Cookie Policy
Reviewed on: 9/24/2026These texts are also published on slt.de: GTC · Withdrawal information · Privacy
Cookies and similar storage technologies
Hurra Mathe uses only strictly necessary storage: Local Storage, Session Storage and IndexedDB in the browser, plus the storage used by Firebase authentication. It supports sign-in, security, language, appearance, offline use and learning progress. Hurra Mathe uses no analytics or audience measurement, no tracking and no advertising. As no services requiring consent are used, no cookie banner is needed.
Essential storage
This includes language and light/dark mode, locally cached learning and synchronisation state, Firebase authentication data, and device/session identifiers that protect accounts against parallel use. Depending on their purpose, these values remain for the session or until sign-out, deletion or a settings change. They are based on providing the service you explicitly requested or our legitimate interest in secure, functional operation (Art. 6(1)(b) and (f) GDPR and applicable ePrivacy law). A cookie choice stored by earlier versions is deleted automatically on start.
| Category and purpose | Storage location | Duration |
|---|---|---|
| User settings: language, light/dark mode, numeric keypad height, automatic synchronisation, and a cookie choice left over from earlier versions | localStorage, sessionStorage | until changed or until the tab is closed; the choice from earlier versions is deleted at start-up |
| Learning and synchronisation data: progress, plan and trial status, attempts in online tests, queue of changes not yet transferred, practice state in demo mode | localStorage | until sign-out; demo practice state 7 days after the last use |
| Session and security: device and session identifiers for single-device sign-in, protection against password guessing, markers for a purchase made by a parent | localStorage, sessionStorage | until the tab is closed, the lockout expires or browser data is cleared |
| Authentication: Firebase sign-in data so you stay signed in | IndexedDB | until sign-out |
| Offline use: static app files in the cache | service worker cache | until the next version of the app |
Security-sensitive forms are protected by a self-hosted proof-of-work check (ALTCHA) on our own servers in Frankfurt; it sets no cookies and involves no third parties. Firebase provides authentication, database and synchronisation. Stripe is used only when a purchase or subscription management is requested. These services are required for security or the requested feature.
Data locations and international transfers
Hurra Mathe’s Cloud Functions and named Firestore database are configured in europe-west3 (Frankfurt). This regional setting does not automatically apply to every Google service: according to Google, Firebase Authentication runs exclusively from US data centres. Stripe may also process data outside the EU/EEA. Spam protection (ALTCHA) runs exclusively on our own servers in Frankfurt. Where an international transfer occurs, the providers state that suitable safeguards include EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. This overview is reviewed regularly.