Controller
Mojtaba JafariZenithStack IT Solutions
Rathenauplan 31
38440 Wolfsburg
Deutschland
Local app data
Your profile, settings and consent status are stored locally in the app. Answers, learning events and test results are held in a local SQLite database. These learning records are not transmitted to TheoriePass. They remain until you delete them in the app or uninstall it. Local processing provides the learning functionality you request.
Content updates
The app checks api.zenithstack.dev for corrections and new content versions. Cloudflare, Inc. processes technically necessary connection data, including IP address, time, requested address, device and network metadata, and the active catalogue version. The purpose is a secure, current and reliable content service. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is the secure delivery and maintenance of learning content.
Optional error reports
Only after your separate, explicit choice does the app send technical error reports to Sentry (Functional Software, Inc.) and limited operational events to our service at api.zenithstack.dev. A random diagnostics installation identifier is separate from purchase and usage identifiers.
Reports may include technical stack traces, app, build and iOS versions, device model, content version, screen name, learning mode, question number, display and language settings, and recent permitted interactions. Text input, selected answers, complete questions, access codes, secrets and screen recordings are not collected as diagnostic fields. Automatic console and network breadcrumbs, Session Replay and screenshots are disabled.
The purpose is to identify and fix errors and freezes. The basis is your optional consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. The app uses a Sentry project with a European ingestion server. Sentry may use international subprocessors. The intended report history is 30 days. Availability and collection are limited by consent, the operating system and the network.
Optional usage statistics
With separate consent, our Cloudflare service processes visited areas, permitted feature interactions, session identifiers, active usage duration, and app and build versions. A random installation identifier enables pseudonymous counting; its hash is stored on the server. It is separate from purchase and diagnostics identifiers. Answers, learning results, question texts, search text, names, email addresses and advertising IDs are not transmitted. The statistics cover participating installations, not every person or every user.
Raw events are deleted after no more than 30 days; summaries without installation identifiers are retained for no more than 365 days. The basis is separate consent under Article 6(1)(a) GDPR and section 25(1) TDDDG.
You can turn off error reporting and usage statistics independently in the privacy settings. Further collection and transmission stop, and the local queue is deleted. Data already received lawfully is deleted according to its retention period; contact us to request earlier deletion from the server. Learning features remain available without these consents.
Messages in the app
The app downloads messages and images published by the provider through api.zenithstack.dev. This involves technically necessary connection data. Messages may be selected according to app version and test or production environment. Read status and received messages are stored locally. Messages work without diagnostics or statistics consent; no read or click event is transmitted without statistics consent.
An update button opens the App Store page; an external button opens the stated HTTPS link, where the destination’s privacy rules apply. Messages do not execute arbitrary code or install updates automatically. Their purpose is to provide information about app usage, changes and operational status. The basis for necessary requests is Article 6(1)(f) GDPR and the legitimate interest in providing this information. In-app messages are not lock-screen push notifications.
In-app purchases and access
When you start or restore an annual subscription or request Premium content, Apple processes the payment. The app sends the Apple transaction identifier, a random app account identifier stored in the transaction, and a random installation identifier to api.zenithstack.dev. The server checks the subscription period, renewal, refund and revocation status directly with Apple. Apple also sends signed server notifications about status changes.
Alternatively, the provider may give individuals an activation code. On redemption, the server stores the code’s hash, the random installation identifier’s hash, a random access identifier, status, expiry and usage timestamps. The secret access credential is stored encrypted in the device keychain in native apps and in local browser storage for web use. The code is bound to the redeeming installation. After reinstallation, this binding can be transferred to the new installation only if the secret access credential is still available.
TheoriePass stores a pseudonymous entitlement and transaction history and the last access time for access, restoration, support, abuse prevention and aggregate activity counts. TheoriePass does not receive your name, Apple ID or credit card data. The legal basis is Article 6(1)(b) GDPR; security and abuse prevention additionally rely on Article 6(1)(f) GDPR. Using only the 30 free questions does not involve an entitlement check.
Recipients, international transfers and retention
Technical recipients are Cloudflare, Inc. for the API, database, delivery and logs; Sentry (Functional Software, Inc.) for optional error reports; and Apple for payment, receipts and server-side subscription confirmation. These providers may process data internationally. Transfers outside the EEA rely in particular on applicable adequacy decisions and Standard Contractual Clauses.
Cloudflare Worker logs are sampled and retained for no more than 7 days. Pseudonymous entitlement, activation-code and transaction data is stored during access and afterwards only for as long as needed for billing, support, abuse prevention, or legal claims and obligations; it is then deleted or anonymised. Optional reports and usage statistics have the separate periods stated above. Apple remains authoritative for payment and customer receipts. Data is not sold or used for advertising or advertising profiling.
Support
When you contact us, we process your message and contact details to handle the enquiry under Article 6(1)(b) or (f) GDPR. Data is deleted when the enquiry is resolved and no retention duty or legitimate need to safeguard claims requires otherwise. The website privacy policy also explains email communication.
Your rights
Subject to the applicable legal conditions, you have rights of access, rectification, erasure, restriction of processing and data portability. Where processing is based on a legitimate interest, you may object for reasons relating to your particular situation. You may withdraw consent at any time with effect for the future; this does not affect the lawfulness of processing before withdrawal.
You may lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence, place of work or the alleged infringement. You may also contact the State Commissioner for Data Protection of Lower Saxony at Prinzenstraße 5, 30159 Hannover, Germany, or poststelle@lfd.niedersachsen.de. To exercise your rights, simply contact us. We do not use automated decision-making with legal or similarly significant effects, or advertising profiling.
Export and deletion
The app can export settings, answers, learning events and test results as JSON. “Fortschritt zurücksetzen” (reset progress) deletes learning records. “Alle App-Daten löschen” (delete all app data) is the complete local deletion function: it also removes your profile, settings, content updates, a diagnostics identifier, and local purchase and activation credentials, including locally stored proof of code activation.
This differs from “Auf Anfangszustand zurücksetzen” (reset to the initial state) in profile settings: that command resets app and learning data but retains proof of code activation so access can be restored. A purchase record held by the App Store remains with Apple and can be restored.
None of these local actions automatically deletes pseudonymous server-side billing or abuse-prevention data. Email us to request access to or deletion of server-side data. Deleting local data or the app does not cancel an App Store subscription.