Privacy Policy
Version 2026-09-27
<!-- Draft — generated from generic templates, not legal advice; review before publishing. -->
# Privacy Policy
**This English page is a courtesy translation. The German version (`privacy.de.md`) is the legally binding text for this service, which is operated from Germany and subject to the GDPR.** If the two versions differ, the German version controls.
This policy explains what personal data we process when you use NixQuest, for what purpose, on what legal basis, and for how long.
## 1. Controller
{{OPERATOR_NAME}}
{{SERVICE_ADDRESS}}
Germany
Email: {{EMAIL}}
## 2. At a glance
- For registered users, NixQuest stores an account (email, password hash, display name), your learning progress and any feedback you give, on our own server in Germany.
- Without an account (demo mode), we store nothing on our server; your progress stays in your browser (localStorage), and we use a random, non-identifying id for anonymous usage statistics.
- We use exactly one strictly-necessary cookie (the session cookie). There is no cookie banner, because we do not use any cookies that would require consent.
- We use a self-hosted, cookieless analytics tool (Plausible) and a small number of external processors (Section 6) who process data on our behalf.
- You can delete your account yourself at any time and export your data as JSON (account settings).
## 3. What we process and why
### 3.1 Registration and account (email + password)
When you register, we process: email address, password (stored as a hash, never in plain text), display name, registration timestamp, verification status, and — during the beta — the invite code used.
- **Purpose:** creating and managing your account, logging in, resetting your password.
- **Legal basis:** Art. 6(1)(b) GDPR (performance of the usage agreement you enter into by registering).
- **Retention:** until you delete your account; see Section 8 on backups.
### 3.2 Login session (session cookie)
After you log in, we set a session cookie that identifies your session. It is `httpOnly`, `Secure` and `SameSite=Lax`, and contains no content readable by you — only a session identifier.
- **Purpose:** keeping you logged in so the app can function at all.
- **Legal basis:** Art. 6(1)(b) GDPR, and Section 25(2) no. 2 of the German Telecommunications-Digital-Services-Data-Protection Act (TDDDG) — a strictly necessary cookie that does not require consent.
- **Retention:** until logout or session expiry.
### 3.3 Bot protection on signup, login and password reset (Cloudflare Turnstile)
On the signup, login and password-reset forms we use Cloudflare Turnstile, a service that distinguishes humans from automated access without the usual CAPTCHA puzzles. This transmits technical data (including your IP address and device/browser characteristics) to Cloudflare for evaluation.
- **Purpose:** protection against automated abuse (e.g. mass signups, password brute-forcing).
- **Legal basis:** Art. 6(1)(f) GDPR (our legitimate interest in a working service free of abuse).
- **Recipient / transfer outside the EU:** Cloudflare, Inc. (USA); transferred under the EU-US Data Privacy Framework (DPF), which Cloudflare has joined. See Section 6.
- **Retention:** as set by Cloudflare; we do not permanently store the check's result ourselves.
### 3.4 Learning progress
We store which lessons and steps you have completed, your per-step results, and a simple progress score (XP), so your progress follows you across devices.
- **Purpose:** performance of the contract (providing the course, including progress tracking).
- **Legal basis:** Art. 6(1)(b) GDPR.
- **Retention:** until you delete your account.
### 3.5 Demo use without an account
Without registering, you can try part of the course. Your progress is stored only locally in your browser (localStorage), not on our server. If you register later, this local progress is merged into your account once.
- **Purpose:** letting you use the demo without being forced to register; carrying that progress into your account if you later sign up.
- **Legal basis:** Art. 6(1)(b) GDPR (pre-contractual step, or use of the free demo feature) or Art. 6(1)(f) GDPR where no contract is being entered into.
- **Retention:** under your control (browser storage); removed when you clear your browser data.
### 3.6 Usage events (learning statistics)
We record certain events to improve the course: lesson start and completion, per-step results (passed/failed, attempt number, whether a solution was revealed), feedback you submit, and a few other technical events.
- For registered users, these events are tied to your account.
- For demo use without an account, we use a randomly generated id stored only in your browser (localStorage), not in a cookie. We do not store an IP address alongside these events.
- **Purpose:** understanding how the course is used, where learners get stuck, and improving the content.
- **Legal basis:** Art. 6(1)(b) GDPR (registered use, part of performing the contract / improving the product) or Art. 6(1)(f) GDPR (legitimate interest in improving the service, demo use).
- **Retention:** 13 months from collection, after which only aggregated, no-longer-personal data is kept.
### 3.7 Feedback (ratings, comments, problem reports)
You can rate lessons 1–5 stars with an optional comment, use a general feedback form, or report a problem on a step. When you report a problem, we also store the code you had written in that exercise at the time, so we can reproduce the issue.
- **Purpose:** quality assurance and improving the course.
- **Legal basis:** Art. 6(1)(a) GDPR (you give feedback voluntarily) or Art. 6(1)(f) GDPR (our legitimate interest in improving the service).
- **Retention:** until handled, and afterwards for as long as is reasonable to track what changed as a result; at the latest, when you delete your account, the link to your identity is removed or the feedback is deleted, unless we have a legitimate interest in keeping it.
### 3.8 Transactional email
We send emails to verify your address and to reset your password, via our provider Brevo (see Section 6).
- **Purpose:** account security and management.
- **Legal basis:** Art. 6(1)(b) GDPR.
- **Retention:** delivery logs are kept per Brevo's standard retention; see their own privacy notices.
### 3.9 Error diagnostics (Sentry)
If the app errors (in the browser or on the server), we send technical error information to Sentry, our error-tracking provider. We configure Sentry to strip known personal fields (such as email addresses) and any exercise code you wrote before it is sent ("PII scrubbing").
- **Purpose:** detecting and fixing technical bugs.
- **Legal basis:** Art. 6(1)(f) GDPR (legitimate interest in a working, bug-free service).
- **Recipient / transfer outside the EU:** Functional Software, Inc. (Sentry), USA; see Section 6.
- **Retention:** per Sentry's default retention (typically 90 days for error events).
### 3.10 Operational monitoring (uptime checks)
An external service (UptimeRobot or similar) periodically calls a technical status endpoint on our servers to detect outages. This does not process any personal data about you.
- **Purpose:** keeping the service available.
- **Legal basis:** Art. 6(1)(f) GDPR.
### 3.11 Traffic analytics (self-hosted Plausible)
We use a self-hosted analytics tool (Plausible), run on our own server, which works without cookies and does not build a persistent per-person identifier. It gives us only aggregated information (e.g. page views, approximate location, browser type).
- **Purpose:** understanding overall use of the site (not the fine-grained, logged-in course area — see 3.6 for that).
- **Legal basis:** Art. 6(1)(f) GDPR (legitimate interest in simple, privacy-friendly traffic measurement); since no cookie is set and no cross-session recognition occurs, we do not believe consent under Section 25 TDDDG is required.
- **Recipient:** none; the data never leaves our own infrastructure.
## 4. Cookies and similar technology (Section 25 TDDDG)
The German Telecommunications-Digital-Services-Data-Protection Act (TDDDG, formerly TTDSG) requires consent before setting a cookie or reading information from your device, unless this is strictly necessary to provide a service you have explicitly requested.
We use:
- **a session cookie** (see 3.2): strictly necessary to keep you logged in — no consent required.
- **localStorage** for your demo progress and, in demo mode, a random anonymous id: not a cookie technically, but treated similarly; in our assessment also strictly necessary for the feature you are using (progress without an account) or covered by a legitimate interest in aggregated statistics.
- **Cloudflare Turnstile** (see 3.3): technically required to protect the forms you are using (signup, login, password reset) from abuse.
We therefore show no cookie banner: in our assessment, we do not use any cookie that would require consent under Section 25 TDDDG. If that assessment changes (for example through new features), we will update this page and, if needed, add consent management.
## 5. Automated decision-making
We do not use any automated process within the meaning of Art. 22 GDPR that produces a legal or similarly significant effect on you. Bot protection (Turnstile) does not make a final decision about access; a failed check merely leads to being asked again.
## 6. Recipients and processors
We do not sell or share your data with third parties for advertising purposes. The following providers process data on our behalf, or receive data from us as part of their function:
| Provider | Location | Purpose | Basis for transfer |
|---|---|---|---|
| Hetzner Online GmbH | Germany (EU) | Hosting the app and database; backup storage (Storage Box) | Data processing agreement (Art. 28 GDPR); no transfer outside the EU |
| Brevo (Sendinblue SAS) | France (EU) | Sending verification and password-reset emails | Data processing agreement (Art. 28 GDPR); no transfer outside the EU |
| Cloudflare, Inc. (Turnstile) | USA (with EU infrastructure too) | Bot protection on signup, login, password reset | EU-US Data Privacy Framework (adequacy decision), supplemented by Standard Contractual Clauses where needed |
| Functional Software, Inc. (Sentry) | USA | Error tracking (with PII scrubbing) | EU-US Data Privacy Framework or Standard Contractual Clauses |
| UptimeRobot | {{UPTIMEROBOT_LOCATION}} | Uptime monitoring (no personal data about you) | – (no personal data involved) |
<!-- {{UPTIMEROBOT_LOCATION}}: fill in the location/processing region of the UptimeRobot account/plan actually used; the server location can differ by plan. -->
We have (or will have, before launch) data processing agreements under Art. 28 GDPR with Hetzner and Brevo. For Cloudflare and Sentry, both US-based, we rely on their participation in the EU-US Data Privacy Framework, backed up by Standard Contractual Clauses as each provider offers them. Details in `dpa-checklist.md` (internal).
## 7. Your rights
Under the GDPR you have the right to:
- **access** (Art. 15 GDPR) the data we process about you;
- **rectification** (Art. 16 GDPR) of inaccurate data;
- **erasure** (Art. 17 GDPR) — for your account, you can trigger this yourself in account settings at any time, with immediate effect;
- **restriction of processing** (Art. 18 GDPR);
- **data portability** (Art. 20 GDPR) — you can export your data as a JSON file in account settings at any time;
- **object** (Art. 21 GDPR) to processing based on Art. 6(1)(f) GDPR;
- **withdraw consent** (Art. 7(3) GDPR) with effect for the future, where processing is based on consent (e.g. feedback);
- **lodge a complaint with a supervisory authority** (Art. 77 GDPR), in particular the data protection authority responsible for {{OPERATOR_STATE_OR_REGION}}, or the authority where you habitually reside.
To exercise any of these rights, an email to {{EMAIL}} is enough.
## 8. Retention and backups
We back up our database nightly; these backups are kept for 30 days and then automatically overwritten. If you delete your account, it is removed from the live system immediately; it may still exist in backups already taken until their 30-day retention expires, after which it is automatically deleted along with the rest of that backup.
## 9. Minimum age
Using NixQuest requires you to be at least 16 years old. We do not collect proof of age, but rely on the corresponding declaration made at registration.
## 10. Notice for US / California visitors
NixQuest is aimed at learners worldwide but is operated from Germany and subject to the GDPR. Given the small size of the service (a beta with under 1,000 learners), we currently do not meet the thresholds of the California Consumer Privacy Act (CCPA/CPRA); we do not "sell" or "share" (as those terms are used under the CCPA) personal data, and we run no advertising tracking. Regardless, US-resident visitors are welcome to send an access or deletion request to {{EMAIL}}; we handle such requests the same way as requests under Section 7 of this policy.
## 11. Changes to this policy
We update this policy when our processing changes. The current version carries the version date shown above.
## 12. Contact for privacy questions
{{OPERATOR_NAME}}
{{EMAIL}}
<!-- At this scale, we do not expect a Data Protection Officer to be required under Art. 37 GDPR; this should be confirmed by a lawyer before a paid launch. -->