Privacy Policy
Last updated: 2026-07-11.
Introduction
German B1 Exam Trainer ("the service") is operated by Zeronext. This Privacy Policy explains what data we collect when you use our website and services, how we use it, and your rights regarding that data.
Data we collect
We collect and process the following data:
- Account data: When you register, we store your email address, name, chosen exam type (Goethe or TELC B1), and exam date. We process this data on the legal basis of contract performance (Art. 6(1)(b) GDPR).
- Progress data: Your exercise attempts, answers, scores, and completion status for each lesson. We process this data on the legal basis of contract performance (Art. 6(1)(b) GDPR).
- Exercise issue reports: If you are signed in and use "Report a problem" on a lesson, we store your account ID, the exercise reference, a snapshot of the lesson title, your chosen category, and any optional text you provide, so we can review content and fix mistakes. We process this data on the legal basis of contract performance (Art. 6(1)(b) GDPR).
- Avatar: If you upload a profile photo, it is stored and linked to your account. We process this data on the legal basis of contract performance (Art. 6(1)(b) GDPR).
- Speaking and writing: When you use the Sprechen (speaking) or Schreiben (writing) modules, your audio recordings and written text are sent to our AI provider to generate feedback. This data is processed solely for that purpose. We process this data on the legal basis of contract performance (Art. 6(1)(b) GDPR).
- AI usage logs and rate limiting: For Sprechen and Schreiben AI features, we log user IDs, timestamps, and call counts to enforce rate limits and prevent abuse. We process this data on the legal basis of legitimate interest (Art. 6(1)(f) GDPR) in platform stability, security, and abuse prevention.
- AI evaluation debugging snapshots: When our AI generates feedback on your Sprechen (speaking) or Schreiben (writing) submissions, we store the AI model's raw response together with a short technical summary of the request (the task type, which scoring dimensions applied, and a word or transcript length — not a separate copy of your full submission). Because the AI response repeats parts of your submission verbatim inside its corrections, these snapshots contain your submitted text. We use them solely to debug and regression-test our scoring — for example, to check whether a change to our prompts or AI model altered how answers are scored — and not to train or improve AI models. We keep them for at most 180 days and then delete them automatically; if you delete your account, they are deleted with it. We process this data on the legal basis of legitimate interest (Art. 6(1)(f) GDPR) in the accuracy and reliability of the AI feedback we provide.
- Abuse protection (IP-based request limits): For certain public actions (e.g. support form submission, account sign-up, password login), we derive a client IP from platform-controlled request headers and store short-lived counters in our infrastructure (Upstash Redis) to limit excessive requests. We do not use this for marketing profiling. We process this data on the legal basis of legitimate interest (Art. 6(1)(f) GDPR) in security, fraud prevention, and service availability.
- Abuse protection (per-user report limits): For signed-in "Report a problem" submissions, we store short-lived counters in our infrastructure (Upstash Redis) keyed to your user ID to limit excessive reports. We process this data on the legal basis of legitimate interest (Art. 6(1)(f) GDPR) in security, fraud prevention, and service availability.
- Website analytics: When we enable Cloudflare Web Analytics on our production deployment, Cloudflare collects aggregate traffic information (e.g. page views, referrers, and coarse technical information such as device type and country) to help us understand how the site is used. This product is designed to work without analytics cookies and without building individual profiles for advertising. We process this data on the legal basis of legitimate interest (Art. 6(1)(f) GDPR) in operating and improving our website. Details are described in Cloudflare's documentation and privacy policy.
- Product analytics and session recordings (consent-based): Only after you accept via our cookie banner, we use PostHog (hosted in the European Union) to understand how the platform is used — which pages and features you visit, where you click, how long steps take, and where people drop off — so we can improve the product. This includes session recordings of your interactions. All text input (such as your email, password, written answers, and exam responses) and other sensitive on-screen content is masked before it leaves your browser, so we do not see what you type. We set a stable identifier so we can recognise your session across visits and, when you are signed in, link activity to your account. We process this data on the legal basis of your consent (Art. 6(1)(a) GDPR); you can decline at any time without affecting your use of the service.
How we use it
We use your data to deliver the service: to personalise your experience (e.g. showing exercises for your chosen exam type and suggesting the next lesson), to provide AI-based feedback on speaking and writing, to process payments for passes and legacy Pro subscriptions, and to send service emails (welcome email after signup, exam date reminder emails, and a one-time follow-up after your recorded exam date). We do not sell your data to third parties.
Legal basis for processing
For transparency, we summarise the legal basis (Art. 6 GDPR) for each type of processing:
- Art. 6(1)(b) — contract performance: Account, progress, avatar, payments, AI feedback, session cookies, local storage, and service emails (welcome, exam reminders, post-exam follow-up).
- Art. 6(1)(f) — legitimate interest: AI usage logs, rate limiting, AI evaluation debugging snapshots (accuracy and reliability of AI feedback), IP-based abuse prevention (including Upstash counters for selected public endpoints), per-user limits on exercise issue reports (Upstash counters), and (where enabled) privacy-preserving website analytics via Cloudflare (aggregate usage; not used for advertising profiling).
- Art. 6(1)(a) — consent: Product analytics and session recordings via PostHog (EU-hosted), which run only after you accept via the cookie banner; and any other non-essential cookies or tools where we explicitly ask for your consent. You can withdraw consent at any time.
Third parties
We rely on the following service providers, each of which has its own privacy policy:
- Supabase: Authentication, database, and file storage (e.g. avatars, audio files). Processed on the legal basis of contract performance (Art. 6(1)(b) GDPR).
- Stripe: Payment processing for pass purchases and legacy Pro subscriptions. Processed on the legal basis of contract performance (Art. 6(1)(b) GDPR).
- Anthropic: Claude for evaluating and correcting your writing and speaking. Your submitted text and speech transcripts are sent to Anthropic solely to generate feedback. Per Anthropic's commercial API terms, Anthropic does not use API inputs or outputs to train its models by default. Processed on the legal basis of contract performance (Art. 6(1)(b) GDPR). See Anthropic's privacy policy.
- OpenAI: Whisper for speech-to-text (transcribing your Sprechen recordings). Your audio is sent to OpenAI solely to produce a transcript. Per OpenAI's API data usage policy, OpenAI does not use API data for model training, and your data is not retained by OpenAI for training purposes. Processed on the legal basis of contract performance (Art. 6(1)(b) GDPR).
- Cloudflare: Content delivery and security for our website, and (where we turn it on) Web Analytics for aggregate, privacy-oriented usage metrics. Web Analytics is processed on the legal basis of legitimate interest (Art. 6(1)(f) GDPR). See Cloudflare's privacy policy.
- PostHog: Product analytics and session recordings, used only with your consent. We use PostHog Cloud hosted in the European Union, so this data stays in the EU. Text input and sensitive on-screen content are masked before recording. Processed on the legal basis of consent (Art. 6(1)(a) GDPR). See PostHog's privacy policy.
- Upstash: Managed Redis used to enforce short-lived, per-IP request limits on selected public endpoints (abuse prevention). Processed on the legal basis of legitimate interest (Art. 6(1)(f) GDPR). See Upstash's privacy policy.
- Vercel: Hosting and deployment platform. User requests are routed through Vercel's infrastructure to serve the application. Processed on the legal basis of contract performance (Art. 6(1)(b) GDPR). See Vercel's privacy policy.
- Resend: Transactional email delivery for service emails (welcome email after sign-up, exam date reminders, post-exam follow-up). Your email address is shared with Resend solely to deliver these service emails. Processed on the legal basis of contract performance (Art. 6(1)(b) GDPR). See Resend's privacy policy.
- BunnyCDN: Content delivery network used to serve Hören audio exercise files. No account or progress data is shared with BunnyCDN; standard HTTP request metadata (IP address, browser type) may be logged by their infrastructure as part of content delivery. Processed on the legal basis of contract performance (Art. 6(1)(b) GDPR). See BunnyCDN's privacy policy.
We recommend reviewing their privacy policies for details on how they process data.
International transfers
Data may be transferred to the United States or other regions where Supabase, Anthropic, OpenAI, Stripe, Cloudflare, Upstash, Vercel, Resend, and BunnyCDN may process it (including Web Analytics when that feature is enabled for our site, and Redis-backed abuse counters). We ensure appropriate safeguards: Standard Contractual Clauses (SCCs) approved by the European Commission per Art. 46(2)(c) GDPR, and where applicable, the EU-US Data Privacy Framework (DPF) under the adequacy decision of July 2023 (Art. 45 GDPR). Stripe, OpenAI, and Cloudflare are certified under the DPF. Our product analytics provider (PostHog) is used on its EU Cloud, so that data is processed within the European Union. You may request a copy of the relevant safeguards by contacting us at the email below.
Cookies and local storage
We use session and authentication cookies so you can stay logged in. If you use the service without an account (guest mode), we store your progress in your browser's local storage so you can continue later or import it when you sign up. This is processed on the legal basis of contract performance (Art. 6(1)(b) GDPR). We also set a first-party functional cookie named "cid" containing a random identifier (httpOnly, valid for 90 days). It is used solely to compile aggregated visitor and conversion statistics for our own service and to help prevent abuse; it contains no personal details, is not readable by scripts or third parties, and is never used for advertising or cross-site tracking. This is processed on the legal basis of our legitimate interest in measuring and improving our service (Art. 6(1)(f) GDPR); you can object at any time via the contact address below. We do not use advertising cookies. When Cloudflare Web Analytics is enabled on our deployment, it is designed to operate without analytics cookies; see Cloudflare's documentation for what their beacon sends. Our product analytics (PostHog) set analytics cookies and local storage only after you accept via the cookie banner; until then, no analytics capturing takes place. You can decline, and your choice is remembered in your browser.
Retention
We keep your account and progress data for as long as your account is active. If you delete your account or request deletion, we will remove or anonymise your data within a reasonable period (e.g. 30 days), except where we must retain it for legal or regulatory reasons. Where Web Analytics is enabled, related metrics are retained according to Cloudflare's policies (see their privacy policy).
AI evaluation debugging snapshots (see "Data we collect") have a separate, fixed maximum lifetime: we keep each snapshot for at most 180 days from the time it is created and then delete it automatically, whether or not your account is still active. If you delete your account, any snapshots we still hold are deleted together with your account.
Your rights
If you are in the EEA, you have the following rights under the GDPR:
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
- Right not to be subject to solely automated decisions (Art. 22)
- Right to lodge a complaint with the Autoriteit Persoonsgegevens
To exercise these rights, contact us at the email below.
Your rights of access and erasure cover all personal data we hold about you, including your progress data, your submitted speaking and writing text, the AI feedback we generated, and the AI evaluation debugging snapshots described under "Data we collect". When you delete your account, these snapshots are erased automatically together with your other account data.
Contact
For privacy-related questions or requests: [email protected].
Changes
We may update this Privacy Policy from time to time. The current version will always be on this page. For material changes, we may notify you by email or through the service where appropriate.