Privacy Policy
Mathedu.online · Last updated: 12 September 2026In short
We do not use Google Analytics or any advertising system. There is no cookie banner because there is nothing to consent to — we store nothing on your device that would require consent. We measure traffic with our own tool running on our server in Germany; it uses no cookies and does not follow you across other websites. Without an account, no data that could identify you ever reaches our server.
Below is the same thing in detail, including an exact list of what the app stores in your browser.
1. Who we are
Mathedu.online is operated by MB Market, s.r.o., the controller within the meaning of Art. 4(7) GDPR.
Full identification and contact details, including registered office, company number and commercial register entry, are in the legal notice.
For anything related to data protection, write to mbmarket491@gmail.com.
We have not appointed a Data Protection Officer — the conditions of Art. 37 GDPR are not met, as our core activity is not large-scale systematic monitoring and we do not process special categories of data.
2. What data we process
Mathedu.online is openly accessible. Registration is optional — every exercise and article works without an account.
Without an account
- Server logs — IP address, browser type and the address requested. Used solely to run the service, protect it from abuse and diagnose technical faults.
- Traffic measurement — page visited, country, device type, referring source. Details in section 6.
- Data in your browser — your answers and settings. These never leave your device unless you are signed in. See section 3.
With an account
- E-mail address — the only personal datum we ask for at registration. We do not collect name, date of birth or postal address.
- Password — stored only as a cryptographic hash (argon2id), never in readable form. Not even we can read it.
- Exercise results — exercise type, difficulty, correctness, time taken and when the answer was given.
- Answer content — for some exercises we also store the text of the question and of the answer, so that the history can be shown. If a child types anything else into the answer field, that is stored too. A single answer is capped at 6,000 characters.
We neither process nor request special categories of data under Art. 9 GDPR (health, religion, ethnicity and the like).
3. Data stored in your browser
The app keeps some things directly on your device. None of them requires consent — each is either strictly necessary or a setting you chose yourself.
| What | Where | Purpose | How long |
| `session` | cookie | keeps you signed in | 30 days from last visit |
| `app_lang` | cookie | chosen language | 1 year |
| `theme` | local storage | light or dark mode | until cleared |
| `matika-app-exercise-settings` | local storage | exercise settings | until cleared |
| `matika-app-statistics` | local storage | answer history and progress | until cleared |
| `matika-app-sync-queue` | local storage | queue of results waiting to reach your account | until sign-out |
| `matika-app-sync` | local storage | marker of which account last synchronised | until sign-out |
Two points deserve emphasis:
`matika-app-statistics` holds the complete answer history, including question text. It is true that, as far as our server is concerned, we collect nothing identifying without an account — but the device itself keeps a detailed record. Be aware of this on a shared or school computer. You clear it by clearing site data in your browser. `matika-app-sync` does not hold your account ID in readable form, only a short cryptographic fingerprint used purely for comparison. It is deleted along with the queue when you sign out; deleting your account also clears the answer history.4. Cookies
We use no cookies that would require consent — which is why you will find no cookie banner here.The `session` and `app_lang` cookies in the table above are strictly necessary for the service you asked for: the first keeps you signed in, the second remembers the language you chose yourself. Under Art. 5(3) of the ePrivacy Directive (and, for UK visitors, PECR) they are exempt from the consent requirement.
If an older `cookie_consent` cookie is still sitting in your browser from when the site used Google Analytics, it is no longer read or written and will expire on its own.
5. What we do not do
So it is clear what you will not find in this document:
- We use no Google Analytics, no Google Tag Manager and no other third-party measurement tool.
- We show no advertising and use no advertising identifiers.
- We do not track you across other websites and build no advertising profiles.
- We do not sell or share personal data.
- We load no fonts, stylesheets or scripts from third parties. Fonts and stylesheets are served from our own domain. The only script from another address is our own traffic measurement (section 6) — it runs on our server in Frankfurt, not with a service that would use the data for its own purposes.
6. Traffic measurement
We use Umami, an open-source tool we host ourselves on our own server in Frankfurt. The data goes to no third party.
Measurement is cookieless — nothing is written to your device. Returning visitors are recognised by a fingerprint computed on the server from a salt that changes once a month. Within a month we can therefore see that someone came back; once the salt rotates, the link is gone and old fingerprints lead to no one.
We collect: page visited, referring page, country, device type, browser and operating system. None of it leads to an individual.
The legal basis is legitimate interest under Art. 6(1)(f) GDPR — we need to know which exercises and articles are used in order to know what to add. Because the IP address is processed when computing the fingerprint, this is processing of personal data even though the result no longer points to a person. You may object at the contact address; any ordinary content blocker will also stop it, with no effect whatsoever on how the site works.
7. Children as users
Mathedu.online is written for children from roughly 5 to 15 years old, and we take that seriously.
Without an account we collect nothing that would identify an individual child, so neither Art. 8 GDPR nor the US COPPA applies. Exercises and articles are fully functional in this mode. The user account is intended for an adult — a parent or a teacher. By registering you confirm that you are at least 18 and that you are acting as a parent, legal guardian or teacher. Children appear under the account as profiles with a nickname; we collect neither a child's name nor their age.We chose this deliberately: the age at which a child can consent differs across our markets (Slovakia and Germany 16, Czechia 15, Spain 14, United Kingdom and USA 13), and an adult-held account is clearer for both child and parent than five different rules.
Because children are a vulnerable group, we treat their data more strictly: no advertising, no profiling, no disclosure to third parties for marketing, and no design patterns that nudge anyone into sharing more.
8. Legal bases
- Performance of a contract — Art. 6(1)(b): account, profiles, storing and synchronising results.
- Legitimate interest — Art. 6(1)(f): server logs (operation and security) and traffic measurement.
- Legal obligation — Art. 6(1)(c): accounting and tax records, where they arise.
We use consent as a legal basis nowhere — there is no occasion for it.
9. How long we keep data
| Data | How long |
| Account, profiles, exercise results | until you delete the account |
| Sign-ins (`sessions`) | 30 days from last visit, deleted daily after a 7-day grace period |
| Password reset tokens | 1 hour; once used, removed on the next daily run |
| Server logs | at most 30 days |
| Traffic measurement | at most 12 months, with no link to a person |
| Encrypted database backups | 14 daily and 8 weekly copies |
You delete your account and all its results yourself on your account page. It disappears from the live database immediately; it falls out of backups with their natural rotation, within 60 days at the latest.
10. Recipients
We pass data only to providers without which the service could not run. We have a processing agreement under Art. 28 GDPR with each of them.
| Recipient | What it processes | Where |
| Render Services, Inc. | application hosting, server logs | Frankfurt, Germany |
| Neon, Inc. | database of accounts and results | Frankfurt, Germany (AWS `eu-central-1`) |
| Resend, Inc. | e-mail address for password resets | USA |
| Cloudflare, Inc. | encrypted database backups | EU |
| GitHub, Inc. (Microsoft) | automation that creates the backups | USA |
We disclose data to no other third party unless required by law.
11. Transfers outside the EU
Servers and database sit in Frankfurt, so ordinary operation never leaves Europe. The providers listed are, however, US companies whose technical support may be able to access data. Transfers rely on the European Commission's Standard Contractual Clauses or on certification under the EU–U.S. Data Privacy Framework, and we have carried out a transfer impact assessment.
Specifically: database backups are created by automation running on GitHub's infrastructure in the USA. The data is encrypted there and then travels to European storage.
12. Your rights
As a data subject you have the right to:
- access your data (Art. 15),
- rectification of inaccurate data (Art. 16),
- erasure (Art. 17) — you delete the account yourself in account settings,
- restriction of processing (Art. 18),
- portability (Art. 20) — your account page has a Download my data button that immediately gives you everything we hold about you on the server as a JSON file,
- object to processing based on legitimate interest (Art. 21), that is, to traffic measurement and server logs,
- lodge a complaint with a supervisory authority (Art. 77).
Write to mbmarket491@gmail.com. We answer within one month. If we cannot grant a request, we will say why.
13. Supervisory authorities
You may complain in any Member State, in particular where you live. Our lead supervisory authority:
- Slovakia — Úrad na ochranu osobných údajov SR, dataprotection.gov.sk
Others that may apply:
- United Kingdom — Information Commissioner's Office, ico.org.uk
- Germany — the competent state data protection authority, or the BfDI, bfdi.bund.de
- Czechia — Úřad pro ochranu osobních údajů, uoou.cz
- Spain — Agencia Española de Protección de Datos, aepd.es
14. Visitors from the United Kingdom
Processing of UK residents' data is governed by the UK GDPR, with the ICO as supervisory authority. Because we use no cookies requiring consent, no obligation arises under PECR.
15. Visitors from the United States
We do not sell or share personal information within the meaning of the California CCPA/CPRA or comparable state laws. We show no targeted advertising and build no advertising profiles, so there is nothing to opt out of. You exercise access and deletion rights the same way as under the GDPR — at the contact address.16. Security
Connections are always encrypted (HTTPS) and passwords are stored as an argon2id hash. Database and backups are encrypted, backups additionally under their own key. The server sends security headers including a content security policy that restricts where anything may be loaded from. Only the operator has access to the production environment.
Should a personal data breach nonetheless occur that poses a risk to your rights, we will notify the supervisory authority within 72 hours and, where the risk is high, you directly.
17. Changes to this policy
We may update this policy, particularly as the service gains features. The current version is always on this page with the date it was last updated. Where a material change affects registered users, we will say so by e-mail.
18. Contact
MB Market, s.r.o.E-mail: mbmarket491@gmail.com
Identification details and registered office: legal notice