Zertifly Privacy Policy

Last updated: 29.06.2026

This Privacy Notice for Zertifly ("we", "us", or "our") describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our website (https://www.zertifly.com) and mobile application (together, the "Services"). Zertifly helps you prepare for the TestDaF exam through speaking, writing, listening, and reading practice with AI-driven analysis. If you do not agree with our policies and practices, please do not use our Services. If you have any questions, please contact us at info@zertifly.com.

1. What Information Do We Collect?

In Short: We collect personal information that you provide to us, and some information automatically.

We collect personal information that you voluntarily provide when you register on the Services, use our practice features, or contact us. The personal information we collect may include:

  • Names — provided when you create an account.
  • Email addresses — for account creation, email verification, and communication.
  • Authentication data — your password (stored only in hashed form) or your Google sign-in identifier.
  • Audio recordings — your voice recordings from speaking practice sessions.
  • Written submissions — texts you submit for writing practice, and the AI feedback generated from them.
  • Learning progress and activity data — your answers, scores, and performance on speaking, writing, listening, and reading exercises.

Sensitive Information

We do not process sensitive information.

Payment Data

If you purchase a subscription, the data necessary to process your payment is handled by Stripe. We do not store your full card number on our servers.

Social Media Login Data

If you choose to register using your Google account, we receive your name, email address, and basic profile information from Google.

Information Automatically Collected

Some information — such as your IP address, browser and device characteristics, operating system, language preferences, and usage patterns — is collected automatically when you visit or use our Services. In our mobile app, we also process a push notification token (see Section 8). This information does not, on its own, reveal your specific identity.

2. How Do We Use Your Information?

In Short: We process your information to provide, improve, and administer our Services, communicate with you, ensure security, and comply with law.

  • To create, authenticate, and manage your account.
  • To deliver and personalize our TestDaF preparation services, including AI analysis of your speaking and writing submissions.
  • To store your audio recordings and written submissions so you can review past sessions and track your progress.
  • To process payments and manage your subscription.
  • To send transactional emails such as email verification, password resets, security alerts, and receipts.
  • To send push notifications on the mobile app, such as practice reminders and account updates (with your permission).
  • To respond to your inquiries and provide support.
  • To improve our website, mobile app, and the quality of our AI features.
  • For fraud prevention and to keep our Services secure.
  • To comply with applicable legal obligations.

3. What Legal Bases Do We Rely On To Process Your Information?

In Short: We only process your personal information when we have a valid legal reason to do so.

Under the GDPR and UK GDPR, we rely on the following legal bases:

  • Consent (Art. 6(1)(a)). For analytics and any optional marketing communications. You can withdraw consent at any time.
  • Performance of a Contract (Art. 6(1)(b)). For account management, delivering our services, processing payments, and transactional communications.
  • Legitimate Interests (Art. 6(1)(f)). For improving our Services, securing them, and preventing fraud.
  • Legal Obligations (Art. 6(1)(c)). For retaining financial records as required by applicable law.

4. When And With Whom Do We Share Your Personal Information?

In Short: We may share information with third-party service providers who help us operate our Services.

The third parties we may share personal information with include:

  • AI Service Providers: OpenAI and Google (Gemini) — power Zertifly's AI evaluation and feedback features.
  • Cloud Database & Storage: Supabase — database and secure storage of your audio recordings.
  • Payments: Stripe — card payment processing.
  • Email: Google (Gmail SMTP) — delivery of transactional emails such as verification codes and notifications.
  • Push Notifications (Mobile): Expo push service, together with Apple Push Notification service (APNs) and Google Firebase Cloud Messaging (FCM), deliver notifications to your device.
  • Authentication: Google Sign-In.
  • Analytics: PostHog and Vercel Analytics — understanding product usage to improve our Services.
  • Website & App Hosting: Vercel.

Business Transfers. We may share or transfer your information in connection with any merger, sale of company assets, financing, or acquisition of our business.

We do not sell your personal information.

5. Do We Use Cookies And Other Tracking Technologies?

In Short: We use cookies and similar technologies to keep you signed in and to understand how our Services are used.

Cookie / StoragePurposeCategoryDuration
Authentication sessionKeeps you signed inEssentialUp to 30 days
CSRF tokenProtects against request forgeryEssentialSession
NEXT_LOCALERemembers your preferred languageEssential1 year
PostHogProduct analyticsAnalyticsUp to 1 year

Our mobile app loads the website inside a secure WebView and may use equivalent local storage to keep you signed in and remember your preferences.

6. Do We Offer Artificial Intelligence-Based Products?

In Short: Yes — we offer features powered by artificial intelligence.

We provide AI features through third-party providers, including OpenAI and Google. When you use our AI-powered features, your text submissions and/or voice recordings may be processed by these providers to generate feedback and responses.

Voice Recordings

During speaking practice, your voice is recorded so you can review your session afterward. Recordings are stored securely in Supabase Storage and processed by our AI providers for transcription and evaluation only. Your voice recordings are never used to train AI models, by us or our providers.

AI-generated content may contain errors and should be treated as a supplementary study tool.

7. How Do We Handle Your Social Logins?

In Short: If you log in using your Google account, we receive certain profile information about you.

Our Services let you register and log in using your Google account. The profile information we receive may include your name, email address, and profile picture. We use this information only for the purposes described in this notice.

8. Mobile Application

In Short: Our mobile app is a secure wrapper around our website, with native sign-in and push notifications.

Push Notifications

With your permission, we send push notifications such as practice reminders and account updates. To do this we register a device push token associated with your account and deliver notifications via the Expo push service, Apple Push Notification service (APNs), and Google Firebase Cloud Messaging (FCM). You can disable notifications at any time in your device settings. The token is removed when you log out, uninstall the app, or delete your account.

Permissions

The app requires internet access. For speaking practice, the app requests microphone access, which is used only to record your speaking responses. You can review and revoke these permissions at any time in your device settings.

In-App Purchases

Subscriptions are purchased through our website via Stripe. The app itself does not process separate in-app purchases.

9. Is Your Information Transferred Internationally?

In Short: We may store and process your information in countries other than your own.

Our Services are hosted and processed across the European Union and the United States. Where we transfer personal information internationally, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (SCCs), with providers including Vercel, OpenAI, Google, and Stripe.

10. How Long Do We Keep Your Information?

In Short: We keep your information only for as long as necessary for the purposes set out in this notice.

We keep your account data for as long as your account is active. When you request account deletion, your personal data (such as name, email, audio recordings, and written submissions) is permanently removed in accordance with your right to erasure under the GDPR.

Audio recordings and written submissions are retained on your account so you can review past sessions and track progress, and are permanently deleted when you delete your account. You can also request deletion at any time by contacting us.

Push notification tokens are retained while your account is active and the device is registered, and are removed when you log out, uninstall the app, or delete your account.

Financial records. Transaction records and invoices may be retained for the period required by applicable law.

11. How Do We Keep Your Information Safe?

In Short: We protect your information through organisational and technical security measures.

We have implemented appropriate technical and organisational security measures designed to protect the personal information we process, including secure storage of audio recordings and hashing of passwords. However, no electronic transmission over the Internet can be guaranteed to be 100% secure.

12. Do We Collect Information From Minors?

In Short: We do not knowingly collect data from children under 16.

We do not knowingly collect data from or market to children under 16 years of age. If you are under 18, you should use the Services only with the involvement and consent of a parent or guardian. If we learn that we have collected personal information from a child without appropriate consent, we will delete it.

13. What Are Your Privacy Rights?

In Short: In some regions you have rights that give you greater access to and control over your personal information.

Depending on your location (for example, the EEA, UK, or Switzerland), you may have the following rights under applicable data protection law (including the GDPR, UK GDPR, and the Data Protection Act 2018):

  • To request access to, and obtain a copy of, your personal information.
  • To request rectification or erasure of your personal information.
  • To restrict or object to the processing of your personal information.
  • To data portability.
  • To withdraw consent at any time where we rely on consent.

To review, update, or delete your account, you can use your account settings or contact us. If you believe we are unlawfully processing your personal information, you also have the right to complain to your local data protection authority.

14. Controls For Do-Not-Track Features

Most browsers and some mobile operating systems include a Do-Not-Track ("DNT") feature. As no uniform technology standard for recognising DNT signals has been finalised, we do not currently respond to DNT browser signals.

15. Do We Make Updates To This Notice?

In Short: Yes — we will update this notice as necessary to stay compliant with relevant laws.

We may update this Privacy Notice from time to time. The updated version will be indicated by an updated "Last updated" date at the top of this notice.

16. How Can You Contact Us About This Notice?

If you have questions or comments about this notice, you may email us at info@zertifly.com.
ZERTIFLY LTD (registered in England and Wales)