Privacy Policy
Last updated: 17 August 2026
This policy explains what personal data Listening, no kidding(“we,” “us”) collects when you use our platform, why we collect it, who we share it with, and the rights you have over it. It is written to be read, not to be survived — if anything here is unclear, email us and we will explain it.
Teachers, read this before you run a live session.
Students choose a name or nickname when they join a live session — we do not ask for a real name. While the session is running, that name and the student’s answers are visible to you as the teacher. The moment you end the session, we delete both permanently: see section 5.
1. Who is responsible for your data
Vito Schiuma, trading as Listening, no kidding, Strada Giovinazzo-Terlizzi, 70038 – Terlizzi (BA), Italy, is the data controller for personal data described in this policy, except where section 1.2 says otherwise.
1.1 Teachers and individual subscribers
If you signed up yourself — on the free plan or a paid one — we are the controller of your account data. We decide what data the platform collects and how it works, so the responsibility is ours, not yours.
1.2 Schools and institutions
Where a school, university or language centre deploys the platform for its own students and signs our Data Processing Addendum, that institution is the controller for its students’ data and we act as its processor, handling that data only on the institution’s documented instructions.
If no DPA is in place, we remain the controller and this policy governs in full. Signing a DPA is free — write to privacy@listeningnokidding.com.
1.3 Privacy contact
Our privacy contact is Vito Schiuma, reachable at privacy@listeningnokidding.com. We are not required to appoint a statutory Data Protection Officer under Article 37 GDPR and have not done so; this is a named contact, which is what the law asks of an operation our size.
2. What we collect, and why
A. Data you give us
- Account data. Your email address, password (stored only as a hash by Firebase Authentication, never in readable form), display name and role. Needed to create and secure your account.
- Lesson content. The prompts, topics, scripts, uploaded audio and imported transcripts you use to build lessons, plus the lessons themselves. This is the core of the product.
- Classroom data. Class names, lesson assignments and the progress records attached to them.
- Billing data.If you subscribe, your email address and subscription status. Card details go directly to Stripe and never reach our servers — we store only Stripe’s customer identifier and your current plan.
- Support messages. What you write to us, so we can reply.
B. Data we collect automatically
- Usage and metering data.Which features you use and how much AI generation you consume, counted against your plan’s monthly credit allowance. We need this to enforce plan limits and to bill correctly.
- Technical data. IP address, browser and device type, and server logs, collected when you connect. Used for security, abuse prevention and rate limiting.
- Cookies and local storage. A short list, all of it strictly necessary. See the Cookie Policy.
C. What we do not collect
We run no advertising, no analytics or tracking pixels, no third-party marketing tags, and no profiling. We do not sell personal data and we do not make automated decisions that produce legal or similarly significant effects.
3. Legal bases (Article 6 GDPR)
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the platform and your account | Account data, lesson content, classroom data | Performance of a contract (Art. 6(1)(b)) |
| Taking payment and managing subscriptions | Billing data, usage and metering data | Performance of a contract (Art. 6(1)(b)) |
| Running live classroom sessions | The name a student chooses, their answers, participation timestamps | Performance of a contract with the teacher or school (Art. 6(1)(b)); where we are processor, the institution’s own basis, normally public task or consent |
| Security, abuse prevention, rate limiting | Technical data, IP address | Legitimate interests (Art. 6(1)(f)) — keeping the service available and unabused |
| Fixing bugs and improving the product | Aggregated usage data, error logs | Legitimate interests (Art. 6(1)(f)) |
| Meeting tax, accounting and legal duties | Invoices and transaction records | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have weighed those interests against your rights and you may object at any time (section 8). We do not rely on consent for anything except optional marketing email, which you can withdraw with one click.
4. Who we share data with
We do not sell personal data. We share it only with the vendors that run parts of the service for us, each under a contract that binds them to process data only on our instructions. The current list, with what each one receives:
| Provider | Purpose | Data shared |
|---|---|---|
| Google Cloud / Firebase (Google Ireland Ltd) | Hosting, database (Firestore), authentication, file storage | Account data, lesson content, live-session data including student names |
| Google (Gemini API) | Generating lesson text, comprehension questions and synthetic speech | Lesson prompts and source transcripts you submit |
| OpenAI, L.L.C. (Whisper) | Speech-to-text transcription of audio you upload or import | The audio file and its resulting transcript |
| Stripe Payments Europe, Ltd. | Subscription payments, invoicing and the billing portal | Email address, billing details, payment card data (collected by Stripe, never by us) |
| Podcast Index | Searching podcast episodes when you build a lesson from a podcast | Your search terms only — no account data |
| Google Fonts | Serving the typefaces used by the interface | Your IP address and browser user-agent, as part of the font request |
The always-current version of this list, including locations and transfer safeguards, is on the sub-processors page. We also disclose data where the law requires it, and would transfer it as part of a merger or sale of the business — with notice to you beforehand.
5. Live classroom sessions and student data
Live sessions are designed so that nothing about a student outlives their class. A student picks a name or nickname to join with, the teacher can download the results before ending the session, and once the session ends we delete the student’s name and every individual answer from our servers.
5.1 What happens while a session is running
When a student joins a session with a code or QR code, the platform:
- asks for a name or nicknameof the student’s choosing — we do not ask for, and the form does not request, a full legal name;
- creates an anonymous Firebase Auth user (no email, no password) and sets the entered name as its display name;
- stores that name, join time and last-seen time in the session’s participant record, for the duration of the session;
- stores each answer the student submits, tagged with their chosen name, for the duration of the session;
- saves the name and participant id in the browser’s local storage, so a refresh does not eject the student from the session.
The teacher who owns the session sees participant names and their individual answers while the session is live, and can export a PDF of the results at any point before ending it.
5.2 Deletion at the end of the session
When the teacher ends the session, we immediately and permanently deleteevery participant’s name and every individual answer from our servers. What remains is an anonymous count — how many people took part, and how the class did on each question — with no name, no per-student row, and nothing that identifies a particular student. That is what lets the teacher’s own analytics keep working without any student’s data being retained.
If a teacher starts a session and never explicitly ends it, we purge it automatically within 24 hours of it starting, so an abandoned session cannot leave student data on our servers indefinitely. Nothing about a specific student is kept beyond their class.
5.3 What teachers must do
If your students are minors, you or your institution are responsible for having a lawful basis for running the session before you do so. In Italy a child can consent to information-society services from age 14 (Article 8 GDPR as implemented by D.lgs. 101/2018); below that age, parental consent is required. Other EU states set the threshold between 13 and 16. Where a school is the controller, this is a matter for the school’s own privacy notice and its DPA with us.
6. AI processing of your content
Lesson generation sends your prompts, scripts and transcripts to Google’s Gemini API; audio you upload or import is sent to OpenAI’s Whisper API for transcription. Both are paid API services whose terms state that submitted data is not used to train their models. We do not use your lesson content to train any model of our own.
Do not paste personal data about identifiable students — assessments, health or behavioural notes — into a lesson prompt. The feature is not built for that.
What the AI produces, how it is labelled, and where it can go wrong is set out on the How we use AI page.
7. How long we keep data
| Data | Retention |
|---|---|
| Account and profile | Until you delete your account |
| Lessons and classroom data | Until you delete them, or until account deletion |
| Live-session participant names and individual answers | Deleted when the teacher ends the session — automatically within 24 hours if the session is never ended. An anonymous, per-question count is kept afterwards; see section 5.2. |
| Usage and credit-metering records | 24 months, for billing disputes and capacity planning |
| Invoices and payment records | 10 years, as Italian tax law requires |
| Server and security logs | 90 days |
| Support correspondence | 24 months from the last message |
8. Your rights
Under the GDPR you have the right to access your data, correct it, have it erased, restrict or object to how we process it, receive a portable copy, and withdraw any consent you have given. You can exercise all of these by emailing privacy@listeningnokidding.com. We answer within one month.
You can delete your account yourself from your profile page. Doing so removes your account, lessons, classrooms, progress records, live sessions, and your usage records. Invoices are retained where tax law requires it, and your Stripe subscription is cancelled.
If we are acting as processor for your school, send your request to the school first; we will help them answer it.
You may also complain to a supervisory authority. Ours is the Garante per la protezione dei dati personali (www.garanteprivacy.it), and you may instead complain to the authority where you live or work.
9. International transfers
Some of our providers process data in the United States. Those transfers rely on the European Commission’s Standard Contractual Clauses, and on the EU-US Data Privacy Framework where the provider is certified under it. The sub-processors page names the safeguard for each one. You can ask us for a copy of the relevant clauses.
10. Security
Accounts are authenticated by Firebase Authentication; session cookies are HTTP-only, Secure and SameSite-restricted. Data is encrypted in transit and at rest by Google Cloud. Firestore security rules enforce document-level ownership, and server-side code checks ownership again on every request rather than trusting the browser. Access to production data is limited to those who need it.
No system is perfectly secure. If a breach puts your rights at risk we will notify the Garante within 72 hours and tell you directly where the law requires it. Report a suspected vulnerability to support@listeningnokidding.com.
11. Children
Accounts are for teachers and adults; we do not knowingly let under-18s create one. Students take part in live sessions without an account and without a real name, under the supervision of their teacher or institution, as section 5 describes. If you believe a child has given us personal data without a proper basis, tell us and we will delete it.
12. Changes and contact
We will post any change here and update the date at the top. For material changes we will email you or show a notice in the app before they take effect.
Vito Schiuma
Strada Giovinazzo-Terlizzi
70038 – Terlizzi (BA)
Italy
Privacy: privacy@listeningnokidding.com
Support: support@listeningnokidding.com