Privacy Policy
1. Controller
The controller responsible for data processing within the meaning of the GDPR is:
Tim Julian Schütz
Odenwaldstraße 16/1
74821 Mosbach, Germany
Email: info@stacktags.io
2. Overview of processing activities
We process personal data only where this is necessary to provide the Service, where you have consented, or where a legal permission applies. Below you will find an overview of the main processing activities, their purposes and legal bases.
3. Account & authentication
To create and manage your account we process your display name, your email address, a profile picture (optional), the password hash and login timestamps. Authentication runs through our own system; passwords are stored exclusively as a bcrypt hash. Optionally we offer passwordless login via an email link.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
4. Learning content & activity
When you create, upload or complete learning content, we store that content along with related activity data (e.g. score, learning progress, answer behaviour) so the Service can function.
Legal basis: Art. 6(1)(b) GDPR.
5. AI-assisted content
To generate exercises, answer options, examples and evaluations we send the content you enter (e.g. a word, a question, an uploaded document) to our AI providers Google (Gemini API) and, where applicable, DeepSeek. You should avoid personal data in these inputs, as this content is processed and possibly cached there. Evaluations are returned and stored in your account.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(a) GDPR (consent when uploading optional content).
6. Multiplayer & chat
In multiplayer games and lobby chats, moves, messages, display name and avatar are transmitted to other players. Chat messages are cached for moderation and for handling reports for the duration of the session; reported messages are retained longer for investigation.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(f) GDPR (legitimate interest in preventing misuse).
7. Payments
Payments are processed by Stripe Payments Europe Ltd. From Stripe we receive only confirmations, the time and status of the payment and the subscription status. Payment details (credit card, SEPA etc.) are processed exclusively by Stripe. The Stripe privacy policy applies.
Legal basis: Art. 6(1)(b) GDPR.
8. Document uploads
If you upload documents (PDF, Word) to create learning units, the content and metadata of those documents are processed. Original files are deleted after processing; extracted content is stored in your account as learning entries. On upload we check the permitted page count for your plan window.
9. Cookies & local storage
We store a small amount of technically necessary data locally in your browser (auth token, language settings, UI preferences). This data is required for the Service to work.
Legal basis: Sec. 25(2) no. 2 TDDDG (technically necessary).
9a. Audience measurement with Umami
To improve the Service we collect aggregated, anonymous usage statistics (page views, referrers, approximate region, browser/device type) using the open-source software Umami, which we self-host on our own servers in the EU. No data is transmitted to third parties.
Umami sets no cookies and stores no personal data. Recognising individual visitors across sessions is not possible — the daily hash is rotated every day from IP address and user agent and is not stored persistently.
Legal basis: Sec. 25(2) no. 2 TDDDG (technically necessary to provide the Service — anonymous audience measurement) and Art. 6(1)(f) GDPR (legitimate interest in functional statistics). Consent is not required because no data relatable to a person is processed.
10. Recipients
Data is passed on exclusively to processors and recipients required to operate the Service:
- Mailgun (transactional email: verification, magic link, password reset; EU region)
- Google LLC (Gemini API; possibly USA — safeguarded by EU standard contractual clauses)
- DeepSeek (AI provider; possibly outside the EU — when sending content you entered)
- Stripe Payments Europe Ltd. (payment processing)
- the hosting provider of our servers
11. Transfers to third countries
Where data is transferred to third countries (in particular the USA), this happens only to recipients that ensure an adequate level of data protection, in particular through EU standard contractual clauses or participation in the EU-US Data Privacy Framework.
12. Retention period
Personal data is stored only for as long as it is required for the stated purposes or as long as statutory retention periods apply. When an account is deleted, personal data is deleted or anonymised within 30 days unless retention obligations prevent this.
13. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). You can withdraw consent you have given at any time with effect for the future. To do so, contact info@stacktags.io.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority is, for example, the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg.
14. Children
The Service is not directed at people under the age of 16. We do not knowingly process data of children under 16 without the consent of their legal guardians.
15. Changes to this policy
We update this privacy policy when legal or technical conditions change. The current version is always available on this page.