The essentials in 20 seconds
- Without an account your progress stays on the device; only de-identified analytics, crash reports and a subscription check go out.
- If you sign in, we sync only progress, settings and the flashcards you create yourself.
- If you sign in, other learners see your name, profile photo, XP and streak on the leaderboard.
- Premium is paid for through the App Store or Google Play. RevenueCat tells us only the subscription status; we never receive card details.
- Pronunciation and spoken answers are recognised by your phone’s built-in speech recognition (Apple or Google). Only if it does not support German is a short recording sent to Google Gemini to be transcribed.
- AI features send Google Gemini only what you trigger yourself: such a recording, a photo of a word list, or text. We never store it.
- Analytics is pseudonymous: it never contains your text, speech or photos.
- Deleting your account wipes both the cloud and the device. We keep no “just in case” backup.
Who we are and what this document covers
The “Deutsch” app helps you learn German from A0 to B2. This policy describes how the app and this web page handle data.
- Data controller
- Oleksandr Turovskyi, independent developer
- Data contact
- foodysupport@gmail.com
- Application
- Deutsch —
com.turoff.deutsch(iOS, Android) - Revision
- 2.2, 2 October 2026
- Scope
- The app, cloud sync and the deutsch web pages (privacy, support)
We deliberately keep the data footprint minimal: anything not listed below is not collected. If you find a discrepancy between this text and how the app behaves, tell us — we will fix either the text or the code.
What data we process
| Data | Why | Where it lives | Linked to you |
|---|---|---|---|
| Account: e-mail, name, internal identifier | Sign-in and cross-device sync | Firebase Authentication | Yes |
| Progress: completed lessons, XP, streaks, review cards, exam results, achievements | So the course resumes where you left off | Device + Firestore (only if you are signed in) | Yes |
| Your own flashcard sets and saved words | This is your material — we store it for you | Device + Firestore (if you are signed in) | Yes |
| Leaderboard profile: name, profile photo, total and weekly XP, streak | The learner leaderboard: other signed-in users can see this. Name and photo can be changed in your profile | Firestore (only if you are signed in) | Yes |
| Profile photo (if you uploaded one) | Showing your avatar in your profile and on the leaderboard | Firebase Cloud Storage | Yes |
| Subscription: Premium status, purchase history, store transaction identifiers, account identifier (anonymous for guests) | Unlocking Premium and restoring it on another device | RevenueCat; the payment itself is taken by the App Store or Google Play | Yes |
| Usage events: screen opened, lesson start/finish, exercise outcome, AI error, subscription screen shown and the outcome of a purchase attempt | To see where the course breaks and fix it | Firebase Analytics | Pseudonymous |
| Crash reports: stack trace, device model, OS version | Fixing bugs | Firebase Crashlytics | Pseudonymous |
| Audio of your pronunciation and spoken answers | Recognising what you said to compare it with the expected answer | Usually recognised by your phone’s built-in service (Apple or Google). Only if it does not support German, or when you dictate a reply in the AI dialogue, is the recording sent to Google Gemini; not stored by us | No |
| Photo of a word list (your choice) | Turning the snapshot into flashcards | Sent to Google Gemini; not stored by us | No |
| Text in the AI tutor, dialogues and handwriting input | Getting a reply or a breakdown | Sent to Google Gemini; not stored by us | No |
| Answers in regular exercises | Checking correctness | On your device only — never transmitted | No |
What we never collect: precise location, contacts, calendar, the list of installed apps, the advertising identifier (the AD_ID permission is explicitly removed from the built manifest), payment or banking data (subscription payments are taken by the App Store and Google Play), health data, and push tokens (the app has no push notifications — only local reminders).
In guest mode your progress never leaves the device. The only things that do are the AI requests you trigger by hand, pseudonymous analytics and crash reports, course content downloads, and a subscription-status check with RevenueCat under an anonymous identifier.
Legal bases for processing (GDPR Art. 6)
| Purpose | Data | Basis |
|---|---|---|
| Provide the app, preserve your progress and show you on the leaderboard | Account, progress, your flashcards, leaderboard profile | Performance of a contract — Art. 6(1)(b) |
| Provide the subscription and check whether it is active | Purchase history, account identifier | Performance of a contract — Art. 6(1)(b) |
| Recognise your pronunciation and spoken answers, or fulfil an AI request you initiated | Audio, photos, text | Performance of a contract at your request — Art. 6(1)(b) |
| Protection against abuse and spoofed clients (App Check) | Device integrity signals | Legitimate interest — Art. 6(1)(f) |
| Stability and course improvement | Pseudonymous events, crash reports | Legitimate interest — Art. 6(1)(f) |
| Study reminders | Your chosen time, notification permission | Consent — Art. 6(1)(a), withdrawn by switching it off |
| Responding to a rights request | Your e-mail and the content of your message | Legal obligation — Art. 6(1)(c) |
You may object to processing based on legitimate interest — write to us and we will either stop it or explain why it prevails.
AI features: what actually leaves your device
No AI feature runs in the background. Data is sent only during something you started yourself: a pronunciation exercise, a photo, a message.
The processor is the Google Gemini API. The app calls it directly over an encrypted connection; if that route is unavailable, the request goes through Firebase AI Logic instead, where App Check additionally verifies it (Play Integrity on Android, App Attest on iOS). Google's terms: Gemini API Terms.
We do not store your AI requests. There is no database on our side holding your speech, photos or tutor conversations — chat history lives only in the memory of the current session on your device. Google may process requests temporarily for safety and abuse prevention under its own terms.
Speech recognition. Pronunciation and spoken answers in exercises and exams are recognised first and foremost by your operating system’s built-in service, in which case Apple or Google processes the audio under their own policies, outside our control. Only if the phone has no recogniser for the language you are learning does the recording go to Google Gemini, as described above.
Please do not type sensitive personal information (identity documents, medical or payment details) into AI features — none of it is needed to learn German.
Device permissions and why they exist
| Permission | Why | Required |
|---|---|---|
| Internet | Downloading lessons and audio, cloud sync | Yes |
| Microphone | Only during pronunciation exercises, spoken answers and dictation in the AI dialogue | No |
| Speech recognition (iOS) | Recognising pronunciation and spoken answers with the built-in iOS service | No |
| Camera and photos | Taking or picking a photo of a word list to build flashcards, or a profile photo | No |
| Notifications | Local study reminders at the time you choose | No |
| Vibration | Haptic feedback in exercises | No |
| Run after reboot | So a scheduled reminder survives a phone restart | No |
| Advertising identifier | Not used — the permission is removed from the built manifest | Removed |
Who we share data with
We do not sell data or pass it to advertisers or brokers. Below is the full list of processors acting on our behalf.
| Provider | What it processes | Role | Policy |
|---|---|---|---|
| Google Firebase | Sign-in, progress sync, the leaderboard, profile photo storage, pseudonymous analytics, crash reports, app-integrity checks | Processor | firebase.google.com |
| Google Gemini API (fallback route: Firebase AI Logic) | Photos and text from AI requests; speech recordings only if your phone cannot recognise German itself, or in the AI dialogue | Processor | ai.google.dev |
| Apple / Google (on-device speech recognition) | Audio of pronunciation and spoken answers, when your phone’s built-in service recognises them | Independent controller | apple.com, policies.google.com |
| Google (fallback text-to-speech) | German phrases from lessons when no pre-rendered audio exists. Contains none of your data | Processor | policies.google.com |
| Supabase | Delivery of course content and audio files. No user data is stored there | Content hosting | supabase.com |
| RevenueCat | Purchase confirmations from the store, subscription status, transaction identifiers and the in-app account identifier (Firebase uid; anonymous for guests). Receives no payment data | Processor | revenuecat.com |
| Apple App Store / Google Play | Taking the subscription payment and its renewals | Independent controller | apple.com, policies.google.com |
| Apple / Google Sign-In | Verifying sign-in with your account | Independent controller | apple.com |
| Vercel | Hosting this page | Processor | vercel.com |
Lesson narration is pre-rendered and shipped as ready-made files, so speech synthesis never receives any of your data. We may also disclose data where the law requires it, or where it is necessary to protect the rights and safety of users.
International data transfers
Our providers are global cloud services, so data may be processed on servers outside your country, including in the European Union and the United States.
For those transfers the providers rely on the European Commission’s Standard Contractual Clauses and/or certification under the EU–U.S. Data Privacy Framework. Details are in each company’s privacy policy, linked in the previous section.
How long we keep data
| Data | Retention |
|---|---|
| Account and cloud progress | For as long as the account exists. Erased immediately when you delete the account |
| Local data on the device | While the app is installed. Wiped when you uninstall it, reset progress, or sign out |
| Lesson audio cache | Up to 150 MB; the oldest files are pruned automatically |
| Crash reports | A limited period under Google’s settings — typically up to 90 days |
| Analytics events | A limited period under Google’s settings — typically up to 14 months |
| Leaderboard profile and profile photo | For as long as the account exists. Erased together with the account |
| Subscription status and purchase history | At RevenueCat, for as long as needed to service the subscription; we will delete them on request. The App Store and Google Play keep their own purchase history under their own rules |
| Audio, photos and text from AI requests | Not stored by us at all |
| Support correspondence | Up to 12 months after the request is closed |
How we protect data
No system is perfectly secure. If you spot a vulnerability, write to foodysupport@gmail.com — we will reply and fix it. If an incident puts your rights at risk, we will notify you and the supervisory authority within the deadlines set by law.
Deleting your account and data
You can delete everything yourself, with no correspondence and no waiting.
- Open “Settings” in the appThe section is reachable from your profile.
- Scroll down and tap “Delete account”The app will ask for confirmation.
- Confirm the deletionIf a long time has passed since you signed in, you will be asked to sign in again — this prevents someone else deleting your account.
- DoneEvery cloud document belonging to your account is erased — profile, lessons, review cards, saved words, daily activity, exams, achievements, reading progress and your flashcard sets — along with your profile photo, your leaderboard row and the entire local database on the device. The account itself is deleted too.
This cannot be undone. We keep no “just in case” archive, so progress cannot be restored after deletion.
Only want to reset progress? “Settings → Reset progress” clears lessons, reviews, achievements and exams while keeping the account.
Using the app as a guest? Your data exists only on the device — just uninstall the app.
Have a subscription? Deleting the account does not cancel it — turn off auto-renewal in your App Store or Google Play settings. To have us erase the records of your purchases at RevenueCat, write to foodysupport@gmail.com.
Cannot access the app? Write to foodysupport@gmail.com from the address the account is registered to, with the subject “Data deletion”. We will complete the request within 30 days at the latest.
Your rights
We give every user the same set of rights, regardless of where they live.
- Access — obtain a copy of the data we hold about you.
- Rectification — correct inaccurate data; most fields are editable right in your profile.
- Erasure — delete your account and all data (see the section above).
- Restriction — temporarily pause processing.
- Objection — object to processing based on legitimate interest, including analytics.
- Portability — receive your data in a machine-readable format.
- Withdraw consent — for example, turn reminders off; this does not affect the lawfulness of earlier processing.
- Complaint — lodge one with the data protection supervisory authority in your country.
To exercise any right, write to foodysupport@gmail.com. We respond within 30 days. To avoid handing your data to someone else, we may ask you to confirm that the message came from the account’s address.
For users in California and other US states: we do not sell personal information, do not “share” it for cross-context behavioural advertising, and do not use it for profiling. We never degrade your experience for exercising your rights.
Children
The app is not directed to children under 13, and we do not knowingly collect their personal data. In countries where a higher age applies to consent (up to 16 in some EU member states), the app should be used with the permission of a parent or guardian.
If you are a parent or guardian and believe a child has given us data, write to foodysupport@gmail.com and we will delete the account and all related data.
Advertising, tracking, data sales and payments
The app contains no advertising, no ad SDKs and no cross-app tracking. Our Apple App Tracking Transparency declaration is tracking = false, which is why the app never shows a tracking prompt. The Android advertising identifier is stripped from the built manifest, so it is unavailable even to bundled libraries.
We make no automated decisions producing legal effects for you. Exercise scoring and the review schedule are learning mechanics, not profiling.
The app offers an optional auto-renewable subscription, Deutsch Premium. The payment itself is handled entirely by the App Store or Google Play acting as independent controllers: card numbers, billing addresses and any other payment details never reach us. RevenueCat receives the purchase confirmation from the store and tells us only whether the subscription is active, keyed to an account identifier rather than to your e-mail address. None of this involves advertising — the app carries none.
What we declare in the App Store and Google Play
This section matches the App Store “App Privacy” card and the Google Play “Data safety” form.
| Category | Collected | Linked to you | Used for tracking |
|---|---|---|---|
| Contact info (e-mail, name) | Yes | Yes | No |
| Identifiers (user ID) | Yes | Yes | No |
| App instance identifier (analytics) | Yes | No | No |
| Purchases (subscription history) | Yes | Yes | No |
| Product interaction | Yes | No | No |
| Diagnostics and crashes | Yes | No | No |
| Audio data | Yes | No | No |
| Photos | Yes | Profile photo only | No |
| Other user content | Yes | No | No |
| Location, contacts, financial info, health, advertising data | No | — | No |
This page
The page you are reading sets no cookies, runs no analytics and contacts no third-party servers — no external fonts, scripts or tracking pixels. All styling is embedded in the file itself.
Your language and theme choices are kept only in your browser’s local storage and are never transmitted. The hosting provider may keep standard access logs (IP address, browser type) for security and abuse protection.
Frequently asked questions
Can I learn without registering?
Yes. The app works without an account and keeps progress on the device. Cloud sync and the leaderboard start only after you sign in — that is your deliberate choice.
Does the app listen in the background?
No. The microphone turns on only during a pronunciation or spoken-answer exercise (or while you dictate a reply in the AI dialogue), and turns off immediately afterwards. What you say is usually recognised by your phone’s built-in service; a recording goes to Google Gemini only if the phone does not support the language you are learning, or in the AI dialogue.
Is my data used to train AI?
We do not submit your data for model training. Requests are processed by Google under the Gemini API terms, and we store neither the requests nor the responses.
Can I turn analytics off?
There is no dedicated switch in the app yet. Analytics is pseudonymous and never contains your text, speech or photos. If you would like us to delete the analytics data tied to your identifier, write to foodysupport@gmail.com.
What happens to my data when I sign out?
Before signing out the app uploads your progress to the cloud and then clears the local database. Signing back into the same account restores everything.
Who can see me on the leaderboard?
Other signed-in learners: they see your name, profile photo, XP and streak. Nobody sees your e-mail address or the rest of your progress. You can change the name and photo in your profile, and deleting the account removes you from the board.
Are there any payments in the app?
Yes — an optional Deutsch Premium subscription. The App Store or Google Play takes the payment, so we never see your card at all. All we learn is whether the subscription is active. Without it the app keeps working: the first sections of your level, one final exam, the first story, the review queue, the dictionary and your statistics stay free.
Changes to this policy
We may update this policy, for example when new features ship. The current revision always lives here, with its date and number shown at the top of the page. We will announce material changes in the app.
- 2.22 October 2026Corrected the order of speech recognition: pronunciation and spoken answers are recognised by the phone’s built-in service (Apple or Google), and a recording goes to Google Gemini only if the phone does not support German, or in the AI dialogue. Clarified when the microphone turns on.
- 2.12 October 2026Corrections. Added the Deutsch Premium subscription: RevenueCat and the stores joined the processor inventory and a Purchases category joined the store declarations; removed the outdated claim that the app has no in-app purchases. Described the public leaderboard and profile photos. Clarified that AI requests go to the Gemini API directly, with Firebase AI Logic as the fallback route; removed the mention of an AI relay server this app does not use.
- 2.018 August 2026Full rewrite: added legal bases, retention periods, the permission and processor inventories, and store declarations. Clarified that Supabase only delivers course content and stores no user data, and that AI requests in public builds go directly through Firebase AI Logic.
- 1.0August 2026First edition of the policy.
Contact
Data controller: Oleksandr Turovskyi, independent developer of the Deutsch app.
foodysupport@gmail.com — we reply within 30 days.
If our answer does not satisfy you, you have the right to lodge a complaint with the data protection supervisory authority where you live.