Privacy Policy
Last updated: June 2026
What We Collect
When you use the hosted cloud beta, we store the email address you use for authentication and the learning data needed to operate the service, including cards, review history, and workspace metadata. Self-hosted instances do not send data to us unless you deploy your own copy that does so.
Operator
The hosted Flashcards service is operated by SAMO DANNI EOOD, company ID 207395566, VAT BG207395566, registered address bulv. Maritza 154, entrance D, floor 6 #14, 4018, Plovdiv, Bulgaria. Flashcards was created by Kirill Markin.
AI Features
If you choose to use AI chat in the hosted app, your typed prompts, card-derived context needed for the request, uploaded files, uploaded images, and dictated audio or transcription requests may be sent to third-party AI providers configured on the server. The exact provider used depends on the hosted server configuration at the time of the request.
Connecting External AI Clients
When you connect Flashcards to an external AI client through the remote MCP server (mcp.flashcards-open-source-app.com/mcp) or the Agent API, the flashcard data you request is sent to that client and to the AI or model provider operating it. That processing is governed by that provider's terms rather than ours.
How We Use Your Data
Your data is used to provide authentication, cloud sync, and optional AI features. We do not sell your data or use it for advertising. Authentication and workspace access are handled by the backend services documented in the public repository.
Data Storage
Hosted cloud data is stored in AWS infrastructure, including Postgres for primary application data. Data is encrypted in transit. We retain your hosted learning data for as long as your account is active, and we delete it when you delete your account or request removal. Operational logs are kept only as long as needed to run and debug the hosted beta, typically up to 90 days.
Cookies
We use authentication cookies such as session, refresh, and logged_in for the login flow. No tracking cookies or third-party analytics are required for the site to work.
Data Deletion
For self-hosted instances, you control the database directly. In the hosted app, you can delete your account from the iOS app or the web app. You can also request hosted data removal through the Agent API or a connected MCP client, and you can contact support if you need additional help with hosted data removal.
Support
For privacy questions, contact kirill+flashcards@kirill-markin.com or use the support page.
Open Source
The entire codebase is open source. You can audit exactly what the application does with your data.