Privacy Policy

Effective Date: 2026-08-26 · Version 1.0

This Privacy Policy ("Policy") explains how Oleh Herasymenko ("we", "us", "our") collects, uses and protects your personal information when you use the mobile application Eduvia (the "App").

We wrote this Policy in plain language on purpose. Many of our users read it through a translator, and a privacy policy is only useful if you can understand it.

This Policy complies with the EU General Data Protection Regulation (GDPR).

Data Controller

Oleh Herasymenko
Röntgenstraße 5
88048 Friedrichshafen
Deutschland
Email: thevaltorna@gmail.com
Website: https://geteduvia.com

The short version

1. The words we use

2. What Eduvia is

Eduvia is an app for practicing spoken German with an AI voice tutor. It offers free conversation, 202 role-play scenarios from A1 to C1, live corrections, an analysis after each session in your own language, a long-term tutor memory, a vocabulary trainer with spaced repetition, progress statistics, short reading texts, and translation of any tutor phrase. The interface and content are available in ten languages.

Eduvia is an independent practice tool. It contains no exam simulations and is not connected to any examination provider. Details are in the Terms of Use.

3. What data we collect

3.1 Account, profile and settings

3.2 Tutor Memory: what the tutor remembers about you

After each free-conversation session, the AI automatically extracts stable personal facts from what you said and saves them. This is what lets the tutor ask next time "How did the move go?" or "How is your daughter doing at school?".

Each memory entry contains:

The AI also keeps "open topics": things worth asking about in the next conversation.

These facts are sent back to Google Gemini at the start of each following session, so the conversation can continue where it left off.

Important things to know:

3.3 Practice sessions and learning data

3.4 Technical and service data

3.5 Sensitive information in free conversation (Art. 9 GDPR)

We do not ask you for sensitive data, and the App has no fields for it. But Eduvia is free conversation: you decide what to talk about. If you tell the tutor about your health, your origin, your religion, your residence status or other sensitive matters, that information becomes part of the text Transcript and may become part of Tutor Memory.

We process such information only to hold the conversation and teach you the language. Never for profiling. Never for advertising. Never to pass on to anyone.

The legal basis is your explicit consent under Art. 9(2)(a) GDPR, which you give by choosing to share this information in the conversation.

You can get a copy of all your data at any time, and you can delete your account, which erases all conversations with it. A single conversation cannot be deleted separately: transcripts are stored for as long as your account exists. If you want to remove something you said, the available option is deleting your account, which erases all conversations together with it.

Practical advice: do not say things you do not want stored.

3.6 Server logs and IP addresses

Our servers keep technical logs so we can find errors and protect the service. Besides the time of a request, the type of operation, error codes, your user ID, session identifiers and technical usage figures, the logs may contain short excerpts of your conversation with the tutor. We do not use logs to study you or build a profile of you: they exist only for diagnostics. Logs are deleted automatically within 7 days, including after account deletion.

The logs of our load balancer contain IP addresses. Legal basis: our legitimate interest in security and diagnostics (Art. 6(1)(f) GDPR).

3.7 Processing on your device

3.8 Children

Eduvia is intended for users aged 16 and older. We do not knowingly collect data from children under 16. If we learn that we have, we will delete it promptly.

4. What we send to Google Gemini

The AI Tutor is powered by Google's Gemini models. For each Practice Session, the request to Gemini contains:

Outside of a live session, we also use Gemini for:

What we do NOT send to Gemini: your email address, your Firebase user ID, device identifiers, payment information, or subscription data.

Where this processing happens

Your account data is stored in Google Cloud Firestore in the Frankfurt region (Germany, EU). Our API and voice synthesis run on Hetzner servers in Germany. For understanding speech and generating the tutor's replies we use Google's Gemini model via Vertex AI: this model is not yet available in any EU region, so these requests (the live conversation as well as the analysis and the other calls listed above) may be processed on Google's infrastructure outside the EU. This processing is covered by the Google Cloud Data Processing Addendum, the EU Standard Contractual Clauses (SCCs), and Google's certification under the EU-US Data Privacy Framework. Google does not use your data to train its models and does not keep it after processing. As soon as the model becomes available in a European region, we will switch the processing to the EU.

What happens to your voice

Your audio travels to Gemini as part of the request and disappears after processing. It is never written to files, never stored in the database, and not kept by Google after the reply is generated. Only the text Transcript is saved.

We do not create voiceprints, and we do not use your voice to identify you. Your voice is processed only to understand what you said.

5. Who else receives data

We use the following providers to run the App.

Provider Role What it receives Location and safeguards
Google: Firebase Authentication Sign-in User ID, email, sign-in method and time Global (US) infrastructure; Google Cloud DPA, SCCs, EU-US Data Privacy Framework
Google: Cloud Firestore Main database All account and learning data Frankfurt (europe-west3), EU
Google: Vertex AI (Gemini) Speech understanding, tutor replies, session analysis Audio of your utterances plus the context listed in Section 4 Global endpoint: processing may occur outside the EU; DPA, SCCs, DPF; no model training
Google: Firebase Analytics Product analytics App events, only if you consent (Section 7) DPA, SCCs, DPF
Google: Firebase Crashlytics Crash reports Crash and non-fatal error reports: stack traces, device model, OS and App version, breadcrumb events and technical context keys (Section 7); plus basic service data at each App launch (a Firebase installation identifier and session events) DPA, SCCs, DPF
Hetzner Online GmbH Hosting of our API and voice synthesis Traffic in transit, plus the technical logs of Section 3.6 (IP addresses and possibly short conversation excerpts), kept 7 days; no database of your data Germany, EU; data processing agreement (AV-Vertrag)
RevenueCat, Inc. Subscription management The internal customer ID we create (rcAppUserId), the purchase and renewal history reported by Apple, and standard technical data its SDK sends with each request (device model and vendor identifier (IDFV), storefront country, app version, IP address) USA; SCCs
Apple Inc. App Store and In-App Purchase Payment data (we never see it) Under Apple's own terms

We do not sell your personal data. We never share your data with examination organizations, language schools, or government authorities.

6. Notifications: local, not push

All reminders (the daily reminder, streaks, weekly progress, words due for review) are scheduled on your phone by the App, using the iOS notification system. There is no push infrastructure behind them: no device token is sent to our servers, and no notification arrives from outside. Reminders work even offline. You control the iOS notification permission at any time in iOS Settings.

7. Analytics and crash reports

These are two different things with two different rules.

Firebase Analytics: off until you say yes

Firebase Crashlytics: on by default, and you can turn it off

8. Legal bases at a glance

How to withdraw or object: analytics with the switch in your Profile; crash reports under Profile → Privacy; notifications and the microphone in iOS Settings (without the microphone, voice features stop working and everything else keeps working); sensitive topics by not raising them, or by deleting your account.

9. Where your data lives and for how long

Your account data is stored in Google Cloud Firestore in Frankfurt, Germany (EU). Our own servers hold no database of your data. The only personal data resting on them is the technical logs described in Section 3.6, which delete themselves within 7 days.

Data How long
Account, profile, Transcripts, Tutor Memory, vocabulary, progress While your account exists; deleted immediately when you delete the account
Database backups (point-in-time recovery and daily snapshots) Up to 7 days; we do not restore deleted accounts from backups
Server logs (IP addresses, technical events, possibly short conversation excerpts) 7 days, including after account deletion
Technical deletion marker after account deletion 48 hours
AI usage records (internal cost control) While your account exists; deleted with the account
Subscription records While your account exists; your RevenueCat record is deleted when you delete the account
Analytics data (only if you consented) 2 months at Google
Crash reports 90 days at Google

10. Deleting your account and taking your data with you

Deleting your account

You can delete your account directly in the App: open your Profile and scroll to the Danger Zone section at the bottom.

What happens, in this order:

  1. Your sign-in record is deleted first. Access to the account stops immediately.
  2. All your data is deleted from the database.
  3. We ask RevenueCat to delete your customer record there.

If a step fails, the App shows an error and asks you to try again. Partial deletion is never shown as success. Your data with us is deleted first in any case: even if RevenueCat is temporarily unreachable, your data on our side is already gone when you see the error.

Honest details you should know:

After deletion you can create a new account, and an active subscription can be restored with Restore Purchases. Deleted learning data cannot be recovered.

Exporting your data

You can download everything we store about you directly in the App, from your Profile. The export is a JSON file: a structured copy of your stored data, plus your sign-in record (email, name, avatar, sign-in providers, and the dates your account was created and last signed in).

The export does not include, and the App tells you this when you export:

11. Your rights

We reply within one month. Contact: thevaltorna@gmail.com.

12. Automated processing and AI transparency

You are talking to an artificial intelligence system (transparency under Article 50 of the EU AI Act). Thorsten is software, not a human, and the App presents it as such.

The App uses AI to recognize your speech, correct you, analyze sessions and estimate your CEFR level. These estimates are approximate study aids. No decision with legal or similarly significant effects is made about you by automated means (Art. 22 GDPR): your estimates are never sent to any examination body, have no effect on any official result, and you can ignore or repeat them at any time.

13. Security

14. Data breaches

If a personal data breach is likely to put your rights and freedoms at risk, we will notify the supervisory authority within 72 hours of becoming aware of it. If the risk to you is high, we will also inform you directly and without undue delay: by email to your account address or with a clear notice in the App.

15. Language versions

This Policy is available in English and German. For consumers residing in Germany, the German version prevails; otherwise the English version prevails. The App interface exists in ten languages for convenience; the binding versions of this Policy are the English and the German one.

16. Changes to this Policy

We may update this Policy. For material changes, for example a new category of data or a new legal basis, we will tell you in the App in advance, so you can review the changes before they take effect; if you do not agree, you can export your data and delete your account. For minor changes, such as clarifications and editorial fixes, we publish the updated version with a new Effective Date.

17. Contact

Oleh Herasymenko
Röntgenstraße 5
88048 Friedrichshafen
Deutschland
Email: thevaltorna@gmail.com
Website: https://geteduvia.com

18. Changelog

Version 1.0 (2026-08-26): Initial release.

© 2026 Oleh Herasymenko. All rights reserved.