Legal
Privacy Policy
We ask for an email address so you can have an account, and we record what you learn so the feed can adapt. Your data lives on servers in the European Union. We do not sell it. Analytics only run if you switch them on. You can export or delete everything from inside the app, at any time, without asking us.
This policy explains our processing of personal data under the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). It applies to the douce scroll app and to this website.
1. Who is responsible
The controller for the processing described here, within the meaning of Art. 4(7) GDPR, is:
- Name
- K. Ryder Digmon
- Address
- Staffelstr. 2
70190 Stuttgart
Germany - privacy@douce.live
We have not appointed a Data Protection Officer. We are not required to under Art. 37 GDPR or §38 BDSG: we are a very small operation, we do not carry out large-scale systematic monitoring as a core activity, and we do not process special categories of data as a core activity. If that changes, we will appoint one and say so here.
2. What we collect, and why
Everything below is data you give us or generate by using the app. We do not buy data about you from anyone, and we do not enrich your profile from external sources.
2.1 Your account
| Data | Why | Legal basis |
|---|---|---|
| Email address | To create the account, sign you in, confirm the address, reset your password and send service messages. | Art. 6(1)(b) — performance of our contract with you |
| Password | Stored only as a salted hash. We never see and cannot recover your password. | Art. 6(1)(b) |
| Account identifier, sign-up and last sign-in timestamps | To operate the account and detect abuse. | Art. 6(1)(b); Art. 6(1)(f) — our legitimate interest in a secure service |
| Display name (optional) | Only if you choose one. It is shown to other people on the leaderboard and next to anything you post. | Art. 6(1)(a) — your consent, given by choosing a name |
2.2 Your learning profile
| Data | Why | Legal basis |
|---|---|---|
| Native language, target languages, level (A1–C2) per language | To generate and select content you can actually read. | Art. 6(1)(b) |
| Interest topics you pick | To shape what the feed writes about. | Art. 6(1)(b) |
| Placement-test answers and result | To estimate your starting level. You can override it at any time. | Art. 6(1)(b) |
| Cards seen, answers given, scores, XP, streak, badges, saved cards, vocabulary mastery, per-skill statistics, error patterns, words you look up, how long each card is on screen and which ones you scroll past, and the topics inferred from that | To avoid repeating content, schedule review, show progress, pitch difficulty, and order your feed toward the topics you actually read. This is profiling in the sense of Art. 4(4) GDPR — it shapes what you are shown. You can see the topics we have inferred, and change or remove them, in the app. It has no legal or similarly significant effect on you, and there is no automated decision-making under Art. 22. | Art. 6(1)(b) |
| Feed preferences, silent mode, theme, voice settings | To make the app behave the way you set it. | Art. 6(1)(b) |
2.3 Things you write, post or send us
| Data | Why | Legal basis |
|---|---|---|
| Douce posts: phrases, context notes, photos you attach | To publish them to other learners, as you intended, after a safety check. See section 3. | Art. 6(1)(b); Art. 6(1)(f) — preventing misuse |
| Comments, reactions, follows | To operate the social features. | Art. 6(1)(b) |
| Upvotes and downvotes on cards, and any reason or note you add | To shape your own feed — a downvote can mute a topic for you, quiet a card type, or, if you choose that reason, become a report we review. | Art. 6(1)(b) |
| Written answers to exercises | To grade them and give feedback. See section 3 on AI. | Art. 6(1)(b) |
| Custom set prompts (topics you ask the app to build a set about) | To generate cards for you, and to run safety checks on the request. | Art. 6(1)(b); Art. 6(1)(f) — preventing misuse |
| Bug reports, feedback and any screenshot you attach | To fix what you reported. | Art. 6(1)(f) — improving the service |
| Reports you file about content or another user | To assess and act on the report, as the Digital Services Act requires. | Art. 6(1)(c) — our legal obligation under Art. 16 DSA |
| Bluesky accounts you follow in the app | To bring those accounts' public posts into your feed. We never post on your behalf. | Art. 6(1)(b) |
Microphone: a voice note you attach to a post, and a recording you make answering another learner's question, are uploaded and stored with that post or answer. That is what they are for — other learners play them back. Like attached photos, they are served from a public address: see what other people can see.
The “repeat after me” card is different. It scores your pronunciation using your browser’s own speech recognition, and is not available in the app, where the card asks you to judge yourself instead. That audio never reaches us. Depending on the browser it may reach the browser’s maker; either way we do not receive it.
2.4 Technical data
When the app or this website talks to our servers, our hosting providers process your IP address, the time of the request, the page or endpoint requested, and your browser or device type. This is unavoidable — it is how the internet delivers a response to the right place — and we rely on Art. 6(1)(f) GDPR, our legitimate interest in delivering and securing the service. Server logs are kept briefly for troubleshooting and abuse defence, then discarded.
We also record a small number of in-app events — session start and end, card completed, XP earned, streak continued, badge earned — against your account, to make the feed and review scheduling work. This is part of the service under Art. 6(1)(b) and is separate from the optional analytics in section 4.
3. AI processing of your input
Most content in douce scroll is generated by AI, and some of the things you type are sent to AI providers to be processed. Here is exactly what, and where it goes.
What leaves our servers and reaches an AI provider:
- Your written exercise answers, together with the question, so the model can grade them.
- Custom set prompts — the topic you type when you ask the app to build a set.
- Words you tap for translation, with the sentence around them for context.
- Text to be spoken aloud, sent to the speech provider when you press play.
- Douce posts you write — the phrase, your note, and the title and description of any link you attach — checked automatically for harmful content before the post is published.
- Photos you attach to a post, checked the same way, before the post is published.
- Questions and answers you send to native speakers, checked the same way before they reach anyone.
- Your side of a role-play in the daily challenge, so the model can reply in character and grade the conversation at the end.
Anything you post publicly is checked before it appears, not after somebody reports it. The check is automated and its only outcome is whether the post is published: if it refuses, nothing is written and you are told, so you can change it and try again. We do not keep the image or the text of a refused post, and nobody at douce sees it unless you report the refusal to us. The check runs on Google's Gemini, and what Google keeps is set out below. You can still report anything that does get published, and a person handles that.
What does not leave our servers to an AI provider:
- Your email address, password, or account identifier.
- Your comments on posts, and your voice recordings.
- Your progress history, XP, streak or leaderboard standing.
Content generation runs in batches on general topics and levels — your interest topics influence what gets generated, but your identity is not attached to those requests.
Our AI providers act as processors under Art. 28 GDPR. Under their business terms, they do not use data submitted through their APIs to train their models. They may keep requests for a limited time to detect misuse of their services, then delete them. Google, which runs the safety check, keeps requests for up to 55 days, and authorised Google staff may review a request its systems flag.
For what the AI produces, how it is labelled, and what it means under the EU AI Act, see the AI transparency statement.
4. Analytics and your consent
We use PostHog, hosted in the European Union, for product analytics, error reporting and feature flags. Analytics are off until you turn them on. On first launch you are asked, plainly, and nothing non-essential runs before you answer.
If you consent, PostHog receives:
- Which screens you open and which features you use, with your account identifier.
- Crash and error reports, with the app version and build.
- Session replay — a reconstruction of your interactions with the interface. Text you type is masked, and logs are excluded, but you should know this is the most intrusive thing we do and it is entirely optional.
Legal basis: your consent, Art. 6(1)(a) GDPR, and §25(1) TDDDG for the storage and reading of information on your device. You can withdraw consent at any time in Settings, with effect for the future; withdrawal does not affect the lawfulness of what happened before.
Essential storage — your login session, your language and level, your consent choice itself — runs regardless, because the app cannot function without it. That falls under §25(2) TDDDG and needs no consent.
This website — the pages you are reading now on douce.live — counts visits with Vercel Web Analytics, which is a different, much smaller thing. It sets no cookie, writes nothing to your device and reads nothing from it, so §25 TDDDG does not apply and there is no banner to click. It never sees your account. Vercel derives a hash from the incoming request so that two page views can be counted as one visit, and discards it after 24 hours; there is no identifier that follows you to another website. What is recorded per page view: the time, the page address and any query parameters, the referring site, an approximate location from your IP address (country, region, city), your device type, and your browser and operating system version. We see only the aggregate. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in knowing whether anyone reads these pages. If you would rather not be counted, any content blocker stops the script — nothing on this site depends on it.
5. What other people can see
Your name and avatar appear beside what you share. Nothing else about you is shown unless you switch it on. Specifically:
- Posts, comments, answers and recordings carry your display name and avatar. Douce posts and comments are visible to signed-in learners. An answer is seen by the learner who asked. A recording plays for everyone who meets its phrase; whether it carries your name is a switch under “Your profile”. Treat all of them as public.
- Your profile opens when someone taps your name. Anyone who has seen your posts, comments, answers or credited recordings sees your name, your avatar, your posts, and how many answers, recordings and checks you have made. Your native language is shown once you have answered a question as a native speaker. Friends — two learners who follow each other — also see your languages, your level and your stamps. Everything else stays off until you switch it on: your streak, your time on douce, the month you joined and when you were last here. You can change each of these in the app, under “Your profile”.
- Following is visible only to the two people involved. When you follow someone, they can see that you do; nobody else can. Who follows you is shown only to you. There are no follower counts and no messages.
- Blocking hides you from each other everywhere, profiles included, and ends any follow between you.
- The leaderboard is off by default. You appear only if you switch it on and have chosen a display name. Then other learners see your display name, avatar, XP and streak — never your email, level, interests or account data.
- Photos and voice recordings attached to posts are served from a public URL. Anyone holding the link can open the image or play the recording, even without an account. Please do not attach anything you would not put on a public website.
- A card you share produces a public link showing that card. It does not reveal that you were the one who shared it.
6. Who else touches your data
6.1 Processors
We use the following providers as processors under Art. 28 GDPR. Each is bound by a data processing agreement and may only act on our instructions.
| Provider | What for | Where processed |
|---|---|---|
| Supabase | Database, authentication, file storage, server functions | EU (eu-west-1, Ireland) |
| Vercel | Hosting for this website and the web app; cookieless visitor statistics for this website | EU edge region; company in the USA |
| PostHog | Optional analytics, error reporting, feature flags | EU (Frankfurt) |
| Anthropic | Content generation; grading written answers | USA |
| Google (Gemini API, Cloud Text-to-Speech) | Content generation; translating tapped words; safety checks on posts, photos and questions before they appear; synthesising spoken audio | USA |
| Resend | Transactional and service email | EU/USA |
| Pinecone | Similarity search over our content library, to avoid duplicates | EU/USA |
We publish changes to this list here before a new provider starts processing your data.
6.2 Content that loads from someone else's server
The app shows public material from external sources — news feeds, Wikipedia and Wikimedia Commons, Mastodon, Lemmy, Bluesky and Stack Exchange. The text is fetched by our servers, so those sources learn nothing about you from it.
Pictures and pronunciation recordings are different: your device loads them from the source itself. The server holding the file therefore receives your IP address, the time of the request and what your device says about itself — the same technical data as in section 2.4, received by them instead of by us. Specifically:
- The picture on a news card — from the publisher's own server or image service.
- Pictures on vocabulary and culture cards, and the human pronunciation recordings some vocabulary cards play — from Wikimedia (wikimedia.org).
- Post pictures and profile pictures on Mastodon and Lemmy cards — from the server the post came from. Bluesky cards carry no pictures (see section 14).
- Profile pictures in the Bluesky account search — from Bluesky.
- The preview picture for a shared link — from the site that was linked.
Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in showing you the material you came for without first copying every picture and recording onto our own servers. You can object under section 9.
A video on a card loads nothing until you tap play. When you do, the player comes from youtube-nocookie.com, or from Vimeo with tracking switched off. These are the providers' own no-tracking modes: no advertising cookie, no cross-site tracking, and the view is not used to personalise anything. They may still store something on your device for the duration of playback, and they do see your IP address — see section 10.
6.3 Services your device contacts directly
Two checks run from your device rather than from our servers, so each of these providers sees your IP address when it runs:
| Who | When, and what for | Legal basis |
|---|---|---|
| hCaptcha (Intuition Machines, Inc., USA) | When you create an account or ask for a password reset — checking that you are a person rather than a bot | Art. 6(1)(f) — keeping automated sign-ups out |
| Have I Been Pwned (USA) | When you choose a password — checking it against known breaches, so a password already published elsewhere cannot be used here | Art. 6(1)(f) — protecting your account from credential stuffing |
Your password never reaches Have I Been Pwned. We send the first five characters of a hash of it — a prefix that hundreds of thousands of different passwords share — and compare the answer on your device.
7. Transfers outside the EU
Your account data, learning data and posts are stored in the European Union. Some processors in section 6 are established in the United States, so limited data reaches them there — principally the text sent for AI processing described in section 3.
Those transfers are covered either by the European Commission's adequacy decision of 10 July 2023 for the EU–US Data Privacy Framework, where the provider is certified under it, or by the Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR together with a transfer impact assessment. You can ask us for a copy of the safeguards at privacy@douce.live.
The servers your device contacts directly are a separate case. A picture, a pronunciation recording, a video player or one of the two checks in section 6.3 may be served from anywhere, including outside the EU. Your device makes those requests itself, so they are not transfers by us and we hold no safeguards for them — which is why those recipients are named in section 6 and not in the processor table. You can object under section 9.
8. How long we keep things
| What | How long |
|---|---|
| Account and learning data | For as long as your account exists |
| Everything, after you delete your account | Erased immediately; backups roll off within 30 days |
| Posts and comments you delete | Removed immediately |
| Server and security logs | Up to 30 days |
| Optional analytics and session replays | Up to 12 months, or until you withdraw consent |
| Content reports and moderation decisions | Up to 12 months, to handle appeals and repeat offenders |
| Correspondence with us | Up to 24 months |
| Public posts from Bluesky, Mastodon and Lemmy | Text, author and picture links removed after 10 days; see section 14 |
Where German commercial or tax law requires longer retention of specific records, we keep those records for the statutory period and restrict them from all other use.
9. Your rights
Under the GDPR you have the right to:
- Access your data and get a copy (Art. 15).
- Correct anything inaccurate (Art. 16).
- Erasure — delete your account and everything in it (Art. 17).
- Restrict processing while a dispute is resolved (Art. 18).
- Portability — receive your data in a machine-readable format (Art. 20).
- Object to processing based on legitimate interests, on grounds relating to your situation (Art. 21).
- Withdraw consent at any time, for analytics or anything else you consented to (Art. 7(3)).
You do not need to email us for the two big ones. Settings → Your data has Download my data and Delete my account. Deletion is immediate and permanent, and this page sets out both routes. For anything else, write to privacy@douce.live and we will respond within one month, as Art. 12(3) requires.
You also have the right to lodge a complaint with a supervisory authority (Art. 77). Ours is:
- Authority
- Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
- Address
- Lautenschlagerstraße 20
70173 Stuttgart
Germany - Website
- baden-wuerttemberg.datenschutz.de
You may also complain to the supervisory authority where you live or work, wherever that is in the EU.
10. Cookies and local storage
We use no advertising cookies and no third-party tracking cookies. What we store:
| What | Purpose | Consent needed |
|---|---|---|
| Session token | Keeps you signed in | No — strictly necessary |
| App preferences (language, level, theme, silent mode) | Remembers your settings | No — strictly necessary |
| Consent record | Remembers your answer so we stop asking | No — strictly necessary |
| PostHog analytics and session replay identifiers | Optional analytics | Yes — only after you opt in |
| Whatever a video player stores while a clip plays | Playing a clip you tapped play on. The player is loaded from youtube-nocookie.com, or from Vimeo with tracking switched off, so no advertising or cross-site tracking identifier is set — see section 6.2 | No — strictly necessary for the clip you asked for, §25(2) TDDDG |
| Vercel Web Analytics (this website) | Counting page views — stores nothing on your device at all | No — nothing is stored or read |
11. Age limit
douce scroll is for people aged 16 and over. We do not knowingly collect data from anyone under 16. If you believe a child under 16 has an account, write to privacy@douce.live and we will delete it.
12. Security
Traffic is encrypted in transit with TLS. Data is encrypted at rest. Passwords are stored only as salted hashes. Access to the database is restricted per user by row-level security, so one account cannot read another's data. API keys for AI and email providers live only on our servers and are never shipped in the app. Access to production systems is limited to the controller and protected by multi-factor authentication.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours under Art. 33 GDPR and tell you directly where Art. 34 requires it.
13. Changes to this policy
We will update this policy as the app changes. The version and date are at the top. For changes that materially affect you, we will tell you in the app or by email before they take effect, and where the law requires it we will ask for your consent again rather than assume it.
Previous versions are available on request.
14. If a post of yours appears in douce
douce shows learners public posts from Bluesky, Mastodon and Lemmy in the language they are learning. If one of those posts is yours, this section applies to you.
- What we take. The post's text, your display name and handle, a link to the post, when you posted it, and its like and repost counts. For Mastodon and Lemmy posts, also links to the first attached image and to your profile picture. From Bluesky we take no photos and no profile pictures.
- Why. So learners read real writing in the language they are learning. We highlight words and phrases worth learning, and some become word cards that link back to your post.
- Legal basis. Art. 6(1)(f) GDPR: our legitimate interest in showing real language. We take only posts that are already public, we take little, and we keep it briefly.
- Who else processes it. Before a post is shown, AI models from Anthropic and Google in the USA check its text for safety and pick out vocabulary. Section 7 covers those transfers.
- Who sees it. Signed-in learners of that language. A learner can also share a post's card, and anyone with that link can open it until the post leaves douce.
- How long. The text, your name, handle and picture links are removed 10 days after we fetch the post. What remains is the link to the post, so a word card can say where it came from.
- Bluesky settings. We take nothing from a Bluesky account that asks apps not to show it to logged-out people, and every learner counts as logged out. If you delete a Bluesky post or turn that setting on, we remove our copy at our next check, and never later than those 10 days.
- Your rights. You can object at any time (Art. 21 GDPR) or ask us to erase what we hold (Art. 17 GDPR). Write to privacy@douce.live with a link to your account or post. For a Bluesky account, we also stop taking your posts.