German Vocabulary

Privacy Policy

Effective date: 30 July 2026 · Applies to the German Vocabulary app for iPhone and iPad, and this website.

The short version

  • Your learning lives with you. Your progress, streaks, settings and your own words are stored on your device and in your own iCloud — a place we cannot read.
  • No account is needed to learn. We don't know your name or email address.
  • Nothing is sold. Not to anyone, not ever, not in any aggregated or "de-identified" form.
  • Optional things stay optional. Sharing usage or crash data, joining the leaderboard, leaving an email with feedback — each is your explicit choice, each can be undone, and declining never limits learning.
  • The leaderboard is the one thing on our servers. If you join it, your nickname and figures live on our servers (operated by Cloudflare, processed globally) so friends on iPhone and Android can play together — see §5. Everything else stays on your device and in your own iCloud. You can delete your leaderboard profile any time.

The rest of this page says precisely what data goes where, why, for how long, and how to exercise your rights. We have tried to write it so a person can actually read it.

1. Who is responsible

The controller for any personal data described here is:

Santhosh Ramapuram Palanivel

Hilde-Domin-Straße 2
69126 Heidelberg, Germany
Email: [email protected]

We are a very small operation — the person answering your privacy email is the person who built the app.

2. What stays on your device and in your iCloud

The heart of the app never reaches us:

These are stored on your device and synced through your private iCloud database, operated by Apple under your Apple account. We have no access to it — technically none, not merely by policy. If you delete the app and its iCloud data, this data is gone; we could not recover it for you because we never had it.

Apple's processing of your iCloud data is governed by Apple's privacy policy.

3. What the app requests from our servers

To deliver its content, the app talks to our servers (operated on Cloudflare's infrastructure). These requests are needed for the app to work:

Server request logs and rate-limit counters are kept only as long as operationally necessary and contain no names or contact details.

4. Things you may choose to send us

Each of the following happens only when you deliberately do it:

4.1 Feedback and ideas (Settings → Help improve the app)

Your message is sent with your app version, learning level and language so we can make sense of it. Leaving an email address is optional and is used only to reply to that one message — no newsletters, no marketing, nothing else. Your email address is automatically deleted after 30 days; the message itself is kept (without the address) so ideas aren't lost. Feedback is never combined with any other data about your app usage.

4.2 Problem reports (Settings → Help improve the app → "Report a problem in the app")

Sends a technical diagnostic report you initiate: app logs and technical state, screened to exclude your words and personal content. Reports are deleted automatically after 30 days.

4.3 Content reports and word submissions

Long-pressing a card to report a wrong picture, audio or translation sends the word's identifier and your chosen reason. If you enable "share my new words", words you add may be sent for curation so other learners can benefit — your name is not attached, and the toggle is off until you say otherwise.

5. Learn with friends

Applies when the leaderboard feature is available in your version. Joining is optional and requires a sign-in; you can delete your leaderboard profile at any time (see below).

If you join, your chosen nickname and your figures — points, day streak, words-mastered count, and which days you were active — become visible to the friends you explicitly invited or accepted, and only to them. There is no public leaderboard, no strangers, and friendship is mutual: if either side leaves, both disappear from each other's boards. Only these fields are ever shown to a friend — never your words, session contents, or the times of day you studied.

Where this data lives, plainly. To let an iPhone learner and an Android learner be friends, the leaderboard runs on our own servers, operated for us by Cloudflare, and processed globally — not pinned to any one region. This is a change from earlier versions, where leaderboard data was exchanged only between participants' iClouds: on the leaderboard, we (and Cloudflare as our processor) can read the nickname and figures we host. We keep as little as possible to make this honest — no email, no real name, no raw Apple identifier: your account is a random player id, a nickname you choose, and a one-way keyed hash of your sign-in identifier.

What the leaderboard server stores, grouped by purpose. The versioned technical inventory is maintained with the feature; this readable summary covers every category:

It stores no push token of any kind (the leaderboard sends no push notifications), no raw sign-in subject, email or real name, no history of individual study events, and no message archive.

Deleting your leaderboard profile. In the app, Settings → Leaderboard → Delete leaderboard profile removes the profile, credentials, sessions, projections, social relationships, invites, cheers, receipts and other profile-serving rows, and disconnects your provider identity from the app. Your learning progress on your device is untouched. Deletion is honored through backups too: a minimal deletion journal, result tombstone and erasure markers are kept long enough to outlive recovery sources and prevent a restore from quietly bringing the profile back, then expire. A moderation report may be retained for abuse review or a documented legal hold; when the reporter deletes their profile, their player id is replaced with a non-identifying tombstone. Operational logs age out under their ordinary security window.

Your rights. Leaderboard profile data is personal data; deletion above is the erasure path. There are no joins between this leaderboard data and the optional usage/crash data in §6, or the feedback channel in §4 — they are kept entirely separate.

6. Help improve the app (optional usage insights and crash reports)

Applies from the app version that introduces the "Help improve the app" option.

The app will ask — once during setup, and at most twice more, months apart — whether you want to help improve it. There are two separate choices, each fully optional:

One-time crash choice while ongoing sharing is off: after the first app screen appears, Firebase Crashlytics may keep a fatal crash report on this device with automatic upload turned off. If the app can prove there is one safe, eligible fatal report, it asks whether to Don't Send or Send Once. No answer, an error, or an ambiguous/multiple-report state sends nothing; unsafe reports are deleted. Send Once queues only that already-captured crash epoch and does not turn on Share crash reports for the future. The local report can contain the technical fields above plus Firebase's pseudonymous installation metadata, but never your vocabulary, answers, notes, name, email, account identifier, notification/purchase tokens, or app-owned MetricKit report. A small payload-free decision journal (report ID and send/delete state only) is protected, excluded from backup/iCloud, capped at 16 entries/8 KiB, and retained only to prevent a duplicate choice or action.

Separate on-device/Apple diagnostics: iOS can deliver Apple MetricKit performance and crash reports back to the app. The app keeps complete copies locally for at most 30 days, 64 reports and 20 MB so a shipping problem can be investigated on that device. They are protected, excluded from backup, and are not sent to us, Firebase, iCloud or the problem-report form. Apple's separate device setting controls whether Apple shares aggregated diagnostics with app developers; the app cannot enable or verify that setting.

What is never sent, with either choice: your name, email, your words, sentences or notes, free text of any kind, search terms, or any account identifier — no account exists. No advertising identifier is used, and the app is built so it cannot collect one.

Honesty about identifiers: if you opt in, the data carries a random per-installation identifier so that "one person did this five times" can be told apart from "five people did this once". It does not name you — but we do not call this data "anonymous", because that identifier can single out an installation. It is pseudonymous, and we treat it as personal data with all the rights below.

This data is processed for us by Google (Firebase Analytics and Crashlytics) on servers worldwide, including in the United States, under Google's data-processing terms and EU transfer safeguards (standard contractual clauses; the EU–US Data Privacy Framework). Google's privacy documentation.

Retention (each service keeps its own clock):

Turning it off (Settings, any time): automatic collection stops immediately, unsent reports are durably scheduled for deletion, and the installation identifier is rotated so nothing new can connect to the old uploaded data. After deletion is confirmed locally, a future fatal crash may again be held only for the separate Send Once choice described above. Data already uploaded is not individually deletable — it simply ages out on the schedules above. We say this plainly rather than promising a deletion we cannot perform.

Legal basis: your consent (Art. 6(1)(a) GDPR), withdrawable at any time with effect for the future.

7. Notifications

Reminders and study nudges are created on your device by the app itself — we do not use usage data to decide who receives what.

The delivery address (push token). While reminders are switched on, your device holds a push token: a technical delivery address, not information about you or your learning. Firebase (Google) and Apple process that token to route occasional broadcast notices — the same notice for everyone, never anything personal or learning-specific. Turning reminders off deletes it. The same notices also appear as in-app cards on Today, so switching reminders off costs you nothing but the interruption.

This is stated here rather than inside the app so the settings screen stays short; it is the complete description of what leaving reminders on involves.

8. What we do NOT do

9. Children

The app is a general-audience language-learning tool and is not directed at children. We do not knowingly collect data from children; the optional data-sharing features are presented for the account holder to decide.

10. Where data is processed

Our own servers run on Cloudflare's global network. Optional improvement data is processed by Google worldwide, including in the United States (§6). Your learning data syncs through Apple's iCloud under your own Apple account. Transfers outside the EU/EEA rest on the providers' standard contractual clauses and, where applicable, the EU–US Data Privacy Framework.

11. Your rights

Under the GDPR you can ask us, free of charge, for:

An honest note on scope: for most of what the app does, we hold nothing about you to retrieve or delete — your learning data is in your iCloud, not with us. Where we do hold something (a feedback message, a diagnostic report), write to [email protected] and we will act on it promptly.

You also have the right to complain to a supervisory authority. For Baden-Württemberg, where we are based: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (baden-wuerttemberg.datenschutz.de).

12. Changes to this policy

When the app gains features that change what data is handled, this policy is updated before or together with that release, the effective date above changes, and material changes are called out in the app rather than slipped in silently.

This policy is provided in English.