← Back to App

Privacy Policy

Last updated: 6. April 2026

Privacy Policy

Last updated: April 2026

1. Who We Are

Artikel Fit ("we", "us", "our") is an online learning platform that helps users practise German grammatical articles (der, die, das). The platform is accessible at artikelfit.de.

Data Controller

Artikel Fit
Seyed Amir Hosseini
Otto-Hahn-Str. 42
61381 Friedrichsdorf
Deutschland, Germany

Email: info@artikelfit.de

If you have questions about this Privacy Policy or how we handle your data, please contact us at the email address above.

2. What Data We Collect and Why

2.1 Account Data

When you create an account we collect the following information. Your email address is used for account identification and transactional emails such as welcome and password-reset messages; the legal basis for this is performance of contract (Art. 6(1)(b) GDPR). Your password is stored only as a bcrypt hash and is never kept in plain text; it is used for authentication under the same legal basis. If you choose to provide your name, we use it for personalisation, also under performance of contract. Your account creation date is recorded for security and fraud prevention under our legitimate interest (Art. 6(1)(f) GDPR). Your trial expiry date is stored for subscription management under performance of contract.

2.2 Learning and Progress Data

When you use the practice features we collect data to power the learning experience. This includes the words you have practised and their scores, which drive spaced-repetition scheduling and personalised review. We also record your practice session history — words answered, points earned, and session duration — for progress tracking and the results screen. Mastered words are tracked for milestones, favourite words are stored for personalisation, and last-scheduled review dates feed the spaced-repetition algorithm. All of this processing is based on performance of contract (Art. 6(1)(b) GDPR).

2.3 Email Communications

We send two types of transactional email: a welcome email when you register, and a password-reset email when you request one. We do not send marketing emails and we do not subscribe you to any mailing list.

Email delivery is handled by Amazon Web Services Simple Email Service (AWS SES), operated by Amazon Web Services, Inc. (USA). Transfers outside the EEA are covered by AWS's Standard Contractual Clauses.

We process bounce and complaint notifications from AWS SES to keep our sending list clean and to comply with email best-practice requirements. If your email address bounces or you mark a message as spam, we suppress future emails to that address.

2.4 Technical and Log Data

When you use the platform our servers automatically record your IP address, browser type and version, pages visited with timestamps, and HTTP status codes. This data is used solely for security monitoring, debugging, and preventing abuse. It is not linked to individual user profiles for analytics purposes. Log files are retained for a maximum of 30 days.

3. Cookies and Local Storage

Artikel Fit uses session cookies strictly for authentication. No third-party tracking cookies, advertising cookies, or analytics cookies are used.

We also use browser localStorage to store minor UI preferences, for example whether a sidebar menu section is expanded. This data never leaves your browser and is not transmitted to our servers.

Because we do not use non-essential cookies, no cookie consent banner is required under the TTDSG or the ePrivacy Directive.

4. Data Sharing and Third Parties

We do not sell, rent, or trade your personal data. We share data only with the following parties. Amazon Web Services (AWS SES) handles email delivery; their servers are in the USA, with EU-West regions used where possible, and transfers are safeguarded by Standard Contractual Clauses. Our hosting provider runs the application infrastructure in EU (Frankfurt) under a data processing agreement (DPA). No other third parties receive your personal data.

5. Data Retention

Account and learning data is kept for as long as your account is active, plus 30 days after account deletion to allow recovery. Server logs are retained for 30 days. The email bounce and complaint suppression list is maintained until you contact us to remove your address.

6. Data Security

We take reasonable technical and organisational measures to protect your data. Passwords are hashed with bcrypt and never stored in plain text. All traffic is encrypted in transit via HTTPS/TLS. Database access is restricted to application processes with no public access. Production servers are not publicly accessible except via HTTPS.

No system is perfectly secure. If you believe your account has been compromised, please contact us immediately.

7. Your Rights Under GDPR

As a person in the EU/EEA you have several rights. Under the right of access (Art. 15) you may request a copy of all personal data we hold about you. Under the right to rectification (Art. 16) you may ask us to correct inaccurate data. Under the right to erasure (Art. 17) you may request deletion of your account and associated data. Under the right to restriction (Art. 18) you may ask us to pause processing your data in certain circumstances. Under the right to data portability (Art. 20) you may request your learning data in a structured, machine-readable format. Under the right to object (Art. 21) you may object to processing based on legitimate interest. Where processing is based on consent, you may withdraw that consent at any time.

To exercise any of these rights, email us at contact@artikelfit.de. We will respond within 30 days.

You also have the right to lodge a complaint with your national supervisory authority. In Germany this is the relevant Landesbeauftragter für den Datenschutz for your federal state, or the Bundesbeauftragter für den Datenschutz und die Informationsfreiheit (BfDI) at www.bfdi.bund.de.

8. Children's Privacy

Artikel Fit is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has created an account, please contact us and we will delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of the page. For significant changes we will notify registered users by email. Continued use of the platform after a change constitutes acceptance of the updated policy.

10. Contact

For any privacy-related questions, requests, or complaints:

Artikel Fit
Seyed Amir Hosseini
Otto-Hahn-Str. 42
61381 Friedrichsdorf
Deutschland, Germany

Email: info@artikelfit.de