Privacy Policy
Last updated: 02.08.2026
This Privacy Policy explains how Eleheim GmbH ("Eleheim", "we", "us", or "our") collects, uses, shares and protects your personal data when you use the Oropen website at https://oropen.com, our web application, our mobile applications (including apps distributed via Google Play and the Apple App Store), and any related services and APIs (together, the "Service").
1. Data Controller and Contact Details
The controller responsible for processing your personal data under the EU General Data Protection Regulation ("GDPR") is:
Eleheim GmbHSchellingstraße 109a
80798 Munich, Germany
Website: https://oropen.com
Email: info@oropen.com
If you have any questions about this Privacy Policy or our data practices, you can contact us at the email address above or via our contact page.
If we appoint a data protection officer (DPO) in the future, we will update this Privacy Policy with their contact details.
2. Scope of this Privacy Policy
This Privacy Policy applies to:
- visitors to our website;
- users who create a Oropen account (web or mobile);
- users who purchase subscriptions or credits via our website or mobile apps;
- any other individuals whose personal data we process in connection with the Service.
It does NOT apply to third-party websites, apps, or services that you may access via links from Oropen (for example, payment processors, Google Play, the Apple App Store, or the Google Drive cloud storage service). Those services are governed by their own privacy policies.
3. What Personal Data We Collect
We collect different types of personal data depending on how you interact with the Service.
3.1 Data You Provide Directly
Account data:
- Email address
- Name or username
- Password (stored in hashed form)
- Language preferences and other profile settings
Subscription and billing-related data:
- Plan type (Free, Plus, Premium, etc.)
- Whether your subscription is active, cancelled, or expired
- Tokens/credits (OPT) and Boosts you purchased or used
Payment card details and sensitive financial information are processed directly by our third-party payment service providers and are not stored on our servers.
Support and communication data:
- Messages you send to our support team
- Feedback you submit (for example, bug reports or feature requests)
- Email address and any information you choose to include in your messages
- Chat support conversations conducted through the Service, including message content, timestamps, and session metadata
Learning and content data ("User Content"):
- Text, flashcards, notes, examples, prompts, and similar content you create or upload
- Media you upload (e.g. audio or images), if the feature is used
- AI prompts, instructions and other inputs you send within the Service
Please avoid including sensitive information (such as health data, political opinions, religious beliefs, etc.) in your User Content, unless you are comfortable with it being processed as described in this Policy.
Camera and media data:
- Photos captured via the in-app camera for flashcard imagery
- Images assigned as deck cover photos
- Photos of handwritten or printed notes for vocabulary extraction
- Metadata associated with captured images (e.g. timestamp, resolution)
Images are stored locally on your device and, if you enable cloud sync, in your connected cloud storage. We do not access or retain your photos on our servers unless you explicitly submit them for AI-based text extraction.
3.2 Data We Collect Automatically
When you use our website or apps, we may automatically collect:
Usage data:
- Pages or screens you visit
- Features you use and actions you perform (e.g. creating flashcards, triggering AI requests)
- Date and time of your visits
- App version and configuration
Device and technical data:
- IP address (short-term and often in truncated or pseudonymous form)
- Browser type and version
- Operating system and device type
- Language settings
- Crash logs and diagnostics
This data helps us keep the Service secure, improve performance, and understand how people use Oropen.
Crash and diagnostic reports:
If you use our mobile app and have not turned crash reporting off (see Section 4.11), the app automatically sends us a report when it runs into an unexpected error. Each report may contain:
- the error type and message, and the technical stack trace
- the app version and build number
- the platform (e.g. Android, iOS, or web) and whether the app is running on the web
- your language/locale setting and the time the error occurred
Before a report leaves your device, the app automatically attempts to remove likely personal or sensitive data — such as access tokens, authentication credentials, and email addresses — from the error message and stack trace. This is a best-effort measure, and we deliberately design the app so that it does not place your learning content into error messages.
Crash reports do NOT include your flashcards, decks, notes, or other learning content, screenshots, your contacts, your location, an advertising identifier, or a precise device fingerprint. Because the report is sent while you are signed in, it can be associated with your account so that we can investigate the underlying problem.
3.3 Data from Third Parties
Depending on how you sign up or pay, we may receive limited data from third parties:
Single sign-on providers (e.g. Google, Apple):
- A unique identifier and basic profile information (such as name and email), if you choose to sign in with those providers.
Payment service providers:
From our web payment processor, Google Play, or Apple App Store we may receive:
- Confirmation that a payment was successful or failed
- Subscription status, product purchased, country, and transaction IDs
- Limited billing information (e.g. last 4 digits of card, masked payment method type)
We do NOT receive or store your full payment card number.
Cloud storage provider (Google Drive):
If you enable cloud synchronisation in the mobile app, we interact with Google Drive through its official API. In this context:
- We may receive an authentication token (an OAuth token with the `drive.appdata` scope) that allows the app to read and write only to a dedicated, app-specific folder within your Google Drive account.
- We do NOT access, read, index, or process any of your other files or folders stored in your Google Drive account.
- The data stored in this dedicated folder consists exclusively of your Oropen application data (such as flashcards, decks, notes, writing-practice corrections, flashcard review history and learning progress, and app settings), together with any media (images and audio) you attached to your cards. Data is stored in a structured format (currently an SQLite database file and individual media files) and is not end-to-end encrypted on the cloud.
You can revoke the app's access to your Google Drive at any time from your Google Account's connected-apps settings.
Product analytics service (PostHog):
- We use PostHog (PostHog, Inc.) as our product analytics provider, currently hosted on its EU Cloud, to collect aggregated and pseudonymous usage data such as pages/screens visited, features used, and basic device information. After you give consent, PostHog also records anonymized session replays that are configured to mask text inputs so that what you type is not captured. We use PostHog only to understand and improve how Oropen is used; we do not use it for advertising and we do not sell or share this data with third parties for their own purposes. Analytics and session recording that rely on cookies or similar device storage are activated only after you give consent via our cookie banner, and you can withdraw that consent at any time.
4. How and Why We Use Your Personal Data (Purposes and Legal Bases)
Under the GDPR, we must have a legal basis for each processing purpose. We generally rely on:
- Performance of a contract (Art. 6(1)(b) GDPR)
- Legitimate interests (Art. 6(1)(f) GDPR)
- Consent (Art. 6(1)(a) GDPR)
- Legal obligations (Art. 6(1)(c) GDPR)
4.1 Providing and Operating the Service
We use your data to:
- create and manage your account;
- provide core features of Oropen (learning content, flashcards, AI interactions, syncing);
- process your subscriptions, Boosts and tokens (OPT);
- provide customer support.
Contract performance; legitimate interests (to operate an efficient and secure Service).
4.2 Payments and Billing
We use account and billing-related data to:
- manage your subscription status;
- verify payments with payment service providers;
- maintain proper accounting and tax records.
Contract performance; legal obligations (e.g. tax and commercial law).
4.3 AI Processing
When you use AI features, we process:
- the text or content you input (e.g. flashcards, writing practice text, OCR input, image-generation prompts, support inquiries);
- any context or data needed to generate the output (such as the source and target language).
We may send this data to third-party AI service providers that process it on our behalf as our processors, under applicable contractual data-protection terms (data processing agreements).
Current AI service providers:
As of the date of this Policy, we use the following third-party AI services as data processors. The list of providers may change from time to time; we will update this Policy when material changes occur.
- Google LLC — Google Gemini models (text generation, writing-practice correction, OCR / text extraction from images, card and content suggestions, and automated routing of support inquiries).
- Microsoft Corporation — Azure AI Speech (text-to-speech synthesis: the text you ask the Service to read aloud is transmitted to Microsoft Azure for audio synthesis).
- Cloudflare, Inc. — Workers AI running the FLUX.1 Schnell image-generation model (the prompt you submit for image generation, in some cases after enhancement by Google Gemini, is sent to Cloudflare for image generation).
These providers may process your data on servers located inside or outside the European Economic Area (EEA). See Section 7 for information about international data transfers and the safeguards we apply.
AI request caching:
To reduce latency and cost and to keep repeat requests affordable, our servers cache the input you submit to AI features together with the output we receive back. Cached text is stored in our own database and generated media (such as audio pronunciations and images) on our own storage infrastructure. Cache entries are deliberately NOT linked to your account: they contain no user identifier, and the anonymous per-tab marker used briefly to allow immediate regeneration is removed shortly afterwards. How long an entry is kept depends on the length of the input: very short, generic inputs (three words or fewer — for example single-word translations and their audio pronunciation) may be retained indefinitely as part of a shared, non-personal lookup store, and may be removed when capacity requires; entries from longer inputs expire and are deleted automatically after a short period (currently about one day for four-word inputs and about one hour for longer text, while generated media derived from longer inputs is kept for up to about one week). Your voice is never cached: audio you record or speak into the Service is never stored in this cache. Because cache entries are not linked to accounts, we cannot look them up by account; if you would like a specific cached entry deleted, contact us at info@oropen.com and include the exact text you submitted and the feature or language pair used, so that we can locate the entry by its content and delete it. This applies in particular where a cached entry contains personal data.
Contract performance; legitimate interests (to provide AI-powered features efficiently and reliably).
4.4 Cloud Synchronisation
If you enable cloud synchronisation in the mobile app, we process your Oropen application data — including your decks, flashcards (front/back content and any attached audio or images), notes, writing-practice corrections, flashcard review history and scheduling data, learning progress, language preferences, and app settings — by storing and retrieving it from a dedicated, app-specific folder in your Google Drive account.
This processing is performed exclusively on your device and between your device and Google Drive. Oropen does not route your synchronised data through its own servers. The synchronisation operates directly between the app on your device and the Google Drive API.
Synchronised data is transmitted to Google Drive over an encrypted TLS connection. However, the data stored in your Google Drive `appDataFolder` is NOT additionally end-to-end encrypted by us. This means that, technically, anyone who gains access to your Google account could read the contents of the Oropen folder using a compatible client. We therefore strongly recommend that you protect your Google account with a strong password and two-factor authentication.
We do NOT access, read, scan, or otherwise process any files, folders, or content in your Google Drive account other than the dedicated Oropen folder created by the app.
Contract performance (Art. 6(1)(b) GDPR) — to provide the synchronisation feature you activated; consent (Art. 6(1)(a) GDPR) — you explicitly choose to enable this feature.
Beta note: Cloud synchronisation is currently offered as a free public beta. During the beta the feature is provided as-is and you use it at your own risk — we recommend keeping local exports of important data (see also Section 9 of the Terms of Service).
4.5 Camera Usage and Image Processing
Our app requests access to your device camera for the following purposes:
- Capturing images to attach to your learning flashcards
- Taking photos to use as deck cover images
- Photographing handwritten or printed notes so that vocabulary can be extracted via OCR/AI and imported into your decks
Photos remain on your device unless you enable cloud sync. We do not upload images to our servers except when you use the note-scanning import feature, in which case the image is forwarded to our AI processor (Google Gemini) for text extraction and deleted from our servers immediately after processing.
The note-scanning feature uses AI-based optical character recognition (Google Gemini) to identify words in your photos. Only the extracted text is stored as part of your User Content; the original image is not retained on our servers.
Consent (Art. 6(1)(a) GDPR) — camera access requires your explicit device-level permission; Contract performance (Art. 6(1)(b) GDPR) for processing images as part of the service.
4.6 AI-Assisted Support Message Routing
When you submit a message through our support or contact channels, the content of your message may be analysed by an automated system powered by third-party AI model providers to:
- categorise your inquiry (e.g. billing, technical issue, account question, feature request);
- determine the appropriate internal team or department to handle your request;
- prioritise urgent or time-sensitive requests.
This automated analysis is used solely for internal routing and prioritisation. No automated decisions with legal or similarly significant effects are made based on this analysis. A human member of our support team reviews and responds to your inquiry after routing.
The AI service used for support message routing is currently Google Gemini, processing this data on our behalf as our data processor under a data processing agreement. If we change this provider, we will update this Policy.
Chat support data, including conversation content and session metadata, is retained only for as long as reasonably necessary to handle follow-up inquiries on the same or related issues and to improve the quality of our support. Closed sessions are automatically deleted or anonymised once that purpose no longer applies. See Section 8 for our general approach to data retention.
Legitimate interests (Art. 6(1)(f) GDPR) — to efficiently route and prioritise support requests for faster response times, and to improve service and support quality. You may object to this processing at any time by contacting us at info@oropen.com; in that case, your messages will be routed manually.
4.7 Improvement, Analytics, and Product Development
We analyze aggregated or pseudonymous usage data to:
- understand how the Service is used;
- improve existing features and develop new ones;
- identify and fix bugs or performance issues;
- monitor overall trends and user engagement.
For product analytics we use PostHog (PostHog, Inc.) as our data processor, currently hosted on its EU Cloud. PostHog processes this data only on our behalf under a data processing agreement; we do not use analytics data for advertising and we do not display third-party ads in the Service. With your consent, PostHog also captures anonymized session recordings that are configured to mask text inputs, to help us diagnose usability issues; you can decline or withdraw this at any time via our cookie banner.
Legitimate interests (to improve and optimize the Service). Where analytics rely on cookies or similar technologies that are not strictly necessary, we rely on your consent (Art. 6(1)(a) GDPR), which you can give or withdraw via our cookie banner.
4.8 Security, Fraud Prevention, and Abuse Detection
We process data to:
- detect and prevent unauthorized access or security incidents;
- investigate and respond to suspected fraudulent or abusive behavior;
- protect the Service, our users, and our infrastructure.
Legitimate interests (to ensure a secure and trustworthy Service); legal obligations.
4.9 Marketing and Communication (With Your Consent)
If you opt in (for example, by subscribing to our newsletter or selecting a preference), we may use your email address to send you:
- product updates, announcements, and feature highlights;
- promotional offers or surveys.
You may opt out at any time by clicking the "unsubscribe" link in any marketing email or by adjusting your preferences in the Service.
We do NOT send marketing emails without your consent or a legitimate basis.
Consent (Art. 6(1)(a) GDPR); or, where permitted by law, legitimate interests.
4.10 Legal and Regulatory Compliance
We may process your data to:
- comply with legal obligations (e.g. accounting, tax, anti-money laundering laws);
- respond to lawful requests from courts, law enforcement, or government authorities;
- enforce our Terms of Service or other agreements.
Legal obligations; legitimate interests.
4.11 Crash Reports and Diagnostic Data
To keep the app stable and to find and fix bugs, our mobile app automatically reports unexpected errors (crashes) it encounters. We use the diagnostic data described in Section 3.2 to:
- detect, reproduce, and fix crashes and other technical faults;
- monitor the stability and reliability of the app across versions and platforms;
- prioritise engineering work on the problems that affect the most users.
Crash reports from our mobile app are transmitted to and stored on our own backend infrastructure. We do NOT send them to a dedicated third-party crash-reporting service (such as Sentry or Firebase Crashlytics); they are handled by us, with the same safeguards as the other diagnostic and feedback data we process ourselves.
Crash reporting is enabled by default but is entirely optional. You can turn it off at any time in the app under Settings → About → Privacy (the "Send crash reports" toggle). When you turn it off, the app stops sending crash reports immediately, with no need to restart. Reports are only sent from released versions of the app, never from development builds.
Legitimate interests (Art. 6(1)(f) GDPR) — to ensure a stable, secure, and reliable Service. You can object to this processing at any time by switching the setting off as described above.
5. Cookies and Similar Technologies
We may use cookies and similar technologies (such as local storage or web beacons) to:
- remember your preferences and session state;
- analyze how you use the Service;
- deliver personalized content or features.
Types of cookies:
- Strictly necessary cookies: required for the Service to function (e.g. session management, security).
- Functional cookies: enhance functionality or remember your settings.
- Analytics cookies: help us understand usage patterns.
You can control or disable cookies via your browser settings. However, disabling certain cookies may limit your ability to use some features of the Service.
For more details on the cookies we use, please refer to our website or in-app cookie settings (if available).
6. Who We Share Your Personal Data With
We do not sell, rent, or trade your personal data. We only share your data in the following circumstances:
6.1 Service Providers and Processors
We may share your data with third-party vendors who provide services on our behalf, including:
- Cloud hosting and infrastructure providers;
- AI service providers — currently Google (Gemini), Microsoft (Azure AI Speech), and Cloudflare (Workers AI) — to power the Service's AI features and support message routing (see Section 4.3);
- Google Drive for optional data synchronisation initiated by you;
- Payment service providers;
- Product analytics — currently PostHog (PostHog, Inc.), hosted on EU Cloud — and monitoring or crash reporting services;
- Email delivery or customer support tools.
These third parties act as data processors and are contractually obligated to use your data only to provide the services we've requested and to keep it secure.
6.2 Google Drive (Synchronisation)
If you enable cloud synchronisation in the mobile app, your Oropen application data is stored in and retrieved from a dedicated app-specific folder within your Google Drive account. Google processes this data in accordance with its own terms of service and privacy policy.
The synchronisation is performed directly between the app on your device and Google Drive. We do not access or store a copy of your synchronised data on our own servers as part of this feature.
We do not access any other files or content in your Google Drive account beyond the dedicated Oropen folder.
6.3 Payment Service Providers
When you make a purchase:
Web purchases: Payment transactions on our website are processed by our third-party payment service provider. They collect and process your payment details in accordance with their own privacy policy and applicable payment card industry standards. We receive only the transaction-related data necessary to manage your subscription (such as confirmation of payment, subscription status, and transaction identifiers).
Google Play / Apple App Store: Purchases made in the mobile apps are handled by Google or Apple. They collect and process your payment data as independent controllers. We receive limited information (e.g. product purchased, country, subscription status) needed to enable your paid features.
6.4 Legal and Safety
We may disclose your personal data if required by law, regulation, legal process, or governmental request, or if we believe disclosure is reasonably necessary to:
- protect our rights, property, or safety;
- protect the rights, property, or safety of users or others;
- detect, prevent, or otherwise address fraud, security, or technical issues.
6.5 Business Transfers
If Eleheim GmbH is involved in a merger, acquisition, asset sale, or similar transaction, your personal data may be transferred as part of that transaction. We will take reasonable steps to ensure the confidentiality of personal data and notify you where required by law.
7. International Data Transfers
We are based in Germany, but some of our service providers and servers may be located in other countries, including outside the European Economic Area (EEA) and the United Kingdom.
Where we transfer personal data to countries without an adequacy decision by the European Commission, we put in place appropriate safeguards, such as the Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms, to protect your data.
This includes transfers that may occur when your data is processed by third-party AI model providers or cloud storage providers located outside the EEA.
You can contact us for more information about the safeguards we use.
8. Data Retention
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, or as required by law.
In particular:
- Account data is kept for as long as your account is active. Accounts that show no sign of use for an extended period may be deleted after we have made reasonable attempts to contact you by email beforehand. If you delete your account, or it is deleted following such a notice, we will delete or anonymise your personal data, unless we need to keep certain information for legal obligations (e.g. tax records) or legitimate interests (e.g. resolving disputes).
- Subscription and billing data may be stored for the period required by commercial and tax law (often up to 10 years, depending on the jurisdiction).
- User Content is stored for as long as you keep it in the Service and/or until you delete it or close your account.
- Camera and media data Photos captured via the in-app camera are stored locally on your device. Images submitted for note-scanning (OCR) are transmitted to our AI processor and deleted immediately after text extraction is complete; only the extracted text is retained as part of your User Content.
- Cloud-synchronised data stored in your Google Drive account remains under your control. Deleting your Oropen account does not automatically delete data stored in your personal Google Drive; you may remove the Oropen folder manually at any time.
- AI request cache as described in Section 4.3, inputs and outputs of AI requests are cached on our servers without any link to your account. Entries from very short inputs (three words or fewer) may be kept indefinitely as part of a shared, non-personal lookup store; entries from longer inputs expire and are deleted automatically after a short period (about a day or an hour for text, up to about a week for generated media). Your voice is never cached. You can request deletion of a specific entry by providing the exact content you submitted (see Section 4.3).
- Logs and technical data are typically kept for a shorter period, unless needed for security, troubleshooting, or legal reasons. Technical logs are deleted or anonymised automatically on a fixed schedule; because of their technical structure and their security purpose, we do not offer early deletion of individual log entries. Logs that are linked to your account are deleted when your account is deleted.
- Crash and diagnostic reports are kept only for as long as needed to investigate and resolve the underlying problem, and are then deleted or anonymised. We do not use crash diagnostics to build long-term profiles of individual users.
- Support and communication data is retained only for as long as reasonably necessary to handle your request, deal with follow-up questions on the same or related issues, and improve the quality of our service. Closed support sessions and feedback submissions are subsequently deleted or anonymised. Where we are required by law to keep certain communications (for example, in connection with a contractual or legal dispute), we keep them only for the period required by that legal basis.
When data is no longer needed, we will delete it or anonymise it in a secure manner.
9. Automated Decision-Making
We use automated processing to route and categorise incoming support messages (see Section 4.6 above). This processing does not produce decisions with legal or similarly significant effects on you. A human member of our team always reviews and responds to your inquiry.
If you have concerns about automated processing of your data, you may contact us at info@oropen.com to request manual handling.
10. Security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or disclosure, including:
- HTTPS encryption for data in transit;
- access controls to limit who can access production systems;
- regular backups and monitoring;
- secure development and operational practices;
- use of scoped OAuth tokens for cloud storage access, limited to app-specific folders only.
However, no system is completely secure. We cannot guarantee absolute security of your data. If you believe your account or data is no longer secure, please contact us immediately.
You are responsible for:
- keeping your password secret;
- using strong, unique passwords;
- securing your devices and keeping your software up to date;
- managing access permissions for any connected cloud storage accounts.
11. Your Rights (EU / EEA / UK and Similar Jurisdictions)
If you are in the European Union, EEA, UK, or another jurisdiction with similar data protection laws, you may have the following rights regarding your personal data:
- Right of access — to obtain confirmation whether we process your personal data and a copy of that data.
- Right to rectification — to correct inaccurate or incomplete personal data.
- Right to erasure ("right to be forgotten") — to request deletion of your personal data in certain circumstances.
- Right to restriction of processing — to request that we limit processing in certain situations.
- Right to data portability — to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller where technically feasible.
- Right to object — to object to processing based on our legitimate interests, including profiling and automated support message routing; and to object to direct marketing at any time.
- Right to withdraw consent — where processing is based on your consent (including consent for cloud synchronisation), you may withdraw that consent at any time, without affecting the lawfulness of processing before withdrawal.
To exercise these rights, please contact us at info@oropen.com or via our contact page. We may need to verify your identity before fulfilling your request.
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU/EEA member state or UK country of your habitual residence, place of work, or place of the alleged infringement. In Germany, this is typically the data protection authority of your federal state.
12. Children's Privacy
The Service is intended for adults aged 18 and over, and we do not knowingly collect personal data from children. Where a minor uses the Service, this must be done through, and under the supervision of, an account held by their parent or legal guardian, who provides any consent required on the minor's behalf.
If we become aware that we have created an account for, or collected personal data directly from, a child in violation of this Policy or applicable law, we will take steps to delete that data. If you believe a child has provided us with personal data, please contact us.
13. Third-Party Links and Services
The Service may contain links to third-party websites, apps, or services (such as payment processors, Google Play, the Apple App Store, or Google Drive). We are not responsible for the privacy practices or content of those third parties.
We encourage you to read the privacy policies of every website, app, or service you visit.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will:
- publish the updated version on https://oropen.com/privacy, and
- update the "Last updated" date at the top.
If we make significant changes, we may also notify you by email or via the Service. The version published on this page applies from the "Last updated" date shown at the top.
15. How to Contact Us
If you have any questions, requests, or concerns about this Privacy Policy or our data practices, please contact us at:
Eleheim GmbHSchellingstraße 109a
80798 Munich, Germany
Website: https://oropen.com
Email: info@oropen.com
Contact Page: /contact