Privacy Policy

Thank you for choosing AI Flashcards: Study & Learn (also called Flashcards) (the "App"). This Privacy Policy describes how ULADZISLAU ZINCHANKA ("We," "Us," or "Our"), an individual entrepreneur based in Poland, collects, uses, and discloses information when You use the App. By using the App, You agree to this Privacy Policy. Our Terms of Use also apply.

Privacy at a glance. Your custom decks, cards, card images, and study progress stay on Your Device unless You use an AI generation feature. AI generation sends only the text needed to create cards (topic, preferences, extracted source text, or a YouTube transcript) to Our Firebase Cloud Functions, which call OpenAI. Photos used for AI are OCR’d on-device — We do not upload those photos for AI. We also use Mixpanel (product analytics), RevenueCat + Apple (purchases), Firebase (Auth, Functions, Storage, quota, Crashlytics, Remote Config), and optional local study reminders. We do not use advertising SDKs or Apple’s App Tracking Transparency prompt. The App does not use the microphone for recording.

1. Definitions

2. Collecting & Using Your Data

2.1 Camera and Photo Library

The App may request camera and photo-library access to:

You may also pick documents (e.g. PDF/DOCX) for on-device text extraction; again, extracted text — not the full binary file as a general rule for AI — is what We send for generation when You use that feature.

The App does not provide a microphone recording feature and does not collect microphone audio.

2.2 Types of Data Collected

2.2.1 Study Content (local)

Stored on Your Device and not uploaded as part of normal study use:

If device backups (e.g. iCloud Backup) are enabled, local App data may be included in those backups as managed by Apple/Google — We have no access. Uninstalling removes local Study Content from the Device.

2.2.2 Data You Provide Voluntarily

If You email dev.ohmyapp@gmail.com, We receive Your email address and message content to respond. No account registration is required to use the App.

2.2.3 Anonymous Account Identifier (Firebase Auth)

The App signs You in anonymously with Firebase Authentication to obtain a stable pseudonymous user ID (UID). This UID is used to enforce AI generation quotas and authorize Cloud Function calls. It is not Your name or email, and there is no password login UI.

2.2.4 Subscription and Purchase Data

Via RevenueCat and Apple, We process:

We do not collect payment-card numbers. Apple processes payments under Apple’s policies.

2.2.5 AI Generation Data (leaves Your Device when You use AI)

When You generate cards with AI, We send to Firebase Cloud Functions (and onward to OpenAI) only what is needed for that request, which may include:

Generated cards are returned to Your Device and stored locally. We use Your anonymous Firebase UID to apply rate limits / quotas (stored in Firebase, e.g. Firestore). We do not use Your Study Content to train Our own models. OpenAI processes prompts under its policies and retention practices for API abuse monitoring — see OpenAI’s privacy policy.

2.2.6 Pseudonymous Usage Data (Mixpanel)

The App sends product-analytics events to Mixpanel (e.g. opens, onboarding, study/deck actions, AI/paywall funnels, reminder permission). Events use a Mixpanel distinct ID and may include technical metadata (app version, device model, OS, locale). Mixpanel may process IP address and derive approximate location (e.g. country/region). Usage Data does not include full card fronts/backs or photo binaries.

2.2.7 Remote Configuration (Firebase Remote Config)

The App fetches feature flags and limits (e.g. free deck/card/AI caps, YouTube/source features, paywall behavior). Firebase may receive an installation ID, app version, and locale / storefront region. Remote Config does not receive Your card text or images.

2.2.8 Crash Reports (Firebase Crashlytics)

If the App crashes or errors, Crashlytics may receive stack traces, device/app metadata, and related diagnostic information to help Us fix bugs.

2.2.9 Predefined Library (Firebase Storage / Firestore)

Downloading predefined decks may involve fetching public deck content and images from Firebase Storage. Which library decks You access may be reflected in network requests to Firebase. Your study progress on those decks remains local.

2.2.10 Local Study Reminders (optional)

With permission, the App may schedule local daily study reminders on Your Device. Reminder text may include a count of cards due. We do not register a remote push token with Our servers for marketing campaigns. You can disable reminders in the App and/or system Settings.

2.3 Use of Your Data

2.4 Data We Do Not Collect

3. Disclosure of Your Data

Your local Study Content is not sold. AI prompts You submit are disclosed to Firebase/Google and OpenAI solely to provide generation.

4. Third-Party Services

ProviderPurposeData SentPrivacy Policy
Google LLC — Firebase (Auth, Functions, Firestore, Storage, Crashlytics, Remote Config) Anonymous auth, AI proxy + quotas, predefined decks, crashes, feature flags Anonymous UID; AI request payloads; quota records; crash diagnostics; config identifiers; library downloads firebase.google.com/support/privacy
OpenAI (via Firebase Functions) AI flashcard generation Topic / transcript / extracted text and generation parameters openai.com/policies/privacy-policy
Mixpanel, Inc. Product analytics Distinct ID; events; technical metadata; IP (approx. geo possible) mixpanel.com/legal/privacy-policy
RevenueCat, Inc. Subscriptions / entitlements Anonymous RC user ID; purchase / subscription metadata revenuecat.com/privacy
Apple Inc. App Store, StoreKit, local notifications Payment / purchase data (Apple); on-device notification scheduling apple.com/legal/privacy
YouTube (Google) — when You use YouTube → cards Caption / transcript fetch initiated from Your Device Requests to YouTube to retrieve captions for the URL You provide (subject to Google/YouTube terms) policies.google.com/privacy

5. Data Retention

Email Us to request deletion of analytics or Firebase identifiers We can reasonably locate and delete via providers.

6. International Transfers

Providers may process data in the United States and elsewhere. For EEA/UK transfers We rely on SCCs, adequacy decisions, and/or provider transfer mechanisms.

6.1 Controller (GDPR)

ULADZISLAU ZINCHANKA
Email: dev.ohmyapp@gmail.com

Supervisory authority in Poland: UODO. You may complain to your local authority (edpb.europa.eu).

6.2 Legal Bases (GDPR)

7. Your Rights

Depending on location, You may have rights of access, deletion, correction, restriction, portability, objection, and withdrawal of consent. California and other U.S. state rights are in Sections 12–13. Contact dev.ohmyapp@gmail.com. Clear local data by deleting decks or uninstalling.

7.1 GDPR

We respond within one month where required (extendable as permitted). We may verify Your request. You may lodge a complaint with a supervisory authority.

8. Security

We use HTTPS/TLS to Service Providers and rely on platform security for on-device storage. No method is 100% secure.

8.1 Breaches

Where required, We will notify authorities (e.g. UODO) and affected users. Report issues to dev.ohmyapp@gmail.com.

9. Children

The App may be rated for younger users under store rules, but AI features and analytics mean parental supervision is recommended. We do not knowingly collect names or emails from children under 13 (COPPA) / under the digital-consent age in the EU. Pseudonymous analytics, anonymous Auth, and purchase processing may still occur on installs. Purchases must be made by someone 18+ (or a parent via their Apple Account). Parents may email Us to request deletion of identifiers associated with a child’s use.

10. External Links

Third-party sites and policies are outside Our control.

11. Changes

We may update this Privacy Policy by posting a new version at this URL. Continued use after changes constitutes acceptance where permitted by law.

12. California (CCPA / CPRA)

Categories collected in the last 12 months may include: identifiers (Mixpanel ID, RevenueCat ID, Firebase UID / installation ID, IP); purchase information; internet/app activity (analytics events); and limited AI prompt content You submit. Sources: Your Device/use; Apple; providers in §4. Purposes: §2.3.

We disclose personal information to Service Providers for business purposes. We do not sell personal information for money and do not engage in cross-context behavioral advertising. Sharing Usage Data with Mixpanel for product analytics may be considered a “sale” under broad CCPA definitions. Opt out by emailing dev.ohmyapp@gmail.com with subject “CCPA Opt-Out.” We do not knowingly sell/share personal information of consumers under 16 for advertising. Exercise know/delete/correct rights via the same email; We aim to respond within 45 days.

13. Other U.S. States

Residents of Virginia, Connecticut, Colorado, Utah, Nevada, and similar states may have access, delete, correct, port, and opt-out rights. Contact dev.ohmyapp@gmail.com.

14. Contact

ULADZISLAU ZINCHANKA
Email: dev.ohmyapp@gmail.com