Privacy Policy for URflashcards.
Şerif Cin (“we”, “us”, or “our”) provides URflashcards (“Application” or “Service”), a language-learning flashcard application available on Google Play and related urflashcards.com pages.
This Privacy Policy explains what information the Application and its service providers access, collect, use, store, share, retain, and delete. We use information to provide, secure, sync, personalize, support, and improve the Service. We do not sell personal information.
Who is responsible for this policy
This policy applies to the current URflashcards Android application distributed through Google Play and to related urflashcards.com legal and support pages. The data controller responsible for information controlled by URflashcards is Şerif Cin, provider of URflashcards.
For privacy questions, account deletion questions, or data requests, contact support@urflashcards.com.
Information you provide, create, or allow
- Local age-group information: the 13–15, 16–17, or 18-and-older group you select during Android privacy setup. This setup does not ask for your date of birth.
- Account information: Firebase user ID, email address, display name, profile image, and Google Sign-In provider information when you choose to sign in.
- Learning data: progress, reviewed cards, answers, mistakes, mastery, SRS/FSRS review state, due-card data, streaks, XP, statistics, settings, selected languages, and study-time data.
- User-created content: custom cards, notes, categories, examples, edits, deleted-card/restoration state, and other flashcard content you create or modify.
- Downloaded-course and local-access data: selected and installed directed language pairs, approved course version and integrity information, update-check time, and the device-local record of the first two free pair unlocks or later rewarded pair unlocks. Downloaded course packs and pair unlocks are not Cloud Sync data and do not move to another installation.
- Purchase and entitlement data: Premium status, subscription entitlement state, restore state, and Google Play purchase metadata needed to unlock paid features. Payment card details are handled by Google Play, not URflashcards.
- Advertising and ad-SDK data: consent status, rewarded-ad interactions and outcomes, IP address and approximate location inferred from it, ad interactions, diagnostic and performance information, and device, account, and advertising identifiers when ads are available and allowed. URflashcards forces non-personalized requests for users who select 13–15 or 16–17. For 18-and-older users, Google’s consent status, regional requirements, available privacy choices, and app configuration determine whether an allowed request can be personalized or non-personalized. The CHILD treatment described below prevents transmission of the Android Advertising ID.
- Voice and pronunciation data: microphone input processed by the configured Android speech-recognition provider, recognition results returned to the Application, and text-to-speech text processed by the configured voice service when you choose those features. URflashcards does not store or upload raw microphone audio to its own servers.
- Notification data: local review-reminder preference, due-card count, due-card identifiers, and scheduled reminder time when review reminders are enabled.
- App-owned diagnostics and local app activity: local app events and troubleshooting information stored on the device under the app analytics storage key, plus logs you choose to send to support. AdMob's separate automatic diagnostics are described below.
How the selected group applies protections
A limited local setup and private preferences storage load first on Android. Except when the Application must first resume a previously requested account-deletion cleanup, a fresh installation shows welcome and language selection before asking an eligible user to select 13–15, 16–17, or 18 and older. An existing installation that needs the current age-group profile opens the same selector directly. Before a group is durably stored, the learning Application does not load, and Firebase, RevenueCat, AdMob initialization and ad requests, purchase, speech, microphone, and local-notification integrations remain inactive.
The selected group is stored only on your device in the Application’s private preferences. URflashcards does not ask for or store a birth date through this setup. The selected group stays inside the Application and its Android bridge, where it configures advertising and privacy protections; it is not sent to URflashcards servers or advertising providers.
The Service is available only to users aged 13 or older, so there is no under-13 choice. A person under 13 is not eligible to use the Service and must not select an inaccurate group. An eligible user can choose Settings > Privacy & Data > Update Age Group to restart this local setup without deleting learning data. Clearing app storage or uninstalling the Application also removes the locally saved group from that device.
The selected group applies advertising and privacy protections. It does not change the core learning experience, create an age profile on our servers, or make a decision about credit, employment, education admission, or another matter producing legal or similarly significant effects.
Why information is processed
URflashcards uses information to operate study and practice sessions, calculate SRS/FSRS review timing, maintain progress, save custom cards and edits, restore deleted cards, deliver and update approved language-pair courses, maintain device-local course access, personalize settings, provide Cloud Sync, back up and restore data, refresh Premium status, show allowed ads, grant eligible rewards, schedule local review reminders, secure the Service, prevent abuse, debug issues, and respond to support requests.
- Requested local functionality: to provide on-device learning, settings, and reminders the user chooses to use.
- Performance of a contract: where applicable, to provide accepted Account features, Cloud Sync, Premium access, purchase restoration, support, and deletion actions requested under the Terms of Service.
- Consent: where applicable for Google’s UMP choices, optional microphone access, or another feature that asks for permission. You can withdraw consent through the available in-app, Google, or Android controls without affecting processing that was lawful before withdrawal.
- Legitimate interests: to secure the Service, prevent fraud and abuse, diagnose faults, maintain reliable operations, answer support requests, and improve the Service where those interests are not overridden by your rights.
- Legal obligations: to respond to valid legal requests, protect legal rights, and keep records that applicable tax, transaction, consumer-protection, or data-protection law requires.
Local data and cloud backup
Some data stays local to your device unless you sign in, enable or use account features, send logs to support, or use a provider-backed feature. Cloud Sync with Firebase may store account details, progress, stats, settings, SRS/FSRS review state, study-time entries, and custom card data so your learning can be backed up and restored across devices.
Live Cloud Sync and new backup uploads may be limited to Premium users. After Premium ends, a signed-in user can still check for and restore the latest existing backup for the selected target language without re-enabling live synchronization, when such a backup exists. If no backup exists or Firebase is unavailable, local learning features may still operate on the device, but cloud backup or restore cannot complete.
Approved course packs are public JSON data delivered over HTTPS from Firebase Hosting. The Application requests only the selected or installed language pair, checks the received bytes and course identity before use, and keeps the last valid copy in private app storage. Course requests do not include Firebase Authentication or App Check tokens. Firebase Hosting can receive ordinary request information such as IP address, user agent, requested path, time, and delivery diagnostics under Google's policies.
Downloaded base cards are stored separately from Learning Data and User Content. A course update replaces only the validated base pack. Explicit user edits are stored as field-owned overlays, so an untouched field follows the approved update while an edited field, user-added example, hidden-card state, and related progress remain user-owned. If a base card or example temporarily disappears, associated edits and progress remain dormant rather than being silently reassigned.
Services that help run URflashcards
After an eligible age group is selected, we use service providers as needed for the features the user chooses, including authentication, cloud sync, app integrity, purchases, advertising, hosting, billing, platform features, and support.
- Google Play Services and Google Sign-In
- Firebase (Authentication, Firestore, App Check, and Hosting)
- Google AdMob
- RevenueCat (subscription entitlement management and purchase/subscription analytics)
- Android device and operating-system services used for text-to-speech and external speech recognition when the user chooses those features.
AdMob, UMP, and ad choices
The free version of URflashcards may show ads outside active study or practice sessions. Google AdMob and advertising partners may collect and share IP address, approximate location inferred from IP address, app launches, taps, video views and other ad interactions, diagnostic and performance information such as app launch time, hang rate and energy use, device and account identifiers, advertising identifiers, and consent status where available and allowed. They use this information to deliver and measure allowed ads, limit ad frequency, produce aggregated reporting, and prevent fraud. For eligible adults, allowed uses may also include ad personalization. URflashcards does not request Android location permission in the current app.
Before AdMob initializes, the locally selected group is applied to the Android Google Mobile Ads request configuration. The CHILD, TEEN, and UNSPECIFIED terms below are configuration labels used by Google Mobile Ads. They do not change the selected group or the Application’s content rating:
- Ages 13–15: CHILD age-restricted treatment, publisher privacy personalization set to DISABLED, Google UMP tagged as under the age of consent, and non-personalized ad requests forced.
- Ages 16–17: TEEN age-restricted treatment, publisher privacy personalization set to DISABLED, Google UMP not tagged as under the age of consent, and non-personalized ad requests forced.
- Ages 18 and older: UNSPECIFIED age-restricted treatment, publisher privacy personalization left at DEFAULT, and Google UMP not tagged as under the age of consent. Requests are not forced to be non-personalized by the age policy, but UMP, regional requirements, available privacy choices, and app configuration still control whether ads can be requested and whether they can be personalized.
Every eligible group receives the G maximum ad-content rating. Under Google’s documented CHILD treatment, personalized ads, remarketing, and third-party ad-vendor requests are disabled, child ad-serving protections apply, and the Android Advertising ID is not transmitted. TEEN treatment disables personalization and applies Google’s teen ad-serving protections. Non-personalized ads can still use identifiers for purposes such as frequency capping and aggregated reporting where permitted. AdMob does not initialize before an eligible local age-group profile exists.
Course-pair rewarded unlocks are not offered to users who select 13–15 or 16–17. An 18-and-older user may affirmatively choose one standard rewarded ad to unlock one additional directed language pair on that installation. The Application records the device-local pair unlock only after Google reports that the reward was earned; the exact pair key is not sent to AdMob for server-side verification.
URflashcards uses Google’s User Messaging Platform consent flow before requesting native ads where required. Depending on your location and Google’s message configuration, this may include a European regulations consent message, a US state privacy message, or a later privacy-options form. These ad-consent choices are separate from accepting the URflashcards Terms of Service and Privacy Policy.
If Google reports that a privacy options entry point is required for your region, the app can show an Ad Privacy Options button in Settings so you can review or change supported ad choices. These controls cannot override the protected non-personalized treatment for users who select 13–15 or 16–17. For an 18-and-older user, available choices may affect whether personalized ads are permitted, but selecting the adult group alone is not ad consent and does not override UMP or regional privacy-law signals.
If you decline or withdraw ad consent where consent is required, URflashcards is designed to keep already available learning features and downloaded courses usable, but ad-funded features, ad fill, rewarded ad-free passes, or adult course-pair rewards may be limited or unavailable.
Premium access and Google Play billing
Purchases and subscriptions are processed by Google Play. RevenueCat helps URflashcards read, restore, and manage entitlement status and provides purchase and subscription metrics. URflashcards does not receive or store your payment card number.
Google Play may retain purchase, tax, fraud-prevention, refund, and billing records according to its own policies and legal obligations. Deleting a URflashcards account does not cancel a Google Play subscription. When a URflashcards account is deleted, URflashcards also requests deletion of the RevenueCat customer profile and purchase history linked to that Firebase account ID; URflashcards confirms that the RevenueCat customer was deleted or was already absent before completing Firebase account deletion.
Speech features
Choosing speech recognition can send microphone input to the Android speech-service provider configured on the device. That provider may process the input off the device and return transcript alternatives to the Application. Text-to-speech can also send text to the configured device voice service, depending on that service and device settings.
URflashcards does not store or upload raw microphone audio to its own servers. You can choose not to use speech features and can revoke microphone permission in Android device settings.
When information may be shared
URflashcards shares information only when needed to provide the Service, process account and sync features, manage purchases, show allowed ads, host legal/support pages, protect users or the Service, comply with law, respond to your request, or work with the service providers listed in this policy.
We do not sell personal information. We do not use a general-purpose behavioral analytics or crash-reporting SDK in the current app code. AdMob automatically processes ad interactions and diagnostic and performance information for advertising, analytics, and fraud prevention, and RevenueCat may create purchase and subscription metrics as described above.
How long information is kept
Local app data remains on a device until it is deleted in the app, app storage is cleared, or the app is uninstalled. Downloaded course packs and free or rewarded pair unlocks normally remain through sign-in, sign-out, and app updates on that installation. In-app account deletion strictly clears URflashcards account data, downloaded courses, local pair unlocks, and other application preferences on the device that completes deletion, while preserving only the device-level age-group profile described below. Offline copies on other devices cannot be remotely erased; clear app storage or uninstall URflashcards on each other device where you also want its local copy removed.
The locally selected age group is a device privacy setting and is not linked to the URflashcards account. It remains after account deletion so the same advertising protections continue to apply on that device. It remains until you use Update Age Group, clear app storage, or uninstall the Application.
You can permanently delete your signed-in URflashcards account, cloud-synced user tree, and associated RevenueCat customer data from Settings > Cloud Sync > Delete Account. You can also use the public Account Deletion page for deletion instructions or requests. Google Play subscriptions must be managed separately through the Google Play account that made the purchase.
Reset Progress under Settings > Reset to Fresh Start deletes progress and custom-card data only for the current target language. Other target languages, the profile, the URflashcards account, and Premium access are retained. If Cloud Sync is in use, the app deletes or durably queues deletion of that language's cloud copy and warns if the retry cannot be saved.
During full account deletion, URflashcards keeps a minimal security record containing the Firebase user ID and deletion status. While deletion is processing or needs retry, that record does not expire automatically, so account data cannot be recreated while Firebase Authentication deletion is unconfirmed. After Firebase Authentication deletion succeeds and the record is marked completed, it becomes eligible to expire two hours later; Firebase's scheduled TTL removal can occur later.
Limited Google Play transaction, tax, fraud-prevention, or legal records, and provider security or operational logs, may be retained by Google Play, Firebase, AdMob, RevenueCat, or the configured Android service provider according to their documented policies and obligations. These records are not used to keep the deleted URflashcards account active.
Controls and data-protection requests
- Use the app locally without Cloud Sync where the feature allows it.
- Use Update Age Group to restart the local privacy setup.
- Delete your account and associated cloud data through the app or account deletion page.
- Delete progress and custom-card data for only your current target language with Reset Progress.
- Disable review notifications in Settings or device settings.
- Open Google ad privacy options when Google requires an entry point for the region.
- Revoke microphone permission in Android device settings.
- Manage or cancel subscriptions through the Google Play account that made the purchase.
- Contact support for privacy questions or data requests.
Depending on the law where you live, you may request access, correction, deletion, or restriction of personal information controlled by URflashcards; object to certain processing; request data portability; withdraw consent; and complain to your local data protection authority. Withdrawing consent does not affect processing that was lawful before withdrawal.
Send requests to support@urflashcards.com. We may need to verify your identity and account before acting on a request. Rights can be subject to lawful limits or exceptions, and provider-controlled records must be requested from the relevant provider.
How information is protected
We use provider security features such as Firebase Authentication, Firebase App Check, access rules, HTTPS, and encrypted transport where supported by the relevant service. Google Mobile Ads SDK data is encrypted in transit by Google. No internet or storage system can be guaranteed to be completely secure, but we use these safeguards to reduce unauthorized access, loss, misuse, or alteration.
Age-related availability and safeguards
The current Service is available only to users aged 13 or older. The Application offers only the 13–15, 16–17, and 18-and-older groups; a person under 13 is not eligible to use the Service and must not select an inaccurate group. Google Play’s content rating and target-audience settings do not replace this eligibility rule or guarantee that every under-13 installation is blocked.
Where applicable law requires a parent or legal guardian to review these terms, authorize a purchase, or otherwise act for a user who has not reached legal adulthood, that review or authorization is still required.
If you believe information from an under-13 user reached Firebase, RevenueCat, AdMob, external speech recognition, or another provider path, contact support@urflashcards.com so we can investigate and delete information controlled by URflashcards where appropriate.
Provider locations can vary
URflashcards and its service providers may process information in countries other than your own. Depending on the provider and destination, transfers may rely on an adequacy decision, contractual safeguards, or another transfer mechanism recognized by applicable law. Provider terms and privacy notices describe their processing locations and safeguards.
External websites and provider policies
The Service may contain links to websites, Google Play pages, provider policies, email clients, or support pages that are not controlled by URflashcards. We are not responsible for the privacy practices, security, content, or availability of those third-party services.
Updates over time
We may update this Privacy Policy to reflect app changes, provider requirements, legal requirements, security needs, product improvements, or clearer wording. The latest version will be posted on this page with a new date.
An updated acceptance step records the new version only after the required affirmative action.
Privacy questions and deletion requests
For privacy-related questions, data requests, support, or account deletion questions, contact support@urflashcards.com.