Privacy Notice
Seller: Ahmed Salem (Apidot) · Last updated: 2026-10-08
Ahmed Salem (Apidot)
Franz-Wolter-Str. 16, 81925 München, Germany
E-Mail: info@apidot.de
Phone: +49 155 1152 9474
Who is responsible
Ahmed Salem (Apidot) is the controller for the personal data described here, unless a payment record is covered by our payment provider acting in its own responsibility. Questions and requests: use the contact address above.
Data we collect and why
- Account data (email address, password hash, and if you sign in with Google: the profile data Google sends) — to create and secure your account and let you sync progress between devices. Basis: contract performance.
- Study progress (which questions you answered, right or wrong, timestamps, bookmarks, mock test results, your settings) — to run the learning schedule and show your dashboard. Basis: contract performance and our legitimate interest in operating the product.
- Purchase records (which plan you unlocked, expiry date, provider transaction reference) — to grant access and support you. Basis: contract performance and legal obligation regarding billing records.
- Device/browser data in server logs (IP address, browser type, timestamps, error messages) — to keep the service working and secure, and to debug faults. Basis: legitimate interest in security and a working service.
- Support messages you send us (email content, sometimes a screenshot) — to answer your question. Basis: contract performance or consent.
Payment card details, invoices and tax handling are collected and processed by our payment provider, not by us; we only see which plan was paid for and the reference needed to grant access.
Who receives data
- Hosting and database providers that run the app for us (as processors).
- Our Merchant of Record, Paddle, for the sale of the product, subscription or access management, payments, tax compliance and invoicing; Paddle also acts as processor for the payment records it holds.
- An AI service used only at build time to draft translations of our help text; no personal data is sent to it.
- Google, if you choose Google sign-in, as identity provider for that login.
- Our professional advisers (legal, tax) where needed.
- Public authorities, where we are legally required to disclose data.
Where data is processed
The app runs on infrastructure inside the EU. Some providers we rely on (our payment provider and Google) may also process data outside the EU/EEA; in those cases the transfers rest on standard contractual clauses or an adequacy decision, and you can ask us for details. Paddle's own privacy notice: paddle.com/legal/privacy.
How long we keep it
Account and progress data: while your account exists. Purchase and billing records: as long as commercial and tax law requires (in Germany generally up to 10 years for accounting documents; the access record itself is deleted with your account). Server logs: up to 30 days. Support messages: up to 24 months after the conversation ends. When data is no longer needed we delete or anonymise it.
Your rights
You can ask to access, correct, or delete your data; to restrict or object to processing; to receive your data in a portable format (a JSON export of your progress is built into the Account page); and to withdraw a consent at any time. Write to the address above and we will answer within one month. You can also complain to a data protection supervisory authority — in Germany, the federal or state authority for your residence; for us that is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach.
Right to object (Art. 21 GDPR): where we process data on the basis of legitimate interest, you can object at any time for reasons arising from your situation; we then stop unless we have compelling legitimate grounds.
Deleting your account
The Account page has a “Delete my account” action that removes your account, your stored progress and your access records. Please export a backup first if you want to keep your study history. Records our payment provider must keep for billing are outside our control and follow its own retention rules.
Security
We use technical and organisational measures appropriate to the risk: encrypted connections (HTTPS), passwords stored only as salted hashes, per-account access rules in the database so each account can read only its own rows, and access to production systems limited to what is necessary.
Cookies and local storage
The app uses your browser’s local storage for two essential purposes: keeping your sign-in session and caching your progress so the app works offline and on this device without an account. No consent banner is needed because nothing beyond these essential uses is stored (§ 25 (2) TDDDG). We do not set advertising, marketing or cross-site tracking cookies, and we do not run third-party analytics scripts. Our hosting provider writes the technical server logs described above.