Skip to main content

Privacy Policy

Last updated: 13 September 2026

This notice describes personal data processing on the German Acharya exam preparation website, including free practice and access through institution-issued licenses for levels A1–B2. It applies to this portal, not to separate mobile apps or other websites.

1. Controller and contact

The operator identified below is the contact for processing carried out to operate this portal. You can send privacy requests to the email address below.

Amrendu Kumar

Teterower Ring 47
12619 Berlin, Germany

Privacy contact: info@germanacharya.com

Legal notice

If a school, employer or training provider supplies your license, it also processes data to allocate access and administer its relationship with you. Its own privacy notice explains that processing. Where it determines the purposes of processing learning data, its instructions and the applicable data-processing agreement govern the portal operator’s role. Contact us or your institution if you need help identifying who handles a request.

2. Data we process

  • Account and authentication: name, email address, account ID, account role, verification status, sign-in and registration dates, and a password hash if you register with a password. Google sign-in also supplies account identifiers and profile information, such as your profile image, and authentication tokens.
  • Licenses: the license code and batch, duration (30, 60 or 90 days), institution or allocation label, any assigned email address, the activating account, selected level, activation and validity dates, renewal or revocation status, and administrator actions and reasons. Allocation information can come from the institution or administrator before you activate a code.
  • Learning and usage: selected exam provider and level, questions and answers, practice progress, mock exam results, scores, AI feedback, and free-use and daily AI-credit counters. Some exercise state and preferences are also saved in your browser.
  • AI interactions: chat messages and relevant conversation history, written answers, uploaded images for text recognition, and microphone recordings you submit for speaking exercises. Processing can produce transcripts, generated responses, spoken replies and feedback.
  • Technical and security information: IP address, browser and request information, timestamps, session and attempt identifiers, access attempts, rate-limit and anti-scraping signals, and diagnostic logs. Some AI diagnostics include account identifiers, excerpts of messages, transcripts or generated feedback.
  • Communications: your contact details, support messages and account-related emails. If you allow analytics, we also process usage events, browser identifiers, referral information and interaction data as described below.

3. Purposes and legal grounds

An email address and authentication details are needed for a registered account; a valid license and selected level are needed for licensed access. Without submitted text, images or audio, the corresponding AI feature cannot evaluate that material. Optional analytics are not a condition of using the portal.

AI scores are practice feedback, not official exam results. Access checks automatically apply license dates, levels and usage limits. Contact support if you believe a restriction is incorrect.

  • Account access, requested exercises, AI feedback and license activation: to provide the service and manage access. Article 6(1)(b) GDPR applies where necessary for our contract with you. For institution-provided access, Article 6(1)(f) may apply to our legitimate interests in delivering and administering the agreed training service; processing on an institution’s behalf follows its instructions and legal basis.
  • Security, misuse prevention, troubleshooting and service-related support: our legitimate interests in protecting accounts, enforcing access limits and maintaining a reliable service (Article 6(1)(f) GDPR).
  • Optional analytics and session recordings: your consent (Article 6(1)(a) GDPR). You can refuse or withdraw it without losing licensed access.
  • Compliance with applicable legal obligations and handling legally required records or requests: Article 6(1)(c) GDPR, where an obligation applies.
  • Storing or accessing information on your device is subject to applicable ePrivacy rules, including Section 25 TDDDG in Germany. We seek consent for optional analytics; storage strictly necessary for a service you request does not require that consent.

4. Licenses and administrator access

Only one login remains active per account. Each successful sign-in replaces a random session identifier stored with your account and in your login token. Previous browsers lose access on their next protected request. This does not permanently register or fingerprint a device.

One activated license is associated with one user account and one selected level. Administrators can generate and allocate codes and see the associated user, selected level, activation status, validity and expiry. They can export license records and make corrections or revoke access; those actions are recorded in an audit history.

Authorized portal administrators also have account and usage management tools. A license recipient does not gain access to other learners’ data. If your institution provides access, it may supply allocation details or receive relevant license administration records. This notice does not imply that every teacher has access to individual conversations.

This portal uses license activation for access and does not collect card details or provide an online subscription checkout. Expiry of a license ends its access entitlement; it does not automatically delete your account or learning history.

5. AI practice and submitted content

When you use AI chat, writing evaluation, speaking exam practice or image-to-text recognition, the portal sends the content needed for that request to Google’s Gemini service, through the Gemini API or Vertex AI as configured. This may include exercise instructions, relevant conversation history, written answers, uploaded images and submitted audio. Google processes the material to generate replies, transcripts and feedback.

For spoken AI replies, text is sent to OpenAI’s speech-generation API. Reply text can contain information from the conversation. Where browser speech synthesis is used as a fallback, processing depends on the browser or operating-system voice service.

Microphone access requires your browser’s permission. Audio submitted for speaking practice is processed by the service; browser microphone permission is separate from optional analytics consent. Avoid including unnecessary personal details or information about other people in exercises.

Saved chats, submitted answers and completed exam results can be associated with your account. AI providers may also retain request data for service operation and abuse prevention under the terms applicable to the configured API. This notice does not promise zero provider retention or that every API configuration excludes model improvement. The provider links below explain their terms.

Live Teacher mode is not available in the current white-label portal. The speaking exam exercises described here remain available.

6. Cookies, browser storage and your choices

Essential storage supports sign-in, request security and the learning features you use. Authentication includes a session cookie with a configured maximum age of 30 days, which can be renewed through continued use. Browser storage can also retain theme preferences, exercise state and dismissed interface notices until reset or cleared.

We remember your analytics choice, its timestamp and preference version in browser storage for 180 days. The choice applies to that browser. When it expires, is cleared or becomes invalid, optional analytics stay off until you choose again. The portal stores the current choice locally; it does not maintain a central consent history.

Google Analytics 4 and Microsoft Clarity load only after you accept analytics and only when configured for this deployment. Rejecting optional analytics leaves essential account and exam functions available. We do not load these analytics services before consent, including in a cookieless tracking mode.

  • Google Analytics 4 measures page visits, usage events and referral sources using browser identifiers and device information. With consent, signup attribution may be linked to your account. Advertising consent is denied, and Google signals and advertising personalization are disabled in the portal configuration.
  • Microsoft Clarity provides heatmaps and session replays of interactions such as clicks, scrolling and navigation. Page content may be captured subject to Clarity’s masking. For signed-in users, the portal sends the application account ID and an account-type tag to Clarity. This is identifiable account-linked processing, not anonymous statistics.
  • Analytics cookies can include Google’s _ga cookies and Clarity’s _clck and _clsk cookies. Provider cookie lifetimes and server-side retention depend on the service and project settings; they are separate from the 180-day consent preference.
  • Use Cookie settings here or at the bottom of the site to change your choice. Rejecting after acceptance stops further tracking, attempts to clear accessible first-party analytics cookies and reloads the page to stop loaded recording scripts. It does not erase information already received by providers.
  • You can also clear site data in your browser. Removing authentication or exercise storage can sign you out or remove locally saved progress. For deletion of previously collected personal data, contact us.

7. Service providers and recipients

The following services support the portal when the relevant feature is used or enabled. Providers receive the information needed to deliver those functions. Infrastructure configuration and provider account settings also affect processing.

Google — sign-in and AI

Google sign-in exchanges authentication and profile information if you choose it. Gemini / Vertex AI processes the content submitted for AI exercises. Google Analytics is covered separately by your optional analytics choice.

Google privacy policy

Google Gemini API / Google Cloud

The applicable Gemini API or Google Cloud terms govern handling of submitted AI content, including provider retention and use of data.

Gemini API terms

Google Cloud / Vertex AI

Where Vertex AI is configured, Google Cloud’s data-processing terms apply to that service.

Google Cloud data-processing terms

OpenAI

Generates audio from text for speaking roleplays and replies. This AI service is separate from advertising tracking.

OpenAI business data privacy

Microsoft Clarity — optional

Processes interaction data and account identifiers for session replays and heatmaps after analytics consent, where configured.

Microsoft privacy statement

Fly.io

The hosting setup uses Fly.io for application infrastructure. Hosting involves request information, application data and operational logs.

Fly.io privacy policy

Tigris

Object storage is used for media and database backups. Database backups can contain account, license and learning records.

Tigris privacy policy

IONOS — email

The current email configuration uses IONOS SMTP to deliver account and service messages, including recipient addresses and message contents.

IONOS privacy policy
  • Authorized administrators, support personnel and your institution may receive relevant information for the purposes described above. Authorities or advisers may receive data where legally required or necessary to address legal claims.
  • The portal does not sell personal data and does not include advertising pixels, advertising conversion APIs or ad placements. Links to external websites are governed by their own privacy notices when you visit them.

8. International processing

Some providers operate internationally and may process data outside the European Economic Area, including in the United States. A European hosting region alone does not ensure that all AI, analytics, email or support processing stays in the EEA.

Transfers requiring GDPR safeguards must use an applicable adequacy decision or another lawful mechanism, such as the European Commission’s standard contractual clauses with any necessary supplementary measures. The mechanism depends on the receiving entity and service agreement. Contact us for details of the safeguards applicable to your data and how to obtain a copy.

9. Storage periods and deletion

For account deletion or a request covering licenses, audit records, logs or provider-held data, email info@germanacharya.com. We may need to verify your identity and coordinate with your institution. If any information must be retained, we will explain the applicable reason and period or criteria. Clearing browser storage alone does not delete server records.

  • Accounts and learning records: kept to provide continued account access and learning history. The portal does not automatically erase these records when a license expires. You can request deletion; retention beyond the service relationship must be justified by an applicable obligation or a specific need, such as resolving a dispute.
  • Licenses and audit records: used to administer allocation and validity, prevent code reuse, investigate misuse and resolve access disputes. They can outlast the license’s validity. The current implementation has no general time-based purge for these records; deletion or removal of personal identifiers requires a separate review.
  • Chats: the interface supports deleting individual chats. Older sessions and messages are pruned as account limits are reached; this is a quantity limit rather than a fixed period in days. Deleting a chat in the portal does not itself erase copies previously processed by an AI provider or included in logs or backups.
  • Security logs, support records and backups: the relevant period depends on troubleshooting, security investigations, recovery needs and any applicable legal obligation. The application does not set one universal automatic expiry for these records. Backup copies are separate from the live database and are not immediately erased by deleting a live record.
  • Optional analytics: the 180-day preference controls future collection, not the lifespan of data already sent to Google or Microsoft. Those records follow the configured provider retention and deletion controls. Contact us about data already collected.

10. Security

The application uses password hashing, authenticated account access, administrator access controls, server-side license checks and rate limits. Production authentication cookies are configured as secure and HTTP-only. Access restrictions and anti-scraping checks help protect exam content and accounts. No online service can guarantee absolute security.

11. Your rights

Subject to the conditions in applicable law, you may request access, correction, erasure, restriction or portability of your personal data, and object to processing based on legitimate interests. You can withdraw consent at any time; earlier lawful processing remains unaffected.

Send requests to info@germanacharya.com. We normally respond within one month; where a lawful extension is necessary, we explain it within that initial period. You may complain to a supervisory authority, including in the country of your habitual residence, workplace or the alleged infringement.

12. Learners under the age of majority

Institutions providing access to minors should give learners and, where appropriate, their parents or guardians information about the service and the institution’s handling of their data. Where parental authorization is legally required, it must be obtained. We do not infer valid parental consent merely from possession of a license code. Contact us with concerns about a child’s data.

13. Changes to this notice

We update this notice when the portal’s processing changes. The date above identifies the current revision. Where a new purpose requires consent, this notice does not replace obtaining that consent.