Privacy Policy
Liu Cards · Last updated: September 20, 2026
Liu Cards is a flashcards and spaced-repetition app made by Codesuma ("we", "us"). This policy explains what information the app handles, how it is used, and the choices you have. We keep the app simple, and we keep this policy simple too.
The short version
- No account or email is required to use the app.
- We only handle the cards you create and the study data needed to schedule your reviews.
- Cards you publish to a channel are visible to other users — everything else is private.
- You can connect an AI assistant such as ChatGPT or Claude. It then works on your deck with your permission, and you can disconnect it at any time.
- We do not show ads, and we do not sell your data.
- We do not collect your location, your contacts, or advertising identifiers.
Information we handle
Anonymous identity. When you first save something, the app creates an anonymous account for you on our backend (a random user ID and a security token), along with a random device identifier. This lets your cards be stored and, once you sign in, follow you across devices. It does not require your name, email, or phone number.
Your content. The flashcards you create — the text on their front and back, any picture you put on a side, and any spoken clip generated for a side — are stored on our servers so they can be saved and synced. We strip the metadata from a picture before storing it, so details such as where a photo was taken do not travel with it.
Study data. To schedule reviews, we store which cards you saved and how you rated each review (for example "Hard" or "Good"), together with timing data the scheduling algorithm needs.
Channel content. Channels are public collections. If you create a channel and publish cards to it, the channel's name and those cards are visible to other users, and other users can save them into their own decks. We also store which channels you subscribe to.
Optional sign-in. If you choose to sign in with Google or Apple to secure your account, we receive your email address from that provider to link your account. This is optional — the app works fully without it.
What we do not collect
- Precise or approximate location.
- Your contacts or address book.
- Advertising identifiers — the app contains no ads and no advertising SDKs.
How we use information
- To provide the app: saving your cards and scheduling your reviews.
- To enable channels: showing cards you publish to the users who browse or subscribe to your channel.
- To run the optional features you ask for: spoken pronunciation, matching cards by meaning, and a connected AI assistant.
- To keep the service working and secure (for example, preventing abuse).
We do not use your information for advertising or profiling, and we do not sell it.
Who we share it with
We share your information only as needed to run the app:
- Other users. Only the cards you publish to a channel, and the channel's name, are visible to others. Your private cards and study data are not.
- Infrastructure providers. We use Supabase (database and authentication) and Fly.io (hosting) to operate the service on our behalf. Your data is processed on their infrastructure under their security measures.
- OpenAI. Two features send card text to OpenAI's API. Spoken pronunciation sends the exact words to be read aloud. Matching cards by meaning, which is how search and an assistant's knowledge tools find related cards, sends both faces of a card. Neither request carries your name, your email, or your account identifier. OpenAI's API terms say data sent this way is not used to train their models. See the OpenAI privacy policy.
- An AI assistant you connect. See the next section.
- Legal reasons. If required by law or to protect rights, safety, and the integrity of the service.
Connecting an AI assistant
Liu Cards can be connected to an AI assistant such as ChatGPT or Claude, so you can build cards and study by talking to it. This is off until you set it up. The app works fully without it.
How the connection is made. The assistant sends you to a page on liucards.app. You sign in there and approve the connection, and we then give the assistant an access token for your account. The assistant never sees your password or your sign-in. We record which assistant connected, and the requests it makes, so we can keep the service working.
What the assistant can read. Once connected, it can ask for the same things you see in the app:
- The text on the front and back of your cards, and the links to any picture or spoken clip on them.
- When each card is next due, how many times you have reviewed it, and a mastery label such as "new" or "known".
- The identifiers of your cards and saved cards, which the assistant needs in order to act on them.
- Your channels, the channels you follow, and cards in public channels.
Nothing else about you is returned. The assistant does not receive your email address, your account identifier, your device identifier, or any record of how you use the app.
What the assistant can change. It can create, edit and delete cards, record the result of a review, save or remove a channel card, and follow or unfollow a channel. It cannot delete your account, and it cannot take over an anonymous account. Those remain things you do in the app. A card an assistant creates records which assistant made it, and the app shows that on the card.
What we receive from the assistant. Only what it sends to our tools: the card text it writes, and a picture when you or it supplies one. A picture arrives as a link, which we download, strip, resize and store like any other card picture. We do not receive your conversation with the assistant, and we do not ask for it. Two of the tools reach OpenAI on your behalf, for spoken pronunciation and for matching cards by meaning. Those are described under "Who we share it with" above.
What the assistant's provider sees. Everything our tools return passes through the assistant, so it reaches the company that runs it. Your conversation with the assistant is covered by that company's privacy policy, not this one. Read theirs before you connect. If you would rather keep your deck away from an assistant, do not connect one.
Personal access tokens. A token you create for a script or another client gives the same access as a connected assistant. Treat it like a password, and email us to have one revoked.
Ending the connection. Remove the connector in the assistant's own settings and it loses access at once. Deleting your Liu Cards account removes every connection along with it.
Data security
Data is encrypted in transit (HTTPS) between the app and our servers. Your account is protected by a security token rather than a password you have to manage.
Data retention and your choices
You can delete individual cards at any time inside the app, which removes them from our servers. To delete your account and all associated data, see liucards.app/delete or email us at info@codesuma.dev and we will process your request.
Children
Liu Cards is not directed to children and is intended for a general audience. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will remove it.
International processing
Our service providers may store and process data on servers located in other countries. By using the app, you understand your information may be processed in those locations.
Changes to this policy
We may update this policy from time to time. We will revise the "Last updated" date above when we do, and significant changes will be reflected on this page.
Contact
The controller of your data is Codesuma, a sole proprietorship registered in the Netherlands with the Chamber of Commerce (KVK) under number 97761257.
Questions about this policy or your data? Email us at info@codesuma.dev. If you live in the European Union you may also complain to your national data protection authority. In the Netherlands that is the Autoriteit Persoonsgegevens.