Skip to content
TalkerApp

Privacy policy

Last updated:

In short

  • We keep your e-mail address, your choice of systems (one or more of Mac, Windows, iPhone and iPad, and Android) and the language of the page. We use them to e-mail you about the TalkerApp release and to count how many people want each system.
  • We do not ask who you are or whether you have a disability, and we do not record that.
  • We delete a sign-up you do not confirm within 7 days of the last link we send you, and straight away when you unsubscribe.
  • The site, the waitlist and our e-mail run on our own server, rented from netcup and located in Austria. Cloudflare carries the traffic to it and runs a bot check. We do not sell your data.
  • The pages of this site set no cookies and run no analytics or advertising scripts.

What this policy covers

This policy explains how we process personal data on the website gettalker.app: when you join the TalkerApp waitlist, when you write to us, and when you visit the site. It follows the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and Polish law.

The TalkerApp program is a separate matter. This policy covers the website and the waitlist only. What the program keeps on your computer, and what it can send out when you switch a cloud service on, is described in the privacy section of How it works. The program’s own privacy information will be published with the release.

Who is responsible for your data

  • Controller: OneFinger - Łukasz Czerwiński, a sole proprietorship registered in the Polish business register (CEIDG).
  • Address: ul. Puchacza 13/1, 20-323 Lublin, Poland
  • Tax and business numbers: Polish tax ID (NIP) 9462590874, business register number (REGON) 540818917
  • Contact for data matters: hello@gettalker.app

We have not appointed a data protection officer. The law does not require one at this scale. Łukasz Czerwiński handles data matters personally, and only he has access to the waitlist.

The waitlist

What we keep

  • Your e-mail address.
  • The systems you chose (one or more of Mac, Windows, iPhone and iPad, and Android) and the language of the page you used.
  • A short campaign tag, only if the link you used to reach the form carried one. It is a word we add to our own links to learn which of them bring people to the form. You do not type it, and it holds nothing about you.
  • The version of the consent text and a fingerprint (hash) of the exact text you were shown. We record them twice: when you sign up (the text of the form) and when you confirm (the text of the confirm page).
  • When you signed up and when you confirmed.
  • When we last e-mailed you, and how many e-mails we sent you in the past day. This counter stops anyone from using the form to flood an inbox.
  • A fingerprint (hash) of the code in your confirmation link, and of the link before it, which keeps working when you ask again for the same system and language. We never keep the codes themselves.

What you agree to

On the form you check one box. Its text is:

I want an e-mail when TalkerApp is ready for my system. I agree to the processing of my e-mail address and my choice of system by OneFinger - Łukasz Czerwiński for this purpose: to send me a confirmation e-mail now and one e-mail about the release for each system I chose, and to count how many people want each system. The release e-mail is commercial information: it will say where to download the program and, if Pro is on sale by then, how to buy a Pro license.

I also expressly agree that the mere fact that I joined this list is processed for this purpose only. That fact may indirectly say something about health, mine or that of someone close to me.

I can withdraw my consent at any time with the link in every e-mail. My sign-up is then deleted.

Why we use it, and on what basis

We use this data for four purposes and no others:

  1. Confirmation e-mail. To check that the address is yours. Basis: your consent (Art. 6(1)(a) GDPR).
  2. Release e-mail, and keeping your sign-up until then. One e-mail for each system you chose, when TalkerApp is available for it. It is commercial information: it says where to download the program and, if Pro is on sale by then, how to buy a Pro license. Basis: your consent (Art. 6(1)(a) GDPR). It is also your consent to commercial information by e-mail under art. 398 of the Polish Electronic Communications Law (Prawo komunikacji elektronicznej). Because the mere fact that you joined may indirectly say something about health, you also give explicit consent under Art. 9(2)(a) GDPR to processing that fact for this purpose only.
  3. Counting interest. We count confirmed sign-ups per system and per page language to decide which system to release first. Each system needs its own security certificate, which costs money. We use counts only. We make no profile of you. Basis: your consent (Art. 6(1)(a) GDPR).
  4. Proof of your consent. When you sign up, and again when you confirm, we keep the version of the consent text and the fingerprint of the text you were shown (the form, then the confirm page), and the times, so that we can show later what you agreed to. Basis: our legitimate interest in proving consent (Art. 6(1)(f) and Art. 7(1) GDPR). You can object (see “Your rights”).

How long we keep it

  • Not confirmed: we delete it when the last confirmation link we sent you expires, at most 7 days after we sent it. A daily job does this, so it can take up to one more day.
  • Confirmed: until the earliest of these: you unsubscribe (we then delete it at once); 30 days after the last release e-mail you are waiting for; or 24 months after you confirmed.
  • Backups: we copy the database once a day, and before every update of the site, and keep each copy for up to 30 days on the same server. A deleted sign-up disappears from the copies when they expire. We use the copies for nothing else.
  • Deleted sign-ups: when you unsubscribe or ask us to delete your data, we keep two things for 30 days: the random internal number of the deleted sign-up and the time it was deleted. Neither holds an address or anything else about you. We use them for one purpose: if we ever have to restore the database from a backup, we can delete your sign-up again.
  • Mail server log: our mail server records each message it sends: the time, the sender, your address and whether it was delivered. We need this to find out why a message did not arrive. The log is kept for up to 5 weeks.
  • Bounces: if a message to you cannot be delivered, the notice about it comes back to hello@gettalker.app and contains your address. We handle it as a message sent to us (see “Messages you send us”).

Protecting the sign-up form

  • What: your IP address, your browser’s technical details (for example its type and version) and the result of an automatic check that a person, not a program, is using the form (Cloudflare Turnstile). A limit on sign-ups per connection keeps your IP address in the server’s memory for one minute. We do not save it in the waitlist database.
  • Why: to stop automated and mass sign-ups, and to stop anyone using the form to flood someone else’s inbox with confirmation e-mails.
  • Basis: our legitimate interest in keeping the waitlist and our e-mail sending free of abuse (Art. 6(1)(f) GDPR).
  • How long: our own technical logs are kept for up to 7 days. Cloudflare keeps what it processes under its own rules (see “Who processes data for us”).
  • The check loads only when you first use a control of the sign-up form: you click or tap a field, a choice, the consent box or the button (or the words that label one of them), or you move the keyboard focus into one. Reading the page, selecting or tapping other explanatory text, and following a link do not load it. The form is on the waitlist page. At most the check asks you to click a box. It never asks you to solve a puzzle.

Visiting the site

Cloudflare and our server process your IP address, the time, the page you ask for and your browser’s details to deliver the site and keep it secure. Our server’s technical logs are kept for up to 7 days and do not contain the codes from confirmation and unsubscribe links. Basis: our legitimate interest in running and securing the site (Art. 6(1)(f) GDPR). We do not use these logs to identify visitors, and we do not link them to the waitlist.

Messages you send us

  • What: your e-mail address, your message, and anything else you choose to include. Please do not send health information.
  • Why: to answer you and deal with your matter. Basis: our legitimate interest in answering people who contact us (Art. 6(1)(f) GDPR).
  • How long: until your matter is closed, and then 12 more months in case it comes back. If you use one of your rights, we keep a record of your request and our answer for 3 years to show that we complied (legitimate interest).

Does joining the waitlist say something about your health?

Possibly, and we want to say so openly. TalkerApp is a program for writing and speaking. People who cannot rely on speech or fast typing may want it, and so may relatives, therapists, students and curious readers. We do not ask which of these you are, and we do not record or guess it. Courts in Europe read “data concerning health” broadly: it can include information from which health could be concluded indirectly.

For that reason the form asks for your explicit consent to processing the fact that you joined (Art. 9(2)(a) GDPR). It is the second paragraph of the consent text above. You can withdraw it at any time with the link in every e-mail. We then delete your sign-up.

Who processes data for us

We use these services. Each one processes data on our behalf under a data processing agreement.

  • netcup GmbH (Karlsruhe, Germany). Rents us the server, located in Austria, that runs the site, keeps the waitlist database and its copies, sends our e-mails and holds the mailbox for hello@gettalker.app. We run the server ourselves. netcup provides the machine and its network.
  • Cloudflare, Inc. (USA). Every request to the site passes through Cloudflare’s network, which delivers it to our server over an encrypted connection and protects the site from attacks. Cloudflare also runs the bot check (Turnstile). For some narrow purposes, running and securing its own network and improving the bot detection in Turnstile, Cloudflare acts as an independent controller. It explains this in Cloudflare’s privacy policy and its Turnstile Privacy Addendum.

We may disclose data to public authorities if the law requires it. We do not sell your data and do not share it for anyone’s advertising.

Transfers outside the European Economic Area

The waitlist database, its copies and our e-mail are on our server in Austria, in the European Union. Cloudflare’s network handles requests in many countries, and Cloudflare does not currently offer to keep the bot check inside the EU. So your IP address and your browser’s details can be processed outside the European Union.

These transfers rely on the EU–US Data Privacy Framework (Art. 45 GDPR, Commission Implementing Decision (EU) 2023/1795), in which Cloudflare takes part. They also rely on the standard contractual clauses approved by the European Commission (Art. 46 GDPR). They are part of Cloudflare’s data processing agreement (Cloudflare data processing agreement). You can ask us for a copy of these safeguards.

Your rights

You have the right to:

  • access your data and get a copy (Art. 15 GDPR);
  • have it corrected (Art. 16);
  • have it deleted (Art. 17);
  • restrict how it is processed (Art. 18);
  • receive it in a portable format (Art. 20);
  • object to processing based on our legitimate interest (Art. 21);
  • withdraw your consent at any time, without affecting what was lawful before (Art. 7(3) and Art. 9(2)(a)).

To use any of them, write to hello@gettalker.app. To protect you from impersonation we may answer only to the address on the list, for example by sending a confirmation link there before we share anything. We answer within one month. For complex requests the law allows two more months, and then we tell you why.

To leave the waitlist you do not need to write. Every e-mail from us has a link to a page with one button. Pressing it deletes your sign-up at once.

You can also complain to the Polish supervisory authority, the President of the Personal Data Protection Office (UODO, Prezes Urzędu Ochrony Danych Osobowych), ul. Stanisława Moniuszki 1A, 00-014 Warszawa (UODO website), or to the authority where you live or work. The Office asks that you first raise the matter with us. Please do: we want to fix it.

Do you have to give us your data?

No. Joining the waitlist is voluntary. Without an e-mail address we cannot tell you when TalkerApp is ready. That is the only consequence.

Automated decisions

The only automated decisions here are the bot check (person or program), the limit on sign-ups per connection and the limit on e-mails per address. They decide only whether the form is accepted or an e-mail is sent. We do not profile you.

Cookies and browser storage

The pages of this site set no cookies and run no analytics or advertising scripts. They load no fonts, images or scripts from other companies. The one exception is the bot check on the sign-up form. Cloudflare delivers it in a frame of its own when you first use a control of the form (see “Protecting the sign-up form”).

  • Language. The language is part of the page address (/en/ or /pl/). Nothing is stored.
  • Color theme. The footer has a control for the color theme: System, Light or Dark. If you choose Light or Dark, the site saves that choice in this browser (local storage, key gt-theme). It is saved only when you press the control, it never leaves your device, and the control says so beside it. Choosing System removes it. If you make no choice, the site follows the setting of your system and stores nothing.
  • Bot check. We set it up so that it saves nothing in this website’s own storage. The frame that Cloudflare delivers may keep one small value in its own browser storage area; that area belongs to Cloudflare’s address, not to this site. Cloudflare says the signals the check collects are strictly necessary for detecting bots, and describes what it processes in its Turnstile Privacy Addendum.

The typing sample

The home page has a sample where you type a few letters, see suggestions and hear the sentence spoken. It runs in your browser. What you type is not sent to us and is not saved. The sample speaks only with voices installed on your device.

How we protect your data

  • Encrypted connections (HTTPS) everywhere.
  • The waitlist database is on our own server in the EU. The program that serves the site runs under an account of its own. It cannot change its own code, and the only files it can change are those of the waitlist database.
  • Only the owner has administrator access to the server.
  • Confirmation codes are stored only as hashes. Unsubscribe links are signed, so they cannot be forged.
  • A bot check, a limit on requests per connection and a limit on e-mails per address protect the form.
  • The site’s logs hold no e-mail addresses. Only the mail server’s log does (see “How long we keep it”). We do not export the list to personal devices.
  • Expired sign-ups are deleted automatically every day.
  • If a personal data breach puts your rights at risk, we tell you and the supervisory authority as the law requires.

Children

The waitlist is for adults. If you are under 16, please do not sign up yourself. Ask a parent or caregiver to do it with their own address.

Changes to this policy

We update this policy when what we process, or who processes it for us, changes, for example when we add a service to this site. The date at the top of this page is the date of the latest version. If a change needs your consent, we ask for it. We do not assume it.

We keep every earlier version of a consent text, and each sign-up records the name of the version its owner agreed to. The versions in use are consent-b-v2-en (English form and confirm page) and consent-b-v2-pl (Polish form and confirm page).

Questions about this page, or something here that is hard to use? Write to us.

hello@gettalker.app