Privacy Policy

This Privacy Policy explains how Deutschub UG (haftungsbeschränkt) processes personal data when you use the Deutschi iOS app, the website deutschi.app, or contact us. It also explains the choices available in the app. Consent is requested separately where it is required; simply using the app does not constitute consent to optional analytics or advertising processing.

1. Controller

Deutschub UG (haftungsbeschränkt)
Pestalozzistraße 25
22305 Hamburg
Germany
Email: info@deutschi.app

Privacy requests can be sent to the email address above.

2. Legal bases and purposes

Depending on the processing, we rely on:

  • Article 6(1)(b) GDPR to provide accounts, synchronize learning progress, and deliver requested app functions;
  • Article 6(1)(c) GDPR to comply with legal obligations;
  • Article 6(1)(f) GDPR for secure technical operation, fraud prevention, error diagnosis, and the protection of our services, where those interests are not overridden by your rights; and
  • Article 6(1)(a) GDPR for optional Firebase Analytics and consent-based advertising processing.

Where information is stored on or accessed from a device, applicable national ePrivacy rules also apply, including Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG): either your consent or the exception for storage/access strictly necessary to provide the service you requested.

3. The deutschi.app website

The website is an informational site. It does not contain registration forms and we do not use website analytics or advertising cookies. It is hosted with Firebase Hosting, a Google service. When a page is requested, technical server data may be processed, including IP address, date and time, requested URL, referrer, browser/user-agent, operating system, and response status. This is necessary to deliver and protect the website. Firebase states that Hosting retains IP information for a limited period of a few months.

The website links to the App Store, Instagram, and TikTok. Those providers receive data only when you follow the respective external link and then process it under their own privacy policies.

4. Accounts, authentication, and learning data

Deutschi uses Firebase Authentication and Cloud Firestore. On first use, the app may automatically create an anonymous guest account with a randomly generated Firebase user ID. A guest account does not require a name or email address. If you register, Firebase Authentication processes your name, email address, password credential, user ID, authentication timestamps, IP address, and technical security information. We cannot read your password.

Cloud Firestore stores data needed to provide and synchronize the app, such as the selected support language, learning and lesson progress, short-story progress, saved vocabulary, and account profile data. These records are assigned to the Firebase user ID. Firebase may keep a local offline cache on the device so the app remains responsive.

The legal basis is Article 6(1)(b) GDPR. Authentication security and abuse prevention are additionally based on Article 6(1)(f) GDPR.

5. App security, cloud functions, and crash reports

Firebase App Check and Apple DeviceCheck

We use Firebase App Check with Apple's DeviceCheck to verify that requests come from an authentic instance of the app. Google and Apple may process attestation tokens and technical information about the app and device. We use this to protect accounts, Firebase resources, and other users against automated abuse. The legal basis is Article 6(1)(f) GDPR.

Firebase Cloud Functions

Cloud Functions perform protected server-side tasks, including account deletion. Authenticated user ID, request time, IP address, function status, and technical logs may be processed to execute and secure these requests.

Firebase Crashlytics

Crashlytics is active to identify and fix app crashes. It may process crash stack traces, error context, app state at the time of a crash, app version, device model, operating-system version, timestamps, and installation identifiers. We use this information only for stability, security, and troubleshooting, based on Article 6(1)(f) GDPR. Firebase states that Crashlytics retains crash information for 90 days.

6. Firebase Analytics

Deutschi uses Firebase Analytics to understand aggregate app usage and improve the app. Where consent is required, the app uses Google's User Messaging Platform and Google's consent mode signals for Analytics storage. Outside regions where this consent is not required, Analytics may be used according to applicable law.

Firebase Analytics may receive app launches, session duration, screens or features used, app version, device model, operating system, a randomly generated app-instance identifier, approximate location derived from the IP address, and advertising interactions. Deutschi does not set the Firebase account user ID in Analytics. We do not use Firebase Analytics to personalize advertising.

You can change available Google privacy choices at any time under Settings → Privacy Settings. Withdrawal disables future consent-based collection; it does not retroactively remove aggregate reports already created. User-level event data is retained according to the Google Analytics setting, for no longer than 14 months, while aggregated reports may remain longer. Where consent is required, the legal basis is your consent under Article 6(1)(a) GDPR and applicable national ePrivacy law, including Section 25(1) TDDDG in Germany.

7. Advertising and Google's consent form

Deutschi uses Google AdMob to display ads. Before requesting ads, the app uses Google's User Messaging Platform (UMP) to collect or communicate advertising privacy choices where required. The list of participating advertising vendors and their purposes is available inside that form. Advertising privacy choices can be reopened under Settings → Privacy Settings → Advertising privacy options.

Deutschi configures every ad request as non-personalized and does not request Apple's App Tracking Transparency permission. Non-personalized ads can still use contextual information and limited technical data for ad delivery, frequency capping, reporting, fraud prevention, security, and measurement. Depending on your choices and applicable law, Google and participating vendors may process IP-derived approximate location, device and app identifiers, device information, ad impressions and interactions, diagnostics, and consent records.

Where consent is required, the legal basis is Article 6(1)(a) GDPR and applicable national ePrivacy law, including Section 25(1) TDDDG in Germany. Contextual ad delivery, security, and fraud prevention may also rely on Article 6(1)(f) GDPR where permitted. We do not sell personal data for money.

8. Local device storage

The app stores necessary preferences and state locally, including language settings, login state, learning caches, and privacy choices. Necessary storage supports the app functions you request. Analytics and advertising consent records are stored to remember and prove your choice. Local app data is normally removed when you uninstall the app, but uninstalling does not automatically delete data already stored in Firebase.

9. Account and data deletion

Registered and anonymous users can start account deletion in the app settings. Registered users may need to sign in again before deletion for security. Anonymous accounts cannot sign in again, so the currently authenticated anonymous account can be deleted directly.

The protected server function deletes the authenticated Firebase Authentication account and the associated Firestore profile, learning progress, short-story progress, and vocabulary records, including subcollections. The deletion flow also clears local app preferences on the current device. Deletion is irreversible.

Deleting the app is not the same as deleting the account. Delete the account in the app before uninstalling if you want server-side data removed. If you no longer have access, contact us; we may need sufficient information to locate and verify the account. Firebase documentation notes that Authentication backup systems may retain deleted data for up to 180 days before it is fully removed. Security, billing, and function logs may remain for their limited provider or statutory retention periods.

10. Service providers and international transfers

We use Google Firebase, Google Cloud, Google Analytics for Firebase, Google AdMob, and UMP. For users in the European Economic Area, the relevant Google contracting entity is generally Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; processing may also involve Google LLC and infrastructure in the United States or other countries. Depending on the service, Google acts as our processor or as a separate controller.

Transfers outside the EEA are protected, where required, through adequacy decisions such as the EU-US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses. DeviceCheck involves Apple and its affiliates. Further information is available in Firebase Privacy and Security, the Firebase iOS data disclosure guide, Google's Privacy Policy, and Apple's Privacy Policy.

11. Retention

Account and learning data is kept while the account is active and until it is deleted or no longer needed to provide the service. Consent choices remain on the device until changed, app data is cleared, or the app is uninstalled. Crashlytics data is retained for 90 days. Analytics user-level event data is retained for no longer than 14 months. Hosting IP information and technical logs are retained for limited operational and security periods. Data required for legal claims, accounting, or statutory obligations may be kept for the applicable limitation or retention period.

12. Your rights

Subject to the legal requirements, you may request access, rectification, erasure, restriction of processing, and data portability. You may object to processing based on Article 6(1)(f) GDPR. You may withdraw consent at any time without affecting processing that was lawful before withdrawal. There is no solely automated decision-making that produces legal or similarly significant effects.

Send requests to info@deutschi.app. We may need to verify your identity. You also have the right to lodge a complaint with a data protection authority, in particular the Hamburg Commissioner for Data Protection and Freedom of Information, or the authority where you live or work. Residents of the United States may also have rights under applicable state privacy laws and can use the same contact address.

13. Changes and contact

We will update this notice when our services or legal requirements change and will show the new date at the top. Material changes may also be communicated in the app. Questions and privacy requests can be sent to info@deutschi.app.