Privacy Policy
Transparency and data protection are important to us. In this privacy policy, we inform you in accordance with Art. 13 and 14 GDPR about how we process and protect personal data and what rights you have.
Last updated: December 2025
1. Controller
Responsible for data processing in connection with InsightQuiz is:
Chris RequardtNansenstraße 13
86179 Augsburg
Deutschland
[email protected]
2. Types of Data Processed
We distinguish between trainers (registered users) and participants (not registered).
2.1 Trainers (Registered Users)
During registration and use of the service, we process the following data:
- Email address
- Password (stored encrypted, never in plain text)
- Display name
- Subscription and payment data (via Stripe)
- Created quizzes, sessions, reports
- Uploaded content for the AI generator
- Feedback messages (optional)
- Log and usage data (e.g., login times, technical logs)
2.2 Participants (Not Registered)
For participation in quiz sessions, we process:
- A self-chosen display name (a random pseudonym in anonymous surveys)
- The answers given — verbatim for free-text and word-cloud questions
- Score, points earned per question, correct-answer streak
- Response time per question in milliseconds
- For lessons and courses additionally: progress, completed modules and a hash of the self-chosen access PIN
Participants do not create an account. We store no email address, no password, no IP address and no device fingerprint about them. Joining works through a six-digit session PIN or a QR code; the PIN belongs to the session, not to a person.
3. Automatic Data Deletion (Data Minimization)
InsightQuiz follows the principle of data minimisation (Art. 5(1)(c) GDPR). Deletion is carried out by a database job that runs every hour — it does not depend on anyone remembering to press a button.
- Live sessions on the Free plan: deleted automatically 48 hours after the session is created
- AI input: PDFs are parsed in your browser and are never transferred to our servers in the first place
- Reports: not available on the Free plan
- Live sessions: retention set per quiz — the editor accepts 1 to 30 days, with nothing set 15 days applies
- Asynchronous surveys: run time set per survey (1 to 30 days, default 7); the survey and its answers are deleted when it expires
- Lesson and course sessions: deleted 120 days after the session's end date
- Flashcard sessions: deleted according to the retention period stored on the session
General Deletion Rules
- Participants and their answers belong to the session: when a session is deleted, they go with it
- When a quiz, lesson or course is deleted, every session created from it and all associated participant data is deleted as well
- Quiz, lesson and course definitions remain until they are actively deleted
- Trainer accounts can be deleted by their owner at any time; profile, content, sessions, participant data and uploaded files go with them
- Statutory retention obligations (e.g. payment and invoice records) remain unaffected
4. Purposes of Data Processing
We process personal data for the following purposes:
- Operation and provision of the InsightQuiz service
- Real-time synchronization between trainers and participants
- Creation of learning progress statistics and reports
- Authentication and account management
- Contract and payment processing (PRO plan)
- Provision of the AI generator for creating quiz questions
- Abuse detection and system security
- Product improvement (customer feedback, anonymized usage analytics)
Legal Basis (Art. 6 GDPR):
- Art. 6(1)(b) (contract performance)
- Art. 6(1)(a) (consent, e.g., cookies / analytics)
- Art. 6(1)(f) (legitimate interest)
- Art. 6(1)(c) (legal obligations)
5. Disclosure to External Service Providers
This is the complete list of external services that receive data in normal operation. It is derived from the outbound connections in the source code. There are no others — in particular no ad networks, no session recorders and no heatmap tools.
5.1 Hosting, database & authentication – Supabase
- Supabase Inc., running on AWS infrastructure
- Location: region eu-central-1, Frankfurt, Germany. There is no second region and no replication outside the EU
- Purpose: database (PostgreSQL), authentication, file storage, server logic (edge functions)
- Data processed: all account, content and participant data
- Legal basis: Art. 6(1)(b) GDPR · data processing agreement in place
5.2 Delivery of the website – Cloudflare Pages
- Cloudflare, Inc. / Cloudflare Germany GmbH
- Purpose: delivering the website and the application frontend over the content delivery network, TLS encryption, protection against denial-of-service attacks
- Data processed: the connection data every page view technically requires — IP address, requested address, timestamp, browser identification
- Content and database do not live here but with Supabase in Frankfurt; Cloudflare delivers the program files
- Legal basis: Art. 6(1)(f) GDPR (secure and reliable provision of the service)
5.3 Payments – Stripe
- Stripe Payments Europe, Ltd., Ireland
- Purpose: subscriptions, invoicing and the customer portal for paid plans
- Data processed: name, email address, billing and payment details of paying customers
- No participant data is transmitted to Stripe
- Legal basis: Art. 6(1)(b) GDPR · Stripe is PCI DSS certified
5.4 AI features and support chat – Mistral AI
- Mistral AI SAS, France — European infrastructure, no transfer to the US
- Purpose: generating quizzes, lessons, courses and flashcards; grading free-text answers; answering questions in the support chat
- PDF processing: happens entirely in your browser using pdfjs-dist — the document never leaves your device and is never stored on our servers
- Only the extracted or entered text, or the chat message, is transmitted
- Legal basis: Art. 6(1)(b) GDPR
5.5 Transactional email – Resend
- Resend (Plus Five Five, Inc.)
- Purpose: team invitations, trial notices, session reports, system notifications
- Data processed: recipient address, subject and content of the message
- No newsletters are sent without separate consent
- Legal basis: Art. 6(1)(b) GDPR
5.6 Error monitoring – Sentry
- Functional Software, Inc. (Sentry) — we use the EU region (data centre in Germany)
- Purpose: detecting and fixing software errors in the web interface
- Collection of default personal data is explicitly switched off; the user context is reduced to an internal ID and email addresses are stripped from error messages before they are sent
- What is sent is the error, the code location and the page path. Query strings are cut off before sending and console output is discarded, so nothing incidental rides along.
- Legal basis: Art. 6(1)(f) GDPR (operational security and debugging)
5.7 Voice-over for the help videos – ElevenLabs
- ElevenLabs Inc.
- Purpose: one-off generation of the audio tracks for our help videos
- Only text we wrote ourselves is transmitted
- No customer or participant data is sent to ElevenLabs; the function can only be invoked internally
- Listed for completeness
5.8 Audience measurement – Google Analytics 4
- Google Ireland Limited
- Used only after explicit consent (opt-in) through the cookie notice
- Consent Mode v2: all consent signals default to denied and the IP address is truncated
- Without consent no cookies are set and no analytics identifiers are stored. The Google script is still loaded on page view — Google sees that request and the truncated IP address
- Legal basis: Art. 6(1)(a) GDPR · consent can be withdrawn at any time
5.9 Embedded videos – YouTube (only when used)
- Google Ireland Limited
- If a trainer embeds a YouTube video in a quiz or lesson, it is delivered in privacy-enhanced mode (youtube-nocookie.com)
- Your browser only connects to Google when the video is played, transmitting your IP address at that point
- With no embedded video no connection is made
- Legal basis: Art. 6(1)(f) GDPR
6. Cookies
We use cookies for basic functions and optional analytics.
6.1 Necessary Cookies (Essential)
These are required for:
- Login / Session
- Security
- Language settings
- Technical functions
They cannot be disabled.
6.2 Statistics Cookies (Optional)
With your consent, we use Google Analytics. These cookies serve to create anonymized statistics to improve our website.
You can change or revoke your cookie settings at any time:
Marketing attribution (how you found us)
If you reach our website through an ad link, a search engine or a referring page, we store technically necessary information about how you got here. This data is stored only alongside your account if you register — it is never passed on to third parties.
Fields collected:
- UTM parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content) from the URL
- Google click ID (gclid), where present
- Referring URL (HTTP referrer) and the first page you opened
Storage before registration: locally in your browser (localStorage) for a maximum of 60 days. Deleted automatically if you do not register.
Storage after registration: linked to your profile for as long as your account exists.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in evaluating our marketing activity).
Objection / deletion: You can object to this processing at any time, or request deletion, via [email protected].
7. Duration of Storage
The storage duration depends on:
- Statutory requirements (e.g. invoice and payment records: 10 years)
- The trainer's retention setting per quiz (1–30 days, default 15) or per survey (1–30 days, default 7)
- Lesson and course sessions: 120 days after the session's end date
- Live sessions on the Free plan: 48 hours after creation
- Account data: until you delete the account
8. Security Measures
We protect your data through:
- Encrypted transport (HTTPS and secure WebSockets only)
- Encryption at rest through the provider's storage encryption
- Passwords are stored only as bcrypt hashes, never in clear text
- Row-level security on every table — access is decided in the database, not only in the application
- Roles held in a dedicated table so nobody can raise their own permissions through a profile update
- Rate limiting and lockout after failed attempts when joining via session PIN
- Rich text is sanitised before rendering; SVG uploads are rejected
- Regular backups and system monitoring
For readers in the United States: FERPA, COPPA and CCPA
This policy is written under the GDPR, which is the law that binds us. US institutions ask three further questions; the answers follow from the same facts described above.
FERPA — when a school assigns InsightQuiz
- We act as a school official under the school's direct control and use education records only to deliver the assigned activity and return its grade.
- No advertising, no sale, no disclosure to third parties beyond the processors listed in this policy.
- Records are deleted on the school's request and automatically at the end of the retention period; the school remains their owner.
COPPA — participants under 13
- Accounts are for educators and organisations and are created by adults; we do not knowingly create accounts for children under 13.
- Where a school uses InsightQuiz with pupils under 13, the school provides consent on the parents' behalf, as COPPA permits in the educational context.
- From pupils we collect only what the activity needs: the name the school chooses (pseudonyms are fine), answers and scores. No email address, no account, no advertising, no behavioural profiling.
CCPA / CPRA — California residents
- We do not sell personal information and do not share it for cross-context behavioural advertising.
- Whether or not the CCPA thresholds apply to us, you can request access, correction and deletion at [email protected].
- You will not be treated differently for exercising these rights.
Statements of practice, not legal advice. Data is hosted in Frankfurt, Germany; there is no US data region — see the Trust Center for what that means for your contract.
9. Your Rights under GDPR
You have the right at any time to:
To exercise your rights, an email is sufficient to: [email protected]
You also have the right to lodge a complaint with a data protection supervisory authority.
10. Changes to this Privacy Policy
We reserve the right to adapt this privacy policy to accommodate new legal requirements or technical changes. The current version is always available on our website.
11. Privacy Contact
For questions about data protection, you can contact us at any time: [email protected]