1. Who We Are
Confident in Mexico (“we”, “us”, “our”) is a Spanish confidence trainer for English-speaking travelers. We operate the website at confidentinmexicoapp.com. You can reach us at support@confidentinmexicoapp.com.
2. What Data We Collect
We collect only what is necessary to provide the service:
- Email address — collected at signup, used to authenticate your account and send password reset emails.
- Password — stored as a one-way bcrypt hash. We never store or see your plaintext password.
- Payment information — processed entirely by Stripe. We never receive or store your card number, CVV, or billing address. We only receive a confirmation that payment was completed.
- Speech audio— audio you record during practice sessions is sent to OpenAI’s Whisper API for transcription and then immediately discarded. We do not store any recordings.
- Usage data — anonymous analytics (pages visited, features used) collected via PostHog to help us improve the product. No personally identifiable information is included in analytics events.
- Session cookie — an HTTP-only, secure cookie is set on login to keep you signed in. It contains no personal data beyond a session identifier.
3. How We Use Your Data
- To create and authenticate your account.
- To grant access to paid content after a successful purchase.
- To send password reset emails when requested.
- To transcribe your spoken Spanish for practice feedback.
- To understand how the product is being used so we can improve it.
We do not sell, rent, or share your personal data with third parties for marketing purposes.
4. Third-Party Services
We use the following third-party services, each governed by their own privacy policies:
- Stripe — payment processing. stripe.com/privacy
- OpenAI — speech-to-text transcription of practice audio. openai.com/policies/privacy-policy
- PostHog — anonymous product analytics. posthog.com/privacy
- Resend — transactional email delivery (password reset). resend.com/legal/privacy-policy
- Amazon Web Services (AWS) — backend hosting and database infrastructure. aws.amazon.com/privacy
- Vercel — frontend hosting. vercel.com/legal/privacy-policy
5. Data Retention
We retain your account data (email and payment status) for as long as your account exists. Speech audio is never retained — it is discarded immediately after transcription. You may request deletion of your account and all associated data at any time by emailing support@confidentinmexicoapp.com.
6. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you.
- Correction — request correction of inaccurate data.
- Deletion — request deletion of your account and personal data.
- Portability — request your data in a portable format.
- Opt-out of analytics — you can disable analytics by using a browser with tracking protection or by contacting us.
To exercise any of these rights, email support@confidentinmexicoapp.com. We will respond within 30 days.
7. Cookies
We use a single, essential session cookie to keep you logged in. This cookie is HTTP-only (inaccessible to JavaScript), marked Secure (HTTPS only), and expires when your session ends or after 30 minutes of inactivity. We do not use advertising or tracking cookies.
8. Children’s Privacy
This service is intended for adults. We do not knowingly collect personal information from anyone under the age of 13. If you believe a child has provided us with personal data, please contact us and we will delete it.
9. Changes to This Policy
We may update this policy from time to time. When we do, we will update the “Last updated” date at the top of this page. Continued use of the service after changes constitutes acceptance of the revised policy.
10. Contact
For any privacy-related questions or requests, contact us at support@confidentinmexicoapp.com.