Our commitment: Your documents are processed
securely and never shared. We use industry-standard encryption for
all data in transit and at rest.
1. Information We Collect
1.1 Information you provide
-
Account data: Email address and display name when
you create an account.
-
Documents: PDFs, images, and study materials you
upload for flashcard generation.
-
Study data: Your progress, card ratings, deck
organization, and study sessions.
-
Payment data: We do not store credit card details.
Payments are processed by Google Play, which may share purchase
confirmation details (product, timestamp, transaction ID) with us.
1.2 Information collected automatically
-
Usage data: App features used, session duration,
crash reports, and performance metrics.
-
Device data: Device model, operating system
version, app version, and locale.
2. How We Use Your Information
We use your information solely to:
- Generate flashcards from your uploaded documents
- Deliver and improve the spaced-repetition study experience
- Manage your account and subscription status
- Respond to support inquiries
-
Send service-related communications (receipts, renewal notices,
policy changes)
-
Analyze aggregate usage to improve the app's features and
performance
We do not sell your personal data, documents, or
study history to third parties. We do not use your
documents to train or improve third-party AI models beyond what is
necessary to process your immediate request.
3. AI Document Processing
When you upload a document, its contents are sent to our AI provider
(OpenAI / OpenRouter) for the sole purpose of extracting text and
generating flashcards. This processing is ephemeral — the AI provider
does not retain your document content beyond the processing request.
You can read OpenAI's data usage policy at
openai.com/policies/api-data-usage.
4. Data Storage & Security
Your documents and flashcards are stored in encrypted Supabase
PostgreSQL databases and object storage (Supabase Storage bucket). We
implement the following security measures:
-
Encryption in transit: All API communication uses
TLS 1.2+ (HTTPS).
-
Encryption at rest: Data is encrypted using AES-256
at the storage layer.
-
Access controls: Our server uses service-role
credentials for database operations, restricted to minimum necessary
privileges. Mobile and web clients use row-level security (RLS)
policies to ensure users can only access their own data.
-
Authentication: User identities are managed through
Supabase Auth, which enforces secure session handling and
token-based authentication.
5. Third-Party Services
We use the following trusted third-party services:
-
Supabase — Database, authentication, file storage
-
OpenAI / OpenRouter — AI flashcard generation
-
Google Play — Subscription payments and receipt
validation
Each service operates under its own privacy and security commitments.
We contractually require them to process data only as necessary to
provide the service.
6. Data Retention
We retain your data for as long as your account is active. Upon
account deletion:
-
Uploaded documents are permanently deleted from storage within 30
days
- Generated flashcards and study progress are deleted
-
Account identifiers (email) may be retained for legal or audit
purposes for up to 90 days
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
-
Delete your account and associated data (available
in-app or by emailing us)
- Export your data in a portable format
-
Withdraw consent where processing is based on
consent
To exercise these rights, contact us at
support@flashprep.fiqraat.app. We will respond within 30 days.
8. Children's Privacy
FlashPrep AI is not directed at children under 13. We do not knowingly
collect personal information from children. If you believe a child has
provided us with data, contact us so we can delete it.
9. Changes to This Policy
We may update this Privacy Policy. Material changes will be
communicated via email or in-app notification. We encourage you to
review this page periodically.
10. Contact
For privacy-related inquiries, contact our data protection
representative:
Email:
support@flashprep.fiqraat.app