Legal
Privacy Policy for Speak Up
1. Introduction
This Privacy Policy explains how the Speak Up mobile application (“the App”) collects, uses, stores, shares, and protects your personal information when you use it. By creating an account or otherwise using the App, you agree to the practices described in this Policy.
Speak Up is operated by Eight Network Creations Private Limited, a private limited company incorporated in India. Throughout this Policy, the words “we”, “us”, and “our” refer to that company, identified in Section 2 below.
We have written this Policy in plain language so that you can clearly understand what we do with your data. If anything is unclear, please reach out using the contact details in Section 15.
This Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 together with the rules made under it.
2. Who we are (the Data Fiduciary)
The “Data Fiduciary” under the DPDP Act, 2023 — that is, the entity that decides why and how your personal data is processed — is a company:
Eight Network Creations Private Limited, a private limited company incorporated in India, with its registered office in Bengaluru. The App is published on Google Play under our organisation developer account, using the developer display name “Octopus Creations”. “Octopus Creations” is only a publisher display name on Google Play; the legal entity that operates the App and is accountable for your personal data is Eight Network Creations Private Limited.
- Name (legal): Eight Network Creations Private Limited
- Registered office: L-148, 5th Main Road, Sector 6, HSR Layout, Bengaluru, Bengaluru Urban — 560102, India
- Account type on Google Play: Organisation
- Developer display name on Google Play: Octopus Creations
- Contact email: support@eight.network
- Website: https://www.eight.network/
In this Policy, “we”, “us”, “our”, and “the developer” all refer to Eight Network Creations Private Limited.
3. Information we collect
We only collect what we need to operate the App, give you a working learning experience, process payments, and meet our legal obligations.
3.1 Information you provide to us
| Category | Examples | When collected |
|---|---|---|
| Account identifier | Mobile phone number (E.164 format) — the only identifier needed to create an account | When you register with a mobile-number OTP |
| Learning profile | Your name (optional), native language, starting level, and learning goals | During onboarding and from in-app settings |
| App preferences | Interface language and notification preferences | During onboarding and from in-app settings |
| Support correspondence | Any information you include when you email us, including the email address you write from | When you contact us |
3.2 Information collected automatically
| Category | Examples | Purpose |
|---|---|---|
| Learning progress | Lessons started/completed, exercise answers (correct/incorrect), XP, streaks, badges, scores, last-played lesson | To save your progress, unlock content, and run gamification |
| Device & technical data | Device model, OS version, app version, language/locale, IP address (transient, for API requests), Firebase Installation ID | To deliver the service, debug, and prevent fraud |
| Push notification token | Firebase Cloud Messaging (FCM) registration token | To send you learning reminders if you opt in |
| Diagnostic data | Crash stack traces, non-fatal errors, performance traces | Through Firebase Crashlytics, to fix bugs |
| Product analytics | Screen views, lesson funnel events, paywall events, button taps | Through Google Analytics for Firebase, to improve the App |
| Subscription status | Plan, status (trial / active / expired / cancelled), trial and renewal dates, and the PhonePe mandate and order references for your subscription | To gate paid content; we never see or store your UPI PIN, card, or bank credentials — see Sections 5 and 12 |
3.3 What we do not collect
To remove any doubt, Speak Up Phase 1 does not collect or process:
- Voice or audio recordings. All Text-to-Speech in Phase 1 runs on-device via the
flutter_ttsengine. We do not record your voice, we do not use the microphone, and no audio leaves your device. - Google or other social-account data. Sign-in is by mobile-number OTP only. The App does not use Google Sign-In or any other social login, and it does not ask for your email address to create an account.
- Photos, videos, or files from your device.
- Precise location (GPS). We do not request or use location permissions.
- Contacts, calendar, SMS, or call logs.
- Sensitive personal data such as health, biometric, financial account credentials, sexual orientation, religious or political beliefs, or caste.
If this changes in a future version (for example, when speech recognition is added in Phase 2), we will update this Policy and ask for your consent before any new collection begins.
4. How we use your information
We use your personal data only for the following purposes:
- To provide the App — create and authenticate your account, save and sync your learning progress, deliver lesson content, run the gamification (XP, streaks, badges), and remember your preferences.
- To process payments and subscriptions — verify subscription status with the payment processor and unlock paid content. We do not store card or UPI details ourselves.
- To communicate with you — send transactional messages (OTP, payment receipts, subscription updates) and, if you opt in, learning reminders and streak nudges via push notifications.
- To keep the App safe and working — detect bugs, prevent fraud, debug crashes, throttle abusive traffic, and improve stability.
- To improve the App — understand which lessons and features work, where users get stuck, and where to invest content effort. We use aggregated and pseudonymous analytics for this.
- To comply with the law— respond to lawful requests from courts, regulators, and law-enforcement authorities, and to enforce the App's Terms of Use.
Legal basis for processing (DPDP Act)
We process your data based on:
- Your consent, given when you create an account, enable notifications, or opt into analytics. You can withdraw consent at any time (see Section 8).
- The performance of a contract with you (delivering paid lessons after you subscribe).
- Our legal obligations (such as retaining payment invoices for tax purposes).
- Legitimate uses as defined under Section 7 of the DPDP Act (e.g., responding to a medical emergency, complying with a court order).
5. How we share your information
We do not sell your personal data, and we do not share it for third-party advertising.
We share limited personal data with the following processors, only to the extent each one needs to perform its function:
| Processor | What is shared | Purpose | Where data is processed |
|---|---|---|---|
| Amazon Web Services (AWS) | Encrypted API traffic and the server-side copy of your account data, learning progress, and subscription records | Application hosting — containers, the PostgreSQL database and its backups, load balancing, secrets, and server logs | India — Asia Pacific (Mumbai), the ap-south-1 region. AWS is a US-headquartered provider; your data is stored in India but the infrastructure is administered by AWS. |
| MSG91 (Walkover Web Solutions Pvt Ltd) | Your mobile number and the one-time password being sent to it | Delivering login OTPs by SMS | India |
| Google Firebase (Cloud Messaging, Crashlytics, Installations, Google Analytics for Firebase) | FCM token, device & app identifiers, crash stack traces, non-fatal logs, pseudonymous analytics events (e.g., lesson_completed, paywall_viewed) | Push notifications, crash reporting, product analytics | Google data centres (multi-region) |
| PhonePe Limited | Your subscription plan, amount, and a merchant order reference. The UPI mandate itself is authorised inside PhonePe or the UPI app you choose — we never see your UPI PIN, card, or bank credentials | Subscription payments and recurring UPI Autopay mandates | India |
Each of these processors is contractually bound (through its standard terms of service) to use your data only for the purposes we instruct, to keep it secure, and to delete it when no longer needed.
Legal disclosures
We may disclose personal data when required by law — for example, in response to a valid order from an Indian court, regulator, or law-enforcement authority, or where disclosure is necessary to prevent fraud, protect our legal rights, or protect the safety of any person.
Transfer of the App
If we sell or transfer the App to another company or entity, or if Eight Network Creations Private Limited is involved in a merger, acquisition, or reorganisation, your personal data may be transferred as part of that transaction. We will notify you in-app or by email before that happens, and the receiving party will be required to honour this Policy or a policy at least as protective.
6. Data storage, transfer, and security
- Primary storage location: The application servers and database are hosted in India, on Amazon Web Services in the Asia Pacific (Mumbai)
ap-south-1region. - International transfers:Some processors named in Section 5 store or administer data outside India. Google Firebase services (FCM, Crashlytics, Google Analytics for Firebase) process data in Google's multi-region data centres, including the United States. AWS keeps your data in the Mumbai region but is a US-headquartered provider that administers the underlying infrastructure. MSG91 and PhonePe process your data in India. We rely on the safeguards offered by those processors and on the cross-border-transfer mechanisms permitted under the DPDP Act, 2023.
- In transit: All communication between the App and the servers uses TLS 1.3 encryption.
- At rest:Passwords are never stored — you sign in with a one-time password instead. The database and its backups are encrypted at rest by AWS. On your device, your session tokens and cached progress are kept in the App's private storage area, which other apps on the device cannot read, and are cleared when you log out or uninstall the App.
- Network isolation:The database is not reachable from the public internet; it sits in a private network segment and accepts connections only from the App's own servers.
- Access controls: Production systems are accessed only by authorised personnel of Eight Network Creations Private Limited; access is protected by strong authentication and logged.
- No system is perfectly secure. If we ever discover a personal-data breach that is likely to cause harm, we will notify affected users and the Data Protection Board of India as required under the DPDP Act.
7. Data retention
We keep your personal data only as long as we need it for the purposes described in this Policy.
| Data category | Retention |
|---|---|
| Account data (phone, name, email, preferences) | While your account is active. If you delete your account, we keep it for 30 days as a grace period, then permanently delete it. |
| Learning progress (XP, streaks, lesson history) | Same as above — deleted with your account after the 30-day grace period |
| Push notification tokens | Until you uninstall the App, disable notifications, or delete your account |
| Crash and diagnostic logs | Up to 90 days, then deleted or aggregated |
| Analytics events (Google Analytics for Firebase) | Up to 14 months, in line with Google Analytics for Firebase's default retention, then deleted or aggregated |
| Payment and subscription records | Up to 8 years after the transaction, to comply with Indian tax and accounting laws (e.g., GST, Income Tax Act) |
| Support correspondence | Up to 24 months after the last interaction |
| Encrypted database backups | A rolling 7 days. Data you delete can therefore survive in a backup for up to 7 days before it ages out |
After the retention period, we either permanently delete the data or anonymise it so it can no longer be linked back to you.
8. Your rights
Under the DPDP Act, 2023, you have the following rights regarding the personal data we hold about you. You can exercise any of these by emailing support@eight.network from the email/phone number linked to your account.
| Right | What it means |
|---|---|
| Right to access | Request a summary of the personal data we process about you and the processors we share it with |
| Right to correction & updating | Ask us to correct inaccurate, incomplete, or outdated information. You can update most of this yourself from the App's Settings screen |
| Right to erasure | Ask us to delete your personal data when it is no longer needed for the purposes for which it was collected. You can also delete your account directly from Settings → Account → Delete Account |
| Right to withdraw consent | Withdraw your consent for processing at any time. Withdrawal does not affect the lawfulness of processing done before the withdrawal |
| Right to grievance redressal | Contact our Grievance Officer (Section 15) if you are unhappy with how your data is handled |
| Right to nominate | Nominate another person to exercise your rights in the event of your death or incapacity |
We will respond to all valid requests within 30 days. We may need to verify your identity before acting on a request, to protect your data from unauthorised disclosure.
9. App permissions
Speak Up requests only the following permissions on Android. Each one is used solely for the purpose described below.
| Permission | Why it is needed |
|---|---|
INTERNET, ACCESS_NETWORK_STATE | To talk to the App's servers and download lesson content |
POST_NOTIFICATIONS (Android 13+) | To show learning-reminder and streak notifications — only after you say yes |
RECEIVE_BOOT_COMPLETED | So that scheduled learning reminders are restored after your device restarts |
VIBRATE | Subtle haptics on correct/incorrect answers |
The App does not request: Microphone, Camera, Location, Contacts, SMS, Storage (legacy), or any “Restricted Permission” as defined by Google Play. Because it holds no SMS permission, you always type your OTP in yourself — the App cannot read your messages.
On Android 11 and above, the App also declares package-visibility queries for upi:// links and for the PhonePe app, so that it can hand you over to your UPI app to authorise a subscription mandate. These are not permissions and give the App no access to those apps or their data.
10. Children's privacy
Speak Up is intended for users aged 13 years and above.
- We do not knowingly collect personal data from children under 13.
- For users aged 13 to 17 (minors), the DPDP Act, 2023 requires the verifiable consent of a parent or lawful guardian before any personal data is processed. By using the App, a minor user confirms that such consent has been obtained.
- We will not perform tracking, behavioural monitoring, or targeted advertising directed at minors.
- If you are a parent or guardian and believe that a child under 13 has provided personal data through the App, or that consent was not properly given for a minor between 13 and 17, please email support@eight.network and we will delete the data promptly.
11. Push notifications
If you grant the notification permission, we may send you:
- Daily streak reminders
- Re-engagement nudges (after 3 days of inactivity, stopping after 7 days of no use)
- Transactional updates (payment success, subscription expiry)
You can turn any of these off at any time from Settings → Notifications inside the App, or from your Android system settings.
12. Payments
Subscriptions are billed through PhonePe Limited using UPI Autopay, the recurring-mandate facility of the UPI network.
- You authorise the mandate inside PhonePe or whichever UPI app you pick, and your UPI PIN, card number, and bank credentials are entered only there. We never see, transmit, or store them.
- To start a subscription, the App hands you over to your UPI app (or shows a QR code you can scan with it). We share only the plan, the amount, and a merchant order reference with PhonePe.
- We only receive the outcome of the mandate and of each charge (success/failure), the references PhonePe returns, your subscription plan, and the trial and renewal dates.
- PhonePe's processing of your payment data is governed by its own privacy policy, available at https://www.phonepe.com/privacy-policy/. If you authorise the mandate in a different UPI app, that app's own privacy policy applies to what it collects.
- For refunds, billing disputes, or chargebacks, email support@eight.network. We will respond within 7 working days.
13. Cookies and similar technologies
Speak Up is a native Android application and does not use browser cookies. It does use device-level identifiers (Firebase Installation ID, FCM token, and the pseudonymous app-instance ID used by Google Analytics for Firebase) for the purposes described in this Policy. These identifiers are reset if you reinstall the App, or if you clear the app's storage from Android system settings.
14. Changes to this Privacy Policy
We may update this Policy from time to time — for example, when new features are added, processors change, or to reflect changes in the law.
- When we make a change, we will update the “Last updated” date at the top of this Policy.
- If the change is significant (for example, a new category of data, a new processor, or a new purpose), we will give you advance notice in the App or by email and, where required by law, ask for your fresh consent.
- The current version of this Policy is always available inside the App at Settings → Privacy Policy and at https://www.speakupnow.world/privacy.
15. Grievance Officer and contact details
If you have any questions, requests, or complaints about how your personal data is handled, please reach out — we want to help.
Eight Network Creations Private Limited has designated a Grievance Officer as required under Rule 5(9) of the Information Technology (Reasonable Security Practices) Rules, 2011 and Section 8(9) of the DPDP Act, 2023. Grievances reach the Grievance Officer through the contact details below.
- Data Fiduciary: Eight Network Creations Private Limited
- Attention: The Grievance Officer
- Registered office: L-148, 5th Main Road, Sector 6, HSR Layout, Bengaluru, Bengaluru Urban — 560102, India
- Email: support@eight.network
We will acknowledge your grievance within 48 hours of receiving it and resolve it within 30 days.
If you remain unsatisfied with our response, you have the right to escalate your complaint to the Data Protection Board of India under the DPDP Act, 2023.
Speak Up is built in India by Eight Network Creations Private Limited. Thank you for trusting us with your learning journey.