Flashcards Privacy Policy
Last updated: June 15, 2026
This Privacy Policy explains what information Flashcards by Lumagate (the "App" or "Service") — provided by Lumagate Inc. ("Lumagate", "we", "us") — collects, how we use it, and which third parties we rely on. It applies to the App on the web and as a native iOS and Android application.
Flashcards is a consumer application that helps you prepare for certification exams. To do that, it creates an account for you and stores your learning progress, so this policy describes that data specifically. If you have questions about this policy or your data, contact us at support@lumagate.us.
1. Identity and Authentication
You sign in through Firebase Authentication using Google, Apple, or Microsoft. We never see or store your password. From your chosen sign-in provider we receive your email address, display name, profile photo URL, and a stable user identifier that we use to recognize your account. If you sign in with Apple and choose to hide your email, we receive Apple's private relay address instead of your real address.
2. Information We Store in the App
Your account data is stored in Google Firebase (Cloud Firestore), which serves as the single source of truth for the App. This includes:
- Your profile (the display name, email, and photo URL provided by your sign-in provider)
- Your flashcard learning progress and study activity
- Cards you have flagged or bookmarked
- Your subscription status and the customer and subscription identifiers issued by your payment provider
- A record of which in-app service notifications you have seen
3. Payments and Subscriptions
We never receive or store your full payment card or bank account details. Payments are handled by the payment provider for your platform, and the App stores only your resulting subscription status and the provider's reference identifiers:
- Web — Stripe hosts the checkout and customer billing portal and processes your card data. The App stores only your subscription status and your Stripe customer and subscription IDs.
- iOS — Apple In-App Purchase (StoreKit) handles all payment data. The App receives validated purchase receipts through our Cloud Functions.
- Android — Google Play Billing handles all payment data. The App receives purchase notifications through our Cloud Functions.
4. Search
Flashcard search is powered by Algolia. When you search within the App, your search query is sent to Algolia to return matching flashcard content.
5. Crash and Error Reporting
On iOS and Android, the App uses Firebase Crashlytics to record crashes and uncaught errors so we can diagnose and fix stability problems. Crash reports include technical diagnostics such as device model, operating system version, and stack traces. Crashlytics is not used on the web; the web app handles errors locally and does not send crash reports to a third party.
6. Abuse Prevention
To protect our backend from abuse, the App uses Firebase App Check to confirm that requests come from a genuine, untampered instance of the App. This uses reCAPTCHA Enterprise on the web, the Play Integrity API on Android, and Apple's DeviceCheck on iOS. These mechanisms assess device and app integrity signals; they do not identify you personally.
7. Service Notifications
The App can display in-app announcements — such as maintenance notices or product updates — that an administrator publishes. These appear inside the App and are tied to your account. The App does not send mobile push notifications and does not collect device push tokens.
8. Cookies, Local Storage, and Logs
On the web, signing in stores authentication tokens in your browser (using local storage and IndexedDB) so that you stay signed in. These are essential to the Service and are cleared when you sign out. Our web hosting provider, Firebase Hosting, also keeps standard server access logs — such as IP address, browser type, and timestamps — for security, troubleshooting, and reliability. We do not use advertising or cross-site tracking cookies.
9. How We Use Your Information
We use the information described above to authenticate you and maintain your account, to save and synchronize your learning progress across your devices, to provide and bill your subscription, to power flashcard search, to keep the Service stable and secure, and to communicate important information about the Service. We do not use your data for advertising, and we do not sell your personal information.
10. Third Parties and Data Sharing
We share data only with the service providers needed to operate the Service, each of which processes data under its own privacy terms:
- Google Firebase — authentication, database, hosting, crash reporting, and App Check
- Stripe — web payments
- Apple — iOS sign-in and In-App Purchase
- Google Play — Android billing
- Algolia — flashcard search
We do not use third-party advertising networks, marketing or tracking pixels, or third-party analytics SDKs.
11. How We Protect Your Data
Lumagate protects your data using industry-standard practices, including encryption in transit (TLS), encryption at rest in Firebase, and role-based access controls on our backend. No method of transmission or storage is completely secure, but we apply reasonable safeguards to protect your information.
12. Data Retention
We retain your account and app data for as long as your account exists. When you delete your account, your Firebase Authentication record and the Firestore data described above are deleted. Some payment and transaction records may be retained independently by our payment processors (for example, Stripe) for the period required by tax, accounting, and dispute-resolution obligations, separate from your account in the App.
Operational and diagnostic data held by our other processors — such as Algolia search logs, Firebase Crashlytics crash reports, and App Check integrity signals — is retained according to each provider's own retention schedule and is generally not linked to your account.
13. Deleting Your Account
You can delete your account at any time from the Settings screen within the App. This removes your authentication record and the app data described in this policy.
14. Your Privacy Rights
Depending on where you live — for example, under the EU GDPR, the UK GDPR, or the California CCPA/CPRA — you may have the right to access, correct, delete, export, or restrict the processing of your personal data. You can delete your account and its associated data directly from within the App. To exercise any other right — access, correction, export, or restriction — contact us at support@lumagate.us and we will respond as required by applicable law. You also have the right to lodge a complaint with your local data protection authority.
15. Children's Privacy
The Service is intended for certification exam candidates and is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us at support@lumagate.us and we will take prompt steps to delete it.
16. International Users
Our service providers are located primarily in the United States, and your information may be processed there. Where required, these transfers are covered by the EU-US Data Privacy Framework, Standard Contractual Clauses, or equivalent safeguards provided by each processor.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with a revised "Last updated" date, and material changes will be communicated through the Service where appropriate.
18. Contact Us
If you have any questions or concerns about this Privacy Policy or how Lumagate handles your information, please contact us at support@lumagate.us.