This document is provided in English. The English version is the controlling version.
Draft pending final legal review.
Privacy Policy
debAIt Privacy Policy
Version 1.1 — Effective [EFFECTIVE DATE]
This Privacy Policy ("Policy") is published by [LEGAL ENTITY NAME], a Texas limited liability company ("debAIt", "we", "us", or "our"), and explains how we collect, use, disclose, and protect personal data in connection with the debAIt competitive debate platform, including our websites, applications, and related services (collectively, the "Service").
The English-language version of this Policy is the controlling version. We may provide a Spanish translation for convenience (una traducción al español puede proporcionarse únicamente como cortesía); in the event of any conflict, the English version governs, except where applicable Mexican or other local consumer-protection law requires the local-language or local-law version to prevail, in which case that law controls (see Section 17).
This Policy is incorporated into and supplements our Terms of Service ("Terms"). Defined terms used but not defined here have the meaning given in the Terms. Disputes, arbitration, and governing law — including the mandatory informal-resolution step, the small-claims carve-out, binding individual arbitration with class-action and class-arbitration waivers, the 30-day arbitration opt-out, the minors/guardian handling, and the non-waivable PROFECO rights of Mexican consumers — are governed exclusively by the "Dispute Resolution" section of the Terms and are not modified by this Policy. Nothing in this Policy waives any right that cannot be waived under applicable law (see Sections 12 and 17).
Table of Defined Terms
- "AI Outputs" — automated outputs generated by artificial-intelligence systems, including debate topics/motions, briefs, transcriptions, content-moderation results, per-turn scores, rationales, confidence values, and final verdicts.
- "Consumer User" — an individual who registers for and uses the Service directly (not through a School deployment).
- "GDPR" — the EU General Data Protection Regulation (Regulation (EU) 2016/679) and, where applicable, the UK GDPR.
- "LFPDPPP" — Mexico's Ley Federal de Protección de Datos Personales en Posesión de los Particulares.
- "Personal Data" — information that identifies, relates to, describes, or can reasonably be linked, directly or indirectly, to an identified or identifiable individual. This term is intended to be equivalent to "personal information" (CCPA/CPRA), "personal data" (TDPSA/GDPR), and datos personales (LFPDPPP).
- "School" — an educational institution or organization that licenses the debAIt for Schools product.
- "School Data" — Personal Data we process on behalf of a School in connection with the debAIt for Schools product, including student education records.
- "Sensitive Personal Data" / "Sensitive Personal Information (SPI)" — categories afforded heightened protection under applicable law, including biometric/voice data, account log-in credentials in combination with access information, and the Personal Data of children we know to be under 13.
- "Service Provider" / "Processor" — where we act on another party's documented instructions, the role described by the CCPA/CPRA ("service provider"), GDPR ("processor"), TDPSA ("processor"), and LFPDPPP (encargado).
- "Student" — an individual who accesses the Service through a School deployment, who may be a minor.
- "Subprocessor" — a third party engaged by us to process Personal Data on our behalf in support of the Service.
- "TDPSA" — the Texas Data Privacy and Security Act.
- "Voice Data" — audio recordings of a user's voice captured during a debate, together with derived transcripts and processing metadata.
1. Controller Identity, Contacts & Scope
1.1 Who we are. The entity responsible for the Personal Data described in this Policy is:
[LEGAL ENTITY NAME] [REGISTERED ADDRESS] Website: https://getdebait.com General support: [SUPPORT EMAIL] Privacy inquiries: [PRIVACY EMAIL] Legal / notices: [LEGAL/NOTICE EMAIL]
1.2 EU/UK representative. If and to the extent we are subject to the GDPR (for example, by offering the Service to individuals in the European Economic Area or United Kingdom), our representative for the purposes of Article 27 GDPR is: [EU REPRESENTATIVE if any].
1.3 Mexico privacy contact. For users in Mexico, our privacy contact (persona o departamento de datos personales) under the LFPDPPP is: [MEXICO PRIVACY CONTACT if any], reachable at [PRIVACY EMAIL]. This Policy, together with any point-of-collection notice we provide, is intended to function as our aviso de privacidad for Mexican users.
1.4 Scope. This Policy applies to: (a) Consumer Users who self-register; (b) visitors to our websites; (c) debAIt+ subscribers; and (d) Students and School personnel who use the debAIt for Schools product, as supplemented by Section 14 (Children's & Students' Privacy) and the Minors & Schools Addendum / School Data Processing Addendum referenced there. It does not apply to third-party services that have their own privacy policies (for example, Stripe, Google, or Discord) except as to data we receive from or send to them.
1.5 Geographic operation. We operate from the United States, with early product expansion to Mexico, and the Service is offered in English and Spanish. By using the Service, you understand that your Personal Data will be processed in the United States and other jurisdictions as described in Section 9.
2. Our Roles
2.1 Consumer Users — we are the controller/business. For Consumer Users, we act as the data controller (GDPR), controller (TDPSA), business (CCPA/CPRA), and responsable (LFPDPPP). We determine the purposes and means of processing your Personal Data.
2.2 School Data — we are a service provider / processor / "school official." For School Data processed through the debAIt for Schools product, we act:
- as a "service provider" and, where applicable, a designated "school official" with a legitimate educational interest under the Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. § 1232g; 34 C.F.R. Part 99, processing student education records under the School's direct control;
- as a "processor" under the GDPR (Art. 28), the TDPSA, and the LFPDPPP (encargado), processing School Data only on the documented instructions of the School;
- consistent with the California Student Online Personal Information Protection Act (SOPIPA, Cal. Bus. & Prof. Code § 22584) and Texas student data protection law (Tex. Educ. Code § 32.151 et seq.), including the prohibitions on selling student data, using covered information for targeted advertising, or building non-educational profiles of Students.
In this role, the School (and, for Students who are minors, the parent/guardian acting through the School) is the contracting party and the controller of School Data. Our processing of School Data is further governed by the data processing terms in the applicable School license / Data Processing Addendum ("School DPA"). In the event of any conflict between this Policy and the School DPA with respect to School Data, the School DPA governs.
3. Categories of Personal Data We Collect
We collect the following categories of Personal Data. Not every category applies to every user.
3.1 Account & authentication data.
- Email address (required, unique).
- Username / callsign (3–20 characters, unique; immutable for 90 days after a change).
- Display name (optional, public).
- Password — we do not store your password; authentication and password hashing are delegated to Supabase Auth. Where you sign in with Google or Discord (OAuth), we receive basic profile data (such as your email address and a username we may generate) from that provider in order to create and operate your account.
- Account type / internal role (e.g., user, teacher, brand, admin) and internal flags (e.g., public-figure flag, founding-member flag, simulator-account flag).
3.2 Profile data.
- Avatar (a preset identifier or a custom photo URL), profile banner image, bio (up to 200 characters), interests (up to 5), language/locale preference (English or Spanish; defaults to Spanish), and equipped cosmetic frame.
- Privacy preferences and notification preferences (see Sections 12–13 and 15).
3.3 Debate content & user-generated content (UGC).
- Posts (up to 600 characters, with up to 4 media attachments), comments (up to 1,000 characters), reactions, saves/bookmarks, hashtags, and @-mentions.
- Direct messages (up to 4,000 characters per message) and message metadata (read timestamps).
- Social-graph data: friend requests and their status, follows/followers, blocks, mutes, and co-presence "lobby" membership and invitations.
- Presence/activity state (online / debating / watching), refreshed approximately every 45 seconds with a roughly 90-second freshness window.
- Reports you file or that concern you (e.g., the reason, status, and the debate or user reported).
3.4 Voice recordings and transcripts. When you participate in a voice debate, we capture raw audio of your voice from your microphone and generate a text transcript, together with transcription metadata (quality indicators, duration estimates, codec/MIME type, and content-moderation flags). See Section 7 for our dedicated Voice & Biometric Data commitments.
3.5 AI-interaction data. Data generated by or sent to our AI systems, including: the debate motion/topic; per-turn and final scores, rationales, and confidence values; moderation results and categories; quote-fidelity and input-sanitization metadata; and cost/usage logs (e.g., audio seconds processed, model used, and computed cost) used for internal monitoring.
3.6 Engagement & gameplay data. XP, levels, wins/losses, win/loss streaks, Elo rating and peak, rank, achievements, unlockable avatars/frames, leaderboard standing, and monthly awards (which carry no cash value and are not redeemable, transferable, or purchasable). Engagement events are logged to support gameplay and product analytics.
3.7 Usage, device & log data. We and our infrastructure providers automatically collect technical data such as IP address, browser/device characteristics, timestamps, last-active time, referral/attribution codes (a referral code may be stored in a cookie during an unauthenticated visit and consumed at signup), session identifiers, and security and rate-limiting counters.
3.8 Cookies & similar technologies. Authentication session tokens are stored in HTTP-only cookies. See Section 15.
3.9 Payment data. For debAIt+ subscribers, we store a Stripe customer identifier, Stripe subscription identifier, subscription plan, status, billing-period end date, price reference, and cancellation flag. We do not store full payment-card numbers, CVV/security codes, or card expiration data — those are collected and processed directly by Stripe. See Section 8.
3.10 School Data (may include minors). For the debAIt for Schools product, we process Student account data, classroom enrollment and history, teacher-assigned debates and completion status, performance scores by rubric axis (e.g., logic, evidence, engagement, clarity, opening/closing), tournament and "School Cup" participation, debate transcripts and recordings, and moderation/conduct flags. For consumer debates, we capture audio for transcription and judging; retained video/clip recording occurs only where both participants have opted in through the in-product recording-consent controls (and, in Schools, only where the School enables it).
3.11 Sensitive Personal Data / SPI. Among the above, the following may constitute Sensitive Personal Data or Sensitive Personal Information under applicable law: Voice Data (treated as biometric/special-category data — see Section 7); account log-in credentials; and the Personal Data of children we know to be under 13, processed only within the Schools product. We do not request government identifiers, financial-account numbers, precise geolocation, health data, or data revealing racial or ethnic origin, religious or philosophical beliefs, sexual orientation, or political opinions as part of normal operation. However, debate content you choose to speak or write may reveal such information about you; we process that content only to operate the debate, judging, moderation, and safety features described in this Policy, and not to infer characteristics about you for any other purpose.
3.12 Age & location data. To confirm eligibility and operate optional features, we collect your date of birth (used to verify you meet minimum-age requirements, including the 18+ requirement for the optional aggregate-insights program described in Section 6A) and, where you choose to provide it, your self-reported country. Date of birth, once set, is not editable through the ordinary profile interface; the country field is optional and you can decline it and still use the Service.
4. Sources of Data
We collect Personal Data from the following sources:
- Directly from you — at registration, onboarding, profile setup, and when you debate, post, message, subscribe, or contact support.
- Automatically — through your use of the Service (usage, device, log, presence, and cookie data).
- From identity/OAuth providers — Google and Discord, when you choose to sign in with them, via Supabase Auth.
- From your School — for Students, account and roster data provided by the School, and classroom/assignment activity.
- From other users — for example, when another user mentions you, sends you a message or friend request, invites you to a lobby, or files a report concerning you.
- From Subprocessors — payment and subscription status from Stripe; transcription, moderation, and judging metadata from our AI and speech providers (see Section 8).
5. Purposes of Processing & Legal Bases
Where the GDPR or comparable law applies, we rely on the legal bases identified below. Under the LFPDPPP, processing is grounded in your consent and in the necessity of processing to provide the service you request, subject to the ARCO framework in Section 12. Under the CCPA/CPRA and TDPSA, we process Personal Data only for the purposes identified here and compatible purposes.
| # | Purpose | Categories used | GDPR legal basis (Art. 6 / Art. 9) |
|---|---|---|---|
| a | Create and authenticate your account; deliver the core Service | Account, profile, log | Art. 6(1)(b) contract |
| b | Conduct voice debates: capture audio, transcribe, and judge | Voice Data, debate content, AI-interaction | Art. 6(1)(b) contract; Art. 9(2)(a) explicit consent for voice/biometric processing (see §7) |
| c | Generate AI topics, briefs, scores, and verdicts | Debate content, AI-interaction | Art. 6(1)(b) contract |
| d | Operate the social layer (feed, friends/followers, messages, lobbies, presence) | UGC, social-graph, presence | Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interests in delivering social features |
| e | Gamification, leaderboards, achievements, monthly awards | Engagement/gameplay | Art. 6(1)(b) contract; Art. 6(1)(f) |
| f | Content moderation, safety, abuse/fraud prevention, rate-limiting | UGC, Voice transcripts, reports, log, security counters | Art. 6(1)(f) legitimate interests in a safe Service; Art. 6(1)(c) legal obligation where applicable |
| g | Process debAIt+ subscriptions and billing | Payment, account | Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation (tax/accounting) |
| h | Transactional communications (confirmations, password resets, service notices) | Account, contact | Art. 6(1)(b) contract; Art. 6(1)(c) |
| i | Optional notifications (friend requests, messages, achievements, match/verdict alerts, push) | Account, notification prefs | Art. 6(1)(f), subject to your toggles and quiet-hours settings; consent for browser/device push |
| j | Product analytics and improvement using aggregated and/or de-identified data | Usage, engagement | Art. 6(1)(f) legitimate interests (see §6) |
| k | Comply with law, respond to legal process, and protect rights and safety | Any, as necessary | Art. 6(1)(c); Art. 6(1)(f); Art. 9(2)(f) |
| l | Provide and administer the debAIt for Schools product | School Data | Processing as processor on the School's instructions (see §2.2) |
| m | Produce and license aggregate, de-identified insights and operate Sponsored Topics (Section 6A) | Engagement/gameplay and debate content, de-identified and limited to consenting adults | Art. 6(1)(a) consent (opt-in, revocable); not relied on as legitimate interests |
You may object to or withdraw consent for certain processing as described in Sections 7 and 12. Withdrawal does not affect processing already carried out and may prevent us from providing features that depend on it (for example, you cannot participate in a voice debate without permitting voice capture). Where we rely on legitimate interests, you may obtain information about our balancing assessment by contacting [PRIVACY EMAIL].
6. Artificial Intelligence & Model Training
6.1 How AI is used. The Service uses third-party AI providers through their application programming interfaces (APIs) to (a) transcribe debate audio to text, (b) moderate transcribed content, and (c) generate debate topics, per-turn scores, rationales, and final verdicts, and to provide AI practice coaching. Our current AI and speech providers are OpenAI (speech-to-text transcription and content moderation) and Anthropic (Claude models for judging and coaching). OpenAI is the provider that receives your debate audio for transcription.
6.2 We do not permit third-party AI providers to train their models on your content. We send your content to these providers only to obtain the output you request (a transcript, a moderation result, a score, a verdict, or coaching). We rely on our providers' API terms and data-processing agreements, under which content submitted via the API is not used to train their models unless we expressly opt in (which we do not). We do not sell your content or Voice Data for model-training purposes, and we do not authorize Subprocessors to do so. The separate, consent-based licensing of aggregate, de-identified insights described in Section 6A does not involve selling your individual content or Voice Data and is governed by that Section.
6.3 Our own product improvement. Any use by us of user content or Voice Data to improve the Service is limited to aggregated and/or de-identified data that does not reasonably identify you and is not used to reconstruct your voice. We do not create voiceprints or biometric templates for model training or any other purpose (see Section 7).
6.4 AI Outputs are automated and may be wrong — and how to contest them. AI Outputs — including verdicts and scores that affect your standing, XP, rank, and leaderboard position — are automated outputs that may be inaccurate, incomplete, or biased, are provided "AS IS," and do not constitute professional, legal, academic, or psychological advice. You should not rely on AI Outputs for any consequential decision. AI results are not official credentials except where a licensed School issues a diploma, grade, or report based in part on them. Our judging pipeline incorporates fairness controls (identity-blind judging in which your identity is not sent to the judge, position-shuffling, confidence scoring, and quote-fidelity checks), but these controls do not guarantee accuracy or freedom from bias. Where required by Article 22 GDPR, the TDPSA's profiling-opt-out right, or comparable law, you may request human review of, express your point of view on, or contest a consequential automated decision by contacting [PRIVACY EMAIL]. Outside of those legally required cases, verdicts are final automated outputs: there is no routine human review of individual verdicts and no formal in-product appeal; contested verdicts are handled through the support process, which may include a discretionary manual review or re-run.
6A. Aggregate Insights & Sponsored Topics
This Section describes an optional, consent-based use of Consumer User data to produce aggregate, de-identified insights that we license to third parties (such as brands and market-research firms), and the related Sponsored Topics feature. It applies only to Consumer Users who are adults (18 or older) and who have given specific, revocable consent. We never use for these purposes, and never license, the data of minors, Students, School Data, Voice Data, or any individual-level record.
6A.1 What we produce. With your consent, we analyze debate-engagement data (such as which side of a motion you argued, the kinds of reasons expressed, and engagement volume) to produce aggregate, de-identified, statistical insights — for example, "X% of 18–24-year-old participants in a given country argued in favor of a motion." These insights describe groups, not individuals.
6A.2 De-identification & k-anonymity. Insights are computed only over cohorts containing at least 100 consenting adult Consumer Users (with a higher threshold for narrower segments), so that no individual can be singled out or re-identified. We do not disclose to any third party your identity, username, account identifier, raw debate text, audio, or any individual-level data. The licensed output is irreversible aggregate statistics, and we provide no party any means to re-identify a participant.
6A.3 Excluded data and people (hard limits). We never include in these insights, and never license: (a) Voice Data (audio recordings or any voice biometric); (b) any School Data or Student data; (c) the data of anyone we know or reasonably believe to be under 18; (d) individual-level records or identifiers; and (e) sensitive categories — debate categories that may reveal political opinions, religious or philosophical beliefs, health, sexual orientation, or racial or ethnic origin are excluded from the saleable set. Our debate categories default to non-saleable and are individually cleared only where they are non-sensitive.
6A.4 Your consent and how to withdraw it. This processing happens only if you opt in. Your consent is specific to this purpose (internal purpose code data_insights), is version-gated (if we materially change this Section, your prior consent stops applying until you agree to the updated version), and is revocable at any time in your account settings (Settings → Data & privacy). On withdrawal, we stop including your data in future insights; aggregates already computed and licensed before withdrawal cannot be recalled, but they contain no individual-level data about you. You may also set a permanent exclusion that removes you from all such processing regardless of consent state.
6A.5 Sponsored Topics. Brands may pay us to introduce a neutral, balanced debate motion (a "Sponsored Topic") into the platform and to receive, in return, the same kind of aggregate, de-identified breakdown described above for that motion. Sponsored Topics are clearly and conspicuously labeled as sponsored wherever they appear, consistent with the U.S. Federal Trade Commission's Guides Concerning the Use of Endorsements and Testimonials (16 C.F.R. Part 255). They are shown only to consenting adult Consumer Users and are never shown within the Schools product or to Students. Participation is always voluntary, and we never disclose any individual participant's stance, vote, or identity to the sponsor.
6A.6 Our brand customers are contractually restricted. Every brand or research customer is bound by a Brand Data License Agreement that permits use of the aggregates only for market research and prohibits any attempt to re-identify individuals, any resale of the data, and any use to target individual users with advertising.
6A.7 Why this is not a "sale" of Personal Data. Licensing irreversible, de-identified aggregates is not a "sale" or "share" of Personal Data under the CCPA/CPRA, the TDPSA, or the LFPDPPP, because no Personal Data is disclosed to the recipient, only group-level statistics are licensed, and no recipient is given any means to identify or contact any individual. Our commitments in Sections 8 and 13 not to sell Personal Data remain fully in force.
7. Voice & Biometric Data (Texas CUBI and Related Law)
PLEASE READ THIS SECTION CAREFULLY. IT DESCRIBES HOW WE CAPTURE AND USE YOUR VOICE.
This Section governs Voice Data and applies in addition to the rest of this Policy.
7.1 What we capture and why. When you join a voice debate, your browser records audio from your microphone for the limited and exclusive purposes of (a) producing a text transcript of your debate turn and (b) enabling AI judging/scoring of the debate. We also use the debate motion as context for transcription and run automated content moderation on the resulting text.
7.2 Consent. We capture Voice Data only after you take an affirmative action to join and speak in a debate, and we present a recording notice and obtain your consent before recording begins: before your microphone is engaged in any judged debate or voice practice session, you must complete a conspicuous, timestamped recording acknowledgment confirming that your voice will be recorded, transcribed, and scored by AI. The acknowledgment is recorded against your debate participation and the debate room, video token issuance, and voice upload are each refused until it exists. This acknowledgment is separate from the optional, mutual opt-in that governs any retained video/clip recording. Under Article 9 GDPR, the CCPA/CPRA (sensitive personal information), and the LFPDPPP (datos personales sensibles), we treat voice as sensitive/special-category data and rely on your explicit consent for its capture and processing. You may decline; if you decline, you cannot participate in voice debates.
7.3 Texas Capture or Use of Biometric Identifier Act (CUBI), Tex. Bus. & Com. Code § 503.001. To the extent a recording of your voice constitutes a "biometric identifier" under CUBI, we make the following commitments:
- Notice and consent before capture. We will not capture your voice for a commercial purpose without first providing notice and obtaining your consent.
- Purpose limitation. We use Voice Data only for the transcription and judging purposes stated in Section 7.1. We do not create a voiceprint or biometric template, and we do not use your voice as a biometric identifier to identify or authenticate you, beyond the stated transcription/judging functionality.
- No sale. We do not sell, lease, trade, or otherwise disclose your voice biometric identifier for value, except as narrowly permitted by § 503.001 (for example, with your consent, or as required to comply with a warrant or other law).
- Reasonable protection. We store and transmit Voice Data using reasonable care that is at least as protective as the manner in which we store and transmit other confidential and sensitive information, consistent with the security measures described in Section 11.
- Destruction within the statutory period. We will destroy any biometric identifier within CUBI's scope within a reasonable time, and in any event no later than one (1) year after the date the purpose for collecting the identifier expires, consistent with § 503.001(c)(3). Our raw-audio retention schedule (Section 7.4) is shorter than this statutory maximum.
If at any point in the future we were to create voiceprints or use voice for identification, we would first obtain separate, informed consent, update this Policy, and set an express destruction timeline. We currently do not do so.
7.4 Retention & destruction schedule for Voice Data.
- Raw audio recordings are stored in a private storage bucket for a limited dispute-review and fairness-audit window of 30 days after the debate, after which they are automatically and permanently deleted by an automated cleanup process.
- Transcripts and derived scores are retained as part of the debate record (see Section 10).
- Upon account deletion, Voice Data associated with your account is deleted or de-identified as described in Sections 10 and 12, subject to the cascade and audit-log exceptions noted there.
7.5 Content-moderation caveat. Automated moderation may produce false positives, particularly on heated political, religious, or social topics that are central to debate. Only a narrow set of severe categories excludes a turn from final judging; other flags affect only spectator captions. Moderation outcomes are AI Outputs subject to the disclaimers in Section 6.4, and you may contest a moderation decision via [SUPPORT EMAIL].
8. How We Share Data & Subprocessors
8.1 We do not sell your Personal Data. We do not sell Personal Data for money or other valuable consideration, and we do not "share" Personal Data for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We do not use Personal Data for targeted advertising under the TDPSA, and we do not sell or process School Data or student data for advertising under SOPIPA / Tex. Educ. Code § 32.151 et seq. See Sections 6A (consent-based licensing of aggregate, de-identified insights, which is not a sale of Personal Data) and 13.
8.2 Subprocessors. We engage the following categories of Subprocessors to provide the Service. Each is bound by contractual confidentiality and data-protection obligations and may process Personal Data only on our instructions and for the purposes below. We maintain a current Subprocessor list and update it as Subprocessors change.
| Subprocessor | Function | Data shared |
|---|---|---|
| Supabase | Authentication, Postgres database, realtime, and file/object storage | Account, profile, UGC, social-graph, debate content, transcripts, raw audio (private bucket), subscription state |
| Vercel | Application hosting and serverless/scheduled functions | Request, usage, and log data incidental to serving the app |
| OpenAI | Speech-to-text transcription and/or text content moderation | Raw debate audio and the debate motion (transcription); transcribed text (moderation) |
| Anthropic | AI judging (per-turn and final verdict) and practice coaching | Sanitized, identity-blind debate transcript and debate metadata |
| LiveKit | Real-time voice/video debate rooms and, where recording is enabled by consent or by a School, recording egress | Live audio/video streams; recording storage where applicable |
| Stripe | Payment processing and subscription management for debAIt+ | Email and payment/card details (collected by Stripe directly); we receive only Stripe identifiers and subscription status |
| Resend | Transactional email (confirmations, password resets, service notices) | Email address and message content |
| Railway | WebSocket transport for real-time debate communication | Connection/session data incidental to real-time messaging |
8.3 Other disclosures. We may disclose Personal Data:
- Legal & safety — to comply with law, legal process, or enforceable governmental requests; to enforce our Terms; and to protect the rights, property, or safety of debAIt, our users, or the public, including for fraud prevention and abuse/safety investigations.
- Within Schools — to the relevant teacher, school administrator, and (through the School) parents/guardians, as part of the educational service (for example, gradebooks, reports, and moderation queues).
- Business transfers — in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to this Policy or a successor policy with comparable protections, and with notice where required by law. Voice Data, School Data, and the data of known minors will be transferred only subject to commitments at least as protective as those in this Policy and the applicable School DPA.
We do not otherwise disclose your Personal Data to third parties for their own independent purposes.
9. International Data Transfers
We operate from the United States and process Personal Data there. As we expand to Mexico and serve users in other countries, your Personal Data may be transferred to, stored in, and processed in the United States and in countries where our Subprocessors operate.
- Mexico ↔ US: transfers of data of users in Mexico to the United States are made consistent with the LFPDPPP, including the disclosures in this Policy, which forms part of our aviso de privacidad. Nothing in this Section limits the non-waivable rights of Mexican consumers under the Ley Federal de Protección al Consumidor (see Section 17).
- EEA/UK ↔ US (if applicable): where the GDPR applies, transfers outside the EEA/UK are made under appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, together with any supplementary measures required by applicable law.
You may request information about the safeguards applicable to transfers of your Personal Data by contacting [PRIVACY EMAIL].
10. Data Retention
We retain Personal Data for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements.
- Account & profile data — retained while your account is active and deleted or de-identified on account deletion, subject to the exceptions below.
- Raw debate audio — automatically deleted 30 days after the debate (see Section 7.4).
- Debate transcripts, scores, and verdicts — retained as part of your debate history.
- Direct messages — currently retained with a soft "read" marker and no automatic purge.
- Subscription & payment-reference data — retained as long as needed for the subscription relationship and for tax, accounting, and audit obligations; Stripe retains card data under its own policies.
- Security, cost-ledger, and forensic/audit logs — retained for security, fraud-prevention, and compliance purposes; certain audit-level records are intentionally not deleted when an account is deleted, and are retained only as long as necessary for those purposes.
- Presence data — short-lived (a roughly 90-second freshness window) and overwritten by ongoing activity.
When we no longer need Personal Data, we delete or de-identify it. Backups containing Personal Data are deleted on a rolling basis according to our backup cycle.
11. Security & Breach Handling
11.1 Security measures. We implement reasonable administrative, technical, and physical safeguards designed to protect Personal Data, including: encryption of data at rest (database and storage) and in transit; HTTP-only session cookies and delegated authentication via Supabase Auth; row-level security policies restricting access to data; service-role-only writes for sensitive tables (for example, notifications and subscription records); private storage buckets and signed, time-limited upload URLs for audio; password-strength requirements; durable, cross-instance rate-limiting on sensitive endpoints (for example, signup, login, and account deletion); and least-privilege access controls. The columns containing email and internal role are restricted so that authenticated users cannot enumerate other users' email addresses through the API.
11.2 No guarantee. No method of transmission or storage is completely secure. While we strive to protect your Personal Data, we cannot guarantee absolute security. You are responsible for keeping your credentials confidential.
11.3 Breach notification. In the event of a breach of security involving Personal Data, we will investigate and notify affected users and the appropriate authorities where and as required by applicable law, including the TDPSA, the Texas Identity Theft Enforcement and Protection Act (Tex. Bus. & Com. Code Ch. 521), other applicable U.S. state breach-notification statutes, GDPR Articles 33–34, and the LFPDPPP, within the timeframes those laws require.
12. Your Privacy Rights & How to Exercise Them
Depending on where you live and which law applies, you may have some or all of the rights below. To exercise any right, contact [PRIVACY EMAIL]. You may also use the in-product tools: data export (a downloadable JSON copy of your profile, posts, comments, debates, friendships, follows, messages, and notifications) and account deletion (irreversible; requires confirming your username and cascades deletion across your linked records, subject to the audit-log and legal-retention exceptions in Section 10). Exercising your rights will not result in discriminatory treatment.
12.1 Verification & timelines. We will verify your identity before acting on a request, typically by confirming control of your account email. We respond within the timeframes required by applicable law — generally 45 days under the CCPA/CPRA and TDPSA (extendable by an additional 45 days with notice), one month under the GDPR (extendable by two further months for complex requests), and, under the LFPDPPP, within 20 business days to respond to an ARCO request and 15 business days thereafter to give effect to it. We do not charge a fee unless a request is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or decline as permitted by law.
12.2 California (CCPA/CPRA). You have the right to: know/access the categories and specific pieces of Personal Data we collect, use, and disclose; delete your Personal Data; correct inaccurate Personal Data; opt out of the sale or sharing of Personal Data and of cross-context behavioral advertising (we do not sell or share — see Section 13); limit the use of Sensitive Personal Information to permitted purposes (we use SPI such as Voice Data only for the limited purposes in Sections 5 and 7); and to non-discrimination for exercising your rights. You may use an authorized agent to submit requests, subject to verification.
12.3 Texas (TDPSA). You have the right to: confirm whether we process your Personal Data and access it; correct inaccuracies; delete Personal Data; obtain a portable copy; and opt out of (i) targeted advertising, (ii) the sale of Personal Data, and (iii) profiling in furtherance of decisions that produce legal or similarly significant effects. Appeal: if we decline to act on your request, you may appeal by writing to [PRIVACY EMAIL] with "TDPSA Appeal" in the subject line; we will respond within 60 days and, if we deny your appeal, we will provide an online method for you to contact the Texas Attorney General to submit a complaint (see Section 17).
12.4 EU/UK (GDPR). You have the right to: access; rectification; erasure ("right to be forgotten"); restriction of processing; data portability; objection to processing based on legitimate interests or to direct marketing; rights related to automated decision-making (Section 6.4); and to withdraw consent at any time (including for Voice Data) without affecting the lawfulness of prior processing.
12.5 Mexico (LFPDPPP — ARCO). You have ARCO rights: Acceso (access), Rectificación (correction), Cancelación (deletion/blocking), and Oposición (objection), plus the right to revoke consent and to limit the use or disclosure of your data. Submit ARCO requests to [MEXICO PRIVACY CONTACT if any] / [PRIVACY EMAIL] with the information required under the LFPDPPP (your identification, the data at issue, and the right invoked). Nothing in this Policy or our Terms waives any non-waivable right under Mexican law — see Section 17.
12.6 Brazil (LGPD — forward-looking). If and when we serve users in Brazil, data subjects will have the rights afforded by the Lei Geral de Proteção de Dados (Lei nº 13.709/2018), including confirmation of processing, access, correction, anonymization/deletion, portability, information about sharing, and revocation of consent, exercisable via [PRIVACY EMAIL].
12.7 Students & parents. Rights in School Data are generally exercised through the School; see Section 14 and the Minors & Schools Addendum.
13. Do Not Sell or Share / Targeted-Advertising Opt-Out
We do not sell your Personal Data, we do not share it for cross-context behavioral advertising, and we do not use it for targeted advertising. We do not sell or process student data for advertising or build advertising profiles of Students. Because we do not engage in these activities, no opt-out is currently necessary. If our practices ever change, we will update this Policy, provide a "Do Not Sell or Share My Personal Information" mechanism, honor opt-out preference signals such as Global Privacy Control (GPC) where required, and obtain any consent the law requires — including affirmative opt-in consent for any sale or sharing of the Personal Data of consumers we know to be under 16, as required by the CCPA/CPRA (and, for those under 13, parental consent).
Aggregate insights (Section 6A). Separately, with the opt-in consent of adult Consumer Users (18+), we license aggregate, de-identified insights to brands and researchers as described in Section 6A. As explained there, this is not a sale or share of Personal Data, involves no individual-level data, and you may withdraw consent at any time in Settings → Data & privacy.
14. Children's & Students' Privacy
CHILDREN UNDER 16 MAY USE THE SERVICE ONLY THROUGH A LICENSED SCHOOL, WITH PARENTAL/GUARDIAN CONSENT OBTAINED THROUGH THE SCHOOL.
14.1 Minimum age for public use. The public, self-signup Service is intended for users age 16 and older. By creating a Consumer account, you represent that you are at least 16 years old. We collect your date of birth at signup and our systems refuse to create a Consumer account for anyone under 16; your date of birth cannot be changed after signup. If we learn that a person under 16 has created a Consumer account outside of a School deployment, we will disable the account and delete the associated Personal Data.
14.2 Under-16 and under-13 access only through Schools. Users under 16 may access debAIt only through a licensed School deployment, with appropriate School authorization and verifiable parental or guardian consent obtained through the School.
14.3 COPPA (children under 13). Within the debAIt for Schools product, where we collect personal information from children under 13, we rely on the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6506; 16 C.F.R. Part 312. Consistent with FTC guidance for the educational context, we rely on the School to provide or obtain verifiable parental consent as the parents' authorized agent, limit collection to what is reasonably necessary for the educational service, do not condition a child's participation on disclosing more information than is reasonably necessary, do not use children's data for targeted advertising or to build non-educational profiles, and provide parents (through the School) the ability to review and request deletion of their child's information.
14.4 FERPA & student records. Student education records are processed under the FERPA framework described in Section 2.2. The School controls disclosure of education records; we act under the School's direction as a "school official" with a legitimate educational interest and do not re-disclose education records except as the School directs or the law permits.
14.5 SOPIPA & Texas student data law. For students, we comply with SOPIPA and Tex. Educ. Code § 32.151 et seq., including prohibitions on selling student data, using covered information for targeted advertising, and creating advertising profiles, and including applicable security and deletion obligations.
14.6 GDPR / LGPD child consent (if applicable). Where the GDPR applies, processing of a child's data based on consent requires consent or authorization of a parent/guardian for children below the applicable age of digital consent (16, or a lower age set by a Member State, down to 13); where the LGPD applies, processing of children's and adolescents' data is in their best interest and, for children, requires specific consent from a parent/guardian. Within Schools, such consent is obtained through the School.
14.7 Parental/guardian rights. Parents and guardians may, through the School, review their child's information, request corrections or deletion, and refuse further collection. Direct such requests to the School or to [PRIVACY EMAIL], and we will coordinate with the School.
14.8 Cross-reference. This Section is supplemented by the Minors & Schools Addendum / School DPA, which governs the School–debAIt relationship in detail.
15. Cookies & Similar Technologies
We use strictly necessary cookies and similar technologies to operate the Service, including:
- Authentication cookies — HTTP-only cookies that store your session (login) token.
- Referral/attribution cookie — a short-lived cookie that records a referral code when you arrive via a referral link, consumed at signup.
- Preference storage — local storage of settings such as your language/locale and certain UI preferences.
We do not use third-party advertising or cross-site tracking cookies. Where required by law, we will request consent for any non-essential cookies and provide controls. You can manage cookies through your browser settings, although disabling essential cookies will prevent the Service from functioning.
16. Changes to This Policy
We may update this Policy from time to time. When we make material changes, we will update the version and effective date at the top and notify you by reasonable means (for example, by email to your registered address or by an in-product notice) before the changes take effect, where required by law. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy, except where additional consent is required by law (for example, for new processing of Voice Data or any new processing of a known minor's data), in which case we will obtain that consent before relying on the change.
17. Complaints & Non-Waivable Rights
17.1 Contact us first. If you have a concern about how we handle your Personal Data, please contact us at [PRIVACY EMAIL] so we can try to resolve it.
17.2 Non-waivable consumer rights. Nothing in this Policy or our Terms — including any governing-law, language, arbitration, or class-waiver provision in the Terms — waives, limits, or overrides any right that cannot be waived under applicable law. In particular, Mexican consumers retain all non-waivable rights under the Ley Federal de Protección al Consumidor, and may pursue remedies before PROFECO (Procuraduría Federal del Consumidor) and other Mexican consumer-protection venues notwithstanding any other provision. Likewise, statutory privacy rights under the CCPA/CPRA, TDPSA, GDPR, and LFPDPPP cannot be waived by contract.
17.3 Supervisory authorities. You also have the right to lodge a complaint with a regulator:
- United States — Texas: the Office of the Texas Attorney General, Consumer Protection Division, regarding the TDPSA and Texas privacy and breach laws (https://www.texasattorneygeneral.gov/).
- United States — California: the California Privacy Protection Agency and the California Attorney General.
- United States — FTC: the Federal Trade Commission, for COPPA and federal consumer-protection matters.
- Mexico: the Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI) for LFPDPPP/ARCO matters, and PROFECO for consumer matters.
- EU/UK (if applicable): your local Data Protection Authority, or the UK Information Commissioner's Office (ICO).
- Brazil (if applicable): the Autoridade Nacional de Proteção de Dados (ANPD).
18. Contact
Questions, requests, or complaints regarding this Policy or your Personal Data:
[LEGAL ENTITY NAME] Attn: Privacy [REGISTERED ADDRESS] Privacy: [PRIVACY EMAIL] Legal / notices: [LEGAL/NOTICE EMAIL] Support: [SUPPORT EMAIL] EU/UK representative (if any): [EU REPRESENTATIVE if any] Mexico privacy contact (if any): [MEXICO PRIVACY CONTACT if any]
Copyright/DMCA notices are handled under the "Copyright / DMCA" section of our Terms of Service; our designated agent is [DMCA AGENT NAME], [DMCA EMAIL]. The DMCA notice-and-takedown procedure (17 U.S.C. § 512) is set out in the Terms, not in this Privacy Policy.
This Privacy Policy is provided in English as the controlling version; a Spanish translation may be made available for convenience only, subject to Section 17.
Version 1.1 — Effective [EFFECTIVE DATE].