Privacy Policy
Privacy Policy
Last updated: 9 September 2026
ANNA is a language-learning platform, currently running as a closed beta for a small group of invited learners. This policy explains what we do with your personal data, why, and what you can require of us.
We have tried to keep it clear and readable. Where the law requires a specific term, we use it and explain what it means.
1. Who is responsible
The data controller is:
Arthur Marques Rheinallee 11 F 67061 Ludwigshafen am Rhein Germany
Email: [email protected]
ANNA is currently operated by an individual rather than a company. You can reach the controller directly at the address above.
We have not appointed a Data Protection Officer. One is not required here: we are not a public body, we do not monitor people systematically on a large scale, and we do not process special-category data on a large scale.
2. Who this applies to
Invited participants in the ANNA closed beta. Participation is adults only — the service is not offered to anyone under 18, and we do not knowingly collect data from children.
The beta is offered to learners in Portugal and Brazil. Because we are established in Germany, European data protection law (the GDPR) applies to everyone. If you are in Brazil, the LGPD applies in addition — see section 11.
3. What we process, and why
We only process data for the purposes below. Each has a legal basis, and each has a retention period.
3.1 Your account
What: your name, username, email address, an encrypted form of your password, your native language, the language you are learning, your level, and when the account was created.
Why: to create your account and let you log in.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR). The beta terms are a contract, even though the service is free.
Kept: for as long as the account exists, plus 30 days after deletion.
Your password is never stored in a readable form. We store a bcrypt hash, a one-way transformation — we cannot recover your password, and neither can anyone who obtains the database.
3.2 Your learning
What: your courses and lessons, your homework and its grades, your exercise answers, your test and exam attempts, and records of your progress.
Why: to deliver the course and show you how you are doing.
Legal basis: performance of a contract.
Kept: for as long as the account exists, plus 30 days after deletion.
Some of these are free-text fields — written homework, open answers, your own notes. What you write in them is stored. We recommend not including sensitive personal details; the exercises never ask for any.
3.3 How the course adapts to you
What: scores measuring how well you have grasped each topic, and a record of the mistakes you make.
Why: so lessons and revision focus on what you actually find difficult. This adaptation is the service.
Legal basis: performance of a contract.
Kept: for as long as the account exists, plus 30 days after deletion.
See section 8 on automated decisions.
3.4 Conversations with the AI tutor
What: the messages you exchange with the tutor, in text and in speaking practice.
Why: to teach you through conversation.
Legal basis: performance of a contract.
Kept: for as long as the account exists, plus 30 days after deletion.
Your messages are sent to our AI provider to generate a reply — see section 4.
3.5 Your notes
What: notes you write yourself and attach to a lesson.
Why: because you asked us to keep them.
Legal basis: performance of a contract.
Kept: for as long as the account exists, plus 30 days after deletion.
Your notes are not sent to any AI model. If that ever changes, we will update this policy before it does, not afterwards.
3.6 Your voice
What: the audio you record during pronunciation and speaking practice, and the text it is transcribed into.
Why: to assess your pronunciation and to understand your spoken answers.
Legal basis: performance of a contract.
Kept: the audio is never stored. It is held in memory only, sent for transcription, and discarded. Only the resulting text is saved, as part of section 3.2 or 3.4.
The audio is transcribed by a third party in the United States — see section 4.
Is this biometric data? No. Under the GDPR, voice becomes biometric data when it is processed in order to identify a specific person. We transcribe what you said in order to teach you; we never use your voice to identify you. Not storing the audio is the practical guarantee behind that.
3.7 Improving ANNA — only if you agree
What: your conversations with the tutor.
Why: to review how the tutor performed and improve the teaching.
Legal basis: your consent (Art. 6(1)(a) GDPR). This is a checkbox at registration, unticked by default and separate from accepting the terms. You can use ANNA fully without it.
What we look at: only conversations from the last 90 days. Older ones are not reviewed for this purpose.
No extra copy is made. Your conversations are already stored as part of your course (section 3.4); this consent does not create new data, it permits an additional use of data that already exists. Withdrawing it stops that use.
What this covers: reviewing conversations to identify where explanations were unclear or the tutor responded poorly, and adjusting the service accordingly.
What it does not cover: training AI models. We do not train models on your data, and our AI providers are configured not to either.
You can withdraw at any time, from your profile page, as easily as you gave it. Withdrawing stops any future use and does not affect what was lawful before you withdrew. It has no effect on your course.
3.8 Keeping the service running and secure
What: server and application logs, which include IP addresses, and error reports.
Why: to keep the service available, detect abuse of the AI features, and fix failures.
Legal basis: legitimate interests (Art. 6(1)(f) GDPR) — running a service securely. We weighed this against your interests: the data is technical, kept briefly, and never used to build a profile of you.
Kept: server and application logs, 14 days. Error reports, 30 days.
The two differ because they are held in different places. Server logs are on our own machine and expire on the schedule we set. Error reports are held by Sentry, whose retention period is fixed by the plan we are on and cannot be shortened by us. Thirty days is also the more honest figure for what these are for: during a beta we deploy most days, and telling whether a fault has come back after a fix takes longer than a fortnight.
Bug reports
If you use the “Report a problem” button, we store what you write, the page you were on, and recent technical errors your browser recorded — the address, method and status code of requests that failed, your screen size, your browser version and the version of the app. We do not store the contents of those requests, so nothing you typed into a lesson is included.
You can also attach a screenshot, and only if you choose to. We show it to you before anything is sent, and you can remove it and send the report without it. It is a picture of the ANNA page you are on — we cannot see other windows, other applications or anything else on your screen. If you are on a page showing your own answers, they will be in that picture, which is one reason to look at it before sending.
We use all of this only to fix the problem. Reports are deleted when the beta ends, and if you delete your account your reports stay but are no longer linked to you.
Your email address
We ask for an email address so you can recover your password and so we can reach you about the beta. You sign in with your username, not your email. We do not use it for anything else, and there is no marketing.
Deleting your account
You can ask us to delete your account and we will. Doing so removes your courses, lessons, answers, notes and progress.
Two things survive, and neither identifies you. Any problem reports you sent stay, no longer linked to you. And the record of what your use cost us in AI processing stays, re-keyed to a random identifier for which we keep no mapping at all — so it can still be counted, and can no longer be traced back to you by us or by anyone else. It contains no name, no address, no course, and nothing you wrote.
4. Who else sees your data
We do not sell your data. We do not share it for advertising. It reaches other companies only where they perform a service for us, under a contract that binds them.
| Who | What they do | Where they are |
|---|---|---|
| Hetzner Online GmbH | Hosts the servers and the database | Germany |
| OpenRouter, Inc. | Routes AI requests (chat, grading, transcription) | USA |
| DeepInfra, Fireworks, Parasail | Run the AI models behind chat and grading | USA |
| Together AI, Groq | Transcribe voice recordings | USA |
| Cloudflare, Inc. | DNS, content delivery, protection against attacks, email forwarding | USA |
| Resend (Plus Five Five, Inc.) | Sends service emails, such as password resets | USA; our data region is Ireland |
| Sentry (Functional Software, Inc.) | Collects error reports so we can fix crashes | USA; our data region is the European Union |
Your account and learning data live in Germany, on servers in the European Union. What leaves is what has to: the text of your conversations and your voice recordings, sent for processing and returned.
On the AI providers. Our contract is with OpenRouter, which is obliged to bind the model providers to equivalent terms. We have configured that account to route only to providers that do not store request data, to refuse providers that train on it, and to exclude specific providers by name. We restrict each individual request to a named list of providers, so the set of companies that can see your data is knowable rather than open-ended. The list can change if a provider becomes unavailable; the constraints do not.
These are settings we have configured on our account. We describe them as such because we cannot independently verify another company's infrastructure.
On Sentry. Error reports can, in principle, capture fragments of text from the application. We have enabled Sentry's data scrubbing at organisation level and configured it to strip the specific fields through which learner text could reach a crash report, and to discard IP addresses. Our organisation is configured in the European Union region.
5. Data leaving the European Union
Several of the companies above are in the United States, which the European Commission does not treat as offering protection equivalent to the EU by default. Two mechanisms cover this:
- Cloudflare, Resend and Sentry are certified under the EU-US Data Privacy Framework, an adequacy decision by the European Commission.
- OpenRouter is covered by Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914), which also cover the model providers it uses on our behalf.
You may request a copy of the relevant clauses at the contact address in section 1.
These are the mechanisms European law provides for such transfers. We have applied them, and we limit transfers to what the service requires.
6. How long we keep things
| Data | Kept for |
|---|---|
| Account and learning data | While the account exists, +30 days after deletion |
| Conversations kept under the consent in 3.7 | 90 days from the conversation |
| Server and application logs | 14 days |
| Error reports | 30 days (fixed by our error-tracking provider's plan) |
| Backups | 30-day rolling cycle |
| Bug reports | While the account exists, +30 days after deletion; all deleted when the beta ends |
| All beta data | Personal data deleted 30 days after the beta ends, unless you continue with the service |
About backups. Deleting your account removes it from the live database immediately. Backups made before that still contain it, and those expire on a 30-day cycle. Deletion is therefore fully complete within 30 days, not instantly — and we would rather state that than make a promise the backups contradict.
When the beta ends. We delete the personal data as described above. We keep anonymous statistics about how the course itself performed — for example, how many learners completed a given chapter, which exercises were answered incorrectly most often, and how long lessons took.
To produce them we permanently remove every identifier and discard the free text, keeping no key or mapping that could reconnect the figures to a person. Once that is done the statistics are no longer personal data and are not covered by this policy, because they can no longer be traced back to you — by us or by anyone else. This is what tells us whether the teaching method works, and it requires nothing that identifies you.
7. Your rights
Under the GDPR you can:
- Access your data and receive a copy
- Correct anything inaccurate
- Delete your data ("right to be forgotten")
- Restrict how we use it
- Receive it in a portable format, to take elsewhere
- Object to processing based on legitimate interests
- Withdraw consent at any time, where processing is based on consent (section 3.7)
- Complain to a supervisory authority
How: email [email protected] from your registered address. We answer within one month. There is no charge.
We identify you by your account — a request from your registered email address is enough. We will not ask you for an identity document, because that would collect more data than the request itself.
The supervisory authority for ANNA is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz Hintere Bleiche 34, 55116 Mainz, Germany Telephone: +49 6131 8920-0 · Email: [email protected]
You may also complain to the authority where you live.
8. Automated decisions
ANNA grades your written and spoken work automatically, using an AI model, and chooses which exercises to show you based on your past results.
We disclose this for transparency. Article 22 GDPR concerns automated decisions producing legal or similarly significant effects; a language-exercise score does not fall into that category — no qualification depends on it, and it has no effect outside ANNA.
If you disagree with a grade, contact us and it will be reviewed manually.
9. Cookies and browser storage
We use no cookies for analytics, advertising or tracking, and no third-party trackers.
We store one thing in your browser: a login token, kept in your browser's local storage so you stay signed in. It is strictly necessary for a service you asked for, which is why no cookie banner appears. Logging out removes it.
If we ever add analytics, we will ask for your consent first.
10. Security
We protect your data with, among other measures: encrypted transport (HTTPS), password hashing, authentication required by default on every route, access controls that scope each record to its owner, rate limiting, encrypted backups tested by restoring them, and servers in the European Union under a data processing agreement.
No system can be completely secure. If a breach occurs that is likely to put your rights at risk, we will notify you and the supervisory authority as required — within 72 hours of becoming aware, in the authority's case.
11. For learners in Brazil (LGPD)
If you are in Brazil, Brazilian law (Lei nº 13.709/2018, LGPD) applies alongside the GDPR.
- Controller (controlador): Arthur Marques, contact details in section 1. The same person is the contact for LGPD purposes (encarregado).
- Legal bases: performance of a contract (Art. 7, II) for the service; consent (Art. 7, I) for the improvement purpose in 3.7; legitimate interests (Art. 7, IX) for security.
- International transfer: your data is stored in Germany. The LGPD permits this; Art. 33, II is satisfied by contractual clauses with each processor.
- Your rights under Art. 18 LGPD — confirmation, access, correction, anonymisation or deletion, portability, information about data sharing, and withdrawal of consent — are exercised the same way, at the same address, within the same time.
- Supervisory authority: Autoridade Nacional de Proteção de Dados (ANPD), Brasília, DF.
12. Changes to this policy
If we change how we handle your data, we update this policy and change the date at the top. For anything significant — a new purpose, a new category of recipient, a longer retention period — we will tell you by email before it takes effect, and where it requires your consent, we will ask for it rather than assume it.
13. Contact
Questions, requests, or complaints: [email protected]