Deckberry Privacy Policy

Last updated: 27 July 2026

Deckberry is a flashcard study app for iOS and Android, operated by Onur Ozgur OZKAN, trading as Deckberry (“Deckberry”, “we”, “us”), based in the United Kingdom. This policy explains what personal data we collect through the Deckberry mobile app and the deckberry.com website, why we collect it, and the choices you have.

For any privacy question or request, contact us at hello@deckberry.com.

The short version

Data we collect

Account data

DataWhenWhy
Email addressWhen you register, sign in with an email code, or use Google / Apple sign-inTo identify your account, send sign-in codes, and contact you about your account
Password (stored as a salted hash — we cannot read it)If you choose password sign-inAuthentication
Sign-in tokens and one-time codesWhile signed inKeeping you signed in securely
TimezoneSet by the appScheduling your daily reviews correctly

Sign-in with Google or Apple sends us a signed token from which we read your verified email address. We receive nothing else from your Google or Apple account, and we never receive your Google or Apple password.

Anonymous accounts hold no personal data — only a randomly generated identifier stored on your device.

Study data

To make spaced repetition work across your devices, we store the decks you have added, your per-card study state, a log of your reviews (which card, your rating, and when), and any deck ratings you submit. This data is linked to your account.

Creator content

If you are a deck creator, we store the decks, cards, and media (images, audio) you upload, together with your account, so we can publish them in the catalog under the terms you agreed to as a creator.

Diagnostics

If the app crashes or hits an error, a crash report is sent to Sentry (our error monitoring provider). It contains technical details — device model, operating system version, app version, and the technical trace of the error. Crash reports are used only to fix bugs.

Server logs

Like almost every online service, our servers and our CDN (Cloudflare) keep short-lived technical logs that include your IP address. We use them for security, abuse prevention, and keeping the service running.

Purchases

Subscriptions and in-app purchases are processed entirely by Apple (App Store) or Google (Google Play). We never receive your card number or billing details. We receive only what we need to unlock what you bought: a transaction/entitlement record and its status (active, expired, refunded). Apple’s and Google’s own privacy policies apply to the payment itself.

Install attribution (Android)

If you install the Android app from a link on our website or a deck page, Google Play’s Install Referrer API tells the app which link brought you there and, for a deck’s own page, which deck to open first. This is read and used entirely on your device — Deckberry’s servers never receive it. Once the app knows which deck to show, it asks our API for that deck’s public content, the same request anyone browsing that deck’s page would make.

What we do NOT collect

No advertising identifiers, no analytics or tracking SDKs, no location data, no contacts, no photos (other than media a creator explicitly uploads), no biometric data.

Data stored only on your device

Downloaded decks, media files, and your offline study progress are stored in a local database on your device so you can study without a connection. Sign-in tokens are kept in your device’s secure storage (Keychain on iOS, Keystore on Android). This local data never leaves your device except through the syncing described above, and it is removed when you delete the app.

Under UK GDPR our legal bases are:

Who we share data with

We share personal data only with the service providers (“processors”) that run Deckberry, under contracts limiting them to processing on our instructions:

ProviderPurposeLocation
Hetzner OnlineApplication servers and database hostingEuropean Union (Germany / Finland)
CloudflareCDN, security, and media file storage (R2)Global network; storage configured in the EU
Sentry (Functional Software, Inc.)Crash and error reportingUnited States
Amazon Web Services (SES)Sending transactional email (sign-in codes, account email)United States / EU
Apple / GoogleSign-in (if you use it) and purchase processingPer their own policies

We do not sell personal data, and we do not share it with advertisers or data brokers. We may disclose data if the law requires it, or as part of a business transfer (in which case this policy continues to apply).

International transfers

Our primary infrastructure is in the European Union. Where a provider processes data outside the UK/EEA (for example Sentry and AWS in the United States), the transfer is protected by UK-approved safeguards — the UK International Data Transfer Agreement/Addendum or the EU Standard Contractual Clauses, and, where applicable, the provider’s certification under the EU–US / UK–US Data Privacy Framework.

How long we keep data

Your rights

Under UK GDPR (and the EU GDPR where it applies) you have the right to access, correct, delete, or receive a copy of your personal data, to restrict or object to certain processing, and to withdraw consent. To exercise any of these, email hello@deckberry.com — we respond within one month.

You also have the right to complain to a supervisory authority. In the UK this is the Information Commissioner’s Office (ICO, ico.org.uk); in the EU, your local data protection authority.

Deleting your account

Open the app → Profile → Delete account, or email us at hello@deckberry.com from your account email. Deletion removes your account, study history, and personal data as described in the retention section above. Published decks by creators may remain available to learners who already downloaded them, but are no longer attributed to any personal data.

Children

Deckberry is not directed at children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child under 13 has created an account, contact us at hello@deckberry.com and we will delete it.

Security

Data is encrypted in transit (TLS) and access to production systems is restricted. Passwords are stored only as salted hashes. Sign-in tokens are kept in your device’s secure storage. No system is perfectly secure, but if a breach affects your personal data we will notify you and the regulator as the law requires.

Changes to this policy

If we change this policy, we will update the date at the top and, for material changes, notify you in the app or by email before they take effect.

Contact

Onur Ozgur OZKAN, trading as Deckberry (United Kingdom) Email: hello@deckberry.com Website: https://www.deckberry.com