Privacy Policy

Last updated 10 August 2026

The short version. If you sign in, Bitecards receives your name, email address and Google account ID from Google — nothing else, and never your password. We ask Google for no access to Gmail, Drive, Contacts, Calendar or any other Google service. Your saved cards and preferences are kept in your own browser, not on our servers. We do not sell your data, show you ads, or use your Google information to train AI models.

1. Who this policy covers

Bitecards is an educational flashcard website operated by an individual (“we”, “us”). This policy explains what happens to information about you when you browse the site, sign in with Google, or subscribe. It applies to the Bitecards website and nothing else.

You can read every free preview card without signing in and without an account. Signing in is optional and only needed to unlock the full library.

2. What we collect

2.1 Google account information (only if you sign in)

Sign-in uses Google’s OAuth 2.0 flow. We request three standard scopes — openid, email and profile — and Google returns:

  • your Google account ID (the sub claim), a stable identifier that lets us recognise you on your next visit;
  • your email address, and whether Google has verified it — we reject sign-ins with an unverified email;
  • your display name, shown in the account menu.

We do not receive or store your Google password. We do not request access to any other Google product, and we deliberately do not keep the access tokens Google issues during sign-in, because we never call a Google API on your behalf. We also do not load your Google profile picture, so signing in adds no requests to Google’s servers as you browse.

2.2 Your session cookie

When you sign in we set one cookie holding the three claims above in encrypted, signed form. It is HttpOnly (unreadable by JavaScript), SameSite=Lax, marked Secure over HTTPS, and it expires after 7 days. Signing out deletes it. A few short-lived cookies also exist purely to make the sign-in handshake safe (a CSRF token, and the PKCE, state and nonce values); they are discarded as soon as the handshake completes.

2.3 Information kept in your browser, not by us

The following live in your browser’s local storage and are never transmitted to us:

  • which cards you have saved, and when;
  • your subscription state while subscriptions are still a preview feature;
  • your light / dark / system theme choice.

Clearing your browser storage for this site removes all of it. PDF export is also entirely local — the file is rendered in your browser and never uploaded.

2.4 Analytics and server logs

The site is hosted on Vercel, which records standard request logs (including IP address) for security and debugging, and provides Web Analytics and Speed Insights — aggregate page views and page-performance measurements. If a Google Analytics measurement ID is configured for the site, Google Analytics 4 also collects page views, referring site, approximate location derived from IP address, and device and browser type.

Analytics data is about traffic, not about you personally. It is not linked to your Google account or to your signed-in identity.

3. What we do with it

  • Authenticate you — recognise you across visits without a password.
  • Decide what you can read — free preview cards for everyone, the full library for subscribers.
  • Administer the site — a small allowlist of email addresses can publish decks; the check is made against the email Google verified.
  • Keep the service working and secure — diagnose errors, detect abuse.
  • Understand usage in aggregate — which decks are read, how fast pages load.

We do not sell or rent your information, show you advertising, build advertising profiles, or use your Google account information to develop, improve or train AI or machine-learning models. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

4. Who else processes your information

  • Google LLC — identity provider for sign-in, and Google Analytics where configured.
  • Vercel Inc. — hosting, content delivery, request logs, Web Analytics and Speed Insights.

That is the complete list today. When paid subscriptions launch, a payment processor will be added to it and this policy will be updated first; card details will go directly to that processor and will never reach our servers.

5. How long it is kept

Today Bitecards has no user database. Signing in produces a session cookie and nothing else — when the cookie expires or you sign out, no record of your visit remains except the aggregate analytics and Vercel’s short-lived request logs. Analytics retention follows each provider’s own defaults.

6. What changes when accounts are stored

We are building towards saved cards that follow you between devices and a real paid subscription, which requires storing account records on our side. When that happens, we expect to store, per account:

  • your Google account ID, email address and display name;
  • your subscription status and the reference the payment processor uses to identify you — not your card details;
  • activity metadata tied to your account, such as which cards you have saved and which decks you have opened.

Nothing in that list is stored yet. This section will be revised — with the “last updated” date changed — before any of it takes effect, and the retention and deletion promises in this policy will apply to it from day one.

7. Your choices and rights

  • Sign out at any time from the account menu; this deletes the session cookie.
  • Revoke our access to your Google account at myaccount.google.com/permissions.
  • Clear what is stored locally by clearing site data in your browser.
  • Opt out of Google Analytics with Google’s browser opt-out add-on, or by blocking analytics scripts.
  • Ask us for access, correction, export or deletion of anything we hold about you, or object to a particular use, by emailing rahulseh1998@gmail.com. We will respond within 30 days. While there is no user database there is generally nothing for us to return or erase, and we will tell you so plainly.

If you are in the UK, EEA or a jurisdiction with comparable law: we process your Google account information to perform the agreement described in our Terms of Service, rely on legitimate interests for security and abuse prevention, and rely on consent for analytics where consent is required. You may withdraw consent or lodge a complaint with your local data protection authority at any time.

8. Security

Traffic is served over HTTPS. The session cookie is encrypted and signed, so its contents cannot be read or altered by anyone who obtains it; a tampered cookie is treated as no cookie at all. We request the narrowest Google scopes that make sign-in work, hold no passwords, and keep no Google access tokens. No system is perfectly secure, and we do not claim otherwise.

9. International transfers

Our hosting and analytics providers are based in the United States and information may be processed there. Where required, transfers rely on the safeguards those providers publish, such as the European Commission’s standard contractual clauses.

10. Children

Bitecards is not directed to children. Do not sign in if you are under 13, or under 16 in the UK and EEA. If we learn that we hold information about a child, we will delete it.

11. Changes to this policy

We will update this page when our practices change, and change the “last updated” date at the top. Material changes — in particular the account storage described in section 6 — will be reflected here before they take effect.

12. Contact

For any privacy question or request, email rahulseh1998@gmail.com.

Questions about this document? Email rahulseh1998@gmail.com.