Who is responsible
The data controller for LearnRocketAI is Bohemian Digital Innovations s.r.o., IČO 19495242, DIČ CZ19495242, with registered address at Vojtěšská 211/6, 11000 Praha 1-Nové Město, Czech Republic.
Use privacy@learnrocketai.com for privacy questions, data access, correction, deletion, objection, portability, or withdrawal requests. Use support@learnrocketai.com for general service questions.
What data we process
We process the data needed to provide the learning service:
- account data such as email address, password hash, role, language, time zone, workspace, usage mode, and account status;
- optional profile and notification data such as name, student name, phone number, WhatsApp consent, preferred notification channel, and reminder settings;
- learning data such as topics, exercises, answers, flashcards, study sessions, progress, completion history, and teacher or parent assignments;
- uploaded or generated materials such as PDFs, photos, notes, textbook extracts, OCR text, prompts, summaries, exercises, flashcards, AI feedback, and generated illustrations;
- technical data such as session identifiers, security logs, request metadata, device/browser information, locale, time zone, and diagnostic records;
- first-party account activity dates and visit or return milestones used for aggregate product measurement;
- notification logs for email, SMS, and WhatsApp delivery, including status, recipient, message type, provider response, and related audit details.
Children and students
A parent, teacher, or workspace administrator may create student records, assign exercises, send credentials, and track progress. Student data can include names, contact details, assigned materials, answers, progress, and reminder settings. The adult or organization that adds a student must have the right to do so and should give appropriate information to the student or their guardian.
Account registration itself is intended for adults, parents, teachers, and students who may lawfully create an account. Where child consent rules apply to information society services, local law may set a minimum age. Czech law uses 15 years; Poland uses 16 years.
Why we process data
We process data for the purposes and legal bases below:
- account creation and sign-in - performance of the service contract;
- generation of exercises, flashcards, summaries, feedback, transcriptions, and speech - performance of the service contract;
- security, technical logs, diagnostics, and abuse prevention - legitimate interests in protecting and operating the service;
- minimal first-party product-use and account-return statistics - legitimate interests in measuring and improving the service;
- notifications needed for account operation, credentials, invite links, reminders, and administrator updates - performance of the service contract or legitimate interests;
- newsletters, marketing, analytics or marketing cookies, and optional WhatsApp communication - consent;
- accounting, tax, compliance, or other legal duties if they apply - legal obligation.
Providers and transfers
We use trusted providers for hosting, infrastructure, email, SMS, WhatsApp, AI processing, storage, and security. These may include providers such as Railway, Cloudflare, SendGrid, Twilio, file storage providers, and OpenRouter or model providers where they are needed to operate the service. Provider names may change as the infrastructure evolves, but they are used only to operate the service.
Some providers may process data outside the European Economic Area. Where that happens, we rely on appropriate safeguards such as EU Standard Contractual Clauses, equivalent contractual protections, provider transfer frameworks, and configuration that limits the data sent to what the feature needs.
AI processing
When you upload materials or request AI features, relevant text, images, prompts, answers, and context may be sent to AI providers to produce summaries, exercises, flashcards, feedback, transcriptions, or speech. Do not upload confidential, sensitive, or third-party material unless you have the right to use it in the service.
We do not use user materials to train our own AI models. External AI providers process submitted data according to their terms, data processing settings, and our configuration for the requested AI feature.
Cookies
Necessary cookies are used for sign-in sessions, security, locale choice, browser time zone, flashcard voice preference, and saving cookie preferences. These cookies are required or useful for the service and do not need optional consent. We retain the saved choice for no more than nine months and ask again after it expires. Analytics and marketing cookies are disabled unless you choose to allow them in the cookie banner.
When analytics cookies are allowed, we may load Microsoft Clarity (provided by Microsoft) to measure product usage through session recordings that include visible product and learning content, heatmaps, and related interaction analytics. When Clarity is enabled for a session after consent, it may capture clicks, scrolls, navigation, page, referrer, and clicked-link URLs, viewport size, device/browser signals, DOM attributes, and readable product content. To make complete workflows observable, dashboards, learning materials, submitted AI prompts once displayed in the conversation, displayed AI responses, exercises, questions, submitted and correct answers, results, feedback, flashcards, progress, and workflow actions are intentionally readable. We explicitly mask selected fragments in dedicated identity, profile, student-management, and invitation controls, including account, administrator, workspace-member, or student identity, contact and profile values, and displayed invitation credentials; Clarity always masks content inside input boxes and dropdowns. This is selective masking, not anonymization: element masking does not protect route identifiers, URLs, or DOM attributes, and visible learning content and session context may still distinguish a person or activity. Clarity does not run before analytics consent, and activity from before consent is not recorded retroactively. You can withdraw analytics consent at any time in Cookie settings; withdrawal sends denied consent signals, clears Clarity cookies, and stops the Clarity session. Microsoft processes Clarity data under its Microsoft Privacy Statement. Microsoft documents that Clarity retains playback data for 30 days, and click and heatmap data and labeled or favorited sessions for 9 months.
Clarity is not loaded for an invited or workspace-managed student unless their stored age is an integer from 18 through 120. A missing, invalid, out-of-range, or under-18 age blocks Clarity completely even when Analytics consent has been granted; this is collection exclusion, not masking.
Independently of optional analytics cookies, LearnRocketAI records a minimal first-party account ledger when an eligible creator actually uses a product page or action. It stores the first and latest qualified activity times, Warsaw activity dates, 30-minute visit boundaries, and first-return milestones so we can calculate aggregate account return and D1/D7/D30 retention. It excludes managed students, internal administrators, test accounts, temporary demos, and impersonated sessions. The ledger does not store viewed content, prompts, answers, browser identifiers, or IP addresses and is removed with the account. This server-side measurement is not sent to Google unless the separate Analytics consent described below is active.
When analytics cookies are allowed, we may use Google Analytics 4 (provided by Google Ireland Limited and Google LLC, as applicable) to measure coarse acquisition groups, registration and creator-product funnels, page and feature use, device/browser category, approximate region, origin-only referrers, quality and failure trends, and new versus returning use. Google Analytics may receive random browser/client and session identifiers, consent state, timestamps, locale, normalized routes and referrer origins, an allowlisted coarse acquisition group, signed-in usage mode, and allowlisted product events such as registration, material creation, generation, failure, retry, and result opening.
We do not send a custom account User-ID and do not use Google Analytics Measurement Protocol. Google’s standard new, returning, and repeat-use statistics therefore describe consenting browsers or devices, not exact people or accounts: the same person using multiple devices may be counted more than once, and people sharing a browser may be combined. When the first-party ledger confirms a first account return or later return visit during an eligible consented request, GA4 may also receive account_first_returned_v1 or account_return_visit_started_v1 without custom application event parameters. We do not add an account, visit, content, deduplication, usage-mode, or acquisition value to those events; ordinary consented GA browser, session, timing, and normalized page context still applies. They remain a consented, best-effort subset rather than the exact eligible-account KPI. Known managed students, test accounts, temporary demos, internal administrators, and sessions in which an administrator impersonates another user are excluded. Events are sent only by an eligible browser. If such a browser observes a generation start after consent, it may keep that run’s internal numeric identifier in first-party local storage for up to seven days and ask our authenticated endpoint for a sanitized success or failure when the browser returns. The identifier is not included in the Google Analytics event. A generation whose start was not observed by an eligible consenting browser may not be recorded.
To prevent the same event from being sent more than once, event-marker keys in local storage are used for up to 30 days and are not sent to Google. An authenticated-browser activity marker uses a 30-minute inactivity boundary, and observed generation-run markers use a seven-day reconciliation window. Expired values are ignored and removed on the next eligible read, so an idle browser may physically retain them until the overall 30-day cleanup. Only the allowlisted coarse acquisition group and its capture time are used from session storage for up to 30 minutes so later funnel events in that browser tab use the same group; expired values are ignored and removed on the next eligible read or when the tab closes. Raw UTM and advertising click identifiers are not stored there or sent as application event parameters. Current values in these browser stores are deleted when Analytics consent is withdrawn.
We configure Google Analytics collection not to send names, email addresses, phone numbers, direct student identifiers, uploaded or generated content, prompts, answers, filenames, full URLs, query strings, or raw campaign values. When both services are configured, GA4 and Microsoft Clarity may run at the same time after the same Analytics consent; each service collects only the data described for it above. GA4 uses the optional first-party _ga and _ga_<stream identifier> cookies to distinguish a browser and retain session state. We configure them to expire no later than 90 days after first creation and do not refresh that deadline on later page loads; browsers may shorten this period. After a consented redirect, the encrypted first-party learn_tool_ga4_events cookie, unavailable to page scripts, may carry up to four allowlisted events to the next page together with an internal account binding and a random deduplication key for no more than 10 minutes. It is deleted after reading or consent withdrawal; the binding and key are not sent to Google. GA4 does not run and no analytics event is sent before analytics consent; earlier activity is not collected retroactively. Withdrawing analytics consent in Cookie settings stops future GA4 collection and removes these cookies where the browser permits. Data collected before withdrawal may remain until deletion or the applicable retention period expires. Google Analytics event- and user-level data retention is configured for 14 months; this setting does not affect standard aggregated reports. Google processes this data under its Privacy Policy and describes its controls in Safeguarding your data, including transfers subject to the safeguards described above.
The consent cookie contains the disclosure schema version, the Necessary, Analytics, and Marketing choices, a random decision marker, and the device-reported UTC decision time. It preserves only the current choice and can be removed when browser data is cleared. The marker is copied only into the encrypted redirect-event handoff, so an event from an earlier consent decision is discarded even if its response arrives late. Neither the marker nor the decision time is sent to Google, Microsoft Clarity, or Google Ads. A separate non-identifying first-party learn_tool_ga4_discard_required cookie records only that server-side redirect-event cleanup still needs confirmation. It is used if cleanup cannot reach the server, expires within 10 minutes, is removed after successful cleanup, and is never sent to Google.
When marketing cookies and similar browser storage are allowed, we may configure Google Ads tags after consent to retain advertising click attribution from a landing page until a completed registration and to measure that conversion. Google’s first-party conversion-linker cookies and local browser storage may contain consented advertising click identifiers and related pseudonymous attribution identifiers. The conversion includes an opaque, account-derived registration transaction marker used only to prevent duplicate conversion counting; it is not a raw database ID. Withdrawing Marketing consent sends denied consent signals, stops future Google Ads conversion collection, and removes applicable first-party Google Ads cookies and local storage where the browser permits. Marketing storage stays denied for Clarity. Learn how Google uses data from sites and apps that use its services.
Known managed students, test accounts, temporary demos, internal administrators, and impersonated sessions are also excluded from this sitewide Google Ads configuration and conversion measurement.
Retention
We keep data under these practical rules:
- account data is kept while the account exists;
- first-party account visit, activity-day, and return milestones are kept while the account exists; collection-period metadata contains no account identifier;
- uploaded materials and generated content are kept until the user deletes them, the account or workspace is deleted, or further retention is legally required;
- learning progress, assignments, answers, notification logs, and audit logs are kept while needed for the learning service, security, troubleshooting, legal obligations, and legitimate operational records;
- technical and security logs are kept for a limited time needed for security and diagnostics;
- backups may be kept for a limited time according to backup cycles.
If an account or workspace is deleted, data is deleted or anonymized unless retention is required for legal, security, backup, or dispute reasons.
Security
We use technical and organizational measures intended to protect data, including access controls, encrypted transmission, access limitation, security logs, and backups.
Automated decisions
We do not make decisions about users based solely on automated processing that would produce legal effects or similarly significant effects. AI features support learning and material generation, but their results should be reviewed by the user.
Your rights
Depending on your situation, you may request access, correction, deletion, restriction, portability, objection to processing, or withdrawal of consent. You may also complain to the competent data protection authority. For a Czech controller, the competent authority is the Office for Personal Data Protection (Úřad pro ochranu osobnÃch údajů, ÚOOÚ). In Poland, you may also contact the President of the Personal Data Protection Office (UODO) if the matter concerns a user in Poland.
Updates
We may update this policy when the service, providers, law, or data practices change. The current version is published on this page.
Latest update date: August 10, 2026.