Legal

Privacy Policy

Restalearn — pre-launch siteVersion 1.1Effective 26 August 2026

1. In short

Restalearn does not exist as a product yet. This site is one page that explains the idea and lets you join a waitlist. So this policy is short, and there is not much in it:

  • The only thing we ask you to type in is your email address. Everything else on the form is optional.
  • We use it for one purpose: to tell you when Restalearn opens to you. If we ever want to send you anything else, we will ask first.
  • We ask for it on the basis of your consent, and you can withdraw that consent with one click in any email we send.
  • We do not sell your data, we run no advertising, we do not profile you, and we use no tracking cookies.
  • If you want your data gone, write to hello@restalearn.com and we will delete it — apart from two small records we explain in section 4.1 and section 7: that you asked us to stop, and that you once agreed to join.

One thing is not working yet. The sign-up form on the front page is switched off while we finish setting up our email provider, so people join by writing to us instead. Nothing about the purpose or your rights changes — section 4.1 says exactly what happens to your address in the meantime.

The rest of this document is the detail behind those five lines. It is written to satisfy Article 13 of the EU General Data Protection Regulation (GDPR) and, for visitors in the United Kingdom, the UK GDPR and the Data Protection Act 2018.

2. Who is responsible for your data

The controller — the person who decides why and how your data is processed — is Vladimir Nedved, founder of the Restalearn project, acting as a private individual. Restalearn is not yet an incorporated company. When it becomes one, the company will take over as controller, this policy will be updated, and everyone on the waitlist will be told before that happens.

Contact for anything in this document, including every privacy request: hello@restalearn.com. A person reads that address, not a ticketing robot.

We have not appointed a Data Protection Officer, and Article 37 GDPR does not require us to have one: we do not monitor people systematically or on a large scale, and we process no special categories of data.

3. What this policy covers

This policy covers this website only — the pages served from restalearn.com and its language versions, and the emails you exchange with us at the addresses published here.

It does not cover the Restalearn learning platform, because the platform does not exist yet. When it launches it will have its own, much longer policy, covering the thinking profile, learning sessions and the AI models involved. You will not be moved from this policy to that one silently: joining the platform will be a separate, deliberate step, with its own information and its own consent.

4. What we collect, why, and on what legal basis

4.1 When you join the waitlist

WhatRequired?Why
Email addressYesTo send you one message when Restalearn opens to you. That is the promise on the front page and the whole point of the list.
“What are you studying right now?”NoSo the first lessons can start from something you actually care about, and so we understand who is interested. Leave it blank and nothing changes. One line is plenty — and please keep sensitive things out of it: health, a diagnosis, religion, politics, or details about other people. We have no lawful basis to hold data of that kind and no use for it, so if it arrives we delete it. A person reads what you write; nothing is inferred from it, and it decides nothing about you.
The “I want to join the Lab” tickNoSo we know you want earlier access in exchange for feedback. If you ticked it, your one message comes earlier and explains what taking part involves.
The date and time you signed up and confirmed, and a copy of the wording you agreed to, in the language you saw itCollected automaticallyThis is the record that shows you consented, which Article 7(1) GDPR requires us to be able to produce.

Legal basis: your consent — Article 6(1)(a) GDPR. There is one form, at the bottom of the front page, with a consent box you tick. Right now that form is switched off: its fields are inactive while we finish setting up our email provider, and next to it are two links that open your mail app instead — one for the waitlist, one for the waitlist and the Lab. An empty message is enough; the subject line carries nothing but which list you asked for and the language you read the page in. Your address then waits in our mailbox and nowhere else. The confirmation step is postponed, not skipped: as soon as the provider is connected we email you the confirmation link, and only clicking it puts you on the list. That wait is not open-ended: if we still cannot send the confirmation 90 days after your message, we delete your address — and you hear nothing about it, because an email announcing the deletion would itself be mail you never agreed to receive. Until you click it we add you to nothing and send you nothing else. If you never click it, the half-finished entry is deleted (see section 7); and if you change your mind before then, one line to hello@restalearn.com removes the address.

While the form is switched off, this page sends nothing anywhere: your address reaches us as an ordinary email and stays in our mailbox — the channel described in section 4.2 — until the confirmation goes out. When the form is switched on it will not post to anyone else’s page either: it goes to a small piece of our own code running on Cloudflare’s network, which checks a hidden field that only automated submitters ever fill in, and then hands your address to Brevo so the confirmation can be sent. Apart from that mailbox, we keep no separate copy of your address outside Brevo.

Withdrawing consent is as easy as giving it. Today one route exists and it always works: a line to hello@restalearn.com. Once the emails start there will be two more — the unsubscribe link at the bottom of every one of them, and the unsubscribe form on this site for when you no longer have the email. Withdrawal does not make the earlier processing unlawful, but it stops it immediately going forward.

Two records outlive your withdrawal, and we would rather say so here than surprise you later.

4.2 When you write to us

If you email hello@restalearn.com or invest@restalearn.com, While the sign-up form is switched off, this is also how people join the waitlist; what happens to those messages is described in section 4.1.

Legal basis: our legitimate interest in answering people who contact us (Article 6(1)(f) GDPR) — and, where your message concerns entering into an agreement with us, steps taken at your request before a contract (Article 6(1)(b) GDPR).

4.3 When you simply visit the page

Serving a web page requires our infrastructure provider to process, briefly, the technical data every browser sends: your IP address, the page requested, the time, your browser's user-agent string, and the page you came from, if any. This happens in server and edge logs.

Legal basis: our legitimate interest in delivering the site and keeping it available and secure (Article 6(1)(f) GDPR). We do not use these logs to build a picture of you, and we never combine them with the waitlist.

4.4 Audience measurement

We want to know whether anyone is reading the page. We use Cloudflare Web Analytics, chosen for what it does not do. Cloudflare states that it “does not use any client-side state, such as cookies or localStorage, to collect usage metrics” and that it does not “‘fingerprint’ individuals via their IP address, User Agent string, or any other data for the purpose of displaying analytics”. Both statements are on Cloudflare's own page, so you can check them without taking our word for it.

Being accurate about this matters more than sounding good, so: Cloudflare does receive your IP address, as every web server must in order to answer you at all, and derives a country from it. What it keeps is aggregate — page views, page paths, referring sites, countries, device type, browser, operating system and load timings. Query strings are not recorded. No identifier is stored that would let Cloudflare or us recognise you on a later visit. The measuring script itself is loaded from static.cloudflareinsights.com — the same company that already delivers this page to you, and nobody new.

Legal basis: our legitimate interest in understanding whether the site works and is found (Article 6(1)(f) GDPR). We weighed that interest against your privacy: the measurement does not identify you, stores nothing on your device, and produces figures we could not trace back to a person even if we wanted to.

One honest complication. Dutch law has an explicit carve-out for measurement with “no or only minor consequences for privacy” (art. 11.7a(3)(b) Telecommunicatiewet), and the Dutch regulator says such measurement needs no consent. Germany and Poland have no equivalent carve-out, and the German supervisory authorities have declined to say that audience measurement is exempt in general. Our own view is that measurement which stores nothing on your device, sets no identifier and cannot single you out falls on the right side of that line — but that is a view, not a settled point, and we would rather say so than pretend the question does not exist.

An honest limit on your right to object: because we keep no identifier for you, we cannot pull one visitor out of an aggregate after the fact. If you do not want to be counted, blocking static.cloudflareinsights.com in your browser or extension works, and we will not try to work around it.

We use no Google Analytics and no advertising, retargeting or social-network tracking of any kind. There are no third-party fonts, no embedded videos and no share widgets: the fonts are served from our own domain precisely so that visiting this page does not tell a third party that you did.

4.5 What is stored on your device

We use no cookies for analytics, advertising or profiling. What is stored is this:

WhatTypePurposeLifetime
themeLocal storageRemembers that you chose the light or dark version, so it does not flip back on your next visit. Written only when you press the toggle.Until you clear it
langLocal storageRemembers the language you picked from the menu, so you are not sent elsewhere next time. Written only when you pick one.Until you clear it
__cf_bm, cf_clearanceCookies Cloudflare may setSecurity only: telling human visitors from automated traffic, and remembering that a challenge was passed. We chose to put the site behind Cloudflare, so these are our responsibility and nobody else’s — we simply cannot read what is inside them, because their contents are encrypted for Cloudflare alone. Cloudflare generates a separate cookie per site and states that it does not track users from site to site or session to session.Per Cloudflare: __cf_bm expires after 30 minutes of inactivity; cf_clearance defaults to 30 minutes

The first two are written only as the direct result of a choice you made, to deliver the preference you asked for. Because they outlive your visit, we treat your click as your consent to be remembered — which is why we say so next to the switch itself, and why “Forget my settings” in the footer of every page erases both in one click. Clearing your browser storage works too, but we do not rely on that: it is your addition, not our mechanism.

One thing happens before you choose anything. On your first visit to the English page, the page reads the language list your browser sends and, if we have that language, sends you to that version. Nothing is stored on your device at that moment, and nothing reaches us beyond the address of the page you land on. Once you pick a language from the menu, your choice is remembered and overrides the detection.

Nothing is inferred from those two choices for any other purpose. Your theme and language are never used to personalise content, to target you or to build a profile, and they never leave your browser. We take the view that the Cloudflare entries are strictly necessary to serve the site securely; they are not used to recognise you anywhere else.

That is why this site has no cookie banner: not because we skipped the question, but because the only things kept on your device are your own two choices, undoable in one click, and a security cookie that protects the page. We will add a banner the day we add anything that needs one.

5. Who else sees your data

We do not sell, rent or trade personal data, and we share it with nobody for their own purposes. We use three service providers, who process data only on our instructions:

ProviderWhat it does for usWhere
Brevo (Sendinblue, Paris, RCS Paris 498 019 298)Holds the waitlist, sends the confirmation and launch emails, handles unsubscribes, keeps the consent recordsBrevo states that all of its database servers are in the European Union — France, Germany and Belgium. Some of its sub-processors are outside the EEA; see section 6
Cloudflare, Inc.DNS, hosting of these static pages, protection against attacks, the audience measurement above, and — once the sign-up form is switched on — running the small piece of our own code that receives it and passes it to BrevoA global network, operated by a company established in the United States
Zoho Corporation B.V.Hosts the hello@ and invest@ mailboxes, so it processes emails you send us — including, while the sign-up form is switched off, the emails by which people join the waitlistEuropean Union — Zoho's European data centres are in Amsterdam and Dublin

Cloudflare's and Brevo's data processing terms apply to our accounts under Article 28 GDPR; with Zoho a data processing agreement is concluded separately, because Zoho does not apply one automatically.

Beyond that, we may disclose data where the law obliges us to — a binding order from a competent authority, for instance. If that ever happens and we are permitted to tell you, we will.

6. Transfers outside the EEA and the UK

Cloudflare. Cloudflare is certified under the EU–U.S. Data Privacy Framework, its UK Extension and the Swiss–U.S. Data Privacy Framework, which the European Commission and the UK government have recognised as providing an adequate level of protection for data sent to certified US companies. Where that certification does not cover a particular transfer, Cloudflare's data processing addendum relies on the Standard Contractual Clauses adopted by the European Commission, with the UK International Data Transfer Addendum for transfers out of the United Kingdom. Cloudflare states that, by default, cookie data may be processed in its data centres in the United States.

Brevo. The waitlist itself sits in the European Union. Brevo's published data processing agreement nevertheless lists sub-processors established outside the EEA — in the United States, India and Canada — including its own group companies providing support, and a log-monitoring provider whose servers are in the United States. Brevo covers those transfers with the European Commission's Standard Contractual Clauses, supplemented by the UK International Data Transfer Addendum.

Access by the controller. The founder lives and works outside the European Economic Area, in a country for which the European Commission has not issued an adequacy decision. Your address stays in the European Union — in our Zoho mailbox while the sign-up form is switched off, in Brevo's systems once it is on; reaching it from outside counts, under Chapter V of the GDPR, as a transfer to a third country. We will not dress that up: the European Commission has not yet adopted standard contractual clauses designed for a controller who — like us — is already directly bound by the GDPR under Article 3(2), so we do not claim to rely on any. What we can tell you is what actually happens. One person has access, over an encrypted connection, to an account protected by a unique password and two-factor authentication. No copy of the list is kept on local equipment. Nothing about you is held anywhere that we could be compelled to hand over beyond what is in that mailbox and in Brevo. And the whole of it is one email address and, if you chose to write one, one line about what you are studying.

If you would rather your address were not reachable from outside the EEA, the honest advice is not to join the waitlist. Nothing else on this site asks anything of you. And if you would like to know which country it is before you decide, write to hello@restalearn.com and we will tell you.

You can ask us for a copy of the safeguards mentioned above by writing to hello@restalearn.com.

7. How long we keep things

DataKept for
Waitlist entry — email, optional text, Lab tickUntil you ask us to delete it, or until 24 months after your last active contact with us — signing up, confirming, replying to an email, or clicking a link in one. Opening an email does not count as contact. Unsubscribing stops the emails and blocks the address but leaves the entry in place, for the reason given in section 4.1; ask us and it goes. If the project is abandoned, the whole list is deleted within 30 days of that decision, after one final email telling you so.
Sign-ups that were never confirmed30 days, then deleted. We chose that period ourselves; no regulator prescribes a number. The 30 days start when the confirmation email goes out; while the sign-up form is switched off, a request that reached us by email waits in the mailbox until we can send that confirmation (see section 4.1) — at most 90 days from the day you wrote to us, after which we delete it. One line from you removes it sooner. Until you confirm, the address is used for nothing except sending the confirmation.
Proof of your consent — timestamps and the wording you acceptedWhile you are on the list, and 5 years after the last email we sent you. Germany’s supervisory authorities work to a three-year limitation period; the Dutch regulator expects consent to be provable for five years after sending. We keep the longer of the two. Then deleted.
Suppression list — the record that you asked us to stop3 years. It exists precisely so that we cannot contact you again by accident. If you want that gone too we will delete it, but then we will not recognise your address if it reaches us by another route — so we will ask you to confirm that is what you want.
Emails you sent us24 months after the conversation ends, unless the content requires longer
Server and security logsAs set by Cloudflare's own retention periods. We archive no copy.
Audience statisticsHeld by Cloudflare, which states it keeps unsampled data for 7 days and then aggregates it; the dashboard reaches back six months. We keep no separate copy.

8. Your rights

Under Articles 15 to 22 GDPR, and the equivalent provisions of the UK GDPR, you have the right to:

Write to hello@restalearn.com. We answer within one month, as Article 12(3) requires; if a request is unusually complex we may extend that by two months and will tell you why within the first month. Exercising these rights is free.

We may need you to confirm that you control the address in question. Where a request arrives from a different address, that is the only way to be sure we are not handing your data to someone else.

If you are in the United Kingdom

Since 19 June 2026 the UK route runs through us first. Under section 164A of the Data Protection Act 2018 you may complain to us directly: email hello@restalearn.com with “Data protection complaint” in the subject line, and we will acknowledge it within 30 days, look into it, and tell you the outcome. You may also complain to the Information Commissioner under section 165 of that Act, and you do not have to come to us first.

Two other UK details: the equivalent rights provisions are Articles 12A and 22A–22D of the UK GDPR, and the one-month clock starts once we have what we need to identify you, pausing while we wait for information we reasonably need in order to answer.

If you want to complain to a supervisory authority

You can go to the authority where you live, where you work, or where the problem occurred. Those most relevant to visitors here:

We would rather you told us first. But that is your choice, and you do not need to contact us before contacting them.

9. Age

The waitlist is not meant for children. Please do not sign up if you are under 16. We do not knowingly collect data from anyone younger; if you believe a child has given us their address, write to hello@restalearn.com and we will delete it.

We use 16 as a single line across all countries because it is the highest age the European Union applies to consent for online services under Article 8 GDPR. Elsewhere the legal threshold is lower — 13 in the United Kingdom, 14 in Spain, 15 in France — but the platform is being built for university-level learners, so one higher line is simpler and safer than six different ones. Sixteen is our own line for this waitlist, not a claim that everyone above it is an adult: when the platform itself launches, the rules protecting people under 18 will be looked at properly, in their own policy.

10. Security

The site is served over HTTPS only. The waitlist lives in Brevo behind an account with a strong, unique password and two-factor authentication, and access is limited to the founder; while the sign-up form is switched off, the addresses that have reached us sit in the hello@ mailbox, protected the same way. We keep the amount of data collected deliberately small, which is the most reliable security measure available to a project this size: data that was never collected cannot leak.

No system is perfectly secure. If a personal data breach occurs, we will notify the competent supervisory authority within 72 hours where it is likely to result in a risk to your rights and freedoms (Article 33 GDPR), and we will tell you directly, without undue delay, where it is likely to result in a high risk to them (Article 34 GDPR).

11. Is providing your data required?

No. Giving us your email is entirely voluntary — no contract, no legal obligation, no consequence to walking away. The only thing you lose by not providing it is the notification when Restalearn opens. The whole site is readable without giving us anything.

12. Changes to this policy

If we change how we handle data, we will update this page and change the version number and date at the top. If the change is significant — a new purpose, a new recipient, a different legal basis — we will email everyone on the waitlist before it takes effect, so you can leave first if you disagree. We will not stretch an existing consent to cover something new by quietly editing this text.

13. Languages

This policy is published in English, Spanish, Polish, German, Dutch and French. All six versions are meant to say exactly the same thing, and we treat them as equally binding: we will never argue that the translation you read does not count. Where the law of your country makes your own language the basis of interpretation — as Polish law does — that is the version that governs for you. Translations elsewhere on this site are made by AI and labelled as such; this document was checked more carefully than that, but if you find that two versions differ, tell us at hello@restalearn.com — we will fix it, and we will not rely on a translation error against you.

Version 1.1 — 26 August 2026. Changed on the day of publication: a limit of 90 days on how long an unconfirmed address waits while the sign-up form is switched off (section 4.1 and section 7). Version 1.0 was online for a few hours the same day, and nobody joined the list under it.

← Back to the main page