Privacy Policy

What we collect, why we collect it, who else sees it, and what you can ask us to do about it.

Last updated 2026-09-09

Who is responsible

Nikulás Óskarsson, trading as Nikulás Software (CVR 46354389), registered in Denmark, is the data controller for the personal data described here. Nikulás Software is a sole proprietorship, so the controller is Nikulás Óskarsson personally. The service itself is My Danish Tutor, at my-danish-tutor.com.

For anything in this policy — including any of the requests listed under Your rights — email nikulas@my-danish-tutor.com.

What we collect, and why

Your account. Your email address, your name, and your password. The password is stored only as a bcrypt hash — we cannot read it, and nor can anyone who obtains the database. We also record when you confirmed your email address.

How you found us. Which button you signed up from and which page you were on. This tells us which parts of the site are worth writing more of.

Your learning. Which exercises you complete and how you answered them, your daily activity and streaks, exercises and words you save, decks and exams you build, and your progress through guided lessons. We also record the reason you give for learning Danish in the welcome screen. This helps us decide what to build and write next.

Feedback you send. Your message, the page you sent it from, and your IP address.

Email preferences. Whether and when you opted into product emails, which consent wording you saw, whether you turned practice reminders on, and when we last sent you one.

Your IP address when you create an account or send feedback, used only to limit how fast either can be done repeatedly.

We do not collect anything else. No advertising identifiers, no cross-site tracking, no data bought from or sold to anyone.

Our legal basis

Performing our contract with you (GDPR Art 6(1)(b)) covers your account and all of your learning data. You asked us to teach you Danish and remember your progress; this is us doing that.

Our legitimate interests (Art 6(1)(f)) cover the IP addresses used for rate limiting, and confirming that an email address belongs to the person using it. The interest is keeping accounts and other people's email addresses safe from abuse, and we keep only what that needs.

Your consent (Art 6(1)(a)) covers practice reminder emails and the separate optional product emails. You give product-email consent for roughly weekly learning tips and new exercises by ticking the unchecked box at signup, and reminder consent by switching reminders on in settings. You can withdraw either at any time in settings, and reminders also include an unsubscribe link. Withdrawing is as easy as giving consent and costs you nothing else.

Emails about your account itself — confirming your address, resetting your password — are part of the contract, not marketing. They have no unsubscribe link because you cannot opt out of a password reset.

Who else sees it

Three suppliers process data on our behalf, each under a data processing agreement, and none of them may use it for their own purposes:

  • DigitalOcean — hosting, the database, and audio file storage. All of it in their Frankfurt region.
  • Mailgun — sending the emails described above, via their EU region.
  • Umami — website analytics. It records page views and where visitors arrived from, without cookies and without any identifier that could single you out or follow you between sites.

Your account, your learning data and your email are stored in the EU. Analytics are the one exception: they are handled by Umami Cloud, and they contain no account data — no name, no email, nothing that links a visit back to you.

How long we keep it

  • Your account and learning data — for as long as the account exists. Delete the account and it goes with it.
  • Accounts that never confirm their email — after 14 days the account stops saving new progress until the address is confirmed. We do not currently delete these automatically; email us and we will remove one on request.
  • IP addresses90 days, then automatically erased.
  • Email confirmation and password reset links — 7 days and 1 hour respectively, and each works only once.
  • Feedback — kept so we can act on it, and no longer linked to you if you delete your account.

Cookies

We set two, both strictly necessary, and neither requires your consent: one that keeps you logged in, and one that remembers you dismissed a sign-up prompt so we stop showing it.

We use no analytics, advertising or tracking cookies. That is why you are not being asked to accept anything.

Your rights

Under GDPR you can ask us to:

  • give you a copy of your data, in a portable format (Art 15, 20)
  • correct anything wrong (Art 16)
  • delete your account and everything in it (Art 17)
  • restrict or object to how we use it (Art 18, 21)
  • withdraw either email consent (Art 7(3))

You can delete your account and export your data yourself from settings. For anything else, email us — we will respond within a month, free of charge.

If you think we have handled your data badly, you can complain to Datatilsynet, the Danish data protection authority. We would rather you told us first, but you are not required to.

Automated decisions

Which exercise we show you next is chosen by straightforward rules based on what you have already done. It has no legal or otherwise significant effect on you, and there is no profiling in the sense of Art 22.

Children

You need to be at least 13 to have an account, which is the age of digital consent in Denmark. We do not knowingly collect data from anyone younger; if you believe we have, email us and we will delete it.

Changes

If we change how we use your data in any way that affects you, we will email you before it takes effect rather than quietly updating this page. The date at the top always reflects the current version.