Privacy Policy

Last Updated: October 20, 2025

This Privacy Policy describes how Repeatedly ("we," "us," or "our") collects, uses, and shares your information when you use our spaced repetition learning service, including our website and browser extension (collectively, the "Service").

1. Information We Collect

1.1 Information You Provide

  • Account Information: Email address for authentication
  • User Content: Flashcards, notes, selected text from web pages, URLs of pages where content was captured, and images you save through our browser extension
  • AI-Processed Content: When you use AI-powered features (including chat, summarization, flashcard generation, and content analysis), your content and messages may be sent to AI service providers
  • Profile Information: Any optional information you choose to add to your profile

1.2 Information Collected Automatically

  • Usage Data: Study progress, review history, interaction with flashcards, and feature usage
  • Device Information: Browser type, operating system, IP address, and device identifiers
  • Analytics Data: We use analytics services (PostHog) to understand how users interact with our Service, including page views, feature usage, and user journeys across our platform

1.3 Browser Extension Data

Our browser extension collects:

  • Text you select on web pages
  • URLs of pages where you save content
  • Images you choose to save
  • This data is transmitted to and stored on our servers to enable cross-device access to your study materials

1.4 Browser Extension Permissions

Our browser extension requests the <all_urls> permission, which grants access to all websites you visit. This permission is necessary because:

  • Universal Content Capture: It allows you to capture and save content from any website without restrictions, which is essential for a learning tool that works across the entire web
  • User-Initiated Only: The extension only accesses page content when you actively interact with it (e.g., selecting text, clicking the extension icon, or using the save feature)
  • No Passive Monitoring: We do not passively read, monitor, or collect data from web pages you visit without your explicit action
  • Limited Data Collection: Even with this broad permission, we only collect the specific content you choose to save, not everything on the pages you visit

While this permission technically allows broad access to web content, we are committed to using it solely for the functionality you request—capturing educational content you explicitly choose to save.

2. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve the Service
  • Create and manage your account
  • Enable spaced repetition learning functionality
  • Sync your content across devices
  • Process AI-powered features including chat, summarization, flashcard generation, and content analysis
  • Send you authentication emails (one-time passwords)
  • Analyze usage patterns to improve the Service
  • Prevent fraud, abuse, and security incidents
  • Comply with legal obligations

3. Data Storage and Security

  • Storage Location: Your data is stored on secure servers provided by Neon Database in the US East region
  • Security Measures: We implement industry-standard security measures to protect your data, including encryption in transit and at rest
  • Data Retention: We retain your data for as long as your account is active or as needed to provide the Service. Backup copies may be retained for up to 90 days after deletion
  • No Access Guarantee: While we strive to protect your data, no method of transmission or storage is 100% secure. You use the Service at your own risk

4. How We Share Your Information

We may share your information with:

4.1 Service Providers

  • Neon Database: Database hosting and storage
  • AI Service Providers: When you use AI-powered features (including chat, summarization, flashcard generation, and content analysis), your content and messages are sent to third-party AI providers (including OpenAI for ChatGPT, Anthropic for Claude, and Google for Gemini). These providers process your data according to their own privacy policies and terms of service. Your content may be used by these providers in accordance with their data usage policies.
  • Stripe: Payment processing for subscriptions and purchases
  • PostHog: Product analytics to help us understand feature usage and improve the Service. PostHog may collect usage data, page views, and interaction events. PostHog processes data according to their privacy policy at https://posthog.com/privacy

4.2 Legal Requirements

We may disclose your information if required by law or in response to valid legal requests, including:

  • Compliance with legal obligations
  • Protection of our rights and property
  • Prevention of fraud or security issues
  • Protection of user safety

4.3 Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

4.4 Public Content (Future Feature)

When we introduce public sharing features, content you choose to make public will be accessible to other users.

5. Your Rights and Choices

5.1 Access and Control

  • Access: You can access your information through your account settings
  • Correction: You can edit or update your information at any time
  • Deletion: You can request deletion of your account and data by contacting hello@repeatedly.cards (deletion features will be added to the Service)
  • Export: You will be able to export your data (feature coming soon)

5.2 GDPR Rights (EU Users)

If you are in the European Economic Area, you have the right to:

  • Access your personal data
  • Rectify inaccurate personal data
  • Request erasure of your personal data
  • Object to processing of your personal data
  • Request restriction of processing
  • Data portability
  • Withdraw consent at any time

5.3 CCPA Rights (California Users)

If you are a California resident, you have the right to:

  • Know what personal information is collected, used, shared, or sold
  • Delete personal information held by us
  • Opt-out of sale of personal information (we do not sell your information)
  • Non-discrimination for exercising your CCPA rights

6. Children's Privacy

The Service is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at hello@repeatedly.cards and we will delete such information.

7. International Data Transfers

Your information may be transferred to and processed in the United States, which may have different data protection laws than your country. By using the Service, you consent to the transfer of your information to the United States.

8. Third-Party Services and AI Providers

8.1 Third-Party Links

Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies.

8.2 AI Service Providers

When you use AI-powered features in the Service (including chat, summarization, flashcard generation, and content analysis), your content is transmitted to third-party AI providers. These providers have their own data practices:

  • OpenAI (ChatGPT): Subject to OpenAI's privacy policy and terms. OpenAI may use your data for model training unless you opt out through their settings.
  • Anthropic (Claude): Subject to Anthropic's privacy policy and terms. Anthropic does not train on user conversations by default for consumer API usage.
  • Google (Gemini): Subject to Google's privacy policy and terms. Google's data usage policies apply to content processed through Gemini.

Important: We recommend reviewing these providers' privacy policies if you have concerns about how your data is processed:

By using AI-powered features, you acknowledge that your content will be processed by these third-party providers according to their respective policies.

9. Cookies and Tracking Technologies

We may use cookies, local storage, and similar tracking technologies to enhance your experience, analyze usage, and deliver personalized content. You can control cookies through your browser settings.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

11. Sensitive Information

Please be aware that content you save through the browser extension may inadvertently include sensitive information from the web pages you visit (medical data, financial information, personal details, etc.). We do not intentionally collect sensitive information, but you are responsible for reviewing content before saving it to the Service. We are not liable for any sensitive information you choose to save.

12. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact us at:

Email: hello@repeatedly.cards