Skip to content

Privacy Notice

Last updated: September 5, 2026

1. Who controls your data

InfraDrill is operated by Piotr Konopka, a natural person based in Poland, acting as the data controller within the meaning of GDPR Art. 4(7) — which covers a natural person just as it does a company.

Piotr Konopka, Wiosenna 20, 55-100 Trzebnica, Poland
Phone: +48 534 735 386

For any privacy question, or to exercise the rights below, contact support@infradrill.dev.

2. What we collect

  • Account data: your email address and a bcrypt hash of your password (we never store or can recover your actual password). We do not ask for your name and there is nowhere to enter one.
  • Usage data: your quiz attempts and answers, flashcard review history, and study-plan checklist progress — this is what powers the progress dashboard and spaced-repetition scheduling, and it exists only because you created an account and used those features.
  • Technical/log data: our servers record IP address, request timestamps, and request paths in operational logs, used for security (detecting abuse) and rate-limiting (preventing brute-force login attempts). These are infrastructure logs kept for operations, not a profiling system.

Audience measurement: we use Cloudflare Web Analytics on the public pages. It records page views, referrer and page-timing information. It sets no cookies, stores nothing on your device, and builds no profile of you here or across other sites. Like any request your browser makes, the one carrying those measurements reaches Cloudflare from your IP address; Cloudflare states that the product does not use it to identify you, and we neither receive it nor see it. Cloudflare acts as our processor for this purpose. Legal basis: our legitimate interest in knowing which pages are used and whether the site is working (GDPR Art. 6(1)(f)). You can block it with any content blocker without affecting the Service.

Bot protection: the sign-in, registration and account-deletion forms are protected by Cloudflare Turnstile. It runs a check in your browser to establish that a request comes from a person rather than an automated script, and processes your IP address together with browser and device signals needed to tell a person from a script. It does not ask you to identify pictures, does not track you across sites, and is not used for advertising. Legal basis: our legitimate interest in protecting accounts from automated credential-stuffing attacks (GDPR Art. 6(1)(f)) — an interest you share, since the accounts being attacked would be yours.

Two roles, not one. Cloudflare processes those signals on our behalf to protect the Service, and it also processes some of them for a purpose of its own — making Turnstile better at telling people from scripts — for which it decides the means itself rather than acting on our instructions. Its own Turnstile privacy notice governs that second part, and we describe both because saying only the first would understate what happens.

3. Cookies and local storage

We don't use cookies or local storage for tracking or advertising. The app stores your login session and UI preferences (like light/dark theme) in your browser's local storage so you stay logged in and your preferences persist — this storage is what keeps you signed in and your preferences applied, rather than anything that profiles you. We set nothing on your device for tracking or advertising.

4. Why we process your data (legal basis)

Account and usage data: processed to perform the contract with you (providing the Service you signed up for) under GDPR Art. 6(1)(b). Security/rate-limiting logs: processed under our legitimate interest in keeping the Service secure and available, under GDPR Art. 6(1)(f).

5. Who we share it with

We use infrastructure providers to run the Service, who process data on our behalf under their own data-processing terms: Google Cloud (application hosting, Frankfurt, Germany) and Neon (managed Postgres database hosting, Frankfurt region, Brevo (transactional email — address-confirmation, password-reset and account-deletion messages; Brevo receives your email address and the message content, and is an EU provider), and Cloudflare (audience measurement and bot protection, both described above)). Our application and database are hosted in EU regions, and each of these providers offers EU-based infrastructure; note that a provider may still route some operational processing (support, security, telemetry) through its own global infrastructure and sub-processors, as set out in its own documentation. We don't sell your data or share it with advertisers.

Payments are handled by Paddle, which acts as Merchant of Record — meaning Paddle, not us, is the seller on your purchase. Paddle collects your payment and billing details and processes them as an independent controller under its own privacy policy. We never see, receive, or store your card details. What reaches us is limited to what we need to give you access and to keep a lawful financial record: the transaction identifier, Paddle's own identifier for you as its customer, the amount, the tax and fee Paddle deducted, what is owed to us, the currency, which pass was bought, and the date. Nothing else does — not your name, not your address, not your email as Paddle holds it, and not your tax identifier. Our receiver decodes only those fields, so a field Paddle adds later cannot start being stored by accident.

Those transaction records are kept even if you delete your account, because tax law requires retaining them and GDPR Art. 17(3)(b) exempts retention required by a legal obligation from the right to erasure. The link to your account is removed, so what remains is a transaction record that we can no longer connect to you — though Paddle, which issued it, still can, so it does not stop being personal data.

6. How long we keep it

Account and usage data is kept for as long as your account is active. If you ask us to delete your account, your account and usage data are permanently deleted once you confirm the emailed link — we do not keep a shadow copy. The single exception is information we are legally required to retain, described at the end of this section.

We also delete accounts that fall dormant, so data does not accumulate indefinitely without a purpose. An account that has never bought a pass is deleted after 1 year without a login, and logging in resets that clock. An account that has bought one is deleted 3 years after its pass expired — kept longer so that a returning customer still finds their own history, and measured from the expiry rather than from the last visit, so that looking at that history does not postpone deletion indefinitely. Buying again starts a new pass, and with it a new period. Payment and transaction records are the exception to all of the above: tax law requires us to retain them, and the right to erasure does not extend to data kept to satisfy a legal obligation (GDPR Art. 17(3)(b)). We keep them for the period Polish tax law prescribes — for the period applicable tax law requires. They survive account deletion and the link to your account is removed. We stop being able to connect them to you; that is not the same as the record ceasing to be personal data, since Paddle — which issued it — still holds the buyer's side of the same transaction.

5a. Why each of these is lawful

The bases above, gathered in one place so the whole picture is readable rather than spread through the section:

  • Your account and the Service — Art. 6(1)(b): we cannot give you an account, keep your progress or deliver a pass without processing this.
  • Transactional email (address confirmation, password reset, deletion confirmation) — Art. 6(1)(b). These are part of running the account, not marketing, and we send no marketing.
  • Payment and tax records — Art. 6(1)(c): tax law requires us to keep them, which is also why erasure does not reach them.
  • Server logs, rate limiting and bot protection — Art. 6(1)(f), our legitimate interest in a service that stays available and is not abused. Turnstile is here.
  • Audience measurement — Art. 6(1)(f), our legitimate interest in knowing whether anyone reads the site. It is aggregate, has no cookie and builds no profile; where it processes nothing personal, no basis is needed at all.

6a. Logs, analytics and bot protection

The three kinds of data that are not tied to your account have their own periods, stated here because a retention notice that covers only account data leaves out everything a visitor generates before they have one:

  • Application and request logs — 30 days, then deleted automatically by our hosting provider. These are the lines the service writes as it runs; they can contain an IP address and an account identifier.
  • Administrative audit logs — 400 days. This is our cloud provider's own fixed period for records of changes to the infrastructure, and it is not one we can shorten. They concern our administrative actions, not your use of the Service.
  • Bot protection and audience measurement — Cloudflare keeps what it needs for those two purposes under its own periods, described in its documentation. Neither writes a cookie, and neither is used to build a profile of you.

6b. Processing outside the EEA

Our application, our database and our email provider are in the EU. Two providers operate globally and processing may reach a country outside the EEA: Cloudflare, whose network answers requests from wherever it is nearest, and Paddle, which handles payment. Where that happens, the transfer rests on the safeguards in that provider's own data-processing terms — the European Commission's Standard Contractual Clauses, or an adequacy decision where one covers the country concerned. We do not start an international transfer of our own; one may happen as part of the service those two providers give us, under the terms named above.

6c. What you have to give us, and what we decide automatically

An email address and a password are required to create an account: the address is how we confirm it is yours and how we send you a password reset. Both are checked by the server, so an account cannot be created without them, and nothing else about you is asked for. Payment and billing details are required to buy a pass, and you give them to Paddle rather than to us. Everything else — quiz answers, exercise attempts, study-plan progress — is generated by using the Service and is not something you are asked to supply.

We do not make decisions about you by automated means in the sense of GDPR Art. 22: nothing here produces a legal effect or similarly significantly affects you. We do calculate your accuracy per category from the answers you give and mark a category weak below a threshold, but that is a view of your own results shown to you, and it decides nothing.

7. Your rights

Under GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Request deletion of your data ("right to be forgotten").
  • Request a portable export of your data.
  • Object to or request restriction of certain processing.
  • Lodge a complaint with your national supervisory authority — in Poland, the Prezes Urzędu Ochrony Danych Osobowych (UODO).

Account deletion is self-service: visit /delete-account — no login required, since this needs to work even if you've lost access to your account. We email a confirmation link to the address on file (valid 24 hours) before anything is deleted, so a request can't be triggered by someone else typing in your email address. Your account and usage data are permanently deleted once confirmed, apart from the transaction records tax law obliges us to keep.

Access, correction, export, and objection requests don't have self-service tools yet — email us at support@infradrill.dev and we'll handle it manually. Self-service tools for these are planned.

8. Children

The Service isn't directed at, and we don't knowingly collect data from, anyone under 18.

9. Changes to this policy

We'll update this page as the Service changes, and update the "Last updated" date above when we do. If a change materially affects how we handle your personal data, we will tell registered users by email rather than relying on you to re-read this page.