Privacy Policy

What Gloop keeps, for how long, what for, and what your rights are.

Version 2026-09-18

This Policy explains how Gloop handles your personal data, in accordance with the Brazilian General Data Protection Law (LGPD, Law 13.709/2018). By using Gloop, you agree to the practices described here.

1. Who handles your data

The controller of the personal data processed on the platform is Raven Soluções Digitais LTDA, registered under Brazilian company number (CNPJ) 65.808.728/0001-90, with address at Avenida Fermino Maltarollo, 455, Parque Gabriel, Hortolândia/SP, CEP 13186-598.

Contact for the Data Protection Officer: legal@gloop.br.com.

2. Data we collect

  • Account: display name, email, phone number and password (stored in a way that no one can see it, not even us). The phone number is used to verify your account by code and to protect against mass account creation.
  • Voice and transcripts: the audio of your speech and its transcript during sessions. Voice data may be considered sensitive; we process it only to provide the service and generate your feedback.
  • Usage and progress: learning profile, identified gaps, session history and performance.
  • CV (optional): if you import your CV to generate mock interviews, we process the submitted text only for that purpose. The CV is included in the export and in the deletion of your data.
  • Purchases: subscriptions are sold by the app stores (App Store and Google Play). We neither receive nor keep your card details: from the store we receive the purchase identifier, the plan and the subscription status, to unlock paid access on your account.
  • What other people see: in the quiz with friends, the recording you make is heard by whoever is playing with you, and your display name and your score appear to your friends on the podium. Do not put anything there that you would not want them to see.
  • Reports and blocks: if you report something, we keep the report (the reason, what you saw and when) for the review; if someone reports one of your recordings, it is hidden and kept until the decision, and a reported name is only hidden if the report is upheld. If you block someone, we keep the block until you undo it. A report is deleted along with the reported account, and if the person who reported deletes their account, their name is removed from the report.
  • Device check: when you create an account and when you start a session, the app asks Apple or Google to attest that it is running on a genuine device and a genuine app. A technical device identifier goes with that request, and the answer is used only to block automation and fraud.
  • Contacts (optional, only in the quiz with friends): if you choose to find friends from your address book, the app opens your device’s contact picker and the phone numbers you select are turned into a scrambled code on the device itself. Only that code leaves the device; we receive no name and no number from your address book, and we do not keep the list. Inviting by link works without accessing any contact.
  • Device and notifications: if you allow notifications, we store the delivery token and a device identifier, so the notice reaches the right device and is not duplicated. You can turn this off in Settings, and the device record is deleted when you sign out.
  • Technical: IP address, access logs and your time zone (to schedule reminders at your local time), for security and as proof of consent. We use one essential authentication cookie (to keep your session); we do not use advertising or third-party tracking cookies.
  • Usage metrics: internal product events (for example, sign-up completed, session evaluated) to operate and improve the service; they are neither sold nor shared for advertising.

3. Why we use it and on what legal basis

We process your data to: create and maintain your account; deliver the sessions and generate feedback; recognise the subscription you bought in the store; send service communications; and comply with legal obligations. The legal bases are performance of the contract (providing the service), your consent (including for processing voice data) and compliance with legal obligations.

4. Sharing and processors

To work, Gloop uses providers that act as processors, handling data under our instructions:

  • speech recognition: Deepgram, which receives the audio of your speech as you speak;
  • pronunciation assessment and speech synthesis: Microsoft Azure Speech, which receives the audio and the transcript;
  • language models that generate the feedback: Anthropic, which receives the transcripts, the submitted text and, where present, the CV;
  • application hosting, database and storage of session audio: Fly.io;
  • subscription sales and device attestation: Apple and Google, through the app stores;
  • transactional email delivery: Resend;
  • phone verification by code, when requested: Twilio;
  • notifications: Google Firebase;
  • optional social sign-in (Google and Apple): when you choose to sign in through those platforms, we receive your email and name from them; we do not receive your password.

Every processor we share data with is engaged under an obligation to protect that data at a level equal to or higher than the one described in this Policy, handling it only under our instructions and only for the contracted purpose. None of them is authorised to use your data for their own purposes or to pass it on.

Some processors may handle data outside Brazil. In those cases, we adopt safeguards for the international transfer as required by the LGPD. We do not sell your personal data. The list above is kept current: if a provider changes, this Policy changes with it.

5. Retention

We keep your data for as long as your account exists and for as long as needed for the purposes above or for legal obligations. Session audio has a shorter retention, depending on the plan: 7 days on Free, 45 days on Standard and 90 days on Pro; after that it is deleted automatically. Transcripts and progress metrics remain while the account exists. When you request account deletion, it takes effect after 7 days (a window to change your mind) and we then erase your data, including audio and the link between the account and the purchase made in the store, except for what the law requires us to keep (such as tax records).

6. Your rights

You can access, correct, export and delete your data. In the app itself, under Settings, you can export your data and request account deletion. The steps for deletion, including for people who cannot sign in, are in Delete your account.

How to withdraw consent: processing your voice is the basis of the service, so withdrawing that consent means closing the account, through the path above. Access to contacts and the sending of notifications are optional and can be turned off at any time, in the device permissions and in Settings, without affecting the rest.

For other requests, write to legal@gloop.br.com.

7. Security

We protect your data with technical and organisational measures. The connection between the app and our servers is protected, your password is stored in a way that no one can read it, not even us, and only the people who need the data to run the service can access it. We do not describe the specific techniques here, because describing them would help anyone trying to get around them. No system is perfectly secure, but we work to reduce risk.

8. Minors

Brazilian law separates a child (under 12) from an adolescent (12 to 18). Gloop is for people aged 13 and over and is not directed at children: for them the LGPD requires specific, prominent consent from a parent, which we do not collect and cannot verify. If we learn that an account belongs to someone under 13, it is deleted and the data erased, and whoever is responsible for the minor can ask for this at any time through the contact in section 10.

Anyone between 13 and 18 declares, at sign-up, that they have permission from whoever is responsible for them, and that declaration is recorded with the date and the version of the documents accepted. We do not ask for a date of birth: the declaration is what we have. The subscription is bought in the store, so the store account belongs to someone old enough to enter into a contract. Processing adolescents' data observes their best interest, as required by the LGPD.

9. Changes to this Policy

We may update this Policy. Material changes will be communicated and, where required, we will ask for consent again.

10. Contact

Questions about privacy and data-subject requests: legal@gloop.br.com. See also the Terms of Use.