InMyTongue
Legal

Privacy Policy

Last updated: 25 July 2026 · Governing version: English

This policy explains, in plain language, what personal data InMyTongue collects, why we use it, how long we keep it, who else processes it, and the rights you have. We built the product to move data as little as possible — and this page tells you exactly how.

The short version

  • We collect only what we need to run your account, bill you, and deliver live translation.
  • We never sell your personal data, and we don't share it for others' advertising.
  • Live audio is translated in real time and processed transiently; a transcript is stored only if the owner turns on saving.
  • Advertising and analytics cookies are off until you agree — you choose in the cookie banner.
  • You're in control: delete any saved sermon — or your whole account — yourself, right from your dashboard, at any time.

1. Who we are

InMyTongue provides live AI translation and subtitling for churches, conferences, schools and events, at inmytongue.com. In this policy, "InMyTongue", "we" and "us" mean the operator of the service. We handle personal data in line with the General Data Protection Regulation (GDPR) and the data-protection law of the Republic of Cyprus.

For data we collect about account owners and website visitors, InMyTongue is the data controller. You can reach us about any privacy matter at support@inmytongue.com (please write "Privacy" in the subject) — this is the point of contact for exercising your rights.

We'd rather earn your trust with plain answers than hide anything in fine print. Everything on this page is written to be honest and easy to act on — if a point isn't clear, just ask and a real person will reply.

2. Controller vs. processor

We wear two hats:

  • As controller — for the data of account owners and operators, our billing records, and visitors to our public website.
  • As processor — when a customer (for example, a church or a conference organiser) uses InMyTongue to collect data about their attendees or members — such as attendee sign-ups, quiz scores or reward points — that customer is the controller and decides what is collected. We process it on their behalf and under their instructions, and offer them a Data Processing Agreement on request.

3. What we collect

CategoryExamples
Account & organisationName, email, hashed password, organisation name/type, country, and any phone or profile details you add.
BillingPlan, invoices, balance, tax country, and a payment-method token. Full card numbers are entered on and held by our payment processor — we don't store them.
Service usageBroadcasts, sessions, chosen languages, hours used (for metering), halls and QR codes.
Attendee / member dataWhere a customer enables memberships: attendee email, hashed password, quiz results and reward points — collected on that customer's behalf.
Speech & transcriptsLive audio is transcribed and translated in real time. A transcript is stored only if the session owner turns on saving (see §5).
Technical & visit dataIP address, approximate location/country, browser and device type, referring page, and visit logs (kept about 12 months).
CommunicationsSupport tickets, contact-form and chat messages, and emails you send us.
CookiesEssential cookies to keep you signed in, plus optional analytics/advertising cookies (only with your consent — see §7).

4. How & why we use it — and our legal basis

WhyLegal basis (GDPR)
Create your account and deliver the translation servicePerformance of a contract
Billing, invoices, and keeping tax/accounting recordsContract & legal obligation
Keeping the service secure and preventing fraud or abuseLegitimate interests
Understanding how our website is used, and advertisingConsent (via the cookie banner)
Improving and supporting the productLegitimate interests
Sending you product or marketing emailsConsent (you can unsubscribe any time)

Where we rely on legitimate interests, we've weighed them against your rights and only proceed where they don't override them. You can object at any time (see §11).

5. Audio, transcripts & translation

When a broadcast is live, the speaker's audio is sent to specialised third-party speech-to-text and machine-translation providers, which return text in the languages attendees have chosen. This audio is processed transiently to produce the translation and is not kept by us as a stored recording.

A written transcript is saved only when the session owner switches on "save this sermon/session". The owner also chooses whether a saved session is public or members-only. The owner can permanently delete any saved sermon at any time from their dashboard — this erases its saved text, translations and any video reference for good (only anonymous usage/billing history remains). If you're an attendee and want a saved session removed, contact the organisation that ran it, or us.

6. Sensitive (special-category) data

Some content — for example the subject of a sermon, or the fact that someone belongs to a particular congregation — can reveal religious beliefs, which the GDPR treats as a special category (Article 9). We only process such content to provide the service you have configured, we minimise it, and we rely on the information being provided by you and your attendees for that purpose. We do not use it for profiling or advertising.

7. Cookies & similar technologies

TypeWhat it doesConsent?
EssentialKeeps you signed in, remembers your language, and protects forms.Not required (the site can't work without it)
Analytics & advertisingHelps us measure our website and marketing.Yes — off until you agree

When you first visit, non-essential cookies are disabled by default. Nothing analytics- or advertising-related runs until you choose "Accept" in the cookie banner, and you can change your mind any time via Cookie settings (also linked in the footer).

8. Who we share it with

We do not sell your personal data. We share it only with service providers ("sub-processors") who help us run InMyTongue, each under a contract that limits them to our instructions:

  • Payment processing
  • Email delivery
  • Cloud hosting
  • Content delivery, DNS & bot/abuse protection
  • AI speech-to-text and machine translation
  • Website analytics and advertising (only with your consent)

A current list of the specific providers is available on request at support@inmytongue.com. We may also disclose data where the law requires it, or to protect our rights and users' safety.

9. International transfers

Some of our providers are located outside the European Economic Area (for example in the United States). Where personal data is transferred there, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, so your data keeps an equivalent level of protection.

10. How long we keep it

  • Account data — for as long as your account is active. You can delete your whole account yourself at any time (see "Your rights" below); when you do, your organisation and its data are erased immediately, except records we are legally required to keep.
  • Invoices & tax records — retained for the period required by accounting/tax law, even after account deletion.
  • Visit & technical logs — about 12 months.
  • Saved transcripts — kept while the owner keeps them; removed the moment the owner deletes the sermon or the account.
  • Backups — rotate on a short cycle and are then overwritten, so deleted data also disappears from backups within that cycle.

11. Your rights

Under the GDPR you have the right to: access your data, correct it, delete it, restrict or object to processing, receive a portable copy, and withdraw consent at any time (withdrawing doesn't affect what happened before). You can also complain to your data protection authority.

You can act on most of these yourself, instantly, from your dashboard — change your email, edit your profile, delete any saved sermon, and delete your entire account. Account deletion is deliberately a two-step, confirmed action: you type your organisation's name to confirm, then enter a one-time code we email to you, so nobody can erase your account by accident or without access to your inbox. Once confirmed, your organisation and all its data (halls, saved sermons, members, website and settings) are permanently removed and cannot be recovered.

For anything you can't do yourself, email support@inmytongue.com and we'll respond within one month. You can also complain to your data protection authority.

12. How we protect it

We encrypt data in transit with HTTPS, store passwords only as salted hashes (never in plain text), restrict internal access, and host on reputable infrastructure. No system is ever perfectly secure, but we take security seriously and will notify you and the relevant authority of a breach where the law requires.

13. Children

InMyTongue is intended for organisations and adults. It is not directed to children under 16, and attendee accounts should only be created by someone of the appropriate age or with a guardian's consent. If you believe a child has given us data, contact us and we'll remove it.

14. Changes to this policy

We may update this policy as the product or the law evolves. When we do, we'll change the "last updated" date above and, for significant changes, tell you directly. The English version on this page is the governing one.

15. Contact us

Questions, requests or concerns about privacy? Email support@inmytongue.com — we're glad to help.

A note on this document. We've written this to be complete and honest about how we actually handle data. It is not legal advice; if you operate under specific local rules, your own counsel should confirm it fits your situation.