Privacy policy
Last updated: September 18, 2026.
Summary: we know neither your name nor your email address. We keep an opaque identifier provided by Google, your drill results and the practice language you chose. Nothing else.
This page translates the French politique de confidentialité of the same date. If the two differ, the French version prevails.
Who is responsible
entrainear is published by Marton Hever, an individual residing in Nova Scotia (Canada), who is the data controller and also acts as the person in charge of the protection of personal information within the meaning of Quebec's Law 25.
Contact for any question or to exercise your rights: support@entrainear.com.
What we collect
-
An opaque account identifier. When you sign in, Google
sends us a technical identifier (the OpenID subject), a string
of digits specific to your Google account and to our application. We
request only the
openidscope, so Google sends us neither your name, nor your email address, nor your photo: we do not receive them, and so we cannot store them. - An account number. Your account carries a plain number with us, assigned by our software and shown in "My account": it identifies your account to us and nothing else, and it is what you can give us to report a problem. If you write to us, we receive the address your message comes from and use it only to reply to you.
- Your practice data. For each answer: the question concerned, the exact text you entered, whether the answer was correct, the mode (accents, practice or exam) and the timestamp. From these we derive a success count per skill, which is the core of the service.
- The practice language (French or English) you chose, which decides the drills you are served.
- Technical timestamps: account creation, last activity, creation and expiry of your sessions.
- The version of the terms of use you accepted (the date at the top of that document, not of this policy) and the date of that acceptance, checked at each sign-in and recorded once per version. This is what lets us know, without an email address, who has not yet accepted a changed version.
What we do not collect
- No name, email address, profile photo, date of birth or country.
- No IP address in our own logs: our server writes no request log. That does not mean no IP address is processed. Cloudflare and our hosting provider, which are our processors and therefore act on our behalf, record technical connection data, including your IP address, for security and abuse prevention, for a short period. We do not access it in the normal course of the service.
-
No advertising tracker, and no audience measurement tool of our own: we
install none and we look at no traffic statistics. The page you are
reading loads no third-party script. Apart from signing in, the only
domains the application contacts are ours: this site,
api.entrainear.comfor your drills andaudio.entrainear.comfor the audio files. Signing in is the exception by nature: the button redirects you to Google, which is the authentication service. - No recording of your microphone: the drills only ask you to listen, never to speak.
We sell no data, we rent none, and we pass none on for advertising.
Pseudonymous does not mean anonymous
An opaque identifier associated with a history of answers is still personal data under the GDPR, PIPEDA and Law 25. We do not claim otherwise. It simply means that we hold the minimum needed, not that we hold nothing.
Why we are allowed to process this data
- Performance of the service you request (GDPR art. 6(1)(b)): without an account identifier and a history of answers, there is neither saved progress nor targeted drills.
- Legitimate interest (GDPR art. 6(1)(f)) in the security of the service: preventing abuse and keeping the service available.
Cookies
Two cookies, both strictly necessary for the service to work. No measurement or advertising cookie, and therefore no consent banner: there is nothing to consent to.
-
__Host-pme_session: your session. Lasts 30 days, renewed with use. It holds a random token; on the server side we store only a SHA-256 hash of that token, never the token itself, so that a backup copy contains no usable identifier. -
__Host-pme_authbind: during sign-in only, to bind the sign-in request to the browser that started it (protection against session fixation attacks). Lasts 24 hours.
Both are HttpOnly, Secure and
SameSite=Lax, so no script can read them and they are never
sent unencrypted.
Who else sees anything
- Google (Google Ireland Limited for the European Economic Area), for authentication. Google knows that you sign in to entrainear and when. Google never receives your drill results. See Google's privacy policy.
- Cloudflare: domain name, content delivery network, web application firewall, hosting of the static pages, storage of the audio files and of the backup copies, encrypted in transit. Cloudflare sees the requests that pass through its network, including your IP address, and keeps a short-lived technical log of them. Cloudflare and Hetzner act as processors on our behalf, not on their own: that processing is legally attributable to us, which is why it is described here rather than left unsaid.
- Hetzner Online GmbH, Nuremberg, Germany: the application server and the database are hosted there.
- ElevenLabs: used to make the audio recordings, upstream and offline. No user data is ever passed to it.
We use no other processor. If a payment service is ever added, this page will change before, not after.
Where the data is
The database is in Germany, in the European Union, and the copies taken before each update stay on that same server. The continuous replication of the database and the audio files are with Cloudflare, whose network is global. The publisher is in Canada and accesses them remotely: Canada has an adequacy decision from the European Commission for organizations covered by PIPEDA, and transfers to Cloudflare rely on the standard contractual clauses.
Communication outside Quebec (Law 25): your personal information is kept and processed outside Quebec, in Germany and on Cloudflare's global network, as well as in Canada where the publisher resides. It is subject to local law there, which may allow foreign authorities to access it in the cases their legislation provides for. What actually limits the exposure is the minimal collection described above: there is neither a name nor an email address to disclose.
How long
- Your account and your results: as long as the account exists. There is no automatic erasure today. The feature exists in the software but it is switched off. If we switch it on, the period chosen will be about 18 months, and the software refuses any period shorter than 90 days of inactivity in any case: that is the floor below which automatic deletion is impossible, whatever the configuration. Deletion would happen without prior warning, since we do not have your email address. This page will change at the same time as the switch-on, with the exact period, and the date at the top will let you see it.
- Sessions: 30 days, then erased by a periodic purge.
- Unfinished sign-ins: 10 minutes, then erased.
- Account deletion: immediate and permanent, see below.
We do not hold your email address, which has a consequence we prefer to put in writing: we cannot warn you before a deletion for inactivity, nor contact you individually in case of an incident. That is the price of minimal collection.
Your rights
Two of them are buttons in the application, under My account, and work immediately without going through us:
- Access and portability: "Download my data" produces a JSON file containing everything we hold about you: account, sign-in identifiers, sessions, statistics per skill, every attempt and every drill served.
-
Erasure: "Delete my account" erases the account, the
associated Google identifier, the sessions, the attempts, the statistics
and the drills. The operation is irreversible and there is no recycle
bin. We keep no copy, with three exceptions, all technical backups:
- The continuous replication of the database to Cloudflare, where the deletion propagates immediately. Earlier snapshots may still contain your data for a while: a full snapshot is taken every 24 hours, and each one is kept for 24 hours before being erased. We commit to up to 48 hours after your deletion, which leaves the margin needed for the snapshot cadence and for when the rule is applied. Two cases lengthen that period: a prolonged replication outage, which also suspends the erasure of snapshots, and a long period without any activity on the service, because it is the arrival of new data that pushes the old data out of the window.
- The last ten copies taken just before an update of the service, files kept on the server in Germany. These ten copies are replaced in rotation at each update, which is a number and not a duration: if we deploy nothing for several months, the oldest one stays that long.
- Copies taken by hand during an emergency repair, if there are any, kept on the same server in Germany. Today they are neither counted nor erased automatically, precisely because they exist when something has gone wrong, and they go only when we delete them by hand.
You also have a right to rectification, restriction and objection. In practice, the only data we hold is your own answers; if there is an error to correct, write to us.
If our answer does not satisfy you, you can complain to your supervisory authority: the CNIL in France, the data protection authority of your country in the European Union, the Commission d'accès à l'information in Quebec, or the Office of the Privacy Commissioner of Canada.
Security
All traffic is encrypted over HTTPS. Session tokens are stored only as a hash. On the modifying requests the application sends (answering a drill, signing out, deleting the account), the server requires both that the request come from the site's official address and that it carry a specific header, which blocks requests forged from another site. Signing in is the exception, because it cannot carry one: it is a redirect from Google, protected by the OpenID Connect protocol and by a cookie that binds the request to the browser that started it. The page runs no third-party script, which a strict content security policy enforces. No system is perfect, and we will not claim otherwise.
In the event of a data breach presenting a risk, we will inform the competent authorities within the legal deadlines and we will inform you by every means available to us: a visible notice on this page and on the home page, and a message in the application. Since we do not hold your email address, we cannot write to you individually; that is not a refusal to warn you, but the limit of what minimal collection makes possible.
Minors
The service is intended for adult language test candidates. It is not meant for people under 16 and we do not knowingly collect their data.
Changes
This page changes when the service changes, and the date at the top is updated at the same time. A substantial change will be announced in the application.