Struct Logo
Struct
Back

Privacy Policy

1. Data Controller

The party responsible for processing personal data on this website is: Simon Wachowitz Rostocker Straße 15 63322 Rödermark Email: struct.today@gmail.com

We have not appointed a data protection officer, as there is no legal obligation to do so under Art. 37 GDPR or Section 38 BDSG. For all questions regarding data protection, you may contact the responsible party named above directly.

2. General Information and Data Security

The protection of your personal data is important to us. We process personal data exclusively in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the German Telecommunications Digital Services Data Protection Act (TDDDG). Personal data is any information relating to an identified or identifiable natural person. Data transmission between your device and our servers is encrypted via a secure TLS connection (recognizable by the "https://" in the address bar). We also take technical and organizational security measures to protect your data against accidental or unlawful processing, loss, and unauthorized access. Please note that, despite all care, data transmission over the internet can have security gaps; complete protection against access by third parties is not possible.

3. Collection and Storage of User Data

When you register in our app, we store the email address you provide, your password (exclusively in encrypted or hashed form), and the app-specific data you create (e.g. modules, grades, study times, timetables, notes, flashcards, and similar content) in order to provide the study-planner functionality. Processing of this data is carried out on the basis of Art. 6 (1) (b) GDPR (performance of the usage contract) and is technically necessary to provide the app. Providing this data is voluntary; however, without a user account and the associated data, the app's personalized functions cannot be provided. We store your account and content data for as long as your user account exists. If you delete your account, the associated personal data is deleted, unless statutory retention obligations (e.g. under commercial or tax law for payment transactions) require otherwise. To ensure stable operation and improve the app, we also record simple usage events in our own database (pages visited and technical errors that occur) together with your user account and the platform used (web, iOS, or Android). This data remains entirely with us, is not shared with third parties, and is not used for advertising. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in the stability and further development of the app).

4. Server Log Files

When you access our application, the infrastructure of our hosting provider automatically processes technical access data in so-called server log files. This typically includes: the IP address of the requesting device, the date and time of access, the address/file accessed, the HTTP status code, the amount of data transferred, the browser type and operating system used, and the previously visited page (referrer), insofar as transmitted. This data is technically necessary to deliver the application, ensure the stability and security of the system (e.g. defending against attacks), and analyze errors. Processing is based on Art. 6 (1) (f) GDPR; our legitimate interest lies in the secure and stable operation of the application. The log files are stored only as long as necessary for these purposes and are then deleted or anonymized.

5. Cookies, Local Storage, and Similar Technologies

Our application stores certain information on your device or accesses it. In doing so, we use exclusively technically necessary technologies that are required for the operation of the app and for functions you have expressly requested (e.g. login and payment). We do not use any cookies or comparable technologies for analytics, tracking, profiling, or advertising purposes, and we do not integrate any corresponding third-party services (e.g. Google Analytics, advertising networks). Since this storage is strictly necessary within the meaning of Section 25 (2) TDDDG in order to provide the service you have expressly requested, no consent is required for it; for this reason we also do not display a cookie banner. Specifically, this concerns:

Local Browser Storage (localStorage)

Our app stores some data locally in your browser (localStorage and IndexedDB) so the application works and your settings persist, such as your language preference, the selected theme, your login session (auth token), onboarding progress, and cached content such as fonts for the notes feature. This data stays on your device and is not transmitted to third parties for advertising or analytics. You can delete it at any time by logging out or clearing the browser data for this site. Storage is based on Art. 6 (1) (f) GDPR and is technically necessary for operating the app.

Functional cookie "sidebar_state"

This technically necessary cookie is set on our own domain (first-party) and merely stores whether the side navigation bar is expanded or collapsed, so that your view is retained on your next visit. It contains no personal content and has a storage period of 7 days. The legal basis is Art. 6 (1) (f) GDPR in conjunction with Section 25 (2) no. 2 TDDDG.

Stripe cookies (fraud prevention during payment)

When you start the Premium purchase, Stripe's payment library (Stripe.js) is loaded on the payment page. Stripe sets its own cookies (e.g. "__stripe_mid" with a lifetime of up to one year and "__stripe_sid" with a lifetime of approx. 30 minutes). These serve exclusively for security and fraud prevention by recognizing the device used during payment. They are only loaded when you actively initiate a payment and are necessary for its secure execution. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (f) GDPR (fraud prevention) in conjunction with Section 25 (2) no. 2 TDDDG. Further information can be found in Stripe's privacy policy (see the "Stripe" section below).

6. Use of Service Providers (Data Processing)

To provide our app securely and performantly we use specialized third-party providers, to whom data is transferred as part of using the app:

Supabase (Hosting, Database & Authentication)

We use the Supabase service for our backend infrastructure, database, and login process. The provider is Supabase, Inc., 972 Mission St, San Francisco, CA 94103, USA. When you use our app, the data you enter and technical log data are processed and stored on Supabase's servers. Supabase uses industry-standard encryption. We have entered into a Data Processing Agreement (DPA) with the provider ensuring that your data is processed only on our instructions and in compliance with the GDPR. If you use the optional sign-in with your Google account (Google OAuth), the data required for login (in particular your email address) is exchanged between Google and our authentication service; the provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Using Google sign-in is voluntary; signing in with email and password is available as an alternative.

Stripe (Payment Processing)

If you choose to purchase our Premium version, payment processing is handled by the payment service provider Stripe. The provider for users within the EU is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. When you make a purchase, the data required for payment processing (such as name, email address, credit-card details) is processed directly via Stripe's servers. We ourselves do not store any complete payment data (e.g. credit-card numbers) in our database. Processing is carried out on the basis of Art. 6 (1) (b) GDPR (performance of a contract). For more information on data protection at Stripe, see: https://stripe.com/de/privacy.

Google Gemini (AI Features)

For our AI-powered features (e.g. AI flashcards, AI study notes, AI mock exams, AI study plan, AI modules, and AI timetable) we use Google's Gemini API. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (for users within the EU), potentially involving Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. When you use an AI feature, the content you provide (e.g. uploaded PDF lecture materials or text input) is transmitted to and processed on Google's servers to generate the respective result. This may involve a transfer to the USA, carried out on the basis of appropriate safeguards under Art. 44 et seq. GDPR (in particular the EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework). Please do not upload any especially sensitive personal data into the AI features. For more information on data protection at Google, see: https://policies.google.com/privacy.

Resend (Email Delivery)

For sending transactional emails (e.g. confirming your email address, login links, and password resets) we use the service Resend. The provider is Resend (Plus Five Five, Inc.), USA. Your email address and technical send metadata (timestamp, message type, delivery status) are transmitted to Resend. We retain these send logs for a maximum of 90 days for troubleshooting and then delete them automatically. Processing is based on Art. 6 (1) (b) and (f) GDPR. Any transfer to the USA is carried out on the basis of appropriate safeguards under Art. 44 et seq. GDPR. For more information, see: https://resend.com/legal/privacy-policy.

7. Transfers to Third Countries

Some of the service providers we use (see above) are based in the USA or process data partly there. In these cases, personal data may be transferred to a third country outside the EU/EEA. Such a transfer only takes place in compliance with the requirements of Art. 44 et seq. GDPR, in particular on the basis of appropriate safeguards such as the EU Standard Contractual Clauses and/or, insofar as the respective provider is certified, on the basis of the EU-US Data Privacy Framework (adequacy decision of the EU Commission). In third countries, a level of data protection comparable to European law may not exist; in particular, government authorities may under certain circumstances be able to access data. Further information on the respective safeguards is available on request at the address stated in the legal notice.

8. Storage Period

As a rule, we store personal data only for as long as is necessary for the respective purposes. Account and content data is stored for as long as your user account exists and is removed after its deletion. Email send logs at our delivery provider are stored for a maximum of 90 days. Server log files are only kept for a short time for security and stability purposes. Where statutory retention periods exist (e.g. commercial or tax law obligations of up to 10 years for payment and invoice data), the data concerned is retained until these periods expire and its processing is restricted during this time.

9. Rights of the Data Subject

With regard to the processing of your personal data, you have the following rights as a data subject:

  • Right of access (Art. 15 GDPR): You may request confirmation of whether and which personal data we process about you, as well as a free copy of this data and information about its origin, recipients, and the purpose of processing.
  • Right to rectification (Art. 16 GDPR): You have the right to request the correction of inaccurate personal data or the completion of the personal data we have stored about you.
  • Right to erasure (Art. 17 GDPR): You may request the deletion of your personal data, unless processing is required to comply with a legal obligation, for reasons of public interest, or for the assertion of legal claims.
  • Right to restriction of processing (Art. 18 GDPR): You have the right to request the restriction of the processing of your personal data, for example for the duration of a review if you dispute the accuracy of the data.
  • Right to data portability (Art. 20 GDPR): You have the right to receive the data concerning you that you have provided to us in a structured, commonly used, and machine-readable format, or to request its transmission to another controller.
  • Right to object (Art. 21 GDPR): Insofar as we process your data on the basis of legitimate interests (Art. 6 (1) (f) GDPR), you have the right to object to this processing at any time for reasons arising from your particular situation.
  • Right to withdraw consent (Art. 7 (3) GDPR): Where processing is based on your consent, you may withdraw it at any time with effect for the future, without affecting the lawfulness of processing carried out up to the point of withdrawal.
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): Without prejudice to any other legal remedy, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR. You may contact the supervisory authority of your habitual residence, place of work, or the place of the alleged infringement. The competent authority for the controller is the Hessian Commissioner for Data Protection and Freedom of Information (Postfach 3163, 65021 Wiesbaden, Germany).

To exercise these rights and for any further questions regarding data protection, you may contact us informally at any time at the address provided in the "Data Controller" section or in the legal notice. Exercising your rights is generally free of charge for you.

10. Validity and Changes to this Privacy Policy

This privacy policy is currently valid. Due to the further development of our application or because of changed legal or regulatory requirements, it may become necessary to amend this privacy policy. The current version can be accessed at any time on this page.

Last updated: July 2026.