Privacy Policy
Last updated: 27 August 2026
This policy explains what LearnQuest collects, why, and what you can do about it. It describes the service as it actually works — if something here stops being true, the policy changes with it.
1. Who is responsible
LearnQuest is operated by:
Kristian Mandrup, trading as Blueforge Studio (enkeltmandsvirksomhed)
[c/o address — to be added]
[postcode and city], Denmark
CVR: [to be added on registration]
Privacy contact: privacy@blueforge.studio
Kristian Mandrup is the data controller for the personal data described below. There is no Data Protection Officer — one is not required at this scale — so privacy enquiries come to the address above and are answered by a person.
2. What we collect
What you give us
| Data | When | Why |
|---|---|---|
| Email address | When you create an account | To sign you in and contact you about your account |
| Display name | When you create an account | To show who is who inside a household |
| Household name | If you create a household | To group family members together |
| Names of household members | When you add someone | So each person's progress is their own |
That is the whole list. We do not ask for your date of birth, postal address, phone number, gender, photograph, contacts, or location.
What the app records as you use it
| Data | Where it is stored |
|---|---|
| Lesson progress, XP, streaks | On your own device, in your browser |
| Shared household goals and rewards | On our server, if you use household features |
| Subscription status | On our server, if you subscribe |
What we do not collect
- No voice recordings. Pronunciation is spoken by your own device using the browser's built-in speech engine. No audio is recorded, and nothing is sent anywhere to be spoken.
- No analytics or tracking. There are no third-party analytics tools, no advertising networks, no tracking pixels, and no cookies used to profile you.
- No data sent to AI providers. LearnQuest's lessons and artwork are produced with AI tools before the app ships. Nothing you type, answer, or get wrong is ever sent to an AI service.
3. Why we are allowed to hold it
| What | Legal basis (GDPR Article 6) |
|---|---|
| Your account and household | Performance of a contract — we cannot provide the service without them |
| Subscription and payment records | Performance of a contract, and a legal obligation to keep accounting records |
| Keeping the service secure and preventing abuse | Legitimate interests — running a service that is not broken by misuse |
We do not rely on consent for anything described here, because nothing here is optional to the service. If we ever add something that is optional, we will ask first and you will be able to say no.
4. Children
LearnQuest accounts are for adults. You must be 18 or over to create one.
Children use LearnQuest through a parent's or guardian's household, as a profile rather than an account. A child's profile has a display name and nothing else — no email address, no password, no login of their own. We do not know a child's age, and we do not ask.
The adult who created the household can see everything the profile records and can delete it at any time. Because a child never gives us their own data and never consents to anything, the consent rules for children in GDPR Article 8 do not arise.
If this ever changes — if children are able to hold their own accounts — this policy will change first, and we will say so clearly.
5. Who else sees your data
| Who | What they get | Why |
|---|---|---|
| Hetzner Online GmbH | Hosts our servers and database, in the EU | We need somewhere to run the service |
| Stripe | Your payment details, if you subscribe | To take payment. Card details go to Stripe directly and never reach our servers |
That is the complete list. We do not sell your data, share it with advertisers, or pass it to anyone else. If a court or a lawful authority compelled us to hand something over, we would comply — and tell you, unless legally prevented.
6. Where your data is
On servers in the European Union, hosted by Hetzner. Your personal data is not transferred outside the EU or the EEA.
Stripe processes payments and may handle payment data outside the EU under its own safeguards. That applies only if you subscribe, and only to payment information — never to your learning data.
7. How long we keep it
| Data | Kept for |
|---|---|
| Your account and household | As long as your account is active |
| Inactive accounts | Deleted after 24 months without a sign-in. We email you first |
| Progress stored on your device | Until you delete it or clear your browser |
| Backups | 30 days, then overwritten |
| Accounting and payment records | 5 years, as Danish bookkeeping law requires |
When you delete a household, everything in it — members, child profiles, goals, progress, and the household itself — is deleted from our database, not hidden or marked inactive. Accounting records are the one exception: the law requires us to keep them, and we are not permitted to delete them on request.
8. Your rights
Under the GDPR you can:
- See what we hold about you
- Correct anything that is wrong
- Delete your data — you can do this yourself from Settings, without asking us
- Restrict how we use it while a question is being resolved
- Take it with you in a portable format
- Object to processing we do on the basis of legitimate interests
To exercise any of these, email privacy@blueforge.studio. We will respond within one month. There is no charge.
We do not make any automated decisions about you, and we do not profile you.
9. Security
Data is encrypted in transit. Access to the production database is limited to the controller. Passwords are never stored in readable form.
We are a small operation and we do not pretend otherwise: there is no security team, and no system is perfectly safe. If a breach ever put your rights at risk, we would tell Datatilsynet within 72 hours and tell you without undue delay.
10. Complaints
If you think we have handled your data badly, please tell us first — privacy@blueforge.studio — and we will try to put it right.
You also have the right to complain to the Danish Data Protection Agency:
Datatilsynet
Carl Jacobsens Vej 35, 2500 Valby, Denmark
Datatilsynet
11. Changes to this policy
If we change anything that affects you, we will email you before it takes effect and post the change here with a new date. Minor corrections — a clearer sentence, a fixed typo — we will just make.