Fazem fé jurídica as versões alemã e inglesa.
Privacy
This statement covers both: this page and the application at app.eduphily.com.
Visiting the page
When you visit, your browser transmits technically necessary details: shortened IP address, time, requested address, status code, amount of data transferred and the identifier your browser reports. The legal basis is the legitimate interest in secure, working operation (Art. 6(1)(f) GDPR).
Retention
Logs are deleted after a short period unless they are needed to investigate an attack.
No cookies, no measurement
This page sets no cookies, embeds no third-party content and measures no visitor behaviour. Fonts and images come from the same server.
Requests by email
If you write, your message and address are stored to handle the request (Art. 6(1)(b) and (f) GDPR) and deleted once they are no longer needed.
Hosting
The page runs on servers of Hetzner Online GmbH in Germany. A data processing agreement is in place.
The application
Everything below covers app.eduphily.com — the part with an account. The overview is complete: whatever is processed there has a section here.
The essentials first
eduphily is a study companion: subjects, topics, notes with handwriting, material and exam dates. Your notes live on your device first and work without a network connection. While you are signed in they are additionally transferred to our server so that your devices hold the same state.
We do not sell data, run no advertising and embed no third-party analytics. There is no usage analysis, no advertising cookies and no cookie banner. The one exception is a YouTube video you play yourself next to a note: for that we ask right there, before anything is loaded from YouTube (see “YouTube videos in the side view”).
eduphily is a closed test round. It is not sold and not advertised; there is no price and no order. Participants are entered individually on an invitation list — without an entry, no account is created. Between you and us there is an unpaid usage relationship which you can end at any time by deleting your account.
Minimum age
eduphily is for people aged 16 and over. Anyone younger must not create an account.
The reason is stated openly: for younger people, Art. 8 GDPR requires the consent of those with parental responsibility in Germany, and a usage relationship with a minor under 16 would be provisionally invalid without their approval (§ 107 German Civil Code). Obtaining and evidencing both properly is a procedure of its own that eduphily does not have today. Rather than claim it, we draw the line.
Age is confirmed when access is granted. If we learn that an account belongs to a younger person, we delete it together with its data.
Who is responsible
John Ollhorn Oertzweg 13 22307 Hamburg Deutschland Email: mail@eduphily.com VAT ID: nicht vorhanden Contact for data protection matters: mail@eduphily.com Competent supervisory authority: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Str. 22, 20459 Hamburg
What data we process and why
The overview below is complete: every processing operation that happens in eduphily has a row here. It is checked mechanically against the source code on every change to the program so that it stays complete.
| What | Why | Legal basis | How long |
|---|---|---|---|
| Account data — The data that constitutes your account. Name, email address and profile picture come from your Google account when you sign in with it. In addition, the language of your account, which the app reports here from your settings. | Maintaining your account, associating your devices with each other and enabling your notes to sync at all. If your account is suspended, a timestamp records since when — that is what makes lifting a suspension possible. The language of your account determines the language in which we write emails to you. | Contract (Art. 6(1)(b)) | Until the account is deleted. Deletion also removes your database on the server. |
| Session data — One record per signed-in device holding the session token, its expiry, plus the IP address and user agent at sign-in time. | Keeping you signed in without signing in again on every start, and making unauthorised access to your account recognisable. | Contract (Art. 6(1)(b)) | Until the session expires or you sign out. |
| Google sign-in — The link to your Google account including the access and refresh tokens Google issues. The table has a password column, but the public installation never fills it — the password path exists solely for automated smoke tests. | Enabling sign-in with your Google account and carrying it beyond the lifetime of a single token. | Contract (Art. 6(1)(b)) | Until the account is deleted. |
| Operator action log — When the operator suspends or deletes an account, one record is written: when, who did it and which account was affected. The record holds only the account's internal identifier — not your name and not your email address. | Making it traceable who intervened in an account and when. Without this record, a suspension or deletion could neither be evidenced nor explained afterwards. | Legitimate interest (Art. 6(1)(f)) | Indefinitely. The record must outlive the action it describes — a deletion that removes its own evidence would be no evidence at all. After your account is deleted, only an identifier remains that belongs to no existing account. |
| Handling note on a feedback entry — When the operator works through a feedback entry, they can mark it as handled. That writes a record holding the feedback's internal identifier, the time and the operator's name. Your feedback itself is not changed — it is stored immutably. | Keeping track of which feedback has already been read and handled. Without this note the operator would have to work through the same set again and again. | Legitimate interest (Art. 6(1)(f)) | For as long as the feedback entry it refers to exists. |
| Verification tokens — Short-lived tokens better-auth creates during sign-in and discards again. | Holding a sign-in flow together across several steps. | Contract (Art. 6(1)(b)) | Until the token expires, typically minutes. |
| Your pre-registration — Your email address from the form on the project site and, if you send us one, a second address for signing in. In addition: when you pre-registered, when you confirmed, the processing state, when and by whom it was decided, a short note by the operator, when we last emailed you, and an internal identifier. Until you confirm, additionally a one-time key stored only as a checksum — in clear text it exists only in the confirmation email. | eduphily is a private, non-public test round with a limited number of places. Your pre-registration tells us that you would like to take part and lets us notify you once a place is free. Without your confirmation by link, the address is not used further. | Consent (Art. 6(1)(a)) | Without confirmation the entry is deleted automatically after three days. With confirmation it remains until you object via the unsubscribe link in every one of our emails, or the test round ends. If you delete your account, the entry goes with it. |
| Test-round invitation — Your email address on the closed test round's invitation list, the date it was granted and a short note about it. The entry exists before there is an account — it is the precondition for one being created at all. | eduphily is a private, non-public test round. The list is the access control: without an entry, signing in creates no account. It also evidences that every access was granted individually. | Legitimate interest (Art. 6(1)(f)) | Until you ask to be removed or the test round ends. Deleting the account does not remove the entry automatically — it existed before the account and is deleted separately on request. |
| Your content — Everything you create in eduphily: subjects, topics, notes with their blocks, exams with dates and the metadata of your material. A block carries its content — text, formulas, Cornell rows, checklists — and the handwriting on top of it: per stroke the points with position, pressure and time. A scanned document carries, per page, its dimensions and the text that on-device recognition reads from it, plus a small preview image of the first page — the image of the page itself is described separately, see "The image file of your scans" further below. This data lives on your device first and is only transferred to the server while you are signed in. You can pin an item so it stays at the top of the list, or archive it: it then disappears from the lists and from the card box, but remains fully intact, searchable and part of every backup — archiving is not deletion and has no deadline. You can also give a folder or a note a study status — learn now, consolidate, no priority or paused. It applies to everything below it and governs only which flashcards the card box presents to you and when; it is not evaluated for anything else. Deleted items first go to a trash: they carry a deletion marker, disappear from the app, and can be restored from there. They are only removed permanently once you empty the trash — there is no deadline after which this happens on its own. If you have imported an export from RemNote, the imported document additionally records which node it came from and at which revision — solely so that a second import finds the same document again instead of creating it twice. Flashcards come with a review log: for every card you answer we record when you answered it, how you rated yourself, which interval followed from that, and which state the card was in beforehand. The app computes from this when you should see the card again, and later adapts the numbers of its scheduling plan to your own answers, on your device; it never leaves your account and is not evaluated to compare you with anyone else. At the press of a button the app adapts the numbers of its scheduling plan to your own answers; the result is twenty-one weights that live in your settings together with the date and the number of answers evaluated. This is computed exclusively on your device. There is also a running study session, one per device: which cards it presents in which order, how far you have got, which ones you set aside, and how long it ran in total. It exists so that an interrupted session can be resumed, and it counts as finished after twenty-four hours; how long you spent on an individual card is deliberately not recorded anywhere. There is also a daily plan: one number per day and device, namely how much was due that day. It is needed so that it remains visible later on which days you reached your goal — what was due shifts with every answer. How much you actually did is already in the review log and is not stored a second time. If you have entered your own access to a language model in the settings (Claude by Anthropic or ChatGPT by OpenAI) and switched on read-along, Minerva’s questions about your note belong to it as well: the quoted passage, the question, whether you answered, postponed or dismissed it, and what you replied. Requests to the language model go directly from your device to the provider, with your key and at your expense — eduphily does not see them, does not relay them and holds no key of its own; what the provider receives is shown in the app before the first request is sent. If you switch on one of the provider’s tools in settings — searching the web, fetching pages, running code or generating images —, the provider carries it out itself, on your account; eduphily itself fetches no third-party page in doing so. Some features require a tool, for instance reading a web page; that is then shown on the button. Which switches you have set stays on the device. For a reply in the conversation we record the addresses and titles of the pages it draws on, and the name and kind of a generated image or file — the file itself only once you file it as material. Added to that, for each tool call that fails, the provider’s short message, and for Claude’s code execution the program’s short text output — both cut to two hundred characters. The same goes for the conversations you have with her in the right-hand sidebar: your questions, her answers, and for each contribution the short note of what it draws on — a single paragraph, the whole note, or only the app’s help texts. They live with the note, stay until you delete them, and go with the note when you delete it. Questions about using the app that you ask without an open note are not stored at all. If you cut out a block, it stays as a clipping in your note’s tray until you insert it again or discard it; Minerva’s suggestions wait there too, with the short label above them and the text she proposes. And a homework item you create with two exclamation marks records when it is due, which phrase in the sentence produced that date (so you can undo the detection), what kind of task it is, how important it is and roughly how long it takes — its text, as with a flashcard, exists in only one place: the block it hangs on. If Minerva suggests a day on which you could do the task and you accept the suggestion, the task additionally records that day — it is your intention, not the deadline, and it only comes into being through your click. A subject or folder can also carry a supplies checklist: what you need to bring for it, such as a book, an exercise book or a pair of compasses. Each entry is one line with the label you type and a tick for whether you have checked it off — eduphily never sees the items themselves, and none of this belongs to your files. Removing a line takes it away immediately and does not move it to the trash; together with the folder itself, the whole list does go there. If you upload an audio file for a vocabulary card — for the word or for the example sentence — a separate entry records which paragraph and which spot it belongs to, that it was uploaded, its format, its size and length, a random identifier of the file, and whether it is already in object storage. The sound itself is described separately, see "The image file of your scans" further below. Your settings also record whether a sound plays on its own during review and whether the sound bar offers a slower speed. If you generate a sound with ElevenLabs, your device sends exactly that one word or example sentence directly to ElevenLabs, with your own key and at your expense — eduphily does not see the request, does not relay it and holds no key of its own; ElevenLabs processes the text as an independent controller, including outside the EU. The sound then records the text sent, the language, the voice, the model and the two voice settings, so the app can tell when the sound no longer matches the text. Your settings also hold the chosen voices, the model and the voice settings; your key stays on the device and is not synced. If you record a sound yourself, the app opens the microphone only when you press the button and only while the recording runs; before the first recording it tells you that the recording is stored in your account as the card’s sound. The recording is then treated like an uploaded audio file. If you attach a file to a folder or a note, your device reads the text out of it once — directly for text files, via a library on your device for PDFs — and stores it as a separate entry next to the file, page by page and at most eight thousand characters per page. A photo or a scanned PDF without a text layer yields nothing this way; only when you press the button does text recognition on your device read the page — for which it is briefly prepared as an image, and that image is discarded afterwards and stored nowhere. When that is not enough — for handwriting and formulas it never is — you can instead have the page read by your own language model: the page then goes as an image directly from your device to the provider, with your key and at your expense, and only for the pages you trigger it for; the number of pages is shown beforehand. What comes back is the text of the page and, if there are any, its formulas. The same applies to a web page: eduphily does not fetch third-party pages — either you share the page into eduphily from your browser, in which case its text sits with you as an attachment, or you have your own language model fetch it, on your account. That text is synced across your devices, the file itself is not; this is what lets you search for it on a second device. You can tick individual attachments for Minerva. The instructions Minerva receives are edited centrally by the operator; none of your input becomes a standing instruction to the model. Without that tick, no attachment goes to the provider. What you have ticked is stored as a list on the folder or note where you ticked it. For the conversation in the right-hand bar you separately choose which other notes and which attachments go along; before anything is sent, the number of characters is shown. That choice initially applies to this one conversation and ends with it. If you set it to "permanently for this note", it is stored on the note and applies to every further conversation about it until you take it back — at which point it is deleted, not merely hidden. | Maintaining your notes, syncing them between your devices, keeping them available without a network connection, and keeping track of how confidently you answered a flashcard in order to compute when you should see it again. | Contract (Art. 6(1)(b)) | Indefinitely, until you delete the content and then empty the trash. It is study material and meant to last. A flashcard’s learning progress is kept even when you change or delete the spot in the text — so a typo does not cost you your progress; it goes away with the note once you empty the trash. Deleting your account removes your database on the server entirely, including whatever is in the trash. |
| The image file of your scans — The actual image of a scanned page — the photograph itself, not the information about it (that lives under "Your content" above). It is stored at Hetzner Object Storage, in addition to the copy on your device and to a mirror copy on the server that exists solely for backups. | Keeping the scanned image and the audio file of a vocabulary card durably stored, in addition to the copy on your device. | Contract (Art. 6(1)(b)) | Indefinitely, until you delete the page and then empty the trash. Deleting a scanned page in the app removes it from the app and from your visible inventory and places it in the trash, from where you can restore it; the image stays in storage until then. Only emptying the trash marks it for deletion — there is no deadline after which this happens on its own. An uploaded page cannot be deleted and cannot be overwritten for thirty days from the upload — not even with the credentials eduphily itself uses to reach the storage; this protects fresh captures against someone with stolen access trying to cover their tracks. When you delete your account, every image file is marked as deleted before your other data falls, and is permanently removed from object storage after 31 days at the latest; the copy on your device stays where it is — you remove that one yourself. The image does not vanish from the backups immediately: the mirror on the server follows on the next nightly run, and the backups themselves are overwritten after six weeks at the latest in regular operation. If you instead empty the trash without deleting your account, the device triggers the same marking — and this time not just once: the request for it is stored before the data falls and stays in place until storage confirms the deletion. If the call does not get through, for instance because the device has no network at that moment, it is retried on the next start; because the request syncs along with the rest of your data, a second device of yours can carry it out as well. Only a request the app itself formed incorrectly is discarded and recorded in its log — retrying would not change it. An audio file you attach to a vocabulary card is stored in the same place under the same rules; wherever a page is mentioned here, the same applies to the sound. Up to 5 MB, a copy is also kept on your device so the sound plays without a network; a larger file lives only in object storage. If you remove or replace a sound, it goes to the trash. |
| Pending deletion requests — When you empty the trash, a short-lived entry is created holding the random identifiers of the image files to be deleted. It contains nothing else — no title, no text, no hint of what the deleted note was about. It syncs along with the rest of your data so that a second device of yours can carry out the deletion if the first one is offline. | Ensuring an image file also disappears from storage when the deletion call does not get through on the first attempt. | Contract (Art. 6(1)(b)) | Until storage has confirmed the deletion, after which the entry is removed. Without a network it stays in place and is retried on every start. Only a request the app itself formed incorrectly is discarded and recorded in its log. |
| Ledger of your files in object storage — One row for every file in object storage — the pages of your scans, the audio of your vocabulary cards, and the files you attach to a folder or a note: a random identifier for the file, which account it belongs to, how many bytes it occupies, which kind of file was declared (image, PDF, audio or video, for example), and whether it is currently being uploaded, permanently stored, or marked for deletion. | Maintaining your storage quota, verifying ownership of every file, checking on upload that a file matches the kind it was declared as, and marking a file for deletion. | Contract (Art. 6(1)(b)) | As long as the associated file exists. After a deletion, the row remains as a marker until the hourly cleanup run has verifiably removed the file from object storage, after which the row is removed too. |
| Rejected uploads — When you upload a file, it is checked after the upload whether its first bytes match the kind it was declared as. If they do not, the file is removed from object storage right away — and a row remains: your account identifier, the time, the declared kind, a short word for the reason (such as "signature does not match") and the first eight bytes of the file as a sequence of numbers. No file name, no content, no image. Those eight bytes are the beginning of every file and say what kind of file it really was; no text of yours is in them. | Recognising whether someone is trying to upload something other than what they declare — and, far more often, whether a version of the app is declaring a file kind incorrectly. Without these rows both would be invisible: the file is removed again immediately. | Legitimate interest (Art. 6(1)(f)) | 90 days. After that the hourly cleanup run removes the row. The same period as for the security logs, so that there are not two different periods for the same kind of record. |
| Your feedback to us — When you tap the button in the bottom right of the app and write to us, exactly that is stored: which of the four kinds you chose (bug, wish, praise, translation error), your text, and — only if you enter one yourself — an e-mail address for a follow-up question. Four technical details are sent along: the version of the app, the identifier of your browser or device (the "user agent"), the name of the view that was open, and the language of the interface. No screenshot, no content of your notes, and no identifier of your account — the feedback is not traced back to you. Sending does require a login so that the database cannot be filled by strangers, but nothing from that credential is carried into the feedback itself. | Finding bugs nobody else reports, and learning what is missing. With an address given, additionally: writing back when a report cannot be understood without a follow-up question. | Legitimate interest (Art. 6(1)(f)) | Indefinitely, for as long as the report still explains something — a bug description stays useful as long as the bug or its consequences do. There is no fixed deadline and one would be a claim: the feedback of a closed trial is little, and it is read by hand, not evaluated automatically. You cannot call up a submitted report again in the app — the path there permits creating only, neither reading nor changing nor deleting. If you want your report removed, a message to the address in the imprint is enough; without an e-mail address given, however, a report can no longer be attributed to you, and then we cannot remove it specifically either. |
| Operational and security logs — The server logs requests and security-relevant events — sign-in, sign-out, rejected attempts. What may appear in clear text is limited to a fixed list of technical fields; everything else is replaced by a placeholder. That list includes IP address, user agent and account ID. The content of your notes never appears in it, not even as an excerpt. | Monitoring operation, finding faults and detecting and repelling attacks on accounts. | Legitimate interest (Art. 6(1)(f)) | Operational logs are deleted after 30 days, security-relevant entries after 90 days. |
| Backups — Encrypted backups of the servers are created and stored on storage space at the same provider. They contain the same data as described above, including the images of your scans since 29 August 2026. For this the object storage is mirrored onto the server before every backup run; that mirror copy is held unencrypted there, readable only by the system user, and is brought in line with the object storage on every run — downwards as well, so a page deleted there also disappears from the mirror. In addition the images are protected against deletion directly at their own storage location, see "The image file of your scans" above. Every night one backup is brought back as a test: the backed-up state is opened on a separate machine belonging to the controller in throwaway databases, it is merely counted for completeness, and the copy is removed again afterwards. Without that test nobody would know whether a backup holds up in a real emergency. | Protecting your data against outage and data loss. | Legitimate interest (Art. 6(1)(f)) | Two layers on top of each other: the backup run keeps seven daily and four weekly states, and the storage space itself holds every state already removed there for a further ten days in snapshots of its own. What is counted are backup runs and not days: in regular operation a deletion during operation reaches every backup after six weeks at the latest; if backup runs fail, correspondingly later. |
Balancing of legitimate interests
Where we rely on a legitimate interest, the balancing test belongs in the open. Here it is:
Operator action log: The interest is evidence of an intervention the operator carried out. It weighs heavily because an unrecorded intervention into someone else's account could not be reviewed. The intrusion stays small: a record is only written when something actually happens — not on viewing — and it holds no name, no address and no content, only the internal identifier. After an account is deleted, nobody can be identified from it any more.
Handling note on a feedback entry: The interest is the handling of the feedback itself — you write it so that someone reads it. The intrusion is very small: the note holds nothing of yours, only the entry's identifier and who handled it when. It comes into being only when the operator acts, and it reveals no more about you than the feedback already does.
Test-round invitation: Our interest is controlling and evidencing access to a non-public test round. Only the address you gave for exactly this purpose is processed, plus a date and a note — no behaviour, no content. Anyone who does not want to take part is not on the list; no countervailing interest is apparent. Addresses from rejected sign-in attempts are not stored.
Rejected uploads: Interest: protecting a service that stores files for minors from being used unnoticed as storage for something else — and noticing bugs in our own app before anyone reports them. Intrusion: low. The row is created only when a check fails, so not in ordinary operation; it carries no file name and no content, but eight bytes describing the kind of file. It is not combined with the rest of your data, serves no advertising and no profile, and is removed automatically after 90 days. There is no milder measure: without a link to the account, a repeated attempt could not be told apart from a one-off mistake, and that distinction is the whole purpose.
Your feedback to us: Interest: improving an application whose bugs often cannot be found at all without its users describing them. Intrusion: low and in your hands — you decide whether to write anything, what it says and whether an address goes with it. The feedback carries no account identifier, is not combined with the rest of your data, and serves no advertising and no profile. The three technical details are the narrowest set that makes a bug report classifiable at all; without them, "it crashes for me" would be unusable. No overriding interests on your side are apparent, especially since nothing is collected that you did not write yourself.
Operational and security logs: Without logs an attack on an account could neither be detected nor reconstructed, and a fault could not be found. Only technical fields from a fixed allow-list are processed; everything else is replaced before writing, and the content of your notes never reaches the log. The lines carrying the full IP address serve to repel repeated sign-in attempts and are necessary for that.
Backups: Without backups a disk failure would mean the final loss of your notes — your own interest in a backup clearly outweighs the interest in its absence. The interference stays low: backups are encrypted, held at the same processor and, in regular operation, overwritten after six weeks at the latest. We name one exception explicitly: for the nightly test a state is decrypted and opened on a machine of the controller's own that does not stand at the processor. That is the price of knowing that a backup actually holds up. It is limited by the fact that the databases started for it have no network connection at all, are used only for counting, and are deleted together with the restored data after every run — including after an abort. The copy does not leave that machine.
What is stored on your device
It is not only cookies that are subject to the consent question, but every access to your device's storage — including the browser's local storage and the local database. That is why every single entry eduphily creates is listed here, together with the assessment of whether it is necessary to operate the service (then it is exempt from consent under §25(2) no. 2 TDDDG) or not.
eduphily stores nothing on your device that serves analysis. Every entry below carries the operation of the service.
Storage on your device
eduphily stores data on your device: your notes in a local database, your files in a second one, plus a few small view markers, the cache for offline operation and a session cookie. On top of that come technical diagnostics for the most recent app starts. All of it is necessary to operate the app and therefore exempt from consent under §25(2) no. 2 TDDDG — eduphily analyses none of it, hands none of it out on its own, and stores nothing on your device that tracks your behaviour or serves advertising.
| Entry | Purpose | Necessary? | How long |
|---|---|---|---|
| `eduphily` | The local database holding your subjects, topics, notes and the handwriting on them. Without it there would be no app — it is the service itself. | Yes — no consent required | Until you delete the data in the app or clear your browser storage. The session cookie expires with the session. Of the diagnostics only the last twenty app starts are kept; each further start displaces the oldest. |
| `eduphily-dateien` | Your images and files. They live separately from the notes and do not sync automatically between your devices — they are too large for that. From here only the pages of a scan go up to Hetzner Object Storage. An image or file you attach to a note is not uploaded anywhere: it stays on this device, and only the details about it — title, type and size — belong to your notes and are synced with them. Nothing is downloaded: what the app shows you is the copy on this device. The one exception is the small preview image of the first scanned page — it belongs to your notes (see "Your content" above) and therefore arrives with them from the server. | Yes — no consent required | Until you delete the data in the app or clear your browser storage. The session cookie expires with the session. Of the diagnostics only the last twenty app starts are kept; each further start displaces the oldest. |
| `eduphily-auswahl-v1` | Which topic or note was open last so the app reopens there. | Yes — no consent required | Until you delete the data in the app or clear your browser storage. The session cookie expires with the session. Of the diagnostics only the last twenty app starts are kept; each further start displaces the oldest. |
| `eduphily-gliederung-v1` | How wide the outline on the left was last and whether it was collapsed. A view setting of this device — it holds nothing from your notes and is not synced anywhere. | Yes — no consent required | Until you delete the data in the app or clear your browser storage. The session cookie expires with the session. Of the diagnostics only the last twenty app starts are kept; each further start displaces the oldest. |
| `eduphily-minerva-leiste-v1` | Whether the right-hand column is open, whether it shows Minerva or the side view, how wide you dragged the side view, and how the outline stood before. A view setting of this device — it holds nothing from your notes, not even what ran in the side view, and is not synced anywhere. | Yes — no consent required | Until you delete the data in the app or clear your browser storage. The session cookie expires with the session. Of the diagnostics only the last twenty app starts are kept; each further start displaces the oldest. |
| `eduphily-meldezeit-v1` | On which weekdays and at what time this device reminds you of homework. A setting of this device — it is not synced anywhere. The scheduled reminders themselves — the task's sentence, its subject and the note's title — are held by Android in its own notification storage until they are due; they do not leave the device, and Android does not show their text on the lock screen. | Yes — no consent required | Until you delete the data in the app or clear your browser storage. The session cookie expires with the session. Of the diagnostics only the last twenty app starts are kept; each further start displaces the oldest. |
| `eduphily-baum-v1` | Which subjects and topics are expanded in the outline. A view setting of this device — it holds nothing from your notes and is not synced anywhere. | Yes — no consent required | Until you delete the data in the app or clear your browser storage. The session cookie expires with the session. Of the diagnostics only the last twenty app starts are kept; each further start displaces the oldest. |
| `eduphily-diagnose-v1` | How long the last twenty app starts took, broken down by stage, plus how many documents were involved and how much storage is in use. Numbers and timestamps, not a word from your notes — the app needs them to be able to explain why a start occasionally takes a long time. They stay on this device and are not sent anywhere; if you want to help with a problem, you can save them as a file in the settings and pass them on yourself. The same place has a button that deletes them. | Yes — no consent required | Until you delete the data in the app or clear your browser storage. The session cookie expires with the session. Of the diagnostics only the last twenty app starts are kept; each further start displaces the oldest. |
| `eduphily-v3` | The cache for the application itself — the files that make offline operation possible. It holds none of your content. | Yes — no consent required | Until you delete the data in the app or clear your browser storage. The session cookie expires with the session. Of the diagnostics only the last twenty app starts are kept; each further start displaces the oldest. |
| `eduphily:authToken` | The session token used by the Android app build. It keeps you signed in there and does the job the session cookie does in the browser — a cookie does not travel reliably between the app and the server. The dedicated prefix is deliberate: several apps may live on one device, and a shared key would let one read the other's session. | Yes — no consent required | Until you delete the data in the app or clear your browser storage. The session cookie expires with the session. Of the diagnostics only the last twenty app starts are kept; each further start displaces the oldest. |
| `eduphily:pendingHandoff` | A sign-in in progress in the Android app build: the app draws a random handover id, opens the sign-in in your browser and uses the id to collect the session token afterwards. The entry holds only that id and the start time — no address, no name — and disappears once the sign-in completes, after ten minutes at the latest. | Yes — no consent required | Until you delete the data in the app or clear your browser storage. The session cookie expires with the session. Of the diagnostics only the last twenty app starts are kept; each further start displaces the oldest. |
| `eduphily:sessionNote` | A marker that a sign-in exists so the app need not ask the server first on start. | Yes — no consent required | Until you delete the data in the app or clear your browser storage. The session cookie expires with the session. Of the diagnostics only the last twenty app starts are kept; each further start displaces the oldest. |
| `better-auth.session_token` | The session cookie. It keeps you signed in and is the only cookie eduphily sets. | Yes — no consent required | Until you delete the data in the app or clear your browser storage. The session cookie expires with the session. Of the diagnostics only the last twenty app starts are kept; each further start displaces the oldest. |
YouTube videos in the side view
If you play a YouTube video next to a note, your device loads it from youtube-nocookie.com, a service of Google Ireland, only after you click “Allow playback”. Google then receives at least your IP address, details about browser and device and which video you request; during playback YouTube stores data in a storage area of its own on your device. eduphily receives none of it. The video's address itself belongs to your content and is kept as material with your notes (see above).
| Entry | Purpose | Necessary? | How long |
|---|---|---|---|
| `ip-adresse` | Goes to Google with every request — no server can deliver a video without it. | No — only with your consent | eduphily stores none of it. Your consent lasts until you reload the app; before the next video you are asked again — that is also how you withdraw it. How long Google keeps the data and the storage on your device is decided by Google; you can delete the YouTube storage through your browser settings. |
| `geraet-und-browser` | What every browser sends when requesting a page: browser identifier, language, screen size. | No — only with your consent | eduphily stores none of it. Your consent lasts until you reload the app; before the next video you are asked again — that is also how you withdraw it. How long Google keeps the data and the storage on your device is decided by Google; you can delete the YouTube storage through your browser settings. |
| `abgerufenes-video` | Which video is played. eduphily sends only the video's identifier and, where the address names one, the start second — no title, no note text. | No — only with your consent | eduphily stores none of it. Your consent lasts until you reload the app; before the next video you are asked again — that is also how you withdraw it. How long Google keeps the data and the storage on your device is decided by Google; you can delete the YouTube storage through your browser settings. |
| `youtube-speicher` | What YouTube stores in its storage area on your device during playback. This is not necessary for the app and therefore happens only with your consent (§25(1) TDDDG): the click on “Allow playback”. Before that the app loads nothing from YouTube, not even a thumbnail. | No — only with your consent | eduphily stores none of it. Your consent lasts until you reload the app; before the next video you are asked again — that is also how you withdraw it. How long Google keeps the data and the storage on your device is decided by Google; you can delete the YouTube storage through your browser settings. |
Who receives the data besides us
| Recipient | Location | Purpose |
|---|---|---|
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen | Deutschland | Betrieb der Server, der Sicherungen (Storage Box) und des Objektspeichers für die Bilddateien der Scans und die Tondateien der Vokabelkarten |
| Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland | Irland | Anmeldung mit Google-Konto und Auslieferung des Profilbilds; über YouTube (youtube-nocookie.com) das Abspielen eines Videos, das Sie in der Nebenansicht ausdrücklich erlaubt haben |
| Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA | USA | Abwehr automatisierter Eingaben im Voranmeldeformular der Projektseite (Turnstile) |
Beyond that we disclose data only where we are legally obliged to — for example in response to a valid official order.
One case you would not expect: if you sign in with Google, your device loads your profile picture directly from Google's servers. Google thereby learns your IP address, even while you are only using eduphily.
Transfers outside the EU
Operation takes place entirely in Germany. A transfer to a third country arises solely from signing in with a Google account: Google processes data within its group of companies in the United States as well. The basis is the European Commission's adequacy decision on the EU-US Data Privacy Framework of 10 July 2023, supplemented by standard contractual clauses.
There are no other transfers. eduphily has no push delivery, no advertising partners and no interface through which third-party programs could access your notes.
Your rights
You have the following rights. Where eduphily serves them directly in the app, that is stated; otherwise an informal message to the address given above is enough. We answer within one month.
- Access (Art. 15): You can request a copy of all data stored for your account. Contact the address given below.
- Rectification (Art. 16): You change your content directly in the app. Name, email address and profile picture come from your Google account and are changed there; otherwise contact the address given below.
- Erasure (Art. 17): Deleting your account also removes your database on the server with all subjects, topics and notes, as well as the images of your scanned pages: every image file is marked as deleted before the database falls; whatever object storage does not remove immediately is cleaned up by the hourly maintenance run.
- Restriction of processing (Art. 18): If you request restriction, we suspend processing until the matter is settled. Contact the address given below.
- Data portability (Art. 20): Your notes live as documents on your device and can be exported from there. For a copy from the server, contact the address given below.
- Objection (Art. 21): You may object at any time to processing based on legitimate interests. This concerns the invitation list, the server logs and the backups; the balancing behind each is set out at the respective point.
- Complaint to a supervisory authority (Art. 77): You may lodge a complaint with a data protection supervisory authority, in particular in the member state of your residence.
The app will get a button for deleting your account; during the closed test round a message to the address given above is enough. The deletion takes your database on the server with it entirely — subjects, topics, notes, handwriting, and the images of your scans: every image file is marked as deleted before the database falls; whatever object storage does not remove immediately is cleaned up by the hourly maintenance run. What it does not take is the entry on the invitation list: it existed before your account and is deleted separately on request. Nor does it take the copy on your device — you remove that one yourself by uninstalling the app or clearing the site data in your browser.
Do you have to provide this data?
You are under no legal or contractual obligation to give us data. eduphily does, however, require an account, and an account requires the name and email address from your sign-in. Without them there is no sync between your devices and no backup of your notes.
Automated decisions and profiling
There is no automated decision-making within the meaning of Art. 22 GDPR. No profile is built, no behaviour is scored and nothing is combined across services.
On the study companion “Minerva”: today it answers from fixed, stored texts. No language model is connected, and none of your notes is given to a third party in order to produce an answer. Should that change, this policy changes first.
Security
The connection between your device and our server is encrypted end to end. Every account gets its own database that no other account can reach — the images of your scans, by contrast, live together with those of other accounts in a shared store; they are kept apart by an access token that only matches your account, and by a check on every single request of who the file belongs to. Logs run through an allow-list: only technical fields may appear in clear text, your notes cannot end up there. Backups are encrypted.
Changes to this policy
This policy changes when the processing changes. Every version carries a date and a checksum of the text so that it stays traceable which text applied when.
Version of 2026-09-26. Checksum of this text: `5c676a8cd7fc4c7d`.