Candli Privacy Policy

Last updated: September 04, 2026

This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.

This Privacy Policy explains how Candli processes Personal Data. Where data processing requires specific consent under applicable law, acceptance of this Privacy Policy alone does not constitute that consent.

Easy-to-read summary

We collect and process only the data needed to operate Candli, provide user accounts and user-created content, investigate technical problems, improve the Service, prevent abuse, fulfil contracts and comply with legal obligations.

We do not sell Personal Data. We do not use Personal Data for advertising or advertising profiling. We send newsletters or other direct marketing only where a user has explicitly subscribed, and the subscription can be withdrawn at any time.

When Candli is used by a school or another organisation and that organisation determines why Personal Data is processed, the organisation acts as Data Controller and Enlightware GmbH processes that data on its behalf. For processing that Enlightware performs for its own purposes, such as customer administration, billing, security and legal compliance, Enlightware may act as Data Controller.

Interpretation and Definitions

Interpretation

The words of which the initial letter is capitalized have meanings defined under the following conditions.

The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:

Collecting and Using Your Personal Data

We collect and process Personal Data only as necessary to provide, operate, secure and improve Candli, fulfil contractual and legal obligations, and respond to users and customers. We do not use Personal Data for advertising or advertising profiling. We use contact information for newsletters or other direct marketing only where the relevant user has explicitly subscribed, and the subscription can be withdrawn at any time.

Types of Data Collected
Personal Data

Depending on how Candli is used, We may process:

  • Not all Candli accounts require directly identifying information. In particular, some educational accounts may use pseudonyms or anonymous access mechanisms.
  • Asset Data

    Asset Data is collected when users take or import pictures or record sounds through the use of the Service.

    Asset Data is used as part of user-created games and projects. Some games and assets can be accessed without authentication through unique, difficult-to-guess identifiers. Anyone who obtains such an access link or identifier may be able to access the associated content.

    Users and organisations using Candli are responsible for ensuring that they are authorised to upload and share Personal Data relating to other persons. In educational use, schools determine whether pupils may upload identifiable photographs, voice recordings or other Personal Data as part of a learning activity.

    Usage Data

    Usage Data is collected automatically when using the Service.

    Usage Data may include information such as Your device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages or features of our Service that You visit, the time and date of Your visit, the time spent on those pages or features, unique identifiers and other diagnostic data.

    Cookies, Browser Storage and Analytics

    Candli uses a persistent authentication cookie to maintain Your authenticated session. The cookie may be stored for up to one year.

    Candli also uses browser storage, including local storage and IndexedDB, for application functionality. This includes storing user preferences and anonymous workspaces, and temporarily retaining data that could not be transmitted because of a network failure. If You choose to have Candli remember Your login, authentication information may also be stored locally in Your browser.

    Candli collects usage analytics to help Us understand how the Service is used, including acquisition, engagement and use of Candli features, identify problems and improve the Service. Analytics events are sent directly to servers operated by Us and are not provided to third-party advertising or analytics services.

    Analytics collection can be disabled. Ordinary usage analytics data is retained for no longer than 100 days. Diagnostic and crash data may be retained for longer where reasonably necessary to investigate and prevent technical problems. Aggregated data that no longer identifies individual users or accounts may be retained for longer.

    We do not use advertising cookies, third-party advertising trackers or cross-site tracking technologies.

    You can configure Your browser to delete or restrict cookies and browser storage. However, doing so may prevent some parts of Candli from functioning correctly or may remove locally stored work.

    AI Features

    AI-powered features are optional. Personal Data is sent to external AI service providers only when such a feature has been enabled and is used.

    When You use AI-powered features in Candli, information necessary to provide the feature may be sent to external AI service providers. This may include prompts, relevant conversation history, generated responses, model and usage information, and a session identifier.

    AI requests may be routed through an intermediary service to selected downstream AI model providers. The set of downstream providers may change as models, providers and processing arrangements evolve.

    For Personal Data submitted to AI inference services, Enlightware restricts processing to providers and configurations that meet its applicable data-protection and security requirements, including zero retention of submitted inference data and appropriate safeguards for international transfers. Where EEA AI data processing is configured for an organisation, AI API payloads are processed only within the European Union or European Economic Area.

    The current AI processing arrangements and downstream providers are listed on Our Subprocessors page.

    Browser Speech Recognition

    Some Candli features may use speech recognition provided by Your web browser. When such a feature is used, audio may be processed by the browser or operating-system provider according to its own privacy practices. Candli receives the resulting transcription for use by the relevant feature.

    Use of Your Personal Data

    The Company may use Personal Data for the following purposes:

    We may share your personal information in the following situations:

    Retention of Your Personal Data

    The Company retains Personal Data only for as long as necessary for the purposes described in this Privacy Policy.

    Analytics data is retained for no longer than 100 days. Diagnostic and crash data may be retained for longer where reasonably necessary to investigate and prevent technical problems.

    Personal Data may be retained for longer where necessary to comply with legal obligations, resolve disputes, enforce agreements, or establish, exercise or defend legal claims.

    Transfer of Your Personal Data

    Candli is operated by Enlightware GmbH in Switzerland. Our primary application infrastructure is located in Switzerland or the European Economic Area.

    We also use global network infrastructure for content delivery and security. Requests may therefore be processed outside Switzerland or the European Economic Area, including technical data such as IP addresses.

    Authenticated or session-specific content is not cached on this global network. Content that can be retrieved without an authenticated session, including game assets identified by unguessable identifiers, may be cached for content delivery.

    Where Personal Data is processed or transferred to a country that does not provide an adequate level of data protection, We use the safeguards required by applicable data protection law.

    Disclosure of Your Personal Data
    Business Transactions

    If the Company is involved in a merger, acquisition, reorganisation or sale of all or part of its business, Personal Data may be transferred where necessary as part of that transaction and in accordance with applicable law.

    Where Personal Data would become subject to materially different processing as a result of such a transaction, We will provide appropriate notice where reasonably possible.

    Additional rights agreed with schools or other institutional customers, including termination or deletion rights, remain subject to the applicable agreement.

    Law Enforcement and Legal Requirements

    The Company may disclose Personal Data where required by law or in response to a valid request from a competent public authority.

    We may also disclose Personal Data where reasonably necessary to establish, exercise or defend legal claims, protect the rights or security of the Company or its Users, or investigate unlawful activity or abuse of the Service.

    Security of Your Personal Data

    We use appropriate technical and organisational measures to protect Personal Data against unauthorised access, loss, misuse, alteration or disclosure.

    These measures include encrypted transmission, access controls, restricted administrative access, system maintenance and backups.

    No Internet-connected service can guarantee absolute security.

    Your Rights under Swiss Data Protection Law

    Under Swiss data protection law, You may have the right to request information about the Personal Data We process about You, request correction or deletion of Personal Data, object to or request restriction of certain processing, and receive Personal Data in a portable format where applicable.

    You may exercise these rights by contacting Us using the contact information below. We may request information reasonably necessary to identify You or the relevant account or data.

    GDPR Privacy

    Legal Basis for Processing Personal Data under GDPR

    Where the GDPR applies and the Company acts as Data Controller, We may process Personal Data on the following legal bases:

    Where Candli is used by a school or other organisation acting as Data Controller, that organisation determines the applicable legal basis and We process Personal Data on its behalf according to its documented instructions.

    Your Rights under the GDPR

    Where the GDPR applies, You may have the right to:

    Exercising of Your GDPR Data Protection Rights

    You may exercise Your rights by contacting Us using the contact information below. We may request information reasonably necessary to verify Your identity or identify the relevant account or data.

    You also have the right to lodge a complaint with the competent data protection supervisory authority.

    California Do Not Track Disclosure

    Candli does not currently respond differently to browser “Do Not Track” signals.

    We do not use third-party advertising trackers or permit third parties to track users across unrelated websites or online services for advertising purposes.

    Children's Privacy

    Candli is an educational service that may be used by children, including children under the age of 13.

    When Candli is used through a school or other educational organisation, the organisation may provide the authorisation required for the processing of pupil data where permitted by applicable law. We process such data only for the educational purposes for which Candli is provided and as otherwise described in this Privacy Policy.

    When applicable law requires parental consent for a particular use of Candli outside such an educational context, the required consent must be obtained before the relevant Personal Data is collected or processed.

    Parents, legal representatives and schools may contact Us to request access to, correction of, or deletion of Personal Data relating to a child where applicable. We may request information reasonably necessary to identify the relevant account or data.

    We do not use children's Personal Data for advertising or advertising profiling. Newsletters or other direct marketing are sent only where the relevant user has explicitly subscribed.

    California Privacy Rights for Minors

    California users under the age of 18 may request removal of content or information they have posted through Candli where applicable under California Business and Professions Code Section 22581.

    Requests may be submitted using the contact information below. We may request information reasonably necessary to identify the relevant account or content.

    Removal does not necessarily ensure complete or comprehensive deletion, for example where the information must be retained by law or has been copied or shared by another person.

    Links to Other Websites

    Candli may contain links to websites or services that are not operated by Us. We are not responsible for the content, privacy practices or security of those third-party services.

    We encourage You to review the privacy policies of any external services You visit.

    Changes to this Privacy Policy

    We may update this Privacy Policy when Candli, Our processing activities or applicable legal requirements change.

    The current version will always be published on this page together with its “Last updated” date.

    For material changes that significantly affect how Personal Data is processed, We will provide reasonable advance notice through Candli and, where We have suitable contact information, by email or another appropriate communication channel.

    Changes that must be implemented promptly for legal or security reasons may take effect sooner.

    Additional notification rights agreed with schools or other institutional customers are governed by the applicable agreement.

    Contact Us

    If you have any questions about this Privacy Policy, You can contact us by email: .