legal
privacy policy
Matraca is a keyboard. That means we take privacy seriously from the very first keystroke. Here's the plain version of what we collect, what we never touch, and what you can demand from us.
last updated: july 2026
who we are
Matraca is a bilingual iOS keyboard app that translates while you type and keeps you practicing in real conversations. This policy explains how we handle your personal data when you use the app, the keyboard, and our website.
The entity behind Matraca is based in São Paulo (Brazil) and Lisbon (Portugal) and acts as the controller of the data described here. For anything privacy-related, reach us at contato@matraca.ai.
the keyboard and full access
This is the most important part, so no hedging. To translate while you type, the Matraca keyboard needs the "Full Access" permission that iOS requests when you install a third-party keyboard. We know that permission is scary, and it deserves an honest explanation.
When you grant Full Access and you're typing inside a Matraca translation field, the text you write is processed to produce the translation — partly on the device itself, and partly in our translation infrastructure when the language requires it. That processing exists for one reason only: to hand you the sentence back in the other language.
What we do NOT do, and never will:
- We do not log or store what you type in password fields, credit card fields, or any field iOS marks as secure — the keyboard is disabled in those contexts.
- We are not a keylogger: we do not silently capture everything you type in other apps outside of Matraca's translation flow.
- We do not sell, rent, or trade what you type. Your keystrokes are not a product.
- We do not use the content of your messages for targeted advertising.
Text sent for translation always travels encrypted and is used only to produce the response and run app features (like your practice history and streak). You can revoke Full Access at any time in iOS Settings — without it, the keyboard's translation features stop working.
what we collect
We collect the minimum needed to make the app work and improve it:
- Account data: the name or handle, email, and login credentials you provide when you create an account.
- Text processed for translation: the sentences you write in the translation flow, and their translations, tied to your account to power history and practice.
- Audio and transcription: when you voluntarily start a voice feature, we capture your recording and generate a text version to provide the requested feature.
- Streak and social data: consecutive days, completed chapters, friend connections, and the friendly pressure that keeps the conversation going.
- Usage analytics: how you move through the app, which features you use, and error reports — aggregated wherever possible.
- Device data: model, iOS version, language, technical identifiers, and diagnostics.
audio, microphone, and transcription
Matraca captures audio only when you voluntarily start a voice feature and while recording is active. iOS microphone permission is requested before the first capture. The temporary file created on the device is deleted after upload, and the audio travels encrypted to Matraca's backend.
Our backend validates the account and request, then sends the audio to one of the transcription providers below. The purpose of this processing is to turn your speech into text to fill in your answer, generate the requested translation, and, when offered by the feature, provide learning feedback. We do not intentionally store raw audio in our database or log its contents.
- AssemblyAI — receives the audio to produce the transcript. As soon as a transcript is completed, or fails after being created, we send an API request to delete the transcript artifact and its associated audio file. If immediate disposal cannot be completed, AssemblyAI states that automatic deletion of uploaded audio begins after 24 hours and completes within 48 hours; limited metadata may be retained for logging and billing.
- Deepgram — receives the audio to produce the transcript. Every Matraca request uses the mip_opt_out option, which excludes the content from its model-improvement program; according to Deepgram, data from these requests is retained only for the time needed to process them.
- OpenAI — does not receive raw audio. When needed for translation, language conversion, or learning feedback, it may receive only the transcript and the languages involved. We send these requests with application-state storage disabled (store=false). OpenAI does not use API data to train its models by default, but may retain content in abuse-prevention logs for up to 30 days, unless a longer period is required by law or reasonably needed for safety.
You can revoke microphone access at any time in iOS Settings > Privacy & Security > Microphone > Matraca. This prevents new recordings and disables features that rely on voice without affecting features that do not use the microphone. To request deletion of a transcript or other data tied to your account, email contato@matraca.ai.
how we use your data
We use your data to:
- Operate the keyboard and deliver translations while you type.
- Transcribe audio you choose to record and provide the requested voice features.
- Maintain your account, streak, chapters, and connections.
- Process subscriptions and payments.
- Improve the product, fix bugs, and understand what works.
- Send important service notices and, with your consent, product news.
- Comply with legal obligations and protect against fraud and abuse.
legal bases
We process your data on the basis of contract performance (delivering the app and feature you requested), your consent (where applicable, including microphone access), our legitimate interests (security, product improvement, fraud prevention), and compliance with legal obligations. Under LGPD and GDPR, you can withdraw consent at any time.
third parties and processors
We don't work alone. To run Matraca, we share strictly necessary data with providers acting as processors, under contract and confidentiality obligations:
- Stripe — payment and subscription processing.
- Google Cloud and Firebase — authentication, backend, database, and secure service hosting.
- AssemblyAI and Deepgram — transcription of audio voluntarily submitted through voice features.
- OpenAI — processing of text and, where applicable, transcripts for translation, language conversion, and learning feedback; raw audio is not sent.
- Analytics and error-reporting providers — to understand usage and stability.
- Apple — App Store distribution and, when you subscribe there, billing management.
We do not sell your personal data to anyone.
payments via stripe
Payments are processed by Stripe. Your card details are collected and handled directly by Stripe under PCI-DSS standards — Matraca does not store your full card number. We receive from Stripe only what we need to manage your subscription, such as payment status and the last digits of your card. Subscriptions made through the App Store are managed by Apple under its policies.
data retention
Raw audio is not kept in Matraca's database: it exists temporarily on the device and in backend memory during processing and is discarded after the request. With AssemblyAI, we request deletion of the transcript and associated audio immediately after processing; in the contingency described above, uploaded audio is automatically deleted within 48 hours. With Deepgram, mip_opt_out requests are retained only during processing. With OpenAI, we use store=false, but abuse-prevention logs may contain the transcript for up to 30 days, subject to legal or safety exceptions.
The transcript returned to the app may become part of your answer or practice history when that is part of the feature you used. In that case, it is handled as account text and stored while the account is active or until you delete the content or request its deletion. When you delete your account or submit a request to contato@matraca.ai, we remove or anonymize linked data, except for what we must retain for legal, tax, security, or fraud-prevention obligations.
security
We use encryption in transit and at rest, access controls, and security practices proportionate to the risk to protect your data. No system is perfect, but we treat your data the way we'd want ours treated. If a significant incident occurs, we will notify you and the relevant authorities as required by law.
international transfers
Matraca operates between Brazil and the European Union, and our providers may process data in other countries. When we transfer data internationally, we apply the safeguards required by LGPD and GDPR, such as standard contractual clauses and adequacy checks.
your rights
Under LGPD and GDPR, you have the right to access, correct, update, port, and delete your data, as well as to object to or restrict certain processing and withdraw consent. To exercise any of these, write to contato@matraca.ai — we respond within the legal timeframes. You may also lodge a complaint with the competent data protection authority (ANPD in Brazil, or your EU supervisory authority).
children
Matraca is not made specifically for children, and we do not knowingly collect children's data without the consent required by law. If we learn we've collected data from someone below the permitted age without the necessary authorization, we'll delete or correct that data.
changes to this policy
This policy may change as the product evolves or the law changes. When a change is significant, we'll let you know in the app or by email and update the date at the top. Continuing to use Matraca after that means you agree to the current version.
talk to us
Question, request, or complaint about privacy? Send a message to contato@matraca.ai. We're in São Paulo and Lisbon.