Legal

Privacy Policy

Effective 2026-08-25 · Last updated 2026-10-11 · Applies to both the Windows Desktop app and the Android app ("Bedside English: Talk & Train", internal codename "MedVoiceTrainer"); §6 also covers the website and the web app · Developer: boyskier · Privacy contact: bedsideenglish.support@gmail.com

Short version: Bedside English has no user accounts or general-purpose developer cloud backend. Your practice history, transcripts, and settings are stored in a local database on your own device. When you use live AI voice, AI feedback, or pronunciation scoring, the speech, text, and exercise context needed for that feature are sent directly from your device to the AI provider you personally configured (e.g. Google Gemini, OpenAI, Anthropic Claude, or Microsoft Azure Speech).

The Android app has one limited, voluntary exception: if you submit an AI-response report, the edited AI response and report details shown to you are sent through Google Apps Script and stored in a private Google Sheet for developer review, as described in §4.2.

The Android app (including the version downloaded from Google Play) and the Desktop app do not contain advertising or analytics SDKs, and we do not sell user data or use it for advertising. Only the Bedside English website and the browser-based web app at bedsideenglish.github.io/app/ use Google Analytics 4, for basic, aggregate usage measurement that never includes your practice content (see §6).

1. Who this policy covers

Bedside English: Talk & Train is a personal, open-source project built by an individual developer (contact below), distributed free of charge on GitHub and, for Android, on Google Play. It is an educational speaking-practice tool for medical and everyday English — not a clinical system, medical device, diagnostic service, or substitute for professional medical advice — and it is not affiliated with OET, OSCE, USMLE, or any residency-matching organization.

2. Data stored on your device

The app stores the following locally (SQLite/Room database on Android; a local data file on Desktop). When you choose a feature that uses an AI or speech provider, the relevant audio, transcript, prompt, or exercise context may also be sent directly to that provider as described in Section 4. If you voluntarily submit an AI-response report in the Android app, the limited report data described in §4.2 is sent to the developer:

On Android, the local database, encrypted credential preferences, and the learner-audio folder are explicitly excluded from Android's automatic cloud backup. Uninstalling the app, or clearing its data from your device's app settings, permanently deletes those local copies. An AI-response report you chose to submit is a separate remote copy governed by §4.2 and §8; clearing or uninstalling the app does not delete a previously submitted report.

3. Microphone and audio access

The app requests microphone access only when a feature needs spoken input — live voice conversation, dictation, pronunciation analysis, or another voice-based exercise. Depending on the feature and your settings, microphone audio may be streamed live to the AI/speech provider you configured, or a short clip may be sent for transcription or pronunciation scoring. You can deny or revoke microphone permission through your OS settings; the app will fall back to text-based practice where available, but voice features will not work without it. The app never activates the microphone for advertising or background monitoring unrelated to the exercise you started.

4. Data sent to the AI provider you configure

Live voice practice, transcription, AI feedback, and pronunciation scoring require an AI or speech model. The app does not include or resell access to any AI provider — you supply your own API key/credential for the provider(s) you want to use. Provider availability may vary by platform, app version, and enabled feature. When you start a session or request feedback, your speech audio, transcript, and/or relevant exercise context is sent directly from your device to that provider's own servers, under that provider's own privacy policy and terms, which we do not control:

ProviderMay receiveTheir privacy policy
Google (Gemini API / Gemini Live)Microphone audio, transcripts, prompts, exercise context, pasted material, text-to-speech textai.google.dev/gemini-api/terms · policies.google.com/privacy
OpenAI (Realtime API / GPT)Microphone audio, audio clips, transcripts, prompts, exercise context (optional features)openai.com/policies/row-privacy-policy
Anthropic (Claude)Transcripts, prompts, exercise context, pasted material (optional, text-based feedback only)anthropic.com/legal/privacy
Microsoft Azure AI SpeechShort audio clips, language settings, reference text (optional, pronunciation scoring, off by default)privacy.microsoft.com/privacystatement

If you don't configure a given provider, no data is ever sent to it. Demo/mock modes run entirely offline and contact no AI provider at all. Providers may process your data in countries other than your own, and their retention, logging, and model-improvement practices are governed by their own policies and your own account with them — review the provider's policy before enabling it or submitting sensitive information.

We recommend practicing with fictional or de-identified scenarios and never entering real patients' or third parties' identifiable information into a session (see §10).

4.1 YouTube transcript lookup

If you paste a public YouTube video URL or ID to import a caption track (for example, for a "teach-back" exercise), the app connects to YouTube to retrieve that video's public page and available captions. YouTube/Google may see normal network request information associated with that request, such as your device's IP address. See policies.google.com/privacy.

4.2 Voluntary AI-response reports (Android)

If you choose “Report” on an AI response or AI feedback and then press the submit button, the Android app sends the following to the developer through a Google Apps Script HTTPS endpoint for the purpose of investigating harmful, unsafe, misleading, or otherwise incorrect AI-generated content:

The report does not include microphone audio, API keys, an account or device identifier, or the rest of the transcript. However, an AI response can repeat names, patient details, medical information, or other content from the conversation. The report form therefore lets you inspect and edit the full copy that will be sent. Please remove any personal, patient-identifying, or confidential information before submitting.

Submitted reports are stored in a private Google Sheet accessible only to the developer. Google provides the Apps Script and Sheets infrastructure and may process the submitted data and ordinary network metadata under its own Privacy Policy. Submission is optional and does not affect your ability to use the rest of the app. After a successful submission, the app displays the random report ID; keep it if you may want to request deletion.

5. App usage telemetry (opt-in, currently inactive)

The app includes an optional telemetry mechanism for coarse usage statistics. It sends nothing unless you explicitly opt in and the developer has configured a telemetry endpoint and key in that build. As of this policy's effective date, no telemetry endpoint is configured in the shipped release of either app, so telemetry currently sends nothing regardless of your consent setting.

If it is ever activated in a future release, telemetry is designed to include only: a random per-install identifier (no account, no device identifier); the event name; app version and OS family; interface/native-language codes; a coarse country code derived from your system locale (never GPS or IP-based geolocation); session mode, duration, counts, and rounded score information; and limited technical error information (exception type and an in-app file/line location, never the error message text). It is designed to never include microphone audio, transcripts, prompts, feedback text, names, API keys, or any other free-form content you typed or spoke. Any future activation will be reflected in an updated "Last updated" date on this page and, for the Android app, in the Google Play Data safety section.

6. Website and web app analytics

The Bedside English website and the web app (the browser version of Bedside English at bedsideenglish.github.io/app/, including when it is added to your home screen) use Google Analytics 4 (GA4) to understand aggregate usage. GA4 may collect page views, session statistics, approximate geographic information, browser and device information, scrolling activity, and outbound link clicks. Google Analytics uses a first-party cookie containing a pseudonymous client identifier to distinguish users and sessions. We do not intentionally send names, email addresses, patient information, practice transcripts, or other directly identifying content to Google Analytics. Google states that IP addresses are not logged or stored by Google Analytics. Analytics data is processed by Google under its applicable terms and privacy policy.

6.1 What the web app measures

In the web app, analytics is limited to counting how many people use it. In addition to the standard GA4 information above, the web app sends only:

The web app never sends microphone audio, transcripts, AI responses, scores, feedback, case or scenario choices, settings, or API keys to Google Analytics. The web app works normally if you block analytics, for example with a content blocker or the Google Analytics opt-out browser add-on.

6.2 Android and Desktop apps: no analytics

The Android app, including the version distributed on Google Play, and the Windows Desktop app do not contain Google Analytics or any other analytics or advertising SDK. Apart from the opt-in, currently inactive telemetry mechanism described in §5, they send no usage measurement to the developer or to any analytics provider.

7. No accounts, no ads, no data sale

There is no sign-up, login, or Bedside English cloud profile on any platform. The Android and Desktop apps do not include advertising or third-party analytics SDKs; the web app includes no advertising and uses Google Analytics 4 only as described in §6. We do not sell data or use it for advertising. Except for an AI-response report you voluntarily submit as described in §4.2, the developer does not receive your practice content; when you choose an AI or speech feature, the app sends the required data directly to the provider you selected, as described in Section 4. The Android app does not request access to contacts, precise location, call logs, SMS messages, photos, or the advertising identifier.

8. Data retention and deletion

Because the app never creates a Bedside English account, there is no separate online account for us to delete. You can remove all local app data at any time by deleting items in-app, clearing stored API credentials, using your OS's "clear app data" option, or uninstalling the app.

9. Security

No method of electronic storage or transmission is completely secure. Please also protect your own device and provider account credentials.

10. Sensitive medical or personal information

Bedside English is intended for simulated education and language practice. Please do not enter, speak, paste, or otherwise submit real patient-identifying information, protected health information, confidential clinical records, or other information you're not authorized to disclose. The app is not a HIPAA-compliant or equivalent clinical information system, and anything you voluntarily include in a voice session, transcript, or pasted material may be transmitted to the third-party AI/speech provider you've selected (§4). If an AI response repeats such information, remove it from the editable report copy before submitting an AI-response report (§4.2).

11. Children and intended audience

Bedside English and its AI integrations are designed for adult learners — medical students, graduates, and residency applicants generally aged 18 or older — and are not directed at children. We do not knowingly collect personal information from children. A parent or guardian who believes a minor submitted personal information in an AI-response report may contact us with the report ID, if available, to request deletion; for information sent directly to a third-party AI provider, contact that provider and/or us at the address below.

12. Your choices

Disabling a permission or removing a provider credential may prevent the related feature from working.

13. Open source

The Android, Desktop, and PWA apps are open source under the MIT license, so you can verify the claims in this policy yourself in the source code:

The informational website's code and content are separate from the MIT-licensed apps. Website rights are reserved; see Copyright & licenses for scope and existing permissions.

14. Changes to this policy

We may update this policy when the app's features, providers, or data practices change. The "Last updated" date at the top of this page will change accordingly, and material changes will be reflected here, in the app, and/or in the Google Play listing as required. This page's history is also visible at github.com/bedsideenglish/bedsideenglish.github.io.

15. Contact

Questions, deletion requests, or privacy concerns: bedsideenglish.support@gmail.com, or open an issue on either GitHub repo above. For deletion of a submitted AI-response report, include the random report ID displayed by the app after submission; do not post sensitive report content in a public GitHub issue.