Privacy at a glance
Tooter uses personal data to deliver personalized, AI-assisted language practice.
This policy identifies what we collect, where it comes from, why we use it, which companies receive it, how long we keep it, and the choices available to you. “Tooter,” “we,” and “us” mean Viral Patterns LLC.
Starting a speaking, avatar, translation, or feedback feature sends the data described below to the named providers needed for that feature.
You can choose not to start an AI feature, deny microphone access, end a session, disable notifications, or request deletion.
We require providers receiving personal data to protect it consistently with this policy, our instructions, and applicable law, including the same or equivalent level of protection required of Tooter.
Device microphone permission controls access to the microphone. The in-product explanation shown before an AI feature should separately identify the recipients, data, and purpose. Starting an AI feature initiates the transfers described in “AI and speech processing.”
Who controls your data and what this covers
Viral Patterns LLC, at 701 Tillery Street #12, Austin TX 78702, United States, is the controller of personal data covered by this policy, unless a notice for a specific feature says otherwise. This policy covers Tooter’s iOS app, tooter.live website, browser-based practice, account and subscription services, notifications, support, and related backend systems. It does not govern a third party’s own service when you interact with that party independently.
Third-party providers generally act as our service providers or processors for the purposes listed here, although they may act as separate controllers for account, fraud, legal, or service-improvement activities described in their own policies and terms.
Complete inventory
Data we collect
The categories below apply only when relevant to the features you use. We do not collect your contacts, precise GPS location, health data, or photo library through the audited Tooter experience. A sign-in provider may supply a profile photo URL if you chose one in that provider account.
| Category | What it includes | How we receive it | Why we use it |
|---|---|---|---|
| Account and sign-in | Firebase user ID; Apple or Google sign-in identifier and token; name, email address, profile photo URL, sign-in provider, and account timestamps. | You, Apple or Google Sign-In, and Firebase Authentication. | Authenticate you, secure your account, initialize your profile, and provide support. |
| Learning profile and preferences | Age range, gender, native and target languages, level and CEFR estimates, goals, selected skills, interests, learning style, pace, confidence, speaking challenges, role-play choices, tutor and voice preferences, correction intensity, pronunciation goals, session settings, reminders, and onboarding answers. | Information you enter or select during onboarding, settings, lessons, and practice. | Personalize lessons, tutors, difficulty, feedback, reminders, and AI session context. |
| Voice, conversations, and AI content | Microphone audio; speech transcripts; messages; prompts; tutor responses; translated captions; lesson or scenario context; and any personal information you choose to say or type. | Your microphone, live-session interactions, and text you submit. | Transcribe speech, conduct live conversations, synthesize tutor speech, translate content, and generate lesson responses and feedback. |
| Learning activity and progress | Session identifiers, tutor and scene, duration, topics, word counts, vocabulary, corrections, grammar and pronunciation observations, scores, summaries, reports, streaks, mastery, recurring errors, recent topics, completed lessons, and generated recommendations. | Your use of Tooter and results generated during a lesson or session. | Save history, show progress, resume learning, and tailor future practice. |
| Purchases and subscription | Product and plan, offer, trial, purchase and expiry dates, transaction or receipt identifiers, entitlement, renewal, cancellation, refund, billing-status information, and account or installation aliases used to restore access. | Apple App Store, RevenueCat, Superwall, and web checkout services. | Complete purchases, provide paid access, restore entitlements, prevent incorrect receipt transfers, and maintain billing records. We do not receive your full App Store payment-card number. |
| Usage, analytics, and screen interactions | Installation and account identifiers, screens and features used, taps and interaction paths, onboarding and paywall answers, experiments, attribution data, app version, operating system, device type, locale, and session-replay images of the visible app interface on supported devices. | Tooter and analytics SDKs when the app or website is used. | Understand conversion and feature use, diagnose broken flows, measure product quality, and improve the service. Session replay does not intentionally capture microphone audio, but visible text or images may appear in a replay. |
| Device, network, and diagnostics | IP address and approximate region inferred from it, user agent, app build and distribution, device and OS details, request path and status, crash reports, stack traces, hangs, performance metrics, logs, timestamps, security events, and push-notification token. | Your device, browser, servers, Sentry, Firebase, and security logs. | Operate and secure Tooter, deliver notifications, investigate failures, prevent abuse, and meet legal obligations. |
| Support and privacy requests | Email address, message contents, attachments, request history, and identity-verification information when reasonably necessary. | Information you send to us. | Respond to you, troubleshoot, and complete account, access, deletion, or other rights requests. |
Please do not say or type information you do not want processed in an AI session, including passwords, payment-card numbers, government identifiers, private information about another person, or confidential medical, legal, employment, or financial information. Voice data is used to understand speech and provide feedback, not to identify you by a voiceprint.
Third-party AI disclosure
AI and speech processing
Tooter cannot provide live AI speaking, transcription, synthesized tutor voice, translation, pronunciation analysis, or interactive avatar features without sending feature data to the providers below. Not every provider is used in every session.
Tooter may send microphone audio, transcripts, selected languages, learning level, goals and preferences, lesson context, recent progress and corrections, and technical session identifiers to Google services. Live avatar sessions additionally use LiveKit for media transport, Lemon Slice for avatar rendering and personalized avatar instructions, and ElevenLabs for tutor speech synthesis.
If you do not want these transfers, do not start the AI speaking, avatar, translation, or pronunciation feature. You can end an active transfer by ending the session and disabling microphone access. Declining an AI feature does not itself delete information from earlier sessions; see “Your choices and rights.”
Google LLC
- Data sent
- Depending on the feature: raw microphone audio (including audio sent directly from your device), WAV/PCM audio used for pronunciation analysis, transcripts and typed text, native and target languages, first name, lesson/topic/scenario, tutor prompts, CEFR and level, goals, interests, preferences, recent vocabulary, progress, errors, corrections, and technical session identifiers.
- Why
- Recognize and transcribe speech; generate real-time tutor text and audio; translate captions; analyze pronunciation, grammar, vocabulary, and progress; and personalize responses.
- When
- Sent only when you start or use a feature that needs live AI conversation, transcription, translation, pronunciation analysis, or generated feedback.
LiveKit, Inc.
- Data sent
- Live learner microphone media, generated tutor or avatar audio and video, user/room/session identifiers, access tokens, and connection or delivery metadata.
- Why
- Provide the encrypted real-time WebRTC room that transports media during live tutor and avatar sessions.
- When
- Sent while you connect to and participate in a live session.
Infinity AI, Inc. dba Lemon Slice
- Data sent
- Avatar identity or image, LiveKit room credentials and session identifiers, generated tutor audio, lesson/avatar instructions, and personalized visual-behavior context. Depending on the session, that context can include first name, languages, age range, gender, goals, level, confidence, interests, learning style, role-play choices, progress, and tutor preferences. Tooter does not currently direct Lemon Slice to use learner microphone audio as its avatar audio input.
- Why
- Animate and render the selected AI tutor avatar in a live session.
- When
- Sent when an interactive avatar session is created and while its generated tutor media is rendered.
ElevenLabs, Inc.
- Data sent
- Generated tutor or lesson text, selected voice identifier, language, model, and voice settings. Generated text may include personalized conversation context.
- Why
- Convert tutor or lesson text into spoken audio.
- When
- Sent when a Tooter feature requests synthesized tutor speech.
Other service providers
We also disclose data to the following providers to operate accounts, infrastructure, analytics, diagnostics, payments, and paywalls. We do not list offline development tools that do not receive learner data through the production service.
Google Cloud and Firebase
Privacy notice- Data
- Account/profile data, authentication state, learning settings and progress, transcripts and session records, generated assets, device tokens, usage events, and server/network metadata.
- Purpose
- Authentication, databases, storage, hosting, cloud processing, analytics, and push-message delivery.
Apple
Privacy notice- Data
- Apple sign-in name/email and identity token; for App Store purchases, product, receipt, transaction, and subscription state.
- Purpose
- Apple account sign-in, identity verification, App Store payment processing, and subscription management.
Mixpanel
Privacy notice- Data
- Stable installation/account identifiers, onboarding answers and preferences, product and paywall events, device/app metadata, attribution, screen interactions, and session-replay images of visible app screens on supported devices.
- Purpose
- Product analytics, funnel measurement, experimentation, and investigation of user-experience failures.
Sentry
Privacy notice- Data
- Crash, hang, failed-request, performance, device, network, IP, user/account context, logs, and error details. Sentry screen replay is disabled in Tooter.
- Purpose
- Error monitoring, reliability, security investigation, and debugging.
RevenueCat
Privacy notice- Data
- Account/install identifiers, email for web checkout, plan, product, transaction/receipt, trial, entitlement, attribution, and subscription lifecycle data. Web checkout may also receive selected onboarding and learning-profile metadata used for the checkout journey.
- Purpose
- Subscription checkout, entitlement verification, purchase restoration, and subscription analytics.
Superwall
Privacy notice- Data
- Account/install/RevenueCat identifiers, paywall placement and interactions, experiment assignment, product, offering, entitlement, and purchase status.
- Purpose
- Present and measure paywalls and purchase flows.
Meta and advertising measurement services (when enabled)
Privacy notice- Data
- Conversion event, funnel/session identifier, source URL, referrer, UTM and ad-click identifiers, Meta cookies such as _fbp/_fbc, IP address, and user agent. Google ad-click identifiers may also be retained for attribution.
- Purpose
- Attribute visits or conversions and measure advertising performance, where configured and legally permitted.
Push notifications may display learning milestones—such as a streak, vocabulary count, mastery update, or resolved mistake—on your lock screen, depending on device preview settings. You can turn off categories in Tooter settings and manage notification previews in iOS Settings.
How we use data and our legal bases
Account access, lessons, live sessions, AI responses, personalization, progress, checkout, entitlements, and requested support. We rely on performance of our contract or steps you request.
Where required, we rely on your affirmative choice for AI data sharing, microphone access, notifications, analytics/advertising technologies, and other optional processing. Consent can be withdrawn for future processing.
Security, fraud prevention, service reliability, debugging, aggregated product analysis, entitlement integrity, and improving user experience—balanced against your rights.
Tax, accounting, consumer protection, lawful requests, dispute handling, recordkeeping, and enforcing or defending legal rights.
AI systems use automated processing to generate tutor responses, translations, scores, recommendations, and personalized lessons. These outputs support language learning; they are not used by Tooter to make legal or similarly significant decisions about you. AI output may be inaccurate, so do not rely on it as professional advice.
Retention and deletion
We keep personal data only while reasonably necessary for the purposes above, taking account of whether your account is active, whether you need history or restoration, the sensitivity of the data, security and abuse-prevention needs, provider settings, and legal requirements. The current systems do not apply one universal deletion deadline to every category.
Tooter transiently buffers raw learner audio during an active turn and does not intentionally store raw live recordings as part of ordinary session history. Audio is transmitted to the providers needed for the feature, which may retain it or related safety metadata under their terms and configured service settings.
Persistent account, settings, transcript, correction, vocabulary, session, and progress records are generally kept while the account is active so history and personalization work, unless you delete the account or request earlier deletion where available.
Learner-state cache entries normally expire after about 15 minutes and active-session cache entries after about one hour. Other coordination or security records can last longer when needed to complete or protect a session.
Usage events, replay data, diagnostics, and security logs follow our configured provider retention and operational schedules, after which they are deleted or aggregated, subject to security, dispute, and legal needs.
Product, transaction, receipt, entitlement, and account-alias records may remain after account deletion to restore purchases, maintain entitlement integrity, prevent duplicate or unauthorized transfers, and satisfy accounting, fraud-prevention, dispute, tax, or legal obligations. These can include hashed aliases and historical internal user-ID linkage.
Website local storage persists until cleared, signed out, or removed by browser policy. Deleted data may remain briefly in protected backups until overwritten in the ordinary backup cycle, and providers may retain required records under their own policies.
In-app account deletion removes the current Firebase Authentication account and the user-owned profile, settings, progress, and session trees from Tooter’s primary systems. It does not cancel an App Store subscription and may not automatically erase every provider record. Contact us if you want us to coordinate a broader provider deletion request where legally available.
Your choices and privacy rights
Do not start an AI feature if you do not want its described data transfers. End the session to stop future live transmission. Revoke microphone access in iOS Settings or browser site permissions.
Update profile and learning preferences in Settings. The iOS app can export a learning-progress report; contact us for a broader access or portability request.
Use Settings → Account → Delete Account in the iOS app, or email us. Deleting the app alone does not delete the account. Cancel paid subscriptions separately through the original purchase channel.
Manage notification categories in Tooter and device settings. Clear browser site data to remove local website storage. Contact us to object to or opt out of eligible analytics or advertising processing.
Depending on where you live, you may have rights to know, access, correct, delete, restrict, object, withdraw consent, opt out of sale/sharing or targeted advertising, and receive a portable copy of personal data. You may also appeal a denied request and complain to your local data-protection authority. We will not discriminate against you for exercising a privacy right.
Submit a request to contact@viralpatterns.app. Tell us the right you want to exercise and the account email, if any. We may verify your identity and authority before acting. An authorized agent may submit a request where law permits. We will respond within the period required by applicable law.
International transfers
Viral Patterns LLC is based in the United States, and Tooter and its providers may process data in the United States and other countries where they operate. Those countries may have different privacy laws. Where required, we use recognized transfer mechanisms and contractual protections, such as standard contractual clauses or an applicable data-privacy framework, together with appropriate technical and organizational measures.
Security
We use reasonable technical and organizational safeguards designed to protect personal data, including HTTPS/WSS encryption in transit, authenticated access, role-based cloud permissions, secret-management controls, monitoring, and restricted operational access. No network, storage system, or AI service is completely secure, so we cannot guarantee absolute security. Protect your sign-in account and contact us promptly if you believe your Tooter account or data has been compromised.
Age eligibility
Tooter’s AI speaking and avatar features are intended for adults. Do not use those features if you are under 18. The broader service is not intended for children under 13, and a person below the minimum digital-consent age where they live must not create an account without a legally valid parent or guardian process. If you believe a child has provided personal data contrary to these limits, contact us so we can investigate and delete it as required.
Changes to this policy
We may update this policy when our features, providers, practices, or laws change. We will post the revised version here and update the effective date. If a change materially expands how previously collected personal data is used, we will provide additional notice and request consent when required before applying the new use.
Questions or requests
Contact us
Email contact@viralpatterns.app for privacy questions, access, correction, deletion, consent withdrawal, advertising opt-out, or complaints.
Viral Patterns LLC701 Tillery Street #12, Austin TX 78702, United States