🇩🇪

Privacy Policy

GermanVault — Learn German

Last updated: 26 May 2026  ·  Effective: 26 May 2026  ·  Version 1.0

This Privacy Policy describes how Hyb-Falcon Digital/Chirag Mendapara ("we", "our", or "us"), the developer of GermanVault, collects, uses, stores, and shares information when you use the GermanVault Android application (com.mendzyy.germanvault). It also explains your rights and how to exercise them.

This policy is provided in fulfilment of our obligations under the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA), and Google Play Store policies. Please read it before using the app. If you disagree with any part of this policy, please do not use GermanVault.

Contents
  1. Who we are (Data Controller)
  2. Data we collect and the legal basis
  3. How we use your data
  4. Third-party service providers
  5. Advertising and your consent
  6. Push notifications
  7. Quiz and AI features
  8. Automated decisions and profiling
  9. Data we do NOT collect
  10. Data retention
  11. Your rights — EU / UK (GDPR)
  12. Your rights — California (CCPA)
  13. Account and data deletion
  14. Children's privacy
  15. Security measures
  16. International data transfers
  17. Changes to this policy
  18. Contact and complaints

1. Who We Are (Data Controller)

The data controller for GermanVault is:

[YOUR FULL LEGAL NAME / COMPANY NAME]

Email: support@germanvault.app

App: GermanVault (com.mendzyy.germanvault)

Platform: Google Play Store (Android)

A data controller is the person or organisation that determines why and how personal data is processed. For questions about this policy or your data rights, contact us using the details above.

We do not have a designated Data Protection Officer (DPO) as we do not meet the thresholds requiring one under Article 37 GDPR. The contact above handles all data protection enquiries.

2. Data We Collect and the Legal Basis

We only collect data that is necessary for the purposes listed below. The column "Legal basis" refers to the lawful ground for processing under Article 6 of the GDPR. Users outside the EU/UK have equivalent protections under their local laws.

Data category When collected Purpose Stored where Legal basis (GDPR)
Email address Account registration or sign-in Authentication; email verification; account recovery Firebase Authentication (Google LLC) Art. 6(1)(b) — Contract
Display name Account registration Personalising in-app greetings and your profile Firebase Auth & Firestore Art. 6(1)(b) — Contract
Firebase User ID (UID) Account creation Securely linking all your data to your account Firebase Auth & Firestore Art. 6(1)(b) — Contract
Learning progress (items viewed, mastery scores, weekly streak) As you use content in the app Powering the Progress Dashboard; cross-device sync Firebase Firestore (learningProgress) Art. 6(1)(b) — Contract
Quiz preferences and results When you configure or submit a quiz Restoring your quiz settings; tracking improvement Firebase Firestore (profiles) Art. 6(1)(b) — Contract
App settings (theme mode, push notification preference) When you change a setting Honouring your preferences; syncing across devices Device localStorage & Firestore (profiles) Art. 6(1)(b) — Contract
Ad consent choice (personalised / essential only) First launch — you actively select your preference Recording and honouring your advertising consent decision Device localStorage only (never leaves your device) Art. 6(1)(c) — Legal obligation
Anonymous device identifier Automatically on first launch (for non-registered users) Enabling the Favourites feature without requiring an account Firebase Firestore (favs collection, as document key) Art. 6(1)(f) — Legitimate interests ¹
FCM push token When you grant the POST_NOTIFICATIONS permission Routing daily word/phrase notifications to your device Firebase Firestore (pushTokens) Art. 6(1)(a) — Consent
Google Advertising ID (GAID) Automatically when ads are displayed Serving personalised or non-personalised ads via AdMob Google AdMob (Google LLC — not stored by us) Art. 6(1)(a) — Consent (personalised)
Art. 6(1)(f) — Legitimate interests ² (non-personalised)
Recent in-app navigation history As you browse content pages Powering the "last visited" feature; understanding which content is most used Firebase Firestore (profiles.recentActivity) Art. 6(1)(f) — Legitimate interests ³

¹ Legitimate interest (device identifier): Enabling core favourites functionality for users who have not registered. Our interest in providing a useful, frictionless experience outweighs the minimal privacy impact of storing a technical identifier, which is not linked to a real-world identity.

² Legitimate interest (non-personalised ads): Displaying contextual advertising to fund a free application. Contextual ads do not involve profiling and the impact on privacy is minimal.

³ Legitimate interest (navigation history): Understanding which content areas are most valuable so we can improve the app. The data is limited to page paths (e.g. /verbs/haben) and contains no sensitive information. You may object to this processing by contacting us (see Section 18).

3. How We Use Your Data

We do not use your data for any purpose that is incompatible with the purposes listed above.

4. Third-Party Service Providers

We share data only with the following sub-processors and partners. Each acts under a data processing agreement or equivalent contractual safeguard. We do not sell your personal data.

Google Firebase (Google LLC)

Firebase Authentication manages secure sign-in. Firebase Firestore stores your learning progress, profile, and settings. Firebase Cloud Messaging (FCM) delivers push notifications. Firebase is subject to Google's Data Processing Agreement under GDPR.
Policy: firebase.google.com/support/privacy

Google AdMob (Google LLC)

AdMob displays in-app advertisements. When personalised ads are enabled (with your consent), AdMob may use the Google Advertising ID and in-app interaction data to show interest-based ads. When you choose "Essential only", AdMob serves non-personalised, contextual ads without profiling. You can also reset or opt out of personalised ads at the Android OS level: Settings → Privacy → Ads → Delete advertising ID (Android 12+) or Opt out of Ads Personalisation (earlier versions).
Policy: policies.google.com/privacy

OpenAI (OpenAI, LLC)

The quiz feature sends a list of German vocabulary items to OpenAI's API via a Firebase Cloud Function. No personal data is included in these requests — only a topic name and app-content vocabulary items. OpenAI processes this data under its API terms and privacy policy. We do not retain prompt content on our own infrastructure.
Policy: openai.com/policies/privacy-policy

Google Play Services (Google LLC)

Play Services handles app distribution, in-app updates, and review prompts. Google processes standard app distribution data as the platform provider under their own privacy policy.

5. Advertising and Your Consent

GermanVault is free to use. We display ads via Google AdMob to fund ongoing development. On first launch you will be shown a consent dialogue with two options:

Your consent is freely given, specific, and can be withdrawn at any time. Withdrawing consent does not affect the lawfulness of any processing that occurred before withdrawal. To change your preference: open the app, go to Settings → Advertising Preferences.

For users in the EEA and UK, this consent satisfies the requirements of GDPR and the UK GDPR. For users in California, personalised advertising constitutes "sharing" of personal information for cross-context behavioural advertising under the CCPA; you may opt out as described in Section 12.

6. Push Notifications

GermanVault can deliver optional daily notifications with a German word or phrase. On Android 13 and later, the app will request the POST_NOTIFICATIONS permission before sending any notification — this permission is off by default and you must actively grant it.

When notifications are enabled, a Firebase Cloud Messaging (FCM) token is generated and stored in our Firestore database (pushTokens collection) solely for routing purposes. This token is not used for advertising or shared with any party other than Google's FCM infrastructure. You can withdraw this consent at any time in Settings → Daily Notifications. Disabling notifications deletes the token from active use; account deletion removes it permanently.

7. Quiz and AI Features

The Quiz feature uses OpenAI's language model (via a Firebase Cloud Function we operate) to generate multiple-choice questions. When you start a quiz, the following data is sent to OpenAI:

Your personal data (name, email, UID, progress, device ID) is never included in quiz generation requests. The OpenAI API key is stored exclusively on our Firebase Cloud Function server — it is not present in the app binary or transmitted to your device. Legal basis for this processing: performance of a contract (Art. 6(1)(b) GDPR) — the quiz is a core feature of the service.

8. Automated Decisions and Profiling

The app performs automated calculations on your local learning data to produce the following outputs:

These calculations are performed for the sole purpose of helping you track and improve your learning. They do not constitute automated decision-making that produces "legal or similarly significant effects" within the meaning of Article 22 GDPR — they affect only your in-app experience and carry no external consequence.

Google AdMob performs profiling for advertising purposes when you consent to personalised ads (see Section 5). We do not carry out any other profiling.

9. Data We Do NOT Collect

10. Data Retention

We retain personal data only as long as necessary for the purposes it was collected:

11. Your Rights — EU / UK (GDPR) GDPR UK GDPR

If you are located in the European Economic Area or the United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR / UK GDPR). We honour these rights for all users regardless of location.

How to exercise your rights: Email support@germanvault.app with the subject line "Data Rights Request" and describe your request. We will respond within one calendar month. If your request is complex or numerous, we may extend this by a further two months, in which case we will notify you within the first month and explain the reason for the extension (Art. 12(3) GDPR). We will not charge a fee for requests unless they are manifestly unfounded or excessive.

12. Your Rights — California (CCPA / CPRA) CCPA

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you the following rights:

To submit a CCPA/CPRA request, email support@germanvault.app with the subject "California Privacy Request". We will respond within 45 days (extendable by a further 45 days with notice).

We do not have actual knowledge of selling or sharing personal information of consumers under 16 years of age.

13. Account and Data Deletion

You can delete your account and all associated personal data at any time, directly within the app:

  1. Open GermanVault and tap the side menu icon.
  2. Go to Settings.
  3. Scroll to the Account section and tap Delete Account.
  4. Read the confirmation message and tap Delete to confirm.

This action immediately and permanently:

Deletion is irreversible. If you cannot access the app, email support@germanvault.app and we will manually process your deletion request within 30 days.

This deletion mechanism satisfies the Google Play requirement (effective December 2023) that all apps allowing account creation must also provide a mechanism to delete the account and associated data from within the app.

14. Children's Privacy

GermanVault is not directed at children. We apply the following age thresholds in line with applicable law:

If you believe your child has created an account or provided personal data through GermanVault, please contact us at support@germanvault.app. We will verify the report and delete the data promptly.

15. Security Measures

We implement the following technical and organisational measures to protect personal data:

Despite these measures, no data transmission or storage system is guaranteed to be 100% secure. If you discover a security vulnerability, please disclose it responsibly to support@germanvault.app.

16. International Data Transfers

GermanVault is operated from [YOUR COUNTRY]. Our service providers — Google LLC (Firebase, AdMob) and OpenAI, LLC — are headquartered in the United States and may process data on servers outside the EEA or UK.

These transfers are protected by one or more of the following safeguards:

By using GermanVault, you acknowledge that your data may be transferred to and processed in countries with different data protection standards than your own. The measures above are designed to ensure that your data receives an equivalent level of protection regardless of where it is processed.

17. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top. We categorise changes as follows:

The current version of this policy is always available at the URL provided in the app's Play Store listing and in Settings → Privacy Policy.

18. Contact and Complaints

For any questions, data subject requests, or concerns about this Privacy Policy or our data practices, please contact:

[YOUR FULL LEGAL NAME / COMPANY NAME] — Data Controller

Email: support@germanvault.app

Subject line for data requests: Data Rights Request

App: GermanVault  (com.mendzyy.germanvault)

Response time: within 1 month (GDPR) / 45 days (CCPA)

If you are not satisfied with our response, you have the right to lodge a complaint with a supervisory authority: