Privacy Policy
This policy explains which personal data Tsumu processes, why it is processed and which rights users have.
1. Controller
The controller responsible for the processing of personal data through Tsumu is:
Robert Safranek Adelheid-Popp-Gasse 8/2/6 1220 Vienna Austria support@seidohub.com2. Scope
This Privacy Policy applies to the public Tsumu website, account registration and authentication, courses, exercises, learning progress, review functions, account settings and support communication.
3. Website access and server logs
When Tsumu is accessed, the web server and hosting provider may process technical request data such as the IP address, date and time, requested resource, referrer, browser and operating-system information, response status, transferred data volume and security or error information.
This processing is necessary to deliver the website, maintain stability, diagnose errors, prevent abuse and protect Tsumu against attacks. The legal basis is Article 6(1)(f) GDPR. The legitimate interests are the secure and reliable operation of the service.
4. Local Tsumu accounts
When a user creates or manages a local account, Tsumu may process:
- Email address, display name and internal user identifier
- Password hash; passwords are not stored in plain text
- Email-verification, password-reset and email-change information
- Account status, roles, permissions and service entitlements
- Login, session and account-security information
- Interface, reference-language and learning-language settings
The legal basis is Article 6(1)(b) GDPR because this processing is necessary to create, authenticate and operate the account. Security processing may additionally be based on Article 6(1)(f) GDPR.
5. Learning and progress data
Tsumu processes data generated through Learning Engine V2, including learning-profile revisions and preferences, placement answers and evidence, selected versioned courses and personal plans, learning sessions and immutable exercise snapshots, submitted answers and idempotency keys, correctness and error classifications, knowledge and review projections, checkpoint results, progress, XP, achievements and deterministic mascot reactions.
This data is used to provide the requested learning service, save evidence, select due reviews, calculate rebuildable learning projections and display personal learning information. Historical answer and session evidence is kept separately from derived knowledge, review and motivation projections so that the latter can be recalculated. The legal basis is Article 6(1)(b) GDPR.
Ordinary planning, answer evaluation, review scheduling, progress and mascot reactions run without an OpenAI request. The production AI provider is currently disabled. If optional AI-supported features are introduced later, this policy and the applicable controls must be reviewed before activation; AI-generated output does not become the source of truth for learning facts.
6. Authentication with Google
Tsumu offers Google OpenID Connect as an optional sign-in method. Google authentication is initiated only after the user selects the Google sign-in option.
Tsumu requests the scopes openid, email and
profile. Depending on the Google Account, Tsumu receives and
uses a stable Google account identifier, email address, display name and
email-verification status. Tsumu does not receive the Google password and
does not request access to Gmail, Drive, Calendar or Contacts. Provider
access and ID tokens are used for the authentication flow and are not
stored as persistent account data.
The legal basis for processing by Tsumu is Article 6(1)(b) GDPR. Google processes data relating to the Google Account and authentication service under its own responsibility.
Google Ireland Limited Gordon House, Barrow Street Dublin 4 IrelandFurther information is available in the Google Privacy Policy.
7. Authentication with SeidoHub
Tsumu may offer SeidoHub as an optional, technically separate identity
provider operated within the same service ecosystem. The authentication
request uses the scopes profile and email.
Tsumu may receive a SeidoHub account identifier, email address, display name and email-verification status. Tsumu does not receive the SeidoHub password. Temporary provider tokens are used to complete the sign-in flow and are not stored as persistent Tsumu account data.
The data is used to authenticate the user and create or link the Tsumu account. The legal basis is Article 6(1)(b) GDPR. Security processing may additionally be based on Article 6(1)(f) GDPR.
8. Cookies and local browser storage
Tsumu uses technically necessary session cookies and comparable storage mechanisms to maintain authenticated sessions, protect requests against misuse, preserve security settings and provide account functionality.
The public landing page stores the selected display language in the
browser's local storage under tsumu-landing-language. This
preference remains on the device until it is removed through browser
settings or overwritten by a new selection.
Tsumu does not currently use advertising cookies or third-party analytics trackers. This policy must be updated and any legally required consent obtained before non-essential tracking is introduced.
9. Web fonts
Tsumu currently loads the Nunito and Noto Sans JP font families from Google Fonts. When a page is opened, the browser may connect to Google servers and transmit technical request data such as the IP address, browser headers and the requested font resource.
The purpose is a consistent and readable presentation of Latin and Japanese text. The legal basis relied upon by Tsumu is Article 6(1)(f) GDPR. Users who block remote font resources can still use Tsumu with system fallback fonts.
10. Hosting
Tsumu is hosted by:
IONOS SE Elgendorfer Str. 57 56410 Montabaur GermanyIONOS may process server logs, website requests, account and learning data, database content, backups and security information on behalf of the controller. Where IONOS processes personal data on behalf of the controller, that processing must be governed by an agreement meeting the requirements of Article 28 GDPR.
11. Communication and support
When a user contacts Tsumu, the submitted contact details, message, timestamps and any information required to investigate the request are processed to answer the enquiry and provide support.
The legal basis is Article 6(1)(b) GDPR where the communication concerns an account or requested service, and Article 6(1)(f) GDPR for general enquiries, service administration and security reports.
12. Payments
Tsumu currently displays planned paid access options, but the production billing provider and checkout are disabled. Tsumu therefore does not currently collect payment-card or bank-account data. This Privacy Policy must be updated before a payment provider is activated.
13. Recipients
Personal data may be processed by the hosting provider, technical processors acting on behalf of Tsumu, Google when Google sign-in is used, SeidoHub when SeidoHub sign-in is used, professional advisers where necessary, and authorities where disclosure is legally required.
Tsumu does not sell or rent personal data.
14. International data transfers
Tsumu is operated from Austria and primarily uses infrastructure in the European Economic Area. Google may process authentication and font request data on servers outside the EEA. Where personal data is transferred outside the EEA, the transfer must rely on an adequacy decision, Standard Contractual Clauses or another mechanism permitted by Chapter V GDPR.
15. Retention
- Account and learning data is generally retained while the account is active and deleted or anonymised after account deletion, unless a legal obligation or overriding security reason requires limited retention.
- Verification, reset and provider state data is retained only until the relevant operation expires or is completed.
- Session data expires according to the configured session lifetime and is revoked when required for account security.
- Server and security logs are retained only for the period needed for operation, troubleshooting, abuse prevention and incident handling.
- Backup copies may remain until they are overwritten in the regular backup cycle and are not used for ordinary processing.
- Support communication is retained until the request is resolved and, where necessary, for the limitation period applicable to related legal claims.
16. Account deletion and provider disconnection
Users may request deletion of their Tsumu account and associated personal data through available account functions or by contacting the controller. Deleting a Tsumu account does not delete the user's Google or SeidoHub account.
Disconnecting an external sign-in method may prevent future access if no alternative login method is configured. Tsumu may require identity verification before deleting an account or changing authentication methods.
17. Data security
Tsumu uses technical and organisational measures appropriate to the risk, including hashed passwords, secure session handling, verification of authentication responses, request protection, access controls and restricted administrative permissions. No method of transmission or storage can guarantee absolute security.
18. Automated decisions
Tsumu does not use personal data for decisions that produce legal effects or similarly significant effects within the meaning of Article 22 GDPR. Automated review scheduling, progress calculation and learning recommendations serve only the learning functionality.
19. Children
Tsumu is not specifically directed at young children. Where applicable law requires permission from a parent or legal guardian for a minor's use of the service or for consent-based processing, the service may only be used after that permission has been obtained.
20. User rights
Subject to the legal requirements, users have the right to access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests and withdrawal of consent with effect for the future.
Requests may be sent to support@seidohub.com . Additional information may be requested where reasonably necessary to verify the identity of the requester.
21. Right to complain
Users may lodge a complaint with the supervisory authority responsible for their habitual residence, workplace or the alleged infringement. The supervisory authority for the Austrian controller is:
Austrian Data Protection Authority Barichgasse 40–42 1030 Vienna Austria dsb@dsb.gv.at22. Changes to this policy
This policy may be updated when the service, processing activities, providers or legal requirements change. The current version is published on this page with its update date.
Last updated: 28 July 2026