Privacy Policy
Last updated: 28 April 2026
1. Who we are
DeutschWeg ("we", "our", "us") provides an online German language learning platform aimed at learners preparing for Goethe-Institut examinations. This Privacy Policy explains what data we collect, how we use it, who we share it with, and the rights you have over it.
2. Data we collect
When you create an account and use DeutschWeg, we collect:
- Account information — your name, email address, country, and password (the password is hashed by Supabase Auth; we never see the plaintext).
- Learning progress — XP earned, lessons completed, exercise scores, and which modules you have started or finished.
- AI Pal usage — messages you send to the AI assistant, the German language patterns the system flags from those messages, the module you were on, and the timestamps.
- Local preferences — your selected level, day-streak counter, and similar UI settings stored on your device via browser localStorage.
We do not knowingly collect personal data from children under 13.
3. How we use it
- To deliver the learning experience — track which modules you have completed, what XP you have earned, and tailor AI Pal feedback to mistakes you have made before.
- To operate the AI Pal and AI Tutor features (your messages are sent to Anthropic for processing — see "Third parties" below).
- To send essential service emails (account confirmation, password reset).
- To improve the product — anonymised, aggregated patterns only.
4. Third parties
We rely on a small number of providers to operate DeutschWeg. Each handles only the data needed for its role:
- Supabase — authentication, database, and file storage.
- Anthropic — processes the messages you send to AI Pal and AI Tutor. Under Anthropic's API terms, your inputs are not used to train their models.
- Cloudflare Pages — serves the website and handles edge caching.
- Render — hosts the API server used by AI Pal and AI Tutor.
- Google Fonts — serves the website typeface.
5. Cookies and local storage
We use browser cookies and localStorage to:
- Keep you signed in (authentication tokens issued by Supabase).
- Remember your selected level and other UI preferences.
- Record that you have seen and answered the cookie consent banner.
We do not use third-party advertising or behavioural tracking cookies.
6. Data retention
We keep your account and learning progress for as long as your account exists. AI Pal error logs are retained so we can give you better feedback over time. You can request deletion at any time — see "Your rights".
7. Your rights
If you are in the EU, UK, or another jurisdiction with similar laws (GDPR, UK GDPR, or equivalent), you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your account and the personal data tied to it.
- Export your data in a portable format.
- Object to processing in certain cases.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email us at leisure.ish@gmail.com. We aim to respond within 30 days.
8. Security
Authentication is handled by Supabase, which uses industry-standard hashing and encryption. All traffic between your browser and our servers uses HTTPS. No system is perfectly secure, but we treat data security seriously and act promptly on any suspected breach.
9. International transfers
Our providers (Supabase, Anthropic, Cloudflare, Render, Google) operate globally and your data may be processed in countries outside your own, including the United States. Where required, we rely on Standard Contractual Clauses or equivalent safeguards that those providers maintain.
10. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top will reflect the most recent revision. Material changes will be notified by email to active users.
11. Contact
Questions or concerns? Reach us at leisure.ish@gmail.com.