Privacy
Last updated: 3 October 2026 · version 4
This page exists in Spanish, Italian and English. If a sentence does not say the same thing in the three languages, the Spanish one counts.
In one sentence
contigo keeps what it takes for the two of you to study together: the name you get from whoever lets you in, your cards, your reviews, and what you exchange while you learn. We do not keep your email when you sign in to the app. There is no advertising, no tracking, and no cookie banner, because there are no cookies to accept.
contigo is a personal, free trial version. If it ever becomes paid, it will say so first, here and in the app, and no data we collect today will be used for payments or advertising without a new privacy notice. The rules of the service are in the terms.
Who handles your data, and how to reach them
The data controller is Eugenio Nerelli, a private individual living in Spain.
For anything about your data, or to report a piece of content or a behaviour: . Press the button to see the address: we do not write it in plain sight because spam robots harvest it.
It is also the single point of contact for users and for authorities (EU Regulation 2022/2065, arts. 11 and 12), in Spanish, Italian or English. There is no postal address: contigo is not an economic activity, because it collects no money and shows no advertising.
contigo is made by one person. I answer myself, usually within a few days, and in any case within one month (art. 12 GDPR).
There is no data protection officer: it is not mandatory (art. 37 GDPR, art. 34 LOPDGDD).
During the trial, access may be limited or by invitation only. If you have an invitation and cannot get in, write to .
How you sign in
There are four ways in: with Google, with Apple, with a passkey (Face ID or Touch ID, no password), or with none of the three, using a personal link. There is no sign-up with an email: you pick one of these ways, and that is it.
| What we receive | What we do with it | Basis |
|---|---|---|
| An identifier of your account: with Google it is the same one you use in every app you accept with that account; with Apple it is an identifier made just for contigo, different from the one Apple gives to any other app | It is your identity inside contigo. It is not your email and it cannot be traced back to you | Contract (art. 6.1.b) |
| The profile name, when you sign in with Google | It becomes the name you see at the top and that the person you study with sees. You can change it, and the change stays here only | Contract |
| A refresh token, encrypted before it is written (Google and Apple) | Keeping you signed in without repeating the sign-in every time | Contract |
| With the passkey, only the public key of your device | Checking your signature when you sign in. The secret stays on your phone, we never see it | Contract |
| If you start without Google, Apple or a passkey ("Empiezo yo" or "Continuar sin Face ID"), a personal link with a long random key. We keep only its SHA-256 fingerprint, not the key | It is your only way back in. That link is your account: whoever has it gets in as you | Contract |
Your email arrives together with the rest, with Google and Apple, and we do not write it down anywhere. We check the signature, take the identifier and the name, and let the rest fall. This has an uncomfortable flip side, and you should know it: we have no way of writing to you, and if you lose access to your Google or Apple account we cannot check that this contigo account is yours. See "Your rights" below.
If you come in with the personal link, you are the key. It is on your phone, and in Profile you can copy the link to keep it (in your password manager, for example). If you lose the link and have no Google, no Apple and no passkey, there is no way to get it back: we do not keep the key, we do not have your email, and we cannot check that the account is yours. The account and everything inside it are lost. From the web you can add Google or a passkey later, so you do not depend on the link alone.
For how Google and Apple handle your data, they answer, with their own notices. In that step they are independent controllers: they decide, not us.
What we collect, really
One line for each thing. "Basis" is the reason why the law lets us handle it: contract means that without that piece of data the app does not do what you asked (art. 6.1.b); legitimate interest means it serves to protect the service (art. 6.1.f); consent means you decide, and you can change your mind whenever you like (art. 6.1.a).
Your profile
| What | Why | Basis |
|---|---|---|
| An internal identifier of your account | Linking your things together | Contract |
| Display name | It is what the app calls you, and how the person you study with sees you | Contract |
| Language you learn, mother tongue, app language | Choosing your course and the language of the explanations | Contract |
| Role in the pair (teacher or student, or both) | Decides what you see and what the other sees | Contract |
| How many cards a day you want | Your daily cap | Contract |
| Streak of days, scores, shields | The count of days in a row | Contract |
| Avatar: an emoji, or the initials of your name. No photos | So that the other person recognises you | Contract |
| SHA-256 fingerprint of the session token | Keeping you signed in without repeating the sign-in on every screen. We do not keep the real token | Contract |
| Your six-character friend code | So that whoever you want to put in your class can find you | Contract |
| The moment (date and time) you ticked the box saying you are at least 18. Not your date of birth or your age | So that an account is only born for adults, and so that we can say when you declared it | Contract |
| The day (the date only) you last signed in | Deleting accounts that have been idle for 24 months (the automatic deletion is not active yet) | Legitimate interest (art. 6.1.f) |
What you study
| What | Why | Basis |
|---|---|---|
| The cards of your deck: front, back, notes, tags | They are your study material | Contract |
| Each review: what grade you gave yourself and when | Deciding when you will see that card again. It is, in fact, a history of your learning: how much you study, when, with what results | Contract |
| Course enrolments and progress | Knowing where you are | Contract |
| Exams and individual exam answers | Giving you the result and letting you review it later | Contract |
| How much English you said you know (nothing, single words, simple sentences or I can chat) and when you said it | Starting from the right place: Tarea 1, or an exam that starts from your level. You can answer again from your profile | Contract |
| The exercises of the new course: what you tapped or typed (up to 400 characters), the grade, why you got it wrong, and when | Correcting you, creating review cards for what you got wrong, and opening the next unit | Contract |
| Which units of the new course you finished and how many times you did them; and, if whoever teaches you marked a unit as done, when and their identifier | Knowing where you are, and letting you both see the same map | Contract |
| Your choice (yes or no, and when you made it) about letting whoever teaches you see your mistakes | Keeping what you decided. With your yes, whoever teaches you sees the mistakes of your last task; with your no, they see none of that | Consent |
In the new course, what you tap or type in an exercise travels to our server, which is what corrects it: in the Tarea your answer is kept; in review only the grade is kept. No machine decides about this data in your place (art. 22): spaced repetition is a formula, not a judgement, and correcting an exercise is a hand-written rule that compares your answer with the accepted ones. Neither produces a legal effect on you.
What happens between two people
This is the part worth reading twice, because it is the one where another person sees things of yours.
| What | Who sees it | Basis |
|---|---|---|
| Your name and your avatar | The person in your class | Contract, towards both |
| Up to eight cards of your deck, while you are in class: up to three of the ones you find hardest and, to make up eight, ones you have not seen yet | Whoever teaches you, and only while the class is open | Contract |
| The sentences you marked as "I want to say this and I don't know how" | Whoever teaches you | Contract |
| The mistakes of your last task in the unit you will do: which exercises you got wrong, what you wrote and why it was wrong | Whoever teaches you, only if you said yes to "My teacher sees my mistakes" (you can change it in your profile any time), and only while the class is open | Consent |
| Your answers to the exercises whoever teaches you shows you during the class: they are checked and saved like the ones in the task | Whoever teaches you, at that moment | Contract |
| The map of your course: which units you did in the task and in the class | Whoever teaches you | Contract |
| The judgement they give you by voice during the class | It reschedules that card in your deck, as if you had graded it yourself | Contract |
| Voice notes: the audio file, who sent it to whom, when, and how long it is | The other person | Contract, towards both |
| Class invitations, open classes, live sessions, applause, events, friendships | The other person | Contract, towards both |
Said plainly: whoever teaches you sees what you struggle with most, and can change when you will see a card again. That is why the app exists, and why a class is made of two people who chose each other, never of strangers matched by us. Whoever teaches can open a class and give its code to whoever they like; nobody is matched without having decided it.
If inside a voice note you name a third person, we keep that data to deliver the message (legitimate interest), and we have no reasonable way of telling that person (art. 14.5.b).
Notifications and the inbox of notices
| What | Why | Basis |
|---|---|---|
| The technical address of your installation at the push service, two encryption keys, the time of the reminder (web only) | Sending you the study reminder and telling you what is happening in your class | Consent: you switch it on, you switch it off whenever you like |
| The inbox of notices: one line for each notice that concerns you, with its text (which carries the other person's name: "X is inviting you to a lesson", "Voice note from X", "X wants to be your friend"), where it leads, and when it was created | The iPhone app reads it to show you the notices on the phone. Only you can see it | Contract |
The inbox is written always, whether or not you switched on the switch on the web, because it is the only way to notify the iPhone. It empties itself after 7 days, and with the account.
What a notice carries: a short text with the name of whoever causes it, never the content of a voice note or of a sentence. The same text travels in the web push notice, encrypted with a key that only your device has (the push service does not read it), and it may show on your lock screen, depending on your phone's settings.
The permission the operating system asks you for is not the consent for the push notice: the consent is the switch inside contigo, and switching it off deletes the subscription. The iPhone does not use the push service: it is the phone itself that shows the notices in the inbox, as long as you give it permission in Settings, and that schedules the 8 pm reminder, without going through our server.
Security
| What | Why | Basis |
|---|---|---|
| A counter per IP address and day | Stopping someone from using the app like an open tap. We keep the counter, not the history | Legitimate interest (arts. 6.1.f and 32) |
Cloudflare's persistent logs are switched off: no records of the requests going through our service are left.
An IP address is personal data. You can object (art. 21) by writing to : we will assess it, but without these counters we cannot keep the app running, so an objection may mean not being able to use it.
Cookies and device memory
contigo does not use cookies and has no banner, and this section explains why that is not an oversight.
The app keeps a few things in the memory of the browser or of the phone. All of them serve to make what you asked for work, and none serves to follow you:
| What it keeps | Where | What it is for |
|---|---|---|
| Your session: the token, a copy of the previous one while you switch links, and a mark of which account the saved things belong to | Web: localStorage (contigo.token, contigo.token.prec, contigo.account). iPhone: the Keychain, on this device only and without iCloud | Staying signed in without repeating the sign-in on every screen |
| The language you chose (at the entrance and on the presentation site) | Web: localStorage (contigo.porta.l, contigo.sito.l) | Reopening the page in the right language |
| The outbox: the grades and writings not yet sent, and the ones the server refused, kept apart | Web: localStorage (contigo.coda, contigo.scartate). iPhone: a file in the app's folder | Not losing your work when the network is missing |
| The class in progress, the sentences you write during it, and the course you chose | Web: localStorage (contigo.lezione-viva, contigo.direzione). iPhone: UserDefaults (contigo.lezioneMosse, contigo.vivo.frasi) | Resuming it where you were if the app is closed halfway |
| A class code you typed before having an account, while you go to Google and back | Web: localStorage (contigo.codice-in-attesa) and sessionStorage (contigo.porta.cod) | Not losing it on the round trip |
| The Google check in progress: a single-use value and your declaration that you are 18 | Web: sessionStorage (contigo.google.*), until you close the tab | Finishing the sign-in with Google |
| "Already done" marks: that you already have a passkey, that you already saw the suggestion to install the app, that this browser already had an account | Web: localStorage (contigo.passkey, contigo.installata, contigo.gia) | Not asking you again or offering what you already have |
| The last notice from the controller that you closed (your internal number and its version) | Web: localStorage. iPhone: UserDefaults (both with contigo.avviso) | Not showing you the same notice again. It is removed when you sign out |
| Up to which notice in the inbox the phone has shown you, and whether the 8 pm reminder is on | iPhone: UserDefaults (contigo.notifiche.ultimo, contigo.notifiche.persona, contigo.notifiche.spiegato, contigo.promemoria) | Not repeating notices to you |
| The file of your data, while you download it | iPhone: temporary folder, protected while the phone is locked | Letting you save it. It is removed when you close the Profile or sign out |
| The app files (Service Worker) | Browser cache | Letting it open offline too |
Spanish law (art. 22.2 of Ley 34/2002, LSSI-CE, which transposes the ePrivacy directive) asks for consent to store information on the device of whoever browses, except when it serves exclusively to provide a service the user expressly asked for. That is the case for everything above: without the token you are not inside, without the outbox you lose the reviews you did on the metro. That is why there is no window to accept: asking for a consent the law does not require is noise, and teaches people to press "accept" without reading.
The day this changes, this page will change too, beforehand. If contigo ever shows advertising, that advertising will use third-party identifiers, and then consent will really be needed: a request will appear in which refusing costs exactly one tap, like accepting, with no pre-ticked boxes and no narrow paths, and the choice will always be changeable from inside the app. While you read this sentence, it has not happened yet.
The presentation site keeps a single thing: the language you chose at the top right.
What we do not collect
This is not a marketing promise: it is how the app is built.
- No email when you sign in to the app. Whoever lets you in sends it to us and we let it fall. We do not have it, we cannot write to you. The presentation site does not ask for any address.
- No password. You sign in with Google, Apple, a passkey or a personal link. A leftover remains from when sign-in with a password existed: the oldest accounts still hold a username and the irreversible fingerprint (PBKDF2) of the password they had then. No part of contigo reads them any more; they are deleted with your account, and they are meant to disappear all together with a cleanup that removes that whole table.
- No phone number, no date of birth. The age limit is in the "Minors" section; we do not keep a date of birth, only the moment you ticked the 18-years box.
- No location. No GPS. From the IP address one can tell roughly which country you come from, and we use it only for the anti-abuse counter.
- No address book, no access to your contacts.
- No advertising, no advertising profile, no data broker. Today we sell nothing to anybody.
- No analytics, no third-party SDK inside the app. We do not know how many screens you opened yesterday.
- The content of your data does not go to any artificial intelligence. The corrector that tells you whether you wrote correctly is a hand-written rule, not an AI model. In the original course it runs inside your device: what you type while reviewing does not leave it. In the new course it runs on our server: what you tap or type in an exercise reaches it to be corrected and is kept as "What you study" says, but it passes to nobody except Cloudflare, which hosts the server. The development of contigo uses a programming assistant (Anthropic): it reads only counts and technical identifiers, never your cards, your sentences or your voice notes.
Voice notes and messages
contigo works in pairs. What you send, you send to one specific person.
- Who sees it: only the other person in your class. There is no wall, no feed, no matching with strangers: a class is born from a code that you give to whoever you want. Nobody can send you anything unless you accepted it.
- Who does not see it: us. We do not listen to voice notes, we do not transcribe them, we do not analyse them, we train nothing on them. The file is put in storage and handed over to the other person, and it can only be downloaded from inside your session, after checking that you belong to the right class. There is one exception: the data file you download yourself (see "Your rights") carries one link per voice note. Those links are valid for 7 days, and during those 7 days anyone who has them can listen to the note without signing in. Treat that file as private.
- How long they stay: as long as the account of whoever sent them exists; when that account is deleted, they are deleted too. A limit of 90 days from sending is decided, but it is not active yet, like the 24 months for accounts that are no longer used (see the table below). The audio file is not in the backups: if we ever have to restore after a failure from there, the audio does not come back with the rest. The row of each note in the database (who sent it, to which class, when, how long it is, whether it was listened to, the type and size of the file) is in the backups, like the rest of the database.
- If something is wrong: write to . We read what you report and decide what to do case by case.
- Notices do not repeat what the note says. The notice says "Voice note from X", with the name of whoever sent it, never what the note says. See "Notifications and the inbox of notices".
Face and voice
contigo does not handle biometric data. We do not have your fingerprint, we do not have a model of your face, we do not have a voiceprint.
When you unlock your phone with Face ID or Touch ID, the recognition happens inside your phone, in the chip the manufacturer reserves for it. contigo receives nothing biometric: your face and your fingerprint do not leave the device, do not go through us, do not exist in our files.
The avatar is an emoji or the initials of your name: we neither ask for nor accept photographs. Voice notes are audio files: we do not extract voiceprints, we do not identify who is speaking, we do not do speech recognition. As long as this is so, and if it changes we will write it here before doing it, there is no data of the art. 9 category in the middle.
Voice in the exercises stays on your phone. When you record yourself to repeat a phrase, the recording sits in the phone's memory: it is not sent to any server, it is not saved in the account and it disappears when you leave the exercise. If your phone can recognise speech without leaving the device, the app may show you the words the phone heard; if it cannot, that button does not exist. There is never a third-party service: the audio does not leave your phone, and nobody grades how you pronounce. In an exam, what you say travels only as text, and only when you confirm it.
Where the data is and who touches it
Cloudflare is our infrastructure provider and handles the data on our behalf, with the instructions we give it, under the agreement provided for in art. 28. The database and the audio files are there.
Cloudflare is an American company with a worldwide network. The contigo code runs at the point of the network closest to you. Transfers outside the European Union are covered by the Data Privacy Framework, which Cloudflare adheres to, and by the European Commission's standard contractual clauses for whatever remains outside. If you want a copy of these safeguards, write to .
Google and Apple let you in. In that step they are independent controllers: they answer, with their own notices, and receive from you the data that anyone receives who uses a service with their sign-in.
The push service of your operating system or browser (Apple on iPhone and iPad, Google or Mozilla elsewhere) receives the web notices in order to deliver them to you, and so it sees which installation they are going to and when. The content travels encrypted with a key that only your device has: they do not read it. This happens only if you switched notifications on in the web; the iPhone app does not use any push service.
Backups. The first restore, the everyday one, is Cloudflare's D1 Time Travel: it rebuilds the database by itself, up to 7 days back, always on. Outside Cloudflare we keep one more copy on GitHub, encrypted with a key that not even GitHub has: it is only for a bigger disaster, it lasts 7 days and it is named here because it touches all your data. The audio files of the voice notes are in neither copy; the row of each note is.
The administrator. The controller accesses the data only for failures and security, with fixed commands and a written reason for each access, which is recorded. He does not read the content of your cards, your sentences or your voice notes with free queries.
Nobody else. There are no partners, no advertisers, no measuring tools.
How we protect it
Everything goes over encrypted connections. Passwords are no longer asked for, so there are no new passwords to steal: of the old ones only an irreversible fingerprint remains, in some accounts. The session token is kept only as a SHA-256 fingerprint: from the fingerprint there is no way back. The Google and Apple refresh token is encrypted before it is written. Voice notes are downloaded only inside an authenticated session and after checking that you belong to that class. The exception is the links in the data file you ask for yourself: they are valid for 7 days.
If a breach happens that puts your data at risk, we report it to the authority within 72 hours (art. 33). If the risk to you is high, we tell you (art. 34): since we do not have your email, we do it with a notice at the top of the app's home screen, in your language, that stays there until you close it. You will see it the next time you open the app.
How long we keep things
| What | How long |
|---|---|
| Profile, account, social identity, class, roles, cards, reviews, enrolments, exams, exercises of the new course, "I want to say" sentences, applause, events | As long as the account exists. Deleted when you ask |
| Voice notes (row in D1 and audio file) | As long as the account of whoever sent them exists. A limit of 90 days from sending is decided but not active yet. The audio file is not in the backups; the row is |
| Class invitation | Valid 30 minutes if not accepted, and 2 hours from acceptance to open the class; after that it can no longer be used, but the row stays as history, with the note the inviter wrote |
| Friend code | Until you join a class |
| Class codes and invitations to a pair | They stay even after expiry or use. Deleting them 30 days later is decided, but it is not active yet |
| Inbox of notices | 7 days, and with the account |
| Mark of a deleted account, in the file storage | See "Deleting the account": today it stays until the controller switches on the automatic cleanup, and from then on 8 days after the account is deleted |
| Truce between devices | 7 days. When you change phone, the old access stays valid for 7 more days and then stops |
| Notification subscription | Until you switch them off. If the push service tells us the installation no longer exists we mark it off, but the row stays with the address and the keys |
| Counter of sign-ups per IP address and day | 7 days |
| Counter of failed sign-in attempts | 30 days |
| Username and password fingerprint of the old sign-ins (only in accounts older than sign-in with Google or Apple) | Until that whole table is removed (the cleanup is ready, not applied yet) or until you delete your account |
| Idle account | The plan is to delete it after 24 months without a sign-in; the automatic mechanism is not active yet, so today no account is deleted on its own for this |
| Backups | 7 days, both on D1 Time Travel and on the encrypted copy on GitHub |
Your rights, and how they are really exercised
You have the right to know what data we have (art. 15), to correct it (16), to delete it (17), to limit its use (18), to take it away in a format another app can read (20), to object to the processing based on our legitimate interest (21), and to withdraw a consent when you gave one (7.3).
In contigo almost all of them are done from inside the app, in your profile:
- Edit the profile: name, languages, daily cap.
- Notifications: the switch that gives and takes away the consent.
- Download my data: the file with everything we have about you.
- Delete my account: see the section below. It is also in the iPhone app, identical.
A copy of your data. From your profile, with "Download my data", you get at once a file (JSON) that covers everything we keep about you: the profile, the cards, the reviews, the exams, the exercises of the new course, the sentences, the classes, the judgements received and the inbox of notices (and your old username, if you had one), plus the links to your voice notes (those links are valid for 7 days, and whoever has them can listen to the note while they are valid). Only the technical secrets are left out (the fingerprints of your token, the encrypted keys and the public key of your passkey). It covers access and portability together (arts. 15, 20). If you cannot sign in, write to .
We do not have your email, so for everything else the only way we have of being sure it is you is that you have signed in to your account (art. 12.6), or that you write to us from there. We will never ask you for an identity document: it would mean collecting more data than we are deleting.
If you lost access to your Google or Apple account, write to anyway and we will see together whether there is a way to check that the account is yours. If there is not, we have to tell you openly: we cannot identify you, and so we cannot give you the data of that account nor delete it on request (art. 11). It is not an excuse, it is the consequence of not having a contact of yours.
For everything else (objection, restriction, complaints, questions) write to . We answer within one month, extendable by two more if the request is complicated, and in that case we explain why (art. 12.3). It costs nothing.
If you think we are getting it wrong you can turn to the Agencia Española de Protección de Datos (AEPD, aepd.es), which is the authority of the country where the controller is established, or to the authority of the country where you live or where the event happened (art. 77). You can also go to a judge.
Deleting the account
It is done from your profile, with Delete my account, inside the app (on the web and on the iPhone it is the same), without writing to us and without asking anyone's permission. You must be signed in, and you must type your name again to confirm: it is there to make sure it is not a tap by mistake.
There is no second thought and no grace period. When you confirm, it happens at once.
Disappears: your profile and your name, the link with Google or Apple and the encrypted refresh token, your whole deck, all the reviews, the enrolments, the exams and the answers, the exercises of the new course, the sentences you wrote, your voice notes, the friendships, the applause, the events, the notifications and the inbox of notices, the sessions open on every device.
Your internal number disappears from the database. No row with your identifier stays, in any table: not the classes you opened, not the class codes and invitations you created, not the class invitations with the note you wrote, not your old username if you had one. All of it is deleted with the account.
But a mark stays, and it is only your number. When an account is deleted we leave in the file storage (Cloudflare R2) an empty file whose name is the date of the deletion and your internal number: neither your name nor anything else. It serves one purpose: if one day we have to rebuild the database from a copy that still included you, that mark lets us delete you again. The automatic cleanup that removes the marks after 8 days is not switched on yet (the controller switches it on), so today the marks stay until then.
Disappears for the other person too: the voice notes you sent them disappear from their conversation as well. In your place, the other person is left without a partner in the class: without your name.
Stays: the other person's deck, their reviews, their progress: they are theirs, including the cards you rescheduled by judging them. The anti-abuse counter stays, which is tied not to your account but to your IP address, and so does the mark above: the sign-up counts per IP and day are kept 7 days, and the failed sign-in attempts 30 days (see the table "How long we keep things"). A deletion reaches the backups within 7 days.
Something we cannot do ourselves. With Apple, deleting the account already revokes the authorisation by itself (barring an Apple failure at that moment). With Google, the link between contigo and your account also remains in your Google account settings: if you want to remove it, go to myaccount.google.com › Security › Third-party apps and revoke contigo's access.
Minors
To use contigo you must be at least 18 years old. When you create the account we ask you to declare that you are, with a tick box: without it, the account is not born, and the server refuses a sign-up that arrives without that declaration. We do not ask for your date of birth or for a document: your declaration is enough for us, and we keep the moment you ticked it, not your age. The rules of the service are in the terms.
The reason: contigo has two people exchange private messages and voice notes, with real voices and real appointments, and an adult matched with a minor is exactly the situation to avoid. We set it at 18, not lower, also because in Spain a bill on the age of digital consent is moving forward.
What the app does to protect whoever uses it applies at every age: no matching with strangers. A class is born from a code that you give to one specific person, so nothing can reach you from somebody you did not choose.
If we find the account of someone younger, we delete it. If you are a parent and you think your child has an account, write to .
If we change this page
If something substantial changes (a new piece of data, a new purpose, a new provider, advertising) we write it here before doing it, we change the date at the top and we put a notice at the top of the app's home screen, which stays there until you close it, not a line hidden at the bottom of the page.
Earlier versions stay available: ask for them at .
This document is written to be accurate about how contigo really works, and every line matches something that is in the code. It has not been reviewed by a lawyer: before switching advertising on, which changes the legal bases and brings in third parties, it must be reviewed.