Privacy Policy

Last updated: March 2025

1. Who we are

neQuitte is a German language learning app powered by AI. When this policy says "we", "us", or "our" it refers to the operator of neQuitte. If you have any questions you can reach us at hello@nequitte.com.

2. What data we collect

We collect only what is necessary to run the service:

  • Account information โ€” your name, email address, and password (stored as a secure hash). You also provide your native language and German proficiency level (CEFR).
  • Conversation content โ€” the messages you send to the AI tutor and the responses you receive. These are stored so you can return to previous conversations.
  • Vocabulary โ€” words you save, including their article, translation, and example sentences.
  • Flashcard progress โ€” which Leitner box each word is in and when your next review is due.
  • Usage data โ€” your learning streak, last practice date, and how many messages you have sent. This is used to display progress stats to you.

We do not collect payment information โ€” the service is currently free.

3. How we use your data

  • To provide the service โ€” your messages are sent to the AI provider (Google Gemini or OpenRouter) to generate tutor responses. Your CEFR level and native language are included in the prompt so the tutor can adapt to you.
  • To remember context โ€” we store the last 10 messages of each conversation to give the AI coherent context.
  • To cache word definitions โ€” when you ask for a word explanation we cache the result so we do not call the AI again for the same word in the same language.
  • To send transactional emails โ€” we send an email verification link when you register and, if needed, a password reset link. We use Resend to deliver these emails.
  • To enforce daily usage limits โ€” we count messages in Redis (a temporary in-memory store) to stay within daily capacity. These counts expire automatically at midnight.

We do not use your data for advertising or sell it to third parties.

4. Third-party services

Running neQuitte involves the following third parties:

  • Google Gemini โ€” your messages and CEFR level are sent to the Gemini API to generate AI responses. Google's usage policies apply.
  • OpenRouter โ€” used as a fallback AI provider when Gemini is unavailable. Your messages may be forwarded to OpenRouter and onward to the underlying model.
  • Resend โ€” used to deliver verification and password-reset emails. Your email address is shared with Resend for this purpose.

We choose these providers carefully and do not authorise them to use your data for their own purposes beyond delivering the service.

5. Data retention

Your data is kept for as long as your account is active. You can delete your account at any time from the Profile page. Deleting your account permanently removes your conversations, vocabulary, and flashcard progress. Backups may retain data for up to 30 days after deletion.

6. Security

Passwords are hashed and never stored in plaintext. All traffic is served over HTTPS. Access to the database is restricted to the application server. We do not store your full message history in browser storage or cookies.

7. Your rights

You can:

  • Update your name, email, or password at any time from your Profile page.
  • Export your vocabulary list as a CSV from the Vocabulary page.
  • Delete your account and all associated data from your Profile page.
  • Request a copy of your data or ask any privacy-related question by emailing hello@nequitte.com.

8. Cookies

We use a single session cookie to keep you logged in. We do not use tracking, analytics, or advertising cookies.

9. Children

neQuitte is not directed at children under 13. If you believe a child has registered without parental consent please contact us and we will remove the account.

10. Changes to this policy

If we make significant changes we will update the date at the top of this page and, where appropriate, notify you by email.