
Effective October 11, 2026
Privacy Policy
This policy explains how PlainDeck handles information when you use the app, its API, assistant connections, and support pages. Contact the PlainDeck developer at nvpz1598@gmail.com or through our support form.
Information we process
- Account information: Firebase Authentication processes your sign-in credentials and, depending on your sign-in method, your email address, name, and Google or Apple account information. PlainDeck uses your Firebase user ID to authenticate requests and separate your library. Email/password sign-in is also supported. Our API does not store your password.
- Your learning library: folders, deck titles and descriptions, card questions and answers, optional source notes, and review history/scheduling are stored on our server to sync your library and provide spaced review.
- Connection and security information: API requests, security-related account identifiers, authorized assistant client records, hashed access/refresh tokens, and basic network/operational logs are processed to run and protect the service.
- Purchases, when available: the relevant app store and RevenueCat process transactions, subscription status, account identifiers, and SDK-related technical information. PlainDeck uses entitlement status to enable paid features; we do not receive your full payment-card details.
- Support requests: Tally processes the email, request category, and message you submit. We use them to investigate issues, respond, and handle data requests. Do not send passwords, access tokens, payment details, or sensitive card content.
How we use information
We use information to sign you in, store and synchronize your library, schedule reviews, enable authorized assistant connections, verify purchases, prevent abuse, and respond to support or deletion requests. We do not sell your personal information, serve ads, or use your library for advertising profiles.
Service providers and assistant access
Firebase (Google) handles authentication; Cloudflare handles HTTPS delivery and hosts these public pages; RevenueCat and Apple/Google handle purchases when configured; Tally hosts the optional support form. Providers may process data in countries other than your own under their applicable privacy terms.
PlainDeck does not automatically send your cards to an AI provider. If you authorize ChatGPT or Claude through the connection consent flow, that assistant can read and change the library allowed by the displayed scope. The assistant provider handles data under its own policy. You can revoke that connection; account deletion revokes our issued assistant tokens.
Retention and deletion
Your active library is retained while your account exists. In-app account deletion removes your folders, decks, cards, and reviews from the active database, revokes assistant access, and deletes your Firebase sign-in account after reauthentication. A minimal deleted-account identifier remains to block old tokens from restoring access. Access-restricted recovery backups may retain prior data until replaced or removed; they are not used as active libraries. Purchase providers retain transaction records separately under their policies and applicable obligations. Support requests are retained as needed to resolve and document your request; you may request their deletion.
To delete your account, open Settings → Delete account. If you cannot use the app, submit an account/data deletion request. We verify account ownership before acting. Deletion does not cancel a store subscription; cancel it in your store account settings.
Your choices and security
You can view, edit, or delete your cards and request access, correction, deletion, or a copy of information associated with your account through support. Availability of specific rights depends on your location. Sign-in and API traffic use HTTPS; library access is restricted by authenticated account ownership. No system can guarantee absolute security.
Children and changes
PlainDeck is not directed at children under 13. Do not use the service if you are below the minimum age applicable to you. Contact us if a child provided personal information so we can investigate and remove it. We may update this policy when the service changes and will show the revised effective date here.