← Back to home

Privacy Policy

Last updated: 11 September 2026. This English version is the binding version of this Privacy Policy.

This Privacy Policy explains how Studio Auralis, operated by Sven Saborowski as a sole trader registered in Finland with business ID Y-tunnus 3577773-3, registered address Graniittilinnankatu 1, 20100 Turku, Finland, collects, uses, discloses, and protects personal data. In this Policy, “we”, “us”, “our”, and “the Provider” refer to Studio Auralis. These terms apply when you use the Medborgarskapsprovet and Samhällskunskapsprovet websites and mobile apps for Android and iOS, together called “the Service”. Sections labelled “mobile app only” apply only if you use our Android or iOS app; everything else applies to both the website and the app. We are the data controller for the personal data described in this Policy. This Policy should be read together with our Terms of Use.

1. Personal data we collect

We collect the following categories of personal data:

  1. Account data. We collect your email address and password through Firebase Authentication, our authentication provider. Firebase stores your password in hashed form; we never see it directly. If you sign in with Google instead, we collect your name, email address, and profile picture as provided by Google.
  2. Usage and progress data. Quiz results, answered and missed questions, study streaks, daily activity statistics, and other progress data you generate while using the Service, stored against your account in our Firestore database.
  3. Payment and subscription data. If you purchase a Subscription, our payment processor, Stripe, and our subscription management provider, RevenueCat, process your payment details, such as card information, and your billing information on our behalf. We never receive or store your full card number. We do receive transaction metadata needed to grant you access to the Service, such as the plan purchased, the amount, and your subscription status.
  4. Content you submit. Reviews, ratings, question reports, and account-deletion feedback you choose to submit through the Service.
  5. Server log data. Whenever you access the Service, our hosting infrastructure, Firebase App Hosting on Google Cloud, automatically records technical data such as your IP address, browser type, operating system, referring page, and date and time of access. This data is used solely to operate, secure, and troubleshoot the Service and is not combined with other data sources.
  6. Analytics data. If you consent to analytics cookies, we collect usage data through Google Analytics, such as pages visited, general device and browser information, and approximate location derived from your IP address. See Section 5 on cookies and analytics.

2. Mobile app only: additional data we collect

If you use our Android or iOS app, we collect the following additional categories of personal data, on top of Section 1 above:

  1. Crash and diagnostic data. Via Firebase Crashlytics, we automatically collect crash reports and error diagnostics when the app crashes or encounters an error, so we can find and fix bugs. These reports include information such as stack traces, device model, operating system version, and app version.
  2. Push notification data. If you grant notification permission, we use Firebase Cloud Messaging to store a device-specific push token linked to your account. We use this token to send you service-related notifications, such as reminders about your subscription or your studies. This token is deleted when you delete your account.
  3. App integrity data. Via Firebase App Check, the app sends a device attestation token to our backend to verify that requests come from a genuine, unmodified copy of the app, which helps prevent abuse and fraud. This does not identify you personally.
  4. Advertising identifier, Android only. Firebase Analytics on Android may access your device’s resettable Advertising ID. We use it only in aggregate form for app usage analytics — we do not use it for ad personalization or ad targeting, and the app does not show ads. You can reset or limit this identifier in your Android device’s privacy settings.
  5. On-device settings. Your language and quiz preferences are stored locally on your device only, not sent to us, so the app can remember them between sessions.

3. How we use your personal data

We only process personal data where we have a valid legal basis under Article 6 GDPR. We use personal data for the following purposes:

  1. to create and manage your account and authenticate you. Legal basis: performance of a contract, Art. 6(1)(b) GDPR;
  2. to provide the Service, including tracking your quiz progress, streaks, and study statistics across sessions. Legal basis: Art. 6(1)(b) GDPR;
  3. to process payments, manage your Subscription, and grant or revoke access to paid content accordingly. Legal basis: Art. 6(1)(b) GDPR;
  4. to respond to question reports, reviews, and support requests you submit. Legal basis: Art. 6(1)(b) GDPR, and Art. 6(1)(f) GDPR, our legitimate interest in maintaining content quality;
  5. to detect and prevent abuse of the Service, including the prohibited uses described in our Terms of Use. Legal basis: Art. 6(1)(f) GDPR, legitimate interest;
  6. to understand aggregate usage of the Service and improve it, where you have given analytics cookie consent. Legal basis: Art. 6(1)(a) GDPR, consent;
  7. mobile app only: to send you push notifications where you have granted notification permission on your device, and to diagnose crashes and verify app integrity via Crashlytics and App Check. Legal basis: Art. 6(1)(a) GDPR, consent, for notifications, and Art. 6(1)(f) GDPR, our legitimate interest in a secure, functioning app, for Crashlytics and App Check;
  8. to comply with legal obligations, such as accounting and tax requirements relating to payments. Legal basis: Art. 6(1)(c) GDPR, legal obligation; and
  9. to operate, secure, and troubleshoot the Service using server log data. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in a functioning and secure Service.

You must provide account data, meaning your email address and password or your Google login, to create an account and use the Service; without it, we cannot give you access. Providing payment data is required only if you choose to purchase a Subscription. All other data is provided voluntarily, such as reviews, question reports, and analytics.

We do not carry out automated decision-making or profiling within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you.

4. Who we share personal data with

We do not sell your personal data. We share personal data with the following categories of recipients, each acting as a processor on our behalf or, where noted, as an independent controller of data you provide directly to them:

  1. Firebase / Google Cloud — Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The ultimate parent company is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. We use Firebase for authentication and Firestore database hosting, covering account and progress data. In the mobile app, this also covers Firebase Crashlytics for crash diagnostics, Firebase Cloud Messaging for push notification delivery, and Firebase App Check for app integrity verification — all part of the same Firebase / Google Cloud service. Firebase acts as a processor on our behalf under a data processing agreement; see Firebase’s Privacy and Security in Firebase and Google’s Privacy Policy.
  2. Stripe — Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. The ultimate parent company is Stripe, Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA. Stripe processes payments and acts as an independent controller for the payment data it collects directly from you at checkout; see Stripe’s Privacy Policy.
  3. RevenueCat — RevenueCat, Inc., 2261 Market Street #5666, San Francisco, CA 94114, USA. RevenueCat manages subscriptions and entitlements, meaning it determines which paid content your account may access, and acts as a processor on our behalf; see RevenueCat’s Privacy Policy.
  4. Google Analytics, GA4 — Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The ultimate parent company is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. We use Google Analytics for usage analytics. On the website, this only runs if you have granted analytics cookie consent. In the mobile app, it runs via Firebase Analytics, which may use your device’s Advertising ID as described in Section 2. See Google’s Privacy Policy and Google Analytics data safeguards. You can also opt out of Google Analytics for all websites using the Google Analytics opt-out browser add-on.
  5. Law enforcement, regulators, or other third parties where required by law, to enforce our Terms of Use, or to protect the rights, property, or safety of the Provider, our users, or others.

5. Cookies and analytics

This section applies to the website. We use a strictly necessary cookie/local storage entry to remember your cookie consent choice, and, where you consent, Google Analytics cookies to measure usage of the Service. Analytics cookies are off by default, using Google Consent Mode’s “denied” setting, and are only activated after you click “Accept” on the cookie banner. You can withdraw consent at any time by clearing your browser’s local storage for this site or, where available, via the cookie banner settings.

Firebase Authentication also stores a session token in your browser’s local storage so that you stay logged in between visits. This is strictly necessary for the Service to function and is not an analytics or advertising cookie.

The mobile app does not use cookies. It stores your session and preferences locally on your device instead, as described in Section 2, and Firebase Analytics on the app operates without a cookie banner, in line with each app store’s data disclosure requirements.

6. International data transfers

Google (Firebase, Google Analytics), Stripe, and RevenueCat may process personal data on servers located outside Finland and the European Economic Area (EEA), including in the United States. Where this occurs, these providers rely on recognized transfer safeguards, such as the European Commission’s Standard Contractual Clauses, to protect your personal data.

7. Data retention

We retain account and progress data for as long as your account is active. If you delete your account through the Service, using Account settings → Delete account, we delete your progress data, missed questions, and Firebase Authentication account. We may retain limited records for longer where required by law, such as anonymized account-deletion feedback or transaction records needed for accounting and tax purposes.

8. Your rights

You have the following rights under applicable data protection law, subject to its conditions. This includes the GDPR as implemented in Sweden through the Act with Supplementary Provisions to the EU Data Protection Regulation, lagen 2018:218 med kompletterande bestämmelser till EU:s dataskyddsförordning, and in Finland through the Data Protection Act, tietosuojalaki, depending on where you reside:

  1. access the personal data we hold about you;
  2. request correction of inaccurate personal data;
  3. request erasure of your personal data, including via the self-service “Delete account” feature in your account settings;
  4. request restriction of, or object to, certain processing;
  5. request a portable copy of your personal data; and
  6. withdraw consent at any time, for example for analytics cookies, without affecting the lawfulness of processing carried out before the withdrawal.

To exercise these rights, contact us at the email address in Section 11.

9. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. As the Provider is established in Finland, the lead authority is:

Office of the Data Protection Ombudsman, Tietosuojavaltuutetun toimisto
PL 800, Ratapihantie 9, 00521 Helsinki, Finland
tietosuoja.fi

You may also lodge a complaint with the supervisory authority of your own country of residence, for example the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten, IMY, imy.se, for users resident in Sweden. A full list of EU/EEA supervisory authorities is available at edpb.europa.eu.

10. Children

The Service is intended for users aged 16 or older, consistent with our Terms of Use. We do not knowingly collect personal data from children under this age. If you believe a child has provided us with personal data without appropriate consent, please contact us so we can delete it.

11. Contact and changes to this Policy

Questions about this Privacy Policy, or requests to exercise your data protection rights, can be sent to fi.studio.auralis@gmail.com. We may update this Policy from time to time; material changes will be reflected by updating the “Last updated” date above.