DRAFT — pending legal review. Not final counsel-approved wording.
Privacy Policy
Version 2.0.0 · Effective 2026-08-01 · Last updated 2026-07-25
Previous versions
- 1.0.0 · 2026-07-25 — First published draft.
This Privacy Policy explains how CramDeck collects and uses personal data, what your rights are, and how to exercise them. The Polish-language version of this document is the binding version; this English text is a translation provided for convenience.
1. Who is responsible for your data
The controller of your personal data is:
JMS Sieracki sp. z o.o.
ul. ks. Pawła Pośpiecha 3A/7, 41-800 Zabrze, Poland
Registered with the National Court Register (KRS) under number 0001197364 by the District Court in
Gliwice, 10th Commercial Division of the National Court Register
NIP: PL6482767937 · REGON: 243188484 · Share capital: PLN 5,000.00
For any privacy matter, write to hello@cramdeck.com or to the postal address above with the subject "Privacy". We have not appointed a Data Protection Officer, because we are not required to under Article 37 GDPR; the address above is the contact point for all data protection questions.
2. What this policy covers
This policy covers the CramDeck website and web application: browsing and studying decks, creating decks, public profiles, the AI deck wizard, payments, integrations (Personal Access Tokens and OAuth-connected agents such as ChatGPT), and our reporting and moderation processes.
It does not cover third-party websites you reach from links in user-created content. We do not control those sites.
3. What data we process, and where it comes from
3.1 Data you give us
| Category | Examples |
|---|---|
| Account | Email address, name, profile image supplied by your identity provider |
| Age | Your date of birth or age band, collected at sign-up, and guardian-consent confirmation if you are under 18 |
| Public profile | Username, display name, biography (up to 280 characters), avatar, visibility settings |
| Study content | Decks, cards, text and images you upload, deck descriptions, tags |
| Learning activity | Favourites, hidden cards, deck groups, study progress, recently viewed decks |
| AI inputs | Deck titles, topics and source text you submit to the AI deck wizard |
| Support and reports | The content of messages you send us, and reports you submit about other users' content |
| Preferences | Interface language, theme, card order and other learning settings |
3.2 Data we receive from others
When you sign in, Microsoft Entra External ID passes us your unique identifier, email address, display name and given name, and — depending on how your account is configured — an approximate city and country. We use it to create and recognise your account.
Stripe tells us that a payment succeeded, was refunded or was disputed, and gives us a customer identifier. Stripe does not give us your card number.
3.3 Data generated by using the service
| Category | Examples |
|---|---|
| Authentication | Session token, sign-in timestamps, linked identity provider |
| Billing records | Stripe customer identifier, amounts, currency, purchased items, plan status, AI credit balance and ledger |
| Integrations | Personal Access Token name, public prefix, scopes and last-used time; OAuth client identifier, label, scopes and link time |
| Media metadata | File name, size, type, storage path, checksum, moderation status |
| Security and audit | Records of security-relevant events such as sign-in, policy acceptance, username change, token revocation, export and deletion |
| Consent records | Each consent choice you make, with its timestamp, the policy version and language you were shown, your IP address and browser user agent as proof under Article 7(1) GDPR |
We do not collect payment card numbers, government identification numbers, or health data, and you must not put such data into decks, media or AI prompts. See section 12.
4. Why we process your data, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Creating and running your account; providing study, creator, profile and feed features | Performance of a contract — Article 6(1)(b) GDPR |
| Authenticating you through Microsoft Entra External ID | Performance of a contract — Article 6(1)(b) |
| Processing payments, subscriptions, credits and deck purchases | Performance of a contract — Article 6(1)(b) |
| Keeping accounting and tax records of those payments | Legal obligation — Article 6(1)(c), with the Polish Accounting Act and Tax Ordinance |
| Generating cards with the AI deck wizard when you ask us to | Performance of a contract — Article 6(1)(b) |
| Giving third-party agents you connect the access you granted them | Performance of a contract — Article 6(1)(b) |
| Verifying your age and, where you are a minor, obtaining guardian consent | Legal obligation — Article 6(1)(c), and Article 8 GDPR |
| Strictly necessary cookies (session, language, consent state) | Legitimate interests — Article 6(1)(f): delivering a service you asked for. Storage on your device is permitted without consent under Article 399(3) of the Polish Electronic Communications Law |
| Analytics cookies | Consent — Article 6(1)(a), and Article 399 of the Electronic Communications Law |
| Marketing and advertising cookies | Consent — Article 6(1)(a), and Articles 398–399 of the Electronic Communications Law |
| Reviewing AI-generated text for harmful content | Legitimate interests — Article 6(1)(f): keeping the service safe and lawful |
| Handling reports of illegal content and moderating content | Legal obligation — Article 6(1)(c), under Articles 16 and 17 of the Digital Services Act |
| Preventing abuse, fraud and unauthorised access; keeping security and audit logs | Legitimate interests — Article 6(1)(f): protecting the service, our users and ourselves |
| Answering your questions and handling complaints and rights requests | Legal obligation — Article 6(1)(c) — and performance of a contract — Article 6(1)(b) |
| Establishing, exercising or defending legal claims | Legitimate interests — Article 6(1)(f) |
Where we rely on legitimate interests, we have weighed those interests against your rights and concluded they do not override them. You can object to that processing at any time — see section 9.
5. Whether you have to give us this data
Providing an email address and completing authentication is necessary to create an account; without it we cannot provide an account-based service, although free public decks remain readable without an account. Providing your age is necessary because we are legally required to treat minors differently. Providing payment details to Stripe is necessary only if you choose to buy something. Everything else — a biography, an avatar, a public profile, AI prompts — is optional.
6. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by automated means, and we do not carry out profiling within the meaning of Article 22 GDPR.
Two automated processes affect content rather than people. Text produced by the AI deck wizard may be screened automatically for harmful content and withheld if it crosses a threshold, and reported content may be triaged automatically. In both cases you can ask a human to review the outcome by writing to hello@cramdeck.com.
7. Who we share data with
We share personal data with the processors listed on our Subprocessors page, which names each provider, what it processes, where it processes it and the transfer safeguard that applies. In summary, we use Microsoft Azure for identity, databases, file storage and AI, Stripe for payments, and — only if you consent — Google for analytics and advertising measurement.
We may also disclose data to public authorities where the law requires it, and to professional advisers where necessary to establish or defend a legal claim. We do not sell personal data and we do not share it with data brokers.
Anything you publish deliberately — a public deck, a public profile, a shared link — is visible to anyone who has the link, and may be indexed by search engines. Choose deck visibility carefully.
8. Transfers outside the European Economic Area
Our infrastructure is hosted on Microsoft Azure in the European Union. TODO(facts) — confirm the exact
region for each service before this policy is approved.
Some providers are established in the United States or may access data from there for support purposes:
| Provider | Safeguard |
|---|---|
| Microsoft | EU Data Boundary commitments, plus the EU-US Data Privacy Framework and the Standard Contractual Clauses in the Microsoft Products and Services Data Protection Addendum |
| Stripe | EU-US Data Privacy Framework certification and Standard Contractual Clauses in the Stripe Data Processing Agreement |
| Google (only with your consent) | EU-US Data Privacy Framework certification and Standard Contractual Clauses in the Google Ads Data Processing Terms |
| OpenAI (only if you connect the ChatGPT integration) | Standard Contractual Clauses in the OpenAI Data Processing Addendum |
The European Commission decided on 10 July 2023 that the United States provides an adequate level of protection for organisations certified under the Data Privacy Framework. That decision was upheld by the General Court of the European Union in September 2025 and an appeal is pending before the Court of Justice. We therefore also maintain the Standard Contractual Clauses as an independent safeguard. You can ask us for a copy of the clauses that apply to a particular transfer.
9. Your rights
Under the GDPR you have the right to:
- Access your data and obtain a copy of it
- Rectify data that is inaccurate or incomplete
- Erase your data, in the circumstances set out in Article 17
- Restrict processing, in the circumstances set out in Article 18
- Portability — receive the data you gave us in a structured, machine-readable format and have it transmitted to another controller where technically feasible
- Object to processing based on our legitimate interests, on grounds relating to your situation
- Withdraw consent at any time, without affecting the lawfulness of what we did before you withdrew it
You can exercise most of these yourself inside the product:
| Right | Where |
|---|---|
| Access and portability | Profile → Privacy & security → Export my data |
| Rectification | Profile → About, and Profile → Public profile |
| Erasure | Profile → Danger zone → Delete account (14-day grace period, then permanent deletion) |
| Withdraw cookie consent | Footer → Cookie preferences |
| Cut off a connected app | Profile → Integrations → Revoke or Unlink |
Otherwise write to hello@cramdeck.com. We respond within one month of receiving a request, and will tell you if we need to extend that by up to two further months because the request is complex. We may ask you to confirm your identity if we cannot otherwise be sure who is asking.
If you think we have handled your data unlawfully, you may lodge a complaint with the Polish supervisory authority:
Prezes Urzędu Ochrony Danych Osobowych
ul. Stawki 2, 00-193 Warszawa, Poland
uodo.gov.pl
You may also complain to the supervisory authority in the EU or EEA country where you live or work.
10. How long we keep data
| Data | Retention |
|---|---|
| Account and profile | For as long as your account exists |
| Decks, cards and media | For as long as your account exists, unless you delete them sooner |
| Recently viewed decks | About 90 days, then automatic expiry |
| Soft-deleted account | 14 days, during which you can restore it by signing in |
| After the 14 days | Permanent deletion of account, profile, decks, cards, media, tokens and connections |
| Payment and accounting records | 5 years from the end of the calendar year in which the tax became due, as required by Polish tax law |
| Security and audit logs | 24 months from the event; after account deletion they are detached from your identity and stripped of identifying content |
| Content reports and moderation decisions | 24 months after the case is closed |
| Consent records | Retained after account deletion as proof that consent was given and withdrawn, as required by Article 7(1) GDPR |
| Cookies | See the Cookie Policy |
Backups are overwritten on their own cycle, so data may persist in backups for a short period after deletion from live systems. We do not restore deleted personal data from backups except to recover from a system failure.
11. AI features
When you use the AI deck wizard, the deck title, topic and any source text you provide are sent to Microsoft Azure OpenAI Service to generate card suggestions. When you ask the wizard to rewrite a card, the text of that card is sent too.
What you should know:
- Microsoft does not use your prompts or the generated output to train its foundation models.
- Microsoft screens prompts and output for abuse. Where content is flagged and human review is needed,
the prompt and the output may be stored for up to 30 days in an isolated store that we cannot read,
and reviewed by authorised Microsoft staff located in the European Economic Area.
TODO(facts)— confirm whether we have been approved for modified abuse monitoring, which removes this storage. - Generated text may also be screened by Azure AI Content Safety, and withheld if it scores above our thresholds for hate, self-harm, sexual or violent content.
- Cards created by the wizard are labelled as AI-generated in the interface, so that you and anyone you share a deck with can tell them apart from cards written by a person.
- AI output can be wrong. Check it before you rely on it, and before you publish it.
Do not put personal data about other people into AI prompts.
12. Data you must not upload
Do not put the following into decks, cards, media, AI prompts or support messages: payment card numbers, government identifiers such as PESEL or passport numbers, health or medical records identifying a real person, biometric data, or login credentials for any service.
Educational material that does not identify a real person — a textbook case description, an anonymised clinical scenario — is fine. Anything that identifies a real patient is not.
13. Security
We protect your data with encryption in transit and at rest, access control on all administrative systems, secret management through Azure Key Vault, hashed storage of integration tokens, and audit logging of security-relevant events. Files in storage are private and reachable only through short-lived signed links.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the President of the Personal Data Protection Office within 72 hours of becoming aware of it, and we will notify you directly where the risk is high.
14. Cookies
We use strictly necessary cookies to keep you signed in, remember your language and store your consent choices. Analytics and marketing cookies are used only if you agree, and you can change your mind at any time. Full details, including every cookie name and how long it lasts, are in the Cookie Policy.
15. If you are under 18
You need to be at least 13 to use CramDeck.
If you are 13, 14 or 15, you can use CramDeck only with the agreement of a parent or guardian, and we ask for their confirmation when you sign up. Because Polish law sets the age for agreeing to online data processing at 16, we do not offer you analytics or advertising cookies at all — we simply do not use them for your account. You also cannot buy anything without a parent or guardian agreeing.
If you are 16 or 17, you can make your own choices about cookies, but you still need a parent or guardian to agree before you buy a subscription, credits or a deck, because under Polish law people under 18 cannot enter into that kind of contract on their own.
In plain words: we keep the things you need to run your account, like your email and the decks you make. We show other people only what you choose to make public — and your profile starts out private. We never sell your information. If you want your account and everything in it gone, you can delete it in your profile settings, and after 14 days it is gone for good. If you are not sure about something here, ask a parent, guardian or teacher to read it with you, or write to us at hello@cramdeck.com and we will explain it.
If you are a parent or guardian and you believe a child has given us data without your agreement, write to hello@cramdeck.com and we will delete it.
16. Changes to this policy
We will publish any new version here with a new version number and effective date, and keep a list of previous versions at the top of this page. If a change materially affects you, we will tell you in the application or by email before it takes effect, and where the law requires it we will ask you to accept the new version.
17. Contact
JMS Sieracki sp. z o.o.
ul. ks. Pawła Pośpiecha 3A/7, 41-800 Zabrze, Poland
hello@cramdeck.com
KRS 0001197364 · NIP PL6482767937 · REGON 243188484