Privacy Policy
Last updated: 2026-08-28
This page explains what data repeat.cards collects when you use the service, why we collect it, who else sees it, and what you can do about it. It covers both the website and the Android app, which share one account and one database; where the two differ, it says so. We've kept the language plain on purpose — if anything is unclear, write to us at [email protected].
What we collect
Account information
When you create an account, we store:
- Your email address (required to sign in and to send you essential emails).
- A hashed version of your password if you signed up with a password — we never store the password itself in readable form.
- If you signed up with Google Sign-In, we additionally store the first and last name that Google sends us as part of the sign-in. We use it to greet you in the app — nothing else. We don't ask you for your name in the email-and-password sign-up form.
Settings and preferences
Things you choose in your profile and settings — your timezone (used to schedule daily review reminders at a sensible local hour), your daily new-card and review limits, your preferred AI model and voice, your reminder schedule. These are stored alongside your account.
Your flashcards and learning data
Everything you create inside the app:
- Decks and the cards inside them — words, translations, example sentences, mnemonics.
- Audio files and images attached to your cards (those you uploaded or that we generated for you using AI).
- Your training history — when you reviewed each card, how you rated it, what the FSRS spaced-repetition algorithm thinks your next review should be.
- Statistics derived from the above (cards due today, daily streaks, etc.).
AI keys and AI usage
If you choose to use AI features (generating mnemonics, audio, example sentences, or images), you provide your own OpenAI or Google AI API key. We store that key in your account so the app can call the AI provider on your behalf when you click an AI button. We never share or reuse your key. If you remove it from your settings, it's deleted from our database.
Every time the app calls an AI provider for you, we write down what that call was: the date and time, which feature asked for it, which provider and model answered, how many characters were sent, how long it took, whether it succeeded, how much the provider billed and what that came to in money. It is tied to your account. We keep these per-call records for 30 days and then delete them automatically.
We do not store the text of what is sent to the AI or the text that comes back — only how long it was. The word you asked about, the sentence it wrote and the picture prompt are not kept in these records.
What the AI produces is shared. A pronunciation of a word is the same recording for everybody, so when a provider makes one we keep it — the word it was made from, the language, the voice, and the audio itself — and serve it to the next person who asks for that word instead of paying to have it made again. That means the text you submit for generation, and what comes back from it, are stored in a library shared with other accounts. These entries are not deleted when an account is closed: they carry no name and no address, and other people's cards are already playing them. A recording you upload yourself is never part of this — it stays yours and is never offered to anybody else.
Pictures are shared by their meaning, not by the word. A drawing of an apple illustrates the same thing whether your card says apple, maçã or яблоко, so a picture made for one of those is offered for all of them. To do that we work out what a word means and keep that too — the word you typed, its language, and a short description of the meaning in English. A picture is filed under the meaning rather than under anything you wrote, and, like the recordings, neither the picture nor the record of what the word means is deleted when an account is closed. A picture you upload yourself is never part of this either.
We also keep a daily total: for each day, feature and model, how many calls were made and what they cost. It holds no text and nothing about which words you were learning. Unlike the per-call records, these totals are kept indefinitely — they are how we know what the service costs to run and how to price it. They are covered again under How long we keep it below.
Email verification and reminders
When you register, we send a verification email. If you opt in to daily review reminders, we send a single email per day at the time you choose. Both go through a transactional email provider.
Usage analytics we keep ourselves
Our own servers record how the service is used, tied to your account. For each day you use repeat.cards we store which API endpoints your client called and how many times, the date you were last active, and which client you used — website or Android app, and its version. We also record which of those you signed up from. We use this to see which features are used, to find errors, and to size the service; we do not use it to build a profile of you or share it with anyone. It is deleted after 180 days.
Google Analytics
The website also uses Google Analytics to understand which pages people visit and where the site is slow. It sets cookies and may collect your IP address (anonymized), browser, device type, country-level location, and the pages you visit. We do not use this for ad targeting. The Android app does not load Google Analytics at all — the first-party record above is the only usage data it produces.
Cookies and session tokens
We use the following types of cookies and stored tokens:
- Authentication tokens. When you sign in, we store an access token and a refresh token in your browser so you don't have to log in on every page. These are essential for the service.
- A session hint. A cookie named
rc_sessionwhose only value is1, set when you sign in and removed when you sign out. It carries no name, no address and no credential — it exists so our server knows whether to send you the marketing page or your dashboard before the page is drawn, and nothing is authorised by it. - Analytics cookies. Set by Google Analytics on the website, see above.
We do not use advertising cookies, third-party tracking pixels, or social sharing widgets that track you across sites.
Why we collect it
We use your data only to:
- Provide the flashcard service — store your decks, schedule your reviews, train you.
- Generate AI content when you request it (using your own API key).
- Send essential transactional emails (verification, password reset, opt-in reminders).
- Understand and improve the product (anonymized usage analytics).
- Detect abuse and keep the service available for everyone.
We do not sell your data to anyone. We do not use your flashcard content to train any AI model. We do not share your account information with advertisers.
Who else sees your data
We use a small number of third-party services to run repeat.cards. The following providers may process some of your data on our behalf:
- OpenAI and Google AI — when you click an AI button, the relevant card text is sent to whichever provider matches the API key you set. The call is billed to your key. These providers have their own privacy policies.
- Google Cloud Text-to-Speech — when you generate audio for a card, we send the text to Google Cloud TTS to synthesize the audio file, which we then store in your deck.
- Google Analytics — usage data, as described above.
- Email provider — to send transactional emails (verification, reminders, password resets).
- Hosting provider — our servers and database run on a hosting platform that processes data on our behalf.
We may also disclose data if required by law (court order, legal subpoena, regulatory request). If that happens, we'll push back on overbroad requests where we can.
Where your data lives
Your account, decks, cards, and training history live in a PostgreSQL database. Audio and image files — the ones you upload and the ones AI generates for you — are stored as files on the same server, beside the database, not with a third-party storage provider. Backups are encrypted at rest.
When you use AI features, your card text travels to OpenAI or Google AI servers. The AI provider's own privacy policy and data-processing terms apply to that flow.
How long we keep it
- Account and learning data — for as long as your account exists. Once you ask us to close it, we delete everything within 30 days, apart from the daily AI cost totals described below and anything the law requires us to retain.
- Email logs — up to 90 days for delivery troubleshooting.
- Our own usage records — 180 days, after which they are deleted automatically.
- Per-call AI records — 30 days, after which they are deleted automatically.
- Daily AI cost totals — kept indefinitely. When an account is closed we remove the link to it, and the figures stay behind under an account number that no longer identifies anybody. They are counts and amounts of money: no address, no name, no cards, no text. We keep them because they are the only record of what running the service costs, and deleting them would leave us unable to answer that for any period at all.
- Shared AI library entries — kept indefinitely. The text submitted for generation, the recordings and pictures produced from it, and what we worked out each word means, stay in a store shared with other accounts, and closing an account does not remove them: they carry no name and no address, and other people's cards point at the same files.
- Google Analytics data — retained per Google Analytics defaults (currently 14 months).
- Backups — rolled over on a 30-day cycle.
Your rights
If you live in the EU, EEA, UK, or another GDPR-aligned jurisdiction, you have:
- The right to access — ask us what data we hold about you.
- The right to correction — fix anything that's wrong. Most fields you can correct yourself in your profile.
- The right to deletion — have your account and the data associated with it removed. Email us to ask; there is no button for it inside the app yet. Two things are exceptions. The daily AI cost totals: we keep them, and because we remove the link to your account first, what is left is a number of calls and an amount of money that no longer identifies you. And the shared AI library: a recording or a picture made for one of your words, and what we worked out that word means, are kept and go on serving other people's cards, under no name and no account.
- The right to data portability — get your data in a machine-readable format.
- The right to object — opt out of any processing based on our legitimate interests (analytics, for example).
- The right to withdraw consent — for anything we do based on consent (e.g. opt-in email reminders).
- The right to lodge a complaint — with your local data protection authority.
To exercise any of these rights, email [email protected] from the address associated with your account. We'll respond within 30 days.
Children
repeat.cards is not directed at children under 16. If you're under 16, please don't create an account without your parent or guardian's permission. If we learn we have collected data from a child without proper consent, we'll delete it.
Changes to this policy
If we change this policy in a material way, we'll update the “Last updated” date at the top and describe the change on this page. We do not currently have a way to email every registered user, so this page is where to look; if we build one, we will say so here. Smaller editorial changes (typos, clarifications) go in without notice.
Questions
Email [email protected]. We read every message.
