Privacy policy
In short
Agora mini MBA works without an account. Your learning progress stays on your device. There is no advertising, no analytics and no tracking. Only when you buy, subscribe or restore is purchase information processed by Google Play and by RevenueCat, the service we use to confirm purchases.
1. Who is responsible
The controller under the EU General Data Protection Regulation (GDPR) is:
Andreas Nowottny (trading as Agora)
Nibelungenallee 45
60318 Frankfurt am Main
Germany
Email: annofinance@gmail.com
We are not required to appoint a data protection officer.
2. Data stored only on your device
The app saves the following in your device’s local storage so that you can pick up where you left off: completed lessons and quiz answers, your review schedule, decision-case choices, notes you write in reflections, the name you enter for certificates, your weekly goal, whether the full programme is unlocked and with which plan, and a short local log of app events (for example “lesson completed”) that the app uses for its own statistics.
This data never leaves your device and we cannot see it. You can delete it at any time in Settings → Reset all progress, or by uninstalling the app. Because nothing is stored on our side, we cannot restore lost progress. If Android backup is switched on for your device, Android may include this data in your personal device backup with Google, under Google’s responsibility.
3. Downloading the app
When you download the app from Google Play, Google processes the data needed for this (for example your Google account and device information) under its own responsibility. See the Google Privacy Policy. We receive only aggregated, non-identifying statistics from Google Play Console (such as the number of installs per country).
4. Buying the full programme
The full programme is sold through Google Play as a monthly or yearly subscription or as a one-time lifetime purchase. Google processes your payment details under its own responsibility; we never receive your card or bank details.
To confirm and restore purchases we use RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA, as our processor under a data processing agreement. When the app starts, and when you buy, subscribe or restore, RevenueCat processes: a random app-user ID created by RevenueCat (not linked to your name or email), the Google Play purchase token and transaction details (product or plan, price, currency, dates, renewal status, store country), device type, operating system and app version, and technical connection data such as your IP address, which is needed to deliver the request. We have switched off RevenueCat’s optional collection of device identifiers.
Legal basis: Art. 6(1)(b) GDPR — we need this to give you the access you paid for and to let you restore it on a new device. RevenueCat also shows us aggregated sales statistics (for example, purchases per country and month), which we use to run the business (Art. 6(1)(f) GDPR). RevenueCat stores data on servers in the USA; the transfer is safeguarded by the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). Purchase records are kept for as long as your access can be restored or your subscription runs, and as long as statutory retention periods require (for accounting records in Germany, generally up to ten years). More information: RevenueCat privacy policy.
5. Our website
Our website is hosted on GitHub Pages by GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA. When you visit it, GitHub logs your IP address for security purposes. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in a secure, reliable website. GitHub is certified under the EU–U.S. Data Privacy Framework (Art. 45 GDPR). The website sets no cookies, loads no external fonts or scripts and uses no analytics.
6. When you contact us
If you email us, we process your email address and your message to answer you (Art. 6(1)(b) GDPR where it concerns a purchase, otherwise Art. 6(1)(f) GDPR). We delete the correspondence when it is no longer needed, unless statutory retention periods apply.
7. No tracking, no advertising
The app contains no advertising, no analytics or crash-reporting services and no social-media plug-ins, and it does not use cookies. We do not sell or share personal data for advertising.
8. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). To exercise them, email us. Because we do not know who you are, we may ask for your Google Play order number (it starts with “GPA.”) to find the purchase record.
You also have the right to lodge a complaint with a data protection supervisory authority, for example the one responsible for us: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany.
9. Age
The app is intended for learners aged 16 and over.
10. Changes
We will update this policy if the app or the law changes. The current version is always available in the app and on our website.
Last updated: 22 September 2026