Who is responsible
Marvin Perzi, trading as Persie0
Angerdorf 6, 3822 Karlstein an der Thaya, Austria
persie0@protonmail.com
This policy applies to Hanzi Hero and this policy page. It supplements the general Persie0 privacy policy; for this app, the more specific information on this page takes precedence.
Information used on your device
The app stores or processes the following information locally for the features you choose:
- vocabulary progress, answers, scores and review schedule
- settings, selected language and playback state
- queued sync changes
Local processing is based on Art. 6(1)(b) GDPR where it is needed to provide a requested feature. Settings that are technically necessary are stored under the necessity exception in § 165(3) TKG 2021. Local information normally remains until you delete it, clear the app's data or remove the app.
Permissions
Hanzi Hero may request these device permissions:
- Files: import/export learning data where offered.
- Notifications/audio service: lessons and playback you request.
- Google/Apple sign-in: only for the cloud sync you enable.
Permissions can be changed in the operating-system settings. A feature that depends on a denied permission may then be unavailable.
Services and data transfers
The following services receive information only for the purposes described below.
Sentry (EU, filtered)
Find and fix defects; protect stability and security. The information involved is: Crash and performance diagnostics, including the error and stack trace, app version, device and operating-system information, technical runtime data and the network IP address visible to Sentry. Common direct identifiers are filtered before transmission, although diagnostic text may still contain information entered or displayed in the app.
Recipient: Sentry; project data hosted in the EU, subject to possible international support/access. Legal basis: Art. 6(1)(f) GDPR (legitimate interests in a secure, reliable app). You may object. Retention: 90 days in the configured Sentry project, then deletion; longer only if an event is preserved for a concrete security/legal claim.
In-app purchases (RevenueCat)
Activate paid features, restore purchases, prevent fraud and provide support. The information involved is: Pseudonymous/anonymous app-user ID, product and entitlement identifiers, purchase/subscription status, store transaction metadata, app/device technical data and IP visible in network logs. Persie0 does not receive your payment-card details.
Recipient: RevenueCat and the selected app store. The store is a separate controller for payment. Legal basis: Art. 6(1)(b) GDPR (purchase/service) and Art. 6(1)(f) (fraud prevention and reliable entitlement state). Retention: For the subscription/purchase relationship and as needed to restore entitlements, resolve disputes and meet statutory accounting/claim periods; then deletion or de-identification.
Country/region detection
Choose regional defaults, currency, language or the appropriate consent flow. The information involved is: Public IP address, request metadata and country/region inferred from IP; no GPS location.
Recipient: The first available country-detection service named above. Legal basis: Art. 6(1)(f) GDPR (minimal regional configuration). You can override regional settings where offered. Retention: The response is used transiently or cached locally; Persie0 does not keep a server log. Providers retain request logs under their policies.
Optional Google Drive learning sync
Back up and synchronize progress at your request. The information involved is: Google authorization/account identifier and app-data access; vocabulary progress, review state, settings and sync metadata.
Recipient: Google; data in the Google Drive account you select. Legal basis: Art. 6(1)(a)/(b) GDPR. Optional; disconnecting withdraws consent for future sync. Retention: Until deleted from Drive/app-data, disconnected with deletion, or the Google account closes; provider backup cycles may apply.
Optional iCloud learning sync
Synchronize progress across your Apple devices. The information involved is: iCloud account-scoped identifier and learning progress/settings submitted through Apple's iCloud services; Persie0 does not receive your Apple password.
Recipient: Apple. Legal basis: Art. 6(1)(a)/(b) GDPR; optional and controlled through the app/iCloud settings. Retention: Until you delete the app's iCloud data, disable sync with deletion, or close the Apple account; Apple backup cycles may apply.
Optional support email
Answer the request, troubleshoot and document the exchange. The information involved is: Sender address, message, attachments and technical mail headers, only when you choose to contact support.
Recipient: Email transport providers and Proton. Legal basis: Art. 6(1)(b) GDPR; Art. 6(1)(f) for support quality and defence of claims. Retention: For the support exchange and up to three years afterwards where needed for legal claims; statutory records longer only if required.
This policy page
GitHub Pages receives the IP address, browser information, request time and requested page path to deliver and protect this page. Persie0 does not add analytics or advertising cookies to these policy pages. Processing is based on Art. 6(1)(f) GDPR; GitHub's infrastructure retention applies.
Processing outside the EEA
Some service providers may process information outside the European Economic Area. Where GDPR requires safeguards, processing relies on an adequacy decision, an applicable EU–US Data Privacy Framework certification, or Standard Contractual Clauses together with appropriate safeguards. You may request information about the applicable safeguard by email.
Deletion and retention
Local data can be removed through the app's delete or reset functions, by clearing app data, or by removing the app. Information held by a connected provider follows the period stated above and that provider's deletion process. Requests concerning data controlled by Persie0 can be sent to persie0@protonmail.com.
Your rights
Subject to the GDPR's conditions, you may request access, correction, deletion, restriction and portability; object to processing based on legitimate interests; and withdraw consent for future processing. You may also lodge a complaint with the Austrian Data Protection Authority.
Children
The app is not specifically directed at children. In Austria, consent for an information-society service can generally be given from age 14; below that age, parental authorization may be required. Provider-specific higher age limits described above continue to apply.
Changes and contact
This policy may change when the app or a connected service changes. The effective date appears at the top of the page. Questions and privacy requests can be sent to persie0@protonmail.com.