Privacy policy
These pages are governed by German law. This English version is a reading aid only; in case of doubt or dispute, the German text is the one that applies.
This policy sets out what data is processed when you visit and use BitDojo, what for, on what legal basis, for how long and who else sees it. It is deliberately written in plain language. Where a technical term is unavoidable, the explanation sits next to it.
Controller
Domenic Moran, Heidelberger Straße 36, 12059 Berlin, Deutschland. Email: bitdojo.de@gmail.com
No data protection officer has been appointed. The conditions of section 38 BDSG are not met.
The principle: as little as possible
The basics course can be read in full without an account. Doing so creates no personal data beyond the server logs. In that case your progress is stored only in your browser and never reaches a server.
When you simply visit the pages
The hosting provider logs technically necessary details: shortened IP address, timestamp, the address requested, the amount of data transferred and the browser identifier. This is required to deliver the site and to fend off attacks.
Legal basis: Article 6(1)(f) GDPR, legitimate interest in secure operation. Retention: 30 days at most.
No content is loaded from third-party servers. Fonts, images and scripts sit on the same server as the site; there is no connection to Google Fonts and no advertising or analytics network.
Cookies and similar storage
No cookies are set for advertising or analytics, which is why there is no consent banner. The only things set are:
- Session cookies after you sign in. Without them you could not stay signed in. They are strictly necessary under section 25(2)(2) TDDDG and therefore require no consent.
- Local storage in the browser for progress, card scheduling, your position in a podcast episode and settings. This data never leaves your device. It is not transferred to a server even when you are signed in.
Account and subscription
For an account, your email address and a timestamp of sign-up are processed. Signing in through the browser uses a one-time link; no password is needed for it.
If you set a password for the mobile apps in your account, that password is not stored in clear text, only a value derived from it (a salted hash). The password cannot be recovered from it. The field stays empty until somebody sets one, and a password once set can be replaced at any time.
When you take out a subscription, the payment reference and the period paid for are added.
Legal basis: Article 6(1)(b) GDPR, performance of the contract. Retention: until the account is deleted, and after that only as far as commercial and tax retention periods require it (invoice data for ten years under section 147 AO).
Progress, exams and certificates
Only the data that has to be on the server is on the server: for each exam attempt the timestamp, the questions drawn, your answers and the result, plus the certificates issued. Which lessons you have ticked off and how your cards stand remains in your browser's storage, account or no account. There is no sync between devices.
Legal basis for exams and certificates: Article 6(1)(b) GDPR, performance of the contract. Without this data an exam could not be marked and a certificate could not be verified later.
Exam history is kept longer than the rest of your progress, because otherwise a certificate could not be checked. If you delete your account you can ask for issued certificates to be declared invalid; until then, who each certificate was issued to stays stored, because that is precisely what it states.
Recipients
No data is sold and none is passed on for advertising. The following processors are used, each under a data processing agreement:
| Service | Purpose | Location | Basis |
|---|---|---|---|
| Vercel Inc. | Delivery of the website and server logs | USA, processing in the EU (Frankfurt) | Standard contractual clauses |
| Supabase Inc. | Accounts and sign-in links, exam attempts, certificates and the non-public storage for audio and handbooks | EU (Frankfurt) | Data processing agreement |
| Stripe Payments Europe, Ltd. | Handling of payments and recurring charges | Ireland | Performance of the contract, Article 6(1)(b) GDPR |
| Anthropic PBC | Reader's view in the CV check: evaluation of the submitted CV by a language model, only after consent | USA | Consent, Article 6(1)(a) GDPR, with standard contractual clauses |
| Apple Inc. / Google Ireland Ltd. | Distribution of the mobile apps through the respective stores | USA / Ireland | Standard contractual clauses |
Audio and handbooks
Podcast episodes and handbooks sit in non-public storage at Supabase. When you play an episode or open a handbook you get an address that is valid only for that retrieval and expires shortly afterwards. The storage service learns the file identifier and the technical details of the request, but not who you are: your entitlement is checked on this server beforehand.
Legal basis: Article 6(1)(b) GDPR for the paid part, Article 6(1)(f) for the free episodes, being the legitimate interest in preventing a paid file from leaking through a guessed address.
Payments
Payments are handled by Stripe. Card numbers and bank details are entered there and never reach this server. What is stored here is only the customer reference at Stripe, the status of the subscription and the period paid for.
Artificial intelligence
The podcast audio is machine narrated. For that, the scripts are transmitted once to a speech service; they contain no personal data of users. The English version of this interface was written and reviewed editorially; no user data was transmitted in the process. The only feature that sends anything you type to a language model is the CV check; the next section says what happens there. The notice required by Article 50 of Regulation (EU) 2024/1689 appears in the footer of every page and above the result of the CV check.
CV check
The CV check is optional and only runs when you upload a file or paste text and press the button. It is meant solely for the person whose CV it is.
What is processed: the content of the uploaded file or the pasted text, the file name and, if you paste one, the text of the job advert. A CV regularly contains special details such as a photo, date of birth, marital status or nationality. You can remove them before uploading; the check works just as well without them, and what is not transmitted cannot be processed.
What is stored: none of it. The file is processed in memory, the result goes to your browser, and after that the content is gone. There is no file storage and no table holding your text. The only thing stored is a counter per account and month so that the limit of one or five evaluations applies; it holds no content.
Who sees it: the first part of the evaluation, machine readability, is computed on this site's server and never leaves it. For the second part, the reader's view, the text of the CV and, where applicable, the job advert are transmitted to Anthropic PBC, San Francisco, USA, and processed there by a language model. Anthropic acts as a processor, does not use the content to train models under its commercial terms for the programming interface, and deletes it after a short time.
Legal basis: Article 6(1)(a) GDPR, that is your explicit consent, which you give with a checkbox before sending. The European Commission's standard contractual clauses apply to the transfer to the USA. You can withdraw your consent at any time with effect for the future by not using the feature any more; processing that has already taken place remains lawful. Without consent the first part of the evaluation stays usable.
What the check is not: there is no automated decision within the meaning of Article 22 GDPR. The evaluation is feedback to you about a document and not a decision about a person. Use by employers to select applicants is excluded under the terms of use.
Deleting the account
The account can be deleted at any time by you. In the browser the route is on the account page under Delete account; in the iOS and Android apps it sits in the same place on the account screen. If you can no longer sign in, bitdojo.de/konto/loeschen-anfragen explains the same process and gives the address a plain email can go to.
What is deleted: the account at the authentication service with the email address and any password set, the profile with the paid period and the identifier of the payment account, all exam attempts with answers and results, all certificates issued, the course progress and study days held on the server, the state of the flash cards and the counter of the CV check. Anything held in the browser's storage or on the phone is untouched by this and goes when that storage is cleared or the app is removed.
What remains, and for how long: invoice and payment data live at Stripe. They stay there for ten years, counted from the end of the calendar year in which the invoice arose. The basis is section 147(1) of the German Fiscal Code and section 14b UStG; Article 17(3)(b) GDPR expressly exempts data whose retention is required by a legal obligation from the right to erasure. The customer record at Stripe is therefore not deleted but kept as the carrier of those records. Once the period is up it is removed as well.
Server logs cannot be picked apart individually either. They contain a shortened IP address and are overwritten after 30 days at the latest.
The identifiers of events delivered by Stripe remain, without any link to a person. They prevent a repeated delivery from being booked a second time; the link to the account and the payload delivered with it are removed on deletion.
If a subscription is running at the time of deletion, it is ended immediately in the same step. A deleted account that keeps being charged therefore cannot occur.
Your rights
- Access to the data stored about you (Article 15)
- Rectification of incorrect data (Article 16)
- Erasure (Article 17)
- Restriction of processing (Article 18)
- Portability in a transferable format (Article 20)
- Objection to processing based on legitimate interest (Article 21)
An email to bitdojo.de@gmail.com is enough. You also have the right to complain to a supervisory authority; for Berlin that is the Berlin Commissioner for Data Protection and Freedom of Information.
Changes
This policy is updated when the processing changes. The current version is always at this address. Version of 11 August 2026.
These pages are governed by German law. This English version is a reading aid only; in case of doubt or dispute, the German text is the one that applies.