Privacy Policy

Last updated: 4 September 2026

Culturily (“Culturily,” “we,” “us,” or “our”) is operated by Jake Geise, an individual based in California, United States. This Privacy Policy explains what we collect when you use the Culturily app and website (including our waitlist), where it is stored, who can see it, how long we keep it, and what happens when you delete your account. If you have any questions, contact us at support@culturily.com.

Culturily records people’s voices. That makes this policy longer and blunter than most, and in places it describes things we have not built rather than things we have. Where we keep something forever, or where a deletion leaves something behind, this page says so in those words.

Who is responsible for your data

Jake Geise is responsible for the data described here, contact support@culturily.com. Because Culturily is currently operated by an individual rather than a company, “we” throughout this policy refers to Jake Geise trading as Culturily.

Who can use Culturily

Culturily is intended for users aged 16 and over. We do not knowingly collect personal data from anyone under 16. If you believe someone under 16 has provided us personal data, contact support@culturily.com and we will delete it. We chose 16 because it is the highest age of digital consent used by any EU member state, so a single limit applies everywhere rather than one that changes by country.

Recording your voice

Culturily asks you one question a day about where you come from, and lets you answer it out loud. If you press the microphone button, your browser records your answer as an audio file and uploads it to us when the answer saves. Typing your answer is always available, and on browsers that cannot record at all the microphone button is never shown. If you refuse the microphone permission, or the recording fails for any reason, your written answer still saves — the recording never blocks the answer.

Where the recording goes. The audio file is uploaded to a private storage bucket held at Supabase, our database and hosting provider. We store it in whatever audio format your device produced — m4a, webm, ogg, mp3 or wav — and we do not convert, trim, normalise, denoise or otherwise alter it. A single recording can carry up to 4 MB of audio. The bucket is private: no browser holds a credential that can read or write it, and the internal path of your audio file is never sent to any browser, including yours.

How long we keep it: indefinitely. We want to be blunt, because this is the part people assume works differently. There is no expiry, no retention window and no automatic deletion for voice recordings anywhere in our system. A recording stays until you delete your account. And if you re-record an answer, the earlier recording is not deleted either — superseded recordings are kept on purpose, so a single answer may have several recordings of you behind it. We are not going to name a retention period we have not built.

Transcripts of what you said

If you ask us to, we can turn what you said into text. We send the recording to Groq, a transcription company in the United States, and they return the words. We store them as a transcript on your answer (up to 20,000 characters), kept verbatim: we do not tidy it, summarise it, or correct it.

Your audio is only sent if you have said yes. The setting is off until you turn it on. We ask you in plain words, after an answer with a recording has saved, and we name Groq when we ask. If you never answer that question, nothing is ever sent — silence is not a yes. If you say no, your audio is never sent to Groq or to anyone else, and your recording is still saved and still playable.

What Groq may and may not do with it. Under their Services Agreement they are not permitted to use what we send them to train or fine-tune any AI model, and they do not retain inference requests by default. We have also switched on their Zero Data Retention setting for our account. They receive the audio file and, if you have set a voice language, that language — nothing else: not your name, not your email, not the question, not your written answer, and nothing identifying your account.

Changing your mind deletes the transcripts. If you withdraw this permission, we delete every transcript Groq produced for you, and we stop sending anything further. That is final: it cannot be switched back on afterwards. Your recordings are not deleted — they stay in your vault and stay playable, because withdrawing permission to write out your words is not a request to destroy your voice. Deleting recordings is a separate thing you can also do, by deleting the answer or your account. Groq keeps no copy for us to ask them to delete.

What we used to do, and why it changed. Until this version, transcription ran in your own browser using its built-in speech recognition — and in Chrome that meant your audio was sent to Google every time you recorded, without our asking you and without naming them. We said here that the choice between on-device and server recognition was your browser’s and outside our control, which was true and was not good enough. We removed that path entirely. Your browser no longer performs speech recognition for us at all, and no audio goes anywhere unless you have said yes to Groq.

Your transcript is stored as text, it is shown to anyone you have given listening access to, and it is included when you download your data.

Who can hear your recordings

A recording can be played by you, and by a listener you invited who has accepted the invitation. Nobody else. A listener sees and hears the same card you do: the recording, the transcript, and your written answer.

There is no permanent link to any recording. Each time a recording is played, our server checks — on that exact request — that there is a live, accepted invitation binding that listener to you, and only then creates a playback link that expires after 60 seconds. Our own server holds the credential that can read the storage bucket, because it has to be the one to mint those links.

You can take access away. Revoking a listener works, and because permission is re-checked on every single play, it takes effect on their next attempt to play anything. An invitation that is never accepted expires by itself after 14 days. If a listener deletes their own Culturily account, their access ends with it.

People who do not have a Culturily account

Culturily holds information about people who never signed up. There are three kinds, and we would rather set them out than leave them to be discovered.

Other data we collect

Information about your background

An earlier version of this policy said Culturily deliberately held nothing about your ethnic or national origin. That is no longer a fair description of the product, and we are correcting it rather than leaving it standing. Culturily now asks you a question a day about where you come from and your family, and stores your answer — in your own words, and often in your own voice. It also stores the culture you choose, which decides the questions you receive.

What remains true is narrower, and we will hold ourselves to it: we do not infer your background. We do not guess it from your surname, your location, or anything else. We hold what you chose to tell us, and nothing we worked out about you behind your back. Choosing a culture selects which questions you are asked. It is a preference, not a declaration of ancestry, and someone with no connection to a culture is as welcome as anyone.

But a recording of you talking about your grandmother is information about your background, it is stored indefinitely, and anyone you have given listening access to can hear it. We would rather say that plainly than repeat a reassuring line that the product has outgrown.

Who we share data with

We do not sell your personal data. This is the full list of outside services any of your data reaches, and what reaches each one:

Telling ourselves that a signup happened. When we switch it on, the creation of a new account sends us a one-line internal notice — through Resend, to a Culturily address of our own. It says only that an account was created, and at what time. It carries no name, no email address and no account identifier, so there is nothing in it that points back to any particular person. It is off unless we deliberately turn it on, and turning it off again takes a setting change rather than a new release.

Some of these providers process data in the United States. Deleting your Culturily account does not instruct any of them to delete their own copies — see “Deleting your account” below.

No paid subscription is available yet. Once one is, web-based membership payments will be handled through Stripe, which acts as the merchant of record and seller for that purchase — processing your payment, billing, and applicable VAT or sales tax. Your payment relationship and receipt for the sale itself will be with Stripe, not directly with Jake Geise. (If an in-app purchase is ever offered in an iOS app, it would be billed by Apple, the merchant of record for that purchase instead.) Stripe acting as merchant of record for the sale does not change who is responsible for Culturily’s own refund and withdrawal commitments — see Terms of Service — which remains Jake Geise.

AI-generated content

We do not generate your answers or write them for you. Today, the one place software interprets your recording is speech recognition: if you have said yes, Groq turns what you said into text, and that transcript can contain errors. If we ever add another — a suggested follow-up question drawn from your own words, or a voice built from your recordings — we will ask you first, separately, and it stays off until you say yes.

Today, the only place your own material is sent is Groq, for transcription, and only if you said yes. Nothing else your system holds is sent to an AI provider: the only thing we send elsewhere is source text and facts drawn from it, for the editorial content we publish. If we ever want to send your recordings, transcripts or answers anywhere else, we will ask you for that specifically, and you can say no or change your mind later. Answers you write are barred by rule from ever entering the content corpus.

Error monitoring

We monitor errors in two places, and they are treated differently on purpose.

In your browser, the Sentry error monitor does not load at all until you accept analytics in our consent banner. If you decline, or never answer, no error data leaves your browser. It is configured not to attach your identity to a report.

On our servers, we monitor errors thrown by our own code — the message, where in our code it happened, and which function was running. This is not gated on your consent, and we want to be straightforward about why: server errors frequently happen on requests that have no signed-in user at all, and consent choices are stored in your browser rather than sent to us, so there is often no consent to check. These reports carry no name, email, or account identifier. You can object to this at support@culturily.com.

How long we keep things

Backups. A copy of the whole database is taken once a night onto a machine controlled by Jake Geise. The most recent 14 nightly copies are kept and older ones are deleted — but separately from those, an archive of 22 older copies is kept permanently and is never deleted. Backups are whole-database snapshots: they cannot be edited to remove one person, and nothing re-applies your deletion to them. This means data from before your deletion continues to exist in that frozen archive with no end date. We use backups only to restore the service, and we do not query them to look anyone up. We state this plainly rather than leaving it implied, because “deleted” should mean what a reader thinks it means.

Deleting your account — what goes, and what stays

You can delete your account from the app. Here is what that actually does.

It deletes:

If we cannot read or delete your recordings for any reason, the whole deletion stops before anything is removed and your account is left intact so it can be retried. We would rather fail visibly than delete your account and leave your voice behind.

It leaves behind:

If you want any of the items in that second list removed, email support@culturily.com and we will do it by hand.

Downloading your data

If you have an account, you can download your vault. You get every answer and every earlier revision of it, the transcripts, the written text, and the actual audio files in the formats they were recorded in, packaged into a single zip file that is assembled in your browser. If any file fails to download it is named in the archive rather than silently dropped.

What the download does not include. It covers your vault only. It does not include your profile or your analytics events. There is no export for answers made before you had an account. If you want any of that, email support@culturily.com and we will put it together for you.

What you can ask us to do

Whatever your country entitles you to, this is what we will do when you ask, and you can ask by emailing support@culturily.com:

We answer these ourselves, by email, and we will not treat you any worse for asking. If you invited someone and they would rather we did not hold their address, they can reply to the invitation email or write to us directly, and we will delete it.

Cookies & tracking

Culturily uses no advertising cookies, sets no cross-site trackers, and does not profile you for advertisers. Product analytics and in-browser error monitoring only run after you accept them in our consent banner. Server-side error monitoring, our own first-party service records, and the anti-bot check are not part of that banner — the anti-bot check runs first because it is a security control.

Do Not Track, and Global Privacy Control. Some browsers can send a “Do Not Track” (DNT) signal, and some send a Global Privacy Control (GPC) signal. Culturily does not detect or act on either one. There is no code anywhere in the product that reads them, so a browser sending one is treated exactly like a browser that does not. We tell you this because California law requires us to say how we respond to such a signal, not because we think the answer flatters us. What we do instead applies to you whether you send a signal or not: we set no advertising cookies, we run no cross-site trackers, we do not sell or share your personal information, and we allow no third party to collect information about your activity across other websites through Culturily. Product analytics and in-browser error monitoring do not start at all until you accept them in the consent banner — declining that banner is the control that actually does something here.

Security

We would rather point at specific things than make a general promise. Your voice recordings sit in a private storage area that no browser can read directly; every playback link is created by our server for one recording at a time and expires after 60 seconds; the internal path of a recording is never sent to a browser; permission to play is re-checked on every request rather than cached. If you sign in with a password, it is stored only as a hash we cannot reverse. Traffic to the site is encrypted in transit.

No system is perfectly secure, and we are not claiming more than the paragraph above. If we become aware of a breach affecting your data, we will tell you.

Changes to this policy

We may update this policy from time to time. If we make material changes, we will notify you in the app or by email. The “Last updated” date at the top shows the latest version.

Contact

Questions, requests, or complaints: support@culturily.com. Jake Geise, California, United States.