Privacy Policy

Effective 21 September 2026

In short

1. Who is responsible

The controller for the processing described here, within the meaning of the EU General Data Protection Regulation (GDPR), is:

Xiyang Lyu
Saarbrücker Str. 268
66125 Saarbrücken
Germany
Email: contact@memocardsapp.com

This policy covers the MemoCards apps for iPhone, iPad and Mac, the sync and deck-generation service behind them at api.memocardsapp.com, and this website.

2. Using MemoCards without an account

Everything you create — decks, cards, images, handwriting, tags, review history and settings — is stored on your device. We do not receive any of it. Study reminders are scheduled on your device by the operating system and involve no server.

The app contains no advertising, analytics or tracking SDKs and does not use Apple's advertising identifier. If you have chosen to share analytics with app developers in your device settings, Apple may give us aggregated usage statistics and crash reports; these do not identify you to us.

3. Your account

An account is optional and is needed only for sync and AI deck generation. You can sign in in three ways:

For each account we store your email address, your display name and profile picture if you set them, the sign-in methods linked to it, and one record per device you sign in on (a random installation ID, the device name, its platform and app version, and when it was last seen). Sessions are kept as hashed refresh tokens only.

Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR); for the IP hash, our legitimate interest in protecting the sign-in service from abuse (Art. 6(1)(f) GDPR).

4. Sync

When you are signed in, the app uploads your library so that it appears on your other devices: decks and subdecks, cards and their text, images, drawings and handwriting attached to them, tags, your review history and scheduling, and deletions. Each change is recorded with the device it came from. Built-in sample decks are not uploaded.

This data is stored on a server we rent from Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in a data centre in Germany. Connections are encrypted with TLS. Hetzner processes the data only on our behalf under a data processing agreement. Backups are kept for up to 7 days.

Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).

5. AI deck generation

AI deck generation turns a PDF you choose into a draft deck you can review before saving. It runs only when you start it, and the app asks for your permission before any document can leave Apple's systems.

Apple Private Cloud Compute

On iOS, iPadOS and macOS 27 or later, the app first tries Apple Private Cloud Compute. The text of the document is read on your device and processed by Apple's models on Apple's servers, which by Apple's design do not keep it or make it available to Apple or to us. We then receive a short report without any document content: whether it succeeded, how many pages, parts, requests and cards were involved, how long it took, and your platform. We use these reports to operate and tune the feature.

Our server and our AI providers

If Private Cloud Compute is not available, or cannot handle the document, the PDF is uploaded to our server. We extract its text and send that text, together with the options you chose (language, level of detail, number of cards and any instructions you typed), to one of these providers, who generate the cards and return them to us:

We use the providers' paid business APIs. Under their terms they process the text only to provide the service to us and do not use it to train their models; they may keep it for a limited time to detect abuse. We store the generated draft, which model produced it and how many tokens it used, so that we can account for its cost. The PDF itself is kept for 14 days after the generation finishes, so that a failed generation can be retried, and is permanently erased from our storage no later than about 45 days after the generation finished.

Please do not generate decks from documents containing sensitive personal information about yourself or others.

Legal basis: your consent (Art. 6(1)(a) GDPR), which you give in the app before your first generation and can withdraw at any time by no longer using the feature; and performance of our contract with you (Art. 6(1)(b) GDPR).

6. Subscriptions

Subscriptions are sold and billed by Apple. We never receive your payment details. When you subscribe or restore a purchase, the app sends us the transaction Apple signed for it — including the product, the original transaction ID, purchase and expiry dates, and whether it is a test purchase — so that the server can confirm your access to paid features. We also count the pages you generate each month to apply the plan's limits.

Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR) and our legal obligation to keep business records (Art. 6(1)(c) GDPR).

7. Sign-in emails

Sign-in codes are sent through Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA), which receives your email address, the code and the language of the message. It processes them only to deliver the email.

8. Server logs and this website

Our web server records each request to the API and to this website: the IP address, time, requested address, response status and the software making the request. We use these logs only to keep the service secure and working; they are rotated automatically and overwritten after a few weeks at most. Legal basis: our legitimate interest in operating a secure service (Art. 6(1)(f) GDPR).

This website sets no cookies, loads nothing from third parties and uses no analytics.

9. Who receives your data

RecipientPurposeLocation
Hetzner Online GmbHServer hosting and backupsGermany
Resend (Plus Five Five, Inc.)Sending sign-in codesUSA
Google LLCAI deck generation (Gemini); Sign in with Google, if you use itUSA
Anthropic, PBCAI deck generation (Claude)USA
AppleApp distribution, purchases, Sign in with Apple, Private Cloud ComputeEU / USA

Where a recipient is in the USA, the transfer is based on the EU–U.S. Data Privacy Framework if the recipient is certified under it, and otherwise on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR). We do not sell your data or share it for advertising.

10. How long we keep data

11. Deleting your data

Delete Account in the app's Account settings erases your account and everything stored with it on our server — profile, devices, sessions, decks, cards, review history, media and generation jobs — and then clears the device you did it from. Data held in backups disappears within 7 days. Delete All User Data in Data Management clears only the device and leaves your account alone. You can also write to us and we will delete your account for you.

12. Your rights

Under the GDPR you have the right to access your data (Art. 15), to have it corrected (Art. 16) or erased (Art. 17), to restrict its processing (Art. 18), to receive it in a portable format (Art. 20 — the app's export already gives you your decks), and to object to processing based on our legitimate interests (Art. 21). You can withdraw consent at any time with effect for the future (Art. 7(3)). To exercise any of these rights, email contact@memocardsapp.com.

You also have the right to complain to a data protection supervisory authority. The authority responsible for us is the Unabhängiges Datenschutzzentrum Saarland, Fritz-Dobisch-Straße 12, 66111 Saarbrücken, Germany.

13. Children

MemoCards is suitable for learners of all ages, but an account is not intended for children under 16 without the involvement of a parent or guardian.

14. Changes

We will update this policy when the app or the service changes. The date at the top shows the current version; if a change significantly affects how your data is used, we will also tell you in the app.

A German version of this policy is available; if the two differ, the German version prevails.