Privacy Policy

Last updated: August 29, 2026

Who is responsible for your data

The data controller for the Noos website and application is Maxime Kaiser, established in France, publishing Noos on a non-professional basis.

For anything about your personal data, whether a question, a request or a complaint, write to official@noosflashcards.com. This Policy covers everything in the Service: creating an account, making and reviewing cards, the AI features, published stacks and the community, and the website itself.

Data we collect

Account data: email address, first and last name, nickname, birth date, native language, country of residence, and an optional profile avatar.

Acceptance record: the date on which you accepted the Terms of Use and the Privacy Policy, and the version of each that you accepted. We keep this as proof of what was agreed.

Your content: the folders, stacks and cards you create, including any text and images you add.

Usage and activity data: daily review counts, AI usage counters (text suggestions and media scans), and review session data such as cards reviewed and session length.

Analytics events: actions such as signing up, logging in, creating a card, running a review session, using an AI feature, and viewing a page, together with context such as the feature involved and your plan.

Campaign data: if you arrive through a link carrying campaign parameters, we keep that first set of parameters in your browser so we can tell which channels bring people to Noos, and attach them to the analytics events above.

Subscription data: Noos does not currently sell subscriptions or take payment. Accounts carry a plan field, which is set to the free plan. If you subscribed while paid plans were previously available, we hold your plan tier and subscription status; card numbers and billing addresses were always collected and held by Stripe, never by us.

Technical logs: our hosting provider records the usual server request data, including IP address, user-agent and timestamp, and keeps it for a limited period for security and diagnostics. We also write an internal log of subscription changes, which records the account concerned and what changed.

How we use your data

Running the Service: creating and managing your account, storing and syncing your content, scheduling reviews, and displaying community content.

AI features: card text and uploaded images are sent to Google's Gemini API to generate suggestions and analyse images. Card text and a language code are sent to Google Cloud Text-to-Speech to produce audio. These calls are made server-side from our Cloud Functions. Your content is not used to train these models.

Analytics: understanding in aggregate how features are used, so we can improve them.

Communications: account and security notices, email verification, and, if you opted in, product updates and learning tips. You can opt out of the optional messages at any time.

Safety and compliance: enforcing our Terms, handling reports of infringing or unlawful content, preventing abuse, and meeting legal obligations.

No advertising. We do not serve ads, we do not sell or share your personal data, and we do not allow third parties to track you across other sites through Noos.

Public content

Every stack has a visibility setting that you control, on every plan. New stacks are created public unless you change that setting; you can change it at any time.

A public stack is published on the open internet, not only to other Noos members. It is served as an ordinary web page to anyone with the link, with no account required; it is listed in our sitemap and submitted to search engines; and it carries structured data that search engines and other services may reuse. It also appears in the in-app community browser, where other users can import a copy into their own account.

The name published beside a stack is the nickname on your profile. If you have not set one, we publish the neutral label "Member", never your real name. The name appears in the page itself, in the page description used by search engines and social previews, and in the structured data.

You can make a stack private at any time. That removes it from our public pages and from the community browser, but it does not retrieve copies other users have already imported, and it does not remove the page from search engine caches, archives or other third-party copies we do not control.

Who we share data with

We share data with the providers below solely to operate the Service. Each processes it on our instructions under a written contract and may not use it for their own purposes. We do not sell your data to anyone.

Google (Firebase and Google Cloud): authentication, database, serverless functions and hosting. All account and content data is stored on Google Cloud infrastructure.

Google Gemini API: receives card text, uploaded images and the target language, to generate AI suggestions and analyse images.

Google Cloud Text-to-Speech: receives card text and a language code, to generate audio.

Google Analytics (Firebase Analytics): receives the behavioural events described above, together with device and browser information.

Resend: sends our account emails, including email verification. Receives your email address and first name, and delivery information such as whether a message was delivered or bounced.

Stripe: handled all payment processing and billing data while paid plans were available, and is PCI-DSS certified. Noos never received or stored raw payment details.

We may also disclose data where the law requires it, or where it is necessary to establish, exercise or defend legal claims.

Legal basis for processing

Performance of our contract with you: creating and running your account, storing your content, scheduling reviews, providing the AI features you invoke, and publishing the stacks you choose to publish.

Your consent: optional marketing emails and analytics. You may withdraw consent at any time, without affecting processing already carried out.

Our legitimate interests: keeping the Service secure and available, preventing abuse, handling content complaints, improving the product in aggregate, and keeping a record of your acceptance of our Terms. You may object to processing based on legitimate interests at any time.

Legal obligation: where we must retain or disclose data to comply with the law.

Cookies and browser storage

Noos sets no cookies of its own. It stores a small amount of information in your browser's local storage:

  • noos_theme: your light or dark mode preference.
  • noos_language: your chosen interface language.
  • noos_ip_checked: a legacy flag left by an earlier version of the site. It is no longer used for anything and holds no personal data.
  • noos_campaign_attribution: if you arrived through a link carrying campaign parameters, the first set of those parameters. This is used for marketing measurement rather than to identify you, and it is attached to the analytics events described above.

The first three are necessary for the interface to behave as you have set it up. Google Analytics may separately set cookies or similar identifiers for session and device recognition; those are set and controlled by Google.

We do not use cookies or browser storage for advertising, and we do not let third parties use them on our site for that purpose. If that ever changes, we will ask for your consent first and update this Policy.

How long we keep data

Account and content: for as long as your account is open. When you delete your account, your profile, folders, stacks, cards and activity history are erased from our active systems immediately, and from backups within 30 days.

Three things deletion does not reach, and we would rather say so than imply otherwise: copies of your public stacks that other users imported, which belong to those users; pages that were public and may persist in search engine caches and third-party archives outside our control; and records we are required to keep by law.

Acceptance records: kept while your account is open and for up to 3 years afterwards, so that we can show what was agreed if a dispute arises.

Analytics data: up to 14 months, per Google Analytics' default retention.

Technical logs: kept for a limited period by our hosting provider for security and diagnostics.

Billing history: retained by Stripe under their policy and as financial regulations require.

Messages you send us: deleted within 30 days of the matter being resolved, unless the law requires longer or we need them for a legal claim.

Your rights

You have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to how we process it, to withdraw consent where processing is based on it, and to receive your data in a portable form.

How to exercise them:

  • Access and correction: most of your data is visible and editable in your profile and your stacks.
  • Erasure: delete your account from the Settings page, which erases your data as described above. You can also ask us to erase specific data.
  • Portability: the Service has no export button yet, so write to us and we will send you a machine-readable copy of your account data and content. We answer within one month, and will tell you if we need longer for a complex request.
  • Marketing: unsubscribe using the link in any marketing email, or write to us.
  • Everything else: write to official@noosflashcards.com.

We may need to verify your identity before acting on a request, and we will not charge you for making one.

Complaints: if you think we have handled your data badly, please tell us first, because we would like the chance to put it right. You also have the right to complain to a data protection authority. In France this is the CNIL (Commission Nationale de l'Informatique et des Libertés, cnil.fr). If you live elsewhere in the EEA or the UK, you may complain to your own national authority.

International transfers

Your data is stored and processed on Google Cloud infrastructure and by the providers named above, which may be located outside your country, including in the United States. Where data leaves the EEA or the UK, we rely on lawful transfer mechanisms, principally the European Commission's Standard Contractual Clauses, together with the safeguards those providers apply.

Security

We use TLS in transit, database security rules that restrict personal data to its owner, least-privilege server-side operations, and periodic review. Access to production data is limited to what is needed to run the Service.

No system is perfectly secure, and we do not claim otherwise. If a breach affects your personal data and is likely to present a risk to you, we will tell you and the relevant authority within the time limits the law sets.

Children

Noos is not for children. You must be at least 16 to use the Service, in every country, with no parental-consent route around it. We ask for your birth date at sign-up to help enforce this.

We do not knowingly collect personal data from anyone under 16. If we learn that we have, we will delete it and close the account. If you believe a child under 16 has an account, write to official@noosflashcards.com and we will act quickly.

Changes to this Policy

We may update this Policy. The "Last updated" date above will change, and we keep a version stamp against your account so it is clear which version you accepted.

Where a change is material, meaning a new purpose, a new recipient or a new category of data, we will tell you by email or in the application before it takes effect, and we will not begin the new processing until we have.