Privacy Policy
Your privacy matters. Here's how we protect and handle your data with complete transparency.
GDPR Compliant
End-to-End Encrypted
User Control
Last Updated: January 2025
Effective immediately for all users
Information We Collect
Account Information
- Name and email address (via Google OAuth)
- Profile picture (optional)
- Account preferences and settings
Content You Upload
- PDF documents for flashcard generation
- Generated flashcard content
- Study progress and statistics
Automatically Collected Data
- Usage analytics and app performance metrics
- Device information and browser type
- IP address and approximate location
How We Use Your Data
Core Services
- Generate AI-powered flashcards from your PDFs
- Save and organize your flashcard collections
- Track your study progress and performance
Product Improvement
- Analyze usage patterns to enhance our AI models
- Improve app performance and user experience
- Debug technical issues and optimize processing
Communication
- Send important account and service updates
- Provide customer support when requested
- Share product announcements (with your consent)
Data Sharing & Third Parties
We DO NOT sell your personal data
- Your content and personal information are never sold to third parties
- We only share data in the limited circumstances described below
Service Providers
- Google OAuth for secure authentication
- MongoDB Atlas for secure data storage
- Vercel for hosting and content delivery
- OpenAI for AI-powered flashcard generation
Legal Requirements
- When required by law or legal process
- To protect our rights and prevent fraud
- In case of business transfers (with notice)
Data Security & Protection
Security Measures
- End-to-end encryption for data transmission
- Secure authentication via Google OAuth 2.0
- Regular security audits and monitoring
- Automated backups with encryption at rest
Access Controls
- Role-based access to your personal data
- Multi-factor authentication for admin access
- Regular access reviews and permission updates
Data Retention
- Account data retained while your account is active
- Processing jobs automatically deleted after 24 hours
- Inactive accounts may be deleted after 2 years
Your Privacy Rights
Access & Control
- Download your data in portable formats
- Update your account information anytime
- Delete your account and associated data
Privacy Choices
- Opt out of non-essential communications
- Manage cookie preferences
- Control data processing for marketing purposes
Geographic Rights
- GDPR rights for EU residents
- CCPA rights for California residents
- Right to data portability and erasure
Questions About Your Privacy?
We're here to help. Contact our privacy team for any questions about how we handle your data.
Contact Privacy Team