Privacy Policy
Effective July 21, 2026
MazoCards is a flashcard application that can be used without creating an account. This policy explains what information is processed when you use browser storage, temporary deck links, Google Sign-In, cloud synchronization, or community features.
Information processed locally
Decks, cards, review schedules, study statistics, preferences, imports, and deletion markers are stored in your browser. This information stays on your device unless you sign in and use cloud synchronization or choose to publish a deck.
Anonymous product measurement
MazoCards records a small set of product milestones: a landing-page visit, a completed import, five studied cards, a second session, and a return after seven days. Each event contains only the milestone, a broad page area, interface language, country, and campaign or one of a few known directory referrers when available. We do not include an account identifier, a stable visitor identifier, deck or card content, or the full page address, and we do not write the raw network address to the product-metrics dataset.
To recognize the one-time milestones, the browser stores first- and last-session timestamps, a session count, campaign labels, and flags for milestones already sent. It does not create a random tracking ID. These local values are removed when you clear MazoCards site data. Measurement is disabled when the browser sends Global Privacy Control or Do Not Track. Aggregate events are stored in Cloudflare Workers Analytics Engine for three months.
Temporary AI-created deck links
An AI agent or other client may send deck content to the MazoCards API to create a temporary study link. The deck content and its random link identifier are stored in Cloudflare Workers KV for up to seven days. Anyone who has the unguessable link can open the deck during that time. MazoCards uses a temporary hash derived from the requesting network address to limit abusive creation traffic; the application does not store the raw address in the deck record.
Information processed when you sign in
Google Sign-In provides MazoCards with your account identifier, email address, display name, and profile image. We also store the unique MazoCards username you choose. Authentication is provided by Google Firebase Authentication.
Cloud synchronization
When signed in, your decks, cards, review schedules, study statistics, and deletion markers may be stored in Google Cloud Firestore under your user account so that they can be synchronized across devices.
Public decks
If you explicitly publish a deck, its title, description, tags, cards, your chosen username, and your display name become visible to other MazoCards users. Do not publish personal or confidential information.
Service providers
MazoCards uses Google Firebase for authentication, hosting, and optional cloud storage, and Cloudflare for the temporary deck API, abuse protection, and aggregate product measurement. These providers process information according to their own terms and privacy policies.
Advertising and consent
MazoCards uses Google AdSense to display advertisements on selected public pages and non-study app screens, including dashboard, creation, and completed-session screens. Google and its advertising partners may use cookies, device information, and similar technologies to deliver, measure, and protect advertising. In the European Economic Area, the United Kingdom, and Switzerland, MazoCards uses Google's certified consent platform so you can accept, reject, or manage the relevant advertising choices. See Google's advertising policies for more information. MazoCards does not place ads inside active study or quiz interactions.
Retention and control
You can export or delete local decks from the application. Signing out clears local study data after attempting a final synchronization. Synchronized account data remains in Firebase until it is deleted. Temporary deck links expire after seven days. To request deletion of your account and associated cloud data, contact the address below.
Security
We use access controls, validation, encrypted HTTPS connections, and browser security policies to protect information. No online service can guarantee absolute security.
Children
MazoCards is not directed to children under the minimum age required to manage their own Google Account in their country. We do not knowingly collect personal information from children who cannot provide valid consent.
Changes and contact
This policy may be updated when the service changes. Material changes will be reflected on this page. For privacy questions or account deletion requests, email support@mazocards.com.