Privacy Policy
Last updated 2 August 2026
The short version. ClusterDrill has no analytics, no advertising, no tracking pixels and no third-party cookies. We collect the minimum needed to give you an account and remember what you bought. We do not sell or share your data, and we never see your card details.
1. Who is responsible
The controller for your personal data is:
- Controller
- Impossible Labs (eenmanszaak, registered in the Netherlands)
- Address
- Boutenburg 67, 1068 ZA Amsterdam, Netherlands
- Email
- info@impossible-labs.io
- KvK
- 95962921
- VAT
- NL005178276B15
For any privacy question or request, email info@impossible-labs.io.
2. What we collect, and why
If you only use the free tier
Nothing is sent to us. No account is required. Your progress is stored in your own browser's local storage under the key hpcTrainer.v1 and never leaves your device. Clearing your browser data deletes it.
If you create an account
- Email address — to identify your account and match a purchase to it. Legal basis: performance of our contract with you.
- Display name, if your sign-in provider supplies one — to address you in the interface. Legal basis: performance of contract.
- An account identifier (uid) generated by Firebase Authentication — the key everything else hangs from. Legal basis: performance of contract.
- Anything you type into the contact form — your message, your email address so we can reply, your name if you give it, and the browser user-agent string the request arrives with. We use it to answer you and for nothing else: no list, no newsletter, no profiling. Legal basis: our legitimate interest in answering people who write to us, and performance of our contract where the message concerns a purchase. Messages are kept while the matter is open and for up to 24 months afterwards, so we can pick up a thread you return to. Ask us and we will delete yours sooner. Your message is stored on our own infrastructure and read there — it is not forwarded to any mail service, newsletter tool or third-party helpdesk on the way to us.
- Last-seen timestamp — so we can identify dormant accounts. Legal basis: our legitimate interest in maintaining the service.
When signing in by email link, your address is briefly stored in your browser under cd.emailForSignIn to complete the sign-in, then removed.
If you buy something
- Your entitlement record — which pack you bought, when your access expires, the order identifier, the amount and currency, and the email used at checkout. Legal basis: performance of contract.
- Your learning progress, if signed in — which questions you have seen and answered. Legal basis: performance of contract.
We never receive your card or bank details. Payment is handled entirely by Stripe as merchant of record, under the name Link.
3. What we do not do
- No analytics, statistics or session-recording tools of any kind.
- No advertising, no ad networks, no remarketing, no tracking pixels.
- No third-party cookies, and no consent banner, because we set nothing that would require one.
- No profiling and no automated decision-making with legal or similarly significant effects.
- No selling, renting or sharing of personal data with anyone for their own purposes.
- No newsletter or marketing email unless you explicitly ask for one.
4. Cookies and local storage
We use no tracking cookies. What we do use is strictly necessary to make the service work:
- Local storage for your progress and interface preferences, on your device only.
- An authentication token set by Firebase Authentication when you sign in, so you stay signed in.
Under Dutch and EU rules, strictly necessary storage of this kind does not require consent. You can clear it at any time in your browser, and signing out removes the authentication token.
5. Who processes data on our behalf
We use a small number of providers. Each acts on our instructions under a data processing agreement.
- Google Ireland Limited / Google LLC — Firebase (Authentication, Firestore, Hosting, Cloud Functions). Hosts the application and stores account, entitlement and progress data. Our data is configured to the
europe-west1 region (Belgium).
- Stripe (Stripe, Inc. and its group companies, including Stripe Payments Europe, Limited in Ireland) — payments, as merchant of record via Stripe Managed Payments, presented to you as Link. They receive the data needed to take payment, issue your receipt and invoice, and handle payment-level support and disputes, and they are an independent controller for their own tax, fraud and accounting obligations.
Both providers are US-linked. Transfers outside the EEA rely on the European Commission's adequacy decision for the EU–US Data Privacy Framework and, where applicable, on Standard Contractual Clauses.
6. How long we keep it
- Account and progress data — while your account exists. Delete your account and it is removed.
- Purchase and entitlement records — kept while your access period runs, and afterwards as long as tax and accounting law requires. In the Netherlands that is seven years. These records survive account deletion because we are legally required to keep them.
- Local storage on your device — until you clear it.
7. Your rights
Under the GDPR you have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing, and to receive it in a portable form. You can also withdraw consent where processing is based on consent.
Email info@impossible-labs.io and we will respond within one month. There is no charge.
If you are not satisfied with how we handle it, you may lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens, or with the supervisory authority in your own country.
8. Security
Access to paid content is enforced by server-side security rules, not by the browser. Entitlements can only be written by our payment webhook, which verifies a cryptographic signature on every request. Payment credentials never reach our systems. No system is perfectly secure, but we do not collect data we do not need, which is the most effective protection we can offer you.
9. Children
ClusterDrill is intended for working professionals and is not directed at children. We do not knowingly collect data from anyone under 16.
10. Changes
If this policy changes we will update the date at the top. Material changes affecting how we use data you have already given us will be notified by email to account holders.
← Back to ClusterDrill