Privacy Policy
Last updated: August 2026
1. Controller
The controller responsible for processing your personal data pursuant to Art. 4(7) GDPR is:
WebUp GbR
Aaron Vermeulen
Auf der Höhe 3a, 78576 Emmingen-Liptingen, Germany
Email: contact@schedlr.de
2. Data We Collect and Why
2.1 Account Data
When you register, we collect your email address and a password (stored in hashed form only — we never see your plaintext password). This data is required to create and manage your account.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
2.2 User Profile Data
During onboarding you provide optional profile data such as your target exam date, preferred study schedule, and module priorities. This data is used exclusively to generate and personalise your study plan.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
2.3 Training & Performance Data
When you use the app, we record your module results, scores, and session timestamps. This data powers your analytics dashboard and readiness score, and is stored only in your account.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
2.4 Payment Data
SCHEDLR does not collect or store payment information itself. When you purchase a Pass you are redirected to Stripe, who processes the payment. We only receive a confirmation of successful payment and your Stripe customer reference. See Section 4.3 for details on Stripe.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
2.5 Contact Messages
When you use our contact form, we process your email address, subject, and message so that we can answer your request. Cloudflare Turnstile also processes technical connection and browser data to protect the form from automated abuse.
Legal basis: Art. 6(1)(b) GDPR for contract-related enquiries and Art. 6(1)(f) GDPR for abuse prevention.
2.6 Server & Access Logs
Our hosting provider (Vercel) automatically records standard server log data including IP addresses, request timestamps, pages accessed, and browser type. These logs are used exclusively for security monitoring and are retained for a maximum of 30 days.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in operating a secure service.
3. Cookies
SCHEDLR uses technically necessary cookies to keep you logged in during your session (authentication cookies set by Supabase). Because these are strictly necessary for the service to function, no separate consent is required for them under § 25(2) TTDSG.
With your consent, we also use analytics cookies (PostHog) to understand how the app is used, and advertising cookies (Google Ads) to measure the effectiveness of our ad campaigns. Neither is active until you opt in via the cookie banner, and you can withdraw your consent at any time — see "Cookie Settings" in the footer of any page.
Legal basis: Art. 6(1)(a) GDPR and § 25(1) TTDSG — your consent.
4. Service Providers (Data Processors)
We use the following third-party service providers who process personal data on our behalf. All processors are bound by data processing agreements (DPAs) in accordance with Art. 28 GDPR.
4.1 Vercel Inc. — Hosting
Purpose: Hosting the SCHEDLR web application.
Location: USA / EU edge nodes.
Data transferred: IP addresses, access logs.
Safeguard: Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR.
Vercel Privacy Policy →
4.2 Supabase Inc. — Database & Authentication
Purpose: User authentication, storage of account, profile, schedule, and training data.
Location: Amazon Web Services, US East (us-east-1), USA.
Data transferred: All data described in Section 2.1–2.3.
Safeguard: Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR; Supabase Data Processing Agreement signed.
Supabase Privacy Policy →
4.3 Stripe Inc. — Payment Processing
Purpose: Processing Pass purchases. When you click "Buy", you are redirected to Stripe's checkout page. SCHEDLR never receives your full card details.
Location: USA / Ireland (Stripe Payments Europe, Ltd.).
Data transferred: Email address, Stripe customer reference, payment confirmation.
Safeguard: Stripe is certified under the EU-U.S. Data Privacy Framework and uses SCCs. Stripe acts as an independent data controller for fraud prevention and legal obligations.
Stripe Privacy Policy →
4.4 Cloudflare Inc. — Bot Protection
Purpose: Protecting the public contact form against automated submissions using Cloudflare Turnstile.
Location: Processing through Cloudflare's global network.
Data transferred: IP address and technical browser/request data required to assess whether a submission is automated.
Safeguard: Cloudflare's Data Processing Addendum and applicable international data-transfer safeguards.
Cloudflare Privacy Policy →
4.5 PostHog Inc. — Product Analytics (consent-based)
Purpose: Understanding how the app is used (page views and product-usage events) to improve SCHEDLR. Session recording, surveys, autocapture, and dead-click capture are all disabled.
Location: EU (PostHog's EU Cloud instance).
Data transferred: Pages visited, product-usage events, and a user identifier for logged-in users.
Consent: Only active if you opt in via the cookie banner. You can withdraw consent at any time via "Cookie Settings" in the footer.
PostHog Privacy Policy →
4.6 Google Ireland Limited — Advertising (consent-based)
Purpose: Google Ads conversion tracking, to measure the effectiveness of our ad campaigns.
Location: USA / EU, per Google's infrastructure.
Data transferred: Advertising identifiers and conversion events (e.g. that a signup occurred), via cookies set by Google's gtag.js.
Consent: Only active if you opt in via the cookie banner. You can withdraw consent at any time via "Cookie Settings" in the footer.
Safeguard: Google is certified under the EU-U.S. Data Privacy Framework and uses Standard Contractual Clauses (SCCs) for any remaining transfers.
Google Privacy Policy →
4.7 Functional Software, Inc. (Sentry) — Error Monitoring
Purpose: Capturing application errors so we can find and fix bugs. This is operational monitoring, not analytics or advertising — it does not use cookies and only activates when something actually goes wrong.
Location: USA / EU, per Sentry's infrastructure.
Data transferred: Error messages, stack traces, the page URL, browser/device information, and your account ID (not your email) so we can tell how many people a bug affects.
Safeguard: Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in operating a working, secure service (the same basis as the server logs in Section 2.6).
Sentry Privacy Policy →
5. Data Retention
We retain your personal data only as long as necessary for the purpose it was collected:
- →Account & profile data: Until you delete your account, or after 24 months of inactivity.
- →Training & performance data: Until you delete your account.
- →Payment records: 10 years from the date of the transaction, pursuant to § 147 AO (German Tax Code).
- →Server logs: Maximum 30 days.
6. Your Rights under the GDPR
You have the following rights with respect to your personal data. To exercise any of them, contact us at contact@schedlr.de .
- →Right of access (Art. 15 GDPR): You may request a copy of all personal data we hold about you.
- →Right to rectification (Art. 16 GDPR): You may request correction of inaccurate data.
- →Right to erasure (Art. 17 GDPR): You may request deletion of your data, subject to legal retention obligations.
- →Right to restriction (Art. 18 GDPR): You may request that we restrict processing of your data in certain circumstances.
- →Right to data portability (Art. 20 GDPR): You may request your data in a structured, machine-readable format.
- →Right to object (Art. 21 GDPR): You may object to processing based on legitimate interest (Art. 6(1)(f)).
- →Right to lodge a complaint: You have the right to complain to a supervisory authority. The competent authority for Baden-Württemberg is the Landesbeauftragter für Datenschutz und Informationsfreiheit Baden-Württemberg (LfDI BW), www.baden-wuerttemberg.datenschutz.de .
7. Children's Privacy
SCHEDLR is not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately at contact@schedlr.de and we will delete it promptly.