Skip to main content

Gestoa — Privacy Policy

Effective date: 13 July 2026
Last updated: 13 July 2026
Version: 1.1

1. Who we are

Gestoa.com (“Gestoa”, “we”, “us”, “our”) is the controller of the personal data described in this Privacy Policy. We operate the Gestoa website and the Gestoa AI public-speaking coaching platform (together, the “Service”).

We are established in Spain and process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the Spanish Organic Law 3/2018 on Data Protection and Digital Rights (“LOPDGDD”), the UK GDPR and Data Protection Act 2018 for users in the United Kingdom, and applicable United States state privacy laws (including the California Consumer Privacy Act as amended by the CPRA) for users in the United States. See §12 and §13 for region-specific rights.

2. Scope

This Policy covers:

  • The Gestoa website — marketing pages, and the waitlist and pilot/enterprise enquiry forms.
  • The Gestoa platform — the account, practice sessions, coaching reports and progress dashboard, once you have an account.

It does not cover third-party websites we link to, which have their own privacy policies.

3. Privacy at a glance

Gestoa is built to measure how you speak while holding onto as little about you as possible. In plain terms:

  • We never store your video. Camera input is analysed entirely in your browser (on-device face-landmark detection). Only numeric metrics — for example gaze percentage, posture-deviation score, gesture frequency — leave your device. The video itself is never uploaded to us and never stored.
  • We do not keep your audio. Your speech is streamed to a speech-to-text provider and converted to a text transcript in real time. The audio recording is not retained by us or by the transcription provider on our behalf.
  • We store metrics and text, not media. Our database holds numeric scores, level histories and text feedback — plus the session transcript. It holds no audio and no video.
  • No biometric identification. We do not create face templates or voiceprints and we do not use your data to identify you biometrically. Because face analysis stays on your device, no biometric special-category data is transmitted to or stored by us (aligned with GDPR Articles 9 and 25).

This section is a summary; the detail is below and prevails if there is any conflict.

4. The personal data we collect

4.1 Website visitors and enquiries

DataSourceNotes
Email addressYou, via the waitlist formRequired to join the waitlist.
Marketing consent flagYouWhether you opted in to marketing emails.
Source pageCollected automaticallyWhich page you signed up from, for attribution.
Name, email, organisation name, role, cohort size, segment, messageYou, via the pilot / enterprise enquiry formProvided when an organisation contacts us about Team/Enterprise use.

4.2 Account and profile data

When you create a Gestoa account: your name, email address, authentication credentials (password hash, or the identifier from a third-party sign-in provider if you use one), and account settings and preferences.

4.3 Billing data

Payments are processed by Stripe. Stripe collects and processes your card and payment details directly; we do not receive or store full card numbers. We receive limited billing information from Stripe — for example the session pack or Plan you purchased, billing country, the last four digits and card brand, and invoice history — to manage your purchases.

4.4 Practice-session data

This is the core of the Service. When you run a session:

  • Transcript (text). Your speech is transcribed to text. The transcript is used to generate your report and is then retained as your session record. Transcripts can contain whatever you choose to say — treat them as confidential, and see §4.7 on sensitive content.
  • Numeric metrics and scores. Voice metrics (e.g. words-per-minute, filler rate, pause duration, pitch variation), body-presence metrics (gaze percentage, posture-deviation score, gesture frequency — computed on your device), and derived skill scores and levels (L1–L4).
  • Text feedback and progress history. The natural-language feedback we generate, your level histories, drill results and radar-chart data over time.
  • Session configuration. Session type, scenario, scheduling and calendar-invitation details you choose.

What we do not collect or store from a session: the video (processed on-device, never uploaded) and the audio recording (streamed for transcription, not retained).

4.5 Technical, device and usage data

Collected automatically when you use the Service, including via the analytics and error-monitoring tools in §6: IP address, device and browser type, operating system, language, referring pages, pages and features used, session/interaction events, approximate location (derived from IP), and diagnostic/crash data.

4.6 Communications and support

If you email us or contact support, we keep your messages and contact details to respond and keep a record.

4.7 Sensitive content within transcripts

We do not intentionally collect special categories of personal data (GDPR Article 9). However, because you speak freely during a session, a transcript may incidentally contain sensitive material — for example legal arguments, health references or personal opinions. Please avoid including personal data about others that you are not authorised to share. We treat all transcript text as confidential user data, restrict access to it, and you can delete your session records at any time (§11).

5. Why we use your data, and our legal bases

Under the GDPR/UK GDPR we rely on the following legal bases:

PurposeData usedLegal basis
Operate the Service — run sessions, generate reports, track progressAccount, practice-session, technical dataContract (Art. 6(1)(b))
Create and manage your account, authenticate youAccount dataContract (Art. 6(1)(b))
Process payments and manage your purchasesBilling dataContract (Art. 6(1)(b))
Manage the waitlist and respond to enquiriesWaitlist/enquiry dataConsent for the waitlist (Art. 6(1)(a)); legitimate interests for responding to B2B enquiries (Art. 6(1)(f))
Prevent spam, fraud and abuse; secure the ServiceTechnical dataLegitimate interests (Art. 6(1)(f)) — keeping the Service secure and available
Product analytics and improvementUsage/technical dataConsent where required (Art. 6(1)(a)), collected via our cookie banner; see the Cookies Policy
Error monitoring and diagnosticsTechnical/diagnostic dataLegitimate interests (Art. 6(1)(f)) — keeping the Service working
Marketing emails and product updatesContact data, marketing consentConsent (Art. 6(1)(a)); you can withdraw at any time
Comply with legal, tax and accounting obligationsBilling, account dataLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have balanced those interests against your rights; you can object at any time (§11). Where we rely on consent, you can withdraw it at any time without affecting prior processing.

6. Analytics, error monitoring and cookies

We use the following third-party tools. Non-essential tools run only where you have given consent through our cookie banner. See the separate Cookies Policy for the full list of cookies and similar technologies and how to control them.

  • Google Analytics 4 (Google) — website and product usage analytics.
  • Google Tag Manager (Google) — a tag-management container we use to load and manage the tags above (and any future tags) subject to your consent settings.
  • Amplitude — product analytics: how features are used, so we can improve them.
  • Sentry — error and performance monitoring, so we can detect and fix bugs and crashes.

We configure these tools to limit the personal data they process (for example, IP-address handling in Google Analytics) and we do not use them to store your session audio, video or transcript content.

7. Automated processing and AI

Your session report is generated by automated means, including large-language-model scoring of your transcript and metrics against our rubric. This automated scoring does not produce legal or similarly significant effects about you — it produces coaching feedback and skill levels. You can request human review of, or provide your point of view on, any automated feedback by contacting us. We do not use your data for automated advertising decisions or credit/eligibility decisions.

8. Who we share data with (processors and sub-processors)

We do not sell your personal data. We share it with service providers (“processors”) who process it on our behalf under contract, only as needed to run the Service:

ProviderPurposeData involvedLocation
SupabaseDatabase, authentication, backendAccount, practice-session, lead data
VercelWebsite/app hosting and deliveryTechnical/request data
RailwayReal-time session gatewaySession stream (transcribed, not retained)
DeepgramSpeech-to-text transcriptionAudio stream in transit → text
OpenAI and AnthropicAI rubric scoring and feedbackTranscript + metric summary
StripePayment processing, subscriptionsBilling/payment data
Google (Analytics, Tag Manager)Analytics and tag managementUsage/technical data
AmplitudeProduct analyticsUsage/technical data
SentryError and performance monitoringDiagnostic/technical data
MailgunWaitlist, account and notification emailsEmail address, message content

We may also disclose personal data where required by law, to enforce our terms, to protect our rights, users or the public, or in connection with a merger, acquisition or asset sale (in which case we will notify you).

We put in place a data processing agreement with each processor as required by GDPR Article 28. A current, detailed sub-processor list is available on request from info@gestoa.com.

9. International data transfers

We are based in Spain (EEA). Some processors listed above are located in, or transfer data to, the United States or other countries outside the EEA/UK. Where we transfer personal data outside the EEA or UK, we rely on an appropriate safeguard, such as:

  • the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum), and/or
  • the processor’s certification under the EU–US Data Privacy Framework (and the UK extension), where applicable.

You can request a copy of the relevant safeguard from info@gestoa.com.

10. How long we keep data

We keep personal data only as long as necessary for the purposes above:

DataRetention
VideoNever stored (processed on-device only).
Audio recordingsNever stored (transcribed in transit).
Session transcriptsRetained for 30 days, then deleted or irreversibly anonymised, unless you delete them sooner.
Metrics, scores, level history, progressFor the life of your account, unless you delete them or close your account earlier.
Account dataFor the life of your account; deleted or anonymised after closure, subject to legal retention.
Billing/invoice recordsAs required by Spanish tax and accounting law (generally up to 6 years).
Waitlist / enquiry dataUntil you unsubscribe or ask us to delete it, or until it is no longer needed.
Salted IP hashes (anti-abuse)Short-lived, only as long as needed for rate-limiting.
Analytics dataPer the provider’s retention settings (see Cookies Policy).

When we no longer need personal data, we delete or irreversibly anonymise it.

11. Your rights

Subject to the GDPR/UK GDPR, you have the right to: access your data; rectify inaccurate data; erase data (“right to be forgotten”); restrict processing; data portability; object to processing based on legitimate interests or to direct marketing; and withdraw consent at any time. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (see §7).

To exercise any right, contact info@gestoa.com. We will respond within one month (extendable by two further months for complex requests). We may need to verify your identity first. Exercising your rights is free unless a request is manifestly unfounded or excessive.

You have the right to lodge a complaint with a supervisory authority. In Spain this is the Agencia Española de Protección de Datos (AEPD) www.aepd.es. In the UK it is the Information Commissioner’s Office (ICO) ico.org.uk. You may also complain to the authority in your EU country of residence.

12. UK users

If you are in the United Kingdom, the UK GDPR and Data Protection Act 2018 apply. Your rights in §11 apply equally, and your supervisory authority is the ICO. International transfers rely on the UK Addendum to the SCCs or the UK extension to the EU–US Data Privacy Framework (§9).

13. US users (California and other states)

If you are a resident of California or another US state with a comprehensive privacy law, additional rights may apply, including the right to know/access the categories and specific pieces of personal information we collect, the right to delete, the right to correct, and the right to opt out of “sale” or “sharing” of personal information and of targeted advertising.

We do not sell your personal information for money. We do use analytics and advertising technologies that, depending on your settings, may constitute “sharing” or “targeted advertising” under some state laws; you can opt out via our cookie banner and by enabling Global Privacy Control (GPC) in your browser. We treat GPC as a valid opt-out of “sale”/“sharing” and targeted advertising and honour it automatically for every visitor — see §3 of our Cookies Policy and our declaration at /.well-known/gpc.json. We do not knowingly process the sensitive personal information of, or discriminate against you for exercising, your rights. To make a request, contact info@gestoa.com; you may use an authorised agent.

Categories of personal information we collect map to the sections above: identifiers (§4.1–4.2), commercial information (§4.3), audio/transcript-derived text and inferences (§4.4), and internet/usage activity (§4.5).

14. Children

Gestoa is not directed to children. You must be at least 18 years old (or older where required in your country) to use the Service. We do not knowingly collect data from children under 18. If you believe a child has provided us data, contact info@gestoa.com and we will delete it.

15. Security

We protect your data with measures appropriate to the risk, including encryption in transit, access controls, row-level security on our database, service-role isolation of sensitive operations, and the privacy-by-design architecture described in §3 (no media stored). No system is perfectly secure, but we work to protect your data and will notify you and the relevant authority of a breach where legally required.

16. Changes to this Policy

We may update this Policy from time to time. We will post the new version here with an updated “Last updated” date and, for material changes, notify you by email or in-product. Continued use after the effective date means you accept the updated Policy.

17. Contact

Questions or requests: info@gestoa.com