Privacy Policy

We take the protection of your personal data seriously. This privacy policy informs you about the nature, scope and purpose of processing personal data when you use our mobile app Sparkling and our public main website at sparkling-main.web.app.

1. Data controller

The data controller within the meaning of the General Data Protection Regulation (GDPR) is:

Corvin Hartmann
Hirschgraben 24
52062 Aachen
Germany

Email: corvin_hartmann@gmx.de

2. General information

The following notes provide a simple overview of what happens to your personal data when you use our app or main website. Personal data is any data with which you can be personally identified.

This app is intended for users aged 16 and over. If you are younger, you need the consent of your parent or guardian.

3. Main website

At https://sparkling-main.web.app (the "main website") we provide information about the app and link to the app stores. When you visit, personal data may be processed – in particular if you consent to optional reach measurement.

3.1 Technically necessary processing (without analytics cookies)
We use Firebase Hosting (Google LLC) to serve the site. We store your language choice and your decision in the cookie notice in your browser's local storage (localStorage). Campaign parameters from the URL (UTM parameters) are temporarily held in sessionStorage until you close the tab – so store links (Google Play / App Store) can carry attribution when you click a download button.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a functional website and traceable store redirects). You may object to this processing (Art. 21 GDPR) if your interests override ours.

3.2 Google Analytics 4 (only after consent)
If you click "Accept" in the cookie notice, we use Google Analytics 4 (GA4). Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, USA).

Purpose: Statistical analysis of website usage (e.g. page views, origin via UTM parameters, clicks on app store buttons) to improve our online offering.

Data processed (examples): Pseudonymous online identifiers (cookie ID), pages/URLs visited, approximate location (via IP address; IP anonymisation is enabled), device and browser information, time on site, UTM parameters passed, and events such as download_click on store buttons.

Legal basis: Consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG (consent to access information on your terminal device).

Cookies: GA4 sets cookies (e.g. _ga, _ga_*). Without your consent, no analytics cookies are set.

Retention: Event and user data in GA4 typically up to 14 months; we store your consent choice locally until you delete it in the browser or decide again.

Third-country transfer: Google may transfer data to the USA. EU standard contractual clauses (SCC) and, where applicable, the EU-US Data Privacy Framework are used. More information: Google Privacy Policy · Google Analytics Terms.

Withdrawal: You can withdraw consent at any time by choosing "Decline" on your next visit, deleting website data/cookies in your browser, or using the browser add-on: Google Analytics opt-out.

4. Data collection in the app

Who is responsible? Data processing is carried out by the app provider (see section 1).

How do we collect your data? Some data is collected when you provide it (e.g. during registration). Other data is collected automatically when you use the app (e.g. learning progress).

Why do we use your data? Some data is collected to ensure error-free provision of the app. Other data may be used to analyse your usage if you have consented (analytics).

5. Account & authentication

Registration is required to use the app.

Data processed:

Legal basis: contract performance pursuant to Art. 6(1)(b) GDPR.

Recipient: Google LLC (Firebase Authentication), 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Processing in the EU region, standard contractual clauses (SCC).

Retention: Until deletion of your account.

OAuth login (Google Sign-In, Sign in with Apple): If you sign in with Google or Apple, only basic data provided by those services (email, name if applicable) is used. Their privacy policies apply: Google, Apple.

6. Learning data & cloud sync

To sync your flashcards, learning progress and settings across devices, this data is stored in a cloud database.

Data processed: Flashcards, folder structure, learning progress (SRS), CEFR language level, activity logs, app settings.

Legal basis: contract performance pursuant to Art. 6(1)(b) GDPR.

Recipient: Google LLC (Firebase Firestore), EU region, standard contractual clauses (SCC).

Retention: Until deletion of your account. Encryption: HTTPS/TLS, encryption at rest.

7. Artificial intelligence (OpenAI)

We use the OpenAI API for: (a) generating learning exercises, daily texts and translations; (b) vocabulary list scanner: scanned images are sent to OpenAI Vision for evaluation (recognition of vocabulary pairs) (see section 8).

Data processed: Your entered vocabulary and texts, language pair, CEFR level; for the vocabulary list scanner also scanned image data. No transmission of email, name or account ID.

Recipient: OpenAI Inc., USA. EU standard contractual clauses (SCC), EU-US Data Privacy Framework, Data Processing Addendum (DPA).

Retention: OpenAI stores API requests for up to 30 days for abuse prevention. API data is NOT used to train OpenAI models.

OpenAI Privacy Policy · OpenAI DPA

AI-generated content in the app is labelled with "✦ AI-generated".

8. Usage analytics in the app (Firebase Analytics)

This section applies only to the mobile app – not the main website (see section 3).

We use Firebase Analytics in the app ONLY after your explicit consent (opt-in).

Data processed: App usage data, device information, anonymised analytics ID. NO IP addresses (automatically anonymised).

Legal basis: consent pursuant to Art. 6(1)(a) GDPR and § 25 TDDDG.

Recipient: Google LLC (Firebase Analytics / GA4), USA. SCC, EU-US Data Privacy Framework.

Retention: 14 months.

Withdrawal: At any time in the app under "Settings → Legal → Analytics".

9. OCR & vocabulary list scanner

(A) Text scanner (single languages): Uses Google ML Kit. Text recognition runs locally – images are NOT sent to external servers.

(B) Vocabulary list scanner (front/back, arbitrary text): Uses OpenAI Vision API. Scanned images are sent to OpenAI Inc. (USA) for evaluation (recognition of vocabulary pairs). Retention at OpenAI: up to 30 days (like other API requests).

Legal basis: contract performance pursuant to Art. 6(1)(b) GDPR. Recipient (mode B only): OpenAI Inc., USA (SCC, DPA).

Google ML Kit may send anonymous usage statistics (no image data). Please scan only content you have rights to.

10. Speech recognition (speech-to-text)

Planned feature, currently not active. Audio is sent to Apple/Google servers for processing. Recordings are not stored permanently.

11. Social features (friends & sharing)

Data processed: username, friend requests, shared folder content. Email addresses are not shared with others.

Share only content you have rights to.

12. Push notifications

Data processed: device token, notification settings. No flashcard content. Withdrawal at any time in settings.

13. Feedback & reviews

Review text and timestamp, stored anonymously (no link to account ID). Retention: 12 months.

14. Security measures

15. Retention periods

16. Automated decision-making & AI

The app uses AI for personalisation (CEFR adjustment, exercise selection, SRS). These adjustments have no legal effects.

17. Google Fonts

The app bundles fonts locally. No connection to Google servers is made.

18. Transfers to third countries (USA)

Safeguards: EU standard contractual clauses (SCC), EU-US Data Privacy Framework, data minimisation, encryption. Affected services: OpenAI, Google LLC, Apple Inc.

You have the right to object to such transfers (use of affected features may be limited).

19. Your rights

You have the rights of access, rectification, erasure, restriction, objection, data portability and withdrawal of consent (Arts. 15–21, 77 GDPR).

Response time: 1 month (may be extended by 2 months).

20. Obligation to provide data

Required: email, password, flashcard content. Optional: analytics, social features, feedback.

21. Supervisory authority

State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW)
Kavalleriestraße 2-4, 40213 Düsseldorf, Germany
Phone: +49 211 38424-0 · Email: poststelle@ldi.nrw.de
www.ldi.nrw.de

22. Changes

We reserve the right to update this privacy policy. For material changes we will inform you via the app and/or a notice on the main website.

Last updated: 26 May 2026

Overview · Legal Notice · Terms of Service