Privacy Policy
Last updated: July 28, 2026
This Privacy Policy explains how studycards.io collects, processes and protects personal data when you use our website and services. We operate globally and follow the requirements of the European General Data Protection Regulation (GDPR).
By using studycards.io you agree to the practices described in this Privacy Policy.
1. Data Controller
The responsible entity for the processing of personal data within the meaning of Article 4 paragraph 7 GDPR is:
Enes Kayali
Sole proprietor, trading as Kayali Digital Solutions
Friedrich-Heene-Straße 7
67061 Ludwigshafen am Rhein, Germany
Email: studycardsio@outlook.de
2. Personal Data We Collect
2.1 Account and Login Information
When you create an account or sign in using a third-party authentication provider, the following data may be transmitted to us:
- Email address
- Name or display name
- Profile picture (if available)
- Provider-specific identifier
- Authentication metadata (such as creation date)
We do not receive or store passwords from any authentication provider.
Currently supported authentication provider:
- Google (via Supabase Auth)
Additional providers may be added in the future. This policy will be updated accordingly.
2.2 Technical and Usage Data
When you access our service, we automatically collect:
- IP address
- Browser type and version
- Device information
- Time and date of access
- Pages visited and interactions
- Referring and exit URLs
This information is required to maintain the functionality, stability and security of the service. Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
2.3 User-Generated Content
To provide our flashcard creation features we store:
- Flashcard set titles and descriptions
- Flashcard content (questions and answers)
- Images uploaded to flashcards
This content is private and only visible to you unless you choose to share a deck. Sharing creates a public link of the form /d/<token> that anyone holding the link can open without logging in, together with a preview image generated for social networks. Sharing is off until you turn it on for a deck, and revoking the link removes public access again.
2.4 Card Images
Images you attach to a flashcard are stored in Supabase Storage in the EU region and count towards the storage allowance of your plan. They are kept for the duration of your account and deleted when you remove them or delete your account.
PDF and PowerPoint files are not uploaded. When you use them to build cards, they are read in your browser to extract text for a prompt you take to your own AI; the file itself never reaches our servers.
2.5 Payment Data
When you subscribe to a paid plan, the following data is processed by our payment provider Stripe:
- Name and email address
- Payment method details (credit card, SEPA, etc.)
- Billing address
- Transaction history and subscription status
We do not store full payment card numbers on our servers. Payment data is processed exclusively by Stripe, Inc. (USA) under PCI-DSS Level 1 certification. We only store your Stripe customer ID and subscription status in our database. For details see Stripe's Privacy Policy.
2.6 Cookies
We use strictly necessary cookies to maintain sessions and provide secure login. These cookies do not require consent under Art. 5(3) of the ePrivacy Directive as they are essential for the service to function. We do not use advertising or tracking cookies.
3. How We Use Your Data
We process personal data only for the following purposes:
- To create and manage user accounts
- To authenticate users via third-party providers
- To store and synchronise flashcard sets
- To store and manage files you upload
- To process payments and manage subscriptions
- To enable PDF export of flashcards
- To send transactional emails (e.g. feedback confirmations)
- To detect and prevent abuse (bot protection)
- To monitor errors and maintain service stability
- To operate, improve and secure our service
- To fulfil legal obligations
We never sell personal data.
4. Legal Basis for Processing
Under the GDPR we rely on:
- Art. 6(1)(b) GDPR — Performance of a contract: Account creation, flashcard storage, file storage, payment processing, PDF export
- Art. 6(1)(f) GDPR — Legitimate interest: Error tracking, server logging, bot protection, security measures, service stability, cookie-free audience measurement (Section 6)
- Art. 6(1)(a) GDPR — Consent: Optional features that require consent (if implemented in the future)
5. Third-Party Service Providers (Data Processors)
We use the following third-party providers to operate our service. Where required, data processing agreements (Art. 28 GDPR) are in place.
Supabase, Inc. (USA)
Database storage, user authentication, file storage. Processes: account data, flashcard content, uploaded images. Data location: EU (Frankfurt) or US depending on project configuration.
Cloudflare, Inc. (USA)
Website hosting (Cloudflare Pages), CDN, DDoS protection, DNS, and Cloudflare Turnstile for bot protection on forms. Processes: IP addresses, request metadata, Turnstile interaction data.
Stripe, Inc. (USA)
Payment processing and subscription management. Processes: name, email, payment method, billing address, transaction data. Stripe is PCI-DSS Level 1 certified. See Stripe's Privacy Policy.
Resend (Plus Five Five, Inc., USA)
Transactional email delivery (e.g. welcome and feedback confirmation emails). Processes: recipient email address, email content. Transfers are safeguarded by the EU Standard Contractual Clauses (SCCs).
Functional Software, Inc. — Sentry (USA)
Client-side error tracking and performance monitoring. Processes: IP address (anonymised), browser information, error stack traces, page URLs. No personal content data is intentionally transmitted.
Better Stack, Inc. (BetterStack / Logtail)
Server-side structured logging and monitoring. Processes: server log entries which may contain IP addresses, request paths and error messages.
Plausible Insights OÜ (Estonia, EU)
Privacy-friendly, cookieless website analytics. Aggregated usage statistics only — no cookies, no cross-site tracking and no personal or content data. Processes: anonymised, aggregated page-view and event counts. Only active once configured in production.
Google Ireland Limited (Ireland/USA)
OAuth authentication provider. When you sign in with Google, Google transmits your profile data (name, email, profile picture) to us via Supabase Auth. See Google's Privacy Policy.
6. Audience Measurement (first-party, cookie-free)
We collect our own aggregated usage statistics. The counter itself sets no cookie and stores nothing on your device. We record the number of page views and an estimate of the number of visitors per day. This counter runs on our own infrastructure; the data is not passed to an analytics provider.
The application does use your browser's local storage and a small number of functional cookies, and we would rather name them than claim otherwise: your login session (Supabase Auth), your language choice, a flag recording that you have seen the welcome screen, and flags that stop the same milestone being counted twice. If you arrive through a campaign link, the campaign parameters from that first visit are also kept locally so a later signup can be attributed to it; they are not shared with third parties and are not used to build a profile. All of these are strictly functional or first-party measurement, which is why there is no consent banner — there are no advertising or cross-site tracking cookies to consent to.
To estimate visitor numbers we derive a truncated checksum from your IP address, your browser identification (user agent) and a secret value that changes every day. Your IP address is processed in memory only and is never stored or logged. The checksum serves solely to avoid counting the same visit twice within a single day. Your IP address cannot be recovered from it, and we do not use it to identify anyone. After no more than 48 hours the checksum is deleted. From that point it can no longer be determined whether a particular visit came from you. Only aggregate daily totals without any personal reference are retained.
There is no cross-site recognition, no profiling, no merging with your account or contract data and no transfer to third parties. The legal basis is our legitimate interest in the needs-based design and audience measurement of our website pursuant to Art. 6(1)(f) GDPR.
Your right to object (Art. 21 GDPR): If your browser sends the "Global Privacy Control" (Sec-GPC) or "Do Not Track" (DNT) signal, no checksum is derived; your visit then only contributes to the anonymous total. You may also object at any time by contacting us at studycardsio@outlook.de.
7. Bot Protection (Cloudflare Turnstile)
We use Cloudflare Turnstile to protect certain forms from automated abuse. Turnstile is a privacy-preserving alternative to traditional CAPTCHAs. It may process:
- IP address
- Browser and device characteristics
- Interaction patterns on the page
No personal tracking cookies are set by Turnstile. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing abuse and protecting the service).
8. International Data Transfers
Several of our service providers are based in the United States (Stripe, Cloudflare, Sentry, BetterStack). When personal data is transferred outside the European Economic Area, we ensure appropriate safeguards are in place:
- EU-US Data Privacy Framework (where the provider is certified under the DPF)
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions by the European Commission
- Additional technical and organisational measures
Where possible, we use EU-based endpoints and regions (e.g. Supabase EU regions, Cloudflare's EU network).
9. Data Retention
We retain personal data only as long as necessary for the purposes described in this policy:
- Account data: Stored for the duration of your account. Deleted upon account deletion request, subject to legal retention obligations
- Flashcard content: Stored for the duration of your account. Deleted when you delete sets or your account
- Uploaded files: Stored for the duration of your account. Deleted when you remove them or delete your account
- Payment data: Transaction records are retained for the legally required period (up to 10 years under German commercial and tax law, §§ 147 AO, 257 HGB)
- Server logs: Retained for up to 90 days for security and debugging purposes, then automatically deleted
- Error tracking data (Sentry): Automatically deleted after 90 days
- Audience measurement (Section 6): The daily checksum used to avoid double-counting a visit is deleted after no more than 48 hours. Only aggregate daily totals without any personal reference are kept
10. Your Rights under the GDPR
You have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR) — obtain information about your stored data
- Right to rectification (Art. 16 GDPR) — correct inaccurate data
- Right to erasure (Art. 17 GDPR) — request deletion of your data
- Right to restriction (Art. 18 GDPR) — restrict processing in certain cases
- Right to data portability (Art. 20 GDPR) — receive your data in a structured, machine-readable format
- Right to object (Art. 21 GDPR) — object to processing based on legitimate interest
- Right to withdraw consent (Art. 7(3) GDPR) — withdraw consent at any time without affecting the lawfulness of prior processing
- Right to lodge a complaint — with a supervisory authority, in particular in the Member State of your habitual residence. The competent authority for us is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz (www.datenschutz.rlp.de)
To exercise your rights please contact us at studycardsio@outlook.de. We will respond within one month of receiving your request.
11. Security Measures
We apply appropriate technical and organisational measures to protect personal data including:
- TLS encryption for all data in transit
- Encryption at rest for database and file storage
- Row-Level Security (RLS) policies on all database tables
- JWT-based authentication with secure token handling
- Input validation and sanitisation (Zod schemas, XSS protection)
- Continuous error monitoring and structured logging
Although no online service can guarantee complete security, we continuously improve our processes.
12. Accounts Created through Third-Party Providers
When you use Google (or another third-party provider) to sign in:
- The provider remains responsible for the authentication process
- We only store basic profile information required to operate the service
- You may manage or revoke access permissions directly within the provider account (e.g. Google Account Permissions)
- Deleting your studycards.io account does not delete your provider account
13. Children's Privacy
The service is not intended for children under the age of sixteen. We do not knowingly collect personal data from users under this age. If we become aware of such processing, we will promptly delete the data and the associated account.
14. Changes to this Policy
We may update this Privacy Policy periodically. The latest version is always available on this page with the updated date shown at the top. Significant changes will be announced through the website. We recommend reviewing this page regularly.
15. Contact
For questions or privacy-related requests please contact:
Email: studycardsio@outlook.de
Enes Kayali
Sole proprietor, trading as Kayali Digital Solutions
Friedrich-Heene-Straße 7
67061 Ludwigshafen am Rhein, Germany