Privacy Policy
Draft — pending legal review. Not yet in force.
This Privacy Policy explains how [CEIDG_LEGAL_NAME] (“we”, “us”) processes personal data when you use the flshcrds mobile app and the public website at flshcrds.app (together, the “Service”). It does not cover our internal admin tools or non-public web surfaces.
1. Data controller
The data controller is [CEIDG_LEGAL_NAME], with its business address at [CEIDG_ADDRESS], NIP [CEIDG_NIP].
Privacy contact: hello@flshcrds.app.
2. Scope
This Policy applies to the flshcrds iOS/Android app and the marketing site flshcrds.app, including this Privacy Policy and Terms pages.
It does not apply to third-party websites, app stores, operating systems, or services we link to (Apple, Google, Facebook, Instagram, RevenueCat, and similar act under their own policies when they process data as independent controllers). A link is not an endorsement.
If we maintain a presence on a social platform, anything you post there is subject to that platform’s terms. We cannot control other users or the platform itself.
3. Age requirement
The Service is a general-audience learning product. It is not directed at children.
You must be at least 16 years old to create an account or use the Service. If we learn that we hold an account for someone under 16, we will delete it.
4. Data we process
Account and identity: email address and authentication identifiers from sign-in (Google and/or Facebook OAuth via our auth provider), and profile fields you set (such as a display name).
Learning library: decks, notes, cards, note types, scheduling state, and review history you create or import — including content you type or import (CSV, Anki packages, or shared decks).
Device and sync: app preferences stored on device; sync of your library to our servers so the Service works; your IANA timezone and a push token when you allow notifications, used for the app-icon badge (today’s study queue), not marketing spam.
Purchases: subscription / in-app purchase status via the app stores and RevenueCat (entitlements). We do not receive your full payment card number.
Support and correspondence: if you email hello@flshcrds.app or otherwise contact us, we process the address you use and the content of that exchange (including screenshots or logs you attach).
Information from other sources: when you choose to sign in with Google or Facebook, those providers send us authentication identifiers and typically your email because you asked them to. We do not receive your password for those accounts.
Diagnostics: if we enable a crash-reporting tool, technical logs about crashes and stability (device/app version, stack traces). We will name the vendor in this Policy before that feature goes live.
Website: the public site is a marketing page. We do not run product analytics, advertising pixels, or a non-essential cookie banner on the landing site in this cut. Essential hosting/security logs may still exist at the infrastructure level (for example IP address, time, and requested URL).
5. Purposes and legal bases (GDPR)
Provide the Service (account, sync, study, import/export, badge): performance of a contract (Art. 6(1)(b) GDPR).
Purchases and entitlements: contract and, where needed, legitimate interests in preventing fraud / restoring purchases (Art. 6(1)(b) and (f)).
Communicate with you about the Service (replies to your requests, security or availability notices, and material product or Policy changes): contract (Art. 6(1)(b)) and/or legitimate interests in administering the Service (Art. 6(1)(f)). We do not send unsolicited marketing.
Security, abuse prevention, and crash diagnostics: legitimate interests in running a stable, secure Service (Art. 6(1)(f)), balanced against your rights.
Legal obligations (e.g. accounting related to paid features, responding to valid requests from public authorities): Art. 6(1)(c).
Aggregated or anonymized statistics that no longer identify you, to operate and improve the Service: legitimate interests (Art. 6(1)(f)). We do not use advertising pixels, interest-based ads, or audience-segmentation tools in this cut.
Where consent is required (for example certain optional notifications or a future non-essential SDK), we will ask before enabling it (Art. 6(1)(a)). You may withdraw consent at any time; withdrawal does not affect processing that was lawful before you withdrew.
7. Recipients and processors
We do not sell your personal data. We use service providers who process data on our instructions or as described in their roles:
Supabase — authentication and database hosting for accounts and your learning library.
Google and Facebook — sign-in (OAuth). They process data under their own terms when you use their login.
Apple and Google Play — app distribution and in-app purchases.
RevenueCat — subscription / entitlement management for in-app purchases.
Expo and Apple/Google push infrastructure — delivery of the app-icon badge related push token.
Crash diagnostics vendor — to be named before go-live of that feature.
Besides those providers, we may disclose data: (a) to a competent public authority, court, or similar body when we believe disclosure is required by law, needed to establish or defend legal claims, or to protect vital interests; (b) to a buyer and its advisors in a sale, merger, or similar transaction — the acquirer must honour this Policy, or we will notify you of the change; (c) to any other person with your consent.
Where a provider processes personal data for us, we take contractual and organisational steps consistent with applicable law, including a data-processing agreement where required.
Some providers may process data outside the EEA. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) offered by those providers.
8. Retention
We do not keep personal data longer than needed for the purposes it was collected. How long depends on whether we have a legal or contractual need, whether the data is required to provide the Service, and that you would reasonably expect library data to remain until you delete it or close the account.
We keep your account and library while your account is active.
When you delete your account in the app, we delete your account and Service data from production systems without undue delay. Backup copies may remain for up to 30 days, securely isolated from further use, then are removed or overwritten in the normal backup cycle.
App stores and RevenueCat may retain purchase records under their own rules. Copies of content other users imported via Deck Share remain in those users’ accounts.
9. Your rights
Under the GDPR you may have the right to: access (know which personal data we process); rectify inaccurate data; erase data (the “right to be forgotten”); restrict processing; object to processing based on legitimate interests; receive your data in a structured, commonly used, machine-readable format (portability); and withdraw consent where processing is based on consent.
You can delete your account in the mobile app (Settings). For other requests, email hello@flshcrds.app. We may ask you to verify your identity so we can respond lawfully and efficiently.
These rights are subject to exceptions and limits in the law — for example we may retain data we are legally required to keep, or refuse a request that would adversely affect others’ rights.
You may lodge a complaint with your local supervisory authority. In Poland this is the President of the Personal Data Protection Office (UODO). Contact details for EU/EEA authorities are published by the European Data Protection Board.
10. Security
We use technical and organisational measures appropriate to a small consumer learning app (access controls, encrypted transport, provider security features). No method of transmission or storage is perfectly secure.
You must keep your sign-in credentials secure and not share them. We do not receive or store your Google or Facebook password.
11. Changes
We may update this Policy. The version published at https://flshcrds.app/en/privacy is the current one. For material changes we will take reasonable steps to notify you (for example in-app or by email) when required.
12. Governing law
This Policy is designed for the GDPR and Polish data-protection law. The controller is established in Poland.
13. Contact
[CEIDG_LEGAL_NAME], [CEIDG_ADDRESS], NIP [CEIDG_NIP].
Email: hello@flshcrds.app.