CardPuff
Privacy Policy
This policy explains what CardPuff processes, why it is needed, and the choices available to you.
Information we process
We process account identity details, profile preferences, vocabulary projects and cards, study progress, usage counters, subscription status, shared-deck memberships, and messages you send through Contact Us.
How information is used
Information is used to authenticate you, provide spaced-repetition study, save preferences and progress, enforce allowances, process subscriptions, deliver invitations and support replies, secure the service, and improve reliability.
Service providers
CardPuff uses Supabase for authentication and database services, Vercel for hosting, Anthropic for requested AI features, Stripe for subscription billing, and Brevo for transactional invitations and support email. Each provider processes only the information required for its role under its own terms and privacy commitments.
Sharing
Decks are private unless an eligible Pro owner enables sharing. Recipients cannot edit the owner’s cards and maintain separate study progress. Targeted invitations are restricted to the invited signed-in email address. Shared access pauses if the owner’s Pro access expires.
Retention and security
We retain information while your account or an operational/legal need remains. Access controls, row-level security, signed webhooks, scoped server functions, and server-only credentials are used to protect data, but no online service can guarantee absolute security.
Your choices
You can update profile settings, stop sharing a deck, remove projects, cancel Pro renewal, or contact us about access, correction, or deletion requests. Legal rights vary by location.
Contact
Submit privacy questions through the Contact Us page.
Last updated: August 1, 2026