NuanceDeck

Privacy Policy

Privacy Policy

Last updated: 2026-09-01. This English version is provided for convenience; in case of discrepancy, the French version prevails.

1. Who is responsible

The data controller is CARACARA LABS, SAS, 173 rue de Courcelles, 75017 Paris, France, RCS Paris 107 841 272. For any question about your data: support@nuancedeck.com.

This policy covers the NuanceDeck websites (nuancedeck.com and subdomains), the web application, the mobile applications, and our emails. It applies to visitors and to account holders.

In short: your data is hosted in the European Union; we collect what the Service needs to work and nothing for resale; we use no advertising trackers; session recording on our website runs only if you opt in; you can export and delete your data yourself.

2. What we collect

Account data. Email address, display name, password (stored hashed; we never see it) or, if you sign in with Google, the identifier, name, email and profile picture Google provides. Whether your email is verified. Account settings (theme, gloss language, grading style).

Optional public profile. A username, a country flag and a profile picture (one you upload, or the one Google provides if you signed in with Google), if you choose to set them. They are shown to other learners next to your public contributions. Each can be cleared at any time; a profile picture you upload is stored on our media storage and deleted with your account.

Learning data. Which words you study, your review history (each answer, its grade and time), your daily targets, the words you skipped or prioritized, your decks, your drill results. This is the heart of the Service and it stays private to you (we show aggregate activity to you only).

Ask AI questions. The question text, the sentence it was asked about, the model used, the answer, the credits charged, and your votes on answers. Questions and answers are public: they are shown to other learners on the relevant card and in the community feed, with your username (or a neutral label). Do not put personal data in a question.

Content reports. The reason, your comment, the reported content, and any screenshot or screen recording you attach. Private to our team.

Plan data. Our subscription provider, RevenueCat, keeps a record for every account, free or Premium: your account identifier and your plan, so that your plan follows you between the web and the mobile applications, purchases can be restored, and we can measure how many learners move from the free plan to Premium. In the applications this goes through RevenueCat's software component, which also receives technical details of the installation (platform, application and system version, device model, an application-scoped device identifier, and the country derived from your IP address). Through that component RevenueCat receives neither your email address nor your learning data; if you buy on the web, the checkout page asks for your email address for your receipts.

Billing data. When you buy Premium, our billing providers (RevenueCat, Stripe, or Apple / Google for store purchases) process your payment. We never receive your full card number. We receive and store: the plan, its status and dates, the platform of purchase, and a customer identifier. Stripe collects the billing address needed to compute VAT.

Support. The emails you send us and our replies.

Waitlist. Email address and the page you signed up from, if you joined the pre-launch waitlist.

Technical data. When you use the Service, our API writes one log line per request (date, route, status, response time, request size, whether you were signed in and, if so, your account identifier) and technical traces of how the request was processed, for security, abuse prevention and debugging. Your IP address is not stored in these logs: it is used in memory to limit request rates, and it is seen transiently by our network provider (Cloudflare) when it routes a request to the API. Emails, passwords, message contents and what you type never appear in logs. When an error occurs on our servers or in the applications (a crash on your phone, an error on the web), an error report is sent to our error-monitoring provider with the technical details needed to fix it (error message and stack trace, application and system version, device model, your account identifier), never your email or your content. Session tokens are stored in cookies or secure device storage to keep you signed in.

Website analytics. On nuancedeck.com we use PostHog (EU cloud) in cookieless mode: page views, clicks, and aggregate click and scroll positions (heatmaps) are counted without any cookie or persistent identifier, so visits cannot be linked across sessions and no consent is required for this. You can nevertheless switch heatmaps off at any time from "Privacy settings" in the site footer.

Analytics in the applications. In the NuanceDeck applications (mobile and web app) we use PostHog (EU cloud) to count a small number of coarse product events tied to your account identifier (for example: signed up, finished a review session, opened a card, starred a deck, asked Ask AI, opened the checkout), so that we can see which features are used and where learners stop. There is no session recording and no automatic capture of your taps or typing in the applications, and the content of what you learn or ask is not sent. If you do not want these events collected, write to us at support@nuancedeck.com and we will stop them for your account; crash reports (above) are needed to keep the Service working.

Session recording (only with your consent). If you accept it in the consent prompt shown on nuancedeck.com, PostHog records how you use the site (pages shown, mouse movements, clicks, scrolling) as a replay that we watch to find and fix usability problems. Everything you type is masked in your browser before it is sent, so your email address or any text you enter never appears in a recording. Recordings are stored in the European Union, kept for at most 30 days, and are not linked to a NuanceDeck account. Refusing changes nothing in what you can do on the site; you can refuse or withdraw at any time from "Privacy settings" in the site footer.

We do not knowingly collect data from children under 16. If you believe a child has created an account, write to us and we will delete it.

PurposeDataLegal basis (GDPR art. 6)
Creating and operating your account, delivering the Service, scheduling your reviewsAccount, settings, learning dataPerformance of the contract
Answering your Ask AI questions and showing community threadsQuestions, votes, usernamePerformance of the contract
Managing your plan (free or Premium) across your devices, selling Premium, invoicing, taxPlan data, billing dataPerformance of the contract; legal obligation (accounting, VAT)
Transactional emails (verification, account creation notices, password reset, renewal reminders, invoices)EmailPerformance of the contract; legal obligation
Product news and the waitlist launch emailEmailConsent (withdraw anytime via the unsubscribe link)
Security, abuse and scraping prevention, enforcing our termsTechnical data, usage patterns, watermarks, hashed email of deleted accountsLegitimate interest: protecting the Service and our content
Improving the Service and its content, fixing reported errorsReports, votes, aggregated usage, plan data (how many learners move from free to Premium)Legitimate interest: improving the product
Operating, securing and debugging the Service: request logs, traces, error and crash reportsTechnical data, account identifier, error detailsLegitimate interest: keeping the Service working and secure
Understanding how the applications are used (product analytics)Coarse product events tied to your account identifierLegitimate interest: improving the product (you may object by writing to us)
Measuring the website's audience and how its pages are used (heatmaps)Anonymous, cookieless analyticsLegitimate interest (no consent required for cookieless, aggregate measurement)
Watching session recordings to find and fix usability problems on the websiteRecording of your interactions on the site, typing maskedConsent (withdraw anytime from "Privacy settings")
Answering your requests and exercising your rightsSupport emailsLegal obligation; legitimate interest

We do not use your data for automated decisions producing legal effects on you. The detection of automated access (see our terms, section 13) uses technical signals and always involves a human review before an account is terminated.

4. Who receives it

We share personal data only with providers that process it on our behalf, under contracts that bind them to confidentiality and to the GDPR (art. 28), and only for the purposes above.

ProviderRoleLocation of processing
Railway CorporationHosting of the API and databaseEuropean Union (Netherlands, region europe-west4)
Axiom, Inc.Storage and search of the API's request logs and tracesEuropean Union (EU region)
Functional Software, Inc. (Sentry)Error and crash reports from the API and the applicationsEuropean Union (EU data residency)
Vercel Inc.Hosting of the websites and web applicationEU and US edge network (static pages)
Cloudflare, Inc.Routing of requests to the API (network proxy) and storage and delivery of audio, profile pictures and report attachments (R2)EU / US
Resend Inc.Sending transactional emailsUS
Google LLCSign in with Google (if you use it); Gemini models that answer Ask AI questionsUS
PostHog Inc.Audience measurement and heatmaps of the website, session recordings with your consent, and product analytics in the applicationsEuropean Union (Frankfurt)
RevenueCat Inc.Plan records for every account (free included), subscription management and entitlements, purchase restorationUS
Stripe Inc.Web payments, invoices, VATEU / US
Apple Inc. / Google LLCStore purchases (if you buy in a mobile application)Under their own privacy policies, as independent controllers

Ask AI and Google. The text of your question and the sentence it concerns are sent to Google's Gemini API to generate the answer. We use the API under commercial terms under which Google does not use this data to train its models. Your identity is not sent; only the question and its context.

We do not sell personal data and we do not share it with advertisers. We may disclose data if the law requires it (for example a court order) or to establish or defend our legal rights, including against abuse of the Service.

5. International transfers

Your data is stored in the European Union. Some providers listed above process data in the United States. Those transfers rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses, with additional safeguards where needed. You can obtain a copy of the relevant safeguards by writing to us.

6. How long we keep it

DataRetention
Account, settings, profile picture, learning data, plan record at RevenueCatLife of the account, then deleted 30 days after you delete the account (during those 30 days the account is inaccessible and can be restored by signing back in)
Hashed email of a deleted account (waiting period before the same address can open a new account)30 days after the final deletion; no expiry for an account terminated for abuse (life of the ban)
Ask AI public questions and answersLife of the account; on deletion, your attribution is removed (anonymized) and the text is kept as part of the community content, unless you ask us to delete the text too
Content reports and attachmentsUntil the issue is resolved, at most 24 months
Billing records and invoices10 years (French accounting law)
Support emails3 years after the last exchange
Waitlist emailsUntil the launch email is sent and you unsubscribe, at most 3 years
API request logs and traces, hosting logs30 days
Error and crash reports90 days
Product analytics events from the applications12 months
Session recordings (with your consent)30 days
Your consent choice for session recording6 months, then we ask again
BackupsRolling backups are overwritten within 30 days of deletion

7. Cookies and device storage

We use only what is strictly necessary to run the Service: a session cookie (web) or secure device storage (mobile) to keep you signed in, and local storage for your preferences and cached content. These need no consent. We set no advertising cookies, and the website's audience measurement works without any cookie. Session recording is off until you accept it: if you do, we store your choice on your device for 6 months, and PostHog stores an identifier (cookie or local storage) so that your recording stays continuous while you browse. Both are removed if you withdraw consent from "Privacy settings" in the footer. If we ever add another non-essential tracker, we will ask first and describe it here. A first-party referral code may be stored temporarily if you arrive through a partner link, so that the partner is credited for your signup; it identifies the partner, not you.

8. Your rights

You can, at any time:

  • access the data we hold about you and obtain a copy;
  • export your learning data in a machine-readable format (portability), from the application settings or by request;
  • rectify inaccurate data (most of it directly in the application);
  • delete your account and data, from the application settings or by request;
  • object to processing based on our legitimate interests, and restrict processing in the cases provided by law;
  • withdraw consent to product emails at any time via the unsubscribe link, and to session recording from "Privacy settings";
  • give instructions about your data after your death (French Data Protection Act, art. 85).

Write to support@nuancedeck.com from your account's email address. We answer within one month. If you are not satisfied, you may lodge a complaint with the French supervisory authority, the CNIL (cnil.fr), or with the authority of your country of residence.

9. Security

Data is transmitted over TLS and stored in access-controlled infrastructure in the EU; passwords are hashed; payment data never reaches our servers; access to production is restricted to the people who operate the Service. No system is perfectly secure. If a breach affecting your data occurs, we will notify the CNIL and, where required, you, in accordance with the GDPR.

10. Changes

We will update this policy when the Service or the law changes. Material changes are announced in the application or by email before they apply. If the operation of the Service is transferred to another company, that company becomes the data controller under this policy and we will inform you beforehand. The current version, with its date, is always available at nuancedeck.com/en/privacy.

11. Contact

CARACARA LABS, 173 rue de Courcelles, 75017 Paris, France. support@nuancedeck.com.