Privacy policy
Last updated October 6, 2026
In short: you can browse the site without an account and without cookies. Our analytics don't identify you. We only get personal data from you when you choose to send us something: a request, a submission, a message to the AI assistant, or an email. We don't sell it and we don't show ads.
1. Who is responsible
The controller of your personal data is Piotr Wilczek, a private individual in Poland, who runs Aha Explainer. Contact: contact@ahaexplainer.com. We have not appointed a data protection officer, as the law doesn't require one for a project of this size.
2. What we collect and why
Visiting the site
Our hosting provider, Netlify, receives the technical data any web server needs to deliver a page: your IP address, browser type, the page requested and the time. It keeps this in short-lived server logs, used to run and secure the site. Legal basis: our legitimate interest in operating a working, secure website (Art. 6(1)(f) GDPR).
Analytics
We use Simple Analytics to count visits and see which explainers are popular. It sets no cookies, does not store IP addresses, does not track you across sites, and reports only aggregate numbers such as page views, referrers, and device types. We cannot identify you from it. Legal basis: our legitimate interest in understanding how the site is used (Art. 6(1)(f) GDPR).
Requesting an explainer
When you request an explainer, we receive the text you write and, if you choose to give it, your email address so we can tell you when it's ready. Please don't put other personal information in requests. We use requests to decide what to build next. Requests may be processed by an AI model provider to sort them or draft explainers. Legal basis: our legitimate interest in running and improving the catalog, and, for your email, your consent, which you can withdraw at any time (Art. 6(1)(f) and 6(1)(a) GDPR).
Submitting an explainer and talking to the AI assistant
When you submit an explainer or talk to our AI assistant, we receive your messages, any files you upload, and the name and contact details you give us. We use them to review your submission, communicate with you, publish the explainer if accepted, and prevent abuse. AI tools may help review submissions; if you disagree with an outcome, you can always ask for a person to look at it. Legal basis: taking the steps you asked for under our terms (Art. 6(1)(b) GDPR) and our legitimate interest in keeping the site safe (Art. 6(1)(f) GDPR).
If we publish your explainer, the author name and contact link you provided are shown publicly on the site and in its public source code repository on GitHub.
Emailing us
If you email us, we receive your address and whatever you write, and use them to reply. Legal basis: our legitimate interest in answering you (Art. 6(1)(f) GDPR).
3. What we don't do
- We don't sell or rent your personal data.
- We don't show ads or use advertising trackers.
- We don't build profiles of you or make decisions about you that have legal or similarly significant effects based solely on automated processing.
- Explainers on the site are self-contained and make no requests to other servers.
4. Who we share data with
We use a few service providers who process data on our behalf, under contracts that require them to protect it:
- Netlify, Inc. (USA): website hosting and server logs.
- Simple Analytics B.V. (Netherlands): privacy-friendly, aggregate analytics.
- GitHub, Inc. (USA): hosting of the site's public source code, including published explainers and their author credits.
- Our email provider: stores the messages you send us.
- AI model providers: process requests and assistant conversations. Before those features launch, we will name the provider here.
We may also disclose data if the law requires it, or to protect our rights or the safety of others.
5. Transfers outside the EU
Some providers above are in the USA. Where data leaves the European Economic Area, it is protected by the EU–US Data Privacy Framework where the provider is certified, or by the European Commission's Standard Contractual Clauses.
6. How long we keep data
- Server logs: kept by Netlify for a short period, according to its own retention settings.
- Requests: until we have dealt with them, and at most 24 months. Your email address is deleted once we've told you about the result, or earlier if you withdraw consent.
- Submissions and assistant conversations: as long as needed to review the submission and handle follow-up, and at most 24 months after the last contact. Published explainers and their credits stay as long as they are published.
- Emails: as long as needed to deal with your message and any follow-up.
We may keep data longer where the law requires it or where we need it to establish or defend legal claims.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and get a copy;
- have it corrected or deleted;
- restrict how we use it, or object to processing based on our legitimate interests;
- receive data you gave us in a portable format;
- withdraw consent at any time, without affecting what we did before;
- complain to a supervisory authority. In Poland that is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl). You can also complain in the EU country where you live or work.
To use any of these rights, email contact@ahaexplainer.com. We will answer within one month. We may ask you to confirm your identity first.
If you ask us to remove a published explainer or credit, we remove it from the site and the current version of the public repository. Where removing personal data from the repository's history is required, we will do that too.
8. Children
Anyone can browse the site, and it is designed to be used in classrooms. Browsing doesn't require any personal data. Requesting or submitting explainers and talking to the AI assistant is for people aged 16 or over, or younger people with permission from a parent or legal guardian. Teachers: please don't ask students to send us personal information. If you believe a child has sent us personal data without permission, email us and we will delete it.
9. Security
The site is served over HTTPS and is fully static, with no user accounts. We keep the personal data we receive to a minimum and limit access to it. No system is perfectly secure, but if a breach affects you, we will tell you and the authorities as the law requires.
10. Changes
We will update this policy when what we do with data changes, for example before new features launch. The date at the top shows the latest version.