Deutsch

Privacy Policy

Last updated: 31 July 2026

This policy covers the Carpincho website (carpincho.app) and the Carpincho app for iOS.

1. Controller

Steffen Giebler — 52N34S Group
Schwedter Str. 25, 10119 Berlin, Germany
Email: privacy@52n34s.com

We are not required to appoint a Data Protection Officer under Art. 37 GDPR.

2. In short

Carpincho works without an account. Vocabulary, audio and the review algorithm are bundled with the app and run on your device. Without an account, your learning data never leaves your phone.

There is no Google Analytics, no PostHog, no advertising SDK, no advertising identifier, no tracking across apps or websites, and no sale of data. The website uses no analytics software and sets no tracking cookies, so it has no consent banner — there is nothing to consent to. The app can collect optional, pseudonymous usage statistics; you can turn that off in Settings.

Data leaves your device in four situations: a voice recording when you use a pronunciation exercise, your learning progress if you create an account, a support message or card report if you send one, and a crash report if the app crashes.

3. The app

3.1 Data that stays on your device

Card states and review schedules, module progress, your variant setting (Rioplatense, neutral Latin American, Spain), interface language and other settings are stored in the app's local storage. Without an account they are not transmitted anywhere, and they are removed when you delete the app.

3.2 Optional account

You can create an account to sync progress between devices and to get a higher daily quota for pronunciation exercises. We store, using Supabase (EU region):

Supabase also sends the transactional emails for sign-up confirmation and password reset on our behalf.

Legal basis: Art. 6(1)(b) GDPR — performance of a contract you requested.

Deletion: You can delete your account in the app under Profile → Delete account. This deletes your login and all associated progress records immediately and irreversibly. You can also write to privacy@52n34s.com.

3.3 Installation ID

On first launch the app generates a random installation ID and stores it locally. It is sent with pronunciation assessments (to enforce the free quota), support messages and card reports (so we can recognise repeat submissions from the same installation).

This identifier is generated by us. It contains no device, hardware or advertising identifier and is not used for advertising. When usage statistics are enabled, events are tied to this ID rather than to a person. It is gone when you delete the app.

Legal basis: Art. 6(1)(f) GDPR — preventing abuse, controlling the cost of a paid third-party service, and handling support requests.

3.4 Pronunciation assessment and microphone access

The app uses the microphone only while you are actively recording in a speaking exercise. It does not listen at any other time.

What happens to a recording:

  1. It is recorded locally (WAV, 16 kHz mono).
  2. It is sent over an encrypted connection to our server function, which forwards it to Microsoft Azure Speech Services in the Germany West Central region, together with the sentence you were asked to say.
  3. Azure returns an assessment. The app shows a band — understood / borderline / would not come across — and marks your weakest words. Numeric scores are never shown.
  4. The recording is discarded. It exists only in the working memory of our server function for the few seconds the assessment takes. It is not written to disk, not stored in our database, and not retained by us in any form. Microsoft acts as our processor; under the Azure Speech terms, audio submitted to the service is not retained after processing and is not used to train Microsoft models.

The assessment result is not stored on our servers either. It is returned to your device and displayed there.

The only thing we record is a usage entry so quotas can be enforced: account ID or installation ID, the length of the recording in seconds, and the language variant. No audio, no text, no result.

Microphone access is requested the first time you open a speaking exercise. You can decline or revoke it in iOS settings at any time; every other part of the app continues to work.

Legal basis: Art. 6(1)(b) GDPR for the assessment itself, Art. 6(1)(f) for the quota entry.

3.5 Support messages and card reports

If you send a support message, we store the message text, any contact address you provide, your installation ID, technical metadata (app and OS version) and, if you are signed in, your account ID.

If you report an incorrect entry using the report button on a card, we store the entry concerned, your note, your installation ID and, if you are signed in, your account ID.

If you are offline, the message stays queued on your device until a connection is available.

Legal basis: Art. 6(1)(b) and (f) GDPR — answering your enquiry and correcting content errors.

3.6 Error tracking

We use Sentry (EU region, ingest.de.sentry.io) to find crashes and errors in the app. Sentry is not used on the website.

The configuration is deliberately restrictive: sendDefaultPii is off, any user object is removed from every event before it is sent, breadcrumbs from text input fields and from the developer console are discarded, and screenshots and view hierarchies are not attached. A report contains the error and stack trace, app version, device model, iOS version, and technical tags identifying the screen, module and language variant in use. When a card report fails to send, the report additionally carries the entry ID and the error code — not your note.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in a stable app.

3.7 App updates

The app is configured for over-the-air updates through Expo Application Services (u.expo.dev). On launch the app may check whether a newer version of the app code is available. This request carries technical information such as app and runtime version and platform. It carries no account data and no learning data.

Legal basis: Art. 6(1)(f) GDPR — delivering fixes and improvements.

3.8 Purchases

Carpincho currently has no paid features. If paid features are introduced, purchases will be processed by Apple through the App Store. We will not receive your payment details. This section will be updated before any such feature goes live.

3.9 Usage statistics

The app collects pseudonymous usage statistics: which exercise was opened, how long a session lasted, how many cards were reviewed, and which intelligibility band a pronunciation assessment fell into. Content is not collected: no voice recordings, no typed answers, no dictation text. The data is tied to a random installation ID, not to a person, and is stored in the EU. You can turn collection off in Settings.

Legal basis: Art. 6(1)(f) GDPR — understanding how the product is used so we can improve it.

3.10 What the app does not do

4. The website (carpincho.app)

4.1 Waitlist

When you join the waitlist we store your email address, your language preference and, if you provide one, your reason for learning Spanish. The data is stored with Supabase in the EU region. We use it only to tell you when Carpincho is available and to send occasional previews of the word list. Confirmation follows a double opt-in: we send one email via Resend to verify the address.

Legal basis: Art. 6(1)(a) GDPR — consent. You can withdraw consent at any time with effect for the future, via the unsubscribe link in any email or at privacy@52n34s.com.

4.2 Hosting

The site is hosted by Vercel. Standard server logs (IP address, timestamp, requested URL, browser type) are processed as part of hosting operations, for security, troubleshooting and abuse prevention.

Legal basis: Art. 6(1)(f) GDPR.

4.3 Fonts

Web fonts are downloaded when the site is built and served from our own domain. Your browser makes no request to Google or any other font provider, and no IP address is transmitted to a font provider.

4.4 Analytics and cookies

The website uses no analytics and no error tracking. It sets no cookies for advertising, analytics or cross-site tracking, and stores nothing on your device beyond what is technically required to operate the site. There is therefore no consent banner: § 25 TDDDG is not triggered.

4.5 Admin area

The internal admin dashboard uses Supabase Auth and is accessible only to the site operator. It processes no visitor data beyond what is described above.

5. Legal bases at a glance

ProcessingLegal basis
Account, sync, learning progressArt. 6(1)(b) — contract
Pronunciation assessmentArt. 6(1)(b) — contract
Quota entry, installation IDArt. 6(1)(f) — abuse prevention, cost control
Support messages and card reportsArt. 6(1)(b), (f)
Error tracking in the appArt. 6(1)(f) — stability
App updatesArt. 6(1)(f) — delivering fixes
Waitlist and confirmation emailArt. 6(1)(a) — consent
Server logsArt. 6(1)(f) — security and operation

6. Processors and recipients

ServicePurposeProcessing location
Supabase (Supabase Inc., US)Database, authentication, server functions, transactional emailEU region; DPA in place
Microsoft Azure Speech Services (Microsoft Ireland Operations Ltd. / Microsoft Corp., US)Pronunciation assessmentGermany West Central; Microsoft Products and Services DPA
Sentry (Functional Software Inc., US)Error tracking, app onlyEU region (ingest.de.sentry.io)
Expo (Expo Inc. / 650 Industries, US)Over-the-air app updatesUS
Resend (Resend Inc., US)Waitlist confirmation emailUS
Vercel (Vercel Inc., US)Website hostingUS / EU edge
Apple (Apple Distribution International Ltd. / Apple Inc., US)App distributionApple's own privacy policy applies

7. International data transfers

Some providers are based outside the EEA or have a US parent company. Where personal data is transferred to the United States, we rely on the EU-U.S. Data Privacy Frameworkwhere the recipient is certified under it, and otherwise on the European Commission's Standard Contractual Clauses. You can request a copy of the relevant safeguards at privacy@52n34s.com. We apply the same standard to users everywhere, not only in the EU.

8. Retention

DataRetention
Local learning data on the deviceUntil you delete the app
Account and progressUntil you delete your account
Voice recordingsNot retained — discarded after assessment
Assessment resultsNot stored on our servers
Quota entries90 days
Support messages and card reports12 months after the matter is closed
Waitlist entryUntil launch communication is complete or you unsubscribe
App error reports (Sentry)90 days
Server logs (Vercel)Approximately 30 days

9. Your rights

Under the GDPR you have the right to:

To exercise any of these, write to privacy@52n34s.com. Account deletion is also available directly in the app.

Competent supervisory authority for us:
Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
Alt-Moabit 59–61, 10555 Berlin

10. Children

Carpincho is not directed at children under 16, and we do not knowingly collect data from children under 16. If you believe a child has provided us with data, write to privacy@52n34s.com and we will delete it promptly.

11. Changes to this policy

We update this policy when the app or the services behind it change. The current version is always available at carpincho.app/privacy. If a change materially affects how we handle your data, we will point it out in the app or by email before it takes effect.