Privacy policy
Version 2.1Last updated In force from
Contents
The short version
- Your progress, your answers and your training history live in your browser and are never uploaded. We do not have a copy, because there is no server to hold one.
- Two things do leave your device: an email address if you type one in, and a small stream of product events with no cross-site identifier in it. Both are itemised below, and both stop entirely if your browser signals an opt-out.
- We have never sold or shared personal data for advertising, and this notice commits us not to.
- The fastest way to delete everything is to clear site data for this domain. It is instant, total, and needs nothing from us.
- Questions, requests and complaints go to team@learn-gto.com.
This summary is written for readability and forms no part of the agreement. Where it and the numbered clauses below differ, the numbered clauses govern.
1.Who we are, and how to reach us
Learn GTO is a poker teaching service at learn-gto.com, operated by Appcelerator Studio, operating from the Republic of Serbia and trading as Learn GTO. In this notice, we, us and Learn GTO mean that operator, and you means the person reading it.
For the purposes of the EU General Data Protection Regulation, the UK GDPR and the Serbian Law on Personal Data Protection, we are the controller of the personal data described here. That means we decide why it is processed and how, and we are the party you hold responsible for it.
Every privacy question, request or complaint goes to one address: team@learn-gto.com. It reaches a person, not a queue, and we would much rather answer you than have you go to a regulator — though § 20 explains how to do that too.
We have not appointed a Data Protection Officer. Our processing does not meet any of the thresholds in Article 37 GDPR that would require one: we are not a public authority, our core activity is not large-scale systematic monitoring, and we do not process special categories of data at scale.
2.What this notice covers
This notice covers the Learn GTO website and everything on it: the course, the trainer, the calculators, the reference pages and the onboarding flow. It applies wherever you are reading from.
It does not cover other companies’ websites that we link to. When you follow a link away from Learn GTO you are on someone else’s site, under their notice, and we have no control over what they do — see § 18.
3.Why so little of your data exists at all
This clause is not a legal requirement. It is here because it explains every clause that follows, and because a privacy notice that lists protections without saying where they come from asks to be taken on trust.
Learn GTO is a static site. Every page is built into a file in advance and served from a content delivery network. There is no application server, no database, no API and no session — there is nowhere for your data to be sent, because there is nothing running that could receive it.
So the equity calculations run on your processor, the drills are graded on your device, and your progress is written to your browser’s own storage. We do not have a copy. We cannot look up your account, because there are no accounts. This is a deliberate design decision with a real cost — it is why your progress does not follow you to a second device — and the benefit it buys is that the overwhelming majority of what you do here never becomes our problem, or our liability, or anybody’s subpoena target.
Two things do leave your device, and they are set out in full in § 4 and § 6.
4.Information you give us
4.1Your email address
If you enter an email address into a form on this site — on the pricing page, at a paywall, at the end of onboarding — we record the address together with the part of the site you gave it on, the plan you were looking at if any, the page path and a timestamp. That record is transmitted to a delivery endpoint so that a human can act on it, and a copy is kept in your browser so a failed submission can be retried rather than silently lost.
We use it to answer you and to tell you when the product opens. We do not sell it, rent it, trade it or hand it to a data broker, and we do not use it for advertising.
In the build you are reading, delivery to a collection endpoint is not configured. Addresses submitted in this build stay in your browser and are queued for delivery if an endpoint is configured in a later release; nothing is transmitted in the meantime.
4.2Your onboarding answers
The questionnaire asks which format you play, roughly how experienced you are and what you want to work on. Those answers tune which drills you are dealt. They are stored on your device and are not transmitted to us.
None of them is a special category of personal data under Article 9 GDPR, and we ask nothing that would be: no health information, no financial position, no religious or political affiliation, and nothing about gambling harm.
4.3What you write to us
If you email team@learn-gto.com, we hold that message, your address and our reply for as long as § 12 allows. Please do not send us anything sensitive that we did not ask for — we have no facility for handling it and no reason to want it.
4.4Payment details
Subscriptions are sold by Dodo Payments, who are the merchant of record — they are the seller on your purchase, they issue your invoice and they collect and remit any tax due. Your card details are entered on their systems and are handled by them as their own controller, under their own privacy notice. We receive confirmation that a subscription started, which plan it is, and its status. We never see or store a full card number.
5.Information stored on your device
The table below is complete. It is generated from the same list of storage keys the application itself uses, so a key cannot be added to the product without appearing here — the code will not compile otherwise.
None of it is transmitted to us. All of it is deleted, permanently and immediately, when you clear site data for this domain in your browser settings. There is no server-side copy, so there is nothing to restore and nothing left behind.
learn-gto:v1:auth:user
Strictly necessary- Contents
- A random identifier of the form anon_…, generated in this browser. It is not derived from anything about you, your hardware or your network.
- Purpose
- Gives your progress something to attach to without an account, and gives a future account something to attach to if you ever sign in.
- Lifetime
- Until you clear site data for this domain.
learn-gto:v1:billing:entitlement
Strictly necessary- Contents
- Whether this browser has the course and trainer unlocked.
- Purpose
- Decides whether a paywall is shown.
- Lifetime
- Until you clear site data for this domain.
learn-gto:v1:onboarding:state
You asked for it- Contents
- Your answers to the questionnaire — the format you play, your experience, what you want to work on — which step you reached, and the plan you last looked at.
- Purpose
- Lets a multi-screen flow survive a refresh, and tunes the trainer to the game you actually play.
- Lifetime
- Until you clear site data, or reset onboarding.
learn-gto:v1:course:progress
Strictly necessary- Contents
- Lessons completed, experience points, level, streak, daily goal and per-day activity.
- Purpose
- The course cannot resume, and your stats cannot exist, without it.
- Lifetime
- Until you clear site data for this domain.
learn-gto:v1:trainer:state
Strictly necessary- Contents
- Trainer session state, and the settings drills are dealt from.
- Purpose
- Resumes a session rather than restarting it.
- Lifetime
- Until you clear site data for this domain.
learn-gto:v1:trainer:hand-accuracy
Strictly necessary- Contents
- Reserved for per-hand correctness tallies. Declared in the code; nothing writes it today.
- Purpose
- Would drive the missed-hand heatmap.
- Lifetime
- Not currently written.
learn-gto:v1:trainer:quota
Strictly necessary- Contents
- Reserved for usage counters. Declared in the code; nothing writes it today, and there is no usage cap anywhere in the product.
- Purpose
- Would meter a limited tier, if one existed.
- Lifetime
- Not currently written.
learn-gto:v1:marketing:early-access
You asked for it- Contents
- Any email address you have typed into a form on this device.
- Purpose
- Keeps a local copy so a submission that failed to reach us is not silently lost, and so the site can stop asking for an address it already has.
- Lifetime
- Until you clear site data for this domain.
learn-gto:v1:marketing:signup-queue
You asked for it- Contents
- Submissions that have not yet reached us: the address, the page and the part of the site it was given on, the plan being viewed at the time, and a timestamp. Capped at the 50 most recent.
- Purpose
- Retries delivery on your next visit if you were offline or the request failed.
- Lifetime
- Deleted the moment delivery succeeds; otherwise until you clear site data.
learn-gto:v1:marketing:content-cta-bar
Strictly necessary- Contents
- A single true or false flag recording that you dismissed a banner.
- Purpose
- Stops the banner reappearing on every page after you closed it.
- Lifetime
- Until you clear site data for this domain.
learn-gto:sid — session storage, not local storage
Measurement- Contents
- A random per-tab identifier. It is not durable, is never linked to an email address, and is not shared with any other site.
- Purpose
- Lets a sequence of events within one visit be read as one visit rather than as unrelated hits.
- Lifetime
- Erased by the browser when the tab closes, and never written at all if you have Do Not Track or Global Privacy Control enabled.
A note on the calculator: the hands and boards you enter there are written into the page’s own address, so a link is a complete, shareable snapshot of what you were looking at. That address stays in your browser unless you share the link yourself. Our measurement deliberately records the path and never the query string, so what you typed into the calculator is not in any event record.
6.Information collected automatically
6.1Hosting and delivery logs
The site is served by Google’s Firebase Hosting content delivery network. Like every web server on the internet, it records the requests it serves: your IP address, your user agent, the URL you asked for, the response it gave and the time. We use those logs to keep the site up and to investigate abuse and outages. Learn GTO adds nothing to them.
6.2Product measurement
Learn GTO records a small, typed set of product events — a calculator was opened, a drill was answered, a paywall was shown, onboarding was completed — so we can tell which parts of a teaching product actually teach. Each event carries the event name, a handful of properties describing it, the page path without its query string, the referrer once per visit, a random per-tab session identifier and a timestamp.
Deliberate limits, which are properties of the code and not promises:
- The session identifier is generated per tab and dies with it. It is not a durable identifier, is never linked to your email address, and is never shared with another site.
- There is no cross-site tracking, no advertising identifier, no fingerprinting, no behavioural profile and no ad network.
- Query strings are stripped before an event is sent, so calculator inputs and plan selections never enter the record.
- If your browser signals Do Not Track or Global Privacy Control, nothing is measured, nothing is sent, and no session identifier is written at all.
Where a tag manager is present on the page, the same payload is also pushed to it. We do not inject a tag manager; nothing happens if the page has none.
In the build you are reading, forwarding to a measurement collector is not configured. No events leave your device in this build.
7.What we never collect
Stated as an undertaking, not as a description of current practice. If any of this changes, this notice changes first.
- Special categories of personal data under Article 9 GDPR: health, biometrics, genetics, race or ethnicity, religion, politics, trade union membership, sex life or sexual orientation.
- Precise geolocation. We do not request it and the site has no code that could.
- Your contacts, your calendar, your microphone, your camera or your files.
- Government identifiers, or any document proving your identity.
- Full payment card numbers, at any point, by any route.
- Data purchased from a data broker, or appended to yours from an outside source.
- Anything at all sold, rented or traded. We have never done it and this notice commits us not to.
8.Why we process it, and our legal bases
Article 6 GDPR requires a lawful basis for each purpose, and the honest version of that table is short, because the purposes are few.
Running the course, the trainer and the calculators
Contract- Data
- The anonymous local identifier, your progress, your trainer state, your entitlement, and your onboarding answers.
- Basis
- Performance of a contract with you, Article 6(1)(b) GDPR. You asked for a trainer that remembers where you got to; it cannot do that without keeping a record of where you got to.
Answering you, and telling you when the product opens
Consent- Data
- Your email address, where in the site you gave it, the plan you were looking at, the page path and a timestamp. Anything you write to us, and our replies.
- Basis
- Your consent, Article 6(1)(a) GDPR, given by typing the address in and submitting it. You can withdraw it at any time, and withdrawing it does not affect anything done before you did.
Understanding how the site is used
Legitimate interests- Data
- Product events, the page path without its query string, the referrer once per visit, a per-tab session identifier and a timestamp.
- Basis
- Our legitimate interests in knowing which parts of a teaching product work, Article 6(1)(f) GDPR, balanced by keeping the measurement first-party, session-scoped, free of any cross-site identifier and switched off entirely for anyone signalling an opt-out.
Keeping the site up and defending it
Legitimate interests- Data
- Request logs kept by our hosting provider: IP address, user agent, the URL requested, the response and a timestamp.
- Basis
- Our legitimate interests in serving the site, absorbing abuse and investigating incidents, Article 6(1)(f) GDPR. No web server can operate without them.
Meeting our legal obligations
Legal obligation- Data
- Whatever a specific obligation requires: accounting and tax records once we sell anything, and records of the privacy requests we receive and how we answered them.
- Basis
- Compliance with a legal obligation, Article 6(1)(c) GDPR, and the equivalent duties under Serbian law.
Where we rely on legitimate interests, you have an unconditional right to object, and for the measurement in particular you can exercise it without contacting us at all by turning on the browser signals described in § 6. Ask us for the balancing assessment behind any of these and we will send it to you.
11.Where your data goes
We are established in the Republic of Serbia, and our providers operate globally, so personal data may be processed outside the country you are reading from — including in Serbia, the European Economic Area, the United Kingdom and the United States.
Serbia is a party to Council of Europe Convention 108 and its modernising protocol, and its data protection law is aligned with the GDPR, but it is not the subject of a European Commission adequacy decision. Transfers of personal data out of the EEA or the UK to us therefore rely on the appropriate safeguards in Article 46 GDPR — principally the European Commission’s Standard Contractual Clauses and, for the UK, the International Data Transfer Addendum — or, where a transfer is occasional and necessary to perform a contract you asked us to perform, on Article 49(1)(b).
Where our providers process data in the United States, we rely on their Standard Contractual Clauses and, where the provider is certified, on the EU-US Data Privacy Framework and its UK extension. Ask us for a copy of the safeguards relied on for any specific transfer and we will send it, redacted only where commercially necessary.
12.How long we keep it
The general rule is that we keep personal data only for as long as the purpose it was collected for still exists, and then delete it. Specifically:
- Everything on your device lasts until you clear site data for this domain, which deletes it immediately and permanently. You control this entirely and do not need us.
- Email addresses are kept until you ask us to delete them, or until 24 months have passed with no contact from you, whichever comes first.
- Correspondence is kept for 24 months after the matter is closed.
- Measurement events are kept in raw form for no more than 14 months, after which they are deleted or irreversibly aggregated into figures that identify nobody.
- Hosting logs are kept under our provider’s retention schedule, which is measured in weeks, not years.
- Records of privacy requests are kept for 3 years, because we have to be able to show a regulator that we answered you.
- Accounting and tax records, once there are any, are kept for the period Serbian tax and accounting law requires, which is longer than any period above and which we cannot shorten at your request.
13.How we protect it
We take the measures Article 32 GDPR requires, judged against how little data there is to protect: the whole site is served over HTTPS; we hold no database of user content and no password to steal; access to what we do hold is limited to the people who need it; and our providers are chosen for their own security posture and bound by contract.
The strongest control here is architectural rather than procedural. Data that was never collected cannot be breached, and § 3 explains why almost none of it is.
No method of transmission or storage is perfectly secure, and anyone who tells you otherwise is selling something. If a breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours as Article 33 requires, and we will tell you directly, without undue delay, where the risk to you is high.
If you believe you have found a security problem, please report it to team@learn-gto.com. We will not pursue anyone who reports a genuine vulnerability to us in good faith and gives us a reasonable chance to fix it.
14.Your rights
Depending on where you live, you have some or all of the following rights over your personal data. Where the GDPR or the UK GDPR applies, you have all of them.
- Access — to be told whether we hold data about you and to receive a copy of it.
- Rectification — to have inaccurate data corrected and incomplete data completed.
- Erasure — to have your data deleted where one of the grounds in Article 17 applies.
- Restriction — to have processing paused while a dispute about accuracy or legitimacy is resolved.
- Portability — to receive the data you gave us in a structured, machine-readable format, and to have it sent to another controller where technically feasible.
- Objection — to object to processing based on legitimate interests, and an absolute right to object to direct marketing at any time.
- Withdrawal of consent — at any time, without affecting the lawfulness of what was done before you withdrew it.
- Complaint — to a supervisory authority, as § 20 sets out.
To exercise any of them, email team@learn-gto.com. It is free. We answer within one month, and will tell you inside that month if a complex request needs the two-month extension Article 12(3) allows. We will only refuse a request that is manifestly unfounded or excessive, and if we do we will explain why and tell you how to challenge it.
An honest limit, which we would rather state than have you discover. Because there are no accounts, almost everything about you exists only in your own browser and is genuinely unknown to us. If you write to us, the only key we can search on is an email address you have given us. For anything else, we cannot identify you from the information we hold, and Article 11(2) GDPR does not require us to collect more data purely in order to be able to.
This cuts in your favour more often than against it. The fastest, most complete erasure available to you needs no request, no verification and no waiting: clearing site data for this domain in your browser settings deletes every item in § 5 instantly and irreversibly. No support ticket can do more.
Where we can identify you, we may ask for information confirming that the address you are writing from is the one the data belongs to. That is an anti-impersonation measure, not an obstacle, and we will not use anything you send for verification for any other purpose.
15.Regional disclosures
The rights in § 14 are given to everyone, wherever they live, because operating one standard is simpler and better than operating five. Some jurisdictions additionally require specific disclosures, which follow.
15.1European Economic Area, United Kingdom and Switzerland
We are the controller. Our legal bases are set out in § 8, our retention periods in § 12, and our transfer safeguards in § 11. You have every right listed in § 14.
We have not appointed an Article 27 representative in the Union or the United Kingdom. Article 27(2)(a) exempts processing that is occasional, does not involve special categories or criminal-offence data on a large scale, and is unlikely to result in a risk to individuals — which describes the processing set out in this notice. We keep that assessment under review and will appoint a representative, and name them here, if it stops being true.
You may complain to the supervisory authority in the country where you live, where you work, or where you think the problem happened. You do not have to talk to us first.
15.2California
This part is for California residents and uses the vocabulary of the California Consumer Privacy Act as amended by the CPRA.
In the preceding twelve months we have collected these statutory categories: identifiers (an email address you submitted; a per-tab session identifier; an IP address in hosting logs); commercial information (which plan you were looking at when you gave us an address); and internet or other electronic network activity (pages viewed and product events). They come from you and from your device as described in § 4 and § 6, are used for the purposes in § 8, and are disclosed only to the service providers in § 10.
We have collected no sensitive personal information, so the right to limit its use has nothing to operate on.
We have not sold, and have not shared for cross-context behavioural advertising, the personal information of any consumer, including anyone under 16, in the preceding twelve months. We do not have a financial incentive programme. We treat the Global Privacy Control signal as a valid opt-out request and honour it automatically, as described in § 6.
You have the rights to know, to delete, to correct, to opt out and to be free from discrimination for exercising any of them — we do not offer a different price or a worse service to anyone who does. Use team@learn-gto.com, or have an authorised agent do it for you with written permission we can verify. If we deny a request you may appeal by replying to our decision, and you may also complain to the California Privacy Protection Agency or the Attorney General.
15.3Other United States privacy laws
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island have substantially the rights described in § 14 under their state statutes, and we extend them to residents of every other state as well. We do not sell personal data, do not process it for targeted advertising, and do not carry out profiling that produces legal or similarly significant effects, so no opt-out of those activities is needed. Where your state gives you a right to appeal a refused request, reply to our decision and a different person will review it within the statutory period; if the appeal is refused you may complain to your state Attorney General.
15.4Serbia
Processing is carried out under the Law on Personal Data Protection (Zakon o zaštiti podataka o ličnosti). You have the rights that law gives you, which correspond to those in § 14, and you may complain to the Commissioner for Information of Public Importance and Personal Data Protection of the Republic of Serbia — see § 20.
15.5Everywhere else
If your country’s law — Brazil’s LGPD, Canada’s PIPEDA, Australia’s Privacy Act, or any other — gives you a right not listed here, write to us and we will honour it to the extent the law requires. We would rather apply the most protective standard than argue about which one applies.
16.Children
Learn GTO is for adults. The service is not directed to anyone under 18, we do not knowingly collect personal data from anyone under 18, and using the service requires you to confirm you are at least that age.
If you believe a child has given us personal data, write to team@learn-gto.com and we will delete it promptly. A parent or guardian can also remove everything stored on the device immediately, without contacting us, by clearing site data for this domain.
17.Automated decisions and profiling
We make no decision about you by automated means that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR. The product does adapt to you — it picks drills from your onboarding answers and your recent accuracy — but that happens on your device, it decides only which poker hand you are shown next, and it affects nothing outside the lesson. Nobody is scored, ranked, priced or refused anything as a result.
18.Links to other sites
Learn GTO links to other websites, and some of those links may earn us a commission. Following one takes you outside this notice and into the hands of a company whose practices we do not control and cannot vouch for. Read their privacy notice before you give them anything. A commercial relationship never changes the arithmetic on this site: the equity figures are computed from the cards, not from who is paying.
19.Changes to this notice
When this notice changes, the version number and the date at the top of the page change with it, in the same release as the change itself. The version you are reading is 2.1.
For a change that materially reduces your protections or widens what we collect, we will not rely on a quietly edited page. We will give reasonable notice before it takes effect, by email where we have your address and by a prominent notice on the site otherwise, so that you can object, withdraw consent or delete your data first.
20.How to complain
Please start with us at team@learn-gto.com. Most complaints are a misunderstanding we can clear up in one reply, and it is much faster than a regulator.
You are not required to. You can go straight to a supervisory authority, and doing so does not affect any other remedy you have:
- Serbia — the Commissioner for Information of Public Importance and Personal Data Protection of the Republic of Serbia, poverenik.rs.
- European Economic Area — the authority in your country of residence or work, listed by the European Data Protection Board at edpb.europa.eu.
- United Kingdom — the Information Commissioner’s Office, ico.org.uk.
- United States — your state Attorney General, and in California additionally the California Privacy Protection Agency.