Privacy policy
Dhana — version of 12 September 2026 ·
Français ·
Deutsch
Dhana is a language-learning app. It is designed to know as little as possible
about you: what you learn stays on your phone, and the server keeps only what it needs to
recognise your account and to limit what it produces.
Who is responsible for your data
René Obe, publisher of Dhana.
Postal address: Schloßstraße 2, 53115 Bonn, Germany
Email: rene@perihelie-labs.net
Dhana has no data protection officer: its size does not require one. Requests are handled by
the person above.
What Dhana does not do
It is shorter to start there, and it can be checked in the code, which is written without any
of these components:
- no advertising, no advertising trackers;
- no audience measurement — no Google Analytics, no Firebase Analytics, nothing equivalent;
- no profiling, no automated decision about you;
- no selling or sharing of data for commercial purposes;
- no access to your contacts, your location, your photos or your microphone;
- no notifications.
What stays on your device, and never leaves it
Most of what you produce while using Dhana is stored in a local database on your phone. The
server does not receive it, does not see it, and does not back it up:
- the cards you have opened, and your shelf;
- the words you review, the ones you set aside, the ones you mark as known;
- your whole review history and the schedule that follows from it;
- your collections;
- the sentences you add to a card yourself, and the notes you write on it.
None of this leaves on its own. If you uninstall the app or lose your phone, this data is
lost, because we have no copy of it — unless you have asked for a backup, which
the next section describes. The app also lets you export it to a file that you keep wherever you
like.
What the server keeps
Five things, and nothing else. The first is there only if you asked for it.
Your backup, if you make one. Settings contains a button “Back up to the
server”. As long as you have not touched it, the server has nothing of what you learn. When you
touch it, the server receives a copy of what the previous section lists — your shelf, your
flashcards and their schedule, your collections, your sentences and your notes — attached to
your account, and replaced with each new backup. We do not read it and do not use it: it is a
file we keep for you, and only you can take it back. It is erased with your account, immediately
and with no backup copy.
Your account. At your first sign-in, Google sends us a stable identifier
specific to Dhana, and your email address. We add the date the account was created; usage
counters — the cards produced, the questions asked and the translations requested, to limit the
cost of the service; numbers, never the text —; the list of cards you have taken, with
their dates — this is the counter the app shows you: a card taken once does not count a
second time, and to know that, the server has to remember which one it was —; and, where
relevant, the status of your subscription. This list says which places, activities and works you
have opened, and in which language; it says nothing about what you did with them. We receive
neither your Google password, nor your contacts, nor the content of your Google account.
Technical logs. The server keeps a log of what it does and what it refuses —
a card written, a sign-in refused, a failure —, dated, with no IP address and without the text
of your requests. It is used to diagnose failures and to spot abuse.
Searches that found nothing. When a search finds nothing, the word searched
for is kept so that the catalogue can be completed. This record holds the word and the date,
with no link to any account: we know that someone searched for “butcher's
shop”, never who.
Reports. At the bottom of each card, a link lets you say that something is
wrong with it, with a sentence if you want to explain; it can also start from a question, already
filled in. The report records the card concerned, the date and your sentence — or, if it starts
from a question, the item, your question and the model's explanation —, never your
identifier. We will know that a card is wrong, never who said so. This is also why we
cannot reply to you: so do not write a question in this field, write what is wrong.
What is passed on to third parties
A language model, at DeepSeek (People's Republic of China). This is the point
that deserves your attention, and we would rather say it plainly. Three actions in the app send
text to this provider:
- when you ask for a place or an activity the app does not know yet to be added, the
word you typed is sent to it;
- when you ask for the translation of a sentence you want to add to a card, that
sentence is sent to it;
- when you ask a question about a sentence or a word on a card, your
question is sent to it, along with the card and the item concerned — and, if it is
a sentence you wrote yourself, that sentence.
These requests carry no account identifier: the provider receives a text, not a person. They
are nevertheless a transfer outside the European Union, to a country that is not covered by an
adequacy decision of the European Commission. This transfer is necessary to provide the service
you ask for: without it, the feature cannot exist. So do not write anything confidential
in these fields.
A second language model, at Zhipu AI — Z.ai (People's Republic of China).
Every card produced is checked by two models that make different mistakes, and this is the
second one. It receives the card — sentences in the language being learned, and their glosses —,
never anything that identifies you. It is the same transfer outside the European Union as above,
for the same reason.
Wikidata, from the Wikimedia Foundation (United States). When you search for
a film, a series or a book, the title you typed is sent to Wikidata to identify the work. Here
again, a text with no account identifier.
Google Ireland Limited. Signing in to the app goes through your Google
account. Google therefore knows that you sign in to Dhana, under its own privacy policy. We pass
on to Google nothing of what you do in the app.
netcup GmbH (Germany). The server is hosted by this provider, which acts as a
processor within the meaning of Article 28 of the GDPR, under contract. The data stays in
Germany.
Google Play. If you take out a subscription, payment is handled by Google
Play. We receive neither your card number nor your bank details: only confirmation that the
subscription is active.
The closed beta
To try Dhana before its release, you can join the Google group
beta_test_dhana from the dhana.eu home
page. This group is hosted by Google, and you join it with your Google account, under Google's
privacy policy. We see the email address of that account there, and only that; the other members
do not see it.
It is used for two things: writing to you with the link to install the test version, and
opening that test to you on Google Play, which accepts the group's members as testers. It is used
for nothing else. You can leave the group at any time from its page, and your address leaves it
at once; we will remove the remaining members at the end of the closed beta.
Cards do not belong to you, and do not speak about you
A card produced at your request joins a shared catalogue and serves every user after you. It
carries no trace of who asked for it, so deleting it would have no effect on your privacy. This
is why cards are not erased when an account is: what you brought into being does not follow
you, and does not point to you.
On what legal basis
- Performance of the contract (Art. 6(1)(b) GDPR) for the account, sign-in,
producing cards, translating your sentences and answering your questions: without this
processing, the service you ask for does not exist. The same goes for the closed-beta
address, which you give us by joining the group to receive the invitation to the test.
- Legitimate interest (Art. 6(1)(f)) for the technical logs, the usage
counters, the list of cards taken, the searches that found nothing and the reports: keeping
the service available, preventing abuse, and correcting the catalogue where it is wrong or
incomplete.
- A legal obligation (Art. 6(1)(c)) for what accounting rules require us to
keep in the case of a subscription.
How long
- Account: until you delete it, or after twenty-four months without any
sign-in.
- Backup: as long as your account exists, replaced with each new backup. It
disappears with the account, at the same moment.
- Technical logs: thirty days.
- Searches that found nothing: until they are reviewed, and at most twelve
months.
- Reports: until the card is corrected, and at most twelve months.
- Closed-beta address: as long as you are a member of the group, and at
most until the end of the closed beta.
- Accounting records for a subscription: the period required by tax
law.
Your rights
You have the right of access, rectification, erasure, restriction, objection and portability
regarding the data that concerns you. To exercise them, write to the address given at the top of
this page; you will receive a reply within one month.
Deleting your account is done directly, without writing to us: see
the page for this purpose.
You may also lodge a complaint with a data protection authority — the one in your country of
residence, or the one responsible for the controller.
Minors
Dhana is not intended for children and does not knowingly collect data about anyone under
sixteen.
Changes
This policy may change along with the app. Every version carries its date at the top, and a
substantial change will be announced in the app before it takes effect.