← FlashSavvy

Privacy Policy

Effective September 21, 2026

In short: FlashSavvy uses your data to provide the features you choose. We do not sell your personal information or use it for advertising.

Information FlashSavvy handles

FlashSavvy may store your decks, cards, study history, scheduling preferences, goals, app settings, images, and short audio attachments. This information is used to operate the app and personalize spaced-repetition scheduling.

Storage and backup

Your study data is stored on your device. When iCloud is available and synchronization is active, Apple processes and stores the synchronized data under your Apple account. Decks or media you intentionally share with the public catalog, report, or download through FlashSavvy may be processed and stored using Firebase services.

Google Sheets connection

Connecting a Google account is optional. If you connect Google Sheets, FlashSavvy requests access needed to let you select spreadsheets and synchronize supported deck and card edits. FlashSavvy uses Google user data only to provide this user-facing sync feature; it does not use Google data for advertising or sell it to third parties.

Google Sign-In provides your account email address, display name, and profile image so the app can identify the connected account. Google displays its own secure file picker, and FlashSavvy receives access only to the spreadsheet you explicitly choose or a spreadsheet the app creates for you. FlashSavvy does not list or browse the other files in your Google Drive. For an authorized spreadsheet, the app reads its name, tab names, column headers, and card rows, and writes supported card changes and row-identification metadata when you use the synchronization features. Imported card content and connection identifiers are stored with your decks on your device and may synchronize through iCloud when that feature is active. Google Sheets access tokens are used by the app to make authorized requests directly to Google APIs.

FlashSavvy's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Workspace API data is not used to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models.

You can disconnect Google Sheets in FlashSavvy and revoke access at any time from your Google Account security settings.

How we protect your data

FlashSavvy uses HTTPS encryption in transit for requests to Google Sheets, Google Drive, and its Firebase backend. Google authorization is handled through Google's Sign-In software; FlashSavvy does not receive or store your Google Account password. Google access tokens are used for the connected account's authorized API requests and are not published with shared decks.

Local study data is stored in the app's private device storage and is protected by the operating system's app isolation and device security settings. Firebase authorization rules restrict access to private account records, and backend services check authentication before processing private cloud requests. Only decks or media you deliberately share through public features are intended to be publicly accessible. These safeguards reduce the risk of unauthorized access; no storage or transmission method can guarantee absolute security.

Optional AI and speech features

When you choose a cloud AI-assisted feature, the information required for that request—such as a deck name, topic, card text, side names, optional guidance, or speech text—is sent to FlashSavvy's Firebase backend and Google Cloud AI services to generate the requested result. Generated results and technical usage measurements are returned to the app. To make interrupted requests safely retryable without charging an allowance twice, FlashSavvy temporarily stores the generated result for up to 14 days and stores account-linked usage events and monthly totals for allowance support and cost reporting.

Cloud AI and Natural Speech are optional. Device speech is processed on the device. Apple Intelligence generation is processed by Apple on the device or with Private Cloud Compute, depending on the option you choose and device support. Google states that customer data sent to managed Vertex AI models is not used to train or fine-tune models without the customer's permission or instruction. Google may temporarily cache or log some generative-AI request data to operate and protect the service, including abuse monitoring, under its Google Cloud terms. Google states that Cloud Text-to-Speech does not log customer text or audio data.

App Store purchases and cloud usage

FlashSavvy automatically creates a pseudonymous Firebase account identifier to verify cloud requests and track usage limits. On Apple devices, the app sends Apple-signed app and purchase proofs, and an App Store device-verification identifier when available, to its backend to recover the same account without asking for your name or a separate app login. The backend stores a hashed App Store app-transaction identifier linked to that account, purchase records, subscription status, cloud-feature usage totals, and remaining purchased cloud allowance. These records support purchase verification, recovery across devices, fraud prevention, and prevention of duplicate allowance grants.

FlashSavvy does not receive your Apple Account password, payment-card details, name, or email address through this recovery process. Apple may ask you to authenticate when you purchase or explicitly restore purchases. The App Store account used for purchases may differ from the iCloud account used to synchronize study data.

Notifications and device permissions

If you allow notifications, FlashSavvy uses them for study reminders and goal progress. Audio, microphone, photo, file, and network permissions are requested only when needed for features you choose.

Service providers

FlashSavvy relies on service providers including Apple (iCloud and device services) and Google (Google Sign-In, Sheets, Drive, Firebase, and optional AI services). Their handling of data is governed by their respective privacy policies and your account settings.

Retention and deletion

Local app data remains until you delete it in the app or remove the app. Synced or intentionally shared data may remain in iCloud, Google Sheets, or shared services until you delete it there or request its removal. Disconnecting Google Sheets or removing FlashSavvy does not itself delete data already stored in your Google account or iCloud.

You can use Delete cloud account in FlashSavvy Settings to delete the pseudonymous Firebase account and its account-linked cloud usage events and reports, temporary generated results, remaining purchased cloud allowance, and account links. FlashSavvy retains a minimized, pseudonymous record of App Store transaction identifiers, products, subscription or refund status, and current allowance or one-time bonus redemption counters associated with the hashed App Store identity. These records prevent duplicate grants, quota resets, and purchase fraud. A later, explicit Restore Purchases can rebind an active subscription after Apple verifies it; previously consumed or deleted add-on allowance is not restored, and already-used current-period allowances remain used. Deleting FlashSavvy data does not cancel an App Store subscription, delete local or iCloud study data, or delete data in your Google account. Subscriptions are managed through your Apple Account. You may also contact us for help with a deletion request.

Children

FlashSavvy is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

Changes

We may update this policy as FlashSavvy evolves. The effective date above will identify the current version.

Contact

Questions or deletion requests can be sent to contact@dosi.studio.