ONE WHO LEARNS

Privacy Policy

Last updated: August 25, 2026

1. Introduction

Welcome to One Who Learns ("we", "us", "our"). We operate the website onewholearns.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

2. Data Controller

The data controller responsible for your personal data is:

maray
Ayk Martirosyan
Lehderstrasse 63
13086 Berlin, Germany
Email: [email protected]

3. Data We Collect

3.1 Account Data

When you create an account, we collect:

  • Email address — used for authentication and account recovery
  • Password — stored as a cryptographic hash, never in plain text

3.2 Learning Data

As you use the Service, we store:

  • Course progress and lesson completion status
  • Vocabulary words you add and their review history
  • Spaced repetition scheduling data
  • Exercise results and scores

3.3 Technical Data

We automatically collect certain technical information:

  • IP address (for security and abuse prevention)
  • Browser type and version
  • Device type
  • Pages visited and timestamps

3.4 Local Storage

We use your browser's localStorage to store session-level preferences such as sidebar state and UI settings. This data remains on your device and is not transmitted to our servers.

4. How We Use Your Data

We use your personal data for the following purposes:

  • Providing the Service — delivering courses, tracking your progress, and scheduling vocabulary reviews
  • Authentication — verifying your identity and securing your account
  • Service improvement — understanding usage patterns to improve the learning experience
  • Communication — sending essential account-related emails (password reset, security alerts)

We do not use your data for advertising or sell it to third parties.

5. Legal Basis for Processing (GDPR Art. 6)

  • Contract performance (Art. 6(1)(b)) — processing necessary to provide the Service you signed up for
  • Legitimate interest (Art. 6(1)(f)) — security, fraud prevention, and service improvement
  • Consent (Art. 6(1)(a)) — where applicable, for optional features

6. Third-Party Services

We use the following third-party services to operate the platform:

6.1 Supabase (Database & Authentication)

Our backend infrastructure is powered by Supabase, which provides database hosting and authentication services. Supabase processes your account data and learning data on our behalf. Data is stored in the EU region.

6.2 Vercel (Hosting)

Our website is hosted on Vercel. Vercel may process technical data (IP addresses, request metadata) as part of serving the website. Vercel's infrastructure uses edge locations globally.

6.3 PostHog (Optional Product Analytics)

We use PostHog (EU cloud) to understand which pages, tools, and product flows are useful or confusing. Before you make a choice, and unless you opt in, this happens anonymously and cookie-free (see below) — if you opt in, PostHog may instead set cookies to recognise your device across visits. We use this data only for product improvement and not for advertising.

Opting in also enables session recording: PostHog records a playback of your visit — the pages you see and how you move through them — so we can find where the product is confusing. Recording happens only if you opt in; if you decline, no session is ever recorded. A recording is a visual playback of your visit — the screens you see, and how you move and click through them — so it can include personal content shown on the page, such as your name or text you have written. As a safeguard, the values you type into form fields, and your password, are always hidden and never recorded. Recordings stay in PostHog's EU cloud, are used only for product improvement, are never used for advertising, and are retained only for a limited period.

Before you make a choice, and if you choose essential only, we still collect anonymous, cookie-free usage measurement through PostHog: no tracking cookies are set, and no persistent or cross-session identifier is created. PostHog counts visits using a privacy-preserving hash computed on its EU servers that rotates each day, so the same visitor cannot be recognised from one day to the next. This lets us see which pages are useful without identifying you, and without waiting for you to answer a banner.

The only difference between not having chosen yet and actively choosing essential only is what — if anything — is stored on your device to remember it. Before you make any choice, nothing at all is stored. If you actively choose essential only, a single first-party flag (in your browser's local storage) records that choice so you are not asked again — it holds no identifier and is never sent to advertisers. Either way, session recording and surveys stay disabled and no playback of your visit is ever made. This anonymous, cookie-free measurement is carried out on the basis of our legitimate interest (Art. 6(1)(f) GDPR — see Section 5), since it involves no tracking cookies and no identification of you. You can opt in at any time from the privacy settings control shown in the app.

Separately, a small amount of operational learning telemetry — such as the outcome of a spaced-repetition card review or a subscription lifecycle event — is recorded on our servers as part of running the Service (the underlying record is already stored in your account to schedule your reviews). This essential, non-advertising telemetry is processed under contract performance and legitimate interest (see Section 5), is not governed by the optional analytics consent above, and never includes the text of your answers.

7. Cookies

We use essential cookies and storage required to run the service, including an authentication session cookie managed by Supabase to keep you logged in.

If you opt in to analytics, PostHog may also set analytics-related cookies and storage so we can measure product usage across visits. Before you make a choice, and if you choose essential only, PostHog sets no tracking cookies — it runs in a cookie-free mode and measures usage anonymously (see Section 6.3). Before you choose, nothing is stored on your device at all; if you actively choose essential only, a single first-party flag in your browser's local storage remembers that choice so you are not asked again. Analytics cookies are set only when you opt in.

8. Data Retention

We retain your personal data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required by law to retain it longer.

9. Your Rights (GDPR)

Under the GDPR, you have the following rights:

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate personal data
  • Erasure — request deletion of your personal data ("right to be forgotten")
  • Restriction — request restriction of processing
  • Data portability — receive your data in a structured, machine-readable format
  • Objection — object to processing based on legitimate interest

To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days.

10. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encrypted data transmission (HTTPS/TLS)
  • Cryptographic password hashing
  • Row-level security policies on the database
  • Regular security reviews

11. International Data Transfers

Your data may be processed outside the European Economic Area (EEA) through our hosting provider Vercel. Where this occurs, we ensure appropriate safeguards are in place in accordance with GDPR requirements.

12. Children's Privacy

Our Service is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe we have collected data from a child, please contact us immediately.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

14. Contact & Supervisory Authority

For privacy-related inquiries, contact us at [email protected].

If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. The competent authority for Berlin is:

Berliner Beauftragte fur Datenschutz und Informationsfreiheit
Alt-Moabit 59-61
10555 Berlin, Germany
www.datenschutz-berlin.de

© 2026 One Who Learns. All rights reserved.

Contact Terms of Service Privacy Policy Imprint