Privacy Policy
Last updated: August 12, 2026
1. Who controls your data
[Legal entity name, address, and registration details — to be completed once business registration is finalized]. For any privacy question or to exercise the rights below, contact [contact email — to be added].
2. What we collect
- Account data: name, email address, and a bcrypt hash of your password (we never store or can recover your actual password).
- Usage data: your quiz attempts and answers, flashcard review history, and study-plan checklist progress — this is what powers the progress dashboard and spaced-repetition scheduling, and it exists only because you created an account and used those features.
- Technical/log data:our servers record IP address, request timestamps, and request paths in operational logs, used for security (detecting abuse) and rate-limiting (preventing brute-force login attempts). These are infrastructure logs, not a separate analytics or tracking system — we don't run any third-party analytics, advertising, or tracking scripts on this site today.
3. Cookies and local storage
We don't use cookies or local storage for tracking or advertising. The app stores your login session and UI preferences (like light/dark theme) in your browser's local storage so you stay logged in and your preferences persist — this is strictly necessary for the Service to function and, under the ePrivacy rules that require cookie consent banners for non-essential tracking, doesn't require one.
4. Why we process your data (legal basis)
Account and usage data: processed to perform the contract with you (providing the Service you signed up for) under GDPR Art. 6(1)(b). Security/rate-limiting logs: processed under our legitimate interest in keeping the Service secure and available, under GDPR Art. 6(1)(f).
5. Who we share it with
We use infrastructure providers to run the Service, who process data on our behalf under their own data-processing terms: Google Cloud (application hosting, Frankfurt, Germany) and Neon(managed Postgres database hosting, Frankfurt region). Both keep your data within the EU. We don't sell your data or share it with advertisers.
When paid subscriptions launch (not yet active — see our Terms of Service), payment processing will be handled by Stripe. We will never see or store your full card details ourselves; Stripe processes that as an independent controller under its own privacy policy. This section will be updated with the specifics when that integration goes live.
6. How long we keep it
Account and usage data is kept for as long as your account is active, and deleted or anonymized within a reasonable period after you ask us to delete your account (see below). Payment/transaction records, once paid plans exist, will be subject to a legal minimum retention period under Polish tax law — the exact figure is being confirmed with an accountant before real payments go live and will be stated here precisely once confirmed, rather than guessed.
7. Your rights
Under GDPR, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your data ("right to be forgotten").
- Request a portable export of your data.
- Object to or request restriction of certain processing.
- Lodge a complaint with your national supervisory authority — in Poland, the Prezes Urzędu Ochrony Danych Osobowych (UODO).
Account deletion is self-service: visit /delete-account — no login required, since this needs to work even if you've lost access to your account. We email a confirmation link to the address on file (valid 24 hours) before anything is deleted, so a request can't be triggered by someone else typing in your email address. Deletion is immediate and permanent once confirmed.
Access, correction, export, and objection requestsdon't have self-service tools yet — email us at [contact email — to be added]and we'll handle it manually. Self-service tools for these are planned.
8. Children
The Service isn't directed at, and we don't knowingly collect data from, anyone under 16.
9. Changes to this policy
We'll update this page as the Service changes (notably: when paid billing and Stripe integration go live) and update the "Last updated" date above.