Private by default
Your profile and study content are visible only to you unless you deliberately choose to publish something.
Privacy Policy
NeuroCards collects what it needs to run your account, sync your study progress and keep the service secure. We do not sell personal data or use it for advertising.
Your profile and study content are visible only to you unless you deliberately choose to publish something.
No advertising profiles, no sale of personal data and no third-party behavioural analytics.
You can update your details, export study content and schedule account deletion from inside the app.
This policy explains how NeuroCards handles personal data when you visit neurocards.net, use the application there, contact us or use a feature connected to the NeuroCards API.
Personal data means information that identifies you or can reasonably be linked to you. Study content can become personal data when it is stored inside your account, even if the subject of a card is not about you.
NeuroCards is operated by [COMPANY NAME], a company registered in England and Wales under company number [COMPANY NUMBER]. Its registered office is [REGISTERED OFFICE ADDRESS].
[COMPANY NAME] is the controller of the personal data described in this policy. That means it decides why and how this data is processed. Privacy questions and rights requests can be sent to privacy@neurocards.net.
NeuroCards does not currently collect payment information, precise location, advertising identifiers or contact lists.
We receive data in three ways:
We use account, study and session data to authenticate you, sync your library, schedule reviews, send requested account emails and provide optional features. Our legal basis is performance of our contract with you.
We use limited technical and security information to prevent abuse, diagnose faults and protect accounts. Our legal basis is our legitimate interest in operating a safe and reliable service.
We may process information to respond to valid rights requests, legal claims or binding requests from authorities. Our legal basis is compliance with legal obligations or our legitimate interests in establishing and defending legal rights.
If we introduce a use that requires consent, we will ask for it separately. We will not quietly repurpose your study data for advertising or unrelated profiling.
AI generation is optional and runs only when an eligible user deliberately submits text, instructions or a PDF. The submitted material is sent through OpenRouter to an AI model, such as Anthropic's Claude models run by Google Vertex AI, so it can produce flashcards.
NeuroCards does not save the original submitted text or PDF in its active database. It saves the resulting deck or cards and a generation record containing operational details such as the model, status, token counts, card count, completion time and any generated notes or error message.
NeuroCards only sends material to AI providers with zero data retention: they process it to answer the request, then don't keep it or use it to train their models. PDFs are read by the model itself, not by another service first. Do not submit personal, confidential or copyrighted material unless you have a lawful reason and permission to use it.
Display names, planned usernames, folders, decks and cards are private by default. NeuroCards does not currently make a deck public merely because you create it.
If NeuroCards makes publishing available and you deliberately choose Publish, the selected deck and cards, together with your display name and username, will become visible to other signed-in NeuroCards users. The publishing screen will explain this before anything is shared.
Other users may be able to import an independent copy into their own library under the licence described in the Terms of Service. Removing the original or deleting your account stops NeuroCards displaying the original listing, but copies already imported or lawfully redistributed may remain. Where reasonably practical, NeuroCards will remove the deleted account's profile link and replace its identity on copies we control with “Deleted user”.
We use a small number of providers to operate NeuroCards. They receive only the information needed for their role.
Ireland and the Netherlands are in the EEA and are covered by UK adequacy regulations. Some providers operate globally. Where personal data is transferred beyond the UK to a place without an applicable adequacy arrangement, we rely on the provider's contractual safeguards or another lawful transfer mechanism.
We may also disclose information where required by law, to protect users or the service, or as part of a genuine corporate reorganisation where the recipient takes on the obligations in this policy.
NeuroCards does not use advertising cookies. It uses a secure authentication cookie and browser storage needed to provide the service you request, including:
This information remains on the device until NeuroCards clears it, the relevant cache expires or you clear the site's browser data. If we introduce non-essential analytics or advertising storage, we will update this policy and request consent where required.
Account deletion cannot recall published content that another person already copied under a continuing licence, although the original listing and profile are removed from NeuroCards.
NeuroCards uses encrypted network connections, secure session cookies, password hashing, access controls, verified-email gates and restricted production credentials. No online service can promise absolute security, but we aim to keep the data and access we hold proportionate to a focused study application.
You can help by using a unique password, protecting access to your email, Google or Apple account and signing out on shared devices. Contact us promptly if you believe an account has been compromised.
You must be at least 13 to create or use a NeuroCards account. NeuroCards is designed with high-privacy defaults for everyone: content is private unless deliberately published, data collection is limited, and there is no advertising or behavioural profiling.
If you believe a child under 13 has created an account, contact privacy@neurocards.net so we can investigate and remove it where appropriate.
Depending on the circumstances, UK data-protection law gives you rights to:
Many account details can be corrected or deleted directly in the app. For anything else, email privacy@neurocards.net. We may need enough information to confirm that the request concerns your account.
You may also complain to the Information Commissioner's Office, the UK data-protection regulator.
We may update this policy when the service, providers or law changes. The effective date at the top will change. We will give a clear in-app or email notice before a material change takes effect where that is appropriate.
We will review this policy before launching community publishing, payments, advertising, additional analytics or any materially different use of personal data.