Privacy Policy.

This Privacy Policy applies to akusento.com.

Last updated: July 10, 2026

1. Privacy at a glance

General information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally. Detailed information about data protection is provided in the sections below.

Data collection on this website

Who is responsible for data collection?

Data processing on this website is carried out by the website operator. The operator's contact details can be found under "Information about the controller" in this Privacy Policy.

How do we collect your data?

Some data is provided by you when you contact us by email or telephone. Other data is collected automatically by the hosting provider when you visit the website. This is primarily technical data such as browser information, operating system, requested page and time of access.

What do we use your data for?

Technical data is processed to provide the website reliably and securely. Information you send to us is processed in order to respond to your request. We do not use analytics, advertising tracking or profiling on this website.

What rights do you have?

You have the right to obtain information about the origin, recipients and purpose of your stored personal data free of charge. You may also request correction or deletion, withdraw consent with future effect, request restriction of processing in certain circumstances, and lodge a complaint with a competent supervisory authority.

2. Hosting

IONOS

This website is hosted by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany ("IONOS"). When you visit this website, IONOS processes technical access data and server log information, which may include IP address information. Further details are available in the IONOS Privacy Policy.

IONOS is used on the basis of Article 6(1)(f) GDPR. We have a legitimate interest in the reliable, secure and technically correct delivery of this website.

Data processing agreement

A data processing agreement under Article 28 GDPR applies to the use of IONOS. It ensures that personal data processed on our behalf is handled only in accordance with our instructions and the requirements of the GDPR.

3. General information and mandatory disclosures

Data protection

We treat personal data confidentially and in accordance with applicable data protection law and this Privacy Policy. Please note that data transmission over the internet, including email communication, can have security vulnerabilities. Complete protection against access by third parties cannot be guaranteed.

Information about the controller

The controller responsible for data processing on this website is:

Wolf v. Khreninger
Ziegelbergstraße 5
76857 Eußerthal

Email: hello@akusento.com

The controller is the natural or legal person who determines, alone or jointly with others, the purposes and means of processing personal data.

Storage period

Unless a more specific storage period is stated in this Privacy Policy, personal data remains stored until the purpose for processing no longer applies. If you submit a legitimate deletion request or withdraw consent, the data will be deleted unless there are other legally permissible grounds for retaining it. In that case, deletion takes place once those grounds cease to apply.

Legal bases for processing

Depending on the circumstances, processing may be based on consent under Article 6(1)(a) GDPR, contractual or pre-contractual measures under Article 6(1)(b) GDPR, compliance with a legal obligation under Article 6(1)(c) GDPR, or our legitimate interests under Article 6(1)(f) GDPR. The applicable basis is explained in the relevant section of this Privacy Policy.

Recipients of personal data

Personal data is disclosed to external recipients only where this is necessary for processing, required by law, supported by a legitimate interest, or otherwise permitted by law. Where a processor acts on our behalf, processing is governed by a valid data processing agreement.

Withdrawal of consent

Where processing is based on consent, you may withdraw that consent at any time with future effect. The lawfulness of processing carried out before withdrawal remains unaffected.

Right to object under Article 21 GDPR

WHERE PERSONAL DATA IS PROCESSED ON THE BASIS OF ARTICLE 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO THE PROCESSING OF YOUR PERSONAL DATA. IF YOU OBJECT, WE WILL NO LONGER PROCESS THE DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS THAT OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR PROCESSING IS NECESSARY FOR THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS.

Right to lodge a complaint

If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or the place of the alleged infringement.

Data portability

You have the right to receive data that we process automatically on the basis of your consent or a contract in a commonly used, machine-readable format. Direct transfer to another controller will take place only where technically feasible.

Access, correction and deletion

Within the framework of applicable law, you have the right to obtain information about your stored personal data, its origin and recipients, and the purpose of processing. Where applicable, you also have the right to request correction or deletion.

Restriction of processing

You may request restriction of processing where:

  • you contest the accuracy of the personal data while we verify it;
  • processing is unlawful and you request restriction instead of deletion;
  • we no longer require the data, but you need it for legal claims; or
  • you have objected under Article 21(1) GDPR while the balancing of interests is pending.

SSL/TLS encryption

This website uses SSL/TLS encryption for security and to protect transmitted content. You can recognise an encrypted connection by the use of https:// and the security indicator in your browser.

Objection to unsolicited advertising

We object to the use of contact details published as part of legal notice requirements for unsolicited advertising or informational materials. We reserve the right to take legal action in the event of unsolicited promotional communication, including spam email.

4. Data collection on this website

Server log files

The hosting provider automatically collects and stores information in server log files that your browser transmits when accessing the website. This may include:

  • browser type and browser version;
  • operating system;
  • referrer URL;
  • hostname or IP address information;
  • requested page; and
  • time of the server request.

This data is not combined with other data sources by us. Processing is based on Article 6(1)(f) GDPR. We have a legitimate interest in the technically correct, secure and reliable operation of the website.

Local data stored in your browser

Some interactive features store data locally in your browser using localStorage so the site can remember your choices and continue an activity between visits. This can include display settings such as the light/dark theme, parser reading preferences (including Furigana mode, line breaks, pitch colors, devoice marks, and highlight rules), language selection, library reading position, recent dictionary searches, and training state such as saved mistakes or failed words for review.

These values remain on your device. They are not transmitted to us, are not used for tracking or analytics, and can be removed at any time by clearing this website's stored browser data. Clearing this local data may reset preferences, recent searches, reading progress, and saved training review items.

Pitch accent reports

If you use the report function in a pitch accent word popup, we process the information you intentionally submit so that we can review and fix parser issues. A report may include the selected word, reading, pitch class, accent-drop metadata, report category, optional note, surrounding sentence context, page or example identifier, training feedback details where applicable, and the submission time.

Reports are transmitted to a server-side endpoint on this website and stored in an internal database hosted by our website provider. The report form does not ask for contact details, and the application does not intentionally store your IP address or user agent in the report table. Technical access data may still be processed in server logs as described above.

Processing is based on Article 6(1)(f) GDPR. We have a legitimate interest in receiving concrete bug reports and improving the parser. Reports are kept until the issue has been reviewed or resolved and are deleted or anonymized when they are no longer needed for this purpose.

Cookies, analytics and external fonts

This website does not use analytics or advertising tracking. It stores your language preference in a cookie (valid for one year) so the site remembers your chosen language between visits; this cookie carries no other information. If you create an account, two additional strictly necessary cookies apply — see Section 5. Website fonts are hosted locally and are not loaded from Google Fonts or another external font provider.

Contact by email or telephone

If you contact us by email or telephone, your request and the personal data contained in it are processed in order to respond. We do not disclose this information without a legal basis.

Processing is based on Article 6(1)(b) GDPR where the request relates to a contract or pre-contractual measures. In other cases, processing is based on our legitimate interest in responding effectively to enquiries under Article 6(1)(f) GDPR, or on consent under Article 6(1)(a) GDPR where consent has been requested.

Contact data remains stored until you request deletion, withdraw consent where applicable, or the purpose for storage no longer applies. Mandatory statutory retention requirements remain unaffected.

5. Account registration and authentication

Why an account is needed

Parts of the Service — unlimited training sessions, unrestricted dictionary search results, and full access to the reading library — require a free account. Anonymous visitors can still use these features in a reduced form without registering.

Data collected at registration

When you create an account, we store:

  • the email address you provide;
  • a salted cryptographic hash of your password (the plain-text password itself is never stored);
  • an optional display name you choose to provide; and
  • account timestamps, such as when the account was created and when you last logged in.

Processing is based on Article 6(1)(b) GDPR, as this data is necessary to provide the account-based features of the Service you request.

Signing in with Google

As an alternative to a password, you can register or sign in using "Sign in with Google." Nothing is sent to Google unless you actively choose this option: clicking it takes you to Google's own sign-in page, and no Google script runs on this page beforehand. If you continue, Google shares your name, email address, and a Google account identifier with us; we store your email address, an optional display name derived from it, and that Google account identifier so we can recognize you on future Google sign-ins. No password is stored for accounts created this way, since Google verifies your identity on each login instead, and if Google reports your email address as already verified, we mark it verified in our system immediately. Processing is based on Article 6(1)(b) GDPR, the same basis as password-based registration above: it is necessary to provide the account you are requesting by choosing this sign-in method.

For the sign-in step itself, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) and its parent company Google LLC (United States) process data as an independent controller, not as our processor — Google determines its own purposes for this step, such as authenticating you and preventing fraud, so no Article 28 data processing agreement applies here. This may involve transferring data to the United States; Google states that it relies on safeguards such as the EU Standard Contractual Clauses for such transfers. For details, see Google's Privacy Policy.

Email verification and password reset

After registration, we send a verification email containing a single-use, time-limited link, sent from our mailbox (hello@akusento.com) via our email provider IONOS. Only a cryptographic hash of this link's token is stored in our database, not the link itself. The same applies to password-reset links, which you can request from the login page at any time.

Processing is based on Article 6(1)(b) GDPR (verifying account ownership as part of providing the Service) and, for security-relevant emails such as password resets, our legitimate interest under Article 6(1)(f) GDPR in preventing unauthorized account access.

Session cookies

When you log in, we set a session cookie to keep you signed in as you navigate the Service. This cookie is essential to the login feature and cannot be disabled while remaining logged in; it does not track you across other websites. We also set a small, non-sensitive cookie that lets the page display your logged-in name immediately after loading, without waiting for a server round-trip; it carries only your display name or email address, never your password or session identifier.

Processing is based on Article 6(1)(b) GDPR, as these cookies are strictly necessary to keep you signed in once you have logged in.

Synced preferences

If you are logged in, certain preferences that would otherwise be stored only in your browser — such as light/dark theme, library display settings, and reading position — are also stored against your account so that they carry over between your devices. See "Local data stored in your browser" above for the full list of preferences this can include.

Rate limiting

To protect the Service against automated abuse (for example, repeated login attempts), we temporarily store a cryptographic hash of your IP address, not the address itself, together with a request count and time window. This hashed value cannot practically be reversed to reveal your IP address and is not combined with your account data.

Processing is based on Article 6(1)(f) GDPR. We have a legitimate interest in protecting the Service and its users from abuse.

Account deletion

There is currently no self-service option to delete your account. To request deletion of your account and associated data, please contact hello@akusento.com. We will delete your data unless we are required or permitted by law to retain it.