Privacy Policy
Last Updated: November 19, 2025
1. Introduction
Welcome to EgalDeutsch. We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our German learning platform.
This Privacy Policy complies with the General Data Protection Regulation (GDPR) of the European Union and German data protection laws (BDSG - Bundesdatenschutzgesetz).
Data Controller: Steve Phan
Contact Email: egaldeutsch.com@gmail.com
2. Information We Collect
2.1 Information You Provide
When you register for an account or use our Service, we may collect:
- Name (first name and last name)
- Email address
- Username
- Password (encrypted)
- Language proficiency level
- Learning preferences and progress
2.2 Automatically Collected Information
When you access our Service, we automatically collect:
- IP address
- Browser type and version
- Device information
- Operating system
- Referring/exit pages
- Date and time stamps
- Clickstream data
2.3 Learning and Usage Data
- Quiz scores and performance
- Stories read and completion rates
- Time spent on the platform
- Learning progress and statistics
- Leaderboard rankings
3. How We Use Your Information
We use the collected information for the following purposes:
- Service Provision: To provide and maintain our learning platform
- Account Management: To create and manage your user account
- Personalization: To personalize your learning experience
- Progress Tracking: To track your learning progress and achievements
- Communication: To send important updates, notifications, and educational content
- Analytics: To analyze usage patterns and improve our Service
- Security: To detect, prevent, and address technical issues and security threats
- Legal Compliance: To comply with legal obligations
4. Legal Basis for Processing (GDPR)
Under GDPR, we process your personal data based on:
- Consent: You have given consent for specific purposes (Article 6(1)(a) GDPR)
- Contract Performance: Processing is necessary for providing our Service (Article 6(1)(b) GDPR)
- Legal Obligation: Processing is required by law (Article 6(1)(c) GDPR)
- Legitimate Interests: Processing is necessary for our legitimate interests, such as improving our Service (Article 6(1)(f) GDPR)
5. Third-Party Services
We use the following third-party services that may process your data:
Netlify (Hosting)
Our platform is hosted on Netlify's infrastructure. Netlify may process technical data such as IP addresses and usage logs.
Privacy Policy: https://www.netlify.com/privacy/
Google Services (Analytics & Functionality)
We may use Google Analytics or other Google services to analyze how users interact with our platform. Google may use cookies and similar technologies to collect usage data.
Privacy Policy: https://policies.google.com/privacy
MongoDB (Database)
User data and learning progress are securely stored in MongoDB databases with encryption and access controls.
Privacy Policy: https://www.mongodb.com/legal/privacy-policy
6. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience. Cookies are small data files stored on your device.
Types of cookies we use:
- Essential Cookies: Required for the Service to function (e.g., authentication)
- Analytics Cookies: Help us understand how users interact with our Service
- Preference Cookies: Remember your settings and preferences
You can control cookie settings through your browser, but disabling certain cookies may limit functionality.
7. Data Retention
We retain your personal data only as long as necessary for the purposes outlined in this Privacy Policy:
- Account Data: Retained while your account is active and for 30 days after account deletion
- Learning Data: Retained to track your progress unless you request deletion
- Analytics Data: Anonymized and retained for statistical purposes
8. Your Rights Under GDPR
As a user in the EU/Germany, you have the following rights:
- Right of Access: Request a copy of your personal data we hold
- Right to Rectification: Correct inaccurate or incomplete personal data
- Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data
- Right to Restriction: Limit how we use your personal data
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing of your personal data
- Right to Withdraw Consent: Withdraw your consent at any time
- Right to Lodge a Complaint: File a complaint with a supervisory authority
To exercise any of these rights, please contact us at egaldeutsch.com@gmail.com
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data:
- Encryption of data in transit (HTTPS/TLS)
- Encryption of sensitive data at rest
- Password hashing using industry-standard algorithms
- Regular security assessments and updates
- Access controls and authentication mechanisms
- Secure database configurations
However, no method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
10. International Data Transfers
Your data may be transferred to and processed in countries outside the EU/EEA. When we transfer data internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, to protect your data in accordance with GDPR requirements.
11. Children's Privacy
Our Service is intended for users aged 16 and above. If you are under 16, please obtain parental consent before using our Service. We do not knowingly collect personal data from children under 16 without parental consent. If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete such information.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We encourage you to review this Privacy Policy periodically.
13. Supervisory Authority
If you have concerns about how we handle your personal data, you have the right to lodge a complaint with a data protection supervisory authority.
For Germany:
Die Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)
https://www.bfdi.bund.de
14. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Data Controller: Steve Phan
Email: egaldeutsch.com@gmail.com