Privacy Policy

Effective Date: January 1, 2025
Last Updated: January 21, 2025
Version: 2.0
IMPORTANT: This Privacy Policy is a legally binding agreement. By using Surge Flashcards, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, you must immediately discontinue use of our Service.

1. Introduction and Scope

This Privacy Policy governs the collection, use, storage, disclosure, and protection of personal information by Surge Flashcards LLC ("we," "our," "us," or "Company") in connection with our mobile application, web application, and related services (collectively, the "Service" or "Platform").

Legal Entity: This Privacy Policy is issued by Surge Flashcards LLC, operating under applicable laws and regulations.

Jurisdiction: This Privacy Policy is designed to comply with applicable privacy and data protection laws including, but not limited to, the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), Children's Online Privacy Protection Act (COPPA), and other applicable federal, state, and international data protection laws.

2. Information We Collect

2.1 Information You Provide Directly

When you create an account and use our Service, we collect:

2.2 Information Collected Automatically

When you access or use our Service, we automatically collect:

2.3 Information from Third-Party Services

Data Minimization Principle: We collect only the minimum information necessary to provide and improve our Service. We do not collect sensitive personal information such as financial account numbers, social security numbers, biometric data, or health information.

3. How We Use Your Information

We use your information for the following lawful purposes:

3.1 Service Provision and Operation

3.2 Communication

3.3 Service Improvement and Development

3.4 Security and Fraud Prevention

3.5 Legal Compliance

4. Payment Processing

WE DO NOT STORE, PROCESS, OR HAVE ACCESS TO YOUR PAYMENT CARD INFORMATION.

4.1 Stripe Payment Processing

All payment transactions are processed exclusively through Stripe, Inc., a third-party Payment Card Industry Data Security Standard (PCI DSS) Level 1 certified payment processor.

Information Handled by Stripe:

Information We Receive from Stripe:

We explicitly DO NOT:

Stripe's privacy policy governs their collection and use of your payment information. We encourage you to review Stripe's Privacy Policy at https://stripe.com/privacy.

4.2 Purchase Information We Store

We store the following purchase-related information in our secure database:

5. Third-Party Services and Data Sharing

WE DO NOT SELL, RENT, OR TRADE YOUR PERSONAL INFORMATION TO THIRD PARTIES FOR THEIR MARKETING PURPOSES.

5.1 Service Providers We Use

Service Provider Purpose Data Shared
Supabase Database hosting, authentication, backend infrastructure Account info, user content, usage data
Stripe Payment processing Transaction details (NOT card data)
Anthropic (Claude) AI content generation User prompts, generated content (anonymized)
Grok AI (xAI) AI content generation User prompts, generated content (anonymized)
Firebase (Google) Web hosting, analytics Usage data, performance metrics
InfoLinks Web advertising (free tier users only) Ad impressions, clicks, device info
Unity Ads Mobile advertising (free tier users only) Ad impressions, clicks, device info

Data Processing Agreements: We maintain data processing agreements with all service providers that handle personal information on our behalf, ensuring they comply with applicable data protection laws.

5.2 AI Content Generation

AI Processing Notice: When you use AI-powered features to generate flashcards or content, your prompts and the generated content are processed by third-party AI service providers (Anthropic Claude, Grok AI). While we do not share your personal identifying information with these providers, your content prompts may be processed according to their respective privacy policies and terms of service.

We Do Not Share with AI Providers:

We May Share with AI Providers:

5.3 Advertising (Free Tier Users Only)

If you use the free tier of our Service, we display advertisements through InfoLinks on web and Unity Ads on mobile platforms (iOS and Android). These ad networks may:

Paid Tier Users: If you subscribe to a paid tier, we do not display advertisements, and ad network tracking does not apply.

Ad Network Privacy Policies:

5.4 Legal Disclosures

We may disclose your information if required by law or if we believe in good faith that such disclosure is necessary to:

5.5 Business Transfers

In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy, your personal information may be transferred to the successor entity. We will provide notice before your information is transferred and becomes subject to a different privacy policy.

6. Data Storage and Security

6.1 Where Your Data is Stored

Your data is stored on secure servers provided by Supabase, which utilizes Amazon Web Services (AWS) infrastructure. Data may be processed and stored in multiple geographic locations to ensure redundancy and service availability.

6.2 Security Measures

We implement industry-standard security measures to protect your information:

Security Disclaimer: While we implement robust security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your information. You acknowledge and accept this inherent risk when using our Service.

6.3 Data Breach Notification

In the event of a data breach that compromises your personal information, we will:

  1. Investigate the breach and assess the impact within 72 hours
  2. Notify affected users via email within the timeframe required by applicable law
  3. Report the breach to relevant regulatory authorities as required
  4. Take immediate remedial action to prevent further unauthorized access
  5. Provide information about steps you can take to protect yourself

7. Data Retention and Deletion

7.1 Retention Periods

We retain your information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

Data Type Retention Period Reason
Account Information Duration of account + 90 days after deletion Service provision, legal compliance
User Content (Flashcards, Decks) Duration of account + immediate deletion upon request Service provision
Transaction Records 7 years Tax and financial compliance
Support Communications 3 years Customer service, dispute resolution
Analytics Data (Anonymized) Indefinite Service improvement (cannot be linked to individuals)
Security Logs 1 year Security monitoring, fraud prevention

7.2 Account Deletion

You may request deletion of your account at any time by:

Account Deletion is Permanent and Irreversible. Upon account deletion:

7.3 Data You Can Delete

You can delete the following data directly from the app at any time:

8. Your Rights and Choices

8.1 Access and Correction

You have the right to:

To exercise these rights, email us at legal@surgeflashcards.com or use the in-app settings.

8.2 Data Portability

You have the right to receive a copy of your personal information in a structured, commonly used, and machine-readable format.

What You Can Export: What Cannot Be Exported:

Note: Flashcards, quizzes, and study data can be deleted by you at any time but cannot be downloaded or exported. This data is permanently deleted upon account deletion.

8.3 Opt-Out Rights

8.4 California Residents (CCPA Rights)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

To exercise CCPA rights, email legal@surgeflashcards.com with "CCPA Request" in the subject line.

8.5 European Residents (GDPR Rights)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR):

Legal Basis for Processing (GDPR):

9. International Data Transfers

Surge Flashcards operates globally. Your information may be transferred to, stored, and processed in the United States and other countries where our service providers operate.

Data Transfer Safeguards:

By using our Service, you acknowledge and consent to the transfer of your information to countries outside your country of residence, which may have different data protection laws.

10. Children's Privacy (COPPA Compliance)

Our Service is NOT intended for children under the age of 13. We do not knowingly collect personal information from children under 13.

If you are under 13: Do not use our Service, create an account, or provide any personal information.

If you are a parent or guardian: If you believe your child under 13 has provided personal information to us, please contact us immediately at legal@surgeflashcards.com. We will promptly delete such information.

Users aged 13-17: If you are between 13 and 17 years old, you should review this Privacy Policy with your parent or guardian and obtain their permission before using our Service.

11. Cookies and Tracking Technologies

11.1 What Are Cookies?

Cookies are small text files stored on your device that help us provide and improve our Service. We use cookies and similar tracking technologies (web beacons, pixels, local storage) to collect usage information.

11.2 Types of Cookies We Use

Cookie Type Purpose Duration
Essential Cookies Authentication, security, core functionality Session / Persistent
Analytics Cookies Usage statistics, performance monitoring Persistent (up to 2 years)
Advertising Cookies Ad delivery and tracking (free tier only) Persistent (up to 1 year)
Preference Cookies Remembering your settings and preferences Persistent (up to 1 year)

11.3 Managing Cookies

You can control cookies through your browser settings:

Note: Blocking essential cookies may prevent you from using certain features of our Service.

11.4 Third-Party Cookies

Third-party services we use (InfoLinks, Unity Ads, Google Analytics) may set their own cookies. We do not control these cookies. Please review the privacy policies of these third parties.

12. Do Not Track Signals

Some browsers support "Do Not Track" (DNT) signals. Our Service does not currently respond to DNT signals because there is no industry standard for how to interpret them. If a legal standard for DNT is established, we will update our practices accordingly.

13. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or Service features.

How We Notify You of Changes:

Your continued use of the Service after the effective date of the revised Privacy Policy constitutes your acceptance of the changes. If you do not agree to the updated Privacy Policy, you must stop using our Service and may delete your account.

14. Contact Information and Data Protection Officer

For Privacy Questions, Concerns, or Data Rights Requests:

Email: legal@surgeflashcards.com

Subject Line: "Privacy Inquiry" or "Data Rights Request"

We will respond to all legitimate requests within 30 days (or as required by applicable law).

15. Dispute Resolution and Governing Law

Any disputes arising from this Privacy Policy or our data practices shall be governed by the laws of the jurisdiction specified in our Terms of Service, without regard to conflict of law principles.

EU/EEA Residents: You have the right to lodge a complaint with your local supervisory authority if you believe we have violated your data protection rights.

16. Limitations of Liability

DISCLAIMER: TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW:

17. Severability

If any provision of this Privacy Policy is found to be unenforceable or invalid, that provision will be limited or eliminated to the minimum extent necessary, and the remaining provisions will remain in full force and effect.