Privacy Policy

DRAFT — English translation of the Polish draft; the Polish version is binding. To be reviewed by a lawyer before publication. Fields [[…]] to be completed.

Version: 0.1 (draft) · Effective from: [[date]]


1. Controller

The controller of personal data is [[company name]], [[address]], [[tax / registration number]] ("we"). Data protection contact: [[e-mail address]]. [[Data Protection Officer: not appointed / DPO details.]]

2. In short

3. What data, why, on what basis, for how long

data purpose legal basis (GDPR) retention
email address account, sign-in, account messages (codes, terms changes, security) contract (Art. 6(1)(b)) until account deletion
sign-in codes (hashed), time and number of attempts sign-in, protection against guessing contract; legitimate interest — security (f) minutes
session id, device id, platform, push token keeping you signed in, notifications you enable contract until sign-out / account deletion
course progress, favourites, settings app functionality, sync between devices contract until account deletion
referral code, referral link, commissions, payout details referral programme and its settlement contract; legal obligation — accounting (c) until account deletion; accounting records [[5 years]]
subscription purchase details (store transaction id, plan, status) access to paid content, "Restore purchases", complaints contract until account deletion; accounting records [[5 years]]
server logs: IP address, time, path, device id security, abuse detection, diagnostics legitimate interest (f) [[30]] days
correspondence with us replying, proof of handling contract; legitimate interest [[3 years]]

We do not profile you or make automated decisions with legal effects. You can use the app as a guest without giving any data — settings then stay on your device only.

4. Recipients

Only processors acting on our behalf under a data processing agreement: [[Amazon Web Services EMEA SARL]] (hosting, EU), [[email provider]] (sign-in codes and account messages), Google (Firebase Cloud Messaging) and Apple (APNs) for push notifications you enable, Google Play and Apple App Store for subscriptions (we never see card details). Public authorities where the law requires it. We do not sell data or share it with advertisers.

5. Transfers outside the EEA

Data is stored in the EEA. It leaves the EEA only for push notifications and store purchases, based on [[an adequacy decision (EU-US Data Privacy Framework) / standard contractual clauses]].

6. Your rights

You have the right of access, rectification, erasure, restriction, portability, objection to processing based on legitimate interest, and to withdraw consent.

7. Security

Connections are encrypted (TLS). Sign-in codes are stored hashed. Server access is limited to people who need it, with [[two-factor]] authentication. Database backups are encrypted and kept in the same region.

8. Children

The app is intended for people aged [[16]]+. We do not knowingly collect data of younger people.

9. Cookies and local storage

The mobile app uses no cookies. The web version uses only storage strictly necessary to work (session, settings, downloaded content), so no consent banner is shown. [[Update if analytics is ever added.]]

10. Changes

We will announce material changes in the app and by email [[14]] days in advance. The current version is always at [[/legal/prywatnosc]].

regulamin · polecenia · usun-konto · zasady-tworcow · zasady-tresci