Privacy Policy

Last updated: 26.07.2026

This privacy policy informs you, in accordance with Article 13 of the General Data Protection Regulation (GDPR), which personal data is processed when you visit and subscribe to this website (“GTO Academy”).

1. Controller

The controller within the meaning of the GDPR is:

Sven Güttner

Walter-Hohmann-Str. 19

45128 Essen

Germany

Email: info@gto-academy.com

A data protection officer is not required under Article 37 GDPR and has not been appointed.

2. General information

GTO Academy is a subscription-based single-page application with a free, account-less preview. The parts of the site you can use without registering — the marketing and information pages, the public range preview and a small number of free sample hands — require no account; we only count how many free hands have been played from your internet connection so that the limit cannot simply be reset (see section 6b). To drill in the full trainer or to subscribe, you create a user account; accounts are provided for us by Clerk (see section 4a). Access to the paid content additionally requires an active subscription, which is taken out via Stripe (see section 6).

Once you drill in the paid trainer, each graded decision is stored in our database under your account so that we can show you your own statistics and leak analysis (see section 6a). The training itself shows no advertising and loads no third-party advertising scripts.

Only if you actively consent via our cookie banner do we load marketing and analytics tools that measure the success of our advertising and how the website is used (in particular Google Analytics and the Reddit pixel; see section 3a). These are never loaded without your prior consent, and you can decline or withdraw at any time. Separately from those tools, we report completed sign-ups to Reddit from our own server so that we can tell which advertisements work; section 3b explains that processing and how to object to it.

Personal data is otherwise processed only to the extent necessary to provide the service, as described below. No automated decision-making, including profiling within the meaning of Article 22 GDPR, takes place.

3. Hosting, server logs and reach measurement (Cloudflare)

This website is hosted on Cloudflare Workers (static assets), a service provided by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA.

When you access the website, your browser necessarily transmits data to the hosting provider’s server. The following data in particular is recorded in so-called server log files: the IP address of the requesting device; the date and time of access; the file or address (URL) requested; the amount of data transferred and the access status; the previously visited page (referrer), if transmitted; and the browser and operating system used (user agent).

The purpose of this processing is to deliver the website, to ensure stability and operational security, and to defend against attacks. The legal basis is Article 6(1)(f) GDPR (legitimate interest in a secure and functional website). The log data is not combined with other data sources and is not evaluated for marketing purposes. Connection data of this kind is retained by Cloudflare only for a short period (as a rule no longer than a few days) and is then deleted or anonymised, unless a specific security incident requires longer retention.

A data processing agreement pursuant to Article 28 GDPR is in place with the hosting provider. Cloudflare operates a global network and may process data, including in the USA. The transfer is based on the European Commission’s adequacy decision for the EU-US Data Privacy Framework; Cloudflare, Inc. is certified under that framework.

Beyond these server logs, we operate no analytics on the hosting layer: there is no cookieless reach-measurement product active on this website, and no measurement beacon is served with our pages.

3a. Consent management and marketing/analytics tools (Cloudflare Zaraz, Google Analytics, Reddit)

To measure the success of our advertising campaigns, we use marketing and analytics tools from third parties. These tools are managed and loaded through Cloudflare Zaraz, a tag-management and consent tool provided by our hosting provider Cloudflare (see section 3). When you first visit the website, a consent banner asks whether you agree to these tools. They are blocked and are only loaded and executed after you give your consent; if you decline, they are never activated and the website remains fully usable.

Current status, stated plainly because a privacy policy should describe what actually happens rather than what is merely configured: as at the date of this policy, no browser-side analytics or advertising tool is being loaded on this website at all — neither Google Analytics nor the Reddit pixel is executing, whether or not you consent. The two tools are described below because they are configured and may be activated; if and when they are, they will be loaded only through the consent mechanism described here, and never before you have agreed. The server-side reporting in section 3b is a separate matter and does run.

Reddit pixel (Reddit conversion tracking). If you consent, we load the Reddit pixel provided by Reddit, Inc., 548 Market Street, San Francisco, CA 94104, USA. It sets cookies and processes data such as your IP address, a device/pixel identifier, information about the pages you view and about conversion events (for example when you begin checkout or start a free trial), in order to measure and optimise the performance of our advertising on Reddit and, where applicable, to build advertising audiences. This may involve a transfer of data to the USA; Reddit relies on the European Commission’s Standard Contractual Clauses and/or the EU-US Data Privacy Framework. Reddit’s own privacy policy applies to the processing carried out by Reddit (reddit.com/policies/privacy-policy).

Google Analytics 4 (web analytics). If you consent, we load Google Analytics 4, a web-analytics service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) for users in the EU/EEA, on behalf of Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). Google Analytics uses cookies and similar identifiers to recognise your browser and processes data such as the pages you view, page-view and interaction events (for example when you begin checkout or start a free trial), the referrer, your approximate location (derived from your IP address) and information about your device and browser, in order to help us understand how the website is used and to improve it. Your IP address is transmitted to Google as part of every measurement request — this is unavoidable, because it is how the connection is made. In Google Analytics 4 it is used to derive a coarse location and is then discarded rather than stored or made available to us in our reports; we never see it there. We mention this because “IP anonymisation” is often described as something a website can switch on, and in Google Analytics 4 it is not: it is Google’s default handling, not a setting under our control. Data may be transferred to the USA; Google relies on the European Commission’s Standard Contractual Clauses and/or its certification under the EU-US Data Privacy Framework. Google’s own privacy policy applies to the processing carried out by Google (policies.google.com/privacy).

The legal basis for loading these tools and for the associated storage of, and access to, information on your device is your consent pursuant to Article 6(1)(a) GDPR and § 25(1) TDDDG. You can withdraw your consent at any time with effect for the future via the “Cookie settings” / “Cookie-Einstellungen” option in the consent banner; the withdrawal does not affect the lawfulness of processing carried out before it. Any further marketing or analytics tools we may activate in future will be loaded in the same consent-first manner and listed here.

3b. Server-side conversion measurement (Reddit Conversions API)

Independently of the browser-side tools described in section 3a, we report a single event to Reddit from our own server when a subscription (including a free trial) is successfully started after a checkout: the fact that a sign-up occurred, a random identifier for that checkout (used to avoid double counting), your IP address, your browser identification (user agent) and your email address in irreversibly hashed form (SHA-256; Reddit can compare the hash with hashes of its own, but cannot read the address from it). If you reached us through a Reddit advertisement, the click identifier of that advertisement is also transmitted; it is stored in your browser when you arrive from such an advertisement and is deleted after 30 days at the latest (see section 7).

The sole purpose is to measure which advertising campaigns actually lead to sign-ups. No profile of your use of the website is created for us in this way, and we do not receive any personal data back from Reddit. The recipient is Reddit, Inc. (see section 3a) in the USA; the transfer is based on Standard Contractual Clauses and/or the EU-US Data Privacy Framework, and Reddit’s own privacy policy applies to its further processing.

Because this reporting takes place on our server and does not store or read information on your device, it does not fall under § 25(1) TDDDG; the legal basis is Article 6(1)(f) GDPR (legitimate interest in measuring the effectiveness of our advertising and in not paying for ineffective campaigns). You have the right to object to this processing at any time on grounds relating to your particular situation (Article 21 GDPR) — an email to info@gto-academy.com is sufficient, and we will then exclude your sign-up from this reporting.

4. Contacting us by email

If you contact us by email (for example at the address given in the Legal Notice), we process the data you send (your email address, the content of your message and any other details you provide) solely to handle and respond to your enquiry. The legal basis is Article 6(1)(f) GDPR (legitimate interest in responding to enquiries); where your enquiry is aimed at concluding or performing a contract, the legal basis is Article 6(1)(b) GDPR.

Your data is deleted once your enquiry has been dealt with conclusively and no statutory retention obligations prevent deletion. Your data is not passed on to third parties.

4a. User accounts and sign-in (Clerk)

To drill in the trainer or to take out a subscription you need a user account. Accounts, sign-up, sign-in and session management are provided for us by Clerk, Inc., 660 King Street, Unit 345, San Francisco, CA 94107, USA (“Clerk”), acting as our processor under a data processing agreement pursuant to Article 28 GDPR.

Depending on how you register, the following data is processed: your email address; the verification codes sent to it; if you sign in with Google, the data your Google account releases for this purpose (in particular your email address, your name and, where available, your profile picture — the login is carried out by Google, and Google’s privacy policy applies to that step, policies.google.com/privacy); and technical sign-in data such as the time of registration and of the last sign-in, the IP address and the browser used, which Clerk also processes to detect and prevent abuse (for example brute-force sign-in attempts). Clerk stores this data on our behalf and issues the session token described in section 7.

We additionally store on your account the information needed to grant access: the status of your subscription (for example active, trialing or inactive), the plan booked, the end of the current billing period, and the identifier of your Stripe customer record (see section 6). We do not store a password — sign-in works with an emailed one-time code or with Google.

The legal basis is Article 6(1)(b) GDPR (creation and performance of the user relationship and of the contract for the paid service) and, for the abuse prevention described above, Article 6(1)(f) GDPR (legitimate interest in secure accounts). Clerk processes data in the USA; the transfer is based on the European Commission’s Standard Contractual Clauses and/or the EU-US Data Privacy Framework. Your account data is stored for as long as your account exists; if you delete your account (see section 9), it is deleted, save where statutory retention obligations — in particular commercial and tax law obligations relating to the billing data held by Stripe — require otherwise. We do not use your email address for advertising or newsletters.

4b. Restoring access by email (legacy sign-in link)

Before user accounts were introduced, access could be restored by requesting a one-time sign-in link for the email address associated with a subscription. The website no longer offers this; the interface has been removed and new links are not created. The corresponding endpoint remains available for a transitional period only so that links already sent out, and subscriptions taken out before the changeover, do not stop working. If it is used, the email address is processed solely to check with Stripe whether it has an active subscription and to send a one-time, time-limited link (15 minutes); the legal basis is Article 6(1)(b) GDPR. Any such emails are sent using Cloudflare Email Sending, provided by our hosting provider Cloudflare (see section 3) and covered by the same data processing agreement; no separate third-party email provider is used. To prevent the function being used to find out who is a customer, the request is answered the same way whether or not the address has a subscription.

5. Fonts (served locally)

This website uses fonts that are served entirely locally from our own server. No connection to third-party servers (in particular not to Google) is established when the fonts are loaded, and no data is transmitted to third parties in the process.

6. Subscriptions and payment processing (Stripe)

Subscriptions to GTO Academy are sold directly by the provider named in the Legal Notice; payment processing is handled by Stripe (Stripe, Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA / Stripe Payments Europe, Ltd. for EU customers). Unlike a merchant-of-record model, we are the contracting party for the sale — Stripe only processes the payment on our behalf.

When you subscribe, you provide your data (in particular your email address, billing details and payment information) directly to Stripe during checkout on Stripe’s systems. We do not receive or store your payment card data. From Stripe we receive only the information needed to grant and maintain access — in particular your Stripe customer id and your subscription’s status (for example whether it is active, trialing, cancelled or expired). The legal basis is Article 6(1)(b) GDPR (performance of the contract you enter into for the paid service).

So that we can tell which subscription belongs to which account, your user account and your Stripe customer record are linked to each other: your Stripe customer id is stored on your account (section 4a) and your account id is stored with your Stripe customer and subscription record. When your subscription changes (payment, renewal, cancellation, expiry), Stripe notifies our server and we update the access status stored on your account; where that information is missing or out of date, our server queries your subscription status from Stripe directly. Stripe’s own privacy policy governs the processing that takes place on Stripe’s systems (stripe.com/privacy). A transfer to the USA may occur; it is based on the EU-US Data Privacy Framework and/or the European Commission’s Standard Contractual Clauses. You can view and manage your subscription, invoices and cancellation at any time via the Stripe customer portal linked in the app.

6a. Training history and statistics

When you drill in the paid trainer, each graded decision is stored so that the app can show you your own progress — the accuracy trend, the leak heatmap and comparable statistics. Each record contains only training data: the identifier of your user account, the spot drilled (game type, number of seats, stack size, position, situation), the hand class shown (for example “AKs”), the action you chose, the action the solver considers best, an assessment of your choice, the resulting score and the time of the decision. No card images, no free text and no other personal details are stored, and the data is not used to assess you as a person; it exists purely to feed your own statistics back to you.

The records are stored in a Cloudflare D1 database operated for us by our hosting provider Cloudflare (see section 3) and covered by the same data processing agreement pursuant to Article 28 GDPR. They are not passed on to third parties and are not used for advertising. The legal basis is Article 6(1)(b) GDPR (performance of the contract — the statistics are part of the service you booked). Your history is kept for as long as your account exists so that long-term trends remain meaningful; you can ask us to delete it at any time, and it is deleted with your account (see sections 4a and 9).

6b. Free sample hands (usage limit)

The free sample hands at /train can be played without an account. To stop the free limit being reset simply by clearing the browser or opening a private window, our server counts how many free hands have been played from your internet connection. We do not store your IP address for this. Instead the address is passed through a keyed cryptographic function (HMAC-SHA-256) using a secret key held only on our server, and only the resulting value, the number of hands played and the first and last time of use are stored in the database described in section 6a.

We should be precise about what that does and does not achieve. The stored value is pseudonymous, not anonymous: without the secret key it cannot practically be traced back to an IP address, but we hold that key, so the value remains personal data and we treat it as such. We do not use it to recognise you anywhere else on the site, and it is never combined with your account, your training history or any other record. Entries that have not been used for 90 days are deleted automatically. In addition, the current count is stored in your browser’s local storage so the app can display it without a server request (see section 7).

The legal basis is Article 6(1)(f) GDPR (legitimate interest in offering a free trial without it being usable without limit). You may object under Article 21 GDPR (see section 9).

7. Cookies and local storage on your device

Sign-in cookies (strictly necessary). When you sign in, Clerk (see section 4a) sets cookies on this domain — in particular a session cookie (“__session”) containing a short-lived, signed token that identifies your account, together with the technical cookies Clerk needs to renew that token and to protect the sign-in against abuse. Our server checks the signature of that token on every request to the protected part of the app. In addition, for subscriptions taken out before user accounts were introduced, two legacy cookies may still be present or be set (“gto_session”, currently 24 hours, and “gto_refresh”, currently 180 days); they contain only a signed, time-limited token identifying the Stripe customer record. None of these cookies contains a tracking identifier, and none is used for analytics or advertising. They are cleared when you sign out.

Because these cookies are strictly necessary to provide the service you explicitly requested (a signed-in session and access to the paid content), they do not require consent under § 25(2) no. 2 TDDDG; the legal basis for the associated processing is Article 6(1)(b) GDPR.

Local storage. Independently of cookies, the app stores two small entries in your browser’s local storage: the number of free sample hands you have played (see section 6b), and — only if you reached the website through a Reddit advertisement whose link carries a click identifier — that click identifier, so that a sign-up that happens later can be attributed to the advertisement (see section 3b). The click identifier is stored for a maximum of 30 days and is then deleted automatically. No subscription or payment data is stored on your device.

No other cookies are set for the operation of the service. Separately, if — and only if — you consent via our cookie banner, the marketing and analytics tools described in section 3a (in particular Google Analytics and the Reddit pixel) may set their own cookies or store identifiers on your device; these are not set without your consent and can be withdrawn at any time.

8. Note for visitors from outside the EU

We apply the GDPR standard described in this policy to all visitors worldwide. We do not sell or share personal information within the meaning of US state privacy laws (such as the California Consumer Privacy Act, CCPA/CPRA). Browser-based advertising and analytics tools are loaded only where you have actively consented to them (section 3a); in addition, completed sign-ups are reported to Reddit from our server for advertising measurement, which you can object to (section 3b). Beyond the technical access data described in section 3, we process only the data needed to provide the service: your account data (section 4a), your Stripe customer id and the subscription status we receive from Stripe (section 6), your training history (section 6a) and the hashed usage counter for the free sample hands (section 6b). Your payment details are handled by Stripe, not by us.

9. Your rights as a data subject

You have the following rights vis-à-vis the controller:

  • the right to access the personal data processed (Article 15 GDPR)
  • the right to rectification of inaccurate data (Article 16 GDPR)
  • the right to erasure (Article 17 GDPR)
  • the right to restriction of processing (Article 18 GDPR)
  • the right to data portability (Article 20 GDPR)
  • the right to object to processing based on Article 6(1)(f) GDPR (Article 21 GDPR)
  • the right to withdraw consent at any time with effect for the future (Article 7(3) GDPR)

Note on the right to object: where we process data on the basis of a legitimate interest (Article 6(1)(f) GDPR), you have the right to object to such processing at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves to assert, exercise or defend legal claims.

An informal message to info@gto-academy.com is sufficient to exercise your rights. If you have a user account, you can also ask us there to delete the account together with your training history; we will then delete both, save where statutory retention obligations (in particular for billing records) require otherwise. Deleting your account does not by itself cancel a running subscription — please also cancel it via the customer portal (see section 6).

10. Right to lodge a complaint with a supervisory authority

Without prejudice to any other legal remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement (Article 77 GDPR). The authority responsible for the controller is: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.

11. Changes to this privacy policy

We will adapt this privacy policy whenever the data processing on this website changes. The version published on this page with the “last updated” date above applies.

GTOAcademy

The poker GTO trainer. Drill solver-approved decisions until the right play is automatic.

Product

Learn

Legal

♠ GTO Academy — poker GTO training. No real-money play.Play responsibly · 18+