SimpleLearn

Privacy and cookies

Updated 9 October 2026

Controller

ImpressMedia, s. r. o. Privacy contact: info@impress.media.

Data and purposes

Accounts contain name, email, legacy password hash, subscription status and sessions. We store activities, assignments and attempts: optional nickname, answers, score and time. Hosting security logs may include IP address and technical request information. Email-code sign-in verifies access to the mailbox. New accounts are created only after code verification.

Legal bases

Accounts and activities are processed to perform the service contract. Security and abuse prevention rely on legitimate interests. Optional language storage requires consent; withdraw it in Privacy settings at any time.

Personal progress

Email-code sign-in provides access to your own results. History displays 7 days on Free and 90 days on Pro; attempts follow the 90-day retention period. Mistake review and daily practice use private saved answers. Existing results remain subject to the same retention period.

Daily practice

Daily practice is built from private saved answers. Text question drafts are created in your browser without sending source text to an AI service; only confirmed questions are saved.

Children and schools

Students play without accounts. Use pseudonyms, avoiding full names and sensitive information. Teachers see results for their own activities. Schools determine the purpose and legal basis for student processing and inform families. Before systematically processing identifiable child data, agree appropriate processing terms with the operator.

Sharing

Anyone can see public activities, which may be indexed. Private activities are accessible to their owner, administrators and visitors with a valid assignment link. Treat that link as an access key. Results are not public.

Cookies and storage

__Host-simplelearn is a necessary Secure, HttpOnly, SameSite=Lax sign-in cookie lasting up to 30 days. simplelearn-consent remembers separate preference and analytics choices in local storage for 180 days. simplelearn-language is stored only with permission and removed on withdrawal. Google Analytics 4 loads only after permission for analytics cookies; it is off by default. Withdrawal in Privacy settings stops measurement and deletes _ga cookies. Google AdSense advertising uses separate consent through Google Privacy & Messaging; advertising settings are available in Privacy settings. Rejecting analytics does not prevent games or signing in.

Providers and transfers

The hosting platform uses Cloudflare infrastructure. If configured, Resend delivers sign-in codes and verification emails. Google processes technical advertising request data and, with permission, usage statistics in GA4. Our analytics events exclude emails, names, activity text, sign-in codes, tokens and user identifiers. If payments are enabled, Stripe processes payments; card numbers are not stored here. Author-provided external images may contact their servers and disclose technical request data. Providers may process data outside the EEA; contact info@impress.media for details of applicable safeguards.

Retention

Account data and activities remain until deletion. Completed attempts are periodically removed after 90 days in bounded batches; high volume can delay cleanup. Expired sessions and reset links are cleaned periodically. Teachers can delete results sooner. Provider logs and required financial records follow separate retention obligations.

Rights and controls

Privacy settings provide JSON data export, deletion of your activity results, and account closure with password confirmation or a fresh email-code sign-in. Students can delete their attempt at the end of a game using its access token; for later requests contact the teacher or operator. Request access, correction, deletion, restriction, portability or object at info@impress.media. We normally respond within one month. You may complain to the Slovak Office for Personal Data Protection or your competent supervisory authority.

Security and recovery

Email-code sign-in requires no password. Codes expire after 10 minutes, can be used once and allow five verification attempts. Legacy passwords use PBKDF2 hashes and traffic uses HTTPS. Recovery codes are shown once; only hashes are stored. A code resets your password once and is replaced with a new code. Store it as securely as a password. Operator accounts and accounts with active subscriptions require contacting the operator for closure.

How Google uses data from sites

Back to games and privacy settings