Privacy Policy
Effective: 2026-08-26
Summary: LearnClash collects data needed to run the app (account info, game progress, device tokens for notifications, support reports you choose to send, and, for Premium study material topics, the material you upload). We use Firebase (Google) for infrastructure, Google Gemini on Google Cloud for AI features, and RevenueCat for subscriptions, with Stripe processing payments for subscriptions bought on our website. Study material is never shown to other users and never used to train AI models; friends you challenge see only the topic name and the generated questions, our staff access it only for moderation and support, uploaded files are deleted right after their text is extracted, and the extracted text is deleted with the topic. On Android, AppsFlyer measures which ads lead to installs and trials, controlled by the same Analytics & Ad Measurement setting. We don't sell your data. On the website, optional ads/matching consent can enable Google Signals and hashed email matching for conversion measurement, demographics, remarketing, and attribution. You can request deletion of your account anytime via the app or by emailing us; remaining data is handled according to our retention schedule.
1. Identity & Contact
Data Controller: Pluxia GmbH, Blegistrasse 7, 6340 Baar, Switzerland (UID: CHE-198.527.946).
Contact: privacy@learnclash.com
Response Time: We respond to privacy requests within 30 days (GDPR) or 45 days (CCPA). Complex requests may take up to 90 days with notice.
2. Data We Collect
2.1 Account Data
When you sign in, we collect:
- Email address — from Google Sign-In or Apple Sign-In (OAuth provider)
- Display name — from OAuth provider, editable by you
- Profile photo URL — from OAuth provider, editable by you
- Unique user identifier (UID) — generated by Firebase Authentication
- Preferred language — auto-detected from device locale (BCP-47 format)
- Account creation timestamp
- Last active timestamp — updated with 5-minute debounce
- Online status: while the app is open, your device writes a small presence record (online, in a match, or offline, plus a last-seen time, whether that match needs your full attention, and whether your Live play setting is on) about every 2 minutes, or about every 25 seconds while a Live invitation you sent is open. Only players you have accepted as friends can see it, as a green or amber dot next to your name and to know whether they can invite you to a Live duel; it is never shown to other players. Turn off Online status in Settings, Privacy to stop publishing it (you then stop seeing your friends' dots too). The record is deleted with your account.
- Onboarding (before sign-up): when you first open the app, we create a temporary anonymous account (a random Firebase UID) so you can try LearnClash before signing up. It is merged into your account when you sign up, or deleted automatically if you do not.
- Sign-in restore key (Android): when you are signed in on Android, your device stores a restore key with Google Play services so that, when you move to a new Android phone and restore your data, you are signed in to LearnClash automatically. We store only the public half of the key together with your user ID; the secret half never leaves Google's systems. The key record on our servers is deleted when you sign out or delete your account; uninstalling the app removes only the copy on your device.
2.2 Game Performance Data
To provide matchmaking and track your progress:
- Skill rating — matchmaking score (Glicko-2 system, shown as an ELO-style number) starting at 1300
- XP (experience points) — progression tracking
- Duel count — total games played
- Current streak — consecutive days you've been active
- Maximum streak — your all-time best
- Streak freezes — available streak protection items
- Last streak date — ISO format (YYYY-MM-DD)
- Preferred categories — your 3-18 category selections for matchmaking
- My topic IDs — topics you're practicing (max 50)
2.3 Learning Progress Data
To implement spaced repetition learning:
- Per-question correct count — how many times you answered correctly
- Last seen timestamp — when you last saw each question
- Next review date — scheduled by our SRS algorithm
- Topic cooldown timestamps — prevents overuse of same topics
2.4 Duel History Data
For each game you play:
- Duel ID and timestamps — created, updated, expires
- Opponent information — UID, display name, photo, ELO (public profile data)
- Round-by-round answers — which option you selected and correctness
- Response time — milliseconds to answer each question
- XP earned — per answer
- Final scores and ELO changes
- Forfeit status — if applicable
- Answer touch characteristics: for each answer you tap in a rated duel, the pointer type, pressure, contact size, hold duration and position on the option, together with your device's operating system and model. Used only for fair-play checks and never to identify you or to link accounts.
2.5 Social Data
For friend features and multiplayer:
- Friend relationships — user IDs, pending/accepted status, friend streak
- Head-to-head statistics — win/loss record against specific opponents
- Unread notification count
- Public profile — your display name, photo, ELO, and XP are visible to other authenticated users for matchmaking and leaderboards
- Question reports — if you report a question issue, we store your user ID with the report
2.6 Feedback & Support Reports
When you send feedback or a bug report from the app, we collect only what is needed to understand and route the report:
- Message and report type - the text you enter and whether you selected bug or idea
- Optional app status diagnostics - app version, build number, flavor, platform, OS version, device model, locale, timezone, text settings, layout insets, network state, route label, and progress counters such as streak, ELO, Mems, level, and XP
- Optional screenshot - captured only after you open the feedback sheet, shown as a preview, removable before sending, and disabled on private screens and active gameplay screens
- Support routing metadata - report ID, Firebase Auth UID, privacy hash, support delivery status, attempts, and error code if delivery fails
- Data we do not include - raw logs, notification tokens, full question content, passwords, payment details, or public screenshot URLs
2.7 Device & Technical Data
For app functionality and security:
- FCM tokens — Firebase Cloud Messaging tokens for push notifications (max 5 per user)
- Firebase App Check attestation — device integrity verification
- Privacy hash — HMAC-SHA256 of your UID for anonymized crash correlation
- Installation UUID — Crashlytics installation identifier
- IP address — processed transiently by Firebase infrastructure, not stored by us
2.8 Analytics & Diagnostics Data
To improve the app:
- Screen views and navigation paths
- Feature interaction events — duel created, question answered, etc.
- Session duration and timestamps
- Paywall views, conversions, dismissals
- Error logs and stack traces — via Firebase Crashlytics
- Diagnostic keys — FCM status, APNs availability
- Breadcrumb logs — activity trail preceding crashes
Google Analytics Advertising Features and User-Provided Data
When you grant ads, demographics, and matching consent on our website, Google Analytics may additionally collect or receive:
- Demographics — inferred age range and gender
- Interests — inferred interest categories based on browsing history
- Cross-device linkage — associates activity across devices you use while signed in to the same Google account
- User-provided data — after website sign-in, a SHA-256 hash of your normalized account email may be sent to Google Analytics for enhanced conversions, Customer Match, demographics, interest reporting, and attribution. We do not send raw email, names, phone numbers, street addresses, city, postal code, or precise location.
These features are disabled by default in the EU/EEA/UK/Switzerland and only activate after you click "Accept all" or opt in via the Privacy preferences link. Global Privacy Control also disables them. You can opt out at any time via Google's Analytics Opt-Out Browser Add-on, your Google Ads Settings, or by clicking "Privacy preferences" in our footer. In the mobile app: we use Firebase Analytics and share measurement data with Google Ads to measure which ads lead to installs and trials and to improve our advertising. This is on by default outside the EU/EEA/UK/Switzerland and stays off until you opt in within them. You can change it anytime under Settings, then Analytics & Ad Measurement. On Android, the same setting also controls AppsFlyer, an install-attribution service that measures which ad networks lead to installs and trials; AppsFlyer receives the Google Advertising ID, an AppsFlyer-generated device identifier, IP address, device information, install events, and trial/subscription events (no payment details, no email). The app does not use Apple's advertising identifier (IDFA) and, on iOS, does not track you across other companies' apps or websites.
2.9 Subscription Data
Managed by RevenueCat:
- Purchase history and product IDs
- Subscription status — active, expired, grace period
- Store identifier — App Store, Google Play, or web (Stripe)
- Expiration and renewal dates
- Web purchases: subscriptions bought on learnclash.com use RevenueCat Web Billing with payment processing by Stripe. Your card details are entered directly with Stripe and are never stored by us.
2.10 Chat Data
If you use AI chat or duel chat features:
- AI conversation history — automatically deleted after 30 days (TTL)
- Duel chat messages — message text, sender user ID, duel ID, thread ID, timestamps, and moderation status
- Clash AI prompts — when you ask Clash or tag @clash, the text you submit is processed to generate the reply. Duel-thread Clash replies use only your visible @clash message and do not include hidden duel state
- Chat safety settings — terms acceptance, chat preference, safe mode, muted or blocked users, and local hide records
- Report and moderation records — created when you report a message or when automated safety systems block a message
2.11 Chrome Extension Data
If you use the LearnClash Chrome Extension (new tab quiz), the following data is stored locally on your device via chrome.storage.local:
- Quiz pool — pre-fetched quiz sets for instant new tab loading (expires after 6 hours)
- Language preference — your selected language override
- Daily streak — number of consecutive days you completed a quiz
- Last played date — date of your most recent quiz completion (YYYY-MM-DD)
- GA4 Client ID — a random UUID generated on first use for anonymous analytics grouping
The extension sends anonymous usage events to Google Analytics 4 (GA4) via the Measurement Protocol:
- Topic selections — which topic you picked (name and ID)
- Quiz completions — that you finished a quiz (no answers are sent)
- Session ID — a random number generated per tab open
The extension communicates with our API to fetch quiz content:
- Language header — your browser's Accept-Language or your language override
- Timestamp header — for rate limiting (not stored)
- IP address — processed transiently for rate limiting, not stored by us
No account required: The Chrome Extension does not require sign-in. No personal information (email, name, or app account data) is collected or linked. All data is stored locally and deleted when you uninstall the extension.
2.12 Study Material Data (Premium)
If you create a private quiz topic from your own study material, we process only what you add and only to build and moderate that topic:
- Material you add - pasted text, web links, YouTube links, PDF files, and photos of notes. Files are uploaded to a private storage bucket that only our servers can read and are deleted right after their text has been extracted (a 7-day automatic clean-up is the safety net if extraction fails).
- Extracted text - the text taken from each source, stored with the topic until you delete the topic or your account, because every later generation run and every fact check of a reported question needs it.
- Screening results - an automated image-safety check for photos and an automated content screening for every source (safe or not, whether it contains instructions to the AI, whether it contains other people's personal data, a one-sentence subject summary, and the detected language). Rejected material is not stored.
- Topic and question data - the topic name and category you chose, the questions generated from your material, question counts, and per-source content hashes (used only to detect the same upload being added twice)
- Consent record - the version of the content rules and AI-processing notice you accepted and when
- Cover image - an AI-generated cover created from the topic name and category only, never from your material
- Who can see what: your material and its extracted text are never shown to other users. Only you (when you review extracted text in the app) and, for moderation and support, authorized LearnClash staff can access them, and the processors listed in Section 4 (Google Cloud: Firebase, Vertex AI, Cloud Vision) store and process them on our behalf under the Google Cloud Data Processing Addendum. Friends you challenge see the topic name and the generated questions, never the material. Nothing from a study material topic ever enters the public topic pool or search.
3. How We Use Your Data
| Data Category | Purpose | Legal Basis (GDPR) |
|---|---|---|
| Account data | Authentication, profile display | Contract performance |
| Game data | Matchmaking, leaderboards, progression | Contract performance |
| Learning progress | Spaced repetition scheduling | Contract performance |
| Device tokens | Push notifications for game events | Legitimate interest |
| Feedback and support reports | Customer support, bug triage, abuse prevention, and support delivery to support@learnclash.com | Legitimate interest / Consent for optional screenshot |
| Analytics (basic) | App improvement, feature usage, funnel analysis | Legitimate interest / Consent (EU) |
| Google Signals and user-provided data | Audience insights, cross-device measurement, advertising features, enhanced conversions, Customer Match, and attribution | Consent (opt-in required) |
| Install attribution data (Android) | Measuring which ad campaigns and networks lead to installs and trials via AppsFlyer | Legitimate interest / Consent (EU) |
| Crash logs | Debugging, stability | Legitimate interest |
| Subscriptions | Premium feature access | Contract performance |
| Study material (Premium) | Extracting text, generating and fact-checking your private quiz questions, and rendering a cover image | Contract performance |
| Study material safety screening and moderation | Rejecting unsafe or infringing material, handling reports and notices, keeping the service safe for users aged 13 and older | Legitimate interest / Legal obligation |
| Answer touch characteristics | Fair-play checks: detecting automated or assisted play in rated duels | Legitimate interest |
| Sign-in restore key (Android) | Signing you in automatically on your next Android device after a device transfer | Legitimate interest |
Automated Decision-Making: We do not use automated decision-making with legal or similarly significant effects (GDPR Article 22). ELO matchmaking is algorithmic but has no legal effect.
4. Third-Party Services
We use the following services to operate LearnClash. For our internal analytics, Google acts as our data processor; for advertising data shared for measurement and personalization (Google Ads conversions and personalized advertising), Google acts as a separate, independent data controller under Google's Privacy Policy:
| Service | Provider | Purpose | Data Shared |
|---|---|---|---|
| Firebase Authentication | Google LLC | User sign-in | Email, UID, OAuth tokens |
| Cloud Firestore | Google LLC | Database storage | All user-generated data |
| Google Analytics 4 (Firebase Analytics) | Google LLC | Usage analytics, funnel analysis, and — with your consent — Google Signals, user-provided data, demographics, interests, cross-device measurement, enhanced conversions, Customer Match, advertising features, and attribution | Events, hashed user ID (SHA-256 of UID), device info, IP (truncated by Google), and — only with ads/matching consent — Google account signals and SHA-256 hashed normalized account email |
| Firebase Crashlytics | Google LLC | Crash reporting | Device info, crash logs, privacy hash |
| Firebase Cloud Messaging | Google LLC | Push notifications | FCM tokens |
| Firebase App Check | Google LLC | Device verification | Device attestation |
| Google Play services (Credential Manager) | Google LLC | Stores the Android sign-in restore key and moves it to your next device during a device transfer or cloud restore | Restore key (the secret half stays on your device or in your Google account backup; we receive only the public half) |
| RevenueCat | RevenueCat Inc | Subscription management | Purchase history, entitlements |
| AppsFlyer | AppsFlyer Ltd | Mobile install attribution and ad measurement (Android only, controlled by the Analytics & Ad Measurement setting) | Google Advertising ID, AppsFlyer device identifier, IP address, device info, install events, and trial/subscription events forwarded by RevenueCat (no payment details, no email) |
| Google Gemini (on Google Cloud Vertex AI) | Google LLC | Question generation, semantic embeddings, translations, report validation, Clash AI replies, and, for Premium study material topics, text extraction, safety screening, and question generation from your material | Question and topic text, which may include user-created topic names and descriptions; AI chat prompts; your display name (for personalization); visible @clash message text when you tag Clash in a duel thread; and, for study material topics, the material you add (extracted text, uploaded PDFs and photos, linked web pages and YouTube videos). Google processes this as our processor under the Google Cloud Data Processing Addendum and does not use it to train AI models; requests may be cached for up to 24 hours, and prompts that Google's automated safety classifiers flag as suspicious may be logged for up to 90 days solely to check for misuse of Google's service. Hidden duel state, live answers, scores, account email, notification tokens, and payment data are not sent |
| Google Cloud Vision | Google LLC | Automated image-safety screening of profile photos and study material photos | The uploaded image, processed transiently; only the safety verdict is kept |
| Stripe | Stripe, Inc. | Payment processing for subscriptions bought on learnclash.com (via RevenueCat Web Billing) | Payment card details (entered directly with Stripe), billing email, and purchase amount. Never stored by Pluxia |
Third-Party AI Services: LearnClash uses Google Gemini, accessed through Google Cloud Vertex AI, for quiz question generation, semantic embeddings, translations, report validation, and Clash AI replies. Question generation processes question and topic text, which may include user-created topic names and descriptions. For Premium study material topics, the material you add is processed to extract its text, screen it for safety, and write questions from it; you are shown this and asked to agree before your first upload. Google acts as our processor and does not use any of this data to train its models. We do not send account email, payment data, notification tokens, or hidden duel state to AI services. When you ask Clash or tag @clash, the prompt or message text you submit, together with your display name (for personalization), is processed to generate the reply. We require all third-party providers to protect your data to the same or an equal standard as described in this policy.
For more information: How Google uses data when you use our partners' sites or apps
Third-Party Privacy Policies:
- Firebase Privacy
- Google Cloud Data Processing Addendum (Gemini on Vertex AI, Cloud Vision)
- RevenueCat Privacy Policy
- AppsFlyer Services Privacy Policy
- Stripe Privacy Policy
5. Data Retention
| Data Type | Retention Period | Deletion Trigger |
|---|---|---|
| Account data | Until account deletion; an in-app deletion request keeps the account deactivated and restorable for 30 days, then erases it (unless immediate deletion is chosen in the dialog) | User request (in-app, via the website deletion page, or email) |
| Sign-in restore key (Android) | Until you sign out or delete your account | Sign-out or account deletion |
| Game history (duels) | For the life of your account | Account deletion |
| Answer touch characteristics | For the life of your account | Account deletion |
| Learning progress | For the life of your account | Account deletion |
| AI chat sessions | 30 days | Automatic TTL expiration |
| Duel chat messages | 60 days | Automatic TTL expiration |
| Duel chat report evidence | 180 days | Automatic TTL expiration |
| Feedback reports | 180 days; optional screenshots 30 days; unsubmitted drafts 30 minutes | Automatic TTL expiration or deletion request |
| Study material uploads (PDF files, photos) | Until their text has been extracted, usually minutes; unfinished uploads at most 7 days | Automatic deletion after extraction; 7-day storage clean-up |
| Study material extracted text, screening results, and generated questions | Until you delete the topic or your account | Topic deletion or account deletion |
| Content rules and AI-processing acceptance record | For the life of your account | Account deletion |
| Question reports | 90 days | Automatic TTL expiration (your user ID is also removed from reports when you delete your account) |
| Topic reports | Kept as moderation records | Account deletion (anonymization) |
| Analytics data | 14 months | Google default retention |
| Crash logs | 90 days | Firebase default |
| Rate limit counters | Hourly windows | Automatic expiration |
On Sign-Out: Local data (FCM tokens, cache, authentication tokens) is deleted from your device. Your account data remains on our servers until you delete your account via Profile → Settings → Delete Account or by emailing us. The Android sign-in restore key is the exception: its record is deleted from our servers when you sign out (Section 5).
6. International Transfers
Your data may be processed outside your country of residence. Destination countries are the United States, Israel, and the EU/EEA:
- Firebase/Google — Uses United States infrastructure (Google Cloud). Transfers are covered by the EU-US Data Privacy Framework (with the Swiss-US DPF for Swiss users and the UK Extension for UK users), under which Google LLC is self-certified, with Google's Standard Contractual Clauses (SCCs) as a supplementary safeguard.
- RevenueCat — United States based, uses SCCs for EU compliance.
- AppsFlyer — Headquartered in Israel (recognized by the EU as providing adequate data protection), with processing in the EU and United States; uses SCCs where required.
- Google Gemini on Vertex AI and Google Cloud Vision (Google LLC) - Processed on Google Cloud infrastructure, primarily in the United States; AI requests use Google's global serving endpoint and may be handled in other regions where Google operates. Covered by Google's Data Privacy Framework certification and SCCs as above.
- Stripe — United States based; certified under the Data Privacy Framework (including the Swiss-US DPF) and uses SCCs where required.
7. Your Rights (GDPR, UK GDPR, and Swiss FADP)
Under the General Data Protection Regulation (and equivalently under the UK GDPR and the revised Swiss Federal Act on Data Protection), you have the following rights:
- Right to Access (Article 15) — Request a copy of your personal data.
- Right to Rectification (Article 16) — Correct inaccurate data via profile settings or by contacting us.
- Right to Erasure (Article 17) — Request deletion of your account. Use the in-app option (Profile → Settings → Delete Account), the web deletion page at learnclash.com/account/delete, or email us; remaining data is handled according to our retention schedule.
- Right to Restrict Processing (Article 18) — Limit how we use your data.
- Right to Data Portability (Article 20) — Receive your data in a machine-readable format.
- Right to Object (Article 21) — Object to processing based on legitimate interest.
- Right to Withdraw Consent — Where consent is the legal basis.
How to Exercise: Email privacy@learnclash.com with your request. Include your account email for verification.
Response Time: Within 30 days. Complex requests may take up to 60 additional days with notice.
Complaints: You have the right to lodge a complaint with your local Data Protection Authority. List of EU DPAs. UK users can complain to the Information Commissioner's Office (ico.org.uk). Swiss users can complain to the Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch).
8. Your Rights (CCPA/CPRA — California Users)
Under the California Consumer Privacy Act and California Privacy Rights Act:
- Right to Know — Request the categories and specific pieces of personal information we've collected.
- Right to Delete — Request deletion of your personal information via the in-app option (Profile → Settings → Delete Account), the web deletion page at learnclash.com/account/delete, or by email.
- Right to Correct — Request correction of inaccurate information.
- Right to Opt-Out of Sale/Sharing — We do not sell your personal information for money. However, when you grant ads/matching consent on our website, we enable Google Analytics Advertising Features (Google Signals) and may send a SHA-256 hashed account email for user-provided data features, which under California law constitutes "sharing" personal information for cross-context behavioral advertising.
Website opt-out methods: You can opt out at any time by: (1) clicking "Privacy preferences" in our footer, (2) declining the consent banner on your first visit, (3) enabling Global Privacy Control (GPC) in your browser (we honor GPC automatically), or (4) using Google's Analytics Opt-Out Browser Add-on. We do not respond to browser "Do Not Track" signals, but we do honor Global Privacy Control.
Mobile app: sharing analytics and ad-measurement data with Google to measure our ads is on by default outside the EU/EEA/UK/Switzerland and off until you opt in within them; you can opt out anytime under Settings, then Analytics & Ad Measurement. - Right to Limit Use of Sensitive Personal Information — Not applicable (we don't process sensitive PI beyond account operation).
- Right to Non-Discrimination — No penalty for exercising your rights.
Verification: We verify requests by confirming your email address matches an account.
Authorized Agents: You may designate an authorized agent to make requests on your behalf with written permission.
Response Time: Within 45 days. May extend by 45 additional days with notice.
CCPA 2026 Updates (Effective January 1, 2026)
- Automated Decision-Making: We do not use automated decision-making technology that produces legal or similarly significant effects.
- Opt-Out Confirmations: We provide confirmation when you opt out of data processing.
- Global Privacy Control (GPC): We automatically detect and honor the GPC browser signal as an opt-out of sharing for cross-context behavioral advertising. When GPC is detected, Google Signals is disabled for your session regardless of prior consent.
9. Children's Privacy
Age Requirement: LearnClash is intended for users aged 13 and older.
We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact us immediately at privacy@learnclash.com.
Parental Rights: Parents may request deletion of any data collected inadvertently from children under 13.
10. Security
We implement industry-standard security measures:
- Encryption in Transit: All communications use TLS/SSL.
- Encryption at Rest: Firebase default encryption for stored data.
- Access Control: Firestore Security Rules with field-level permissions.
- Device Verification: Firebase App Check validates device integrity.
- Anti-Cheat: Server-side answer validation; correct answers never sent to client.
- Rate Limiting: Prevents abuse of sensitive operations.
- Cryptographic Protection: HMAC-SHA256 for privacy hashes and session tokens.
- Secret Management: API keys stored in Google Secret Manager.
Disclaimer: No system is 100% secure. We cannot guarantee absolute security but take reasonable measures to protect your data.
11. Cookies & Identifiers
Mobile App: LearnClash does not use cookies. We use the following identifiers:
- Firebase Installation ID — identifies app installation
- FCM Token — for push notifications
- App Check Token — device attestation
- Google Advertising ID — Android only, used for install attribution while ad measurement is enabled
- AppsFlyer ID — Android only, a random device identifier generated by AppsFlyer for install attribution
Website (learnclash.com): The LearnClash website uses Google Analytics 4 (GA4) with Google Consent Mode v2, delivered via our own server-side tag manager (sGTM) running on learnclash.com. Your browser sends analytics requests to our server (Google Cloud Run, us-central1), which then forwards them to Google Analytics. No analytics request connects directly to googletagmanager.com or google-analytics.com. We distinguish two cookie categories, each independently controlled via the consent banner and the "Privacy preferences" footer link:
Cookie categories
- Analytics cookies (controlled by
analytics_storage): basic pageview, session, and event measurement. All four cookies are first-party onlearnclash.com:_ga(2 years, identifies the browser across sessions),_ga_SCDL21Y0MG(2 years, holds the current GA4 session state),FPID(2 years, HttpOnly, server-set first-party identifier that survives Safari ITP's 7-day cookie cap), andFPGSID(30 minutes, SameSite=Strict, server-set session identifier). Used to understand which pages are visited and to measure funnel conversion. Default: denied in the EEA, UK, and Switzerland until you choose to allow analytics; enabled elsewhere unless you opt out. No third-party ad profiling. - Advertising cookies / Google Signals / user-provided data (controlled by
ad_storage,ad_user_data,ad_personalization) — enables Google Analytics Advertising Features including demographics, interest categories, cross-device measurement, remarketing, enhanced conversions, Customer Match, and attribution. After website sign-in and only when this category is allowed, we may send Google Analytics a SHA-256 hash of your normalized account email. Default: denied until you choose to allow ads, demographics, and matching. Automatically disabled when Global Privacy Control is detected, regardless of prior consent. Under California law this constitutes "sharing" for cross-context behavioral advertising.
Opt out or change your choice at any time: click "Privacy preferences" in the footer of any page. Legal pages (privacy policy, terms, impressum, support) do not load any analytics or trackers regardless of consent.
Chrome Extension: The LearnClash Chrome Extension uses GA4 via the Measurement Protocol (not cookies). It stores a small amount of data locally on your device (quiz pool, streak, language preference, and a random analytics identifier); we treat this local storage as strictly necessary for the extension to function, and the analytics identifier is anonymous and deleted when you uninstall the extension. See Section 2.11 for details.
For EU users, we comply with Google's EU User Consent Policy requirements.
12. Policy Updates
We may update this Privacy Policy to reflect changes in our practices or legal requirements.
- Notification: Significant changes will be communicated via in-app notification.
- Continued Use: Continued use after changes constitutes acceptance.
- Version History: Material changes are documented below.
Version History
| Date | Change |
|---|---|
| 2026-08-26 | Added the Android sign-in restore key (Sections 2.1, 3 and 5), which signs you in to LearnClash automatically on a new Android device after a device transfer. |
| 2026-08-26 | Added answer touch characteristics (Sections 2.4, 3 and 5), recorded for fair-play checks in rated duels, and extended the Online status record (Section 2.1) with the busy kind and the Live play setting that friends read for Live duel invitations. |
| 2026-08-16 | Added Premium study material topics: new Section 2.12 (material you add, extracted text, screening results, consent record, who can see what), legal bases in Section 3, Google Gemini row updated to Google Cloud Vertex AI with the no-training, caching, and abuse-monitoring disclosures, new Google Cloud Vision row, retention rows for uploads, extracted text, the acceptance record, and content reports, and the Google Cloud Data Processing Addendum link. |
| 2026-07-22 | Legal audit revision: corrected AI processor disclosures (Google Gemini only; removed the erroneous xAI listing), added web subscription payments via RevenueCat Web Billing and Stripe, the web account-deletion page link, Swiss FADP and UK GDPR rights with FDPIC and ICO complaint routes, destination-country list for international transfers, the onboarding anonymous-account disclosure, and retention wording clarifications. |
| 2026-06-12 | Added AppsFlyer (Android only, controlled by the Analytics & Ad Measurement setting) install attribution and ad measurement disclosures in Sections 2.8, 3, 4, 6, and 11. |
| 2026-06-09 | Clarified that your display name is included in Clash AI chat prompts sent to Google Gemini for personalization. |
| 2026-05-24 | Clarified that Clash AI prompts and visible @clash duel-thread messages are processed by Google Gemini to generate replies, while hidden duel state, account email, notification tokens, and payment data are not sent. |
| 2026-05-22 | Added consent-gated Google Analytics user-provided data disclosures for hashed account email matching, enhanced conversions, Customer Match, remarketing, demographics, interest reporting, and attribution. Clarified that city, postal code, phone number, raw email, names, street address, and precise location are not sent. |
| 2026-05-20 | Added duel chat message, report, block, moderation, and 60-day/180-day retention disclosures. |
| 2026-05-17 | Adopted server-side Google Tag Manager (sGTM) on learnclash.com. Analytics requests now route through our own Google Cloud Run server (us-central1) before reaching Google, instead of the browser connecting directly to googletagmanager.com and google-analytics.com. Added FPID (2-year HttpOnly first-party identifier) and FPGSID (30-minute SameSite=Strict session identifier) to the Section 11 cookie list. No change to which data is collected, no change to data recipients, no change to consent behavior. |
| 2026-04-15 | Enabled Google Analytics Advertising Features (Google Signals). Added granular consent banner with separate Analytics and Advertising categories. Added Global Privacy Control (GPC) auto-detection. Updated Sections 2.7, 3, 4, 8, and 11 to disclose demographics, interest categories, cross-device measurement, and CCPA sharing classification. |
| 2026-03-27 | Added Chrome Extension data disclosures and updated Section 11 to cover extension analytics. |
| 2026-01-08 | Initial comprehensive policy with GDPR, CCPA/CPRA 2026, Firebase disclosures, in-app account deletion, public profile visibility, and third-party AI clarifications per Apple Nov 2025 guidelines. |
13. Contact Us
For privacy inquiries, data requests, or questions about this policy:
We aim to respond to all inquiries within 30 days.