Effective Date: December 4, 2025 Last Updated: December 4, 2025 This Privacy Policy describes how Bliss Coach ("we," "us," or "our") collects, uses, and shares your information when you use the Sofia mobile application (the "App"), an AI-powered Spanish learning platform. 1. Who We AreApp Name: Sofia • Developer: Bliss Coach • Company Address: 72 avenue parmentier, 75011 Paris, France • Contact for Privacy Questions: privacy@blisscoach.com 2. Information We Collect We collect information to provide and improve the AI-driven educational service. You have the option to use the App without creating a registered account, in which case some data is stored locally on your device. 2.1. Information You Directly ProvideCategoryData PointsPurpose of CollectionAuthentication (If you create an account)Email (may be masked via Apple Sign-In), Name, User ID (UUID), Authentication Token.To manage your user account, secure your progress, and facilitate login.Onboarding & PersonalizationSpanish level, Native language, Age range, Gender, Learning methods, Primary goal, Practice frequency, Anxiety level, Improvement areas, Interests, Engagement goal.To create a personalized Spanish learning curriculum and tailor AI responses.Learning & Progression DataGems, Keys, Streak, User Level, XP, Trophies, Completed Lessons/Quests, Conversation time.To track and display your progress, provide gamification rewards, and keep you motivated.Audio DataVoice recordings (temporary).To transcribe your speech (via OpenAI Whisper) for pronunciation evaluation and to generate the AI chat response. Recordings are temporary and deleted immediately after transcription.Conversation DataChat messages, Voice transcriptions, AI-generated responses.To maintain context during conversations and evaluate your learning.Subscription Data (Future IAPs)Apple/Google Purchase Receipt, Transaction ID, Expiration Date.To verify and manage your premium subscription status. We never receive your payment card information. 2.2. Technical and Usage DataDevice & Usage: Push notification token, Notification preferences, App language, Timezone, Last open date, Last lesson date. • Local Storage: Progression and Onboarding data is stored locally (AsyncStorage) on your device if you do not create an account. 2.3. Permissions Requested (Note on Camera/Photos) We may request the following permissions on your device: • Microphone: REQUIRED to use the core AI chat functionality (voice recording and transcription). • Notifications: OPTIONAL for daily practice reminders. • Camera/Photo Library: NOT CURRENTLY USED. This permission is requested in preparation for future interactive features but is not actively used. You may deny this permission without impacting current functionality. 3. How We Use Your Information We use the collected data for the following legitimate purposes: • Service Provision: To deliver the core functionalities of the App, including personalizing your learning path, tracking your progression, and facilitating interactive AI conversations. • Service Improvement: To analyze aggregated and anonymized data (e.g., lesson completion rates) to debug, improve the App's performance, and enhance the user experience. • Communication: To send essential service notifications, respond to your support requests, and send push notification reminders (if enabled). • Legal Compliance: To comply with applicable laws, respond to legal requests, and protect our rights and the safety of our users. 4. Sharing and Disclosure of Your Information (Third-Party Services) We rely on carefully selected third-party services to operate the App. Data is shared only as necessary to provide their specific service.Third-Party ServiceData SharedPurposePrivacy PolicyData LocationSupabaseAuthentication, User Profile, Progression Data, Subscription Data.Database hosting and secure user authentication.https://supabase.com/privacyEU/USOpenAI (Whisper/GPT)Temporary Audio Recordings, Conversation Messages, User Context (e.g., Spanish level).Whisper: Transcribes your voice. GPT: Generates AI Spanish responses.https://openai.com/policies/privacy-policyUSElevenLabsAI-generated text responses in Spanish.Text-to-Speech (TTS) to provide Sofia’s voice responses.https://elevenlabs.io/privacyUS/EUApple/GoogleEmail (if shared), Name (if shared), IAP Receipt.Authentication (Sign-In) and managing in-app purchases.Apple: https://www.apple.com/privacy/ Google: https://policies.google.com/privacyUSExpoPush Notification Tokens, Anonymous Crash Logs.Infrastructure for development and delivery of notifications.https://expo.dev/privacyUS Note on Audio Data: Your voice recordings are sent to OpenAI Whisper temporarily for transcription and are deleted immediately after the transcription is complete. We do not use audio data for any purpose other than facilitating the real-time AI conversation. 5. Data Security and RetentionSecurity Measures: We use industry-standard security practices, including HTTPS/TLS encryption for data in transit, encryption at rest in our database, and Row Level Security (RLS) to ensure users can only access their own data. API keys for third-party services are stored securely on the server side. • Retention: We retain your personal data for as long as your account is active or as needed to provide you with the App's services. • Account Deletion: If you delete your account (via Settings > Account > Delete My Account), all associated personal data will be immediately and irreversibly deleted from our primary servers (Supabase). Exception: We may retain aggregated, anonymized data for analytical purposes and certain legal/billing records where required by law. 6. Your Data Protection Rights (GDPR & CCPA) Depending on your location, you have the right to:

  1. Right of Access: Request a copy of the personal data we hold about you.
  2. Right to Rectification: Request correction of any inaccurate or incomplete data.
  3. Right to Erasure ("Right to be Forgotten"): Request the deletion of your personal data. This can be done directly via the App's Settings > Delete My Account.
  4. Right to Data Portability: Request that your data be transferred to you or a third party in a structured, commonly used, and machine-readable format.
  5. Right to Object/Restrict Processing: Object to or restrict how we process your personal data in certain circumstances. To exercise any of these rights, please contact us at privacy@blisscoach.com. We will respond to your request within the legally required timeframe. 7. Children's Privacy (COPPA) The App is classified as 4+ for the App Store, but the Terms of Service require users to be at least 13 years of age to create an account and fully utilize the interactive features. We do not knowingly collect personally identifiable information from children under 13. If we become aware that we have collected personal data from a child under 13, we will take steps to delete that information as quickly as possible. 8. Changes to This Privacy Policy We may update our Privacy Policy from time to time. We will notify you of any material changes by posting the new policy in the App and on our website, and updating the "Last Updated" date at the top of this policy. You are advised to review this Privacy Policy periodically for any changes.