Privacy Notice

Last updated: 5/13/2026

TaroTea (“we”, “us”, “our”) respects your privacy and is committed to protecting your personal data. This Privacy Notice explains how we collect, use, store and protect your information when you use TaroTea.

TaroTea is a web application for learning Cantonese. We only collect information that is needed to provide the service, manage accounts, process subscriptions, improve reliability, and support learning features.

Who we are

TaroTea is operated as a Cantonese learning web application.

If you have any questions about this notice or your data, you can contact us at:
[email protected]

What data we collect

We collect different types of information depending on how you use TaroTea.

  • Account information: such as your email address, user ID, account status and subscription status.
  • Authentication information: login and session information handled through our authentication provider. We do not store your password.
  • Learning progress: such as XP, streaks, completed quizzes, unlocked words, quiz answers, accuracy, and related progress data.
  • Pronunciation and speech feature data: if you use speech or pronunciation features, we may process the audio you submit, transcripts, scores, feedback, and usage counts for those features.
  • Payment and subscription information: such as your plan, subscription status, billing status, and Stripe customer or subscription IDs. We do not store your full card details.
  • Technical and usage data: such as page requests, error logs, device/browser information, timestamps, and security logs needed to operate, debug and protect the service.
  • Preferences: such as your selected audio voice preference where you choose to save it.

How we use your data

  • To create and manage your account
  • To log you in and keep your account secure
  • To provide access to free and paid content
  • To track learning progress, XP, streaks, unlocks and quiz results
  • To provide pronunciation, audio and speech feedback features
  • To process subscriptions, billing and account upgrades
  • To prevent abuse, fraud or misuse of the service
  • To debug errors, improve reliability and maintain the app
  • To communicate important service, account or billing updates

Legal basis for processing

Under UK GDPR, we rely on the following legal bases:

  • Contract: to provide the TaroTea service you sign up for, including account access, paid features, learning progress and subscription management.
  • Legitimate interests: to operate, secure, debug and improve the app, prevent misuse, and understand how the service is performing.
  • Legal obligation: where we need to retain billing, accounting, tax or compliance records.
  • Consent: where required, such as for optional non-essential cookies or similar technologies if we introduce them in future.

Third-party services

We use trusted third-party providers to operate TaroTea. These providers only process data as needed to provide their services to us.

  • Auth0: authentication, login and account security.
  • Stripe: payment processing, subscriptions, invoices and billing.
  • OpenAI: speech-to-text and pronunciation-related processing, where you choose to use pronunciation features.
  • Hosting, database, storage and infrastructure providers: to host the app, store content, deliver audio files, run background jobs, cache data, monitor reliability and protect the service.

Some providers may process data outside the United Kingdom. Where this happens, we rely on appropriate safeguards required by data protection law.

Cookies and similar technologies

TaroTea uses cookies and similar technologies to operate the app, keep users signed in, remember preferences, and protect the service. We do not use advertising cookies.

TypePurposeExample
Essential cookies Used for login, authentication, session management, security and access to account features. Authentication/session cookies
Preference cookies Used to remember choices you make in the app, such as your preferred audio voice. audio-voice
Analytics or advertising cookies We do not currently use advertising cookies. If we introduce optional analytics or advertising cookies in future, we will ask for consent where required. Not currently used

The audio-voice preference stores whether you selected male or female audio playback. It is used only to keep your chosen audio voice across pages and is not used for advertising, analytics or tracking across other websites.

You can change your audio voice preference using the audio voice switch in the app. You can also delete cookies through your browser settings.

Data retention

We keep personal data only for as long as needed for the purposes described in this notice.

  • Account data is kept while your account is active.
  • Learning progress is kept while your account is active so we can provide progress tracking, XP, streaks and unlocked content.
  • Billing and subscription records may be kept for as long as required for tax, accounting, legal or fraud-prevention purposes.
  • Technical logs are kept only as long as needed for debugging, security, reliability and operational purposes.
  • If you request account deletion, we will delete or anonymise personal data unless we need to keep limited information for legal, billing, security or fraud-prevention reasons.

Your rights

Under UK GDPR, you may have the right to:

  • Access your personal data
  • Correct inaccurate or incomplete data
  • Request deletion of your personal data
  • Object to certain processing
  • Request restriction of processing
  • Request data portability
  • Withdraw consent where processing is based on consent

To exercise these rights, contact us at:
[email protected]

Account deletion

You may request deletion of your TaroTea account at any time. When an account is deleted, we aim to remove account information, learning progress and related app data from active systems, subject to any information we must keep for legal, billing, security or fraud-prevention reasons.

Security

We use reasonable technical and organisational measures to protect your personal data, including authentication controls, access controls, secure third-party providers and operational monitoring. No online service can be guaranteed to be completely secure, but we work to protect your data and reduce risks.

Children

TaroTea is not intended for children under 13. If you believe a child has provided us with personal data, please contact us so we can review and take appropriate action.

Complaints

If you have concerns about how we handle your data, please contact us first so we can try to help. You also have the right to complain to the UK Information Commissioner’s Office.

Changes to this notice

We may update this Privacy Notice from time to time. Any significant changes will be reflected on this page. The “Last updated” date above shows when this notice was most recently changed.

Contact

If you have any questions about this Privacy Notice, please contact:
[email protected]