Surayt

Privacy Policy

Effective 12 August 2026 Version 1.0 Applies to Surayt for iPhone

Short version: Surayt is free and is not funded by advertising. We never sell your data. We store your account and your progress so the course works, plus product analytics and crash reports so the app can improve. Delete your account in the app and everything we hold about you goes with it.

This is a translation. In case of any conflict, the Swedish version prevails.

1. Who is responsible

The data controller is Eric Kurtto, a private individual in Sweden. Surayt is a non-commercial community project and is not incorporated. Contact: hej@surayt.se.

This policy covers the Surayt mobile app and this website, surayt.se.

2. What we process

2.1 Account

An account is required to save progress and continue on another device. We process your name, email address, whether that address is verified, a profile image URL if your sign-in provider supplies one, and the dates the account was created and last changed. If you register with email, the password is stored only as a hash. We never see your password in plain text.

2.2 Sign in with Apple or Google

If you sign in with Apple or Google we receive an account identifier from the provider and the tokens needed to verify the sign-in. If you use Apple's private email relay we only ever receive the relay address, never your real one.

2.3 Sessions

To keep you signed in we store a session token together with its expiry, your IP address and your device's user agent. This is used for authentication and to detect abuse.

2.4 Profile and learning preferences

Display name, how much Surayt you said you already knew, your goal for the course, and your in-app settings.

2.5 Course progress

So the course and its review system work, we store:

2.6 Feedback you send

If you send feedback in the app we store the message, the screen it was sent from, the lesson day where applicable, and your user ID. The message is also forwarded as a notification to the project's private Telegram channel so that we see it quickly.

Please do not put sensitive information in the feedback box. A message already delivered to Telegram remains there until deleted manually, even if you later delete your account.

2.7 Product analytics

We use PostHog to understand how the app is used and what needs improving. This covers in-app events such as opening a lesson or completing an exercise, which screens were viewed, app lifecycle events such as launch and backgrounding, app version and platform. Events are linked to your user ID.

We do not use analytics for advertising and never share them with ad networks. If you would rather not be included, email hej@surayt.se and we will switch it off for your account and delete what has already been collected.

2.8 Crash reports

We use Sentry to catch errors and crashes. A report contains the error message, stack trace, app version, operating system and device model. Automatic collection of personal data is disabled in our configuration.

2.9 Notifications

If you accept daily reminders they are scheduled locally on your device. We do not send notifications from our servers and do not store a push token. You can turn reminders off in the app's settings or in iOS settings.

3. What we do not collect

This website sets no cookies at all and loads no third-party resources. The fonts are served from our own domain.

PurposeLegal basis
Creating and running your account, saving and syncing progressPerformance of a contract, Article 6(1)(b)
Keeping you signed in and protecting the account from abuseLegitimate interests, Article 6(1)(f)
Crash reports and product analytics to improve the appLegitimate interests, Article 6(1)(f)
Handling feedback you choose to sendLegitimate interests, Article 6(1)(f)
Daily remindersConsent, Article 6(1)(a), which you can withdraw at any time

Where we rely on legitimate interests we have balanced our interest in a working, improving app against your privacy. The data is limited, is not used for advertising, and is not shared for anyone else's purposes. You may object at any time, see section 8.

5. Who receives the data

RecipientRoleLocation
Our cloud providerHosting of server and databaseEU/EEA
PostHogProduct analyticsUSA
SentryCrash reportsUSA
TelegramNotification when new feedback arrivesOutside the EU/EEA
Apple and GoogleSign-in, if you choose itIndependent controllers

Apple and Google act as independent controllers for their own processing when you sign in, and their privacy policies apply to that part. The same is true of Apple's handling of your App Store download.

Otherwise we disclose data only where required by law or a decision of a public authority.

6. Transfers outside the EU and EEA

Your account and your progress are stored with our cloud provider inside the EU/EEA and are not transferred to a third country.

Product analytics and crash reports are processed in the USA by PostHog and Sentry respectively. Notifications about new feedback go to Telegram, which is established outside the EU/EEA. These transfers rely on the European Commission's Standard Contractual Clauses or, where applicable, a valid adequacy decision. Email us if you would like a copy of the safeguards for a particular transfer.

7. How long we keep it

DataRetention
Account, profile, progress, badgesFor as long as the account exists. Deleted when you delete the account.
SessionsExpire automatically.
Feedback in our databaseDeleted when you delete the account.
Feedback notification in TelegramRemains until deleted manually.
Analytics at PostHogNo more than 12 months.
Crash reports at SentryNo more than 90 days.

8. Your rights

Under the GDPR you have the right to:

Email hej@surayt.se. We reply as quickly as we can and within one month at the latest.

If you are unhappy with how we handle your data you can complain to the Swedish Authority for Privacy Protection, IMY, or to the supervisory authority in your own country.

9. Deleting your account

You can delete the account yourself in the app under Profil, then Inställningar, then Radera konto. This removes the account and all learning data attached to it. Full instructions are on the account deletion page.

10. Children

The content suits all ages, but you should be at least 13 to create an account. If you are younger, a parent or guardian should create the account and accept the terms with you. If we learn that an account belongs to a younger child without a guardian's involvement, we delete it.

11. Security

All traffic between the app and our servers uses HTTPS. Passwords are stored hashed. Sign-in tokens are kept in the device's secure storage, the iOS Keychain. Database access is limited to those who need it to run the service.

No service is risk-free. If a personal data breach occurs that is likely to result in a high risk to you, we will inform you and report it to IMY under Articles 33 and 34.

12. Changes

If we change this policy we will update the date at the top and publish the new version here. For significant changes we will tell you in the app before they take effect.

13. Contact

Eric Kurtto, Sweden
hej@surayt.se