Privacy Policy
Last updated: 2 September 2026
Your privacy matters to us. This Privacy Policy explains what information Repeat & Learn ("Repeat & Learn", "we", "us", or "our") collects, why we collect it, how we use and share it, and the choices and rights you have. We try to collect only what we genuinely need to run the service, to be transparent about it, and to keep it secure.
1. Who we are and what this policy covers
Repeat & Learn is a spaced-repetition learning application that helps you store knowledge items ("cards"), schedule reviews, optionally deliver them through Telegram, Discord, or the Repeat & Learn Cards app, and optionally process them with AI features.
The service is operated by Vadym Kustov, a sole proprietor (Kleinunternehmer) established in Germany, who is the data controller for the personal data described here. This policy applies to the Repeat & Learn web application at https://repeatandlearn.com, our APIs, our Telegram and Discord bot integrations, the Repeat & Learn Cards app, and any future mobile apps.
The controller's contact details are:
Vadym Kustov
c/o Impressumservice Dein-Impressum
Stettiner Str. 41
35410 Hungen
Germany
Phone: +49 156 798 216 28
Email: hello@repeatandlearn.com
The same details are published in our Impressum.
2. Information we collect
Information you provide directly:
- Account data — your email address, a username, and (unless you sign in only with Google) a password, which we store only as a salted hash, never in plain text.
- Profile and preferences — your interface language, timezone, quiet-hours settings, and similar app preferences.
- Your content — the knowledge items / cards you create, their categories, folders, file types, notes, and the scheduled tasks you configure. Your card content is encrypted at rest in our database.
- Support messages — if you contact us through the in-app support form, we store the message and your email so we can reply.
- Product survey answers — from time to time we ask you two short questions about the product and for a star rating. Answering is entirely optional, and you can close the survey. We store what you answered, the free-text comment if you wrote one, the rating, your interface language, and whether you ticked the box allowing us to show your answer publicly. We use the answers to decide what to build next and, in aggregate and anonymous form, to describe the product on our website. We publish an individual answer word-for-word only if you ticked that box; aggregated figures contain no personal data. See Section 5 for how long we keep them.
- AI chat conversations and your ratings of them — your messages in the "Discover" AI chat and the replies you receive are stored in your account, encrypted at rest, so the conversation is still there when you come back. If you rate a reply with 👍 or 👎, we also store that rating and any reason or comment you add to it.
Information collected automatically:
-
Authentication tokens — when you log in, we set httpOnly session cookies (
rl_access_token,rl_refresh_token) so you stay signed in. Your browser also stores a small non-sensitive session hint in local storage. -
Operational records — basic timestamps such as account creation, last login, and when cards are scheduled or shown, used to run the spaced-repetition logic.
-
Study activity — when you open the app and when you answer a card, together with the hour of day in your own timezone. We use this to show you your study statistics, to know which day counts towards your streak, and to send study reminders at the time you normally study (see Section 3). These records are about when you studied, not what you studied, and they are kept for a limited period (see Section 5).
-
Delivery-channel identifiers — if you connect a delivery channel, we store what is needed to reach you there: your Telegram chat identifier, your Discord user and direct-message identifiers, or, for the Repeat & Learn Cards app, the push subscription your browser issues for each device you enable notifications on.
-
Where you came from — if you arrive through a link we posted on a social network, that link carries a short label identifying the post (for example
li-20260825-spacedrepetition). Your browser keeps that label in local storage for up to 90 days, and if you then create an account we store it with your account so we can tell which of our posts brought people here. The label identifies our post, not you: it contains no information about you, is never shared with anyone, and is deleted from your browser as soon as you register. If you arrive any other way, no label is stored at all. -
Page views — we count page views on our website using Cloudflare Web Analytics: both the public pages anyone can open (the landing page, the pricing page, the support and legal pages) and, once you are signed in, the pages of the app itself. For each view it records the address of the page, the website or app that linked you to it, your approximate country, and the type of browser and device you used. A page address never contains your content — our addresses name a section, for example
/knowledge-base, never an individual card, and the part of an address after?is not recorded at all. It sets no cookies and stores nothing in your browser; your IP address is used only in passing to work out the country and is not kept. It cannot identify you, it cannot be linked to your account, and it does not follow you across other websites.
Apart from that page count, we do not use advertising networks, tracking pixels, session recording, cross-site profiling, or any service that builds a profile of you. We do not sell your personal data.
Information from third parties:
- Google Sign-In (optional) — if you choose to sign in with Google, Google sends us your basic account identifier to create or link your account. We do not receive your Google password.
- Payment providers — if you purchase a subscription, our payment providers send us your subscription status and the provider-side identifiers needed to manage it (see Section 4).
3. How and why we use information
We use the information we collect to:
- provide the core service — store your cards, schedule and deliver reviews, and run AI features you request;
- authenticate you and keep your account secure;
- process payments, manage subscriptions, and count how much of your plan's allowances you have used;
- send you essential service emails (email verification, password reset, support replies);
- send study reminders — if you have not reviewed anything during the day, we send a single message to one of your connected delivery channels, at the hour you normally study. The message may name your current streak and one or two cards that are due, so you know what is at stake. It is never sent more than once a day, it respects your quiet hours, it stops after a month of inactivity, and you can turn it off in your profile at any time. We do not use email for these reminders;
- tell you when a batch of cards is left unfinished — cards arrive in batches, and the next batch is only sent once the current one has been answered. If you answer part of a batch and then stop, we send one message to that same chat about six hours later, saying how many cards you have answered and how many are still waiting. It is sent at most once per batch, it respects your quiet hours, it never shows the content of a card, and the same profile switch that turns study reminders off turns it off as well;
- respond to your support requests;
- understand what to improve, from the product survey answers you choose to give us;
- improve the quality of AI replies — when you rate a reply in the "Discover" chat, that exchange becomes visible to us: a person on our side reads the question, the reply, and any comment you added, together with the email address of the account it came from. This applies only to conversations you have rated — 👍 as well as 👎. Conversations you never rate are not opened by us; they stay encrypted in your account and are only ever shown back to you;
- detect, prevent, and address abuse, fraud, or technical problems;
- comply with legal obligations.
Legal bases (GDPR). We are established in Germany, so the EU General Data Protection Regulation applies to our processing. We rely on: performance of a contract (to provide the service you signed up for), legitimate interests (to secure the service, prevent abuse, and measure in aggregate how our public pages are used), consent (where required, e.g. optional integrations and AI features), and legal obligation (e.g. tax records for payments).
4. Who we share information with (sub-processors)
We do not sell your data. We share data only with service providers that help us operate Repeat & Learn, and only as needed. These are:
| Provider | Purpose | What it receives |
|---|---|---|
| Supabase | Database hosting — where your account and your cards are stored; our database is located in Ireland (EU) | All account data and card content we store (card content is encrypted at rest) |
| Fly.io | Application hosting — our servers and background jobs run there | Any data processed while the service is running |
| Cloudflare (USA) | Counting page views on our website (Web Analytics) | The address of the page opened (never its content, and never the part after ?), the site that linked you there, and your browser and device type; your IP address is used in passing to determine the country and is not stored |
| Paddle.com Market Ltd | Payments & subscriptions (acts as Merchant of Record) | Email and subscription/checkout data needed to process payment |
| RevenueCat | Mobile in-app subscription management (when mobile apps launch) | Subscription identifiers and status |
| AppSumo | Selling and managing lifetime deals | We receive the licence key and tier of a purchase; we send back only the one-time code from their "Redeem" button |
| OpenAI (USA) | Content moderation for "Concise" and the "Discover" chat; text generation for "Concise" and for turning a pasted word list into word pairs | The text you chose to process — the card's text, your chat question, or the list you pasted |
| Perplexity (USA) | Web search behind the "Discover" AI chat | Your question, the text of any card you attached to it, and recent messages of that conversation |
| Lyceum (Germany) | A provider we may use for writing the answer in the "Discover" AI chat, for "Concise" and for word-list processing. Not in use at the time of writing | Your question, the text of any attached cards, recent messages, and the web summary |
| Google — Gemini API (USA) | Writing the answer in the "Discover" AI chat; also "Concise" and vocabulary "Smart fill" | The same as Lyceum above |
| Telegram | Optional delivery of your cards via the Telegram bot | The card content delivered to you, plus Telegram chat/user identifiers |
| Discord | Optional delivery of your cards via direct message from our Discord bot | The card content delivered to you, plus Discord user/direct-message identifiers |
| Browser push services (Google, Mozilla, Apple, depending on your browser) | Delivering notifications to the Repeat & Learn Cards app | Only a notification signal — see below |
| Optional "Sign in with Google" | Authentication request data | |
| Resend (with SMTP fallback) | Sending service emails | Your email address and the message (e.g. verification link) |
About push notifications. Notifications for the Repeat & Learn Cards app are relayed by the push service your browser vendor operates. The notification itself carries no card content — only a short prompt telling you that something is waiting. The cards themselves are fetched from our servers by the app after you open it, over an authenticated connection.
About AI features. AI features are optional: they run only when you start them, and only on the text you hand to them. What leaves our systems depends on the feature:
- "Concise" and "Smart fill" for vocabulary decks send the text of the card, or the words and lines you pasted, to the AI provider currently configured for that feature — Google (Gemini), OpenAI, or Lyceum. Translations of individual words are cached on our servers, so the same word is not sent twice. "Concise" and the "Discover" chat additionally pass your text through OpenAI's moderation service before generating anything.
- "Discover" AI chat sends your question, the text of any cards you attach to it, and the recent messages of that conversation to a web-search provider (Perplexity) and to the provider that runs the model writing the answer (Google Gemini at the time of writing). Your Discover conversations are stored in your account, encrypted at rest.
Which provider serves a given AI feature can change; whenever it does, the table above and Section 8 are updated with it, so they always describe the provider actually in use.
We never send your email, your password, or cards you did not choose to process.
Your content is not used to train AI models. We do not train our own models on it, and we do not allow our AI providers to train theirs on it. We reach every one of these services through its paid business API, where the provider's terms exclude using customer content to train or improve their models — that is a deliberate choice on our part, because the free tiers of some of these services reserve exactly that right. You can simply not use AI features if you prefer your content never leaves our systems for this purpose.
We may also disclose information if required by law, to enforce our Terms, to protect the rights and safety of users or the public, or in connection with a merger, acquisition, or sale of assets (in which case we will notify you).
5. How long we keep information
We keep your account data and content for as long as your account is active. Verification and password-reset tokens are short-lived and expire automatically. Detailed study-activity records (Section 2) are deleted automatically after 90 days; the day-level record of which days you studied is kept for as long as your account exists, because your streak is counted from it. When you delete your account, we delete your personal data and content, except where we must retain certain records (for example, payment/tax records) to comply with the law. Product survey answers are deleted automatically after 24 months. The label recording which post you arrived from (Section 2) is kept for as long as your account exists and is deleted with it; in your browser it expires after 90 days or as soon as you create an account, whichever comes first.
6. Security
We protect your data with measures including encryption in transit (HTTPS), encryption at rest for your card content and other sensitive fields, hashed passwords, signed session tokens, and signature verification on payment webhooks. No method of storage or transmission is 100% secure, but we work to protect your information and review our practices.
7. Your choices and rights
You can:
- Access and update your account information and preferences in the app.
- Export or request a copy of your data by contacting us.
- Delete your account and data at any time using the in-app "Delete account" feature, which removes your personal data and content (subject to the legal-retention exceptions above).
- Choose not to use optional features (Telegram, Discord, or Cards delivery, AI features, Google Sign-In), and disconnect any delivery channel at any time in the app.
- Turn off study reminders and unfinished-batch messages in your profile — one switch covers both — and set quiet hours during which we send you nothing at all.
You have the rights to access, correct, delete, restrict, or port your data, to object to certain processing, and to withdraw consent where processing is based on it. You also have the right to lodge a complaint with a data-protection supervisory authority — either in the EU country where you live or, since we are established in Germany, with the authority competent for us. To exercise any of these rights, contact us (see Section 11). We will not discriminate against you for exercising your rights.
Our competent supervisory authority (zuständige Aufsichtsbehörde) is:
Sächsische Datenschutz- und Transparenzbeauftragte
Devrientstraße 5
01067 Dresden
Germany
Phone: +49 351 85471 101
Email: saechsdsb@slt.sachsen.de
Website: www.datenschutz.sachsen.de
8. International data transfers
We and our service providers may process your data in countries other than yours. Your account and your cards stay in the EU: our application servers run in Frankfurt, Germany, and our database is hosted in Ireland. Supabase and Fly.io are US-incorporated companies, so remote administrative access from outside the EU cannot be ruled out; that is covered by the safeguards below. Some of the providers listed in Section 4 are located outside the EU — in the United States (for example OpenAI, Perplexity, Google, Cloudflare). This includes the text you hand to an AI feature: at the time of writing, the answers in the "Discover" chat and in "Concise" are written in the United States. Where a transfer outside the EU does take place, we rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses). You can request a copy of these safeguards from us — see Section 11. If you do not want your text processed outside the EU, do not use the AI features — every other part of the service works without them.
9. Cookies
We use a small number of strictly necessary cookies to keep you signed in and operate the service (our authentication session cookies). We do not use advertising or third-party tracking cookies. Because these cookies are essential to provide the service, the app may not function correctly without them.
Besides those cookies, our own website stores a few small values in your browser's local storage: your interface preferences, a non-sensitive session hint, and — only if you arrived through one of our social-media posts — the label of that post (Section 2). None of these are shared with third parties and none are used to build a profile of you or to follow you across other websites.
The visit count described in Section 2 needs no cookie and no consent banner: it neither stores anything on your device nor reads anything from it, which is precisely why we were able to choose it over the usual analytics products.
10. Children
Repeat & Learn is not directed to children under the age of 13 (or the minimum age required in your country), and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.
11. How to reach us
For privacy questions or to exercise your rights, contact us at hello@repeatandlearn.com or by phone at +49 156 798 216 28. You can also reach us through the in-app support form, or write to:
Vadym Kustov
c/o Impressumservice Dein-Impressum
Stettiner Str. 41
35410 Hungen
Germany
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the app or by email.
This Privacy Policy is adapted from Automattic's legalmattic templates and is made available under the Creative Commons Attribution-ShareAlike 4.0 International license.