Privacy Policy
What data Olauda processes, why, and what rights you have.
Overview
This privacy policy covers the website olauda.com and the app at app.olauda.com. It explains which personal data we process, why we need it, how long we keep it and what rights you have.
Last updated: October 9, 2026
Controller
The controller responsible for data processing is Deniz Keskin, Berlin, Germany. You can reach us by email at kontakt@olauda.com.
Olauda is a private, non-commercial project. We do not sell data, show ads or share data for advertising.
Visiting the website and app
When you open the website or the app, our server processes your IP address, the date and time, the requested address and your browser identifier (user agent). Without this data we cannot deliver the pages or fend off attacks.
So that nobody can guess passwords and two-factor codes or use us to send mass emails, we limit the number of requests per IP address, and per network (/64 prefix) for IPv6. The counters for this are kept in memory only and expire after a short time.
Our servers and database are operated for us by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in data centres in Germany. Hetzner processes the data on our behalf.
The legal basis is our legitimate interest in a secure and working service (Art. 6(1)(f) GDPR).
Your account
To create an account we need your email address and a password. We only store a hash of your password (Argon2), never the password itself. We also store for your account:
- your settings (language, colour scheme, personalisation) and your course selection,
- when you registered and when you last signed in,
- whether two-factor authentication is enabled, the secret it needs (encrypted) and your recovery codes (as a hash only), each with when they were created and used,
- your passkeys: their public key, identifier and name, and when they were added and last used. The private key never leaves your device,
- if you sign in with Google, your Google account ID and that Google account's email address.
We only send you emails your account needs: the confirmation code after registration, codes to reset or set your password, and security notices whenever the protection of your account changes, for example when your password is changed, two-factor authentication is turned on or off, or a passkey or Google account is added or removed. We do not send newsletters or ads.
We cannot create an account without an email address. The legal basis is the performance of our terms of use (Art. 6(1)(b) GDPR).
Groups and content
In groups we process the content you and other members create: tasks and exams with descriptions, images and files, announcements, timetables and substitutions, and chat messages. We also store your membership, your role and when you last opened the group, so we can show you what is new.
Other members only see you under a randomly generated name, not your email address. They do see everything you post in the group.
We store private tasks encrypted (AES-256-GCM). Encryption happens on our server: it protects the data in the database but is not end-to-end encryption.
The legal basis is the performance of our terms of use (Art. 6(1)(b) GDPR).
Images and files
Images and files you attach to tasks, and group pictures, are stored with Cloudinary Inc. (USA). When you upload a file, our server first checks its type and size and only then passes it on to Cloudinary. Each file can be opened via a randomly generated address; anyone who knows that address can open the file. Files that are no longer used, for example because the task was deleted or the group picture replaced, are deleted automatically, within about a day.
Cloudinary processes the data on our behalf. The transfer to the USA is based on the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework, under which Cloudinary is certified (Art. 45 GDPR).
Previews of Office files
Word, PowerPoint and Excel files attached to tasks are displayed in the app with Microsoft's Office viewer (Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland). When you open such a file, your browser loads the preview from Microsoft's servers. Microsoft receives your IP address, your browser's identifier and the address of the file, and fetches the file itself to display it.
Microsoft processes this data as an independent controller; Microsoft's privacy statement applies. Data may be transferred to Microsoft Corporation in the USA, which is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR).
The legal basis is our legitimate interest in displaying documents directly in the app, without you having to download them and have suitable software installed (Art. 6(1)(f) GDPR). Images and PDF files are displayed without Microsoft.
Sending emails
We send emails via Resend, Inc. (USA). Resend receives your email address and the content of the email. Resend processes the data on our behalf and is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR).
Sign in with Google
You can register and sign in with your Google account. We then redirect you to Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Google sends us your Google account ID, your email address and whether Google has verified it. We do not request any other data.
What Google processes during sign-in is governed by Google's own privacy policy. Data may be transferred to Google LLC in the USA, which is certified under the EU-U.S. Data Privacy Framework.
Signing in with Google is optional; you can just as well register with an email address and password. The legal basis is Art. 6(1)(b) GDPR.
Sign-ins and security
To protect your account and the service, we store:
- for each sign-in (session) the IP address, browser identifier and timestamps. In your account settings we use this to show your signed-in devices with an approximate location. We determine the location with a database on our own server and do not pass your IP address on for this;
- a security log with IP address and browser identifier: sign-ins, failed sign-in attempts and sign-outs, changes to your password, passkeys, two-factor authentication and Google link, the export and deletion of your account, the creation and deletion of groups, invites, changes to memberships, roles and group permissions, and every action by admins.
This lets us detect and prevent abuse and unauthorised access. The legal basis is our legitimate interest in the security of the service (Art. 6(1)(f) GDPR).
This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.
Activity log
We log which actions happen in your account, for example opening the app (with browser identifier), creating, editing or checking off tasks, and changes to settings. We only store the type, time and IDs of the affected entries, not their content.
We use the log to investigate errors and abuse and to see how many people use the service. Only we as operators can view it. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).
Reports
When you report a task or message, we store the reported content, your reason, your email address and the email address of the person who created the content. This lets us review the report and follow up if needed. The legal basis is our legitimate interest in a safe service (Art. 6(1)(f) GDPR).
Audience measurement
To understand which pages are used, we use Umami Cloud (Umami Software, Inc., USA) on the website and in the app. The data is stored on servers in the EU (Germany).
Umami records the page visited and its title, the referring page, browser, operating system, device type, screen size, language and country. In the app we first remove query parameters and the secret part of invite links.
Umami does not set cookies or track you across other websites; according to Umami, your IP address is not stored. We only see aggregated statistics.
The legal basis is our legitimate interest in improving our service (Art. 6(1)(f) GDPR). You can object at any time.
Cookies and local storage
We only use cookies and local storage that are technically necessary or that store a setting you chose (Section 25(2) no. 2 TDDDG). We do not use tracking or advertising cookies.
- App, sign-in: access_token (15 minutes), refresh_token (7 days), csrf_token (30 days, protection against forged requests), mfa_pending_token (5 minutes, during the two-factor prompt), oauth_state_token and oauth_pending_token (10 and 15 minutes, during sign-in with Google).
- App, local browser storage: language, colour scheme, time of the last session renewal and, until you are signed in, an opened invite link (at most 24 hours).
- Website: i18n_locale (language, 1 year), nuxt-homepage-color-mode (colour scheme, 1 year), cookie_notice_dismissed (notice closed, 180 days).
Retention
- We keep account data until you delete your account.
- We delete unconfirmed sign-ups once their confirmation code has expired after 2 days.
- Codes to reset or set your password are valid for 30 minutes. We delete them after 24 hours; until then, we use them to limit how many codes an email address receives.
- We delete session data with IP address and browser identifier about 7 days after it was last used.
- We delete the activity log after 30 days and the security log after 90 days. Attacks on an account are often noticed only weeks later, so we keep it longer.
- We delete chat messages automatically after 7 days.
- We delete tasks and exams in groups automatically 90 days after their due date.
- We delete schedule changes such as substitutions and cancellations automatically 90 days after the day they apply to.
- We keep reports until we have handled them.
- All other group content is kept until you, the group admins or we delete it, or the group is deleted.
Deleting your account
You can delete your account at any time in your account settings. If you own a group, you need to transfer or delete it first.
On deletion we immediately remove your account data, sessions, group memberships, chat messages, private tasks, your Google link and your activity log.
Tasks and announcements you created in groups remain available to the group but are no longer linked to your account. Security log entries are deleted once their 90-day period ends, reports once they have been handled.
Your rights
Under the GDPR you have the right to:
- access the data we hold about you (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure of your data (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- object to processing based on our legitimate interest (Art. 21 GDPR).
You can download a copy of all data for your account yourself at any time in your account settings under "Account" as a ZIP file. It contains your data in a machine-readable format (JSON) and the information required by Art. 15 GDPR.
For anything else, email us at kontakt@olauda.com.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), Alt-Moabit 59–61, 10555 Berlin, Germany.
We do not use automated decision-making or profiling.
Changes
We update this privacy policy when the service or the law changes. You can always find the current version on this page.