Privacy Policy
Last updated: July 29, 2026
This privacy policy describes how the SnappyCards flashcard learning system (https://snappycards.app) processes personal data. The service is operated by ORYNEX INTERNATIONAL LLP (brand name shown in the interface: Orynex LLC / SnappyCards).
The purpose of this policy is to explain, in a transparent and easy-to-understand way, what data we collect, for what purposes and on what legal bases we process it, who we share it with, how long we retain it, and what rights you have under the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679 of the European Parliament and of the Council).
1. The data controller and contact details
The operator of the SnappyCards service and the controller of personal data is the following company:
- Company name: ORYNEX INTERNATIONAL LLP (brand name shown in the interface: Orynex LLC / SnappyCards)
- Legal form: BC Limited Liability Partnership (British Columbia, Canada)
- Registration number: LL0003199
- Registered office: Vancouver, BC, Canada
- Operator's website: https://orynex.co/
- Product: https://snappycards.app
For data protection and general enquiries, the controller can be reached at info@orynex.co.
2. What personal data we process
In the course of providing the service, we process the following categories of personal data:
- Account data: email address, name and password. The password is handled by Supabase Auth and is stored exclusively in hashed (irreversible) form – we never store a readable, plain-text password.
- Profile data: the interface language, your native language, the languages you are learning, and your user role (student, teacher or school administrator).
- User content: the flashcard sets and cards you create, along with the media (image, audio, video) uploaded to them.
- Usage data: your learning sessions, the measured reaction times, and your per-card progress and mastery level.
- Pronunciation-check audio recording: the short audio recording captured with your microphone, which we process solely for the duration of its conversion into text, and do not store.
- Purchase and subscription data: the amount, currency, status and items of the order, the details of the receipt issued, your AI credit balance and its movements, and the customer, subscription and payment identifiers received from Stripe. We do not process or store card numbers, expiry dates or CVC codes – these are handled exclusively by Stripe.
- Technical data: IP address, browser and device data, and system logs.
3. Purposes and legal bases of processing
We determine the individual processing purposes and their legal bases under Article 6 of the GDPR as follows:
- Performance of a contract (GDPR Article 6(1)(b)): creating and maintaining your account, providing the learning service, storing sets and cards, tracking and displaying your learning progress, and fulfilling the subscriptions, AI credit packages and flashcard sets you order.
- Legitimate interest (GDPR Article 6(1)(f)): maintaining the security of the service, preventing abuse and fraud, debugging, and developing and improving the quality of the service.
- Consent (GDPR Article 6(1)(a)): IP-based language detection (geolocation) after you accept the cookie consent, as well as any marketing communications. Consent may be withdrawn at any time, free of charge.
- Legal obligation (GDPR Article 6(1)(c)): complying with obligations arising from tax and accounting rules, in particular issuing the receipts related to paid subscriptions and to purchases made in the shop.
4. Processors and third parties
We use the following processors and third-party providers to operate the service. Appropriate GDPR-compliant data-processing agreements or contractual safeguards are in place with each of them.
Primary processor:
- Supabase: database (Postgres), authentication (Auth), file storage (Storage) and back-end functions (Edge Functions). Primary data storage takes place within the European Union, in the eu-north-1 (Stockholm, Sweden) region.
Additional processors:
- Resend: sending transactional emails (confirmation, invitation, password reset).
- OpenAI (USA): per-card translation of flashcards.
- Anthropic (Claude, USA): batch translation of the interface (UI) texts.
- fal.ai (USA): AI-based image and video generation for cards.
- ElevenLabs (USA): text-to-speech (TTS) for cards.
- Groq (USA): converting the audio recorded for the pronunciation check into text; we do not store the recording.
- Google (Analytics, USA): visitor statistics (Google Analytics 4) on the marketing pages, exclusively where you have accepted the analytics cookie consent – see Section 7.
- Netlify: static hosting and content delivery (CDN) for the website.
- Stripe (USA): payment processing for subscriptions, AI credit packages and the flashcard sets available for purchase in the shop.
- ipapi.co: IP-based language detection on your first visit, exclusively after you accept the cookie consent.
Payment takes place on the Checkout page operated by Stripe: your bank card details are handled exclusively by Stripe, they do not reach the SnappyCards system and are not stored there. We transmit to Stripe your email address, the name of the purchased item, and the internal identifiers of the order and of your account; from Stripe we receive back the identifiers, amount, currency and status of the payment.
5. International data transfers
Primary data storage takes place within the European Union: in Supabase's eu-north-1 (Stockholm, Sweden) region. Your data is therefore, by default, stored within the EU.
The controller has its registered office in Canada (British Columbia).
Some of the processors listed in Section 4 (for example OpenAI, Anthropic, fal.ai, ElevenLabs, Groq, Google, Stripe, Resend, Netlify) operate in the United States. The lawfulness and adequate level of protection of transfers to them are ensured by the Standard Contractual Clauses (SCC) adopted by the European Commission, as well as other appropriate safeguards.
6. Data retention periods
We retain your account until it is deleted. When the account is deleted, an immediate, permanent (hard delete) removal takes place: your private sets and your account are permanently erased – there is no 30-day grace period and no possibility of recovery.
For technical or legal reasons, certain data survives account deletion, but with any link to your identity severed:
- The usage and cost log (ai_usage_log) is retained after the user is deleted, but without the user's identifier – the log is append-only and serves the purpose of billing and accounting.
- The log of AI credit movements (credit_transactions) is likewise retained, without the user's identifier.
- Audit log entries are retained, but the data subject's identifier is set to NULL: the trace remains, while the link to the individual is removed.
Orders, receipts, subscription data and your credit balance, by contrast, are deleted from our systems together with your account; the record of payment transactions is thereafter kept by the payment processor (Stripe) under its own retention rules.
7. Cookies and local storage
The service stores a few items that are strictly necessary for its operation in your browser's local storage (localStorage):
- sb-<project>-auth-token: the Supabase login session token; strictly necessary for the operation of the service.
- snappy_user_language: the selected interface language; strictly necessary.
- snappy_consent: your decision regarding cookie consent; strictly necessary.
- in addition, minor operational settings (such as view preferences and identifiers of pending invitations); these are likewise strictly necessary, operational items.
A non-essential element is ipapi.co's IP-based geolocation, which only runs if you accept third-party cookies. If you decline, the system relies on the browser's navigator.language setting to detect the language – this information does not leave your device.
The cookie banner also includes a separate “analytics” consent category. The service uses Google Analytics 4 (measurement ID G-6K8XK8M6QT) under this “analytics” category. It is only activated with your consent: it is disabled by default (Google Consent Mode v2, denied by default), and it begins collecting data only after you accept the analytics category in the cookie banner.
You can change or withdraw your consent decision at any time by clicking the “Cookie settings” link in the page footer, which reopens the selection bar.
8. Your rights as a data subject
Under Articles 15–22 of the GDPR, you have the following rights in relation to the personal data we process about you:
- Right of access: you may request information about what data we process about you.
- Right to rectification: you may request the correction or completion of inaccurate or incomplete data about you.
- Right to erasure: you may request the deletion of the data we process about you.
- Right to restriction of processing: in certain cases you may request the restriction of processing.
- Right to data portability: you may request that we provide your data in a structured, machine-readable format.
- Right to object: you may object to processing based on legitimate interest.
- Withdrawal of consent: you may withdraw consent-based processing at any time, free of charge; this does not affect the lawfulness of processing carried out before withdrawal.
You may exercise your rights at info@orynex.co. In case of a complaint, Hungarian users may turn to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH, https://naih.hu); all EU/EEA users may also lodge a complaint with the data protection supervisory authority of their place of residence.
9. Minors and parental consent
SnappyCards supports the parental consent process when minors register, in line with Article 8 of the GDPR, which governs the conditions applicable to a child's consent in relation to information society services.
If the registering user is below the age required for consent, processing takes place with the consent, or the confirmation thereof, of the parent or the person holding parental responsibility. As part of this, the parent can grant or refuse consent through the process provided by the system.
10. Data security
To protect your data, we apply multiple layers of technical and organizational measures:
- Row Level Security (RLS) on every data table, ensuring that each user can only access their own data and data they are authorized to access.
- JWT-based (token) authentication for every login and back-end operation.
- Encrypted (HTTPS) data transmission between the browser and the server.
Please note that transmission and storage of data over the internet can never be entirely risk-free. The measures above keep the risk at a reasonable level, but we cannot guarantee complete security.
11. Deleting your account and data
You can delete your account and the associated data at any time using the deletion function available from the account menu. Deletion is immediate and permanent (hard delete): there is no grace period, and deleted data cannot be recovered afterwards.
What is deleted: your account, your profile data, your private flashcard sets (created solely for yourself and not shared with any specific group), your learning progress and session data, and your orders, receipts, subscription data and credit balance.
What is retained: the usage and cost log, as well as the log of AI credit movements, are retained without your user identifier (append-only, for accounting purposes); audit log entries are retained, but your identifier is set to NULL (an anonymized trace). Sets shared with other users may also be retained, but without the personal identifier linked to them.
12. Changes to this policy
We may update this policy from time to time, for example in the event of a change in legislation, a new feature, or the introduction of a new processor. We will notify you of material changes through the service or by email. The applicable effective date is indicated at the top of the document; we recommend that you review the current version of this policy from time to time.
13. Contact
You can reach the controller with your data protection questions, requests or complaints at info@orynex.co. We aim to respond to every enquiry within a reasonable time, in accordance with the GDPR.