Privacy Policy

Cookieless product analytics, no tracking cookies, no ad technology and no card details. Here is exactly what is stored, why, and how to get rid of it.

In effect from 2 October 2026

1.Who controls your data

The data controller for Laureo is Filippe Frulli, a sole trader established in Ireland, at Apartment C127, Newmarket Yards, D08C3XR, Dublin.

For anything in this policy, including a request to see or delete your data, write to contact@laureo.eu.

2.What we do not collect

Worth stating first, because it shapes everything below.

  • No tracking or advertising cookies, no pixels, no fingerprinting, no ad networks, and no third-party trackers. This is why you were not asked to accept cookies: the only things we store in your browser keep you signed in and remember your chosen language, which are strictly necessary and need no consent. They are listed in full under Cookies below. Our analytics tool (below) sets no cookie either.
  • No card details. Checkout appears inside our upgrade page, but the card fields themselves are served by Stripe, in a frame we cannot read into. Your card number goes to Stripe and never reaches our servers, and we could not store it if we wanted to.
  • No selling or sharing. We do not sell your data, rent it, or hand it to advertisers or data brokers. There is no marketing list.

3.What we do collect

Practising without an account

You can answer questions without signing up. When you do, we create a practice record identified by a random identifier and nothing else: no email address, no name, and nothing that could be used to contact you. Your answers attach to that record exactly as they would to an account. If you later create one, it takes over the same record, which is why your score and your streak survive signing up rather than starting again.

Account

Your email address, and either a password (stored only as a cryptographic hash that we cannot read) or the fact that you signed in with Google. If you use Google, we receive your email address and account identifier from Google; we do not receive your Google password. We also store your preferred interface language and when the account was created.

Practice

Which questions you were served, the answer you chose, whether it was correct, and how long you took. From that we derive your streak, your accuracy, your per-topic weak points, and, for Pro users, the mistake bank.

This is the substance of the product rather than a by-product of it: without it there is no progress tracking and no way to serve you a question you have not already seen.

Purchases

Whether you hold Pro access and when it expires, plus the identifiers of the payment events we have already processed (so a repeated notification from Stripe cannot grant the same purchase twice). Stripe separately holds your name, billing email, billing country and payment details as the payment processor. See their privacy policy.

Technical

Our hosting and database providers keep short-lived operational logs (IP address, request time, error traces) as part of running and securing the service. We do not build profiles from them.

Product analytics

We use PostHog, in cookieless mode, to see which pages and features are used and how fast the site loads. It sets no cookie and writes nothing to your browser’s storage; instead it computes a rotating, one-way hash on PostHog’s own servers, so a visit cannot be tied back to you as a person and cannot be linked across days. The events for a session are additionally tied to whichever practice record you are working under, the same way your answers are: the anonymous one if you have not signed up, your account once you have. That is how we see how candidates use the product. We do not record your screen, and no question, answer or explanation you see is ever sent to PostHog. Vercel separately measures page load speed for every visitor; see their privacy policy for what that involves.

4.Why we are allowed to hold it

Under the GDPR, each purpose needs a legal basis. Ours are:

  • Performance of a contract: running your account, serving questions, keeping your progress, and delivering and honouring a purchase. Without this data there is no service to provide.
  • Legitimate interests: keeping the service secure, preventing abuse and fraud, fixing faults, and understanding which features are used so we can improve the product. For the last of these we rely on cookieless analytics precisely so that no consent-requiring storage is involved; we have weighed this against your interests, the data involved is minimal, and it is not used to profile you individually or for marketing.
  • Legal obligation: retaining transaction and tax records for as long as tax law requires.

We do not rely on consent for any of this, because we do nothing optional with your data. There is no consent to withdraw and no marketing to unsubscribe from.

5.Who processes it for us

We use a small number of providers, each under a data processing agreement, each doing one job:

  • Supabase: the database and the sign-in system. Your account and practice data live here, in a database hosted in the EU (Stockholm, Sweden).
  • Stripe: payment processing.
  • Vercel: website hosting and delivery, and page-speed measurement.
  • PostHog: cookieless product analytics, processed in PostHog’s EU region.
  • Resend: sending the emails the service cannot work without, namely your sign-up confirmation, password resets, and the receipt for a purchase. It processes your email address for that and nothing else. There is no marketing mail.
  • Google: only if you choose to sign in with Google, and only for that.

Your practice data stays in the EU. Some of these providers are US-headquartered and may process limited data (such as payment or operational log data) outside the EEA; where that happens it is covered by the European Commission’s Standard Contractual Clauses or an equivalent transfer mechanism.

We will also disclose data where the law requires it, such as a valid court order or legal obligation, and we will tell you if that happens unless we are prohibited from doing so.

6.How long we keep it

Your account and practice data are kept for as long as your account exists. There is no automatic expiry, because a study history is only useful if it accumulates. The same holds for a practice record created without an account: we do not delete it on a timer either.

One consequence of that is worth stating plainly. A record with no account attached can only be reached from the browser that created it, so clearing your browser abandons it rather than deleting it, and because the record holds no email address or name we have no way to connect it to you if you ask us to remove it. The practical route to deleting it is to create an account, which takes over that same record, and then use the deletion below.

Deleting your account deletes it. You can do this yourself at any time from Settings; it takes effect immediately and removes your profile and practice history along with the account. It is not reversible and we cannot restore it afterwards.

Two things survive deletion, both narrowly: records of completed transactions, which tax law requires us to retain for a number of years, and the identifiers of processed payment events, which contain no personal data. Backups are cycled out on a rolling basis, so a deleted record may persist in a backup for a short period before being overwritten.

7.Your rights

If you are in the EU or the UK, you have the right to:

  • access the personal data we hold about you, and get a copy;
  • correct it if it is wrong;
  • erase it, which you can do yourself, immediately, from Settings;
  • port it, receiving it in a structured, machine-readable format;
  • restrict or object to processing based on legitimate interests.

Email contact@laureo.eu to exercise any of these. We will respond within one month. We will not charge you, and we will not make the service worse for you because you asked.

If you are unhappy with how we have handled your data, you can complain to your national data protection authority. You do not have to come to us first, though we would rather you did.

8.Cookies

Laureo stores four things in your browser, and no more:

  • Session cookies, which identify your practice record so you are not asked to log in on every page. One is set as soon as you start practising, whether or not you have an account. They are read only by us. Signing out clears them, and so does deleting your account.
  • A language cookie (NEXT_LOCALE), which remembers which of the six site languages you chose so you are not returned to English on your next visit. It holds a two-letter code and nothing else.
  • A small copy of your own account details, held in your browser’s local storage so a signed-in page can render immediately instead of blank while we re-check your session. It never leaves your device and is cleared when you sign out.
  • Two small flags in your browser’s session storage, recording that you dismissed the prompt offering to save your progress, and that you have already asked to create an account. They hold nothing else, and the browser discards them when you close the tab.

All four are strictly necessary or functional: each one exists to make something you asked for work, and none of them tracks you or is shared with anyone. Under the ePrivacy rules they do not require a consent banner, which is why you have not seen one. Blocking cookies in your browser will prevent you from signing in.

Our analytics (above) sets no cookie and writes nothing to local or session storage either, which is why it does not change any of this.

If you pay, Stripe sets its own cookies for fraud prevention inside its checkout frame. That happens under Stripe’s policy, not ours.

9.Children

Laureo is intended for adults preparing for EU recruitment procedures and is not directed at children. You must be at least 16 to hold an account. If you believe a child has created one, tell us at contact@laureo.eu and we will delete it.

10.Changes to this policy

If we change how we handle your data we will update this page and move the effective date at the top. If a change is significant (a new processor, a new purpose, a new category of data) we will tell you by email before it takes effect. Related: Terms of Service and refund policy.