Privacy Policy
Last updated: May 2026
1. Who We Are
Cards ("we", "us", "our") is a mobile flashcard learning application. If you have questions about this policy, contact us at legal@cards.app.
2. What Data We Collect
Account data. When you create an account we collect your email address, display name, and language preference.
Study data. We sync your study sessions, FSRS scheduling state, and deck progress to our backend so your learning is available across all your devices.
Device data. When you opt in to push notifications, we store your FCM (Android) or APNs (iOS) push token, device platform, and locale.
Telemetry. We use Sentry for crash and error reporting. Sentry reports are anonymised — they contain stack traces and device context but no personally identifiable information unless you voluntarily include it in a bug report. We also collect anonymised analytics events (screen views, study actions) to understand how the app is used.
Subscription state. Your subscription status (free / Pro) is managed by RevenueCat. Apple or Google process all payment transactions; we never see your card number or billing details.
3. Why We Collect It
| Purpose | Data used | |---|---| | Sync your study progress across devices | Account data, study data | | Error monitoring and app stability | Telemetry (Sentry) | | Product improvement | Anonymised analytics events | | Billing and subscription management | Subscription state (RevenueCat) | | Push notifications (opt-in only) | Device push tokens |
4. Third Parties
We share data with the following sub-processors:
- Apple App Store / Google Play — payment processing for subscriptions and in-app purchases.
- RevenueCat — subscription state management. RevenueCat receives your store receipt; we receive only the subscription tier.
- Sentry — error monitoring. Data is processed under Sentry's DPA.
- Apple Sign In / Google Sign In — if you choose to authenticate with these providers, they share your email address and display name with us. We do not receive your password.
- FCM (Firebase Cloud Messaging) / APNs (Apple Push Notification service) — delivery of opt-in push notifications.
We do not sell your personal data to third parties.
5. Data Retention
We retain your data for as long as your account exists. When you delete your account, your personal data is queued for hard deletion within 30 days. Anonymised, aggregated analytics data may be retained indefinitely.
6. Your Rights
Depending on your jurisdiction you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your account and associated data (use the in-app "Delete account" option in Settings, or email legal@cards.app).
- Export a copy of your study data (available in-app).
- Object to processing or withdraw consent.
To exercise any of these rights, contact legal@cards.app.
7. Children
Cards is not intended for children under 13 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact legal@cards.app and we will delete it promptly.
8. International Transfers
Your data is stored on servers located in Frankfurt, Germany (EU) operated by Fly.io. Some of our sub-processors (including Sentry and RevenueCat) are based in the United States. Where data is transferred outside the EU/EEA, we rely on appropriate safeguards (Standard Contractual Clauses or adequacy decisions) as required by applicable data protection law.
9. Changes to This Policy
If we make a material change to this policy, we will notify you via an in-app banner and, where required, by email at least 14 days before the change takes effect.
10. Contact
Questions or complaints: legal@cards.app
To delete your account, visit /delete-account.