Privacy Policy
Last updated: 14 June 2026
This Privacy Policy explains what personal data Cardly collects when you use the app, why we collect it, the legal grounds for it, and the rights you have under the EU General Data Protection Regulation (GDPR).
Data controller
Cardly is a personal, non-commercial project run by Davide Michelon (the "data controller"). For any privacy question or request, contact: davidemichelon10@gmail.com.
Data we collect
- Account data: when you sign in with Google, we receive your name and email address to create and identify your account.
- Learning data: the decks and cards you create, and your study history (reviews, schedules, statistics).
- Technical data: essential cookies to keep you signed in and protect against request forgery (see the cookie table below). We do not use analytics, advertising, or tracking cookies.
Legal bases for processing
- Performance of the service you request (Art. 6(1)(b) GDPR): authenticating you, storing your decks, scheduling reviews, and generating cards when you ask for AI generation.
- Legitimate interest (Art. 6(1)(f) GDPR): keeping the service secure (e.g. preventing abuse and protecting against request forgery).
How we use your data
We use your data solely to provide the service: signing you in, storing your decks, scheduling reviews, and showing your statistics. We do not sell your data and we do not use it for advertising.
Third-party processors
- Google — sign-in (OAuth). Google processes your authentication and provides us your name and email.
- OpenAI — used only when you request AI deck generation: the topic you type is sent to OpenAI to generate cards. OpenAI does not use data submitted via its API to train its models and retains it only for a limited period for abuse monitoring. Do not include personal or sensitive information in topics.
Where your data is stored & international transfers
Your account and learning data are stored on servers located in the European Union. Some third-party processors (Google, OpenAI) are based in the United States, so limited data may be transferred outside the EU. Such transfers rely on the European Commission's Standard Contractual Clauses (SCCs) as a safeguard.
Cookies
Cardly uses only strictly necessary cookies. No consent is required for these under the ePrivacy rules; we show a short notice for transparency.
| Cookie | Purpose | Duration |
|---|---|---|
sessionid | Keeps you signed in | Session / up to 2 weeks |
csrftoken | Protects forms against request forgery | 1 year |
Data retention
We keep your data for as long as your account exists. You can delete your account at any time from Settings, which permanently removes your decks, cards, and study history.
Your rights
Under the GDPR you have the right to access, correct, export, restrict, or delete your personal data, and to object to its processing. You can delete your data directly via the account-deletion option in Settings, or contact us for any other request. You also have the right to lodge a complaint with your local supervisory authority — in Italy, the Garante per la protezione dei dati personali (www.garanteprivacy.it).
Minimum age
Cardly is not intended for children under 14. If you are under 14, please do not use the service.
Changes to this policy
We may update this policy from time to time. The "last updated" date at the top reflects the latest version.