Privacy Policy

Last updated 19 August 2026

Froga is a learning platform built around public track records, so it's important to be precise about what's visible to others and what isn't. This page explains what we collect, why, and what control you have.

Draft — not yet in force. This document has not been through a legal review and may be incomplete. It is published early so it can be read and corrected; it does not yet bind anyone. Set LEGAL_DRAFT = false once reviewed.

Who is responsible

Turhan Ergene operates Froga and is the data controller for the personal data described here. For any privacy question or request, contact [email protected].

What we collect

Only what the product actually needs to work:

  • Account — your email address and a securely hashed password, or, if you sign in with Google, the account identifier Google returns. We never see your Google password.
  • Profile — username, and optionally a display name, avatar, bio, interests, occupation, how you heard about us, and website/GitHub/LinkedIn links. Everything except the username is optional.
  • Learning activity— which rooms you start and finish, your score, and per-question detail: the answer you submitted, whether it was correct, and how long you took. This is what powers your results, level, streak and badges, and creators' analytics for their own rooms.
  • Things you create — rooms, questions, learning paths and any images you upload.
  • Social actions — who you follow, your bookmarks, and the star ratings you give.
  • Safety records — reports you submit, and any moderation action taken on your account (including the reason).
  • Service records — if you use the AI features, a record of each generation (which feature, which model, how many tokens, what it cost) so we can apply per-account limits. If you change your email address, a timestamped record that you did, so we can rate-limit it. Neither stores the content you submitted or the address you asked for.

We do not collect payment data. There is no checkout on Froga today; premium is granted manually. If that changes, this page will be updated before any payment is taken.

What is public

This is the part most worth reading. Froga profiles are public by design — the point is a shareable track record — and public means visible to anyone on the internet, including people who are not logged in, and to search engines.

Publicly visible on your profile at /u/your-username:

  • Your username, display name, avatar, bio, occupation, links, and the month you joined.
  • Your username and room title, shown as the credited original on any copy another user makes of a room you published.
  • Your level and XP, average score, category mastery, a 30-day activity graph, and badges.
  • Rooms you created and set to Public, along with their ratings.
  • Your follower and following lists.

Two things you control, both in profile settings:

  • Recently solved— the list of individual rooms you completed. Turn this off and it disappears for everyone else. Your aggregate stats (level, average, mastery, activity) stay public either way, because they don't identify any individual test.
  • Show my name to creators— turn this off and your name and avatar are hidden from a creator's analytics for rooms you played. Your result still counts toward their aggregate numbers.

Your email address is never public. It is visible only to you and, for support and moderation purposes, to Froga staff.

Why we process it (legal bases)

  • To perform our contract with you — running your account, saving your results, showing your progress.
  • Legitimate interests — keeping the platform safe and free of spam and abuse, and preventing people from forging their own scores.
  • Consent — the optional profile fields, which you can clear at any time.

Who we share it with

We do not sell your data, and we do not use it for advertising. We share it only with the providers needed to run the service:

  • Supabase — our database, authentication and file storage provider. Your account, profile, activity and uploads are stored there, in their EU (Ireland) region.
  • Railway — hosts the application itself. Requests pass through it, which means it processes your IP address and standard server logs.
  • Resend, delivering through Amazon SES — sends our transactional email (sign-up confirmation, password reset, email-change confirmation). They process your email address and the contents of those messages. We send no marketing email.
  • OpenAI — only if you use the AI-assisted question generation, and only the text you submit to it. See the next section.
  • Google — only if you choose to sign in with Google, and only to verify that sign-in.
  • Cloudflare — routes mail sent to our published contact addresses, so a message you send us passes through it.

Froga currently runs no third-party analytics, advertising or session-recording tools. Our web fonts are served from our own servers, so loading a page does not send your IP address to a font provider. We may also disclose data where we are legally required to.

AI-assisted features

Creators can have questions drafted automatically from a topic or a passage of source text. This is optional, it is not part of playing a room, and if you never use it nothing of yours is sent to an AI provider.

When you do use it:

  • What is sent is the text you typed — your topic, instructions or source material — together with our own fixed instructions to the model. Nothing else travels with it: no username, no email address, no account identifier.
  • The provider today is OpenAI, which processes the request in the United States.
  • Drafts come back to you for review and are stored only if you choose to add them to a room. Nothing is written to your room automatically.
  • We keep a record that a generation happened — feature, model, token counts, cost — to enforce per-account limits. That record does not include what you wrote.

Don't paste anything confidential, or anyone else's personal data, into the generator. It leaves our systems, and once it has, it is governed by the provider's terms rather than ours.

Where your data is stored

Your account, profile, learning activity and uploads live in the EU — Supabase's Ireland region — and our transactional email is delivered from Amazon SES in Ireland too.

Two things leave the EU/EEA. Text you submit to the AI generator is processed by OpenAI in the United States. Our hosting and mail-routing providers are US-headquartered companies and may process data, in particular server logs, outside the EEA. Where that happens, the transfer relies on the European Commission's Standard Contractual Clauses in those providers' data processing terms.

Cookies and local storage

We use cookies strictly to keep you signed in — they hold your authentication session and nothing else. Your light/dark theme preference is kept in your browser's local storage and never leaves your device. There are no advertising or tracking cookies, so there is no consent banner to click through.

How long we keep it

Your account data is kept for as long as your account exists. Delete your account and it goes, as described below. Moderation records are kept after deletion for as long as needed to enforce our rules, but the link to your account is removed, so they no longer identify you.

Deleting your account

You can delete your account yourself, at any time, from profile settings. No email, no waiting period. It takes effect immediately and cannot be undone.

Deleting your account permanently removes:

  • Your login and profile, including every optional field and your avatar.
  • Every room, question and learning path you created — including rooms other people have played or added to their own learning paths.
  • Your entire play history, scores and per-question answers.
  • Your follows, bookmarks and the ratings you gave.

Moderation records naming you as the actor are kept but anonymised. Because deletion also removes content other people may be using, consider transferring or unpublishing rooms you want to survive before deleting.

Your rights

If you are in the EU/EEA or UK you have the right to access, correct, export, restrict or object to our processing of your personal data, to withdraw consent, and to have your data erased. Most of these you can exercise directly in the app: edit your profile to correct data, use the visibility toggles to restrict it, and delete your account to erase it. For anything else — in particular a copy of your data in portable form — email [email protected] and we'll respond within one month.

You also have the right to lodge a complaint with your local data protection supervisory authority.

Children

Froga is not intended for children under 16. We don't knowingly collect data from them; if you believe a child has created an account, contact us and we will remove it.

Changes

If we change this policy materially, we will update the date at the top of this page and, for significant changes, tell you in the app before they take effect.