HHolaDoneType Spanish until it sticksPRIVACY · 2026-08-23
Practice stays local by default. You enable anything extra.
No account is required. There are no ads, payments, or marketing trackers. Anonymous analytics require consent, and cross-device sync is off until you create or connect a sync space.
Local practice data: course position, round order, completion, daily counts, mistakes, accent rule, sound, and speech speed are stored in browser localStorage.
Not uploaded by default: practice data is not sent to the sync database until you create or connect a sync space.
Delete local data: clear site data for HolaDone in your browser. Deleted local data cannot be recovered.
What happens if you allow anonymous analytics?
Purpose: understand whether practice starts, completes, or is abandoned, and improve round length and mode transitions.
Sent: manually defined summary events such as mode, level, item count, duration, errors, and independent-answer rate.
Never sent: typed text, specific cards, card IDs, sync codes, sync contents, session replay, heatmaps, or automatic error capture.
Provider: PostHog Cloud EU. With consent, a random browser identifier is stored locally for return and retention measurement. HolaDone does not connect it to a name, email, or account.
Decline or withdraw: the site still works normally. You can change the choice in Settings; withdrawal affects future collection.
What happens if you enable sync?
Synced data: practice position, recent queues, daily records, per-card evidence, mastery, mistakes, challenges, and preferences are encrypted in the browser before upload.
Encryption: the browser derives an AES-256-GCM key from the 20-character sync code. Vercel Functions and Upstash Redis handle derived credentials and ciphertext, not the plaintext code or a directly usable decryption key.
Code responsibility: anyone with the code can join, modify, or delete that progress. Treat it like a password. HolaDone has no account recovery.
Retention: each cloud write renews ciphertext expiry to 400 days. Delete cloud data in Settings; stopping sync on one device does not delete the cloud copy.
Speech and hosting boundaries
Spanish speech: uses browser Speech Synthesis. A voice may be local or may use a network service according to your browser and operating-system settings.
Hosting: Vercel hosts the site and sync endpoint; optional encrypted sync data is stored in Upstash Redis. Providers may process technical request and security information.
External links: source notes link to GitHub, Instituto Cervantes, Kaikki, and other third parties whose own privacy rules apply.