Privacy Policy
Datenschutzerklärung
Last Updated: January 30, 2026
1. Data Controller Information
The data controller responsible for the processing of your personal data on this website is:
LearnWell GmbH
[Street Name and Number]
[Postal Code] Berlin
Germany
Email: hello@learnwell.ai
Phone: [Phone Number]
Data Protection Officer
For all data protection inquiries, you may contact our Data Protection Officer:
Email: privacy@learnwell.ai
2. Overview of Data Processing
LearnWell is an AI-powered exam preparation platform. We process personal data to provide our services, improve your learning experience, and comply with legal obligations. This Privacy Policy explains how we collect, use, and protect your data in compliance with the EU General Data Protection Regulation (GDPR), German data protection laws (BDSG), and applicable international privacy regulations.
3. Categories of Personal Data We Collect
3.1 Account and Profile Data
- Name and email address
- Account credentials (password stored in hashed form)
- Profile information and preferences
- Communication preferences
3.2 Learning and Progress Data
- Exam enrollments and study progress
- Practice attempt results and performance metrics
- Bookmarked questions and notes
- Study calendar and scheduling data
3.3 Payment and Transaction Data
- Subscription plan and billing history
- Payment method details (processed securely by Stripe)
- Invoice and receipt information
3.4 Technical and Usage Data
- IP address (hashed for consent records)
- Browser type and version
- Device information and operating system
- Usage patterns and session data
- Cookies and similar technologies (see Section 10)
3.5 AI Coach Interaction Data
- Chat conversation history
- Coach memory and personalization data
- Learning context and preferences
4. Purposes and Legal Bases for Processing
We process your personal data for the following purposes, based on the corresponding legal bases under GDPR Article 6:
4.1 Contract Performance (Art. 6(1)(b) GDPR)
- Creating and managing your user account
- Providing access to exam preparation content
- Processing practice attempts and tracking progress
- Managing subscriptions and processing payments
- Providing customer support
4.2 Consent (Art. 6(1)(a) GDPR)
- Setting non-essential cookies (analytics, marketing)
- AI Coach memory and personalization features
- Marketing communications and newsletters
- Personalized learning recommendations
You may withdraw consent at any time through your account settings or by using the Cookie Settings link in the footer.
4.3 Legitimate Interests (Art. 6(1)(f) GDPR)
- Improving and optimizing our platform
- Ensuring security and preventing fraud
- Analyzing aggregated usage patterns
- Communicating service updates and changes
4.4 Legal Obligations (Art. 6(1)(c) GDPR)
- Retaining financial records for tax purposes
- Responding to lawful requests from authorities
- Maintaining consent records for compliance
5. Recipients and Third-Party Processors
We share your personal data only with trusted third parties who assist us in operating our platform. All processors are contractually bound to protect your data (Art. 28 GDPR):
5.1 Infrastructure and Hosting
- Vercel Inc. (USA) – Website hosting and deployment
- Supabase Inc. (USA) – Database hosting and authentication
5.2 Payment Processing
- Stripe Inc. (USA) – Secure payment processing
5.3 AI Services
- Anthropic PBC (USA) – AI Coach functionality
5.4 Analytics (with consent)
- Vercel Analytics – Privacy-focused usage analytics
We do not sell your personal data to third parties.
6. International Data Transfers
Some of our service providers are located in the United States. When transferring personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) – We use EU Commission-approved SCCs with all US-based processors
- EU-US Data Privacy Framework – Where applicable, we work with processors certified under the DPF
- Supplementary Measures – Additional technical and organizational measures to protect data in transit and at rest
You may request a copy of the applicable safeguards by contacting our Data Protection Officer.
7. Data Retention
We retain your personal data only as long as necessary for the purposes described in this policy:
- Account data: Until account deletion, plus 30 days for backup recovery
- Learning progress: Until account deletion or upon your request
- Payment records: 10 years (German tax law requirements)
- Consent records: 3 years from the date of consent
- AI Coach conversations: Until you delete them or disable Coach memory
- Server logs: 90 days for security purposes
8. Your Rights Under GDPR
As a data subject, you have the following rights under GDPR. You can exercise these rights through your Privacy Center in account settings or by contacting us:
8.1 Right of Access (Art. 15 GDPR)
You have the right to obtain confirmation of whether we process your personal data and to receive a copy of that data. Use the "Download My Data" feature in your Privacy Center.
8.2 Right to Rectification (Art. 16 GDPR)
You have the right to correct inaccurate personal data. Update your profile information directly in your account settings.
8.3 Right to Erasure (Art. 17 GDPR)
You have the right to request deletion of your personal data ("right to be forgotten"). Use the "Delete Account" feature in your Privacy Center. Note that some data may be retained for legal obligations.
8.4 Right to Restriction (Art. 18 GDPR)
You have the right to request restriction of processing in certain circumstances. Contact our Data Protection Officer to exercise this right.
8.5 Right to Data Portability (Art. 20 GDPR)
You have the right to receive your data in a structured, machine-readable format (JSON). Use the "Download My Data" feature in your Privacy Center.
8.6 Right to Object (Art. 21 GDPR)
You have the right to object to processing based on legitimate interests. Contact our Data Protection Officer to exercise this right.
8.7 Right to Withdraw Consent (Art. 7(3) GDPR)
Where processing is based on consent, you may withdraw consent at any time. This does not affect the lawfulness of processing before withdrawal. Manage your consent preferences in your Privacy Center or through Cookie Settings.
8.8 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority. For Germany, the relevant authority depends on your location. The federal authority is:
Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)
Graurheindorfer Str. 153
53117 Bonn
Germany
Website: www.bfdi.bund.de
9. How to Exercise Your Rights
You can exercise most of your rights directly through your account:
- Privacy Center: Access via Dashboard → Settings → Privacy & Data
- Cookie Settings: Click "Cookie Settings" in the website footer
- Email: Contact privacy@learnwell.ai
We will respond to your request within 30 days. In complex cases, we may extend this period by up to 60 additional days, with prior notification.
10. Cookies and Tracking Technologies
We use cookies and similar technologies to operate our platform and, with your consent, to analyze usage and personalize your experience.
10.1 Essential Cookies
These cookies are necessary for the website to function and cannot be disabled:
- Authentication and session management
- Security features and fraud prevention
- Cookie consent preferences
10.2 Analytics Cookies (Consent Required)
With your consent, we use analytics cookies to understand how visitors interact with our website:
- Page views and navigation patterns
- Performance metrics
- Error tracking
10.3 Personalization Cookies (Consent Required)
With your consent, we use personalization features to enhance your learning experience:
- AI Coach memory and context
- Learning recommendations
- Interface preferences
10.4 Managing Cookie Preferences
You can manage your cookie preferences at any time by clicking "Cookie Settings" in the website footer. You can also control cookies through your browser settings, though this may affect website functionality.
11. AI Coach and Automated Processing
Our AI Coach feature uses artificial intelligence to provide personalized learning assistance. Here's how we handle AI-related data:
11.1 How the AI Coach Works
The AI Coach analyzes your questions and learning context to provide helpful explanations and guidance. Conversations are processed by our AI service provider (Anthropic) to generate responses.
11.2 Coach Memory
With your consent (Personalization category), the AI Coach can remember context from previous conversations to provide more relevant assistance. You can:
- View a summary of stored Coach memory
- Delete all Coach memory at any time
- Disable Coach memory entirely (conversations won't be stored)
11.3 Chat History
Your chat conversations with the AI Coach are stored to allow you to review previous discussions. You can delete individual conversations or all chat history through your Privacy Center.
11.4 AI Limitations
The AI Coach can make mistakes. Always verify important information from official sources. Do not share sensitive personal data, passwords, or confidential information in chat conversations.
11.5 No Automated Decision-Making
We do not use AI for automated decision-making that produces legal effects or similarly significantly affects you (Art. 22 GDPR). The AI Coach provides educational assistance only.
12. Data Security
We implement appropriate technical and organizational measures to protect your personal data:
- Encryption of data in transit (TLS/HTTPS) and at rest
- Secure authentication with hashed passwords
- Regular security assessments and updates
- Access controls and employee training
- Incident response procedures
While we strive to protect your data, no method of transmission over the internet is 100% secure. We encourage you to use strong passwords and protect your account credentials.
13. Children's Privacy
Our Service is not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16. If you believe we have collected information from a child, please contact us immediately at privacy@learnwell.ai.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will:
- Update the "Last Updated" date at the top of this page
- Notify you of material changes via email or in-app notification
- Request renewed consent where required by law
We encourage you to review this policy periodically.
15. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights:
General Inquiries:
Email: hello@learnwell.ai
Data Protection Officer:
Email: privacy@learnwell.ai
Postal Address:
LearnWell GmbH
[Street Name and Number]
[Postal Code] Berlin
Germany