Privacy Policy
Last updated: April 25, 2026
Wyld Cardz ("Company," "we," "us," or "our") operates the Wyld Cardz mobile application ("App" or "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App.
By using Wyld Cardz, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not use the App.
1. Information We Collect
1a. Device Identifier
When you first launch Wyld Cardz, the App automatically generates a random anonymous identifier ("Device ID") — a UUID (universally unique identifier). This identifier is:
Stored locally on your device using encrypted local storage
Transmitted to and stored in our database to associate your data with your device
Not linked to your name, email address, or any other personally identifiable information unless you subscribe to a paid plan
If you reset your Device ID or uninstall the app, a new Device ID is generated on next launch. Historical data associated with the old Device ID cannot be recovered.
1b. Email Address (Subscribers Only)
If you subscribe to a paid plan, you provide an email address through Stripe's checkout process. We receive your email address from Stripe and use it to:
Send billing receipts and invoices
Notify you of subscription renewals, cancellations, or changes
Respond to support and billing inquiries
Notify you of material changes to our Terms or Privacy Policy (where required)
You cannot use a paid subscription without providing an email address.
1c. Camera Access and Images You Upload
Wyld Cardz requires access to your device's camera and photo library to enable its core functionality — capturing images of study materials (textbooks, notes, diagrams) and converting them into digital flashcards.
Purpose: The camera and photo library are used solely to capture or select images of text and study materials at your explicit direction. We do not access your camera or photos at any other time or for any other purpose.
Data Handling: Images are transmitted over HTTPS to our secure backend servers, where they are forwarded to Anthropic's Claude API for AI-based text extraction and flashcard generation. Images are never used for advertising, profiling, or any purpose other than generating the flashcards you requested.
Storage: We do not store your raw images on our servers longer than is necessary to complete the conversion process. Once your flashcards are generated and saved, the original image is immediately discarded. We do not retain copies of your photos and we do not sell or share your image data with third-party advertisers.
User Control: Camera and photo library permissions are optional — you can grant or revoke them at any time through your device's system settings (Settings → Wyld Cardz). Revoking access only prevents future image-based flashcard creation; it does not affect flashcard bundles you have already created.
You should not upload images containing sensitive personal information (government IDs, financial documents, medical records, etc.).
1d. Flashcard and Bundle Data
The flashcard content generated from your images — including card text, bundle titles, and subject labels — is stored in our database and linked to your Device ID. This data is retained to provide you access to your study materials across app sessions.
1e. Study Progress and Gamification Data
If you use the Practice features, we store the following data linked to your Device ID:
Your daily study streak count
Total XP (experience points) earned
Per-card mastery status ("Got it" / "Still Learning")
Date of last daily review completion
This data is used to power the app's gamification features and is not used for advertising or profiling purposes.
1f. Usage and Technical Data
We collect limited technical data to operate and improve the Service, including:
Number of bundles created in the current billing period (for subscription limit enforcement)
Bundle creation timestamps
Error logs and crash reports (which may include device OS version and app version, but not personal identity)
We do not collect precise geolocation data, advertising identifiers (IDFA/GAID), or behavioral analytics.
2. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, our legal basis for processing your personal data is:
Data | Legal Basis
Device ID and usage data
Legitimate interests — operating and improving the Service
Email address (subscribers)
Contract performance — fulfilling your subscription
Images (transient processing)
Contract performance — generating the flashcards you requested
Progress and gamification data
Legitimate interests — providing the features you use
Device ID and usage data | Legitimate interests — operating and improving the Service
Email address (subscribers) | Contract performance — fulfilling your subscription
Images (transient processing) | Contract performance — generating the flashcards you requested
Progress and gamification data | Legitimate interests — providing the features you use
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your data protection rights.
3. How We Use Your Information
We use the information we collect to:
Generate flashcards from your uploaded images
Store and display your flashcard bundles and study progress
Manage your subscription, process payments, and send billing communications
Enforce subscription plan limits (bundle quotas)
Detect, prevent, and respond to fraud, abuse, or security incidents
Improve and optimize the performance and reliability of the Service
Comply with legal obligations
We do not use your data for:
Targeted advertising or ad retargeting
Selling your personal data to third parties
Building user profiles for marketing purposes
Training AI models on your uploaded images (see Section 4b)
4. Third-Party Services and Data Sharing
We do not sell your personal data. We share limited data with the following trusted third-party service providers solely to operate the Service.
4a. Stripe, Inc. (Payment Processing)
Purpose: Processing subscription payments and managing billing.
When you subscribe to a paid plan, you are directed to a payment page hosted by Stripe. We share your email address and Device ID with Stripe to create and manage your subscription. Stripe directly collects your payment card details, billing address, and other payment information.
Stripe may collect and process the following in connection with your subscription:
Name (if provided during checkout)
Email address
Payment card details (collected and stored by Stripe, not us)
Billing address
IP address and device/browser information (for fraud prevention)
This data is governed by Stripe's Privacy Policy, available at https://stripe.com/privacy. By subscribing, you acknowledge that your payment data will be shared between Wyld Cardz and Stripe for billing and subscription management purposes. Stripe is a certified PCI DSS Level 1 service provider.
4b. Anthropic, PBC (AI Processing)
Purpose: Generating flashcards from your uploaded images.
Images you upload are transmitted to Anthropic's Claude API for AI-based analysis and content generation. Anthropic processes your images solely to return generated flashcard content. We do not share your Device ID, email, or any other identifying information with Anthropic alongside image data.
Anthropic's data handling is governed by their Privacy Policy at https://anthropic.com/legal/privacy and their Usage Policy at https://anthropic.com/legal/usage-policy.
Note on AI training: Anthropic's API terms state that data submitted via the API is not used to train their models by default. We do not authorize the use of your images for model training purposes.
4c. Supabase, Inc. (Database and Backend Infrastructure)
Purpose: Storing flashcard bundles, device records, subscription status, and study progress.
Your Device ID, bundle data, flashcard content, subscription information, and gamification data are stored in databases hosted on Supabase's infrastructure. Supabase stores data in the United States (AWS us-east-1 region unless otherwise configured).
Supabase's data handling is governed by their Privacy Policy at https://supabase.com/privacy and their DPA (Data Processing Agreement).
4d. Expo and EAS (App Distribution)
Purpose: Building, distributing, and updating the App.
Wyld Cardz is built using the Expo platform. Expo/EAS may collect diagnostic information such as app version and build metadata. This is governed by Expo's Privacy Policy at https://expo.dev/privacy.
4e. Apple App Store and Google Play
Purpose: App distribution and in-app purchase infrastructure.
If you download the App from the Apple App Store or Google Play Store, those platforms may collect usage data in accordance with their own privacy policies. We do not control data collected by Apple or Google through their platform services.
4f. Legal Disclosures
We may disclose your information if required to do so by law, court order, or governmental authority, or if we believe in good faith that such disclosure is necessary to: (a) comply with a legal obligation; (b) protect our rights or property; (c) prevent fraud or security threats; or (d) protect the safety of users or the public.
4g. Business Transfers
In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred to the acquiring entity. We will notify you via the email address associated with your subscription (if applicable) before your data is transferred and becomes subject to a different privacy policy.
5. Data Retention
Data Type | Retention Period
Device ID and anonymous usage data
Retained as long as associated bundles exist; orphaned Device IDs (no bundles, no subscription) may be purged after 12 months of inactivity
Flashcard bundles and cards
Retained until you delete them or delete the app
Email address (subscribers)
Retained for the duration of your subscription and up to 7 years thereafter for tax, legal, and accounting purposes
Stripe payment records
Retained by Stripe per their retention policy; we retain billing references for 7 years
Card progress / gamification data
Retained as long as your Device ID is active
Uploaded images
Not retained — deleted immediately after flashcard generation
Error logs
Retained for up to 90 days
Device ID and anonymous usage data | Retained as long as associated bundles exist; orphaned Device IDs (no bundles, no subscription) may be purged after 12 months of inactivity
Flashcard bundles and cards | Retained until you delete them or delete the app
Email address (subscribers) | Retained for the duration of your subscription and up to 7 years thereafter for tax, legal, and accounting purposes
Stripe payment records | Retained by Stripe per their retention policy; we retain billing references for 7 years
Card progress / gamification data | Retained as long as your Device ID is active
Uploaded images | Not retained — deleted immediately after flashcard generation
Error logs | Retained for up to 90 days
When you delete a bundle, associated flashcard data is permanently deleted. When you reset your Device ID via the App's settings, a new Device ID is generated; the old Device ID and its data are not immediately deleted but become inaccessible from your device. To request permanent deletion, see Section 8.
6. Data Security
We implement industry-standard technical and organizational measures to protect your data, including:
HTTPS/TLS encryption for all data transmitted between the App and our servers
Encrypted local storage for your Device ID on your device
Row-level access controls in our database — your data is only accessible using your Device ID
Stripe PCI DSS compliance for all payment data
Access controls limiting employee access to production data
However, no method of electronic transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. In the event of a data breach affecting your personal data, we will notify affected subscribers as required by applicable law.
7. International Data Transfers
Wyld Cardz is operated from the United States and our service providers are primarily located in the United States. If you are located in the EEA, UK, or other regions with data transfer restrictions, please be aware that your data may be transferred to and processed in countries that may not have the same data protection laws as your country.
Where required, we rely on the following transfer mechanisms:
Standard Contractual Clauses (SCCs) adopted by the European Commission
Adequacy decisions where applicable
Service provider DPAs (Supabase, Stripe, Anthropic)
8. Your Rights
Rights for All Users
You have the right to:
Access the data we hold about you
Delete your data (see below)
Opt out of non-essential communications
To request data deletion, email support@wyldcardz.app with your email address (if a subscriber) or your Device ID. You can find your Device ID in the App's Account settings. We will respond within 30 days.
Note: Because free-tier users interact anonymously, we cannot identify or delete data for users who have not provided an email address and do not know their Device ID.
Rights for EEA / UK Users (GDPR)
If you are in the European Economic Area or United Kingdom, you have the following additional rights under the GDPR / UK GDPR:
Right to rectification — correct inaccurate data
Right to restriction — restrict how we process your data
Right to data portability — receive your data in a structured, machine-readable format
Right to object — object to processing based on legitimate interests
Right to withdraw consent — where processing is based on consent
Right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK, or your national DPA in the EU)
To exercise any of these rights, contact us at support@wyldcardz.app.
Rights for California Residents (CCPA / CPRA)
If you are a California resident, you have the right to:
Know what personal information we collect about you
Delete personal information we have collected
Correct inaccurate personal information
Opt out of the sale or sharing of personal information
We do not sell or share your personal information as defined under the CCPA. We do not use your data for cross-context behavioral advertising.
To exercise your California rights, contact us at support@wyldcardz.app. We will not discriminate against you for exercising these rights.
9. Children's Privacy (COPPA)
Wyld Cardz is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child under 13 has used the App or provided personal information, please contact us immediately at support@wyldcardz.app and we will promptly delete any such information.
If we learn that we have inadvertently collected personal information from a child under 13, we will take steps to delete that information as quickly as possible.
10. Links to Third-Party Sites
The App may contain links to third-party websites or services (such as Stripe's payment pages). We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any personal information.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
Update the "Last updated" date at the top of this document
Notify active subscribers by email (where required by applicable law)
Post the updated policy on our website at wyldcardz.app/privacy
Your continued use of the App after changes are posted constitutes your acceptance of the updated policy.
12. Contact and Data Controller
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Wyld Cardz
Email: support@wyldcardz.app
Website: wyldcardz.app
If you are located in the EU/EEA and we are required to appoint a Data Protection Officer or EU representative, that contact information will be listed here: [DPO/EU Representative contact if applicable]
