Privacy Policy
Last updated: 15 August 2026
This policy describes how Vurmify processes your personal data and what rights you have. We collect as little as possible, never sell your data and use no advertising trackers.
1. Who is responsible for your data
Vurmify is run jointly by Jacob Melin and Jonathan Yttergård, both private individuals. We are joint controllers (Art. 26 GDPR) for the processing described here. You may contact either of us, via the contact address below, to exercise your rights (see section 7).
- Contact: [email protected]
- A postal address is provided on request via the contact address above.
2. What data we collect
2.1 Account data
You can create an account in two ways: with an email address and password, or by signing in with Google.
With email and password: we store your email address and your password. The password is never stored in clear text - it is handled and stored hashed by our authentication provider (Supabase). We cannot see your password.
2.2 If you sign in with Google
If you choose "Continue with Google" you are sent to Google to sign in. Your Google password never leaves Google and never reaches us. Once you have approved the sign-in, we receive a limited set of data from your Google account:
- your email address and whether Google has verified it
- your name and a link to your Google profile picture
- a technical account ID at Google, which ties your sign-in to the right account with us
The data is stored with our authentication provider (Supabase) as part of your account, so that you can sign in again. We never publish your real name or your Google profile picture. The leaderboard only shows a display name that you choose yourself, and until you have chosen one it says "Anonymous". Your Google profile picture is never shown in the service; avatars are drawn characters served from our own server.
We ask Google for nothing more than this. We get no access to your Gmail, your contacts, your calendar or any other Google service. You can withdraw the connection at any time under your Google account → Apps with access to your account. That does not delete your Vurmify account; you do that in the app (see section 7).
2.3 Profile data
- Display name (optional; shown to other users on leaderboards only if you have turned on "Show me on leaderboards", see section 3)
- Avatar - we only store a short text seed (e.g.
Felix), not an image
2.4 Study data
To be able to save your progress we store:
- Which lessons you have completed and with what result
- Which exams you have passed and with what result
- XP, current streak, longest streak, last day played
- Your XP history per day (for charts and weekly leagues)
- Your review schedule and progress in daily quests and weekly challenges
2.5 Usage statistics
We log simple events in order to understand where in the service users get stuck, for example that the app has been opened or that a lesson has been started or completed.
- If you are signed in, the event is linked to your account.
- If you are signed out, the event is stored with no identifier at all. We can see that something happened, but never that two events came from the same visitor, and we store nothing on your device for statistics.
We do not collect IP addresses, device IDs or location data in our own statistics, and we use no advertising trackers or tracking cookies.
2.6 Information stored locally in your browser
We set no cookies of our own. Instead we use localStorage so
that the service works:
| Key | Contents | Purpose |
|---|---|---|
vurmify_v6 | Your progress | So the app works offline and between visits |
vurmify_lang | Chosen language | Remembers your language |
vurmify_home_path | Chosen course on the start page | Remembers your choice |
sb-...-auth-token | Your sign-in session | Keeps you signed in |
Our hosting provider Cloudflare may set a strictly necessary security
cookie (e.g. __cf_bm) to protect the site against abuse and automated
traffic. Such strictly necessary cookies do not require consent and are not used to track you
across websites. If you click "Continue with Google", Google sets its own cookies on
Google's domain, as part of the sign-in you started yourself. We set no
cookies on our side and cannot read Google's.
You can clear localStorage at any time via your browser settings. That signs you out and removes locally saved progress (progress that has been synced to your account remains).
2.7 Do you have to provide the data?
To have an account we need to be able to identify you. If you register with email, an email address and a password are required; if you sign in with Google, the data Google sends us is required (section 2.2). Without it we cannot provide the service. Display name and avatar are entirely optional. Study and usage data is created automatically as you use the service.
3. Why we process the data and on what legal basis
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Create and run your account, save and sync your progress | Performance of a contract (6.1 b) |
| Sign you in with Google, if you choose that method | Performance of a contract (6.1 b) - you choose the method yourself, email and password work just as well |
| Show you on leaderboards and in the league (display name, avatar, XP, streak) | Consent (6.1 a) - see the paragraph below the table |
| Send necessary emails (confirmation, password reset) | Performance of a contract (6.1 b) |
| Protect against abuse: CAPTCHA, checking against known leaked passwords, anti-cheating rules | Legitimate interest (6.1 f) - keeping the service secure |
| Understand how the service is used and improve it (aggregated statistics) | Legitimate interest (6.1 f) |
About the leaderboards and your consent. The leaderboards and the league are public: anything shown there can be read by anyone, including visitors who are not signed in. That is why you are not shown on them unless you have said yes yourself. The setting "Show me on leaderboards" lives in your profile and is off by default - it is not pre-ticked, and a new account never ends up on a list on its own. Turning it on shares your display name, avatar, XP and streak. You can withdraw your consent at any time by switching the same setting off; you then disappear from the leaderboards and the league immediately. Saying no affects nothing else in the service - all lessons, exams and progress work exactly the same.
We never sell your data and do not use it for advertising.
4. Who we share data with
We use the following providers (processors and third parties). They only receive the data needed for their function:
| Provider | Function | What they receive |
|---|---|---|
| Supabase (servers within the EU, Ireland) | Database, authentication, server functions | Account and study data |
| Cloudflare | Hosting (Pages), CAPTCHA (Turnstile) and email forwarding for our contact address | Technical traffic data, e.g. IP address. If you write to us, the sender address and the contents of your email pass through their email service as well. |
| Google (Google Ireland Limited) only if you choose "Continue with Google" | Sign-in with a Google account, and the support address shown on Google's consent screen, which is a Google Group | That you in particular signed in to Vurmify, together with the technical information Google itself collects about the sign-in. Google is an independent controller for its own processing of your Google account. If you write to the support address shown on the consent screen ([email protected]), the sender address and the contents of your email pass through Google's group service. |
| Resend | Sending transactional email | Your email address and the content of the message |
| Have I Been Pwned | Checking for leaked passwords at registration | Only the first five characters of a hash of the password - never the password, and the service cannot reconstruct it |
Note in particular: the leaked-password check is built so that your password never leaves your browser. Only a short hash prefix is sent, which matches thousands of different passwords at once (known as k-anonymity). The fonts, the software libraries (such as the animation and sign-in libraries) and the avatar images are served from our own server - we do not use Google Fonts or an external avatar service, and therefore send them no data. The exception is Cloudflare Turnstile (CAPTCHA), whose script is loaded from Cloudflare on the sign-in and registration page; beyond that we load no code from external CDNs.
About Google: we send no data to Google when you merely visit or use Vurmify. Contact with Google arises only if you yourself click "Continue with Google", and then happens by you being sent to Google's own sign-in page. We load no Google script on our pages. If you choose email and password instead, Google never learns that you use Vurmify.
5. Where the data is stored and transfers outside the EU/EEA
Your account and study data is stored with Supabase on servers within the EU (Ireland).
Resend (sending transactional email) stores account and metadata as well as logs in the USA, regardless of the chosen sending region - even though the email itself is sent from the EU/Ireland. This is a confirmed transfer to a third country. The transfer takes place on the basis of the European Commission's Standard Contractual Clauses (SCC).
Google (only if you choose Google sign-in): your counterparty is Google Ireland Limited within the EU, but Google also processes data in the USA. Google is certified under the EU-U.S. Data Privacy Framework, which the European Commission has decided provides an adequate level of protection, and additionally applies Standard Contractual Clauses. How Google processes your Google account is governed by Google's own privacy policy, not by this one.
Other providers (Cloudflare, Have I Been Pwned) may process data, such as IP address or email address, outside the EU/EEA. Such transfers take place on the basis of the European Commission's Standard Contractual Clauses or equivalent safeguards.
6. How long we keep the data
- Account data and study data: for as long as your account exists. If you delete your account, everything is removed immediately and permanently (see section 7).
- Usage statistics: individual events (raw data) are deleted on an ongoing basis, at the latest after about 30 days. Only anonymised, aggregated statistics per day - with no connection to you as a person - are kept longer in order to follow trends over time.
7. Your rights
Under the GDPR you have the right to:
- Access the data we hold about you
- Rectify incorrect data (you change your display name and avatar yourself in your profile)
- Erase your data - you can do this yourself directly in the app: Profile → Delete account. Your account and your progress are deleted immediately and permanently. Statistics that were linked to the account are de-identified at that same moment; any remaining anonymous raw data is then cleared on an ongoing basis (see section 6). We take no backups of the database, so there is no copy in which your data could remain after deletion. Should we start taking backups, we will update this policy and state how long a deleted item may remain in them. If you signed in with Google, the connection to your Google account disappears at the same moment; the Google account itself we do not touch.
- Object to processing carried out on the basis of legitimate interest
- Withdraw a consent at any time (Art. 7(3)). This applies to the leaderboards and the league: switch off "Show me on leaderboards" in your profile and we stop showing you there. Withdrawing consent does not affect processing that was lawful before you did so.
- Receive your data in a machine-readable format (data portability)
- Restrict processing in certain cases
Contact us at [email protected] to exercise your rights.
If you are unhappy with how we process your data, you have the right to complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), imy.se.
7.1 Automated decision-making and profiling
We use no automated decision-making that has legal effects for you or similarly significantly affects you (Art. 22 GDPR). XP, streaks and leaderboards are calculated by machine, but this is simple point-counting that does not affect your rights or opportunities, and we do not profile you.
8. How we protect the data
- All traffic goes over HTTPS and is forced to HTTPS (HSTS)
- The database is protected by row-level access rules (Row Level Security) - technically, each user can only reach their own rows
- Passwords are stored hashed, never in clear text, and are checked against requirements for length and complexity
- If you sign in with Google we store no password for you at all, and your Google password never reaches us
- CAPTCHA protects registration, sign-in and password reset
- Points and progress are awarded by the server, not by the browser, to prevent manipulation
Should a personal data breach nevertheless occur that entails a risk to your rights and freedoms, we will report it to the Swedish Authority for Privacy Protection (IMY) within 72 hours of becoming aware of it, and inform you directly where the law requires it.
9. Age
Vurmify is not directed at children under 13 (the age of consent for data processing in Sweden). You must confirm that you are at least 13 before the account can be used, whether you register with email or sign in with Google. The requirement is enforced on our server: registering with email creates no account without the confirmation, and if you sign in with Google the service cannot be used until you have confirmed in the app. If you are a guardian and believe your child has created an account, contact us and we will remove it.
10. Changes to this policy
We may update this policy. We will give notice in the app of any significant changes. The date at the top shows when it was last changed. If the party responsible for the service changes (for example if operations pass to a company), we will update the details in section 1.
11. Contact
Jacob Melin and Jonathan Yttergård
[email protected]
Vurmify