Privacy Policy

Last Updated: May 23, 2026

This Privacy Policy explains how Flashcards World SL ("we", "us", "our") collects, uses, and protects information when you use flashcards.world (the "Website"). It covers the website specifically — our Android and iOS apps have separate privacy policies at privacy.html and privacy_ios.html.

1. Information We Collect

Account data. If you sign in, we store your email and authentication tokens via Firebase Authentication. We use this to associate flashcard sets with your account and to sync them across devices.

Content you create. Flashcard sets you create (terms, definitions, images, tags) are stored on our servers so you can access them from any device. Sets you mark as public may appear in our community catalogue.

Server logs. Standard web-server logs containing IP address, user agent, referer, and timestamps. Retained for up to 90 days for security and abuse prevention.

Cookies and similar technologies. See section 3 below.

2. How We Use Information

  • Provide the core Service (sync flashcards, sign-in, search community catalogue).
  • Protect against abuse (rate-limiting, anti-spam, fraud detection).
  • Communicate with you about your account or the Service (transactional emails only).
  • Comply with legal obligations, respond to lawful requests, and protect our rights.
  • Serve advertising (see section 4), subject to your consent where required.

We do not sell personal information. We do not run Google Analytics or Firebase Analytics on the Website.

3. Cookies and Tracking Technologies

We use cookies, localStorage, and similar device-storage mechanisms for:

  • Essential functions — keeping you signed in, remembering your preferences (dark theme, language).
  • Advertising — with your consent, Google AdSense and its partners use cookies and device identifiers to deliver ads, measure ad performance, and detect fraud. See section 4.

EU and UK visitors are shown a consent banner (Google Funding Choices / Google CMP) on first visit; you can withdraw or modify your consent at any time through that banner or your browser settings.

4. Advertising and Third Parties

We use Google AdSense to serve advertisements on the Website. Google and its advertising partners — collectively the "third-party vendors" listed at Google's advertising partner list — use cookies (including the DoubleClick cookie) and similar technologies to deliver ads based on your visits to this and other websites. Personalized advertising is disabled by default for users in regions that require consent under GDPR and only enabled if you opt in through the consent banner.

You can opt out of personalized advertising at any time at adssettings.google.com, or learn more at policies.google.com/technologies/partner-sites. US visitors can use optout.networkadvertising.org; EU visitors can use youronlinechoices.com.

Our consent management complies with the IAB Transparency & Consent Framework (TCF v2.2) where applicable.

5. Other Service Providers

  • Cloudflare — hosting, content delivery, DDoS protection. May log IP and request metadata for security purposes.
  • Firebase (Google) — authentication and account storage. See Firebase privacy.
  • Google AdSense — see section 4.

6. Legal Bases (GDPR)

For visitors in the European Economic Area and the United Kingdom, we process personal data under the following legal bases (GDPR Art. 6):

  • Performance of a contract — to deliver the Service you requested (sign-in, set sync).
  • Legitimate interests — server logs for security, abuse prevention, and quality measurement.
  • Consent — personalized advertising and any non-essential cookies. You can withdraw consent at any time via the consent banner.
  • Legal obligation — to respond to lawful requests from public authorities.

7. Your Rights

Subject to applicable law (GDPR, UK GDPR, CCPA / CPRA, and similar), you have the right to access, correct, delete, or port the personal data we hold about you, and to withdraw consent or object to certain processing. To exercise any of these, contact us at [email protected]. We aim to respond within 30 days.

US residents (California, Virginia, Connecticut, Colorado, Utah, and similar jurisdictions): we do not sell or share personal information as those terms are defined under your state's privacy law.

8. Children's Privacy

The Service is not directed at children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children under that age. If you believe we have collected such information, please contact us and we will delete it.

9. Data Retention

Account data is retained as long as your account is active. You can request deletion at any time. Server logs are retained for up to 90 days. Backup snapshots may take up to 30 days longer to be fully erased. Anonymized aggregate metrics may be retained indefinitely.

10. International Transfers

Our service providers (Cloudflare, Google) operate globally and may process data in countries outside the EEA / UK. Such transfers are protected by the European Commission's Standard Contractual Clauses or equivalent safeguards.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced at the top of this page; we recommend reviewing it periodically. The "Last Updated" date at the top reflects the latest revision.

12. Contact

Flashcards World SL
Email: [email protected]
For data protection inquiries, please include "Privacy" in the subject line.