Reflashcard

Privacy Policy

Last updated 2026-09-06

Reflashcard is a reading and vocabulary app. This policy explains what leaves your device, who processes it, on what legal basis, how long it is kept, and how to get it back or erase it.

The short version

  • Your PDF files never leave your device. They are opened, parsed and stored locally; only a word or passage you select, plus the sentence around it, is sent to our servers.
  • We store your account, the flashcards you make, and your study history — that is what makes review scheduling work across devices.
  • AI features send that text to AI providers outside your country, including DeepSeek in the People's Republic of China. Read the AI section before you use them; it is the part of this policy that matters most.
  • The app never opens your microphone or your camera. It asks for neither permission, and there is no voice feature.
  • You can export everything you have made, and delete your account and its data from inside the app at any time.
  • No ads, no advertising identifiers, no analytics SDKs, and we do not sell your data.

Who is responsible for your data

The data controller for Reflashcard is Halil Sarıkaya, Karatay, Konya, Türkiye — reachable at [email protected].

Write to that address to ask a question about this policy or to exercise any of the rights listed below. We answer within 30 days.

What we collect, why, and on what legal basis

We collect only what a feature needs in order to work. Everything below is collected directly from you — from the account you create and the actions you take in the app. We do not buy data or obtain it from third parties.

DataWhyLegal basis
Email address and authentication identifiersSo you can sign in and your data follows you to a new device. Handled by Supabase Auth; we never see or store a password.Performance of our contract with you (GDPR Art. 6(1)(b); KVKK m.5/2-c)
Decks, flashcards, definitions, the source sentence of each card, notes, highlights and bookmarksThis is the content you create — the product itself — and it is synced so it survives a lost device.Performance of contract
Review history: ratings, intervals, due dates, reading-time countersThe spaced-repetition schedule and your statistics are computed from it.Performance of contract
File name and page number of documents you openSo a card can jump back to the exact place it came from. The document's contents are never uploaded.Performance of contract
The word or passage you send to an AI feature, and its surrounding sentenceIt is the input to the answer you asked for.Performance of contract
Usage counters: AI generations this monthTo enforce fair-use quotas and keep the service affordable to run.Our legitimate interest in preventing abuse and cost overrun (GDPR Art. 6(1)(f); KVKK m.5/2-f)

Providing account data is a contractual requirement: without it there is no account and no sync. You do not have to use any AI feature — the reader, your cards and offline review all work without them.

What we do not collect

  • The contents of your PDF files. Parsing and caching happen entirely on your device.
  • Advertising identifiers, location data, contacts, photos, or a listing of the files on your device.
  • Third-party analytics or advertising SDKs — the app ships with none.
  • Special-category data (health, beliefs, biometrics). Please do not put such information into notes or AI prompts; if you do, it is processed as ordinary card content and we have no way to treat it differently.

AI features — what you should know before using them

You are talking to a machine. Card definitions, translations, explanations, stories and quizzes are all produced by AI models, not by a person, and their output can be wrong or invented — that is true everywhere in the app, whether or not a given screen carries an explicit label saying so.

When you use one of these features, the text you selected and the sentence around it are sent to the AI provider that answers the request. We send the fragment, never the document.

Nothing that identifies you goes with it. The request is made by our server, not your device, so the provider never sees your IP address; and it carries no account id, no device id and no name — just the text and what to do with it. Your identity stays on our side, where the usage counters live. This is deliberate: it means a sentence with nothing personal in it stays a request with nothing personal in it.

Important: our text AI provider is DeepSeek, whose published privacy policy states that it stores data on servers in the People's Republic of China and permits use of submitted content to train and improve its models. We cannot contractually override that on your behalf. DeepSeek is now our ONLY AI provider — the realtime voice feature that ran on Google Gemini was removed, and read-aloud does not go to an AI provider at all — see the processor table below.

So: do not paste anything into an AI feature that you would not be comfortable having stored abroad and potentially used to improve a model. Everything else in the app — reading, cards you write yourself, review, offline study — works without sending anything to an AI provider.

Microphone and camera

The app does not use your microphone and does not use your camera. On Android it requests neither permission — the only permissions it declares are internet access, reading a file you pick, and (on Android 13+) showing you a study reminder.

This used to be different. Until September 2026 there was an optional voice feature, Reader Live, which streamed your microphone to Google's Gemini live-audio API while a session was open. It was removed — the feature, the permission and the audio code — so the microphone is now out of the app entirely rather than merely switched off.

The shared word cache

When you generate a card for a word we have never seen, the resulting dictionary entry — the word, its part of speech, definitions and examples — is stored once in a shared cache and reused for everyone else who looks that word up. This is why generation is usually instant and free of quota.

What is shared is the dictionary entry for the word. Your sentence, your document, your notes and your review history are never part of it, and the cache cannot be traced back to you by other users.

The entry itself is not deleted when you delete your account, because by then it is a dictionary definition serving other people rather than a record about you.

Who else processes your data

These are our processors. Each receives only what its feature requires, and each is bound by a data-processing agreement.

ProviderWhat it receivesWhere
SupabaseAuthentication and the hosted Postgres database holding your account and study data.European Union
DeepSeekAll text AI: card generation, translation, explanation, page chat, stories and quizzes. Receives the selected text and its context — not the document.People's Republic of China
ReplicateText-to-speech, present in our backend but switched off at launch — read-aloud currently runs on your device's own text-to-speech engine, and no sentence is sent anywhere for it. We will turn this row into a live one, not silently, if we ever enable server-side voices.United States (not active today)
YouTube / GoogleWhen you paste a video link into Listening Lab, its transcript is fetched. Playback runs in YouTube's own embedded player under YouTube's terms and privacy policy.United States
Railway, CloudflareHosting for the backend API (Railway), the web app (Cloudflare Pages), and the images and audio the app serves (Cloudflare R2). Each also sees the network request itself — including your IP address — in order to route it.United States / global edge
jsDelivr (CDN)Page scanning only. When you scan a page in a language for the first time, the app downloads that language's text-recognition data file from this CDN, which sees your IP address. The recognition itself runs on your device; no page image and no text is ever sent.Global edge

We will update this table before adding any new processor. Check the date at the top of this page to see when it last changed.

Sending data outside your country

To provide seamless cloud synchronization, vocabulary lookup, and AI features, our infrastructure providers (Supabase, DeepSeek, Cloudflare, Railway) operate on servers located outside Türkiye and/or the European Economic Area. When you use these features, only the limited data required for that specific action is securely transmitted to international servers.

For transfers to processors established in the United States and the European Economic Area, we rely on the safeguards established by those providers: the European Commission's Standard Contractual Clauses (SCC) within their data processing agreements and international security standards.

These transfers are carried out pursuant to the necessity of performing the service you requested (performance of contract under applicable law and KVKK Art. 5/2-c) and the international data security commitments of these providers. Data security is maintained through these international standards and encrypted transmission protocols.

The servers of DeepSeek, our text AI provider for card generation and contextual translation, are located in the People's Republic of China. When using an AI feature, only the selected word and surrounding sentence are transmitted; your name, email, identity, and original files are never shared. As a sound privacy practice, we recommend not entering sensitive personal data into AI prompts. If you do not use AI features (such as offline reading or writing cards manually), none of your data is sent to this provider.

How long we keep things

DataKept for
Account, decks, cards, notes, review historyAs long as your account exists. Deleted within days of account deletion.
Monthly AI usage countersAs long as your account exists — the same as your other account data.
Support correspondenceUp to 3 years, so we can handle follow-ups and complaints.
Database backupsNone kept today — deletion removes the row from the live database and there is no backup copy for it to persist in. This will change if the hosting plan adds scheduled backups; we will update this row first.

Your rights

Under the GDPR and, in Türkiye, under KVKK m.11 you can ask us to give you a copy of your data, correct it, erase it, restrict or object to how we use it, and receive it in a portable format. Where processing rests on consent, you can withdraw that consent at any time. You can also ask whether we process your data at all and, if so, why.

Two of those you do not need to ask us for — they are built into the app:

  • Export — Settings → Data & Backup → Export my data writes a JSON file with your decks, cards and full review history.
  • Erasure — Settings → Danger Zone → Delete account removes your account and every row of your data from our servers and clears the local copy on the device. It cannot be undone.
  • If you can no longer sign in, request deletion at https://reflashcard.com/delete-account or write to [email protected] from the address on the account. We complete it within 30 days.

Complaints

If you think we have handled your data badly, tell us first at [email protected] — most things are fixable quickly. You also have the right to go to a regulator without asking us: in Türkiye the Kişisel Verileri Koruma Kurumu (kvkk.gov.tr), and in the European Economic Area or the United Kingdom the data-protection authority of the country you live in.

Automated decisions

The review schedule is computed by an algorithm, but it only decides when a flashcard is shown to you. Nothing in the app makes a decision that has a legal or similarly significant effect on you, so the Art. 22 rules on automated decision-making do not apply.

Children

Reflashcard is not directed at children. You must be at least 16 to create an account, or 13 where your country's law permits it and a parent or guardian agrees. We do not knowingly collect data from anyone below that age; if you believe a child has created an account, contact [email protected] and we will delete it.

Storage on your device

The app stores data on your device so it works offline: your decks and review queue in a local database, your PDFs in a local cache, and your sign-in session and preferences in local storage. These are necessary for the app to function and are not used for tracking or advertising — there are no third-party cookies. Signing out or deleting your account clears them; uninstalling the app removes them entirely.

Security, and what happens if it fails

Traffic runs over HTTPS, requests are authenticated with short-lived tokens, and every database query is scoped on the server to the signed-in account. Passwords are never stored by us — authentication is delegated to Supabase.

No system is perfect. If a breach occurs that is likely to put your rights at risk, we will notify the competent authority within 72 hours and tell you directly without undue delay.

Changes to this policy

If this policy changes materially — a new processor, a new category of data, a new purpose — we will update the date at the top and show you the new version in the app before the change takes effect. Continued use after that means you accept it. Past versions are available on request.

Terms of ServiceDelete your account