Basset

Privacy policy

Last updated: 4 October 2026

Basset is a reading app for learning a language. This policy describes what it stores, why, and what you can do about it. It covers the app and the server it talks to, both operated by the person named in the imprint.

What Basset stores

You can read every book in the app without an account. An account exists so that your words and your place in a book follow you to another device, and nothing below is collected until you create one.

What Why
Email address, username, and your password as a bcrypt hash To let you log in, to send you a code that confirms the address is yours, and to send you a reset code if you forget your password. The password itself is never stored and cannot be recovered from the hash.
Words you saved, the meaning you chose for each, and the sentence from the book you met it in Your vocabulary list, and the cards the trainer asks you.
Grammar rules you opened, with the sentence you met them in Your grammar collection.
Which book, level and paragraph you are reading To put you back where you were, on any device.
A record of each card you answered and of the days you read, with timestamps The streak, the daily goal, the activity calendar and the badges on the progress tab. None of it can be reconstructed after the fact, which is why it is recorded as it happens.
Your IP address, briefly, while a request is being handled To limit how often login, registration and password reset can be attempted from one address, which is what stops password guessing. The counters are held in memory for at most an hour and are not written to the database. When a request fails, the web server also notes its IP address in the server's log, which is kept for 14 days.
If the app crashes: the error message, the place in the app's code where it happened, the app version and your phone's operating system version So that a fault can be found and fixed. This is the one thing sent without an account, because a crash can happen before you have one. The report goes to Basset's own server and is written to its log; it contains no account, no words and nothing you were reading, and it is not passed on to any crash-reporting service.

What Basset does not do

Where it is stored, and who else sees it

The server runs in Germany and the database sits on that machine. Three other parties are involved, each doing one thing:

Hetzner, the hosting provider
Runs the physical machine and can technically access it, as any host can. It also keeps a copy of the whole server, made once a day, for 7 days. Hetzner is Hetzner Online GmbH in Germany.
Brevo, for email
Delivers the two emails Basset sends: the code that confirms your address when you register or change it, and a password-reset code when you ask for one. It therefore sees your email address and that code, and nothing else. Brevo is Sendinblue SAS in Paris, France.
Expo, for app updates
Delivers fixes to the app's own code without a trip through the app store. Each time the app starts, it asks Expo's update service whether a newer version exists, which tells Expo your IP address, a random identifier this installation of the app made up for itself, the app version and whether your phone runs iOS or Android — nothing about your account, your words or what you read. Expo is 650 Industries, Inc. in the United States, certified under the EU–U.S. Data Privacy Framework.

How long it is kept

Your rights

Under the GDPR — and the UK GDPR, which gives the same rights — you can ask for a copy of your data, correct it, have it deleted, restrict or object to its processing, and complain to a data protection authority. Three of those are buttons in the app, so you do not have to ask anyone:

For anything else, write to the address in the imprint. You can also complain to your local data protection authority.

Legal basis

Your account and learning data are processed to provide the service you asked for (Art. 6(1)(b) GDPR). Rate limiting, server logs and the update check rest on the legitimate interest in keeping the service secure, available and free of known faults (Art. 6(1)(f) GDPR). The UK GDPR has the same provisions under the same numbers.

Children

Basset is not directed at children under 16, and no account should be created for one without a parent or guardian's involvement.

Changes

If this policy changes, the date at the top changes with it. Changes that affect what is collected or who sees it will also be announced in the app before they take effect.