Privacy policy
Effective: 18 August 2026
Controller
The data controller for Hydra (hydrapt.com, app.hydrapt.com) is Midnite Compile GmbH. Contact details: see imprint.
What we process
We only process data you generate by using the app:
- Account data: email address, display name, language and locale.
- Training results (score, correct/wrong, timestamps, platform marker).
- Evaluation data per run: the test configuration used, the duration, summary figures and per-item entries (correct or incorrect, time taken, type of error), at most 200 entries per run. For tests with very many items we store a summarised time distribution instead of the individual values. Training runs and tests you abort are recorded as well. We use this data for your own analysis (progress report, data export) and to improve the tests; it is visible only to you and does not feed into the leaderboards.
- A coarse device indication per run: input type (pointing device or touch) and the size class of the viewport (mobile, tablet, desktop). It helps put results in context. No browser or device identifier and no user agent is stored for this; these two classes do not allow your device to be recognised.
- Subscription status (entitlement, product, period) — payment data sits exclusively at Stripe.
- Technical logs (Sentry, EU-hosted) for error diagnostics, PII-free.
Processors
We use the following external services:
- Stripe (payment processing; its own controller for the payment itself, see the “Payments via Stripe” section).
- RevenueCat (subscription management, webhook bridge).
- Brevo (transactional email delivery, EU region).
Payments via Stripe
Purchases in the web app run through an embedded Stripe checkout that we integrate via our provider RevenueCat. You enter card and account details as well as your billing information directly with Stripe. We never see them and do not store them.
For the payment itself Stripe acts as its own controller, not as our processor. Stripe operates as merchant of record: it is the seller of the transaction, calculates and remits VAT and issues the receipt you receive by email. Stripe's own privacy notice applies to this.
We pass an identifier of your Hydra account to RevenueCat and Stripe so the purchase is assigned to the right account. In return we receive only the subscription status: entitlement, product, term and payment route. Billing address, invoice history and payment method are managed in Stripe's customer portal, which you can reach in Hydra under “Profile”.
Purchases through the Apple App Store or Google Play do not run through Stripe. The privacy notices of the respective store apply there; in that case too we only receive the subscription status.
Community forum
As a Pro member you can create topics and posts in the forum. We process this content to enable and moderate the exchange (Art. 6(1)(b) GDPR, performance of the contract).
- We store your post text, the chosen area and timestamps, as well as your votes and reports. Your username is shown, not your email address.
- Posts are visible to all Pro members. Do not share anything there that you do not want others to see, in particular no data about other people.
- If you delete your account, your posts remain without your name (“Deleted user”) so ongoing discussions stay readable. The forum runs on our own infrastructure; no additional processor is involved.
Your rights
You may at any time request access, correction, deletion and data portability. A full data export is available in your profile and can be triggered once per day. Deleting your account from the profile removes all your data irreversibly (profile, scores including their evaluation data, recorded training runs and aborted tests, subscription record).
Privacy contact
Send privacy inquiries to the email listed in the imprint.