CroatiappAcademy
CoursesThe AcademyBlogContactLegalStart for free

N.º 03 · Croatiapp Academy

Privacy policy

What personal data we process, why, who we share it with, how long we keep it and how to exercise your rights.

Version 1.0In force since 1 October 2026
Contents
  1. 1Who the controller is
  2. 2What data we process
  3. 3Why we use it and on what legal basis
  4. 4Where the data comes from
  5. 5Artificial intelligence and your data
  6. 6What other people can see
  7. 7The emails we send you
  8. 8Who we share data with
  9. 9Data outside the European Union
  10. 10How long we keep it
  11. 11Your rights
  12. 12Deleting your account
  13. 13Children
  14. 14Security
  15. 15Complaining to the authority
  16. 16Changes to this policy

Privacy policy

In short

  • We process only what we need to run the Academy for you: your account, your progress, what you write and your purchases.
  • We don't sell your data or show ads. Analytics (PostHog, in the EU) and YouTube videos only load if you agree.
  • What you write to the AI is sent to AI model providers so they can answer you. We don't train models on your data.
  • Some providers are in the USA: data is transferred with GDPR safeguards (the EU-US Data Privacy Framework and standard contractual clauses).
  • You can see, download, correct and delete your data. If something doesn't seem right, you can complain to AZOP, the Croatian data protection authority.

This summary helps you find your way around; it doesn't replace the full text.

1. Who the controller is

Controller
Martín Silva Molina
OIB
42550330688
Address
Ul. Ivana Rendića 28b, 10000 Zagreb, Hrvatska
Privacy contact
legal@croatiapp.app

We haven't appointed a data protection officer because we aren't required to (art. 37 of Regulation (EU) 2016/679, the GDPR), but everything you send to the address above is read by the person responsible. This policy covers all croatiapp.app websites and the Croatiapp apps for iOS.

2. What data we process

  • Account: email, first and last name, username, profile photo, language, password (encrypted and stored by Clerk), the provider you sign in with (Google, Apple) and your role.
  • Learning: lessons watched and completed, the second you reached in a video, answers and results in exercises, games and exams, cards collected, points, favourite words.
  • What you write: notes, sticky notes, pins, notebooks, exercise routines, your chats with the Profesorica, the sentences you analyse, your requests to generate exercises or notebooks, and the images you upload for analysis.
  • Analyses: diagnoses, your estimated level, error patterns and your “Tu indeks” profile, built from your results.
  • Purchases: what you bought, when, the amount, the Stripe payment ID, your kunas and their transactions. We never see your card details.
  • Gifts: if you give a gift, the recipient's name, email and message; if you receive one, the code and when you redeemed it.
  • Community: comments, votes, likes, reports, and what you submit to the portal (reviews, events, listings).
  • Messages: what you send us by email, through the contact page or through the forms on this site.
  • Technical data: IP address, browser, operating system, device language, server logs and errors.
  • Usage (only if you accept analytics): pages you view, buttons you tap, load times and, if you accept session recording, how you moved around the page.

We don't ask for or want sensitive data (health, religion, political opinions…). Please don't put it in your notes or in your chats with the AI.

3. Why we use it and on what legal basis

PurposeDataLegal basis (GDPR)
Create and maintain your account, and keep you signed in across all sites with one sessionAccount, technical dataContract (art. 6(1)(b))
Provide the courses and save your progress, notes, notebooks and cardsLearning, what you writeContract (art. 6(1)(b))
AI features: the Profesorica, Fabián, generated exercises and notebooks, the diagnosis and the examWhat you write, learning, analysesContract (art. 6(1)(b))
Build your “Tu indeks” profile and personalise exercises and notebooksLearning, analysesContract (art. 6(1)(b))
Take payment, deliver what you bought, send gifts, manage kunasPurchases, gifts, accountContract (art. 6(1)(b))
Invoicing and meeting our accounting and tax obligationsPurchasesLegal obligation (art. 6(1)(c))
Reminding you by email about a course you started if you stop coming (two at most each time)Email, name, progressLegitimate interest in helping you finish what you started (art. 6(1)(f)); one click to unsubscribe
Letting our team know on the phone what happens in the Academy (sign-ups, purchases, finished lessons, exams) so we can help you betterName, email, the actionLegitimate interest in supporting and improving the service (art. 6(1)(f))
Send the recipient a gift that someone bought for themRecipient's name and emailLegitimate interest of the giver and the recipient (art. 6(1)(f))
Show your comments, moderate the community and handle reportsCommunity, accountContract (art. 6(1)(b)) and legal obligation (DSA)
Reply to your messages, complaints and data protection requestsMessages, accountContract or pre-contractual steps (art. 6(1)(b)), legal obligation (art. 6(1)(c))
Security, fraud and abuse prevention, finding and fixing bugs (Sentry)Technical data, accountLegitimate interest in a secure service that works (art. 6(1)(f))
Measure how the Academy is used so we can improve it (PostHog)Usage, technical data, identifierConsent (art. 6(1)(a) GDPR and art. 43 ZEK)
Session recording (PostHog)UsageConsent (art. 6(1)(a))
Watch the lesson videos (YouTube)Technical dataConsent to YouTube cookies (art. 43 ZEK)
Emails about news or promotions, if we ever send themEmail, nameConsent or, for customers, similar products with an unsubscribe link in every email (art. 50 ZEK)
Where the legal basis is your consent, you can withdraw it at any time; this doesn't affect anything done before. Where it's the contract, we can't provide the service without that data.

4. Where the data comes from

  • Almost all of it from you: what you write and what you do in the Academy.
  • If you sign in with Google or Apple, they give us your name, your email (or Apple's private relay email) and your photo.
  • If someone gives you a course as a gift, that person gives us your name and email. We tell you this in the gift email itself.
  • Stripe confirms each payment and its status.

5. Artificial intelligence and your data

For the Profesorica to answer you, for Fabián to analyse a sentence or for an exercise to be generated, we send AI model providers your message and the minimum context needed: the lesson and the second of the video you're on, the subtitle line at that moment, your answers and results when you ask for an analysis, and the image if you uploaded one. The request goes through the Croatiapp API and a server we run that picks the model; from there it goes to Groq or Cerebras (USA).

  • We don't use your data to train AI models, and we choose providers that commit not to train on the data we send them.
  • Conversations are saved in your account so you can pick them up again, until you delete them or delete your account.
  • Profiling and automated decisions: the AI uses your results to produce diagnoses, an estimated level and “Tu indeks”. This is profiling (art. 4(4) GDPR) used only to personalise your learning. We don't make decisions that have legal effects or similarly significant effects on you based solely on automated processing (art. 22 GDPR): marks are for guidance only, they don't block your access to anything and you can ask a person to review them.

More detail: Artificial intelligence at Croatiapp.

6. What other people can see

Your notes, notebooks, progress, chats and purchases are visible only to you. What you publish on the blog or the portal (comments, reviews, listings) is visible to anyone, with your name and profile photo, and is machine-translated into the site's other languages. If you delete a comment, it disappears.

7. The emails we send you

We send you service emails: sign-in codes (sent by Clerk), purchase confirmations, gifts, replies to your messages and important notices about your account or these documents. If you start a course and don't come back for 3 days, we send you a reminder with the lesson where you left off (and one more after a month; never more than two in a row). Every reminder has a link to stop them. We don't currently send newsletters or advertising. If we ever do, it will only be with your consent or, if you've already bought from us, about similar products, with an unsubscribe link in every email.

8. Who we share data with

We don't sell or rent out your data. We share it only with the providers we need to run the Academy, who process it on our behalf (processors, art. 28 GDPR) under a data processing agreement, or as independent controllers where stated:

ProviderPurposeDataLocation
Clerk, Inc.Accounts, sign-in, sessionsAccount, IP, deviceUSA
Convex, Inc.The Academy's databaseAccount, learning, what you write, purchasesUSA
Vercel Inc.Hosting for the websites and the APITechnical data, everything that passes through the sitesUSA and global network
Cloudflare, Inc.DNS, network and storage for course contentTechnical data (IP)USA and global network
Stripe Payments Europe, Ltd.Payments. Acts as an independent controller to prevent fraud and meet its legal obligations (its policy)Email, name, payment details, country, IP; for gifts, the recipient's name and emailIreland (EU) and USA
Resend (Plus Five Five, Inc.)Sending emailsEmail, name, email contentUSA
Apple (Apple Inc.)Push notifications to the team's phone (APNs)Name, email and the actionUSA
PostHog, Inc.Analytics and session recording, only with your consentIdentifier, usage, technical data; when signed in, your email and nameEU (Frankfurt)
Functional Software, Inc. (Sentry)Error monitoringIdentifier, email, browser, the errorEU (Germany)
Groq, Inc. and Cerebras Systems Inc.Artificial intelligence modelsYour messages and the lesson contextUSA
Our own AI server (VPS)Intermediary that picks the model; it doesn't store your messagesYour messages and the contextGermany (EU)
Google LLC (Cloud Translation) and Translated S.r.l. (MyMemory)The translator and comment translationThe text to be translatedUSA / Italy (EU)
Google Ireland Ltd. (YouTube)Playing the videos. Independent controller for its cookies (its policy)Technical data, YouTube cookiesIreland (EU) and USA
Google and AppleSign-in with their accounts. Independent controllersWhatever you authorise them to shareUSA
RevenueCat, Inc.In-app purchases in the iOS appsUser identifier, purchasesUSA
Open-Meteo (Switzerland)Weather on the portal (only the city's coordinates are sent, never your location)IPSwitzerland
We may also disclose data to authorities, courts or advisers (accountants, lawyers) where the law requires it or to defend our rights, and to whoever takes over the Academy if it changes hands, after telling you first.

9. Data outside the European Union

Several providers are in the United States. Transfers are made with the safeguards in Chapter V of the GDPR: the EU-US Data Privacy Framework adequacy decision (Decision (EU) 2023/1795) for certified providers and, in addition or instead, the European Commission's standard contractual clauses (Decision (EU) 2021/914). Switzerland has an adequacy decision. You can ask for a copy of the safeguards at legal@croatiapp.app.

10. How long we keep it

DataHow long
Account, progress, notes, notebooks, chats, analysesAs long as you have an account. When you delete it, they're erased within 30 days; backups follow their own cycle, up to 90 days more.
Unused free accountsIf an account with no purchases isn't used for 36 months, we email you and, if you don't reply within 30 days, we delete it.
Purchases, invoices and paid kuna transactionsThe period required by Croatian accounting and tax law (up to 11 years).
Public commentsUntil you delete them, we remove them through moderation or you delete your account.
Content reports and moderation actions2 years from the decision.
Consumer complaintsAt least 1 year from our reply (art. 10 of the Zakon o zaštiti potrošača); generally 3 years.
Messages and data protection requests3 years from our last reply.
Analytics (PostHog)24 months.
Errors (Sentry)90 days.
Server logsAs long as each provider keeps them (usually under 30 days).
Your cookie choice12 months (then we ask you again).

11. Your rights

At any time, free of charge, you can ask us for:

  • Access: to know what data of yours we process and get a copy (art. 15).
  • Rectification: to correct data that's wrong (art. 16). You can change most of it from your account.
  • Erasure: to delete your data (art. 17), except what the law requires us to keep.
  • Restriction: to stop using it while a problem is being resolved (art. 18).
  • Portability: to receive your data in a structured format (JSON) so you can take it elsewhere (art. 20).
  • Withdrawal of consent whenever you like (art. 7(3)): for cookies, from your preferences.

Email us at legal@croatiapp.app or use the form below. We'll reply within one month at the latest (this can be extended by two further months if the request is complex, and we'll let you know). If we can't confirm it's you, we'll ask you to write to us from your account email.

Exercise a data protection right

Write from your account's email address so we know it's you.

We only use these details to deal with this request. See the Privacy policy.

12. Deleting your account

  1. Go to your account → Settings → Delete account, or email us at legal@croatiapp.app from your account email (you can also use the form above and choose “Erasure”). In the iOS apps, go to Profile → Delete account.
  2. We'll ask you to confirm first, because deleting your account means losing the courses you bought and your kunas.
  3. Within 30 days we delete your account and everything linked to it: progress, notes, notebooks, routines, chats, analyses, cards and favourites. Your public comments are deleted or anonymised.
  4. We keep only what the law requires: records of purchases and invoices, for the tax retention period.

13. Children

In Croatia, the age at which you can consent to online services yourself is 16 (art. 19 of the Zakon o provedbi Opće uredbe o zaštiti podataka, the Croatian Act implementing the GDPR). If you're under 16, you need permission from your parent or guardian to create an account, and you can't accept analytics on your own. If you're a parent or guardian and believe a child has given us data without permission, write to us and we'll delete it.

14. Security

We use encrypted connections (HTTPS), encrypted passwords, access to data only for those who need it, providers with security certifications, and masking of everything you type in session recordings. If there's a personal data breach that puts your data at risk, we notify AZOP within 72 hours and, if the risk is high, you as well.

15. Complaining to the authority

If you think we've mishandled your data, please tell us first: we'll want to put it right. But you have the right to lodge a complaint with a supervisory authority (art. 77 GDPR). In Croatia, that's:

Authority
Agencija za zaštitu osobnih podataka (AZOP)
Address
Selska cesta 136, 10000 Zagreb, Hrvatska
Phone
+385 1 4609 000
Website
azop.hr

or the authority in the EU country where you live or work.

16. Changes to this policy

If we change something important (for example, a new provider or a new purpose), we'll let you know by email or in the Academy before it takes effect. Previous versions are listed at the bottom of this document.

Previous versions

  • v1.0 · 1 October 2026 · First version.
Back to top