SubjectCards is operated by TrueStandard Labs LLC, a Texas limited liability company. This policy covers both subjectcards.com and the SubjectCards iOS app. They run on the same servers and keep the same kinds of data, so one document describes both.
The short version: we keep the account details you sign in with, the phrases and decks you create, and your study progress. We send the text of your phrases to Google to write the card and to voice it. We do not sell your data, we do not run ads, we do not run analytics, and we do not use your phrases or study history to train AI models.
Who we are
SubjectCards is a flashcard app for learning languages. You study decks with native-speaker audio, and you can type a phrase you wish you could say; we turn it into a card with audio and keep it in front of you with spaced repetition.
The service is operated by TrueStandard Labs LLC, a Texas limited liability company. You can reach us at [email protected].
Information you give us
Your account. On iOS the app creates an anonymous account the first time it runs, identified only by a random token stored in your device's Keychain. Nothing about you is attached to it until you choose to sign in. When you sign in with Apple we receive your Apple user identifier, the email address you share (which may be an Apple private relay address), and, on your first sign-in, the name you choose to share. When you sign in with Google, on the web or in the app, we receive your Google account identifier, email address, name, and the URL of your Google profile picture. We use these to keep your progress across devices and to recognise you when you come back.
Phrases you type. When you ask for a card, the phrase is sent to our server and on to Google's Gemini API, which writes the card. The option you press is stored in your account as a flashcard, together with its translation, pronunciation, example sentence, and the audio we generate for it. Phrasings you did not press are not stored as cards.
Decks and preferences. The names of custom decks you create, and the answers you give during onboarding: your level, your goal, and the language you are learning.
Web purchases. If you buy a deck on the website, Stripe handles the payment. We store your Stripe customer ID, the payment reference, the amount, and the currency. Your card number never reaches our servers.
Support requests. If you email us, we keep the email so we can answer it.
Information collected automatically
Device record (iOS). The random device token, the platform, the app version, and the last time the app talked to our server. The same token is the identifier we use with RevenueCat, the service that manages the subscription.
Study progress. For each card you review: its status, the number of repetitions, the ease factor, the interval, when it is next due, and when you last studied it. The app syncs these so your progress survives a new phone.
Subscription state (iOS). Whether Premium is active. RevenueCat sends our server the event type and your device token when a subscription starts, renews, or expires.
Server logs. Like every web server, ours records incoming requests: the IP address, the endpoint, timing, and request parameters. For card creation the parameters include the phrase you typed. Sign-in tokens and credentials are filtered out of logs. We use logs only to debug problems and to keep the service secure.
Cookies (web only). The website sets a session cookie so you stay signed in and a remember-me cookie when you sign in with Google; both expire after six months at the latest. There are no analytics or advertising cookies, because we do not run analytics or ads. The iOS app itself does not set cookies; when you sign in with Google from the app, the sign-in runs in a system web view that shares cookies with the website.
Fonts (web only). The website loads the Inter typeface from Google Fonts, so Google receives the standard request data (your IP address and browser details) when a page loads.
On your device (iOS). Your decks, cards, study state, settings, and cached audio are stored on the phone so you can study offline. That copy is yours; it is not shared with anyone.
How we use it
- To run the service: build your cards, play their audio, schedule reviews, and sync progress between your devices.
- To apply the limits of the free tier (three custom cards, daily generation limits) and to unlock Premium when you subscribe.
- To process purchases and keep records of them.
- To answer your support requests.
- To keep the service secure, prevent abuse of the card generator, and debug problems.
- To meet legal obligations, such as tax records for purchases.
What we do not do
- We do not sell or rent your personal information.
- We do not show ads or share data with advertising networks.
- We do not run analytics or tracking SDKs in the app or on the website.
- We do not use your phrases, cards, or study history to train AI models.
- We do not send marketing email.
How AI processes your phrases
Three things leave our server for Google when you use the phrase feature. The phrase you typed goes to the Google Gemini API, which writes up to three ways a local would say it. The text of the card you press goes to Google Cloud Text-to-Speech, which returns the audio. When you name a custom deck, the name goes to Gemini to pick a tile symbol for it.
We send only the text needed for that request, never your name, email, or account identifier. Google processes it under the terms of its Cloud and Gemini API services. We do not use any of this to train models, and we do not permit our providers to train on it through our account.
How long we keep it
Account data, decks, cards, and progress are kept for as long as your account exists. Anonymous iOS accounts stay tied to the device token; deleting the app does not delete the server record, so if you want it gone, email us.
When you delete a custom deck in the app, the cards that belong to it and their progress are deleted with it. Purchase records are kept as long as tax and accounting rules require. Support emails are kept for as long as we need them to help you. Server logs are kept for operational purposes and are not linked to your account by design.
Your rights
Wherever you live, you can ask us to show you the personal data we hold about you, correct it, delete it, or send you a copy. There is no self-serve delete button yet; email [email protected] from the address you sign in with and we will do it within 30 days. If you only ever used the app anonymously, tell us roughly when you installed it and which language you were learning; we may not be able to find an anonymous account without that.
If you are in the EU, the EEA, or the UK, you also have the right to restrict or object to processing, and to complain to your local data protection authority. Our legal bases are performance of our contract with you (running the service), our legitimate interests (security, preventing abuse, debugging), and compliance with law.
If you are in California, the CCPA gives you the right to know what we collect, to delete it, to correct it, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined in the CCPA, and we will never treat you differently for exercising a right.
Security
Everything between the app, the website, and our server travels over HTTPS. The iOS device token is stored in the Keychain. We do not use passwords: sign-in goes through Apple or Google, so there is no password of yours for us to lose. No system is perfectly secure, and if we learn of a breach that affects you we will tell you.
Where your data lives
We are based in the United States and our server is hosted there. If you use SubjectCards from somewhere else, your data is transferred to and processed in the United States, where privacy law may differ from your own.
Children
SubjectCards is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us data, email us and we will delete it.
Changes to this policy
When we change this policy we update the date at the top. If a change is material, we will also say so in the app or on the website before it takes effect.
Contact
TrueStandard Labs LLC, a Texas limited liability company. Email [email protected].
Subjectcards is a TrueStandard Labs LLC product.