LEGAL
Privacy Policy
What Germanium stores, where it is stored, who can see it, and how to delete it — in plain language, for a product that collects almost nothing.
VON GERMANIUM
Operator — Divyansh Sharma (Germanium)
Who is responsible
Germanium is operated by Divyansh Sharma (Germanium). Questions, requests, or complaints about data go to flowdivs@proton.me — a human reads it.
What we collect — and what we deliberately don't
- Email address and password — only if you create an account. Used exclusively to authenticate you. No newsletter, no marketing, no sale, no sharing.
- Learning progress — archived days, worksheet answers (including what you typed on graded items), review-queue state, and self-rated confidence. This is the product working; it is stored per account and visible only to you.
- Your Anki deck, if you import one — parsed in your browser. The media cache lives on your device (IndexedDB) and never leaves it. Germanium's servers never receive your deck.
- Nothing else. No analytics trackers, no advertising pixels, no fingerprinting, no social plugs, no third-party ad networks. Signed-out visitors generate no stored data at all — progress in a signed-out session lives in your browser's memory and vanishes when you close the tab.
Where your data lives
| Data | Stored in | Who can read it |
|---|---|---|
| Account (email, password hash) | Supabase Auth (EU-region infrastructure) | Only the operator, for account recovery |
| Learning progress | Supabase Postgres, one row per user, locked by row-level security | Only your account — enforced at the database layer, not the application layer |
| Anki media cache | Your browser (IndexedDB) | Only your device |
Your rights
- 01Access — email us and we export your full progress row as JSON within 30 days.
- 02Erasure — email us and your account and progress row are deleted within 30 days. Signing out and clearing your browser removes everything on your side immediately.
- 03Portability — your progress row is already a single JSON document; export on request, or via the desk's download at any time.
- 04Objection — the data exists only to run the product. Decline by not creating an account; the full course works signed-out (progress just isn't saved between sessions).
Third parties
- Supabase — database and authentication hosting (the infrastructure your progress sits on). Supabase acts as data processor; their DPA applies.
- Cloudflare — static site hosting and bot protection (Turnstile) on the sign-in form. Cloudflare processes connection metadata (IP, challenge results) as any host does.
- Deutsche Welle / YouTube — the course lessons link out to DW's platform; when you watch a lesson you are on their infrastructure under their terms. Nothing about your Germanium usage is sent there by us.
Children
Germanium is a language course open to everyone, but accounts are not directed at children under 13 (or 16 in the EU, whichever applies to you). If you believe a child created an account, email us and it will be removed.
Changes
If this policy changes materially, the change is dated at the top of this page. Continued use after a change means acceptance — but data collected under the old policy is never retroactively re-scoped.
Is Germanium GDPR compliant?
Germanium is built on the GDPR's data-minimization principle: collect almost nothing, store it once per account, lock it with row-level security, and delete it on request within 30 days. Data-minimization is the compliance strategy — there is simply very little to protect.
Does Germanium sell or share my personal data?
No. Germanium collects only an email address and your learning progress, shares neither with advertisers or data brokers, and the only processors are the infrastructure providers (Supabase hosting, Cloudflare delivery) needed to run the site at all.
How do I delete my Germanium account and data?
Email the address at the top of this page and your account and progress row are deleted within 30 days. Signed-out sessions store nothing, so most visitors have nothing stored to delete.