Privacy Policy — Lapicida Latinus

*As of October 2026*

1. Data Controller

Andreas Blankenstein
Riederhöhe 12a
28279 Bremen
Germany

Email: [email protected]
Website: https://lapicida-latinus.de

2. General

We process personal data only to the extent necessary for the operation of this website, the app, and the services offered. Processing is carried out in accordance with the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG).

3. Hosting

This website is hosted by:

Hostinger International Ltd.

61 Lordou Vironos Street, 6023 Larnaca, Cyprus

When you visit the website, the server automatically stores so-called server log files that your browser transmits. These include: IP address, date and time of the request, URL accessed, browser type and version, operating system, and referrer URL.

This data is technically necessary to deliver the website and is not combined with other data sources.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest: operation and security of the website)

Retention period: 30 days, followed by automatic deletion

A Data Processing Agreement (DPA) has been concluded with Hostinger.

Cloudflare: The website and our app server (api.lapicida-latinus.de) are reached through the network of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Cloudflare protects against attacks, encrypts the connection and delivers content. To do so, all requests — from the website and from the app — pass through Cloudflare, which briefly processes your IP address and the technical details of the request. Cloudflare is our processor (Art. 28 GDPR); Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest: secure and reliable operation)

4. Cookies and Cookie Settings

This website uses cookies. Technically necessary cookies are set without consent. All other cookies (e.g., for analytics or marketing) are only activated after you give your consent via the cookie banner.

You can change or revoke your cookie settings at any time via the “Cookie Settings” link in the footer of this website.

We use Real Cookie Banner to record and document your consents in compliance with the GDPR.

5. Contact Form

When you send us a message via the contact form on this website, the following data is collected and stored in the WordPress database:

– Name
– Email address
– Your message
– Time of submission

We store your message in the database (and not just via email) to ensure reliable processing and traceability.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest: responding to your inquiry); for purchase-related inquiries, Art. 6(1)(b) GDPR

Retention period: Until your inquiry has been fully processed, followed by a maximum of 3 months, unless statutory retention periods apply

6. Registration and User Account

When you create a user account, we process:

– Email address
– Password (stored in encrypted form)
– Name
(if applicable) – Date of registration
– License status and purchase history

Legal basis: Article 6(1)(b) of the GDPR (performance of a contract or pre-contractual measures)

Retention period: For the duration of the contractual relationship; data relevant for tax purposes is retained for 10 years (Section 147 of the German Fiscal Code (AO))

7. Purchase and Payment Processing

7.1 WooCommerce

We use WooCommerce (Automattic Inc., USA) to process purchases. When a purchase is made, the following data is processed: name, address, email address, selected payment method, and order details. This data is necessary for the performance of the contract.

Legal basis: Art. 6(1)(b) GDPR

Retention period: 10 years (tax-related retention requirement pursuant to § 147 AO)

7.2 PayPal

If you select PayPal as your payment method, the necessary data will be transmitted to PayPal to process the payment:

PayPal (Europe) S.à.r.l. et Cie, S.C.A.

22-24 Boulevard Royal, 2449 Luxembourg

PayPal may transfer data to the United States. This is based on standard contractual clauses pursuant to Art. 46(2)(c) of the GDPR.

PayPal Privacy Policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full

Legal basis: Article 6(1)(b) of the GDPR

7.3 Stripe

If you select credit card as your payment method, the necessary payment data will be transmitted to Stripe:

Stripe Payments Europe, Ltd.

1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland

Stripe may transfer data to the United States. This is based on standard contractual clauses pursuant to Art. 46(2)(c) of the GDPR and the EU-U.S. Data Privacy Framework.

Stripe Privacy Policy: https://stripe.com/de/privacy

Legal basis: Article 6(1)(b) of the GDPR

7.4 Cancellation via the Form

If you cancel your subscription using our cancellation form, we process your name, your email address, your licence number, the reason (if you give one) and, as proof, your IP address and your browser identifier. We use this information to carry out the cancellation, confirm receipt to you by email and be able to prove the cancellation.

Legal basis: Art. 6(1)(b) and (c) GDPR (contract; cancellation button under Section 312k BGB)

Retention period: We delete the IP address and browser identifier after 12 months, and the cancellation itself three years after the end of the year in which you cancelled.

8. Newsletter “Letters from the Officina”

What we collect. For the “Letters from the Officina” newsletter we process your email address. In addition, we store the time of your signup, your IP address and your browser identifier, as well as the route by which you signed up.

What for. We use your email address solely to send you the newsletter. The time of signup, IP address and browser identifier are not stored for the purpose of sending, but as evidence that the signup genuinely came from you — we are legally required to keep such a record.

Legal basis. The newsletter is sent on the basis of your consent (Art. 6(1)(a) GDPR). We store the evidence data on the basis of our legitimate interest in being able to demonstrate a legally valid signup (Art. 6(1)(f) GDPR).

How signing up works. After you submit the form, we send you an email containing a confirmation link. You are only added to the list once you click that link. If you sign up via a personal link from an email we had previously sent to that exact address, the additional confirmation step is omitted — clicking the personal link already proves that the address is yours.

Who receives the data. We do not pass your address on to third parties and do not use it for advertising outside this newsletter. Subscriber data is held on our own server. For the technical dispatch and for server operation we use Hostinger International Ltd. as a processor; a data processing agreement is in place.

No performance tracking. We do not measure whether you have opened an email or clicked a link. There are no tracking pixels and no click tracking.

How long. We store your data until you unsubscribe. After you unsubscribe, we retain your address and the record of your consent in order to ensure that you receive no further emails and to be able to demonstrate that consent was given. You may request complete erasure at any time.

Your withdrawal. You may withdraw your consent at any time, without giving reasons. Every email contains an unsubscribe link for this purpose; one click is enough. Alternatively, an informal message to [email protected] will suffice. The lawfulness of the processing carried out up to that point remains unaffected.

9. Google Services

We use various services provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google may transfer data to servers in the United States. This is based on standard contractual clauses pursuant to Art. 46(2)(c) GDPR as well as the EU-U.S. Data Privacy Framework.

9.1 Google Analytics (via Google Site Kit)

With your consent, we use Google Analytics to statistically analyze the use of our website. In doing so, pseudonymous user profiles are created. IP addresses are anonymized before being transmitted to Google (IP anonymization enabled).

Legal basis: Article 6(1)(a) of the GDPR (consent via cookie banner)

You can prevent data collection by Google Analytics by rejecting the corresponding category in the cookie banner or by installing the browser add-on at https://tools.google.com/dlpage/gaoptout.

9.2 Google Tag Manager

Google Tag Manager itself does not store any cookies and does not collect any personal data. It is used solely to manage the integrated tags (e.g., Google Analytics). It only becomes active once you have accepted the relevant cookies.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest: efficient tag management)

9.3 Google Search Console

We use Google Search Console to monitor our website’s search performance. No individual user data is processed in this process; only aggregated, non-personal statistics are analyzed.

Legal basis: Art. 6(1)(f) GDPR

9.4 Google Ads (Conversion Measurement)

We run ads on Google. With your consent, we include the Google Ads tag for this purpose. If you reach the website through one of our ads, Google can use a cookie (e.g. “_gcl_au”, lifetime up to three months) to recognise whether a certain action followed the click, such as a purchase. We only see aggregated figures. We do not use Google Ads to show you ads based on your visits to our site (no remarketing).

Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG (consent via the cookie banner). You can withdraw it at any time via “Cookie settings” in the footer.

10. Spam Protection (Friendly Captcha)

To protect our forms from spam and misuse, we use Friendly Captcha:

Friendly Captcha GmbH

Tal 8, 80331 Munich, Germany

Friendly Captcha does not set cookies, does not create user profiles, and does not perform cross-site tracking. To solve the captcha, technical device data (browser information) is temporarily processed. Personal data is not stored permanently.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest: protection against misuse)

Friendly Captcha Privacy Policy: https://friendlycaptcha.com/legal/privacy-end-users/

11. Lapicida Latinus App

11.1 App Download (App Store and Google Play)

The app is available in Apple’s App Store and on Google Play. During download, installation and purchases in the app, Apple or Google process their own data under their own privacy policies; we have no influence over this. For purchases in the app, see 11.10.

11.2 App Use Without an Account

You need neither a user account nor an email address for the app, and the exercises also work offline. When your device is online, however, the app connects to our server: to fetch messages (11.3), load content and send usage events (11.4). What is transmitted in each case is described in the following sections. Details such as your name or email address are only included if you enter them yourself.

11.3 App Messages (Device Identifier)

To deliver messages to you in the app (e.g. notes about updates or new content), the app creates a random device identifier for the app when it is first started and stores it on your device. It is a random number, not a feature of your device, and contains neither a name nor an email address. Because it stays the same, data carrying it is pseudonymous, not anonymous. When you have read a message, we store this against the identifier so that the message does not appear again. If you use a licence, the identifier is transmitted together with the licence number.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract: provision of app functionality)

Retention period: The identifier on your device disappears when you uninstall the app. We delete the read markers on our server 12 months after reading, or immediately on request.

11.4 Usage and Exercise Data (Telemetry)

The app sends data about how you practise and which features you use — e.g. completed exercises and their results, the first start, the chosen language and whether you use a smartphone, tablet or computer. This data is linked to the app’s random device identifier (11.3) and — if you have one — your licence number, not to your name; it is therefore pseudonymous, not anonymous. We use it to improve the app and find errors, and in a class to show your teacher your exercise results (11.12). We do not sell it and do not combine it with data from other providers. We do not record where you click.

With a licence, you can switch off the transmission at any time in the app settings under “Telemetry” (default: on). The free version has no switch for this; write to us and we will delete the data for your device (contact under 1.).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving the app and fixing errors); in a class, the agreement with your school (11.12).

Retention period: 24 months, then automatic deletion.

11.5 Bug Reports

If something strikes you in the app, you can send us a message. It contains your description, technical details about the situation (app version, platform) and the device identifier described in section 11.3; if you use a licence, its number is transmitted as well, and if you are in a class, its identifier. We do not ask for an email address. The message is also delivered to us by email (sent via our host Hostinger).

Reply: We can answer you inside the app. The reply is delivered to the licence under which the message arrived, and only to the single device if there is no licence. It is visible to you alone. A reply is one-way — you cannot write back to it in the app.

Legal basis: Art. 6(1)(b) GDPR (handling your enquiry)

Retention period: Until resolved, at most 6 months

11.6 Vocabulary Scan (Photo Recognition)

Purpose and scope. The app offers an optional feature that lets you take a photo of a vocabulary list or textbook page. The image is used solely to automatically recognise the vocabulary it contains (Latin word, part of speech and meaning) and add it to your vocabulary list. No further analysis of the image takes place – in particular, no person or facial recognition.

Processing. For text recognition, the photo is transmitted to our service provider Anthropic (Anthropic PBC, USA) and processed there by an AI model (Claude). The photo is not stored permanently; it is only processed for the duration of the recognition and then discarded.

No AI training. The transmitted content is not used by the service providers to train their AI models.

Legal basis. Art. 6(1)(b) GDPR (provision of the feature you actively requested).

Third-country transfer. The transfer to Anthropic (USA) takes place on the basis of the EU Standard Contractual Clauses (see also section 12).

Daily limit without a licence. Without a licence, the number of scans per day is limited. So that we can count them, we do not store your IP address in plain text, only as a hash value that we form with a secret key and the date. It changes daily, so different days cannot be linked with each other. We delete these entries after 7 days.

Voluntary. Use of the vocabulary scan is voluntary. Without using this feature, no photo is transmitted.

11.7 Learning Progress in the Cloud (Sync)

When you activate a license, your learning progress is stored on our server. This is what allows you to continue at the same point on up to three devices and to keep your progress when you change devices.

What is processed: your learning progress (which vocabulary and forms you have practised, the respective level and timestamps), your app settings, vocabulary lists you created yourself, as well as the license number and the app’s random device identifier.

In addition, we keep up to three earlier states as a backup copy so that accidental overwriting can be undone. Drawings you create for vocabulary are backed up as well.

The progress is linked to the license number, not to your name. If you do not activate a license, nothing is synchronised — the app remains fully usable offline (see 11.2).

Storage location: A server operated by us at Hostinger International Ltd., data centre Frankfurt am Main (Germany). The learning progress is stored only there; the encrypted connection to it runs through Cloudflare (see 3).

Legal basis: Art. 6(1)(b) GDPR (performance of a contract — syncing across devices is part of the license)

Retention: For as long as the license exists. After the license expires or is revoked, we delete the learning progress, the backup copies and your drawings automatically after six months. This period gives you time to decide about renewing without losing your progress.

Immediate deletion: You can remove your progress at any time — in the app under Settings → Manage license → “Sign out of this device” (for an expired licence: “Sign Out & Delete Data Now”). The progress is deleted from our server immediately. We delete the backup copies immediately on request (contact under 1.).

11.8 Notifications

The app can send you two kinds of notifications. Both are switched off until you switch them on yourself in the app under Settings → Notifications, and you can switch each of them off again at any time. Your operating system will additionally ask for your permission when you switch them on.

“What you achieved yesterday” (morning recap): This notification is scheduled by the app on your device. It compares your learning progress with the state at the start of the day and lets you know the next morning at around 9 a.m. — only after a day on which you practised. No data is sent to us or to third parties for this; the comparison stays on your device.

“News from Lapicida” (push messages): If you switch on this notification, we receive a delivery token for your device from Apple (iPhone/iPad) or Google (Android). We store on our server: the delivery token, the platform (iOS or Android), the app’s random device identifier, which it also uses to fetch messages (see 11.3), your licence number if you have one, the app version and the time of registration. We use this information solely to deliver messages that we publish in the app (e.g. notes about updates or replies to your enquiry), and only those that the app would also show you when you open it. The number on the app icon shows how many messages you have not read yet. No advertising, no profiling, no analysis.

Delivery on Android: via Firebase Cloud Messaging, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google processes the delivery token, an installation ID of the app and the content of the notification on our behalf (Art. 28 GDPR). This may involve a transfer to Google LLC in the USA; Google LLC is certified under the EU-U.S. Data Privacy Framework (adequacy decision, Art. 45 GDPR), and the EU Standard Contractual Clauses apply in addition. We use only this delivery function of Firebase, no analytics or statistics features.

Delivery on iPhone and iPad: via the Apple Push Notification service. For users in the European Economic Area, the controller is Apple Distribution International Limited, Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. Apple processes the delivery token and the content of the notification; according to Apple, transfers to Apple Inc. in the USA are based on the EU Standard Contractual Clauses (Art. 46 GDPR).

Legal basis: Art. 6(1)(b) GDPR (performance of a contract — providing an app feature that you switch on yourself). Storing and reading the delivery token on your device is strictly necessary for this feature you requested (Section 25(2) No. 2 TDDDG).

Retention: If you switch the notification off, we delete the information about your device from our server and return the delivery token to Apple or Google. If Apple or Google reports a delivery token as invalid (e.g. because the app was deleted), we delete the information about that device as well. According to Google, Google keeps the installation ID until it is deleted; deletion from all of Google’s systems takes up to 180 days.

11.9 Rating in the App

You can rate Lapicida Latinus directly in the app. We send your star rating, your text and — if you provide them — your name and email address to our web shop. There the review is first stored non-publicly and checked by us; once approved, it appears on the product page with the stars, the text and the name you gave. Your email address is not published.

To prevent the same person from submitting several reviews in a short time, we use the app’s random device identifier: one review per device is possible within 90 days.

Legal basis: Art. 6(1)(b) GDPR (publishing the review you submit) and Art. 6(1)(f) GDPR (protection against abuse); reading the device identifier is strictly necessary for this function you trigger (Section 25(2) No. 2 TDDDG).

Retention period: The review stays published until you ask us to delete it (contact under 1.). For the 90-day limit we store the device identifier only in hashed form and delete the record after 24 months.

11.10 Buying a Licence in the App

If you buy a licence in the app, Apple (App Store) or Google (Google Play) handle the payment; we do not receive any payment data from them. So that we can assign the purchase to your licence, we use the service RevenueCat (RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA). RevenueCat receives a buyer identifier, the product purchased and the status of the subscription and — if your licence is linked to an email address — that email address. RevenueCat is our processor (Art. 28 GDPR); the transfer to the USA is based on the EU Standard Contractual Clauses (Art. 46 GDPR).

If you have your licence number sent to you by email, we use the address you give only for that; the email is sent via our host Hostinger.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract)

Retention period: as under 7.1 (retention for tax purposes, 10 years)

11.11 AI Help in the App

With a licence, you can use the “AI translation & explanation” button in the sentence analysis to have a Latin sentence translated and explained or a word looked up. We send the sentence or word you enter to Anthropic (Anthropic PBC, USA), where an AI model (Claude) creates the answer. We do not transmit any licence number, name or device identifier to Anthropic. Please do not enter any personal details in the input field. The content is not used to train AI models. The transfer to the USA is based on the EU Standard Contractual Clauses (see 12).

The simple sentence analysis without a licence runs entirely on our own server, without an AI provider.

Legal basis: Art. 6(1)(b) GDPR (feature you requested)

11.12 Classes (Joining with a Code)

If your teacher gives you a join code, you can use it to join a class in the app. The app then transmits the code, the device identifier (11.3), the type of your device (e.g. “iPhone”), the app version and — if you enter it — the name under which your teacher should see you. As long as you are in the class, your teacher sees this name, your exercise results (11.4), your learning progress and help requests you send them in their overview.

Your school is responsible for the class; we process this data on its behalf (Art. 28 GDPR, data processing agreement). Questions about the class are best addressed to your teacher or school. If you leave the class, the transmission to the teacher ends. We delete your entry in the class (name, device type) six months after you leave, and help requests six months after they were last changed.

Teachers who use the Officina create an account for it (email address, name, password — stored encrypted, optionally a phone number).

Legal basis: Art. 6(1)(b) GDPR; for the class, the agreement with your school

11.13 Third-Party Content in the App

Fonts: Some game views (e.g. Unda, Turbo, Tribunal, Stafette) load fonts from Google Fonts (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Google receives your IP address in the process.

Handwriting recognition: If you use the pen, the app downloads a language model from Google once; the recognition itself runs on your device.

Wiktionary: Only if you allow it in the settings does the app query Wiktionary (Wikimedia Foundation, USA) for your own vocabulary that we do not know; Wikimedia learns your IP address in the process.

Legal basis: Art. 6(1)(f) GDPR (display and functioning of the app); for Wiktionary, your consent via the switch (Art. 6(1)(a) GDPR)

12. Data Transfer to Third Countries

Some of the services we use transfer data to countries outside the EU/EEA (particularly the U.S.). Where this is the case, the transfer is based on appropriate safeguards pursuant to Art. 46 of the GDPR (Standard Contractual Clauses) or on the EU-U.S. Data Privacy Framework. Transfers to the USA are made in particular by: Cloudflare (3), Google (9, 11.8, 11.13), Apple (11.8), Anthropic (11.6, 11.11), RevenueCat (11.10) and — only with your permission — Wikimedia (11.13). For details, please refer to the privacy policies of the respective providers.

13. Retention Period

Personal data will be deleted or blocked as soon as the purpose for which it was stored no longer applies. In addition, data may be retained if statutory retention obligations apply (e.g., tax-related retention periods: 10 years pursuant to Section 147 of the German Fiscal Code (AO)).

14. Your Rights

You have the following rights with respect to your personal data:

– Right of access (Art. 15 GDPR): You may request information about the data we have stored.

– Rectification (Art. 16 GDPR): You may request the correction of inaccurate data.

– Erasure (Art. 17 GDPR): You may request the erasure of your data, provided that no statutory retention obligations prevent this.

– Restriction of processing (Art. 18 GDPR)

– Data portability (Art. 20 GDPR): You may receive your data in a machine-readable format.

– Objection (Art. 21 GDPR): You may object to the processing of your data based on legitimate interests.

Withdrawal of Consent (Art. 7(3) GDPR): You may withdraw any consent you have given at any time, effective for the future.

To exercise your rights, please contact: [email protected]

15. Right to File a Complaint with the Supervisory Authority

You have the right to lodge a complaint with the competent data protection supervisory authority:

The State Commissioner for Data Protection and Freedom of Information in Bremen (LfDI Bremen)

Arndtstraße 1
27570 Bremerhaven
Phone: +49 421 361-2010
Email: [email protected]
Website: https://www.datenschutz.bremen.de

16. Data Security

We implement technical and organizational measures to protect your data against accidental or intentional manipulation, loss, destruction, or access by unauthorized persons. Our security measures are continuously improved in line with technological developments. Data transmission on our website is encrypted (TLS/HTTPS).

17. Validity of This Privacy Policy

This Privacy Policy is current as of October 2026. We reserve the right to update it in the event of changes to the legal landscape or to our services. The most current version is available at https://lapicida-latinus.com/en/privacy-policy/.