Privacy Policy

Update: June 6, 2025

1. Data Collection

We collect: Email, card content, FSRS progress parameters, uploaded media, and technical logs (IP, device info).

Processing ActivityLegal Basis (GDPR)
Providing Sync & Premium FeaturesContract Performance (Art. 6(1)(b))
Security & Anti-abuseLegitimate Interest (Art. 6(1)(f))
MCP/AI Integrations (Optional)Consent (Art. 6(1)(a))
Tax & Financial RecordsLegal Obligation (Art. 6(1)(c))

3. Sub-processors

We use: Cloudflare (Infrastructure), Stripe/Paddle/Apple/Google (Payments), OpenAI/Anthropic (Optional AI).

4. Cookies & Trackers

We use essential security cookies (e.g., Cloudflare __cf_bm). We do not use marketing trackers.

5. Automated Decision-Making

The FSRS algorithm uses your review history to schedule card intervals. This does not produce legal or similarly significant effects under GDPR Art. 22.

6. Data Retention

  • Account Deletion: Personal data (cards, media, records, backups) is deleted from production servers immediately upon account termination.
  • Financial Records: We retain transaction and tax records as required by law for accounting and audit purposes.

7. User Rights (GDPR/CCPA)

You have the right to access, correct, delete, and export your data (JSON/CSV).

  • Complaint Right: You have the right to lodge a complaint with your local Data Protection Authority.
  • Identity Verification: We verify requests via your registered email.

8. Children

The Service is not intended for users under 13 (or 16 in the EU).

9. Contact

For privacy inquiries or to exercise your data rights, contact us:

MiniCards Studio Beihai, Guangxi, China support@minicards.app