Version 2.0.0 · effective 12 September 2026 · earlier versions
This policy says what Erudia collects, why, who receives it, how long we keep it, and what you can do about it. We do not sell personal data, we do not run advertising, and we do not track you across other sites.
Erudia is operated by an individual based in Chicago, Illinois, United States. The operating entity and its postal address will be named here when it is formed. Contact for anything in this policy: erudia@erudia.org.
We have not appointed a representative in the European Union.
We have not appointed a representative in the United Kingdom.
We do not collect health data, precise location, biometric identifiers, or anything about you from other companies.
Everything above comes from you or from your use of the service. Running your account, syncing progress, scheduling reviews and processing subscriptions are necessary to provide the service you asked for. Measuring the learning engine with learning events is our legitimate interest in making it work, and you can object. Analytics cookies run only with your consent. Where you live may give these bases specific legal names; section 8 lists them.
We use a small set of providers to run Erudia. Each receives only what its job needs.
Other learners see your display name, country and community content if you choose to take part. We disclose data when the law requires it, to defend a legal claim, or to a successor that takes over the service, who is bound by this policy. We do not sell it, share it for advertising, or give it to data brokers.
Each category has a period, and a job runs monthly to enforce it.
| what | kept for | then |
|---|---|---|
| Your account: email, hashed password, display name, country, birth month and year, subscription status | while your account is open | deleted when you delete your account (all tables, immediately) |
| Learning progress and review state | while your account is open | deleted with the account |
| Per-question learning events | 24 months from the event | deleted by the monthly retention job; older rows survive only as aggregate counts with no user id |
| Records of which version of the terms you accepted, and when | while your account is open, then 6 years | kept after deletion with your user id replaced by a one-way hash of your email, as evidence of the contract |
| Privacy requests, copyright notices, dispute notices, arbitration opt-outs | 6 years from closure | deleted by the retention job |
| Checkout attempt counters (rate limiting) | 30 days | deleted by the retention job |
| Duel queue entries | 24 hours | deleted by the retention job |
| Duel and graph-duel match records | 24 months | deleted by the retention job |
| Admin and moderation audit log | 36 months | deleted by the retention job |
| Database backups | rolling; each backup is discarded within 30 days | a deleted account leaves every backup within that window |
You can do most of this yourself in Settings: change your name and country, export everything as a JSON file, and delete your account, which erases every table immediately. For anything else, use the privacy request desk or email erudia@erudia.org. You can ask us to:
We verify a request by a reply from the email address on the account, or, for a request about someone else's data, by asking for enough information to show you are entitled to make it. We answer within 30 days, or sooner where the law says so: one month, extendable by two months for complex requests (GDPR Art. 12(3)) in the European Union; one month; the clock stops while we wait for identity information you have been asked for (UK Data (Use and Access) Act 2025) in the United Kingdom; 45 days, extendable once by 45 days (CCPA) in California. There is no charge.
Do Not Track and Global Privacy Control. We do not sell or share data, so those signals change nothing about how we treat you. We honour them by doing what we already do.
Erudia keeps your progress and your sign-in in your browser's local storage, which is essential and always on. Analytics cookies are set only if you accept them in the banner, which defaults to declined; you can decline without losing anything. Every cookie and stored key, its purpose and its lifetime is listed in the Cookie and Storage Notice.
European Union and United Kingdom. If the GDPR or UK GDPR applies to you, the bases in section 3 are: contract (Article 6(1)(b)) for running the service; legitimate interest (Article 6(1)(f)) for measuring the engine, which you may object to; consent (Article 6(1)(a)) for analytics cookies. You have the rights in section 6 and the right to complain to your supervisory authority. Our providers are in the United States; transfers rest on the standard contractual clauses in their terms. If you are under the age of digital consent where you live (between 13 and 16 across the EU), consent-based processing needs a parent's agreement; we ask for none, because analytics consent is off by default and everything else rests on contract.
California. This policy is our notice at collection. Categories collected: identifiers, account and learning data, internet activity, and, for known children, age. We do not sell or share personal information, and we have no "Do Not Sell or Share" link because there is nothing to opt out of. You may request access, deletion and correction as in section 6, and we do not discriminate for exercising a right. The California Consumer Privacy Act's thresholds do not currently apply to a business of our size; we honour these rights regardless.
Other US states. The state privacy laws with size thresholds do not currently apply to us. We honour access, correction and deletion requests from anyone, and we tell you in the request desk which deadline applies.
Canada. We handle personal information under PIPEDA's fair-information principles. We send no marketing email without your express consent or a purchase in the last two years, and every message carries an unsubscribe link.
Brazil. We process your data under the LGPD's contract and legitimate-interest bases and honour the rights in section 6. We have not appointed a Brazilian officer; contact erudia@erudia.org.
Australia. We are a small business under the Privacy Act's threshold and follow the Australian Privacy Principles as a matter of policy.
Erudia is for learners 13 and older. We ask your birth month and year before we collect anything else. A learner under 13 can use the lessons as a guest, with nothing stored beyond their own device, and cannot create an account, choose a display name, appear on a leaderboard or post to the community. If we learn that an account belongs to someone under 13, we stop syncing it and follow the Children's Privacy Notice, which tells a parent how to consent or delete. If you believe a child under 13 has an account, email erudia@erudia.org.
Data travels over TLS. Access is restricted at the database level with row-level security, so your row is readable only by you and by the service that needs it. Scripts we load from other domains are pinned by hash. We keep a written security programme with a named coordinator and an annual review. If a breach puts your data at risk we will tell you and the authorities the law names, within the time the law sets, and no later than 30 days after we find out.
When this policy changes in a way that matters, we tell you 30 days ahead by email and in the app and ask you to accept again; the version line at the top shows the date. A change to how we use data never applies to data already collected without your agreement.
Questions or requests: erudia@erudia.org · Privacy request desk