, RevenueCat, and the applicable app store. These links describe their own practices. We use service providers under their applicable agreements and take reasonable steps to protect information they process for us.

3. How we use information

We use information to provide and personalize lessons and conversations; authenticate accounts and sync progress; fulfill subscriptions and promotions; provide support; measure and improve app performance and onboarding; prevent fraud, abuse, and unauthorized access; and comply with legal obligations. We do not use your voice or conversation content to train a Pabo model. OpenAI's content-handling rules depend on its service and our account configuration, as explained above.

For people in the EEA, UK, or another place requiring a legal basis, we rely on: performance of our contract to provide accounts, conversations, learning features, and paid access; our legitimate interests in security, support, and product improvement, where those interests are not overridden by your rights; compliance with law for applicable records; and consent where law requires it, including for any optional processing that we identify as consent-based. You can withdraw consent where we rely on it without affecting earlier processing.

4. Retention and deletion

We keep account, synced learning, entitlement, and usage information while needed to operate your account and provide the service. We keep feedback and app-activity events for product improvement and security according to [INSERT VERIFIED RETENTION SCHEDULE BY CATEGORY]. We keep purchase and transaction records for [INSERT VERIFIED PERIOD OR CRITERIA] where required for accounting, disputes, fraud prevention, or law. Local history and preferences remain on your device until you delete them, clear app data, or uninstall the app, subject to device backups. Providers may retain copies under their own policies and legal obligations. For example, OpenAI may retain API safety or abuse-monitoring data for the period described in its data controls.

You can delete an individual local conversation in the app and remove saved words or language progress using the available controls. To request deletion of your account and associated server data, contact support+pabo@markdid.dev. We will verify the request and explain any information we must retain. The app does not currently offer an in-app account-deletion control. Deleting the app alone does not delete your server account, and deleting an account does not automatically cancel an app-store subscription. Manage or cancel your subscription in your store account first.

When an account is deleted, most account-linked records are removed. Some app-activity events may remain with the account ID removed but an install ID still present. We will handle requests to delete those events where required by law and technically feasible.

5. Your choices and rights

You may decline microphone permission and use features that do not require live voice. You can mute or stop a live session, delete local conversations, and manage your subscription through the app-store account. You can contact us at support+pabo@markdid.dev to request access, correction, deletion, or a copy of information we hold, or to object to or restrict processing where applicable. We may need to verify your identity. Rights and exceptions vary by location. If you are in the EEA or UK, you may complain to your local data-protection authority. If you are in a US state with applicable privacy rights, you may exercise those rights through the same contact without discrimination for doing so. We do not currently offer a separate sale or cross-context behavioral advertising opt-out because the app does not perform those activities.

6. International processing and security

We and our providers may process information outside your country, including in the United States. Our Supabase project's primary database is hosted in Northern Virginia, United States (`us-east-1`). Other providers may process information in other locations. Where law requires safeguards for an international transfer, we use the relevant contractual or other approved mechanism [CONFIRM ACTUAL TRANSFER MECHANISM BEFORE PUBLICATION]. We use access controls, encrypted connections, and other reasonable safeguards. No system is perfectly secure, so please avoid sharing sensitive information in a practice conversation that you do not want transmitted to an AI provider.

7. Children

Pabo is intended for adults age 18 and older. Before entering the app, users must confirm that they are at least 18. The confirmation is a self-attestation; we do not independently verify age. Pabo is not directed to people under 18. If you believe a person under 18 has created an account or provided personal information through Pabo, contact support+pabo@markdid.dev. We will review the report and delete the account and associated information as required by law, subject to information we must retain.

8. Changes and contact

We may update this policy as the app or law changes. We will post the revised policy with a new effective date and provide additional notice when required. Material changes will not be applied retroactively in a way that law prohibits.

Operator: MarkDid, LLC
Privacy contact: support+pabo@markdid.dev
Mailing address: 2855 N. Canyon Rd., Provo, UT 84604, United States

pabo.

Talk more. Learn more.

PrivacyTermsContact
© 2026 MarkDid, LLCPabo is for adults 18 and older.