Privacy policy
Last updated: 7 August 2026
This policy explains what we collect when you use Parla Italiano at eetali.com, why we collect it, and what you can do about it.
1. Who we are
Parla Italiano is operated by [Legal entity name], [registered address], company number [number]. We are the data controller for the personal data described here.
If you have a question about this policy or want to exercise any of your rights, email privacy@eetali.com.
2. You can use the course without an account
The entire course works signed out. If you never create an account, your progress is stored only in your own browser and never reaches our servers. You can clear it at any time with Reset progress at the bottom of the page.
3. What we collect
| Data | When | Why |
|---|---|---|
| Email address | You create an account | To identify your account and let you sign in. Required. |
| Password (hashed) | You create an account | To verify sign-in. Stored only as a PBKDF2 hash — we never hold your actual password. |
| Name, telephone number, postal address | You choose to enter them | Entirely optional. Used only to personalise your account. |
| Course progress | You use the course while signed in | To sync your progress between your devices. |
| Appearance and notification preferences | You change them | To apply your settings across your devices. |
| Passkey public keys | You set up Face ID or Touch ID | To verify biometric sign-in. See section 6. |
| Session records: IP address, browser user agent, timestamps | You sign in | Security — so you can see and end sessions, and so we can detect abuse. |
| Sign-up record: email, country, referring page, browser user agent | You create an account | To understand where sign-ups come from and to investigate abuse. |
We do not collect payment details, we do not use advertising trackers, and we do not sell or share your personal data with third parties for their own marketing.
4. Cookies
We use exactly one cookie:
-
eetali_session— a strictly necessary cookie that keeps you signed in. It contains a random token, no personal data. It isHttpOnly(unreadable by scripts),SecureandSameSite=Lax, and expires after 30 days.
We do not use analytics, advertising or tracking cookies, which is why you are not asked for cookie consent. Your appearance settings and guest progress are kept in your browser's local storage rather than in cookies, and never leave your device unless you sign in.
5. Legal basis for processing (UK GDPR)
- Contract — your email, password and progress: we cannot provide an account without them.
- Legitimate interests — session and sign-up records, to keep the service secure and working.
- Consent — marketing emails. Off by default; you can withdraw consent at any time in your profile.
6. Face ID, Touch ID and passkeys
If you set up biometric sign-in, your face or fingerprint never leaves your device and is never sent to us. Your device performs the biometric check locally and then signs a one-time challenge with a private key that stays in its secure hardware.
We only store the matching public key, which cannot be used to reconstruct your biometrics or to impersonate you. We do not process biometric data, and therefore do not process special category data.
7. Where your data is held
Data is stored in Cloudflare D1, with the primary copy in Western Europe (London). Cloudflare Inc. acts as our processor; details are in their GDPR documentation. Cloudflare operates globally, so some data may be processed outside the UK under the safeguards described in their data processing addendum.
8. How long we keep it
- Account data and progress — until you delete your account.
- Sessions — 30 days, or until you sign out. Expired sessions are deleted automatically.
- Sign-up records — retained for [retention period, e.g. 24 months] after account deletion, for fraud prevention and analytics. These hold your email and country but no progress or profile data.
9. Your rights
Under UK GDPR you have the right to:
- access a copy of your data;
- have inaccurate data corrected — you can edit most of it yourself in your profile;
- have your data erased — Delete my account in your profile does this immediately;
- restrict or object to processing;
- data portability;
- withdraw consent for marketing at any time.
Email privacy@eetali.com to exercise any of these. We will respond within one month.
If you are unhappy with our response you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
10. Children
This service is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
11. Security
- Passwords are hashed with PBKDF2-SHA256 (100,000 iterations, unique random salt per user).
- Session tokens are stored only as hashes, so a database leak cannot be replayed as a sign-in.
- All traffic is encrypted with HTTPS.
- Changing your password ends every other active session.
No system is perfectly secure, but we take these measures seriously and keep them under review.
12. Changes to this policy
If we make a material change we will update the date at the top and, where the change affects you meaningfully, tell you by email or a notice in the app.