Privacy Policy
We collect an email address and the stories you choose to keep. That is close to all of it.
Last updated 12 September 2026
Who is responsible
Decyb Technology LLP, 4127 Palm City, Kohara, Ludhiana, Punjab, India, is the controller of the personal data described here. Reach us at contact@say-able.com.
What we collect
- Your email address, because it is how you sign in and how we reach you about your account.
- Sign-in codes and session tokens, stored only as keyed hashes. We cannot read a live code or session token out of our own database.
- Which stories you have saved, and when.
- Subscription records — which plan you are on, and the payment identifiers Razorpay gives us. We never receive your card number.
- Server logs, for security and debugging. These record identifiers, timestamps and status codes. They do not record request bodies, email addresses or the contents of what you read.
We do not sell or share your data for anyone else’s marketing, and we do not build a profile of you ourselves.
Analytics and advertising
If you agree to it, we use Google Analytics to understand how the site is used, and Google Ads to measure which advertising brings people here. Both are provided by Google, both set their own cookies, and both mean some information about your visit is sent to Google and processed on our behalf.
Nothing loads until you say yes. We ask once, in a banner, and until you answer we tell Google’s tag explicitly that it has no consent. Reading works exactly the same whichever you choose, and you can change your mind by clearing this site’s data in your browser.
What is sent, if you agree:
- Pages you open on this site, with the usual technical detail a browser provides — approximate location from your IP address, device and browser type, and how you arrived.
- That an account was created, when you sign up for the first time. Not which account, and not your email address.
- That a story was finished, with which story it was and how long it was.
What is never sent: your email address, your account identifier, the text of a story, or anything you record or write. We do not pass Google anything that identifies you to us.
What we do not collect
There is no password, so there is no password to leak. We do not ask for your name, address, date of birth or phone number, and we do not record audio. If that changes — spoken practice is on our roadmap — we will update this policy before it ships, not after.
Cookies
One cookie we set ourselves: vocab_session, which identifies your signed-in session. It is strictly necessary for the service to work, it is not readable by page scripts, and it is not used for tracking. Signing out clears it.
Two preferences kept in your browser, not as cookies and never sent to us: your answer to the analytics question, and how far you had read through a story if you are not signed in.
Third-party cookies are set by Google Analytics and Google Ads, and only if you agree to analytics. Decline and none are set.
Why we are allowed to hold it
- To perform our contract with you — running your account, your shelf and your subscription.
- Our legitimate interests — keeping the service secure and working, and preventing abuse of the sign-in process.
- Your consent — and only your consent — for analytics and advertising measurement. It is the one thing here you have to agree to before it happens, and declining costs you nothing.
- Legal obligation — keeping records of payments for as long as tax rules require.
Who else sees it
We use a small number of processors, each for one job:
- Razorpay — takes payments. They handle card details; we do not.
- Our email provider — delivers sign-in codes and account email.
- Our hosting provider — runs the servers and the database.
Stories are written with the help of a language model before publication. That happens in our authoring process, on our own material. Nothing you do on the site — what you read, what you save, your email address — is sent to a language model.
Where it is stored
Our servers and database are hosted with a provider that may process data outside your country. Where data leaves your region, we rely on the safeguards our providers offer for those transfers.
How long we keep it
- Sign-in codes — expire in ten minutes and are single-use.
- Sessions — expire thirty days after sign-in, or when you sign out.
- Account and shelf — until you ask us to delete them.
- Payment records — as long as tax and accounting rules require.
- Server logs — a short rolling window, then discarded.
Your rights
You can ask us for a copy of your data, ask us to correct it, or ask us to delete it. Deleting your account removes the account record and your shelf. We keep the minimum payment records the law requires, and we will tell you what those are.
Write to contact@say-able.com. We will respond within thirty days. If you are unhappy with our answer you can complain to your local data protection authority.
Children
The service is aimed at adult learners and we do not knowingly collect data from children. If you believe a child has created an account, tell us and we will remove it.
Changes
If we change this policy we will update the date above, and we will email account holders about a change that materially affects them.