SpeakUp
FeaturesHow it worksStart for Free

Legal

Privacy Policy for Speak Up

Effective date: 1 September 2026

Last updated: 1 September 2026

Applies to: Speak Up mobile application (Android), published on Google Play under the developer display name “Octopus Creations”.

Operated by: Eight Network Creations Private Limited, Bengaluru, India.


In short: you sign in with your mobile number only — no Google or social login, and no email address is needed for an account. The App never records your voice: all speech is generated on your device. We do not sell your data or share it for advertising. You can delete your account and all your learning progress from Settings → Account → Delete Account inside the App, or by emailing support@eight.network. This summary is for orientation only — the sections below are what apply.

Contents

  1. Introduction
  2. Who we are (the Data Fiduciary)
  3. Information we collect
  4. How we use your information
  5. How we share your information
  6. Data storage, transfer, and security
  7. Data retention
  8. Your rights
  9. App permissions
  10. Children's privacy
  11. Push notifications
  12. Payments
  13. Cookies and similar technologies
  14. Changes to this Privacy Policy
  15. Grievance Officer and contact details

1. Introduction

This Privacy Policy explains how the Speak Up mobile application (“the App”) collects, uses, stores, shares, and protects your personal information when you use it. By creating an account or otherwise using the App, you agree to the practices described in this Policy.

Speak Up is operated by Eight Network Creations Private Limited, a private limited company incorporated in India. Throughout this Policy, the words “we”, “us”, and “our” refer to that company, identified in Section 2 below.

We have written this Policy in plain language so that you can clearly understand what we do with your data. If anything is unclear, please reach out using the contact details in Section 15.

This Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 together with the rules made under it.

2. Who we are (the Data Fiduciary)

The “Data Fiduciary” under the DPDP Act, 2023 — that is, the entity that decides why and how your personal data is processed — is a company:

Eight Network Creations Private Limited, a private limited company incorporated in India, with its registered office in Bengaluru. The App is published on Google Play under our organisation developer account, using the developer display name “Octopus Creations”. “Octopus Creations” is only a publisher display name on Google Play; the legal entity that operates the App and is accountable for your personal data is Eight Network Creations Private Limited.

  • Name (legal): Eight Network Creations Private Limited
  • Registered office: L-148, 5th Main Road, Sector 6, HSR Layout, Bengaluru, Bengaluru Urban — 560102, India
  • Account type on Google Play: Organisation
  • Developer display name on Google Play: Octopus Creations
  • Contact email: support@eight.network
  • Website: https://www.eight.network/

In this Policy, “we”, “us”, “our”, and “the developer” all refer to Eight Network Creations Private Limited.

3. Information we collect

We only collect what we need to operate the App, give you a working learning experience, process payments, and meet our legal obligations.

3.1 Information you provide to us

CategoryExamplesWhen collected
Account identifierMobile phone number (E.164 format) — the only identifier needed to create an accountWhen you register with a mobile-number OTP
Learning profileYour name (optional), native language, starting level, and learning goalsDuring onboarding and from in-app settings
App preferencesInterface language and notification preferencesDuring onboarding and from in-app settings
Support correspondenceAny information you include when you email us, including the email address you write fromWhen you contact us

3.2 Information collected automatically

CategoryExamplesPurpose
Learning progressLessons started/completed, exercise answers (correct/incorrect), XP, streaks, badges, scores, last-played lessonTo save your progress, unlock content, and run gamification
Device & technical dataDevice model, OS version, app version, language/locale, IP address (transient, for API requests), Firebase Installation IDTo deliver the service, debug, and prevent fraud
Push notification tokenFirebase Cloud Messaging (FCM) registration tokenTo send you learning reminders if you opt in
Diagnostic dataCrash stack traces, non-fatal errors, performance tracesThrough Firebase Crashlytics, to fix bugs
Product analyticsScreen views, lesson funnel events, paywall events, button tapsThrough Google Analytics for Firebase, to improve the App
Subscription statusPlan, status (trial / active / expired / cancelled), trial and renewal dates, and the PhonePe mandate and order references for your subscriptionTo gate paid content; we never see or store your UPI PIN, card, or bank credentials — see Sections 5 and 12

3.3 What we do not collect

To remove any doubt, Speak Up Phase 1 does not collect or process:

  • Voice or audio recordings. All Text-to-Speech in Phase 1 runs on-device via the flutter_tts engine. We do not record your voice, we do not use the microphone, and no audio leaves your device.
  • Google or other social-account data. Sign-in is by mobile-number OTP only. The App does not use Google Sign-In or any other social login, and it does not ask for your email address to create an account.
  • Photos, videos, or files from your device.
  • Precise location (GPS). We do not request or use location permissions.
  • Contacts, calendar, SMS, or call logs.
  • Sensitive personal data such as health, biometric, financial account credentials, sexual orientation, religious or political beliefs, or caste.

If this changes in a future version (for example, when speech recognition is added in Phase 2), we will update this Policy and ask for your consent before any new collection begins.

4. How we use your information

We use your personal data only for the following purposes:

  1. To provide the App — create and authenticate your account, save and sync your learning progress, deliver lesson content, run the gamification (XP, streaks, badges), and remember your preferences.
  2. To process payments and subscriptions — verify subscription status with the payment processor and unlock paid content. We do not store card or UPI details ourselves.
  3. To communicate with you — send transactional messages (OTP, payment receipts, subscription updates) and, if you opt in, learning reminders and streak nudges via push notifications.
  4. To keep the App safe and working — detect bugs, prevent fraud, debug crashes, throttle abusive traffic, and improve stability.
  5. To improve the App — understand which lessons and features work, where users get stuck, and where to invest content effort. We use aggregated and pseudonymous analytics for this.
  6. To comply with the law— respond to lawful requests from courts, regulators, and law-enforcement authorities, and to enforce the App's Terms of Use.

Legal basis for processing (DPDP Act)

We process your data based on:

  • Your consent, given when you create an account, enable notifications, or opt into analytics. You can withdraw consent at any time (see Section 8).
  • The performance of a contract with you (delivering paid lessons after you subscribe).
  • Our legal obligations (such as retaining payment invoices for tax purposes).
  • Legitimate uses as defined under Section 7 of the DPDP Act (e.g., responding to a medical emergency, complying with a court order).

5. How we share your information

We do not sell your personal data, and we do not share it for third-party advertising.

We share limited personal data with the following processors, only to the extent each one needs to perform its function:

ProcessorWhat is sharedPurposeWhere data is processed
Amazon Web Services (AWS)Encrypted API traffic and the server-side copy of your account data, learning progress, and subscription recordsApplication hosting — containers, the PostgreSQL database and its backups, load balancing, secrets, and server logsIndia — Asia Pacific (Mumbai), the ap-south-1 region. AWS is a US-headquartered provider; your data is stored in India but the infrastructure is administered by AWS.
MSG91 (Walkover Web Solutions Pvt Ltd)Your mobile number and the one-time password being sent to itDelivering login OTPs by SMSIndia
Google Firebase (Cloud Messaging, Crashlytics, Installations, Google Analytics for Firebase)FCM token, device & app identifiers, crash stack traces, non-fatal logs, pseudonymous analytics events (e.g., lesson_completed, paywall_viewed)Push notifications, crash reporting, product analyticsGoogle data centres (multi-region)
PhonePe LimitedYour subscription plan, amount, and a merchant order reference. The UPI mandate itself is authorised inside PhonePe or the UPI app you choose — we never see your UPI PIN, card, or bank credentialsSubscription payments and recurring UPI Autopay mandatesIndia

Each of these processors is contractually bound (through its standard terms of service) to use your data only for the purposes we instruct, to keep it secure, and to delete it when no longer needed.

Legal disclosures

We may disclose personal data when required by law — for example, in response to a valid order from an Indian court, regulator, or law-enforcement authority, or where disclosure is necessary to prevent fraud, protect our legal rights, or protect the safety of any person.

Transfer of the App

If we sell or transfer the App to another company or entity, or if Eight Network Creations Private Limited is involved in a merger, acquisition, or reorganisation, your personal data may be transferred as part of that transaction. We will notify you in-app or by email before that happens, and the receiving party will be required to honour this Policy or a policy at least as protective.

6. Data storage, transfer, and security

  • Primary storage location: The application servers and database are hosted in India, on Amazon Web Services in the Asia Pacific (Mumbai) ap-south-1 region.
  • International transfers:Some processors named in Section 5 store or administer data outside India. Google Firebase services (FCM, Crashlytics, Google Analytics for Firebase) process data in Google's multi-region data centres, including the United States. AWS keeps your data in the Mumbai region but is a US-headquartered provider that administers the underlying infrastructure. MSG91 and PhonePe process your data in India. We rely on the safeguards offered by those processors and on the cross-border-transfer mechanisms permitted under the DPDP Act, 2023.
  • In transit: All communication between the App and the servers uses TLS 1.3 encryption.
  • At rest:Passwords are never stored — you sign in with a one-time password instead. The database and its backups are encrypted at rest by AWS. On your device, your session tokens and cached progress are kept in the App's private storage area, which other apps on the device cannot read, and are cleared when you log out or uninstall the App.
  • Network isolation:The database is not reachable from the public internet; it sits in a private network segment and accepts connections only from the App's own servers.
  • Access controls: Production systems are accessed only by authorised personnel of Eight Network Creations Private Limited; access is protected by strong authentication and logged.
  • No system is perfectly secure. If we ever discover a personal-data breach that is likely to cause harm, we will notify affected users and the Data Protection Board of India as required under the DPDP Act.

7. Data retention

We keep your personal data only as long as we need it for the purposes described in this Policy.

Data categoryRetention
Account data (phone, name, email, preferences)While your account is active. If you delete your account, we keep it for 30 days as a grace period, then permanently delete it.
Learning progress (XP, streaks, lesson history)Same as above — deleted with your account after the 30-day grace period
Push notification tokensUntil you uninstall the App, disable notifications, or delete your account
Crash and diagnostic logsUp to 90 days, then deleted or aggregated
Analytics events (Google Analytics for Firebase)Up to 14 months, in line with Google Analytics for Firebase's default retention, then deleted or aggregated
Payment and subscription recordsUp to 8 years after the transaction, to comply with Indian tax and accounting laws (e.g., GST, Income Tax Act)
Support correspondenceUp to 24 months after the last interaction
Encrypted database backupsA rolling 7 days. Data you delete can therefore survive in a backup for up to 7 days before it ages out

After the retention period, we either permanently delete the data or anonymise it so it can no longer be linked back to you.

8. Your rights

Under the DPDP Act, 2023, you have the following rights regarding the personal data we hold about you. You can exercise any of these by emailing support@eight.network from the email/phone number linked to your account.

RightWhat it means
Right to accessRequest a summary of the personal data we process about you and the processors we share it with
Right to correction & updatingAsk us to correct inaccurate, incomplete, or outdated information. You can update most of this yourself from the App's Settings screen
Right to erasureAsk us to delete your personal data when it is no longer needed for the purposes for which it was collected. You can also delete your account directly from Settings → Account → Delete Account
Right to withdraw consentWithdraw your consent for processing at any time. Withdrawal does not affect the lawfulness of processing done before the withdrawal
Right to grievance redressalContact our Grievance Officer (Section 15) if you are unhappy with how your data is handled
Right to nominateNominate another person to exercise your rights in the event of your death or incapacity

We will respond to all valid requests within 30 days. We may need to verify your identity before acting on a request, to protect your data from unauthorised disclosure.

9. App permissions

Speak Up requests only the following permissions on Android. Each one is used solely for the purpose described below.

PermissionWhy it is needed
INTERNET, ACCESS_NETWORK_STATETo talk to the App's servers and download lesson content
POST_NOTIFICATIONS (Android 13+)To show learning-reminder and streak notifications — only after you say yes
RECEIVE_BOOT_COMPLETEDSo that scheduled learning reminders are restored after your device restarts
VIBRATESubtle haptics on correct/incorrect answers

The App does not request: Microphone, Camera, Location, Contacts, SMS, Storage (legacy), or any “Restricted Permission” as defined by Google Play. Because it holds no SMS permission, you always type your OTP in yourself — the App cannot read your messages.

On Android 11 and above, the App also declares package-visibility queries for upi:// links and for the PhonePe app, so that it can hand you over to your UPI app to authorise a subscription mandate. These are not permissions and give the App no access to those apps or their data.

10. Children's privacy

Speak Up is intended for users aged 13 years and above.

  • We do not knowingly collect personal data from children under 13.
  • For users aged 13 to 17 (minors), the DPDP Act, 2023 requires the verifiable consent of a parent or lawful guardian before any personal data is processed. By using the App, a minor user confirms that such consent has been obtained.
  • We will not perform tracking, behavioural monitoring, or targeted advertising directed at minors.
  • If you are a parent or guardian and believe that a child under 13 has provided personal data through the App, or that consent was not properly given for a minor between 13 and 17, please email support@eight.network and we will delete the data promptly.

11. Push notifications

If you grant the notification permission, we may send you:

  • Daily streak reminders
  • Re-engagement nudges (after 3 days of inactivity, stopping after 7 days of no use)
  • Transactional updates (payment success, subscription expiry)

You can turn any of these off at any time from Settings → Notifications inside the App, or from your Android system settings.

12. Payments

Subscriptions are billed through PhonePe Limited using UPI Autopay, the recurring-mandate facility of the UPI network.

  • You authorise the mandate inside PhonePe or whichever UPI app you pick, and your UPI PIN, card number, and bank credentials are entered only there. We never see, transmit, or store them.
  • To start a subscription, the App hands you over to your UPI app (or shows a QR code you can scan with it). We share only the plan, the amount, and a merchant order reference with PhonePe.
  • We only receive the outcome of the mandate and of each charge (success/failure), the references PhonePe returns, your subscription plan, and the trial and renewal dates.
  • PhonePe's processing of your payment data is governed by its own privacy policy, available at https://www.phonepe.com/privacy-policy/. If you authorise the mandate in a different UPI app, that app's own privacy policy applies to what it collects.
  • For refunds, billing disputes, or chargebacks, email support@eight.network. We will respond within 7 working days.

13. Cookies and similar technologies

Speak Up is a native Android application and does not use browser cookies. It does use device-level identifiers (Firebase Installation ID, FCM token, and the pseudonymous app-instance ID used by Google Analytics for Firebase) for the purposes described in this Policy. These identifiers are reset if you reinstall the App, or if you clear the app's storage from Android system settings.

14. Changes to this Privacy Policy

We may update this Policy from time to time — for example, when new features are added, processors change, or to reflect changes in the law.

  • When we make a change, we will update the “Last updated” date at the top of this Policy.
  • If the change is significant (for example, a new category of data, a new processor, or a new purpose), we will give you advance notice in the App or by email and, where required by law, ask for your fresh consent.
  • The current version of this Policy is always available inside the App at Settings → Privacy Policy and at https://www.speakupnow.world/privacy.

15. Grievance Officer and contact details

If you have any questions, requests, or complaints about how your personal data is handled, please reach out — we want to help.

Eight Network Creations Private Limited has designated a Grievance Officer as required under Rule 5(9) of the Information Technology (Reasonable Security Practices) Rules, 2011 and Section 8(9) of the DPDP Act, 2023. Grievances reach the Grievance Officer through the contact details below.

  • Data Fiduciary: Eight Network Creations Private Limited
  • Attention: The Grievance Officer
  • Registered office: L-148, 5th Main Road, Sector 6, HSR Layout, Bengaluru, Bengaluru Urban — 560102, India
  • Email: support@eight.network

We will acknowledge your grievance within 48 hours of receiving it and resolve it within 30 days.

If you remain unsatisfied with our response, you have the right to escalate your complaint to the Data Protection Board of India under the DPDP Act, 2023.

Speak Up is built in India by Eight Network Creations Private Limited. Thank you for trusting us with your learning journey.

SpeakUp
Privacy PolicyTerms of Service
© 2026 Speak Up. Built for learners.
Eight Network Creations Private Limited