Privacy Policy
Privacy Policy
Last updated: 2026-09-01. This English version is provided for convenience; in case of discrepancy, the French version prevails.
1. Who is responsible
The data controller is CARACARA LABS, SAS, 173 rue de Courcelles, 75017 Paris, France, RCS Paris 107 841 272. For any question about your data: support@nuancedeck.com.
This policy covers the NuanceDeck websites (nuancedeck.com and subdomains), the web application, the mobile applications, and our emails. It applies to visitors and to account holders.
In short: your data is hosted in the European Union; we collect what the Service needs to work and nothing for resale; we use no advertising trackers; session recording on our website runs only if you opt in; you can export and delete your data yourself.
2. What we collect
Account data. Email address, display name, password (stored hashed; we never see it) or, if you sign in with Google, the identifier, name, email and profile picture Google provides. Whether your email is verified. Account settings (theme, gloss language, grading style).
Optional public profile. A username, a country flag and a profile picture (one you upload, or the one Google provides if you signed in with Google), if you choose to set them. They are shown to other learners next to your public contributions. Each can be cleared at any time; a profile picture you upload is stored on our media storage and deleted with your account.
Learning data. Which words you study, your review history (each answer, its grade and time), your daily targets, the words you skipped or prioritized, your decks, your drill results. This is the heart of the Service and it stays private to you (we show aggregate activity to you only).
Ask AI questions. The question text, the sentence it was asked about, the model used, the answer, the credits charged, and your votes on answers. Questions and answers are public: they are shown to other learners on the relevant card and in the community feed, with your username (or a neutral label). Do not put personal data in a question.
Content reports. The reason, your comment, the reported content, and any screenshot or screen recording you attach. Private to our team.
Plan data. Our subscription provider, RevenueCat, keeps a record for every account, free or Premium: your account identifier and your plan, so that your plan follows you between the web and the mobile applications, purchases can be restored, and we can measure how many learners move from the free plan to Premium. In the applications this goes through RevenueCat's software component, which also receives technical details of the installation (platform, application and system version, device model, an application-scoped device identifier, and the country derived from your IP address). Through that component RevenueCat receives neither your email address nor your learning data; if you buy on the web, the checkout page asks for your email address for your receipts.
Billing data. When you buy Premium, our billing providers (RevenueCat, Stripe, or Apple / Google for store purchases) process your payment. We never receive your full card number. We receive and store: the plan, its status and dates, the platform of purchase, and a customer identifier. Stripe collects the billing address needed to compute VAT.
Support. The emails you send us and our replies.
Waitlist. Email address and the page you signed up from, if you joined the pre-launch waitlist.
Technical data. When you use the Service, our API writes one log line per request (date, route, status, response time, request size, whether you were signed in and, if so, your account identifier) and technical traces of how the request was processed, for security, abuse prevention and debugging. Your IP address is not stored in these logs: it is used in memory to limit request rates, and it is seen transiently by our network provider (Cloudflare) when it routes a request to the API. Emails, passwords, message contents and what you type never appear in logs. When an error occurs on our servers or in the applications (a crash on your phone, an error on the web), an error report is sent to our error-monitoring provider with the technical details needed to fix it (error message and stack trace, application and system version, device model, your account identifier), never your email or your content. Session tokens are stored in cookies or secure device storage to keep you signed in.
Website analytics. On nuancedeck.com we use PostHog (EU cloud) in cookieless mode: page views, clicks, and aggregate click and scroll positions (heatmaps) are counted without any cookie or persistent identifier, so visits cannot be linked across sessions and no consent is required for this. You can nevertheless switch heatmaps off at any time from "Privacy settings" in the site footer.
Analytics in the applications. In the NuanceDeck applications (mobile and web app) we use PostHog (EU cloud) to count a small number of coarse product events tied to your account identifier (for example: signed up, finished a review session, opened a card, starred a deck, asked Ask AI, opened the checkout), so that we can see which features are used and where learners stop. There is no session recording and no automatic capture of your taps or typing in the applications, and the content of what you learn or ask is not sent. If you do not want these events collected, write to us at support@nuancedeck.com and we will stop them for your account; crash reports (above) are needed to keep the Service working.
Session recording (only with your consent). If you accept it in the consent prompt shown on nuancedeck.com, PostHog records how you use the site (pages shown, mouse movements, clicks, scrolling) as a replay that we watch to find and fix usability problems. Everything you type is masked in your browser before it is sent, so your email address or any text you enter never appears in a recording. Recordings are stored in the European Union, kept for at most 30 days, and are not linked to a NuanceDeck account. Refusing changes nothing in what you can do on the site; you can refuse or withdraw at any time from "Privacy settings" in the site footer.
We do not knowingly collect data from children under 16. If you believe a child has created an account, write to us and we will delete it.
3. Why we use it and on what legal basis
| Purpose | Data | Legal basis (GDPR art. 6) |
|---|---|---|
| Creating and operating your account, delivering the Service, scheduling your reviews | Account, settings, learning data | Performance of the contract |
| Answering your Ask AI questions and showing community threads | Questions, votes, username | Performance of the contract |
| Managing your plan (free or Premium) across your devices, selling Premium, invoicing, tax | Plan data, billing data | Performance of the contract; legal obligation (accounting, VAT) |
| Transactional emails (verification, account creation notices, password reset, renewal reminders, invoices) | Performance of the contract; legal obligation | |
| Product news and the waitlist launch email | Consent (withdraw anytime via the unsubscribe link) | |
| Security, abuse and scraping prevention, enforcing our terms | Technical data, usage patterns, watermarks, hashed email of deleted accounts | Legitimate interest: protecting the Service and our content |
| Improving the Service and its content, fixing reported errors | Reports, votes, aggregated usage, plan data (how many learners move from free to Premium) | Legitimate interest: improving the product |
| Operating, securing and debugging the Service: request logs, traces, error and crash reports | Technical data, account identifier, error details | Legitimate interest: keeping the Service working and secure |
| Understanding how the applications are used (product analytics) | Coarse product events tied to your account identifier | Legitimate interest: improving the product (you may object by writing to us) |
| Measuring the website's audience and how its pages are used (heatmaps) | Anonymous, cookieless analytics | Legitimate interest (no consent required for cookieless, aggregate measurement) |
| Watching session recordings to find and fix usability problems on the website | Recording of your interactions on the site, typing masked | Consent (withdraw anytime from "Privacy settings") |
| Answering your requests and exercising your rights | Support emails | Legal obligation; legitimate interest |
We do not use your data for automated decisions producing legal effects on you. The detection of automated access (see our terms, section 13) uses technical signals and always involves a human review before an account is terminated.
4. Who receives it
We share personal data only with providers that process it on our behalf, under contracts that bind them to confidentiality and to the GDPR (art. 28), and only for the purposes above.
| Provider | Role | Location of processing |
|---|---|---|
| Railway Corporation | Hosting of the API and database | European Union (Netherlands, region europe-west4) |
| Axiom, Inc. | Storage and search of the API's request logs and traces | European Union (EU region) |
| Functional Software, Inc. (Sentry) | Error and crash reports from the API and the applications | European Union (EU data residency) |
| Vercel Inc. | Hosting of the websites and web application | EU and US edge network (static pages) |
| Cloudflare, Inc. | Routing of requests to the API (network proxy) and storage and delivery of audio, profile pictures and report attachments (R2) | EU / US |
| Resend Inc. | Sending transactional emails | US |
| Google LLC | Sign in with Google (if you use it); Gemini models that answer Ask AI questions | US |
| PostHog Inc. | Audience measurement and heatmaps of the website, session recordings with your consent, and product analytics in the applications | European Union (Frankfurt) |
| RevenueCat Inc. | Plan records for every account (free included), subscription management and entitlements, purchase restoration | US |
| Stripe Inc. | Web payments, invoices, VAT | EU / US |
| Apple Inc. / Google LLC | Store purchases (if you buy in a mobile application) | Under their own privacy policies, as independent controllers |
Ask AI and Google. The text of your question and the sentence it concerns are sent to Google's Gemini API to generate the answer. We use the API under commercial terms under which Google does not use this data to train its models. Your identity is not sent; only the question and its context.
We do not sell personal data and we do not share it with advertisers. We may disclose data if the law requires it (for example a court order) or to establish or defend our legal rights, including against abuse of the Service.
5. International transfers
Your data is stored in the European Union. Some providers listed above process data in the United States. Those transfers rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses, with additional safeguards where needed. You can obtain a copy of the relevant safeguards by writing to us.
6. How long we keep it
| Data | Retention |
|---|---|
| Account, settings, profile picture, learning data, plan record at RevenueCat | Life of the account, then deleted 30 days after you delete the account (during those 30 days the account is inaccessible and can be restored by signing back in) |
| Hashed email of a deleted account (waiting period before the same address can open a new account) | 30 days after the final deletion; no expiry for an account terminated for abuse (life of the ban) |
| Ask AI public questions and answers | Life of the account; on deletion, your attribution is removed (anonymized) and the text is kept as part of the community content, unless you ask us to delete the text too |
| Content reports and attachments | Until the issue is resolved, at most 24 months |
| Billing records and invoices | 10 years (French accounting law) |
| Support emails | 3 years after the last exchange |
| Waitlist emails | Until the launch email is sent and you unsubscribe, at most 3 years |
| API request logs and traces, hosting logs | 30 days |
| Error and crash reports | 90 days |
| Product analytics events from the applications | 12 months |
| Session recordings (with your consent) | 30 days |
| Your consent choice for session recording | 6 months, then we ask again |
| Backups | Rolling backups are overwritten within 30 days of deletion |
7. Cookies and device storage
We use only what is strictly necessary to run the Service: a session cookie (web) or secure device storage (mobile) to keep you signed in, and local storage for your preferences and cached content. These need no consent. We set no advertising cookies, and the website's audience measurement works without any cookie. Session recording is off until you accept it: if you do, we store your choice on your device for 6 months, and PostHog stores an identifier (cookie or local storage) so that your recording stays continuous while you browse. Both are removed if you withdraw consent from "Privacy settings" in the footer. If we ever add another non-essential tracker, we will ask first and describe it here. A first-party referral code may be stored temporarily if you arrive through a partner link, so that the partner is credited for your signup; it identifies the partner, not you.
8. Your rights
You can, at any time:
- access the data we hold about you and obtain a copy;
- export your learning data in a machine-readable format (portability), from the application settings or by request;
- rectify inaccurate data (most of it directly in the application);
- delete your account and data, from the application settings or by request;
- object to processing based on our legitimate interests, and restrict processing in the cases provided by law;
- withdraw consent to product emails at any time via the unsubscribe link, and to session recording from "Privacy settings";
- give instructions about your data after your death (French Data Protection Act, art. 85).
Write to support@nuancedeck.com from your account's email address. We answer within one month. If you are not satisfied, you may lodge a complaint with the French supervisory authority, the CNIL (cnil.fr), or with the authority of your country of residence.
9. Security
Data is transmitted over TLS and stored in access-controlled infrastructure in the EU; passwords are hashed; payment data never reaches our servers; access to production is restricted to the people who operate the Service. No system is perfectly secure. If a breach affecting your data occurs, we will notify the CNIL and, where required, you, in accordance with the GDPR.
10. Changes
We will update this policy when the Service or the law changes. Material changes are announced in the application or by email before they apply. If the operation of the Service is transferred to another company, that company becomes the data controller under this policy and we will inform you beforehand. The current version, with its date, is always available at nuancedeck.com/en/privacy.
11. Contact
CARACARA LABS, 173 rue de Courcelles, 75017 Paris, France. support@nuancedeck.com.