1. General Information & Data Controller (Verantwortliche Stelle)
Pursuant to Article 4(7) of the EU General Data Protection Regulation (GDPR) and applicable German data protection laws (BDSG, DDG), the data controller responsible for the processing of personal data on this platform is:
🏢 Platform Operator & Data Controller
Controller: Maiko Zobel (sole proprietorship), operating the NihonTale platform
Postal Address:
Holztraubacherstraße 5
84066 Mallersdorf-Pfaffenberg
Germany
Email: support@nihontale.com
VAT ID: DE350466867
Service Type: Interactive Japanese Language Learning & Visual Novel Platform
Official Website: https://www.nihontale.com
This privacy policy applies to all users of NihonTale, including registered subscribers, trial users, and general website visitors. We ensure that all personal data is processed lawfully, fairly, and transparently.
Data Protection Officer: We are not required to appoint one. § 38(1) sentence 1 BDSG triggers the duty at 20 people permanently engaged in automated processing, and sentence 2 triggers it regardless of headcount once a data protection impact assessment under Art. 35 GDPR becomes necessary. Neither applies here: NihonTale is run by one person and processes no special categories of data and performs no systematic monitoring.
Automated decision-making: We do not use automated decision-making, including profiling, within the meaning of Art. 22(1) and (4) GDPR. Your learning statistics steer which exercise you are shown next; they produce no decision with legal or similarly significant effect for you (Art. 13(2)(f) GDPR).
Is providing your data mandatory? Providing an email address and a password is necessary to conclude the user contract; without them no account can be created and the learning progress cannot be stored across devices. There is no statutory obligation to provide the data. You are free not to register — the free content is accessible without an account.
Do Not Track and Global Privacy Control: NihonTale embeds no analytics service and no third-party tracker, so there is nothing here that a browser "Do Not Track" header would need to switch off. Should we ever introduce analytics, it would load only after consent. We additionally honour the Global Privacy Control (GPC) signal: if your browser sends it, all non-essential categories are treated as declined and we do not ask you again.
2. Data Collection & Processing Purposes (Datenerhebung & Verarbeitungszwecke)
2.1. Account Registration Data
When you create an account on NihonTale, we collect personal information necessary to establish and maintain your user account, including:
- Your email address (used for authentication, account recovery, and essential transactional emails).
- Your account password (stored exclusively as salted, irreversible cryptography hashes using bcrypt).
- Account creation timestamp, locale preferences, and preferred interface settings.
2.2. Learning Progress & Profile Data
To deliver an interactive, personalized language learning experience, we process and store data related to your platform activity:
- Completed visual novel story chapters, dialogue checkpoints, and interactive decision branches.
- Kana and Kanji learning stats, exercise review scores, and SRS (Spaced Repetition System) interval scheduling data.
- Character interaction history (such as progress and settings with our AI character coach Yui).
- Gamification metrics including consecutive daily streaks, total study duration, and achievement badges.
3. Legal Basis for Data Processing (Rechtsgrundlagen nach DSGVO)
We process your personal data strictly in accordance with European data protection regulations (GDPR Article 6):
- Performance of a Contract (Art. 6(1)(b) GDPR): Processing your account credentials, payment state, and study progress is strictly required to fulfill our contractual agreement to deliver the NihonTale learning platform.
- Legitimate Interests (Art. 6(1)(f) GDPR): Processing server logs and session tokens. Our legitimate interest lies in ensuring the technically error-free operation and the security of our systems and in defending against attacks.
- Compliance with Legal Obligations (Art. 6(1)(c) GDPR): Retaining billing records and transaction data to comply with statutory tax and commercial retention duties (see section 7).
- Consent (Art. 6(1)(a) GDPR): The newsletter, and any storage on your device that is not strictly necessary. Consent is always given by an active choice on an empty checkbox, never by a pre-ticked one, and can be withdrawn at any time with effect for the future — see section 8.
3.1. Emails we send
Service emails — password reset links, order and cancellation confirmations, invoices, notice of material changes — are part of performing the contract and are sent on Art. 6(1)(b) GDPR. They cannot be switched off while you hold an account, because without them the contract cannot be performed.
The newsletter is sent solely on your consent under Art. 6(1)(a) GDPR and § 7(2) UWG. It is optional, never bundled with account registration or the Terms, and the checkbox starts empty. Every issue carries a one-click unsubscribe link that works without logging in and without any follow-up question, and the switch also sits in your profile. As a sender established in Germany writing to recipients worldwide, we include our postal address in the footer of every newsletter, as US law (CAN-SPAM) requires.
Withdrawing consent does not affect the lawfulness of the mailings sent before it.
4. Payment Processing & Financial Data (Stripe Payments)
💳 Secure Payment Gateway Provider
Provider: Stripe Payments Europe, Limited, One Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland
Purpose: Encrypted payment processing, subscription management, invoicing and transaction security.
Data Transmitted: Your email address, the selected plan and the payment details you enter on Stripe's own checkout page. Card numbers and CVV codes never reach our servers.
Data Received: Stripe Customer ID, Subscription ID, subscription status, renewal dates and invoice references.
Legal Basis: Art. 6(1)(b) GDPR — performance of the subscription contract. Without payment processing the paid contract cannot be performed.
Third Country Transfer: Data may be transferred to Stripe, Inc., 354 Oyster Point Boulevard, South San Francisco, CA 94080, USA. The basis is the European Commission's adequacy decision of 10 July 2023 (EU-US Data Privacy Framework), under which Stripe, Inc. is certified; in addition, Stripe has entered into Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.
Data Processing Agreement: In place as part of Stripe's Data Processing Agreement.
Privacy Policy: https://stripe.com/privacy
4.1. Financial Data Protection: All credit card transactions, recurring subscription billing, and payment processing are handled securely by Stripe. When you subscribe to a Premium plan, payment card details are transmitted directly to Stripe via end-to-end TLS encryption. NihonTale does not store full credit card numbers, CVV security codes, or banking PINs on our servers.
4.2. Subscription Metadata: We receive and retain transaction metadata from Stripe to grant access to premium content, including your Stripe Customer ID, Subscription ID, status (active, past_due, canceled), plan renewal dates, and digital invoice history.
5. Cookies, Local Storage & Session Data (Cookies & Speicherung)
5.1. Technical Session Cookies
NihonTale uses technical session cookies (such as PHPSESSID) essential for platform operation. These cookies contain temporary session tokens that keep you securely authenticated while navigating between visual novel chapters and practice modules.
5.2. Browser LocalStorage & SessionStorage
We utilize browser LocalStorage and SessionStorage to cache non-sensitive user settings on your device, including:
- Audio playback preferences, voice speed, and background music volume levels.
- Furigana display toggles (Romaji, Hiragana, or Kanji mode).
- Temporary exercise state and visual novel dialogue text scaling options.
5.3. Managing Cookie Preferences
Essential cookies are required for fundamental site operation. You can configure your browser to block or delete cookies, but doing so will prevent logging into your account and preserving study progress.
The complete list of what NihonTale stores on your device — name, provider, purpose and lifetime of every single entry, each with its own on/off switch — is on the Cookies page. That page is the single source; this policy explains the legal basis and points there rather than repeating the table, so the two can never disagree.
Legal basis: § 25(2) no. 2 TDDDG for the strictly necessary storage described above, which needs no consent because the service cannot be delivered without it. Anything not strictly necessary would require your consent under § 25(1) TDDDG and Art. 6(1)(a) GDPR beforehand — at present, nothing of that kind is embedded. You can reopen your choices at any time via “Cookie Settings” in the footer of every page; withdrawal is as easy as consent and does not affect the lawfulness of processing carried out before it.
6. Hosting, E-Mail Dispatch & Server Logs (Hosting, E-Mail-Versand & Web-Server Logs)
🖥️ Website Hosting Provider
Provider: Contabo GmbH, Aschauer Straße 32a, 81549 Munich, Germany
Purpose: Operation of the web server and database on which NihonTale runs, including the storage of the account and learning data described above.
Server Location: Data centre within the European Union. Hosting does not involve any transfer of personal data to a third country outside the EU/EEA.
Legal Basis: Art. 6(1)(f) GDPR – our legitimate interest in a secure and reliable provision of the platform. A data processing agreement pursuant to Art. 28 GDPR is in place with the hosting provider.
Privacy Policy: https://contabo.com/en/legal/privacy/
✉️ E-Mail Dispatch Provider
Provider: Brevo GmbH, Köpenicker Straße 126, 10179 Berlin, Germany (a subsidiary of Sendinblue SAS, Paris)
Purpose: Technical delivery of account e-mails, in particular password reset links. Brevo acts purely as an SMTP relay; we do not maintain contact lists or run marketing campaigns there.
Data Transmitted: Your e-mail address together with the subject, content and technical delivery data of the individual message.
Server Location: According to Brevo, data is hosted in data centres within the European Union. Any sub-processors are listed in Brevo’s data processing agreement.
Legal Basis: Art. 6(1)(b) GDPR – performance of the user contract, since password recovery is part of providing your account. A data processing agreement pursuant to Art. 28 GDPR is in place.
Privacy Policy: https://www.brevo.com/legal/privacypolicy/
When accessing the NihonTale website, the web servers operated on our behalf by the hosting provider named above automatically record technical connection data in web server log files. The logged information includes:
- Anonymized or pseudonymized IP address of the requesting device.
- Date, exact time, and timezone of the server request.
- Requested URL path, HTTP method, and HTTP status code.
- Web browser version, operating system, and User-Agent header string.
- Referrer URL (the website page from which you visited NihonTale).
Server logs are processed exclusively to ensure web server stability, protect against cyberattacks (such as DDoS or brute-force unauthorized access), and diagnose software bugs.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in ensuring the technically error-free operation and the security of our systems and in defending against attacks.
Retention: Log entries are deleted automatically after 14 days at the latest. Entries kept beyond that period because they document a specific attack are retained only until the incident concerned has been dealt with.
7. Data Retention & Storage Duration (Speicherdauer & Löschung)
7.1. Active Account Data: Your account profile, learning metrics, and subscription records are stored for as long as your NihonTale account remains active.
7.2. Account Deletion: If you request account deletion or delete your profile within settings, your personal data and account credentials will be permanently erased from our active database within 30 days, unless statutory retention obligations apply.
7.3. Statutory Retention Period: Invoices, payment records and the associated transaction data must be retained for at least eight years and, in cases provided for by law, longer — pursuant to § 147(3) of the German Fiscal Code (AO), § 14b(1) of the German VAT Act (UStG) and § 257(4) of the German Commercial Code (HGB). The period runs from the end of the calendar year in which the document arose. Books, records and annual accounts are kept for ten years under § 147(1) no. 1 AO.
7.4. What deleting your account does not remove: Invoices and payment records are the one exception to section 7.2. They cannot be deleted with the account, because the retention duty above overrides the right to erasure for exactly this category (Art. 17(3)(b) GDPR). Everything else — your email address, password hash, learning progress, statistics and settings — goes.
7.5. Other periods: Server log files are deleted after 14 days at the latest (see section 6). Records of consent are kept for as long as the consent has effect plus the limitation period, because Art. 7(1) GDPR puts the burden of proving consent on us. Email enquiries are deleted once the matter has been dealt with and a reasonable follow-up period has passed.
8. Your Rights under GDPR & International Privacy Laws (Ihre Rechte)
Under the EU General Data Protection Regulation (GDPR) and international privacy frameworks, you hold statutory rights regarding your personal data:
- Right of Access (Art. 15 GDPR): You have the right to request information on what personal data we hold about you and receive a copy.
- Right to Rectification (Art. 16 GDPR): You have the right to request correction of inaccurate or incomplete personal records.
- Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): You have the right to request permanent deletion of your personal data.
- Right to Restriction of Processing (Art. 18 GDPR): You may request restriction of processing under certain legal prerequisites.
- Right to Data Portability (Art. 20 GDPR): You have the right to receive your personal learning data in a structured, machine-readable format.
- Right to Object (Art. 21 GDPR): You have the right to object to data processing based on legitimate interests at any time.
- Right to Withdraw Consent (Art. 7(3) GDPR): Where processing rests on your consent — the newsletter, and any future analytics — you may withdraw it at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before it. The newsletter switch sits in your profile and in every newsletter footer; cookie choices are reopened via “Cookie Settings” in the page footer.
- Right to Lodge a Complaint (Art. 77 GDPR): You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement.
🏛️ Supervisory Authority Competent for Us
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
www.lda.bayern.de
You are free to approach the authority in your own country instead.
8.1. How to exercise these rights
Send an informal email to support@nihontale.com. No particular wording and no reason are required.
- Identification: We answer to the email address held on your account. That is the identity check — we will not ask you for identity documents or any other detail beyond what is needed to identify you (Art. 12(6) GDPR).
- Deadline: We reply without undue delay and at the latest within one month of receipt (Art. 12(3) GDPR). If a request is complex, that period may be extended by two further months — we will tell you within the first month, with reasons.
- Cost: Free of charge (Art. 12(5) GDPR).
- Scope of an access request: Our answer covers all the information in Art. 15(1)(a)–(h) GDPR — purposes, categories of data, recipients, envisaged storage period, your rights including the right to complain, the source of the data, and information about automated decision-making — not merely a printout of your account fields.
- Portability: On request we provide the data you have given us in a common, machine-readable format (Art. 20 GDPR).
Some of these you can also do yourself, right away: change your password, switch the newsletter on or off, and delete your account with everything in it, all in your profile.
9. Data Security & Encryption Standards (Datensicherheit)
9.1. End-to-End Encryption: All data transmitted between your browser and our servers is encrypted using modern TLS (Transport Layer Security 1.2 / 1.3) protocols with strong cipher suites.
9.2. Password Hashing: User passwords are never saved in plaintext. We utilize industry-standard cryptographic password hashing (bcrypt) with random salts.
9.3. Security Audits: We maintain strict technical and organizational measures (TOMs), including access controls, firewall monitoring, and regular vulnerability checks to prevent unauthorized access or disclosure.
10. Contact Information & Data Protection Enquiries
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact our support team:
📧 Official Data Protection Contact
Contact Email: support@nihontale.com
Controller: Maiko Zobel, Holztraubacherstraße 5, 84066 Mallersdorf-Pfaffenberg, Germany
Response Time: We aim to answer within 48 hours. For requests under Art. 15–21 GDPR the binding deadline is one month from receipt (Art. 12(3) GDPR).
We are dedicated to addressing any data protection inquiries swiftly and thoroughly.
11. AI-Generated Content & Transparency (KI-generierte Inhalte)
Pursuant to Article 50 of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), we inform you that certain content on NihonTale is created with the assistance of artificial intelligence systems:
- Character voice audio: The spoken dialogue of our characters (including Yui, Ema, and other NPCs) is generated using AI-based text-to-speech (TTS) technology, not human voice actors.
- Dialogue & story text: Portions of the visual novel's dialogue and story text are drafted with the assistance of large language models (LLMs) and subsequently reviewed and edited by our team before publication.
- Backgrounds & character artwork: Scene backgrounds and character illustrations used throughout the visual novel are created with the assistance of AI image generation tools.
As NihonTale is an evidently fictional, creative visual novel, this notice satisfies the transparency obligation under Art. 50(2) AI Act in a manner appropriate to a work of fiction. Corresponding synthetic-content markers are additionally embedded in the underlying game data in machine-readable form.