Privacy Policy

1. Data Controller & Contact

The controller responsible for processing personal data on TypeSprint is:

Francazi Digital e.U.
Owner: Andreas Francazi
Nordbahnstraße 13/199
1020 Vienna, Austria

Legal form: registered sole proprietorship (eingetragenes Einzelunternehmen)
Company register number: FN 670145h
Register court: Handelsgericht Wien (Commercial Court of Vienna)

Further details are listed in our Imprint.

For data protection inquiries, requests to access, correct, or delete your data, please contact us at contact@typesprint.io.

2. Data We Collect

2.1 Data Stored in Your Browser

We store the following data locally in your browser (localStorage):

  • Language preference - Your selected language (English, German, Spanish or Portuguese)
  • User preferences - Your chosen username (3-20 characters), avatar and optional country flag
  • Display settings - Light or dark mode and, in learn mode, your keyboard layout
  • Test state - Which test is open in which browser tab, so that reloading the page brings you back into the test

This data remains on your device and is not transmitted to our servers unless you join or create a test or save a result.

2.2 Data Stored on Our Servers

When you create or join a typing test, we store:

  • Username - Your chosen display name (3-20 characters)
  • Avatar - Your avatar, assembled from predefined parts, and optionally a country flag
  • Role - Whether you joined as a player or spectator
  • Test results - Characters typed, typos, points, speed (WPM and CPM), accuracy, consistency and a per-second record of characters, keystrokes and errors
  • Device class - Whether you typed on a phone or a computer
  • Timestamps - When you created your user account and test sessions

Our server recalculates every result and checks it for plausibility. Implausible results are marked and left off the leaderboards.

If you choose to register an account (optional), we additionally store:

  • Email address - Used for login and password reset only
  • Password - Stored as a secure one-way hash (bcrypt), never in plain text
  • Session token - An HTTP-only cookie to keep you logged in (expires after 90 days)
  • Learn mode - For every lesson attempt: the lesson, keyboard layout, stars, duration, characters typed, typos, keystrokes, mistyped keys, speed, accuracy, consistency, device class and time; for every lesson your best result
  • Classes - The classes you create (name, join code, members) and the classes you join
  • Schools - If your class belongs to a school with a license for the school version: the school's name, its teachers and the license (period and number of seats)
  • Coins and avatar items - Your balance of virtual coins (no real money) and the avatar items you bought with them
  • Leaderboard setting - Whether you want to appear on the public leaderboards

If you sign in via Google or Microsoft, we additionally store:

  • OAuth provider name - Which service you used to sign in (Google or Microsoft)
  • OAuth provider ID - Your unique identifier from the provider, used to link your account
  • Email address - Retrieved from the provider to create your account

We do not receive or store your Google or Microsoft password. Authentication is handled entirely by the respective provider via the OAuth 2.0 protocol.

Anonymous users (without an account) are not required to provide any personally identifiable information beyond their chosen username.

If you use the contact or bug report form, we store:

  • Name, email address and message - What you enter in the form
  • Technical details - Your language, browser (user agent) and, for bug reports, the page address and window size shown on the form
  • Hashed IP address - A pseudonymised hash used only to limit the number of submissions
  • User ID - If you were logged in when you sent the message

Screenshots attached to a bug report are sent to us by email only and are not stored in our database.

2.3 Cookies

We use the following cookies:

  • Session cookie (ts_session) - Keeps you logged in to your account on typesprint.io and on the school version edu.typesprint.io (HTTP-only, expires after 90 days)
  • OAuth cookies (oauth_state, oauth_code_verifier) - Temporary cookies used during Google/Microsoft sign-in to secure the authentication flow (expire after 10 minutes)

These cookies and the browser storage described in 2.1 are strictly necessary for functions you use, so they need no consent and we show no cookie banner. We use no tracking or advertising cookies.

2.4 Visit Statistics

To see how many people find TypeSprint and through which links, we count visits to our public pages (such as the home page, the leaderboards and the guides) ourselves, without cookies and without an analytics service. When you arrive from another website or via a link, we record:

  • Landing page - The page you arrived on and its language
  • Source - The domain of the website you came from, or the source named in the link
  • Country - Derived from your IP address by our hosting provider; the address itself is not stored
  • Device class - Whether you use a phone or a computer

To count each visitor only once per day, we compute a one-way hash of your IP address, your browser identifier (user agent) and a random value that changes every day. The hash and the random value are deleted at the end of each day. After that only the daily totals remain, which cannot be traced back to anyone. Nothing is stored in your browser for this.

While you are logged in, a visit only adds one to a daily total, without any of the details above and without the hash. Visits to test, lesson and class pages and to the school version edu.typesprint.io are not counted at all. The legal basis is our legitimate interest in knowing how our website is found (Art. 6(1)(f) GDPR).

2.5 Username Check and Technical Data

  • Username check - Every username is checked automatically when it is chosen or changed, for example for swear words, extremist codes and names that look like an email address, a phone number or a link. The check runs entirely within TypeSprint; usernames are not sent to any external service. Rejected names are stored for 30 days together with the reason, the time and, when an account is renamed, its user ID, so that we can correct wrong decisions. Digits in names rejected as a phone number or other personal detail are masked before storage.
  • Server logs - Our hosting provider records your IP address and browser identifier (user agent) in server logs, which are deleted after one day.
  • Error reports - If a page runs into an error in your browser, it sends us a short technical report with your browser identifier and, if you are logged in, your user ID. It only appears in the server logs.

2.6 Who Can See Your Data

  • Other participants of a test see your username, avatar, flag, live progress and result. The results page of a test can be opened by anyone who has its link.
  • Everyone can see your username, avatar, flag and result on the public leaderboards if a result is good enough, and a profile card with your best result per test duration and your total number of lesson stars. You can turn this off in your settings. Students of a school with a license appear there only once they agree; they are asked with a preview the first time a result would make a leaderboard.
  • The teacher of a class sees the username, avatar, flag, learning progress and every lesson attempt of the class members.
  • Members of the same class see each other's username, avatar, flag and summarised progress (lessons completed, stars, average speed and accuracy, last activity).
  • Teachers of a school with a license see the school's name, the license period and how many of its seats are used, but not who the other teachers are.

Email addresses are never shown to other users, not even to teachers. If you do not want to be recognised, choose a username that does not contain your real name.

3. Why We Collect Data

Local storage: Essential for providing core functionality:

  • Remembering your language preference across visits
  • Pre-filling your username and avatar when joining tests

Providing TypeSprint: Running typing tests, saving and showing results and leaderboards, your account, your learning progress, classes and password reset. The legal basis is providing the service you use (Art. 6(1)(b) GDPR).

Security and fair leaderboards: The plausibility check of results, the username check, server logs, error reports and the submission limit of the contact form. The legal basis is our legitimate interest in a secure service with fair results (Art. 6(1)(f) GDPR).

Contact and bug reports: To answer your message (Art. 6(1)(b) GDPR if it concerns your account, otherwise Art. 6(1)(f) GDPR).

Visit statistics: Show us how many people visit TypeSprint and which websites and search engines lead them here, so we know which pages and partnerships are worth our effort.

4. Data Retention

Local storage: Data remains in your browser until you clear your browser data or we update/remove it programmatically.

Test results: Kept to preserve test history and leaderboards, including the results of players without an account. Tests that are never finished are deleted after 11 hours, together with the entries of players who joined them without an account. As we cannot tell who is behind a username, players without an account can have a result deleted by sending us the link to the test and their username.

Accounts: Kept until you delete your account in the settings or ask us to delete it. Deleting an account removes all of its data: the account itself, learning progress and lesson attempts, coins and avatar items, the classes you created, your class memberships, your test results and the tests you created, including the other participants' results in them.

Schools: A school and its license are kept while the school uses TypeSprint and deleted together with its classes when the agreement ends.

Automatic deletion: Sessions after 90 days, password reset links after one hour, unfinished Google or Microsoft sign-ups after 10 minutes, rejected usernames after 30 days, server logs after one day.

Backups: The database is backed up daily and the last eight backups are kept, so deleted data remains in backups for at most eight days.

Contact and bug report messages: Automatically deleted from our database after 90 days. The email copy stays in our mailbox until your request has been handled.

Visit statistics: The daily hashes are deleted at the end of each day. The daily totals contain no personal data and are kept.

5. Third-Party Services

We use the following third-party services:

  • Google - Used for optional social sign-in (OAuth 2.0). When you sign in with Google, we receive your email address and a unique user identifier. Subject to Google's Privacy Policy.
  • Microsoft - Used for optional social sign-in (OAuth 2.0 via Microsoft Entra ID). When you sign in with Microsoft, we receive your email address and a unique user identifier. Subject to Microsoft's Privacy Statement.
  • Vercel - Hosts the website (server functions in Dublin, EU; pages are delivered from the nearest location of its network). Vercel processes your IP address to deliver the pages, including short-lived server logs, and tells us your country for the visit statistics. Subject to Vercel's Privacy Policy.
  • MongoDB Atlas - Cloud database service for storing test and user data, including backups, in Ireland (EU). Subject to MongoDB's Privacy Policy.
  • Pusher - Real-time communication service for multiplayer tests, operated by MessageBird UK Limited, with servers in Ireland (EU). It receives the username, avatar, flag, role, device class and live progress of the participants. Subject to Pusher's Privacy Policy.
  • Hetzner - Hetzner Online GmbH (Germany) sends our password reset emails and hosts our mailbox contact@typesprint.io. Subject to Hetzner's Privacy Policy.

Our servers are located in the EU. Vercel and MongoDB belong to companies based in the United States, so access from the US cannot be fully ruled out; such transfers are protected by the EU-US Data Privacy Framework and by Standard Contractual Clauses. For Pusher's operator in the United Kingdom, the EU adequacy decision for the United Kingdom applies.

6. Use by Schools

Schools can conclude a data processing agreement with us under Art. 28 GDPR. For the accounts, lessons, classes and tests of its students and teachers, the school is then the controller, and we process this data only on its behalf and according to its instructions. The agreement takes precedence over this privacy policy.

With a license, a school uses the school version at edu.typesprint.io, where only accounts of licensed schools can use TypeSprint. It shares accounts and data with typesprint.io, counts no visits and loads no code from third parties into the browser; the only external connection is the real-time service for tests (Pusher). Students of the school appear on the public leaderboards only once they agree.

Students, parents and teachers should direct questions about the use at their school to the school; requests that reach us are forwarded to it. Schools can request the agreement at contact@typesprint.io.

7. Your Rights Under GDPR

If you are located in the European Economic Area (EEA), you have the following rights:

  • Right of access - Request a copy of the personal data we hold about you
  • Right to rectification - Request correction of inaccurate data
  • Right to erasure - Request deletion of your data ("right to be forgotten")
  • Right to restriction - Request that we limit how we use your data
  • Right to data portability - Request your data in a machine-readable format
  • Right to object - Object to our processing of your personal data
  • Right to withdraw consent - Withdraw consent for data processing at any time

You can delete your account yourself at any time in the settings. To exercise any of these rights, please contact us at contact@typesprint.io. We will respond within 30 days.

You also have the right to lodge a complaint with your local data protection authority if you believe we have not handled your data appropriately.

8. Data Security

We implement appropriate technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction:

  • HTTPS encryption for all data transmission
  • Secure database hosting with MongoDB Atlas
  • Passwords stored as one-way hashes, never in plain text
  • OAuth 2.0 with PKCE for secure social sign-in flows
  • Regular security updates and monitoring
  • Access controls and authentication mechanisms
  • Permission checks on the server: teachers see only their own classes
  • Database and backups encrypted at rest

However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security of your data.

9. Changes to This Policy

We may update this privacy policy from time to time. Changes will be posted on this page with an updated revision date. Continued use of TypeSprint after changes constitutes acceptance of the updated policy.

Last updated: September 2026