HoligenceBack to Holigence

Privacy Policy

Version
6.0.0
Effective date
Last updated

Version numbers follow MAJOR.MINOR.PATCH. MAJOR: a new purpose of processing, a new category of recipients, or a change to how you exercise your rights. MINOR: a clarification of an existing practice. PATCH: wording, typos or contact details. Earlier versions are listed in the changelog at the end.

This Privacy Policy explains how Holigence GbR ("Holigence", "we", "us", "our") processes personal data when you use Holigence: the web application for preparing for Level I of the CFA® Program, and the Holigence apps for iOS and Android, which open the same web application (together, the "Service"). The web application is served at https://holigence.app.

It provides the information required by Articles 13 and 14 of the EU General Data Protection Regulation (GDPR), and it also covers the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG).

At a glance

  • You can study as a guest without an account. Guest learning data stays in your browser.
  • Accounts use passkeys. We never ask for a password. An account does not require your real name, email address or phone number. You can add an optional email address for your requests and for important account and security notices. It is never used to sign in or to recover an account.
  • We do not sell personal data, show advertising, or use analytics, tracking or advertising cookies.
  • The personal AI Tutor sends your question and relevant learning context to one AI provider, Anthropic or OpenAI (currently Anthropic); the data may be transferred to the United States (section 4).
  • You can dictate a question to the AI Tutor with a microphone button. The microphone records only after you press the button. The recording is transcribed by a speech-to-text model at Cloudflare, is held in memory only for that request and is not stored. The text appears in your question field, and it becomes a Tutor message only if you send it (sections 2.4 and 4).
  • Community features are optional. If you opt in to matchmaking, a learner you may not know sees your alias and the result of your duel with them. Matchmaking estimates a hidden level from your learning progress and your matched duel results. It is used only for pairing, and the app shows it to you only as a rough band, never as a number (section 2.5).
  • If you report a problem with a question or flashcard, we store your report with your account. An AI model may help us check the reported content, but it never receives your comment or anything else about you (section 2.10).
  • You can export your account data under Settings > Data, and delete your account from the account screen or under Settings > Data (section 10).

1. Who is responsible

The controller responsible for processing your personal data is:

  • Holigence GbR
  • Stettiner Straße 26, 61184 Karben, Germany
  • Represented jointly by: Niklas Sipf and Marcel Molenda (partners)
  • Email: privacy@holigence.de

We have not appointed a data protection officer, because the law does not require one for us. For all privacy questions write to privacy@holigence.de, including to exercise your rights (section 10).

2. Personal data we process

What we process depends on how you use the Service. We collect most of the data in this section from you and from your use of the Service. Other learners provide some data about you: invitations to study partnerships, groups and duels, and the results of duels you play together (section 2.5). Payment status comes from our payment provider (section 2.7).

2.1 Using Holigence as a guest

Without an account, your learning data is stored only in your browser on your device (section 7). This includes your study profile (exam date, weekly study time, study days, language and time zone), your settings, your notes on concepts and your progress. We do not receive it, with these exceptions:

  • Lesson help: When you ask the lesson help a question, the question and the concept you are viewing are sent to our server so it can look up an answer in the study catalogue. The lesson help does not use AI. We do not store the question, and it is not passed to any third party.
  • Creating an account: When you create an account, the language and time zone of your guest profile are taken over into the account. Other guest data stays in your browser.
  • Technical data: Every request reaches our servers and involves the connection data described in section 2.8.

2.2 Your account and sign-in

  • Account identifiers: A random account identifier and a random account handle (used to find your account during recovery), both generated by us, and the alias you choose (3 to 40 characters), which you can change in your account at any time. We recommend that you do not use your real name as your alias.
  • Passkeys: For each passkey: the credential identifier, its public key, a signature counter, how your device can reach the passkey, whether it is synced between devices, when it was created and last used, and the name you give it, if any (1 to 40 characters). The private key and any fingerprint or face data never leave your device or passkey provider, and we never receive them.
  • Your passkey provider: When you create a passkey, your device or passkey manager (for example iCloud Keychain, Google Password Manager or a password manager app) stores your account identifier and alias with the passkey. That provider processes this data under its own terms. If you change your alias, passkeys saved earlier may keep showing the old alias in your device's password manager.
  • Recovery codes: We store only a keyed cryptographic hash of each recovery code, never the code itself.
  • Sessions and sign-in checks: For each sign-in session we store a hash of the session token, a hash of the request-protection token, when the session was created, expires and was ended, the passkey it was started with (not recorded for sessions that began before this was introduced), and when you last confirmed a passkey in it (a recent passkey check, valid for 10 minutes). Challenges for signing in, for a passkey check and for adding a passkey expire after 5 minutes and can be used once; only a hash of each challenge is stored.
  • Account email address (optional): The address you add, when you confirmed it, and, while it waits for confirmation, the pending address with a keyed hash of its code, when the code expires and how many attempts you have made.

You can add an email address to your account. We store it only after you enter the six-digit code we send to that address. The code expires after 15 minutes, and you have 5 attempts to enter it. Requesting a new code erases the previous code. Until you confirm, the address is stored as pending. The pending record is erased when you cancel it, when you confirm the code, or, if the code expires unused, by a scheduled cleanup within minutes after it expires. A confirmed address is kept until you remove it, which erases it at once, or until you delete your account.

We use the address for two purposes only: to identify you when you send us a request (Art. 12(6) GDPR), and to send you important account and security notices, including notices under Art. 34 GDPR. We send no marketing or newsletters to it. It is not used to sign in or to recover an account, and it is separate from the address for email reminders (section 2.6). It is part of your data export (section 10.1).

Sending account email is not active yet. Before we activate it, we will name the email delivery provider in section 5.

2.3 Learning data in your account

  • Study profile: Exam date, weekly study minutes, study days, typical session length, language and time zone.
  • Confirmed answers: For each answer you confirm: the question, the option you chose, whether it was correct, your confidence (1 to 5) if you give it, how long you took, timestamps, and a random identifier the app creates for each browser or device.
  • Practice and mock exams: The sessions you start, their progress and their results.
  • Derived learning state: Estimates of your mastery of each concept, the questions you answered incorrectly, your study plan and your review schedule (section 9).
  • Your own content: Notes and bookmarks.
  • Activity: Which notifications and review reminders you have read.
  • Integrity checks: When an automated check finds an inconsistency in your answer history, we record the type of problem and its position in the history, but no answer content.

2.4 The personal AI Tutor

  • Conversations: Your messages (up to 2,000 characters each), the Tutor's replies, the context attached to each message (the screen you were on, your study context, explanation visuals, proposed and confirmed notes, and references to answers and earlier conversations), the AI model used, the amount of text processed, and timestamps.
  • Voice input (optional): When you press the microphone button in the Tutor's question field, your browser asks for microphone permission. Recording starts only after you press the button, and it stops when you press Stop or after 60 seconds; Cancel discards it. Your browser converts the recording to a WAV audio file (16 kHz, mono) and sends it to our server, which passes it to the speech-to-text service (sections 4 and 5). The text comes back and appears in your question field. You can read and edit it, and it is sent to the Tutor only when you send it. The audio is held in memory for that one request and is not stored, and we keep no transcript unless you send the message. Our logs record only the duration and the outcome of a transcription. We do not identify who is speaking, we do not use your voice to identify you, and we do not infer emotions, stress or other characteristics from it.
  • Tutor guidance: How the Tutor classified each step of the conversation. If the Tutor notices a possible knowledge gap, misconception or calculation error, it may record it as a diagnostic signal, with a short quote of up to 200 characters from your message.
  • Monthly Tutor allowance: For each account and calendar month (UTC), the estimated cost of your Tutor requests in US dollars, and the reserved amounts of requests still in progress. Both are amounts only, with no link to your messages or answers. They keep your Tutor use within a limit of 3 US dollars per account and month: a request that would exceed the limit is not sent to the AI provider. We keep them until your account is deleted, and they are part of your data download.
  • Voice input allowance: For each account and calendar month (UTC), the estimated cost of your voice transcriptions in US dollars, as an amount only, with no link to your messages or answers. It keeps voice input within a limit of 0.20 US dollars per account and month: a transcription that would exceed the limit is not sent to the speech-to-text service. We also keep one monthly total of these amounts for all accounts, without any link to an account. The amounts for your account are kept until your account is deleted.

Section 4 explains what is sent to the AI provider and to the speech-to-text service, and section 5 names both recipients.

2.5 Community features

Study partnerships, private duels, groups and matchmaking are optional. When you use them, we process: who invited whom, the status of each invitation and partnership (invitations expire after 7 days), the questions in a duel with your answers, confidence and response times, the groups you create or join with their names, members, roles and joining and consent dates, the duel results you choose to share with a group, and the matchmaking data described below.

Matchmaking finds you an opponent at a similar level for the same three-question duel. It starts only when you tick its consent box and start a search, and you give that consent again for every search. For each search you choose one pool: the public pool, where anyone who has opted in can be matched with you, or one of your study groups, where only its current members can be. The two pools never mix. For matchmaking we process:

  • Your searches: The pool (and the group, for a group search), the status (waiting, matched, stopped or expired), when the search started and when it runs out (72 hours later), and, once it is matched, when that happened and which duel it led to.
  • Learning summary: When you start a search, we compute a summary of your own learning progress from your confirmed answers: for each concept that duels use, a rounded mastery estimate, how uncertain it is and how many answers it is based on. It is stored with your waiting search and used only to estimate your level and to choose the questions of your matched duel. When you are matched, both players' summaries are used to choose the questions; neither of you sees the other's summary, but the chosen questions can hint at it (see "Matched opponent" below). The summary is removed from the search when the search ends (section 8).
  • Hidden level: An estimate of your duel level, how uncertain it is, how much it has been changing and how many matched duels have changed it, and the level and its uncertainty at the start of each search. Until both players have finished a matched duel of yours, it is computed from your learning summary, anew for each search; after that, only the results of your matched duels change it (section 9). It is used to pair you and to show you your own level. The app never shows it as a number, neither to you nor to anyone else: you see only a band (Starting, Building or Advanced). What your data export contains is described below.
  • Blocks: Which opponents you blocked, and when.

Who can see what:

  • Study partner: Your alias, once they have accepted the partnership.
  • Duel opponent: Your alias and, once both of you have finished, how many questions you answered correctly. Not your chosen answers, confidence or response times. This also applies to matched duels.
  • Matched opponent: A learner you are matched with, who in the public pool can be someone you do not know, sees what a duel opponent sees, and that you were matched at a similar level, from which they can infer that your level is roughly like theirs. The questions of your matched duel are chosen with both players' learning summaries (section 9), so they can also tell your opponent that, on the concepts of those questions, your estimated mastery is probably not far from theirs. They do not see your hidden level, your learning summary or your other duels, and they do not become your study partner.
  • Group members: The group name and each member's alias, role and joining date. Only the group owner sees pending invitations.
  • Group ranking: Only duels that both players have chosen to share with that group: aliases, correct answers per duel, completion times, wins, draws, losses and rank. A matched duel can be shared too, if both players are members of that group.

There is no public leaderboard and no public profile. Nobody outside your partnerships and groups can see your community data, except a learner you are matched with in the public pool, who sees only what is described above for a matched opponent. Other learners cannot see who is searching.

You can block the opponent of a matched duel. Your open matched duels with them then end, and they see them as withdrawn; they are not told that you blocked them. Finished duels, partner duels and partnerships are not affected. Neither of you will be matched with the other again. A block cannot be undone in the app; it is deleted when either account is deleted.

Your consent (section 3) covers each search: reading your learning progress, estimating your level from it, pairing you and choosing the questions of your matched duel. You can withdraw it at any time with effect for the future by stopping a waiting search, or by not starting a new one: from then on, your learning progress is not read for matchmaking and you are not paired. A search that is already matched can no longer be stopped; its learning summary was removed when it was matched. Stopping a search does not delete your blocks.

Your hidden level is kept after a search ends, on the basis of legitimate interests (section 3). Duels that were already matched continue, and you can still play them; once both of you have finished one, its result still changes both players' hidden levels, so that the duel counts for your opponent as it does for you. A level that matched duels have shown is not reset by stopping a search, which keeps pairing fair for everyone. Your hidden level therefore stays stored until you delete your account (section 8), and the app keeps showing you your band. Once a matched duel of yours has counted, a later search continues from your level; until then, your level is estimated anew from your learning summary for each search. You can object to this processing (section 10).

Your data export (section 10.1) contains your matchmaking data as stored, including your hidden level and the levels stored with your searches as numbers. It does not contain the identifier of anyone you blocked, or whether anyone has blocked you.

If you delete your account, duels you played are deleted for both participants, including the other person's duel answers, and groups you own are deleted together with their memberships and the group searches in them. This includes matched duels. Your hidden level, all your searches, including a waiting one, and every block you made or that names you are deleted too. The other person's own learning history is not affected. A matched opponent's hidden level keeps the results of duels already counted, and their own record of the search that matched you stays, without its link to the deleted duel, until it is removed as described in section 8.

2.6 Email reminders (optional)

If you switch on email reminders, we process your email address, the time you gave consent, the time you confirmed the address, and, if you withdraw, the time of withdrawal. This address is separate from the account email address (section 2.2). Confirmation links expire after 15 minutes, and we store only a hash of the link's token. For each scheduled reminder we store the concept and the time it is due.

A reminder email contains the due date and a link to the Service, but no answers or other learning content.

Email reminders are not active yet. Before we activate them, we will name the email delivery provider in section 5.

2.7 Paid plans and payment

Payments are handled by Stripe. When you start a checkout, we create a customer record at Stripe that contains no name or email address. We then send Stripe that customer identifier, the selected price, your language and the addresses to return to. You enter your payment details, email address and billing information directly on Stripe's pages. We never see or store your card number.

We store your Stripe customer identifier, the status of your checkout attempts, and your plan and subscription status, which we receive from Stripe.

Stripe also processes payment data for its own purposes, such as fraud prevention and compliance with financial regulation. For those purposes Stripe is a separate controller; see https://stripe.com/privacy.

2.8 Technical data

  • Connection data: To deliver the Service and protect it from attacks, our hosting provider processes your IP address, the time of each request, the address requested and the technical information your browser sends. Our application does not store your IP address.
  • Rate limiting: To stop abuse, we count requests per short time window under a keyed hash derived from your IP address (and your account identifier when you are signed in). These entries expire after their time window and are removed automatically as new requests arrive.
  • Application logs: For each request to our programming interface we log the method, the route, the result status, the duration and database usage figures. For Tutor requests we also log the provider, the model, the token counts, the stop reason and any cache reads and writes; for a provider error, its HTTP status, error type and request identifier; and for a request that the provider rejects as invalid (HTTP 400), the provider's error message, up to 300 characters. For each provider request of a Tutor reply we also log timing values in milliseconds (until the response headers arrived and until the response was complete) the time until the first text of a streamed reply, and the number of provider requests in the reply; for each reply, its duration, the time before its first provider request and the total time it waited for the provider. For a voice transcription we log its duration and its outcome. These logs contain no IP address, account identifier, message, reply, audio or other learning content.
  • Language and time zone: On your first visit, the app chooses a language from your browser's language settings and time zone. This happens on your device; we do not use your IP address to determine your location.

2.9 Contacting us

The support form in the app saves your request only in your browser, and it does not reach us. To contact us, email privacy@holigence.de. We then process your email address, your message and any information you include, in order to answer you.

2.10 Reporting a problem with a question or flashcard

When you are signed in, you can report a problem with a practice question or a flashcard, for example false information, unclear wording or a calculation error. Reporting is optional. We store the following with your account:

  • The report: The question or flashcard you reported, including the exact version you saw, the reason you chose, the app language, and when you sent the report and when you last updated it. If you report the same problem with the same content again while your first report is still open, we update the first report instead of storing a new one.
  • Your comment: Optional, up to 1,000 characters. Before we store it, we replace email addresses, links, phone numbers starting with +, IBANs and runs of 12 or more digits (such as card or account numbers) with placeholders. Please do not include personal data in it.
  • Your answer context: For a question only: the answer option you had selected, your confidence (1 to 5) if you had selected an option, and whether the solution was shown.
  • The review: Whether we have checked the report, the result of the check, and when its status last changed.

To prevent abuse, one account can send at most 5 reports in 10 minutes, 20 in an hour and 50 in 24 hours (section 2.8).

We read the reports ourselves. To help us check the reported content, we may give an AI model (Claude, by Anthropic) the question or flashcard, the number of reports for each reason and, for a question, how often each answer option had been selected in those reports. The AI model never receives your comment, your alias, your account identifier, the identifier of a report or any other detail of a single report, so it receives no information that relates to you. A report and its review never change your learning data, your mastery estimate or your study plan. We do not answer reports individually; if a report is correct, we correct the content.

3. Purposes and legal bases

Why we process personal data, and on which legal basis
PurposeData (section)Legal basis
Providing guest use, the lesson help and delivering each request (connection data)2.1, 2.8Art. 6(1)(b) GDPR (providing the Service you use, including the connection data each request needs); storage on your device: § 25(2) no. 2 TDDDG
Creating your account, signing you in, managing your passkeys and alias, and recovering access2.2Art. 6(1)(b) GDPR
Saving your progress, estimating mastery, planning and selecting practice2.3, 9Art. 6(1)(b) GDPR
Running the personal AI Tutor2.4, 4Art. 6(1)(b) GDPR
Transcribing your voice input for the Tutor, and the limit for voice input2.4, 4Art. 6(1)(b) GDPR (you start a recording by pressing the microphone button); for the limit, Art. 6(1)(f) GDPR: our legitimate interest in limiting the cost of AI requests per account
Keeping your Tutor use within the monthly allowance of 3 US dollars per account (the estimated cost of your requests)2.4Art. 6(1)(b) GDPR (the allowance is part of the Tutor service you use) and Art. 6(1)(f) GDPR: our legitimate interest in limiting the cost of AI requests per account
Study partnerships, duels (including playing a matched duel) and groups2.5Art. 6(1)(b) GDPR
Matchmaking for a search: reading your learning progress, estimating your hidden level from it, pairing you with another learner and choosing the questions of a matched duel2.5, 9Art. 6(1)(a) GDPR (your consent, which you give for each search and can withdraw)
Matchmaking between searches: keeping your hidden level after a search ends, changing it with the results of your matched duels and showing you its band2.5, 8, 9Art. 6(1)(f) GDPR: the legitimate interest of all players that a matched duel counts for both of them, and that a level shown by matched duels is not reset by stopping a search, so that pairing stays fair
Blocking a matched opponent2.5Art. 6(1)(b) GDPR for the blocks you make; Art. 6(1)(f) GDPR where another learner blocks you (the legitimate interest of learners not to be matched again with someone they do not want to play)
Showing your shared duel results in a group ranking2.5Art. 6(1)(a) GDPR (your consent, which you can withdraw)
Sending email reminders2.6Art. 6(1)(a) GDPR (your consent, which you can withdraw)
Identifying you when you send us a request, and sending important account and security notices (including notices under Art. 34 GDPR) to your account email address2.2Art. 6(1)(b) GDPR
Selling and managing paid plans2.7Art. 6(1)(b) GDPR
Keeping accounting and tax records2.7, 8Art. 6(1)(c) GDPR together with § 147 German Fiscal Code (AO)
Collecting and checking your reports about problems in questions and flashcards, and correcting the content2.10, 8Art. 6(1)(f) GDPR: our legitimate interest, and that of all learners, in correct learning content
Security, preventing abuse, rate limiting, logs and integrity checks2.2, 2.3, 2.8, 2.10Art. 6(1)(f) GDPR: our legitimate interest in a secure, reliable Service that cannot be misused
Documenting the deletion of an account and preventing its reuse8Art. 6(1)(c) GDPR together with Art. 5(2) and Art. 17 GDPR; Art. 6(1)(f) GDPR
Answering your messages and requests2.9Art. 6(1)(b) GDPR where they concern the Service; otherwise Art. 6(1)(f) GDPR (our interest in answering you); Art. 6(1)(c) GDPR for requests under sections 10 and 11
Establishing, exercising or defending legal claimsas neededArt. 6(1)(f) GDPR

Providing a passkey and an alias is necessary to create an account, and you can change your alias later. Without them you can study as a guest, but you cannot use an account or a paid plan. No law requires you to provide personal data. The account email address, email reminders, community features and the AI Tutor are optional.

We do not use your personal data to train AI models, we do not sell it, and we do not use it for advertising.

4. The personal AI Tutor and its AI providers

The personal AI Tutor runs on an AI model of one of two providers, which we access through their programming interfaces: Anthropic (the default) or OpenAI. Holigence chooses the provider; you cannot choose it in the app. Currently it is Anthropic. We use one provider at a time, and each message you send goes to exactly one of them. Section 5 names both providers, and section 6 describes the safeguards for the transfers to them.

When you send the Tutor a message, our server sends the selected provider:

  • your message and up to 20 earlier exchanges of the conversation (each your message and the Tutor's reply), within a fixed size limit;
  • your study settings (exam date, weekly study time, study days, session length, language and time zone);
  • up to five of your most recent confirmed answers (question, your choice, the correct option, and when you answered);
  • your mastery estimates, priority gaps, study plan and earlier diagnostic signals (section 2.4), and the screen or task you are on;
  • when the Tutor needs them to answer you, further information it retrieves from your account: older confirmed answers, your earlier Tutor conversations, and your active lesson bookmarks;
  • earlier explanation visuals you were shown (their parameters and computed values);
  • the Tutor's earlier proposals to add text to one of your notes, with the proposed text and whether you confirmed it.

Your notes are not sent. The Tutor cannot read what your notes say. It can propose an addition to a note, and the addition is saved only when you confirm it in the app.

We do not send the provider your alias, your account identifier, your email address, payment data or your IP address. The provider sees requests from our server, not from your device.

Voice input is transcribed before anything is sent to the AI provider, and the audio never goes to Anthropic or OpenAI. Our server sends the audio to Cloudflare, Inc., which runs the Whisper large-v3-turbo speech-to-text model on Cloudflare Workers AI for us (section 5). The request contains the audio and the language of your interface, which the model uses as a hint, and no account identifier. Cloudflare states that it does not use customer content to train AI models made available on Workers AI. The transcript becomes a message only when you send it, and this section then applies to it as to any other message.

How each provider handles the data:

  • Anthropic (default): Under Anthropic's Commercial Terms, Anthropic Ireland, Limited is the contracting party for customers in the European Economic Area. The data may be transferred to Anthropic, PBC in the United States and to its sub-processors. Anthropic's Commercial Terms state that Anthropic may not train models on Customer Content from the Services. By default, Anthropic deletes API inputs and outputs from its back-end within 30 days of receiving or generating them. It keeps them longer only where the law requires it, where needed to resolve a dispute between the parties, or where content is flagged under its Usage Policy; for flagged content it keeps inputs and outputs for up to 2 years and trust and safety classification scores for up to 7 years. Anthropic also keeps a cache of the Tutor's instructions and of the conversation history. By default the cache lasts 5 minutes and is refreshed at no extra cost each time it is used (https://platform.claude.com/docs/en/build-with-claude/prompt-caching); we use the default, not the 1-hour option.
  • OpenAI: OpenAI Ireland Ltd. is the contracting party for customers in the European Economic Area and processes the data under OpenAI's Data Processing Addendum. Transfers go to OpenAI OpCo, LLC in the United States, the data importer named in the DPA. OpenAI states that data sent to the OpenAI API is not used to train or improve OpenAI models. By default, abuse-monitoring logs of API use are retained for up to 30 days, unless longer retention is required by law or is reasonably necessary to protect OpenAI's services or any third party from harm. We send each request with storage turned off (store set to false), so that OpenAI does not keep the response for later retrieval. OpenAI caches the start of longer prompts automatically by default, for a short time; we do not request its extended cache retention.

Both providers process the data on our behalf under a data processing agreement (Article 28 GDPR): the Anthropic Data Processing Addendum (effective 24 February 2025) and the OpenAI Data Processing Addendum (version v.010126). Section 6 links both.

Deleting your Tutor history or your account in Holigence does not delete data that has already been sent to the provider. That data is subject to the provider's retention described above.

AI answers can be wrong. The Tutor's explanations are learning help, not an official assessment. Chatting with the Tutor never raises your mastery estimate, and changes it proposes to your study plan or notes take effect only after you confirm them.

5. Recipients

We use the following service providers. They process personal data on our behalf and according to our instructions, unless stated otherwise.

Service providers that receive personal data
RecipientPurposeDataLocation
Cloudflare, Inc. (United States)Hosting the Service, its database (Cloudflare D1) and its logs (Workers Logs); speech-to-text for the Tutor's voice input (Cloudflare Workers AI)All data processed on our servers (sections 2.1 to 2.10), and the audio of a voice input while it is transcribed (section 2.4)The database is in the European Union. Cloudflare, Inc. is a United States company and transfers data to the United States (section 6). A request is handled by the Cloudflare data center that receives it, which can be outside the EU for users outside the EU. Cloudflare's Customer Data Processing Addendum states that Cloudflare and its sub-processors may process data outside the European Economic Area; Cloudflare's documentation does not say where Workers AI transcribes the audio. Restricting processing to the EU (Cloudflare's Data Localization Suite) is an Enterprise-only add-on that is not used.
STRATO GmbH, Berlin, GermanyReceiving and storing e-mails sent to privacy@holigence.de (e-mail hosting)The content and metadata of the e-mails you send usGermany (Strato states that its hosting is in Germany)
Anthropic Ireland, Limited (contracting party for customers in the EEA); Anthropic, PBCAI model for the personal AI Tutor, when selected; processor under the Anthropic Data Processing AddendumThe data listed in section 4Ireland (contracting party); the data may be transferred to Anthropic, PBC in the United States and to its sub-processors (section 6)
OpenAI Ireland Ltd. (contracting party for customers in the EEA); OpenAI OpCo, LLCAI model for the personal AI Tutor, when selected; processor under the OpenAI Data Processing AddendumThe data listed in section 4Ireland (contracting party); transfers go to OpenAI OpCo, LLC in the United States, the data importer named in the DPA (Schedule 1) (section 6)
StripePayment processing and subscription management; as a separate controller for its own purposes (section 2.7)The data listed in section 2.7Ireland and United States

Other recipients:

  • Other users: Only what section 2.5 describes, and only when you use community features. With matchmaking in the public pool, this includes learners you do not know.
  • Authorities and courts: When we are legally obliged to disclose data.
  • Professional advisers: Lawyers, tax advisers and auditors who are bound to confidentiality, when needed to meet our legal obligations or to defend legal claims.

We do not sell or rent personal data, and we do not share it for advertising.

6. Transfers outside the European Economic Area

Some recipients in section 5 are located in the United States or process data there: Cloudflare, Inc. for hosting and voice input, Anthropic or OpenAI for the AI Tutor (whichever is selected), and Stripe. Data protection law in the United States may offer a lower level of protection than in the European Economic Area.

For the AI Tutor, our data goes to the provider's contracting entity in Ireland (section 5). Anthropic: the data may be transferred to Anthropic, PBC in the United States and to its sub-processors. OpenAI: the transfers go to OpenAI OpCo, LLC in the United States, the data importer named in OpenAI's Data Processing Addendum. These onward transfers are safeguarded as follows. Anthropic: the EU Standard Contractual Clauses, Module Two (controller to processor) and, where applicable, Module Three, which its Data Processing Addendum incorporates, governed by Irish law. OpenAI: its Data Processing Addendum requires that transfers from OpenAI Ireland Ltd. outside the European Economic Area rest on agreements containing the Standard Contractual Clauses or on an adequacy decision of the European Commission under Article 45 GDPR.

For hosting and voice input, the transfer to Cloudflare, Inc. rests on its certification under the EU-U.S. Data Privacy Framework, which Cloudflare states in its Privacy Policy. Its Customer Data Processing Addendum also states that Cloudflare and its sub-processors may process data outside the European Economic Area. If that certification lapses, Cloudflare relies on the EU Standard Contractual Clauses, which its Customer Data Processing Addendum incorporates (Modules Two and Three, as in its section 6.2).

The data processing addenda are published at https://www.anthropic.com/legal/data-processing-addendum and https://openai.com/policies/data-processing-addendum/.

To receive a copy of the safeguards for these transfers, write to privacy@holigence.de.

7. Storage on your device and cookies

The Service stores information on your device only where this is strictly necessary to provide the service you request (§ 25(2) no. 2 TDDDG), so it does not ask for your consent. We use no analytics, tracking or advertising cookies, and we load no scripts, fonts or other content from third parties.

What the Service stores in your browser
NameTypePurposeHow long
__Host-holigence_sessionCookie (HttpOnly, Secure)Keeps you signed in to your account30 days, or until you sign out or delete your account
__Host-holigence_d1Cookie (HttpOnly, Secure)Makes sure you see your own latest changes when the database is read from copies. Set only when database read replicas are enabled, which they are not in production. Contains no personal dataUntil you close your browser
holigence-guest-v2Local storageGuest study profile, settings and notesUntil you reset browser data in Settings or clear site data
holigence-device-preferencesLocal storageTheme, compact mode, reduced motion and reading font on this deviceUntil you clear site data
holigence-support-tickets-v1Local storageSupport requests you saved on this deviceUntil you reset browser data in Settings or clear site data
holigence-session-change, holigence-tutor-history-changeLocal storageKeep several open tabs in sync. Contain random values onlyOverwritten with each change; until you clear site data
holigence-auth-csrfSession storageProtects your account requests against forgeryUntil you sign out or close the tab
holigence-blueprint-reading:…Session storageRemembers which module you were readingUntil you close the tab
holigence-review-displays-v1Session storageAvoids showing the same review reminder twiceUntil you close the tab or switch reminders off
holigence-blueprint-answers-v1IndexedDB (accounts only)Keeps answers that have not reached our server yet, so they are not lost when you are offlineUntil you clear site data
holigence-shell-…, holigence-text-v1Service worker cacheLets the app start offline: app files and interface text in your language. No personal dataReplaced by newer versions; until you clear site data

Older versions of the Service used other names (for example holigence-guest-state-v1). The Service deletes them when it finds them.

Browser notifications: if you switch on review reminders in the browser and allow notifications, your browser shows them on your device while Holigence is open. We use no push service.

"Reset browser data" in Settings deletes guest data and saved support requests. To remove everything the Service has stored on a device, clear the site data for Holigence in your browser settings.

8. How long we keep data

  • Guest data: In your browser until you remove it (section 7). We do not hold a copy.
  • Account data: As long as your account exists. It is deleted when you delete your account (section 10), except for the records listed below.
  • Tutor history: Until you delete it in the Tutor or delete your account. It remains readable after a paid plan ends. Diagnostic signals stop being used to shape your practice after 30 days; they are stored until you delete your Tutor history or your account.
  • Voice input: The recording exists only in memory while it is transcribed, for that one request, and we do not store it. The transcript is kept only if you send it, as a Tutor message (Tutor history above). Cloudflare's documentation for Workers AI does not state how long it keeps the inputs of a request (section 5). The per-account transcription amounts are kept as described in section 2.4.
  • Short-lived records: Sign-in challenges expire after 5 minutes, and so do passkey-check and add-passkey challenges, deletion confirmations after 2 minutes, email confirmation links after 15 minutes, invitations after 7 days, prepared data exports after 15 minutes and sessions after 30 days. Expired sessions and challenges, used recovery codes and the other expired records are deleted with your account at the latest.
  • Matchmaking: A search runs for at most 72 hours. When it is matched or you stop it, its learning summary is removed at once; the level stored with it when it started stays with the ended search. A search that runs out is marked as expired, and its summary removed, the next time you open matchmaking or start a search; until then the summary stays stored but is no longer used. Ended searches are kept for 7 days from when they were matched, stopped or marked as expired, and at most your 10 most recent; older ones are deleted the next time you start or stop a search, and all of them with your account. A group search is deleted at once when you leave the group, are removed from it or the group is closed. Your hidden level and your blocks are kept as long as your account exists; a block is also deleted when the other account is deleted. Matched duels are kept like other duels: until you or your opponent deletes the account.
  • Email reminder address: Until you withdraw your consent to email reminders (the address is then erased immediately) or delete your account.
  • Account email address: Until you remove it (it is then erased at once) or delete your account. A pending address is erased as described in section 2.2.
  • Content reports: An open report is kept until we close it, as corrected, as not a problem or as a duplicate. A closed report is deleted automatically 12 months after it was closed. All your reports are deleted with your account. The review notes we keep on our own computer contain the reported content, the reasons, the comments and the result of the check, but no alias or account identifier; we delete them after 180 days (section 2.10).
  • Rate-limit entries: Removed automatically after their time window (section 2.8).
  • Hosting logs: Cloudflare keeps the Service's Workers Logs for up to 7 days. They contain the application's log lines (section 2.8) and, for each request, the invocation details Cloudflare records (request, response and related metadata). Cloudflare does not publish where Workers Logs are stored; they are covered by its Customer Data Processing Addendum and the safeguards in section 6.
  • Payment and accounting records: As long as German tax law requires, generally up to 10 years (§ 147 AO).
  • Deletion record: When you delete your account, we keep your random account identifier marked as deleted, the deletion request identifier, and when the deletion was requested and completed. We keep this record as long as we need it to prove that the deletion was carried out and to prevent the identifier from being used again. It contains no learning data, alias or contact data.
  • Backups: Cloudflare D1 keeps the production database's history for 30 days, so that it can be restored to a point in time (Workers Paid plan). A restore overwrites the database in place. Deleted data can remain in that history until it expires. A database export made for a restore drill contains personal data; we delete it after the drill.
  • Your messages to us: As long as needed to handle your request and any follow-up, and longer only where the law requires it.

9. Profiling and automated decisions

To personalise your learning, the Service automatically evaluates your confirmed answers. It estimates your mastery of each concept, identifies gaps, proposes a study plan, schedules reviews and selects practice questions. This is profiling within the meaning of Art. 4(4) GDPR.

The AI Tutor also classifies your messages. A diagnostic signal (section 2.4) can make the estimate for a concept less certain and influence which questions you see next, but it never changes your mastery estimate. You can dismiss a signal.

Voice input (section 2.4) is not profiling: the speech-to-text service only turns the recording into text. It does not identify the speaker, and it does not infer emotions, stress or other characteristics from the voice.

If you use matchmaking (section 2.5), the Service also estimates a hidden duel level for you and uses it to pair you with another learner. This is profiling too. In plain words, it works like this:

  • Starting level: From your learning summary we estimate how well you would do in a three-question duel against a learner who answers half of the questions correctly, and turn this into a starting level with an uncertainty. With no answers on these concepts yet, the level starts in the middle with the highest uncertainty.
  • After each matched duel: When both players have finished a matched duel, the one with more correct answers out of three wins; equal numbers are a draw. The winner's level goes up and the loser's goes down, more so when the result was unexpected or a level is uncertain; after a draw, the two levels can move towards each other (the Glicko-2 rating method, also used in chess). Response times never count. Partner duels and unfinished duels do not change your level.
  • Inactivity: When you have not played matched duels for a while, your level becomes more uncertain, so your next results move it more and you can be matched more widely.
  • Pairing: You are paired with a waiting learner in the same pool whose level is close to yours. The accepted difference grows during the first 24 hours of the longer-waiting search and with the uncertainty of both levels, up to a fixed limit. You are not paired with someone you blocked or who blocked you, with the same learner more than once in 24 hours, with someone you already have an open duel with, or while either of you has 10 open duels. Pairing is tried only while one of the two searching learners has matchmaking open in the app or starts a search.
  • Questions: The three questions come from the free study modules and are chosen with both players' learning summaries. Concepts on which both players' estimated mastery is neither very low nor very high are preferred, and so are concepts on which the two estimates are close. A concept on which they are far apart (0.4 or more on the scale from 0 to 1) is used only when too few other concepts remain, so the questions can tell each player that, on their concepts, the other's estimate is probably not far from their own (section 2.5). The concepts of each player's last matched duel are avoided where possible.
  • What you see: Your level only as a band: Starting, Building or Advanced.

These evaluations only help you study. We make no decision based solely on automated processing that has legal effects on you or affects you similarly significantly (Art. 22 GDPR). Your access, your price and anything outside the Service do not depend on them. Matchmaking decides only whom you play and which three questions you get, and you can stop it at any time; your hidden level does not change your mastery estimates or your study plan. Readiness and mastery are internal learning measures, not a prediction that you will pass the exam.

10. Your rights

Under the GDPR you have the right to:

  • Access (Art. 15): learn whether we process your data and receive a copy of it;
  • Rectification (Art. 16): have inaccurate data corrected. You can change your study profile, your settings, your alias and your account email address yourself in the app. To correct anything else, write to us;
  • Erasure (Art. 17): have your data deleted;
  • Restriction (Art. 18): have processing restricted in certain cases;
  • Data portability (Art. 20): receive the data you provided in a structured, commonly used, machine-readable format;
  • Objection (Art. 21): object to processing, as described in the box below;
  • Withdrawal of consent (Art. 7(3)): withdraw consent at any time with effect for the future, for example by switching off email reminders, removing a shared duel result from a group or stopping a matchmaking search (section 2.5);
  • Complaint (Art. 77): lodge a complaint with a supervisory authority (section 10.3).

10.1 Exercising your rights in the app

  • Export: Under Settings > Data, signed-in users can download all account data stored on our servers as a machine-readable JSON file. Sign-in secrets are excluded. Very large exports are limited to 64 MiB of stored content and a 128 MiB file. Guests can export the data stored in their browser.
  • Delete your Tutor history: In the Tutor, at any time.
  • Delete your account: From the account screen or under Settings > Data, after confirming with your passkey. All sessions and recovery codes stop working immediately. Your account data is deleted from our database, and the customer record at Stripe is deleted. We keep only the records listed in section 8.
  • Your alias, passkeys and account email address: In your account you can change your alias at any time; add, rename or remove passkeys, but not the last one; and set, change or remove your account email address. Removing a passkey ends every other sign-in that was made with it, and every other sign-in whose passkey is not recorded (those that began before this was introduced). Adding or removing a passkey, and setting or changing the email address, need a passkey confirmation from the last 10 minutes. Removing the email address erases it at once.
  • Not deleted with your account: Data stored in your browser (section 7), files you have downloaded, data already sent to the AI provider (section 4), payment records we must keep (section 8), our review notes on content reports until they are deleted after 180 days (section 8) and backup copies until they expire.
  • Interrupted deletion: If a deletion is interrupted, you can resume it in the app within 24 hours. Otherwise a scheduled job completes it automatically, normally within about 75 minutes after it was interrupted; where a payment provider must first close your customer record, the job waits until that has succeeded. If it still cannot be completed, write to privacy@holigence.de and we will complete it.

10.2 Requests by email

You can exercise all your rights by writing to privacy@holigence.de. Because an account has no real name attached to it, and its email address is optional, we may ask you to confirm a request from within your signed-in account or, if you have confirmed an account email address, through that address, so that we do not disclose or delete someone else's data. We answer within one month. In complex cases this period can be extended by up to two further months, and we will tell you if it is.

10.3 Supervisory authority

You can lodge a complaint with any data protection supervisory authority, in particular in the EU member state where you live, work or where you believe an infringement took place. The authority responsible for us is:

  • Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Wilhelmstraße 7, 65185 Wiesbaden

11. Security

We protect your data with technical and organisational measures appropriate to the risk, including:

  • encrypted connections (HTTPS with HTTP Strict Transport Security);
  • a strict content security policy that lets the app load resources only from our own address;
  • sign-in with passkeys instead of passwords;
  • storing session tokens, challenges, recovery codes and email confirmation codes only as cryptographic hashes;
  • rate limits on sign-in and other sensitive functions;
  • checking on our server, for every request, that you may access the data you request;
  • a fresh passkey confirmation before an account is deleted, before a passkey is added or removed, and before the account email address is set or changed.

No method of transmission or storage is completely secure. If a personal data breach occurs, we will notify the competent supervisory authority within 72 hours where Art. 33 GDPR requires it. If the breach is likely to result in a high risk to you, we will also inform you without undue delay (Art. 34 GDPR). If you have confirmed an account email address (section 2.2), we use it for such a notice. We may also show a notice in the app.

12. Children

Holigence is designed for adults preparing for the CFA® Program and is not directed at children. When you create an account, you confirm that you are 18 or older. Children under 18 must not create an account or buy a plan. If we learn that a child under 18 has created an account, we will delete it.

14. Changes to this policy

We update this policy when our processing or the law changes. Each version shows its version number and dates at the top, and the changelog below lists every change. Before a material change takes effect (a new purpose, a new category of recipients, or a change to how you exercise your rights), we will tell you in the app. Where a change requires your consent, we will ask for it.

15. Contact

Changelog

  • 6.0.0 (): Voice input for the AI Tutor (MAJOR: a new purpose). A microphone button in the Tutor's question field lets a signed-in learner with the paid AI Tutor dictate a question of up to 60 seconds, after the browser has asked for microphone permission; the microphone records only after the button is pressed, until the learner stops it or for at most 60 seconds. The recording is sent to a speech-to-text model at Cloudflare (Workers AI), held in memory for that one request and not stored. The text appears in the question field and becomes a Tutor message only if the learner sends it. We keep the transcription amount per account and month, against a limit of 0.20 US dollars, and one global monthly total without any link to an account, on the legal basis of Art. 6(1)(b) GDPR. No speaker identification, voice biometrics or emotion recognition (at a glance, sections 2.4, 2.8, 3, 4, 5, 6, 8 and 9).
  • 5.0.0 (): Content reports (MAJOR: a new purpose). Signed-in users can report a problem with a practice question or flashcard. We store the report with the account: the content and its exact version, the reason, an optional comment (with email addresses, links, phone numbers and long digit sequences replaced before storage), the answer context for questions and the review status, on the legal basis of Art. 6(1)(f) GDPR (correct learning content). Reports are rate-limited. An AI model (Claude, by Anthropic) may help check the reported content, but it receives only the content and counts of reasons and selected options, never a comment or anything that relates to a person. Closed reports are deleted 12 months after closing, all reports with the account, and our review notes after 180 days (at a glance, sections 2.10, 3, 5, 8 and 10.1).
  • 4.1.0 (): Tutor timing logs (section 2.8, MINOR: a clarification of an existing practice). The operator log of Tutor requests now also records timing values in milliseconds for each provider request (including the time to the first text of a streamed reply) and each reply, with the number of provider requests. No content, identifier or learner data is logged.
  • 4.0.0 (): Account security (MAJOR: a new purpose). An optional account email address, used to identify you when you send us a request (Art. 12(6) GDPR) and to send you important account and security notices, including notices under Art. 34 GDPR, on the legal basis of Art. 6(1)(b) GDPR. It is stored only after you confirm a six-digit code sent to it, and it is not used to sign in or to recover an account. Sending is not active yet (introduction, at a glance, sections 2.2, 3, 8, 10 and 11). Several passkeys per account (up to 10), each with an optional name, that you can list, add, rename and remove; the last passkey cannot be removed, and removing a passkey ends the other sign-in sessions made with it or with an unrecorded passkey (sections 2.2 and 10.1). Each session records the passkey it started with and when you last confirmed a passkey in it; adding or removing a passkey and setting or changing the email address need a passkey confirmation from the last 10 minutes (sections 2.2, 10.1 and 11). The alias can be changed in your account at any time, which replaces writing to us to correct it (section 10). Account deletion can also be started from the account screen (section 10.1). An interrupted deletion is completed automatically by a scheduled job once it is older than 60 minutes, so it no longer depends on resuming it within 24 hours or on writing to us (section 10.1).
  • 3.0.0 (): Tutor providers, controller, hosting, processors and review corrections (sections 1 to 8, 10.1, 12, 13 and 15): the personal AI Tutor is provided by one of two AI providers, Anthropic (the default) or OpenAI, chosen by Holigence, one per message; both are named as recipients with their data processing addenda and transfer safeguards. Holigence GbR, a partnership in Karben, is the controller, and the supervisory authority is the Hessian Commissioner for Data Protection and Freedom of Information. The Service is hosted by Cloudflare, Inc. at holigence.app, with its database in the European Union, and OpenAI Sites is no longer used. E-mails to privacy@holigence.de are hosted by STRATO in Germany. Learners' notes are not sent to either provider. When you create an account, you confirm that you are 18 or older. The minimum age is 18 (previously 16).
  • 2.0.0 (): Matchmaking for duels (sections 2.5, 3, 5, 8, 9 and 10): a new purpose, estimating a hidden duel level from your learning progress and matched duel results to pair you with another learner, based on your consent for each search, with the level kept between searches on the basis of legitimate interests; and a new group of recipients, learners you may not know who are matched with you in the public pool. Section 2.5 no longer says that nobody outside your partnerships and groups can see your community data.
  • 1.0.0 (): First complete Privacy Policy in English, now the only binding version. It replaces the privacy and data processing sections of the legal notices.