Privacy Policy
Last updated: September 18, 2026
Gestique is sign-language technology built so that the most sensitive thing it touches — video of you signing — is analyzed on your own device by default and is never stored on our servers. This policy explains exactly what we do collect, why, how long we keep it, and how to get rid of it. It covers gestique.io and the tools on it: Relay, Mirror, Coach and Corpus (together, the “Service”).
1. The short version
- By default, your camera video never reaches our servers. Analysis runs in your browser and produces numbers — hand, face and body landmark coordinates. Only those numbers are sent, and only when a feature needs them. Coach offers an optional switch to run that analysis on our server instead, for older phones: it is off unless you turn it on, and even then the frames are read and discarded, never stored (section 3).
- You do not need an account to use the demos. Signing in is optional and only adds progress tracking.
- We do not sell your data. If you allow analytics cookies, we use Google Analytics to count visits and see which pages get used — nothing more. Analytics remains off unless you opt in. We do not run advertising pixels, we do not build advertising profiles, and we never connect analytics to your camera or your practice data.
- Gestique is free, and the movement data helps build it. The landmarks from practice and from Corpus contributions may be used to research and develop sign-language technology, including products we may sell in the future. That is movement data only, held without a link to you (section 6).
- You can delete everything by emailing info@gestique.io.
2. Who we are
Gestique is a project created and operated by Forrest Moulin (“we”, “us”, or “our”). Forrest Moulin operates gestique.io and is the controller responsible for the personal data described in this policy. For any privacy question, request or complaint, contact Forrest Moulin at info@gestique.io. We aim to respond within 30 days.
3. Camera video, and what actually gets sent
This is the part most people care about, so it is the most specific section here.
By default, everything runs on your device. When you use a camera feature, your browser opens your camera and runs Google's MediaPipe models on your own device. Those models turn each frame into a set of coordinates describing where your hands, face and body are. In this mode the video frames themselves are never uploaded, never written to our disks, and never seen by us.
What may be transmitted to our servers is the derived numeric data — the landmarks — because the models that interpret them run server-side. In practice that means:
- Relay sends feature vectors derived from landmarks so the sentence decoder can produce captions.
- Coach sends landmarks from a practice attempt so it can be graded against reference examples.
- Mirror sends landmarks so they can be smoothed and retargeted onto an avatar.
Landmark data is not video and cannot be turned back into video. It does not contain your face's appearance, your surroundings, or audio. It is a description of movement.
The one exception is a choice you make. Some phones are too slow to run the models well. Coach therefore offers a switch, beside the camera picker, to have the analysis done on our server instead. It is off by default, it only appears where our server offers it, and while it is on the practice screen shows an amber notice. With it on, the camera frames from a practice attempt (and, for sign practice, the short recording of that attempt) are sent to our server so it can extract the same landmarks. They are processed in memory or in a temporary folder that is deleted the moment the read is done, on the error path too. They are never stored, never viewed by a person, and never used to train anything. What remains afterwards is exactly what the on-device mode would have sent: the landmarks.
We are deliberately precise about this: by default your video never leaves your device; if you choose server-side analysis it leaves your device for the seconds it takes to read it and is then gone; and in neither case is any video ever stored on our servers. The only video we keep is a Corpus clip you have explicitly chosen to contribute (section 6).
4. If you sign in with Google
Signing in is optional. If you choose to, we use Google OAuth and request three
scopes: openid, email and profile. We do
not request access to your Gmail, Drive, Calendar, Contacts or any other Google
service, and we cannot read them.
From Google we receive and store:
- your Google account identifier (the stable
subclaim), which is what your account is actually keyed on; - your email address and whether Google has verified it;
- your display name and profile picture URL, used to show who is signed in.
We use this only to create and recognize your account and to attach your own practice progress to it. We do not use it for advertising, we do not build profiles from it, and we do not sell or transfer it.
Your Google address is not a mailing list. It was given to us to prove who is signing in, and we do not send anything to it on that basis. If you ever want updates from us, there is an unticked box on your account page: ticking it is a separate, dated choice, stored separately, and you can untick it or use the unsubscribe link in any message we send. An account created with a passkey has no email address at all unless you type one there yourself.
Limited Use
Gestique's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, we do not transfer this data to others except as necessary to provide or improve the Service, comply with law, or as part of a merger or acquisition; we do not use it for advertising; and we do not allow humans to read it except with your explicit consent, for security purposes, to comply with applicable law, or where the data is aggregated and de-identified.
Sessions
When you sign in we set one cookie, gsq_session, which holds a random
token and expires after 30 days. We store only a SHA-256 hash of that token, so
the cookie's value cannot be recovered from our database. A short-lived
gsq_oauth cookie carries the OAuth state during sign-in and expires
after ten minutes. Both are strictly necessary and neither is used for
advertising. Google Analytics sets its own cookies separately — see section 8.
If you accept analytics cookies, we also set gsq_activity, a random
first-party browser identifier lasting up to one year. It lets us count active
browsers without storing names, IP addresses, or individual action histories.
Choosing “Required only” clears this cookie and stops signed-out browser counting.
The native app uses an install identifier and an HTTP cookie for similar usage counts.
5. What we store when you are signed in
Only counters and labels — never recordings:
- Progress counters: how many signs you have passed, how many corpus contributions you have made, and time spent practicing.
- Per-sign results: for each sign, how many times you passed or missed it, so the app can show you what still needs work.
- Quiz results: scores and run counts per quiz scope.
- Lesson progress: practiced steps, your place in each lesson, completion times for badges, and results from embedded sign practice: best and latest match scores, attempt counts, and passed or skipped signs. This record does not include practice names, hearing-status choices, or video.
- Active-user counts: first and most recent tracked activity times under a hashed account identifier, so one account using the website and app counts once. The dashboard shows counts, not identities.
Conversation lessons also save progress in your browser so you can resume. When you sign in on Coach, that device’s unsigned lesson progress is added to your account. Clearing browser storage removes progress that has not synced.
If you are not signed in, we do not keep per-account progress. We keep aggregate action totals and, for browsers allowing analytics and for app installs, first and most recent activity times under a hashed browser or install identifier.
6. Contributions and reports
Corpus contributions. If you choose to contribute a clip to the community sign corpus, that clip is stored anonymously. If you are signed in, a counter on your account increases so you can see how many you have contributed, but the stored clip itself carries no link back to your account. Contributions are used to build training and reference data for sign-language models. This is always an explicit, opt-in action.
Practice examples. When a practice attempt is graded as good, its landmark data may be kept as a reference example to improve grading accuracy. This is landmark data only, never video.
What this data may be used for. Gestique is free to use today, and we are building sign-language technology with it. The movement data described in this section, and the movement data from your practice attempts, may be used to research, develop, train, test and evaluate that technology. We mean this broadly: it covers new features and new models, not only the ones you see now, and it covers products or services we may offer commercially in the future. It also covers data we have already collected and still hold. If we did not say this plainly now, we would have to come back and ask you later.
What does not change: this is movement data and never your video; it is held without a link to your identity; and we do not sell your personal information or license anything that identifies you. If you would rather not take part, you can practice without an account, and Corpus contributions are always a button you choose to press.
Issue reports. If you use a “Something look wrong?” button, we store what the screen showed and the landmark data behind that result so a human can investigate. These reports never contain video.
7. Technical data we cannot avoid
Like any website, our servers see your IP address and browser user-agent on each request. We use them for security and abuse prevention only — rate limiting, blocking automated scanners, and keeping one visitor from exhausting the shared machine. They are not used to build a profile of you and are not combined with your account.
8. Third parties
We keep these to a minimum. We have no advertising partners and run no advertising pixels; the one analytics partner is named below.
- Google — for sign-in, if you use it (see section 4).
- Google Fonts — pages load the Poppins typeface from
fonts.googleapis.comandfonts.gstatic.com. This means Google receives your IP address as part of serving the font files. No cookie is set by this request. - Google Analytics (GA4, measurement id
G-HYLRGGEW3N), loaded only after you choose “Accept analytics.” It records the ordinary things a visit-counter records — pages viewed, referrer, approximate location from IP, browser and device type — and sets its own cookies to tell a returning browser from a new one. It runs on the marketing and product pages; it is not loaded on the internal lab pages.
What it never receives: your camera video, your landmark data, your practice results, or anything tying a measurement to your account. You can change your choice below at any time. You can also opt out browser-wide with Google's opt-out add-on, or by blockinggoogletagmanager.com. - Our hosting provider — the servers running gestique.io are rented from an infrastructure provider that necessarily processes traffic on our behalf.
We do not sell personal data, and we do not share it for cross-context behavioral advertising.
9. How long we keep things
- Camera video: never stored. Frames or a recording sent under the optional server-side analysis (section 3) exist only for the seconds they are being read, then are deleted.
- Account data: for as long as your account exists, then removed on request.
- Sessions: 30 days, or until you sign out.
- Corpus contributions and reference examples: retained as part of the dataset, in anonymous form, unless you ask us to remove a specific contribution.
- Server logs: rotated on a short cycle and kept only as long as needed for security.
10. Your rights and how to use them
You can ask us to show you what we hold about you, correct it, delete it, or provide it in a portable form. Depending on where you live — for example under the GDPR in the EEA and UK, or the CCPA/CPRA in California — you may also have the right to object to or restrict certain processing, and to lodge a complaint with your data protection authority.
To exercise any of these, email info@gestique.io from the address on your account. Deleting your account removes your profile, your session records and your progress counters. Anonymous corpus contributions cannot always be traced back to you by design — tell us roughly when you contributed and we will do our best to locate and remove them.
You can also revoke Gestique's access to your Google account at any time from your Google account permissions page.
11. Security
Traffic to gestique.io is encrypted with TLS. Session tokens are stored only as hashes. Database access uses a least-privilege account. The demo APIs are rate limited and admission controlled. No system is perfectly secure, but the strongest protection here is structural rather than procedural: by default the video never reaches us, and when you opt into server-side analysis it is discarded as soon as it has been read, so there is no store of video to lose.
12. Children
Gestique is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact info@gestique.io and we will delete it.
13. International transfers
Gestique is operated from the United States, and data is processed there. If you use the Service from outside the US, you understand that your data will be transferred to and processed in the US.
14. Changes to this policy
If we change this policy we will update the date at the top of this page, and for material changes we will give clearer notice. Continuing to use the Service after a change means you accept the updated policy.
15. Contact
Questions, requests or complaints? Contact Forrest Moulin at info@gestique.io.
See also our Terms of Service.
Gestique is built with the Deaf community. If something in this policy is unclear or reads as evasive, tell us — that is a bug.
