Privacy Policy
Last updated: 2026-09-17 · This privacy policy describes the processing currently implemented in the installed app.
At a glance
- We process account data, learning material and progress when you use the corresponding learning feature.
- AI features send requested content to an AI provider through our backend. A local guest example in Flutter v2 requires no upload for this purpose.
- During the current test phase, usage analytics runs from launch; the app has no switch for it in this phase. You can object at any time via the analytics settings on studyventure.app (which applies to your account in the app as well) or via the support page; your learning features remain available.
- You can delete your account in your profile. Without the app, you can reach us through Delete account or Support.
1. Controller
Benneth Müller, Borgfelder Straße 16, 20537 Hamburg, Deutschland. Contact: ben@creaiter.com.
2. Providing the application
The installed app's interface is loaded from the device as a local app bundle. When downloading or updating the app, the privacy terms of the respective app store also apply.
When you select Privacy Policy or Legal notice in the app, the app opens the corresponding public page in your browser at studyventure.app. When the page is retrieved, website host Netlify processes technically necessary connection and device information, such as IP address, time, requested URL, browser and operating system details, for delivery, stability and abuse prevention. This website visit is covered by the Privacy policy for the web interface. The version bundled with the app is available as a labelled offline fallback; reading it does not retrieve a web page.
Guest learning material and guest answers remain on the device in Flutter v2. However, the public feature configuration is retrieved from the StudyVenture backend API hosted on Render even before sign-in. Signed-in account, study set, import, AI, match and deletion features also use this API. The connection data required for the request and the content explicitly submitted in each case are processed through Render's infrastructure. Details: Render privacy information. Further provider information is at the end of this section.
The technically necessary provision of requested features is based on Article 6(1)(b) GDPR. For stability, error handling and abuse prevention, we process necessary technical data on the basis of our legitimate interest in a secure, functioning service (Article 6(1)(f) GDPR).
Further provider information and unresolved details
We name the services involved alongside each feature. Some details of the provider accounts actually used have not yet been conclusively verified: the respective contracting entity, data processing agreements, subprocessors, processing regions, specific logging and retention periods, and safeguards used for possible transfers to third countries. We therefore cannot guarantee processing exclusively in Europe, a particular provider-side deletion period or a general exclusion of logging and model training. The linked provider information explains general terms; it does not replace confirmation of our specific account configuration. You can send questions about this to ben@creaiter.com.
3. Learning account, sign-in and contact
For registration, sign-in and session management, the app sends your email address and the credentials needed for your chosen sign-in method to Supabase Auth, such as a password or confirmation code. The interface does not store the password in plain text. Supabase keeps the session in protected device storage and refreshes the access token; the StudyVenture server receives the token to associate protected learning actions with the account. The legal basis is Article 6(1)(b) GDPR for providing the learning account.
Provider: Supabase, Inc./Supabase Pte. Ltd. Details: Supabase privacy information. Further information on providers and transfers is in section 2.
Flutter v2 offers email sign-in using a password or a requested sign-in link or email code. Sign-in with Google or Apple is currently paused; the corresponding provider buttons are not offered. Technical preparation alone does not initiate sign-in with Google or Apple.
3.2 Account messages and support
Supabase generates requested messages for account confirmation, sign-in, password resets and account security. Hostinger sends these messages. This involves processing the recipient address, message content including necessary confirmation or sign-in links, and delivery information. Such links may contain short-lived sign-in credentials; do not share them. The legal basis for requested account messages is Article 6(1)(b) GDPR.
When you contact us by email, we process your address, message text, any attachments you choose to include, and the metadata required to deliver and answer the message. The support mailbox is also hosted by Hostinger. We handle contractual matters under Article 6(1)(b) GDPR and general enquiries under Article 6(1)(f) GDPR based on our legitimate interest in responding and communicating securely. We use the information to handle your enquiry. Further information: Privacy at Hostinger.
4. Learning material, AI processing and progress
Signed-in users can send entered text, selected documents and images, and supported video URLs to the StudyVenture backend API to generate flashcards. An image can be selected from the photo library, taken with the camera or selected as a file. The app reads the selected source and only transmits it after the user triggers the creation action; the guest route does not provide this upload path.
When importing from Quizlet or Anki, the app first sends the pasted export or selected import file to the backend for a preview. Only the subsequent confirmation creates the selected study sets in the account. The import preview and confirmed result are associated with the signed-in learning account.
The Flutter v2 app contacts only the StudyVenture backend API for card generation and does not contact any AI provider directly. Depending on its actual server configuration, the backend may use OpenAI, Google Gemini or Anthropic; the provider selected in production is not hard-coded in the app. Further provider information and currently unresolved details are in section 2. Before the first AI import the app obtains permission for this feature; it can be revoked at any time under Profile → Legal.
When trying the app without an account, the bundled sample set and answers remain in the local guest database on the device. This learning route sends neither guest learning material nor answers to an AI provider and creates no server-side Quickstart preview. However, the app may retrieve the public feature configuration from the backend even before sign-in; this involves technically necessary connection data.
Flutter v2 currently has no character studio. This client therefore does not transmit images or role options for this feature.
With the AI tutor, only a question that has been explicitly submitted is sent to the StudyVenture backend API. A prepared draft may contain the current game question and the user's answer; opening the tutor does not submit this draft. The request also includes the selected study set's identifier, language, tutor role and learning action, and at most six entries from the previous conversation. The backend adds at most six cards from this study set, selected on the server for their relevance to the question, and sends the context to the AI provider configured on the server. In addition to questions and answers, card excerpts may include existing answer options, explanations, hints, examples and keywords. Before the first question to the AI tutor the app obtains permission for this feature; it can be revoked at any time under Profile → Legal.
StudyVenture does not persist the tutor chat in its database. The Flutter v2 interface keeps the history in the memory of the current game screen; it is discarded when that screen is left or the app restarts. Closing and reopening the tutor window within the same game screen may preserve the history. The displayed study set and card references identify the study set used and do not constitute an independent check of the AI answer against an original document. Section 2 applies to possible logs at the AI provider and unresolved provider details.
Users under 16 should only enable the AI features with the agreement of a parent or guardian. The AI permission dialog shows a corresponding notice; nothing is blocked. The sole basis for this is the age band stored during setup (under 14, 14–17, 18–24, 25 and older) — no date of birth is collected. The age band determines the wording of the interface (shorter texts during setup below 14), the example sets suggested, the length of the daily learning path and whether this notice appears.
Video sources and quality checks
For a supported video source, the backend sends the normalized video URL to Supadata (Dumpling Software UG) to retrieve a transcript. The transcript is then passed to the configured AI provider for the requested card creation. The source reference and processing job are stored in association with the account. Further information: Privacy at Supadata.
The backend supports OpenAI, Google Gemini and Anthropic; server configuration determines which services process a particular generation request. A quality check may send the original material or medium and proposed cards to the same AI provider again. It serves to check the requested cards; no additional permanent review log of this AI assessment is created. The exact provider assignment currently used in production has not yet been conclusively verified. Information on processing through the APIs: OpenAI: API data controls, Google: Gemini API terms and Anthropic: commercial terms. This information must be distinguished from the terms for personal chat accounts. The contractual version and account settings applicable to the specific service still require separate verification.
For AI card and tutor requests from signed-in users, we store the account ID, UTC date and number of reserved AI provider attempts in Supabase. Failed attempts also count. These technical counters limit daily AI usage, prevent abuse and control costs; they are separate from optional usage analytics. There is one counter row per account. When another attempt is reserved on a new UTC day, the date and count in that row are replaced. Otherwise, the row is retained until account deletion and is deleted with the account. A separate global daily counter row contains no account ID; deleting an individual account does not reset that counter.
Stored study sets, cards and confirmed learning actions are associated with your account so you can learn, resume and view your progress. Depending on the feature, this includes answers, correctness, learning timestamps and game or learning progress. The purpose is to provide the requested learning service (Article 6(1)(b) GDPR); separate optional usage analytics is explained in the analytics section.
Purchasing is currently disabled; the regular product route offers no purchase completion. Technically prepared purchase or plan interfaces alone do not trigger a payment. If you already hold entitlements from earlier use, they may remain associated with your account. The description of payment processing must be supplemented before purchasing is enabled.
5. Live matches
In live multiplayer, the StudyVenture backend processes participant associations through learning accounts, display names, the study set used, match and invitation codes, game configuration, connection and match status, and timestamps. During the game, questions, answers, HP and rankings are synchronized between participating clients and the match server. After the match, the score, number of correct answers and, for each round, card reference, submitted answer, correctness and response latency are stored in Supabase. This data supports running the requested game, reconnection, server-side evaluation and displaying results; the legal basis is Article 6(1)(b) GDPR.
Flutter v2 has no interface for asynchronous challenges. This client therefore does not create, open or transmit challenge links or challenge attempt logs.
6. Storage in the app
The Flutter v2 app uses the following storage only for the purposes stated:
flutter_secure_storageand thus iOS Keychain or Android Keystore for the Supabase session, including access and refresh tokens, and for the short-lived PKCE proof used during sign-in.- App-owned SQLite databases and settings files for the bundled guest set, local guest progress, account-specific library and learning states, language, appearance, music and the last known remote configuration. An onboarding draft prepared before sign-in may be stored locally. Before transfer to an account, this draft is assigned to the existing identifier of the target account. Other accounts do not take it over; a failed local deletion is not treated as successful cleanup.
- Separate files for each account store that you turned analytics off, or explicitly turned it on again. Without a decision of your own, nothing is stored there.
- An account-specific, non-secret UUID allows an already prepared deletion request to continue with the same request ID. Flutter v2 explicitly does not store a recovery secret for this purpose.
- The PixiJS game surface loaded from the app package runs in a local WebView. It receives only the narrowly projected game state from Flutter, with no session or refresh tokens and no direct backend credentials.
These technically necessary storage accesses support sign-in, the requested app feature and secure local resumption. The storage accesses are based on section 25(2), no. 2 TDDDG. Subsequent processing is necessary for performance of a contract under Article 6(1)(b) GDPR; technical security and abuse prevention serve the legitimate interest in a secure service (Article 6(1)(f) GDPR). Usage analytics runs without a prior prompt; section 7 states its legal basis and how to turn it off.
7. Optional usage analytics with PostHog
The app asks nothing at launch. During the current test phase, usage analytics is active from launch; the app has no switch for it in this phase. As long as you have not decided, nothing is stored and nothing is sent to the account — in particular, no consent is recorded. An objection is recorded with the account (version v7); it takes effect in the app on the next sign-in or account refresh and discards pending transmissions. That account record also works the other way round: the app fetches the state stored with your account on every sign-in and follows it. An objection you declared in the web interface therefore also switches analytics off in the app, and a reinstall inherits the account state instead of starting over. While the account cannot be reached, the decision stored on the device applies until the next successful lookup. Without configured analytics, no analytics events are transmitted and no analytics identifier is created. No additional mandatory step is introduced, and turning it off does not affect any learning feature.
Recorded are visible setup steps, next, back and skip actions, save attempts and their results, and navigation and background transitions. Existing account routes also record broad areas, learning attempts, the first visible question, confirmed answers, completion and interruption. Creation and import routes report method, source type, preview, result and broad waiting time. The Pro offer records viewing, explicitly selected plan options, closing and an actually blocked purchase action. Automatic pre-selections derived from an exam date are not transmitted. Without a successful purchase, there is no purchase or revenue event.
Learning progress, creation and return visits: Random, transient session and attempt identifiers connect learning start, the first visible question, the first confirmed answer, completion and interruption. For set creation, we record the method, broad source type, preview, saving step and result, plus waiting time and card count in ranges. An uncertain saving status is distinguished from a confirmed error. Sessions and identifiers change on restart, account or consent changes and after at least 30 minutes in the background. Earlier actions are not added retrospectively. For registered accounts, the account UUID is used to evaluate whether learning resumes on later days. No additional permanent device identifier is created; guests are not included in this account-based return measurement.
The account UUID associates the recorded events with your account. Transient random attempt identifiers and sequential event numbers connect observed flows. Pending transmissions remain bounded in memory and are discarded when analytics is turned off. The same applies to an anonymous guest account: it is recorded until an objection is recorded with the account. The purely local guest route without an account sends no analytics.
Answers, goals, subjects, date and grade values, time budgets, learning content, email addresses, names, domain-specific set/card/game IDs and free-form error text are not transmitted. This channel creates no screen recordings or session replays and does not collect general crash reports. The tutor, memory-image tool and Flame reference game are not measured in this client. Missing completion proves neither a crash nor the cause of a possible interruption.
The legal basis for the running collection is our legitimate interest in product measurement under Article 6(1)(f) GDPR. Prior consent under section 25(1) TDDDG for the device storage access this requires is not obtained. You can object at any time — via the analytics settings on studyventure.app (privacy page; the objection applies to your account in the app as well) or via the support page. The recipient is PostHog, Inc., with Frankfurt in the EU as the intended cloud location. During HTTPS transmission, the recipient technically also processes connection data such as the IP address. Retention, data processing arrangements, subprocessors and possible third-country transfers depend on the operator's configuration; unresolved details are in section 2. Withdrawal ends future collection; already stored events are not automatically deleted. Deletion requests can be sent to the contact address above. Further information: Privacy at PostHog.
For a signed-in account, previously stored local analytics consent is not sufficient on its own: the account's current consent status is also checked before activation. This prevents a previous withdrawal from being overwritten by an old device decision. You give new consent explicitly through the existing analytics setting. If verification fails, analytics remains disabled. Guests can continue to decide about optional local analytics without an account.
8. Retention and deletion
Account, learning material and progress data remain stored for as long as necessary for your learning account and requested features, legal duties or handling a deletion request. Data used to handle support enquiries is retained only for as long as required by the matter and any statutory retention duties.
Flutter v2 offers two-step self-service account deletion in the profile. Before final confirmation, the app displays the deletion preview reported by the server, requires the word “LÖSCHEN” or “LOESCHEN” and starts deletion only after a second action explicitly described as irreversible. Local cleanup of account databases begins only after confirmed server completion. This does not guarantee deletion of every separate settings file or any previously created device backup.
The app remembers only the non-secret request ID of a prepared deletion request and stores no local recovery secret. If the app is terminated during final confirmation and only sign-in appears afterwards, there is therefore no dedicated recovery screen. In this case, and for a deletion request without the installed app, use the public route at Delete account.
The local guest learning route creates neither a server-side preview nor an online learning account. Its local data can be removed by deleting the app data. The necessary configuration request is separate from this.
9. Data subject rights
Under the GDPR, you have in particular the following rights, subject to its conditions:
- Access (Article 15), rectification (Article 16) and erasure (Article 17),
- Restriction of processing (Article 18),
- Data portability (Article 20),
- Objection to processing under Article 21,
- Withdrawal of consent with effect for the future (Article 7(3)),
- Complaint to a data protection supervisory authority (Article 77).
Your right to object
Where processing is based on legitimate interests (Article 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation. We stop this processing unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or grounds for pursuing or defending legal claims. If processing for direct marketing takes place, your objection ends that use without such a balancing of interests.
How we handle your request
We respond to your request without delay, at the latest within one month of receipt. Where an extension is necessary because of scope or complexity, we inform you within that month and give reasons; an extension of at most two further months is possible. Requests are generally handled free of charge. Where we have reasonable doubts about identity, we request only the additional information necessary for confirmation. We answer electronic requests electronically where possible. If we refuse a request, we explain why and inform you about complaint procedures and judicial remedies.
To exercise your rights, simply send a message to ben@creaiter.com.
Flutter v2 currently has no automated self-service data export feature. Requests for access or data portability can be submitted through the public support page.
10. Required information and automated decisions
Account and learning material data are required only when the relevant feature is used. Analytics is entirely optional. No decision based solely on automated processing with legal or similarly significant effects within the meaning of Article 22 GDPR takes place.