Privacy Policy
This Privacy Policy explains how GoethéB1 ("we", "us", the "Service", at b1goethe.com) collects and uses your personal data when you use our website and practice app for preparing the Goethe-Zertifikat B1 exam. We are committed to protecting your privacy and complying with the EU General Data Protection Regulation (GDPR) and applicable data-protection laws.
1. Who is responsible for your data
The controller responsible for your personal data is:
- Operator: Elif Yılmaz (operating as “GoethéB1”)
- Address: Abide Bayram Sk 19, Gazimağusa 99450, North Cyprus (TRNC)
- Email: hello [at] b1goethe.com
As the operator is established outside the EU/EEA, our representative in the EU under Art. 27 GDPR is: [EU REPRESENTATIVE, to appoint; name & EU address].
2. What data we collect
- Account data, your name, email address, and a securely hashed password (we never store your password in plain text). If you sign in with Google, we receive your name and email from Google.
- Learning progress, your practice results, scores, saved vocabulary, streaks, and settings, so we can save and sync your progress.
- Writing submissions, the texts you write in the Schreiben (writing) practice and the automated feedback generated for them, so we can grade your writing and show your history.
- Technical data, basic server logs (IP address, browser type, timestamps) needed to operate and secure the Service.
- Cookies, a single strictly-necessary login/session cookie (see Section 4).
We do not collect special-category data (e.g., health, ethnicity), and we do not knowingly collect data from children (see Section 9).
3. Why we use your data, and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Create and run your account; sign-in | Performance of a contract (Art. 6(1)(b)) |
| Save and sync your learning progress | Performance of a contract (Art. 6(1)(b)) |
| Generate automated feedback on the writing you submit | Performance of a contract (Art. 6(1)(b)) |
| Keep the Service secure; prevent abuse | Legitimate interests (Art. 6(1)(f)) |
| Send study reminders / notifications (if you enable them) | Your consent (Art. 6(1)(a)) |
| Website analytics (Google Analytics via Google Tag Manager) | Your consent (Art. 6(1)(a)) |
| Product analytics & session replay (Amplitude) | Your consent (Art. 6(1)(a)) |
| Send you study-tips / newsletter emails (only if you opt in) | Your consent (Art. 6(1)(a)) |
You can withdraw any consent at any time (e.g., turn off reminders, unsubscribe) without affecting processing already carried out.
Marketing emails (newsletter)
If you tick the optional box when you create your account (it is never pre-ticked), or switch on “Study tips & news by email” in your settings, we will send you occasional study tips and product news. We rely on your consent (Art. 6(1)(a) GDPR), and we record the fact and time you gave it as proof of consent. You can withdraw your consent at any time, and withdrawing is as easy as giving it: use the unsubscribe link in any email, or the toggle in your account settings. We keep your subscription status until you unsubscribe or delete your account. We do not share your email address with our analytics providers.
4. Cookies
We use a strictly-necessary session cookie to keep you logged in; this is essential to provide the Service and does not require consent. We also use analytics tools that are not strictly necessary and therefore require your prior consent (which we ask for through our cookie-consent banner; you can accept or decline, and change your choice at any time):
- Google Analytics (loaded via Google Tag Manager), to understand how the site is used; it sets analytics cookies.
- Amplitude (product analytics and session replay), to understand how the app is used and improve it. Amplitude stores an identifier in your browser (cookie / local storage), and its session-replay feature records a reconstruction of your interactions with the app (clicks, navigation, and scrolling; text you type into inputs is masked). We use a pseudonymous identifier and do not send Amplitude your name or email address.
Declining does not affect your use of the Service. We do not use advertising cookies.
5. Who we share data with
We do not sell your personal data. We share it only with service providers ("processors") who help us run the Service, under data-processing agreements:
- Our servers & database, your account and progress data is stored in a PostgreSQL database on a virtual private server (VPS) we operate, provided by Namecheap, Inc. (USA). Cloudflare, Inc. (USA) provides DNS, CDN caching, and security (WAF / DDoS protection) in front of the Service, and hosts our public marketing pages (Cloudflare Pages).
- OpenAI (OpenAI, L.L.C., USA), to generate automated feedback on the texts you submit in writing practice. Your submitted text is sent to OpenAI's API to produce the feedback; under OpenAI's API data-usage terms, this content is not used to train their models.
- Google (Google Ireland Ltd. / Google LLC), for (a) website analytics via Google Analytics and Google Tag Manager, and (b) "Sign in with Google", only if you choose it.
- Amplitude, Inc. (USA), our product-analytics and session-replay provider, used to understand how the app is used and improve it. We send Amplitude pseudonymous usage data only, never your name or email address.
- Resend (resend.com, USA), our email-delivery provider, used to send account emails (email verification and sign-in links) and, if you opt in, our newsletter.
- Namecheap, Inc. (USA), email forwarding for our contact address (hello [at] b1goethe.com).
We may also disclose data where required by law.
6. International data transfers
Some of the providers we use are located outside the European Economic Area (EEA) — including Google, Amplitude, and Resend in the USA — and our operating entity is based outside the EEA. Where personal data is transferred outside the EEA, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses or, where applicable, the EU-US Data Privacy Framework. You may contact us for more information about these safeguards.
7. How long we keep your data
We keep your account and progress data for as long as your account is active. When you delete your account, we delete your personal data from our active systems promptly and from backups within our normal backup-rotation cycle. Server logs are kept only for a short period for security and troubleshooting.
8. Your rights
Under the GDPR (and similar laws) you have the right to:
- Access and export your data, use "Export my data" in your account settings.
- Delete your account and data, use "Delete my account" in your account settings.
- Correct inaccurate data, edit your profile, or contact us.
- Object to or restrict certain processing, and withdraw consent at any time.
- Lodge a complaint with your local data-protection authority.
To exercise any right, email hello [at] b1goethe.com. We respond within one month.
9. Children
The Service is intended for users aged 16 and over (the digital-consent age in Germany and several EU countries). We do not knowingly collect data from children under this age. If you believe a child has provided us data, contact us and we will delete it.
10. How we protect your data
We use appropriate security measures, including password hashing (Argon2id), encryption in transit (HTTPS/TLS), access controls, and encryption at rest where applicable. In the event of a personal-data breach that is likely to put your rights at risk, we will notify the relevant authority and, where required, affected users.
11. Changes to this policy
We may update this policy from time to time. We will post the updated version here with a new "Last updated" date and, for material changes, notify you where appropriate.
12. Contact
Questions about your privacy? Email hello [at] b1goethe.com or write to Elif Yılmaz, Abide Bayram Sk 19, Gazimağusa 99450, North Cyprus (TRNC).