Privacy Policy

Last updated · October 2, 2026

1. Who we are and what this policy covers

Bretzi is a language-learning service operated by StroopTaal ("we", "us", "our"). For the purposes of the EU General Data Protection Regulation (GDPR) we are the controller of the personal data described on this page.

This policy covers the Bretzi apps for iOS and Android, this website, and the emails and notifications we send you. It does not cover the App Store, Google Play, or any other service you reach through a link from us. Those run under their own policies, and we are not responsible for them.

You can reach us through our support page or at [email protected]. Our Terms of Use govern your use of the service itself.

2. What we collect

2.1 What you give us

  • Your email address, when you sign in with Apple, with Google, or with an email and password
  • A password, stored only as a one-way hash, if you sign in with email
  • A display name or leaderboard nickname, if you choose one
  • Your level, learning goals, target region, how long you have lived in Germany, your daily goal, and the coaching character and conversation topics you pick
  • Support messages, the screenshots you attach to them, question reports, and feedback you send us

2.2 What the app records while you learn

  • Lessons, questions, exercises and exam simulations you complete, and the answers and scores behind them
  • Mistakes, weak skills, vocabulary and review schedules, saved words and word lists
  • Streaks, XP, achievements, level changes and placement results
  • Speaking-session length and number of turns, listening and podcast activity, and minutes counted toward your daily goal
  • Bretzel balance, free-preview usage and referral history

2.3 Technical data

  • Platform, operating-system version, app version, app language and time zone
  • IP address, which appears in server and security logs
  • Push tokens for Apple and Google notification delivery
  • An anonymous device identifier, if you use the app without creating an account
  • An analytics instance identifier, and on Android a Google Play Integrity result used to detect tampered installs

2.4 Purchases

Which subscription or product you bought, when, and its trial, renewal, cancellation and refund status, together with the transaction identifiers the store gives us. Payment is handled entirely by Apple or Google. We never see or receive your card or bank details.

2.5 How you found us

Install and campaign data such as the Apple Search Ads attribution token, the Google Play install referrer, campaign and keyword identifiers, UTM parameters, and invite or referral codes, including the signals we use to detect referral abuse.

2.6 What you send to the AI features

Chat messages, recordings you make in speaking practice and pronunciation checks, photos of documents you scan, and text you submit for writing feedback. Section 4 explains what happens to these.

3. Why we use it, and our legal basis

  • To provide the service you asked for (GDPR Article 6(1)(b)): creating and running your account, saving your progress, generating lessons, running AI features, delivering premium access you paid for, and answering support requests.
  • Our legitimate interests (Article 6(1)(f)): keeping the service secure, detecting fraud and abuse of quotas, referrals and purchases, fixing bugs, understanding which features work, and measuring our own marketing. We balance these against your interests and you can object, as described in section 10.
  • Your consent (Article 6(1)(a)): marketing emails, optional push notifications, appearing on the leaderboard under a name you choose, and non-essential cookies on this website. You can withdraw consent at any time without affecting what we did before.
  • Legal obligations (Article 6(1)(c)): keeping the records that tax and accounting law requires us to keep.

The app scores your answers and adjusts your level, your review schedule and your daily plan automatically. That is automated processing, but it only decides which exercises you see next. It produces no legal effect and nothing similarly significant for you.

We do not process special categories of data such as health, religion or political opinion, and we ask you not to put them into the app. If you do, you do so on your own initiative and at your own risk.

4. AI features: what leaves the app

Several features work by sending what you write, say or photograph to an external AI provider, currently OpenAI and Google, and showing you what comes back.

  • Chat and writing feedback: your message and enough of the conversation to make sense of it are sent, processed, and returned as a reply or a correction.
  • Live speaking practice: your device connects directly to the AI provider using a short-lived token we issue. The audio of that call does not pass through our servers. We store the length of the call, the number of turns, and the written transcript and feedback the provider produces.
  • Transcription and pronunciation checks: the recording is sent to the provider, converted to text and scored, and returned. We do not keep the audio. We keep the text and the score so your progress works.
  • Document scanning: the photo is sent to the provider, read, and returned as extracted words and explanations. We do not keep the photo.
  • Spoken audio you hear is generated by text-to-speech providers, currently ElevenLabs and Google. Nothing about you is sent for this beyond the sentence to be spoken.

We send this content under our commercial agreements with these providers rather than as ordinary consumer input, and those agreements limit what they may do with it. We do not control their systems, and beyond those agreements we give no warranty about how they process it.

Please do not put sensitive information into the AI features. Do not send identity or citizen-service numbers, medical details, bank details, or other people's personal data, and cover them before you photograph a document. Once you have sent something to a provider we cannot always pull it back.

Where and how we use AI is set out in plain language on our AI transparency page.

The FSP simulation

If you use the FSP simulation in Bretzi, we process what you say and write in it: your voice during the call, the transcript of the conversation, the documentation you write, and the scores and feedback generated for them. We do this to run the simulation and grade your session (GDPR Article 6(1)(b)).

  • Providers: as in live speaking practice, your device streams the call straight to the AI provider, not through our servers. The conversation and the grading run on AI services from OpenAI and Google, which act as our processors and may process data in the United States. Transfers are protected as described in section 7. Under their terms these providers do not use this data to train their models; they may keep request logs for a limited period to prevent abuse.
  • What we keep: we do not store recordings of your voice. We delete transcripts and written documentation 90 days after the session. Scores and feedback stay until you delete the simulation in the app or delete your account.
  • What we do not do: we do not use your voice to identify you, we do not analyse your emotions, and we do not infer your origin from your accent.
  • Scores are an automated practice estimate with no legal or similarly significant effect. They are not an official exam result.

The patients in the simulation are fictional. Do not enter information about real patients or about your own health.

5. Who we share your data with

We do not sell your personal data and we do not rent or trade it. We use a small number of service providers who process data on our instructions:

  • Hosting: Hetzner Online GmbH, Germany, for our servers and database
  • Storage and delivery: Cloudflare, for audio, images and support attachments
  • AI: OpenAI and Google, for chat, speaking practice, transcription, document reading and content generation; ElevenLabs and Google for speech
  • Email: Brevo, for account, support and progress emails
  • Notifications: Apple and Google, for push delivery
  • Purchases: Apple and Google, for billing, subscription status and refunds
  • Abuse prevention: Google reCAPTCHA on the support form and Google Play Integrity on Android
  • Analytics and measurement: Google, and Meta as described in section 6

We may also disclose data where the law, a court or a regulator requires it, where it is needed to establish or defend a legal claim or to protect our rights, users or systems, and to professional advisers bound by confidentiality. If our business is merged, acquired or sold, data may transfer with it, and this policy keeps applying until it is replaced by one that is not materially less protective.

6. Advertising and measurement

We show no advertisements inside the app and we use no ad-serving network. Our iOS app never asks for tracking permission and does not read Apple's advertising identifier.

We do measure our own advertising, and this is the part you should know about:

  • Where we advertise an app on Meta, that app includes Meta's measurement SDK. It reports app opens, trial starts and purchases to Meta so we can see which campaigns work. Attribution runs on Apple's SKAdNetwork and on Meta's aggregated event measurement, not on an advertising identifier.
  • When a trial or purchase happens, we may also send Meta an irreversibly hashed version of your email address and of your internal user number, so we can tell which of our campaigns produced it. Meta uses this for matching and acts as an independent controller for its own purposes under its own policy.
  • We record the Apple Search Ads attribution token and the Google Play install referrer so we can attribute an install to a campaign.
  • We send our own app and subscription events to Google Analytics so we can see how people move through the app.

This is based on our legitimate interest in running a viable product. You can object at any time through our support page, and we will stop including you.

7. Where your data is stored, and transfers outside the EU

Our servers and database are located in Germany, inside the European Union. Files are stored with Cloudflare on infrastructure we configure for European storage.

Some of our providers — including OpenAI, Google, Meta and Cloudflare — are established outside the European Economic Area or process data outside it. Where that happens we rely on the European Commission's Standard Contractual Clauses, on an adequacy decision such as the EU-US Data Privacy Framework where the provider is certified under it, and on the additional safeguards in our agreements with them. You can ask us for details through our support page.

8. Security

We protect your data with measures appropriate to the risk: encrypted connections, passwords stored only as one-way hashes, short-lived access tokens, restricted and logged administrative access, and hosting inside the EU.

No app, server or internet connection is ever completely secure. We cannot guarantee that unauthorised access, loss or disclosure will never happen, and except where the law does not allow us to say so, we do not accept liability if it does. Keep your sign-in details to yourself, use a password you do not use elsewhere, and tell us immediately if you think someone else has used your account.

9. How long we keep it

  • Your account and learning data: for as long as your account exists.
  • After you delete your account: you can delete it yourself in the app. Deletion is scheduled, and after a grace period of seven days your account and the data attached to it are permanently erased. Signing back in during those seven days cancels the deletion. After erasure we cannot restore anything.
  • Support requests and their attachments: for as long as we need them to handle the request and for a reasonable period afterwards in case it reopens.
  • Purchase and billing records: for as long as tax and accounting law requires, currently seven years in the Netherlands. These are kept even after an account is deleted, because we are legally obliged to keep them.
  • Server and security logs: a short period, normally measured in weeks.
  • Aggregated statistics that can no longer identify you: indefinitely.

An account that has been inactive for a long time may be deleted after we have given you notice at the email address on the account.

10. Your rights

Under the GDPR you have the right to:

  • Ask what personal data we hold about you and get a copy
  • Have inaccurate data corrected
  • Have your data erased
  • Restrict how we process it
  • Object to processing based on our legitimate interests, including our marketing measurement
  • Receive your data in a portable format
  • Withdraw consent you have given, at any time

Many of these you can do yourself: your profile, notification settings, leaderboard choice and account deletion are all in the app. For anything else, write to us through our support page. We answer within one month, and may extend that by two months for complex requests, telling you why. We may ask you to confirm you are the account holder before we act, and we may decline requests that are manifestly unfounded or excessive.

If you think we have handled your data badly, please tell us first. You also have the right to complain to a supervisory authority, in the Netherlands the Autoriteit Persoonsgegevens, or to the authority where you live.

11. Children

Bretzi is intended for people aged 16 and over. We do not offer it to children under 16 and we do not knowingly collect their personal data. We do not ask for a date of birth, so we rely on you telling us the truth when you accept our Terms of Use.

If you are a parent or guardian and believe a child under 16 has an account, contact us and we will close it and delete the data.

12. Notifications and email

Push notifications are optional and controlled by your device. To send a reminder at a useful moment we use the hour you choose, your time zone and the times you have recently opened the app. You can turn them off in the app or in your device settings.

We always send transactional emails you cannot opt out of while you have an account, such as sign-in codes, password resets and purchase or subscription notices. Progress emails, product updates and campaign emails are separate, and each has its own switch in the app and an unsubscribe link in the message.

13. What other learners can see

The leaderboard is optional. Until you choose to appear on it under your own name, you are shown to others under a generated pseudonym that is not derived from your real name or your email address.

If you opt in, the nickname you choose and your weekly score are visible to the other learners in your league. Do not use a nickname that contains your full name, your address, an email address, a phone number or anything else you would not put on a public page. Certificates and progress cards you share outside the app are shared by you, and what happens to them afterwards is outside our control.

14. This website and cookies

Strictly necessary cookies keep this website working, remember your language and hold your cookie choice. They do not need consent.

Analytics and advertising cookies, set through Google Analytics, only run after you accept them in the cookie banner. In the European Economic Area they are switched off by default until you accept, and you can change your mind at any time through the banner. Rejecting them changes nothing about what the site does for you.

Our support form uses Google reCAPTCHA to block automated submissions, which involves Google processing technical and interaction data under its own policy. Reading the blog and the rest of the site requires no account.

15. Changes, and how to reach us

We may update this policy as the product and the law change. The date at the top always shows the current version. If a change materially affects how we use your data we will tell you in the app or by email before it takes effect. Using the service after that date means the current version applies to you.

Questions, requests and complaints: