Privacy Policy

Last updated: 23 July 2026. Effective for accounts created on or after this date.

What we collect

When you create an account: your username, email address, and password (stored as an irreversible hash โ€” we never see or store your actual password). You can optionally add your birth year, used only to compare your results against others in a similar age range, a feature built on top of this field.

As you train: every trial you complete (which exercise, the difficulty level, whether you got it right, how long you took, and exercise-specific details like which flag or word was shown), your session history, your current level and streak on each exercise, your monthly assessment scores, and โ€” for World Flags specifically โ€” which items you've learned and when each is next due for review.

If you build a memory palace: the labels you give each station. These are free text you write yourself, and if you name real, personally significant places โ€” a childhood home, an old address โ€” that's information about you, stored as you entered it. We don't use it for anything beyond displaying it back to you during that exercise.

Technical data: a session cookie and a CSRF-protection cookie, both strictly necessary to keep you logged in and the site secure. Neither is used for tracking or advertising, and we don't currently use any analytics, advertising cookies, or third-party trackers on this site.

Why we process it

To provide the service you've signed up for: running exercises, adapting their difficulty to you, tracking your progress, and showing you your assessment history. This is processing necessary to perform our contract with you as a user (GDPR Article 6(1)(b)). Where we look at aggregated, de-identified trial data to improve the exercises themselves, that's on the basis of our legitimate interest in making the product better (Article 6(1)(f)), and it's never used to identify you individually.

Who we share it with

Our hosting provider, to run the servers this site runs on. Once we enable a dedicated email service for password resets and account emails, that provider will process your email address for that purpose alone. If we introduce paid subscriptions, a payment processor will handle your payment details directly โ€” we won't see or store your card details ourselves. We do not sell your data, and we do not share it with advertisers.

Where it's stored

On servers located in the European Union. We don't currently transfer your data outside the EU/EEA; if that ever changes, we'll update this policy and rely only on a legally recognized transfer mechanism.

How long we keep it

For as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where we're legally required to retain something longer โ€” for example, financial records, once paid subscriptions exist.

Your rights

Under GDPR, you can ask us to: show you what we hold about you, correct anything inaccurate, delete your data, export it in a portable format, or restrict or object to specific processing. Email info@skjerp.com for any of these, and we'll respond within the timeframes GDPR requires. If you're not satisfied with our response, you can complain to Denmark's data protection authority, Datatilsynet.

Children

In line with Danish law, you must be at least 13 years old to create an account without a parent or guardian's consent. If you're between 13 and 17, we'd encourage you to involve a parent or guardian, particularly if paid features are ever introduced.

Changes to this policy

If we make a material change, we'll post the update here and, where required, notify you directly.

Contact

Questions about this policy or your data: info@skjerp.com.