Privacy policy
Data controller
Jordi Bravo, 8 Rue de Stavelot, L-2553 Luxembourg, is the controller for the processing of your personal data in Medborgarklar. Contact: hej@medborgarklar.com. Full seller identification is in the terms.
What data we process
- Account data: your email address and a cryptographically hashed password (we never store the password in clear text).
- Study data: your answers to questions, which areas you have practised, results of diagnostics and mock exams, and the times of those events.
- Session data: a session identifier in a cookie, plus the time the session is created and expires.
- Language choice: your choice of Swedish or English, stored in a cookie.
- Watch lists: see the dedicated section below.
We do not ask for gender, age, citizenship, country of origin or details of your migration application, and we process no special categories of personal data.
The watch lists (an email about the date, and about the pass mark)
You can leave your email address to get one email when a specific fact is published. There are two separate lists and you may be on either, or both:
- Date of the next sitting — one email the day UHR publishes the date and the locations.
- The pass mark — one email when UHR publishes the pass mark.
Double opt-in is always required. When you submit the form the address is stored as unconfirmed, and the only email that can ever go to it is a confirmation email. If you do not click the link in that email within 14 days, the address is never used for anything. We do not store the confirmation link itself, only a cryptographic fingerprint of it.
| What is stored | Why |
|---|---|
| Your email address | It is the whole point: it is where the email goes |
| Which list, and whether the signup is unconfirmed, confirmed or ended | So that only confirmed addresses can ever be mailed |
| Your language choice (Swedish or English) | So the announcement reaches you in your language |
| The time of the signup, of the confirmation and of any unsubscribe | So we can show that consent exists and when it was given or withdrawn |
| The page the form stood on, and the exact sentence you agreed to | So we can show what you said yes to, not merely that you did |
| Fingerprints (hashes) of the confirmation and unsubscribe links | So the links work without being readable out of the database |
| Your IP address | Not stored. We do not log it at signup and do not attach it to the address |
| Name, phone number or any other detail about you | Not asked for and not stored |
Legal basis: consent (Article 6(1)(a) GDPR). The consent is freely given, specific to each list, and can be withdrawn at any time without affecting anything else in the service.
Withdrawing takes one click. Every email we send contains an unsubscribe link that takes effect the moment you click it: no login, no account, no confirmation step and no reason required. You can also write to hej@medborgarklar.com and we will delete the address entirely.
How long: an unconfirmed signup is deleted automatically 30 days after the confirmation link expires. A confirmed signup is kept until the fact you are watching has been published and the email has gone out, and for at most 12 months after that, or until you unsubscribe — whichever comes first. If you unsubscribe we keep only the fact that the address unsubscribed, so it cannot be added again by accident; if you want that deleted too, write to us.
The list never leaves us. We do not share it with, and never upload it to, Meta, Google or any other advertising network, in any form — not as a file, not as hashed addresses, and not to build lookalike audiences. That is a binding promise and the application deliberately has no export function. If we ever wanted to change it, this policy would have to change first and a separate, specific consent would have to be obtained.
Diagnostic without an account
If you take the diagnostic without creating an account, the result is stored with no link to an identified person. In detail:
| What is stored | For how long |
|---|---|
| A randomly generated id for the run | 90 days |
| Your score and the number of questions | 90 days |
| Which question identifiers you were given and whether each answer was right or wrong, per area | 90 days |
| The time of the run | 90 days |
| Your IP address | Not stored at all with the result |
| Name, email or any other identifier | Not stored |
After 90 days anonymous diagnostic results are deleted automatically. If within that time you create an account and choose to save the result, it is linked to your account and then follows the account data rules below.
Why we process it and on what legal basis
- To give you access to your account and save your progress — performance of a contract (Article 6(1)(b) GDPR).
- To keep the service secure and prevent abuse — legitimate interest (Article 6(1)(f)).
- To meet accounting and consumer law obligations once payment is switched on — legal obligation (Article 6(1)(c)).
- For anonymous statistics on how the diagnostic performs — legitimate interest (Article 6(1)(f)), on data not linked to an identified person.
- To send the emails you asked for from the watch lists — consent (Article 6(1)(a)), which you can withdraw in one click.
- To measure which ads actually lead somewhere, using the Meta pixel — consent (Article 6(1)(a)). See the dedicated section below.
Cookies
Two necessary cookies are always used: a session cookie that keeps you logged in, and a language cookie that remembers whether you chose Swedish or English. Neither requires consent.
Beyond those there is one advertising measurement cookie. The Meta pixel sets _fbp, and _fbc if you arrived through an ad link. It is not set until you have consented: without consent Meta's script is never loaded, no cookie is created and no event is sent to Meta.
We ask first. The first time you visit the site a bar appears at the bottom of the page with two equal choices: Accept or Reject. It does not block the page, nothing in it is pre-ticked, and simply carrying on reading is not a yes — the pixel stays switched off until you explicitly accept it. Under Settings you see the two categories separately: strictly necessary cookies, which are always on and require no consent, and advertising measurement, which is off from the start.
You can change your mind at any time. Your choice is stored in a cookie of our own, mk_consent, for six months, and the bar does not reappear until it expires. At the bottom of every page there is a Cookie settings link that reopens the same choice. If you withdraw your consent the pixel stops sending events immediately, without the page reloading, and _fbp and _fbc are deleted from your browser.
Measuring how the site is used
We measure how the site is used with our own measurement, on our own server. That measurement uses no cookie and no advertising network, and is a different thing from the Meta pixel described in the section after this one.
- We record events such as “diagnostic started”, “diagnostic completed”, “result shown”, “guide read” and “account created”, together with the page address, the language and the time.
- We record where the visit came from: a search engine, an ad campaign or a linking site, taken from the address parameters or the referring domain.
- So that we can tell whether the same visit both started and finished the diagnostic, a random identifier is kept in the browser's session storage and disappears when you close the tab. It cannot be linked to you and does not follow you between visits or between sites.
- We do not store your IP address, your email address or any individual answers alongside these events.
The legal basis is legitimate interest (Article 6(1)(f)) in knowing whether the service works. The data is used in aggregate and is not shared with anyone.
The Meta pixel (Facebook and Instagram)
We advertise the service on Facebook and Instagram. To see which ads actually lead somewhere we use the Meta pixel in your browser and Meta's Conversions API from our server. This means that data about how you use the site is disclosed to Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland.
- What is shared: that a page was viewed and which one, and whether you signed up to a watch list, created an account, started a purchase, completed a purchase or completed the free diagnostic. The event carries the page address, your IP address, your browser's user agent and Meta's own cookie ids (
_fbp,_fbc). - Your email address: for account creation and purchases the address is sent one-way hashed with SHA-256, never in clear text, so that Meta can match the event against an account they already have.
- The watch lists are excluded. The promise above stands unchanged: an address from a watch list is never sent to Meta, not even hashed. When someone signs up, only the fact that a signup happened is sent, never whose.
- What is never shared: your password, your answers to individual questions, your results, and which areas you have practised.
The legal basis is your consent (Article 6(1)(a) GDPR for the processing, and the rules on storing information in your device for the cookie itself). Without consent the pixel is not active, and you can withdraw consent at any time: open the cookie settings and choose Reject. Saying no affects nothing else in the service.
Meta's role: Meta is not our processor. For the collection itself we and Meta are joint controllers, and thereafter Meta processes the data as an independent controller for its own purposes. Meta transfers data to the United States; the transfer relies on the EU standard contractual clauses and Meta's certification under the EU–US Data Privacy Framework. Meta's own information is in Meta's privacy policy.
Processors
We use the following processors. All of them process data on our instructions and under a data processing agreement.
| Processor | Role | Where data is processed |
|---|---|---|
| Neon (Neon Inc.) | Database holding account and study data | EU — Frankfurt, Germany |
| Cloudflare, Inc. | Delivery of the website, running the application at the edge, protection against overload | EU nodes; transfers to third countries under the EU standard contractual clauses |
| Transactional email provider | Sending confirmation emails and the notifications you asked for | EU. The provider is named here before sending opens to the public |
| Payment provider | Handling card payment and receipts for the full-access purchase | Processing within the EU/EEA. We store no card details. |
Recipients that are not processors
Meta Platforms Ireland Limited receives usage data as described in the Meta pixel section above, and only if you have consented. Meta does not process it on our instructions but as a joint and thereafter independent controller, and is therefore not a processor.
We do not sell data. The only advertising network that receives anything is Meta, to the extent described above and only with your consent. That holds in particular for the watch lists: they are never uploaded to Meta, Google or any other advertising platform, in any form, and the addresses on them are excluded from the Meta pixel's events as well. We will not store card numbers.
How long we keep it
- Account data and study data: as long as you have an account.
- Login sessions: 90 days.
- Anonymous diagnostic results without an account: 90 days, then automatic deletion.
- An unconfirmed watch-list signup: deleted 30 days after the confirmation link expires.
- A confirmed watch-list signup: until the watched fact is published and the email has gone out, then at most 12 months — or until you unsubscribe.
- Records required by accounting law once payment is switched on: for as long as the law requires.
- Your advertising-measurement choice (the
mk_consentcookie): six months. Meta's own_fbpand_fbccookies: up to 90 days, per Meta's setting. Data already disclosed to Meta is governed by Meta's own retention periods.
If you ask for deletion we remove your account, your answers and your results within 30 days, except for data we are legally required to keep.
Your rights
You have the right of access, rectification, erasure, restriction, data portability and to object to processing. Write to hej@medborgarklar.com and we will reply within 30 days. You also have the right to complain to a supervisory authority: in Luxembourg the Commission nationale pour la protection des données (CNPD), or the authority in the EU country where you live — in Sweden the Swedish Authority for Privacy Protection (IMY).
Children and young people
The service is aimed at people aged 16 and over, in line with the knowledge requirement applying from the age of 16. A person aged 16 or 17 is a minor; see the section on age and capacity to contract in the terms.
Changes
We update this policy when the processing changes, for example when payment opens. The date of the latest change is shown below.
Last updated: 1 September 2026 — the Meta pixel and advertising measurement added; they require your consent.