Privacy Policy
Privacy Policy
Your voice stays on your machine
Speech recognition and the speaking voice run in a helper that lives on your own computer. Audio is never uploaded — there is nowhere for it to go. What leaves your machine is the text of the conversation, so that the tutor can think about what you said. If you run the tutor against a local model, nothing leaves at all.
What we store
- Your account: a username, your email address, and a one-way hash of your password (we never store the password itself). If you sign in with Google or GitHub, we store the email that provider reports and no password.
- Your practice: session transcripts (as text), the code you write, the prompts and responses of the model calls, assessments, summaries, and any short notes the tutor keeps to remember your context. These exist so the product can bring back what went wrong.
Who else sees it
- The model that does the thinking receives the text of the conversation (your transcribed words and your code) to generate the tutor's replies. By default and in production this is Anthropic; the operator can point it at another provider.
- Our email provider delivers account-confirmation and password-reset emails, and so handles your email address for that purpose.
- A payment provider — only if paid plans are ever turned on — processes payments. We never see or store your card details; only a record that a purchase happened.
- The landing site (usegadfly.com) is hosted by Cloudflare and loads fonts from Google Fonts, so those services see the ordinary requests any web host and font service see.
Cookies and tracking
The product sets no advertising or tracking cookies. Your sign-in is a token kept in your browser's local storage, not a cookie; the only cookies are two short-lived ones used during Google/GitHub sign-in, deleted right after. The landing site sets no tracking cookies either — if we measure landing traffic at all, we use a cookieless analytics tool that does not build a profile of you. Your IP address is used only, and briefly, in memory to rate-limit sign-in attempts; it is not written to the database.
Your controls
From Settings → Your data you can download everything as one JSON file, and delete your data with the word DELETE. A signed-in person deleting their own account removes the account, its sign-in and any purchase record too — that is a full deletion and cannot be undone.
Where the data lives
Account and practice data live in a database on a server we operate, reached over an encrypted (HTTPS) connection. We keep your data while your account exists; deleting it removes it as described above.
Contact
Questions about your data, or a request about it, go to [email protected]. Using Gadfly is also subject to the Terms of Service.