1. Introduction
Welcome to ConvoSparr ("we," "our," or "us"). ConvoSparr is a product of Tarsonix Technologies (OPC) Private Limited, a company incorporated in India.
Who controls your data depends on how you got here. If you signed up yourself, we are the data controller responsible for your personal information. If your employer bought ConvoSparr for a team and invited you, your organization is the controller of your practice data and we act as its processor. Section 12 covers what that means for you in practice. This Privacy Policy explains how we collect, use, share, and safeguard your information when you visit our website and use our AI-powered voice conversation practice platform (the "Service").
We have tried to write this policy in plain language and to describe what actually happens to your data, including the third-party services that process it. Please read it carefully. By using the Service, you agree to the practices described here. If you do not agree, please discontinue use of the Service.
2. Information We Collect
If you are on a team account
We hold the organization you belong to, your role in it, and the group you are assigned to. Every practice session you run carries your organization's identifier, which is what lets your team see it. Section 12 explains who can see what.
If you try the demo without an account
The demo call on our home page needs no sign-up. When you use it we process the session audio, the transcript produced from it, and the score. If you ask to see the full breakdown we also store the email address you give us. We keep a hashed form of your IP address and a signed identifier in a cookie, to stop one visitor consuming the demo repeatedly. An unclaimed demo is deleted after 30 days; if you create an account and claim it, it moves to your account.
Account & Profile Information
When you create an account or complete onboarding, we collect:
- Full name, username, and email address
- Password (stored only as a secure hash by our authentication provider, never in plaintext)
- If you sign in with Google: your name, email address, and profile picture as provided by Google
- Profile details you provide during onboarding: date of birth, gender, country, and phone number
- Your timezone (auto-detected from your browser to power local-day streaks), which you can change
Practice Session & Usage Data
When you use the practice features, we collect and store:
- Scenario, persona, call type, domain, and difficulty selected for each session
- Session start and end times, and total session duration in seconds
- Practice credits consumed per session and your remaining balance
- Briefing content you enter to set up a session, such as the product or service you are pitching, target audience, selling points, your sales role, or salary and custom-scenario context
- AI-inferred role or counterpart derived from your briefing
- Performance scores and skill-level metrics (for example active listening, objection handling, rapport, anchoring, composure)
- AI-generated session summaries, highlights, and improvement suggestions
- Achievements earned, practice streaks, and cumulative score history
Voice & Transcript Data
When you conduct a voice practice session, your microphone audio is streamed in real time so it can be transcribed and processed by AI. We do not ourselves record or store your voice audio, and we do not keep an audio recording of your sessions on our systems. To make a live conversation possible, however, your audio is sent to the third-party speech providers described in Section 4, and your speech is converted to text. What we store on our systems is:
- Text transcripts of your practice conversations, including speaker labels (you vs. the AI persona) and timestamps
- AI-generated analysis derived from those transcripts: highlighted moments, performance metrics, and coaching suggestions
Please see Section 4 for important details about how our speech-to-text provider may retain and use the audio you send during a session.
Analytics & Session Activity
To understand how the Service is used and to improve it, we use product-analytics tools that collect information about how you interact with the app. This includes:
- Product events and usage metadata, such as pages and features used, sessions started and completed, and account or subscription actions, linked to your account identifier and email
- Session replays, which reconstruct your interactions with the app interface (clicks, navigation, and on-screen activity) so we can diagnose issues and improve usability. Text you type into form fields is masked in these replays. We do not capture your voice or microphone audio in analytics
See Section 7 for the analytics providers we use, the cookies and similar technologies involved, and how consent works.
Technical & Diagnostic Information
We automatically collect certain information when you use our platform:
- Browser type and version, device type, and operating system
- IP address and approximate, IP-derived location
- Pages visited and time spent
- Error reports and crash diagnostics (captured by Sentry, see Section 4)
3. How We Use Your Information
We use the information we collect to:
- Create and manage your account, and authenticate your identity
- Provide and operate the AI voice practice platform
- Calculate and track your practice credits and subscription entitlements
- Generate AI-powered performance analysis, scores, and coaching feedback after each session
- Track your progress metrics, practice streaks, and achievements over time
- Process payments and manage your subscription via Paddle
- Send transactional and account emails such as password resets, email confirmations, security notices, subscription receipts, and session summaries
- Monitor platform health, diagnose technical errors, and improve usability
- Detect and prevent fraud, abuse, or violations of our Terms
- Review session transcripts where needed. Authorized members of our team may read conversation transcripts to debug problems you report, check the quality and safety of the AI (for example whether the AI stayed in its correct role), and improve the Service. We limit this access to what is necessary for these purposes
- Comply with our legal obligations and enforce our agreements
We do not train our own AI models. The AI conversation and analysis are produced by third-party model providers accessed through the services described in Section 4. We do not sell your personal information.
4. How We Share Your Information
We do not sell your personal information. We share it only with the categories of parties below.
Service Providers & Sub-processors
The following third-party services process data on our behalf to operate the platform. Where a provider may use data for its own model improvement, we say so plainly.
- Supabase (United States): Database, authentication and secure file storage. Account and profile data, session records, transcripts, scores and analysis.
- Vercel (United States): Hosting and delivery of the web application, and automated bot detection on sign-up and call-start requests. Requests to the Service, including IP address and standard request metadata. Bot detection is Vercel BotID, a Vercel product, so it is covered by this entry rather than listed separately.
- Cloudflare (United States): Human-verification challenges on sign-in, sign-up, password reset and the no-signup demo. Challenge interaction data and IP address at the moment a challenge is solved.
- Railway (United States): Hosting for the real-time voice service. Live audio and conversation transcripts while a session is running.
- LiveKit (United States): Real-time audio transport for live voice sessions. Session audio in transit. Not persisted by LiveKit.
- Deepgram (United States): Real-time speech-to-text transcription. Your session audio. Under our current plan Deepgram may retain that audio and use it to improve its own speech-recognition models. Avoid speaking sensitive personal information during sessions.
- Cartesia (United States): Text-to-speech voice synthesis for the AI personas. Only the AI-generated text, so it can be spoken aloud. Never your speech. Under Cartesia's standard terms it may use the text we send and the audio it generates to improve its models.
- OpenRouter (United States): Gateway to the language models powering the live conversation and the post-session analysis. Session context and transcripts, routed to third-party model providers. Configured so providers do not train on your data. Providers may still briefly retain it as needed to process a request. The underlying models change over time.
- PostHog (United States): Product analytics and session replay. Product-usage events, an account identifier, and masked session replays of your use of the app. Gated by your cookie choice. Inputs are masked in replays.
- Sentry (United States): Error monitoring and crash diagnostics. Technical error context such as the page and the error stack. Configured to minimise personal data.
- Resend (United States): Email delivery. Your name and email address, to deliver account, security and transactional email.
- Paddle (United Kingdom): Payment processing and subscription management. Billing information, handled directly by Paddle as Merchant of Record. We never receive or store full payment card details.
- Google (United States): Optional sign-in with Google. If you use it, your name, email address and profile picture.
The canonical list, with each provider's legal entity and the data it sees, is on our Subprocessors page. It is generated from the same source as this list, so the two cannot drift apart.
Each provider processes data under its own terms and privacy policy. We encourage you to review the policies of any provider you are concerned about.
Legal Requirements
We may disclose your information if required to do so by law, court order, or a governmental or regulatory authority, or where we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
Business Transfers
In connection with a merger, acquisition, restructuring, or sale of assets, your data may be transferred to a successor entity. We will notify you before your data becomes subject to a materially different privacy policy.
5. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encrypted connections (TLS/HTTPS) for data transmitted between your browser and our servers
- Row-Level Security policies enforced at the database layer, so each user can access only their own data
- Passwords stored only as secure hashes by our authentication provider, never in plaintext
- API keys and service credentials stored as protected environment secrets
- Access to session transcripts limited to authorized team members for the purposes in Section 3
No method of transmission or storage is completely secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.
6. Your Rights
India (Digital Personal Data Protection Act)
If you are in India, you have the following rights under the Digital Personal Data Protection Act, 2023 (DPDP Act) in relation to your personal data:
- Right to access a summary of the personal data we process about you
- Right to correction and updating of inaccurate or incomplete data
- Right to erasure of your personal data
- Right to withdraw consent at any time, where processing is based on consent
- Right to grievance redressal through our Grievance Officer (see Section 14)
- Right to nominate another individual to exercise your rights in the event of death or incapacity
EU / EEA and UK Users (GDPR / UK GDPR)
If you are located in the European Union, European Economic Area, or the United Kingdom, you have the following rights under the GDPR and UK GDPR:
- Right of access to the personal data we hold about you
- Right to rectification of inaccurate or incomplete data
- Right to erasure ("right to be forgotten")
- Right to restriction of processing in certain circumstances
- Right to data portability in a structured, machine-readable format
- Right to object to processing for certain purposes
- Right to withdraw consent where processing is based on consent
- Right to lodge a complaint with your local supervisory authority
Where we rely on a lawful basis other than consent, it is typically the performance of our contract with you (to provide the Service) or our legitimate interests in operating, securing, and improving the Service, balanced against your rights.
California Users (CCPA / CPRA)
If you are a California resident, you have the right to know what personal information we collect and how it is used, the right to delete your personal information, the right to correct inaccurate information, the right to opt out of the "sale" or "sharing" of personal information, and the right to non-discrimination for exercising your rights. We do not sell your personal information. Our use of analytics providers may be considered "sharing" under California law; you can limit this through the cookie and analytics controls described in Section 7.
All Users
Regardless of your location, you may:
- Delete your account and all associated data at any time from Settings within the app. This action is irreversible and permanently removes your profile, session transcripts, analytics, and other personal data we hold, subject to the limited retention described in Section 8.
- Update your profile information at any time from Settings.
- Manage your cookie and analytics preferences as described in Section 7.
- Opt out of non-essential communications by following the unsubscribe link.
To exercise any right that is not available through self-service, contact us at hello@convosparr.com. We will respond within the timeframes required by applicable law.
7. Cookies, Analytics & Session Replay
We use the following categories of cookies and similar technologies:
- Essential cookies — set by our authentication provider to keep you logged in, plus a cookie that stores your theme preference. These are required for the Service to function and are always on.
- Analytics & session-replay technologies — used by PostHog (and, on our marketing pages, Google Analytics) to measure usage and record masked replays of in-app activity, as described in Section 2. These set cookies or use similar local storage.
- Attribution cookie — if you consent to analytics, we store one first-party cookie recording how you first reached us: a channel name (for example "linkedin") and the website that referred you. We do not store the full referring address, and we do not store campaign or medium parameters. It expires after 30 days, and is deleted as soon as it is attached to a new account. If you decline analytics, it is never written.
We do not use advertising cookies and we do not run behavioral advertising. Where required by law (including for users in the EU, EEA, and UK), we ask for your consent before enabling analytics and session-replay technologies, and you can withdraw or change your choice at any time. Disabling essential cookies will prevent you from logging in and using the Service.
8. Data Retention
We retain your data for the following periods:
- Account and profile data — retained for the lifetime of your account
- Session transcripts, scores, and analytics — retained while your account is active
- In-app notifications: notification entries and their read state are stored with your account; personal notifications are deleted after 90 days, announcement read state is kept while the announcement exists, and all of it is deleted with your account
- On account deletion — your profile, session records, transcripts, analysis, credits, and progress are permanently deleted from our systems
- Billing and limited audit records — transaction and compliance records may be retained by us and by Paddle as required by applicable tax and accounting law (typically up to 7 years), independent of account deletion
- Third-party providers — data already shared with the providers in Section 4 is retained or deleted under their own policies
- No-signup demo sessions: if you tried the demo without an account, that session and its transcript are deleted after 30 days. If you later created an account and claimed it, it lives with your account instead
- Team accounts: your organization's data is kept while its subscription is live. After cancellation it has 90 days to request an export, then it is permanently deleted. A departed member's data stays with the organization for the same period
9. International Data Transfers
ConvoSparr is operated by Tarsonix Technologies (OPC) Private Limited, based in India. Our service providers store and process data primarily in the United States and other countries, which may have different data protection standards than your country of residence.
For users in the EU, EEA, and UK, we rely on appropriate legal mechanisms for international transfers, including Standard Contractual Clauses where applicable. By using the Service, you understand that your data will be transferred to and processed in countries outside your own.
10. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies independently.
11. Children's Privacy
The Service is intended only for individuals who are 16 years of age or older, and old enough to enter a binding contract where you live. We do not verify age at sign-up and do not knowingly collect personal information from anyone below that threshold. If you believe a minor has provided us with personal information, please contact us and we will delete the account and associated data.
12. If you use ConvoSparr through your employer
When your organization buys ConvoSparr for a team, your organization is the data controller for your practice data and we act as its processor, on its instructions. The controller-processor terms are in our Data Processing Addendum.
What your team can see
Your organization's owner and admins can review any member's practice sessions, and a manager can review their own group's. That means the transcript of a session, its score, and the coaching notes produced from it. Call audio is not captured today; if that changes, we will update this policy and ask you again before it applies to you.
We show you this in the product before you practise, as a monitoring notice you accept. That notice carries a version number, and a material change means we ask you to read it again. You can withdraw at any time in Settings, under Security; withdrawing pauses your practice access until you accept again. Your organization remains responsible for the employment-law side of monitoring you.
Deletion and your rights
Because your organization owns this data, you cannot delete your own sessions or your own account from a team plan. You keep your statutory rights over it: access, correction, erasure and portability. Email privacy@convosparr.com from your work address and we handle the request with your organization, after verifying who you are.
Retention follows your organization's subscription, as described in Section 8. The commercial terms it agreed to are our Business Terms, and the providers involved are listed on our Subprocessors page.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by posting the updated policy on this page, updating the "Last updated" date, and, where required by law, notifying you by email.
14. Contact Us
If you have any questions, requests, or concerns about this Privacy Policy or your personal data, including to exercise your rights or raise a grievance, please contact us:
Company: Tarsonix Technologies (OPC) Private Limited
Product: ConvoSparr
Registered address: Sri Kamakshi Amman Nagar, Kambarasampettai, Tiruchirappalli, India - 620101
Grievance Officer / Privacy contact: hello@convosparr.com