Privacy Policy
Last updated: July 24, 2026
This Privacy Policy explains how Yurii Pylyponiuk ("StudySwipe", "we", "us") handles personal information when you use StudySwipe Flashcards, our website, and related support services. Most learning data stays on your device, but optional AI, subscription, advertising, and support features use the services described below.
Controller and contact
Yurii Pylyponiuk, based in the Netherlands, is the controller of the personal information described in this policy. Privacy requests can be sent to support@pyronix-moneyflow.com.
If you are in the EEA, UK, or Switzerland, you may also complain to the data protection authority where you live or work. We will add any legally required local representative or data protection contact here if our operations make one necessary.
Information that stays on your device
Decks, cards, study history, progress, streaks, quests, energy state, notification preferences, language, theme, and other settings are stored locally. We do not require an account for the core app.
Learning data remains until you reset it in the app, uninstall the app, or erase the device. Reset all data keeps your selected language and completed-onboarding preference. Apple device backups may retain app data according to your Apple and device settings.
Information we process
- AI deck creation: images you select, image metadata needed to decode the files, extracted study content, prompts, and generated cards.
- Subscriptions and quotas: a pseudonymous RevenueCat app user identifier, product and entitlement status, purchase history, and a monthly AI-usage counter.
- Advertising and consent: consent choices, device or advertising identifiers where permitted, coarse location derived from network information, ad interactions, advertising data, and performance or crash diagnostics.
- Network and security data: IP address, request time, app or device details sent by network protocols, and limited service logs used for security, abuse prevention, and reliability.
- Support: your email address and any information, screenshots, or diagnostic details you choose to send us.
How we use information and our legal bases
- Provide requested app features, AI deck generation, subscriptions, purchase restoration, and support (performance of our contract).
- Protect the app, enforce quotas, prevent abuse, troubleshoot failures, and maintain service reliability (our legitimate interests and, where applicable, legal obligations).
- Serve and measure ads, store consent choices, and access advertising identifiers where required (consent). You may withdraw consent without affecting earlier lawful processing.
- Comply with tax, consumer-protection, law-enforcement, and other legal requirements (legal obligation).
AI deck creation
Images are uploaded only after you choose the AI deck feature. Our backend processes them in memory and sends them to OpenAI to generate flashcards. We configure the OpenAI Responses API not to store response application state. OpenAI may retain limited abuse-monitoring logs for up to 30 days unless law or an approved zero-data-retention arrangement requires otherwise.
We do not use your images or generated cards to train our own models. OpenAI states that API business data is not used to train its models by default. Do not upload confidential, regulated, or third-party material unless you have permission to process it.
Purchases and subscriptions
Apple processes App Store payments. RevenueCat helps validate purchases and provide Pro entitlements. We do not receive your full payment-card details.
Our backend temporarily caches Pro status for about five minutes and retains a pseudonymous monthly AI-usage counter for about 35 days. Apple and RevenueCat retain transaction records under their own legal obligations and policies.
Advertising, tracking, and consent
Free users may choose to watch rewarded ads supplied by Google AdMob. The app uses Google User Messaging Platform to request consent where required and provides an in-app Ad Privacy Choices control. On iOS, Apple App Tracking Transparency controls access to the advertising identifier for tracking.
Google's iOS privacy manifest identifies possible collection of device identifiers, advertising data, product interactions, coarse location, crash data, performance data, and other diagnostics. Some data may be linked to a device and used for third-party advertising or measurement. Your available choices depend on region, consent, device settings, and the ad-serving mode.
Service providers and disclosures
We may also disclose information when required by law, to protect users or the service, or as part of a business reorganization subject to appropriate safeguards. We do not disclose your on-device decks because we do not receive them unless you choose an online feature or send them to support.
- Apple: app distribution, payments, subscription management, and device services.
- OpenAI: AI image and text processing for deck generation.
- RevenueCat: subscription validation, entitlement management, and purchase analytics.
- Google AdMob and User Messaging Platform: rewarded ads, consent management, measurement, fraud prevention, and diagnostics.
- Vercel and Upstash: backend hosting, security logs, and pseudonymous quota or entitlement-cache storage.
Retention
- On-device learning data: until you reset the app, uninstall it, or erase the device or backup.
- AI request data on our backend: held in memory for the request and not intentionally persisted; provider abuse-monitoring logs may remain for up to 30 days.
- Pseudonymous quota counters: about 35 days; Pro-status cache: about five minutes.
- Support messages and security records: only as long as reasonably needed to resolve the request, protect the service, and meet legal requirements.
- Advertising, purchase, and infrastructure records: according to the provider's published retention rules and applicable law.
International transfers
Our providers may process information in the United States and other countries. Where EU, UK, or Swiss transfer rules apply, we rely on adequacy decisions, approved standard contractual clauses, the EU-U.S. Data Privacy Framework where valid and applicable, or another lawful transfer mechanism, together with supplementary safeguards where needed.
Your EEA, UK, and Swiss rights
Depending on the law and circumstances, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent; and complain to a regulator. Email support@pyronix-moneyflow.com. Because most learning data is local, the fastest deletion method is Settings → Account → Reset all data.
We do not make decisions producing legal or similarly significant effects solely through automated processing. AI-generated flashcards may be inaccurate and should be reviewed by you.
United States privacy rights
Residents of California and other covered states may have rights to know, access, correct, delete, or obtain a copy of personal information and to opt out of certain targeted advertising, sale, sharing, or profiling. We do not sell personal information for money. Use of AdMob may be considered sharing or targeted advertising under some state laws.
Use Settings → Privacy & support → Ad Privacy Choices and iOS tracking settings to control advertising, or email support@pyronix-moneyflow.com. We honor applicable requests and do not discriminate for exercising privacy rights. Authorized agents may submit requests, but we may verify authority and identity. We do not knowingly use or disclose sensitive personal information for purposes requiring a separate right to limit.
Children
The service is not directed to children under 13. Users in the EEA, UK, or Switzerland must be at least 16 unless a parent or guardian has authorized use where local law permits a lower age. We do not knowingly collect personal information from a child in violation of applicable law.
If you believe a child provided personal information improperly, contact support@pyronix-moneyflow.com so we can investigate and delete it where required.
Security
We use data minimization, encrypted network transport, secret management, access controls, short-lived caches, and pseudonymous identifiers where practical. No service is completely secure, so please avoid uploading information you do not need for the requested feature.
Changes and contact
We may update this policy as the service or law changes. Material changes will be posted here with a new date. Questions and requests: support@pyronix-moneyflow.com.