Privacy Policy
Last updated: 5 August 2026
This is a convenience translation. The German version is the legally binding one.
1. Controller
Xherdi Lika, Gubitzstr. 6, 10409 Berlin, Germany Email: support@decksmd.app
We are not legally required to appoint a data protection officer.
2. Scope — and what is expressly not covered
This policy covers the website decksmd.app and the DecksMD Pro subscription service. The contractual terms of the service are in our Terms of Service; on questions of data processing, this policy governs.
It does not cover free use of the Obsidian plugin with your own API keys. If you select
your own provider in the plugin (OpenAI, Anthropic, Google, or a local model), the plugin
sends your content directly from your device to that provider. That data never reaches
our servers at any point. Your API keys are stored only locally, in a file in the plugin
directory (ai-keys.json), are not synced with your vault, and are never transmitted to us.
Without AI features the plugin works entirely offline: cards, study progress and statistics stay in your vault.
3. Processing of your content by DecksMD Pro
This is the most important section of this policy.
What is transmitted
When you use DecksMD Pro to generate cards, the plugin sends to our service:
- the text of the selected note or section,
- your instruction (e.g. “make cards for chapter 3”),
- cards already generated in the current run, so duplicates are avoided,
- for PDF and image processing, the rendered page images of the pages you selected.
This content may contain personal data if your notes contain personal data.
What happens to it
Our server receives the request, adds the system instruction and forwards it to OpenRouter, Inc., which routes it to the appropriate language model. The response is returned to your device.
Your content is not stored. It is processed only for the duration of the request and discarded afterwards. We never retain note content, instructions, images or generated cards. No content appears in our logs either: on failure we log only the error status, the name of the model requested, and the provider’s error message.
We do not use your content to train AI models. In addition, every request we send carries an explicit flag prohibiting storage and use for training, and we route requests only to providers whose published policies exclude training on, or retaining, the content they receive. We set this flag technically on every single request; how a provider actually handles the request is governed by that provider’s own published policies.
After a request completes we retain only consumption figures: the number of tokens processed and the cost incurred. The content of your notes cannot be reconstructed from those figures.
Legal basis
Art. 6(1)(b) GDPR — processing is necessary to perform the contract, because it is the service you asked for.
Special categories of personal data (Art. 9 GDPR)
Many of our users study medical, nursing or psychology material, so one clarification matters here.
Study material about a subject is generally not health data under Art. 9 GDPR. A card about the symptoms of a condition, a textbook extract or a lecture handout contains no personal reference — there is no data subject the information relates to. You can process such content without concern.
It is different for documents relating to specific individuals: patient records, case notes with identifying details, test results, therapy notes or similar. Those do contain special categories of personal data.
We expressly ask you not to submit such material. The service is not intended for it, we do not request it, and our processing is not directed at it. The same applies to third-party personal data for which you have no legal basis.
If you nevertheless submit such content: we process it solely as part of the generation you requested, do not store it (see above), and do not analyse it. We neither intend nor carry out any independent processing of special categories within the meaning of Art. 9(1) GDPR. You remain responsible for whether the input was permissible — in particular towards the individuals concerned and, for professional records, with regard to any duty of confidentiality.
For notes containing personal information we recommend using a local model in the plugin. The data then never leaves your device (see section 2).
4. Third-country transfer to OpenRouter (USA)
OpenRouter, Inc., based in the United States, is the model gateway through which we run AI processing. When you use DecksMD Pro, the content described in section 3 is transferred to the USA.
OpenRouter in turn forwards the request to the respective model provider, which performs the actual processing. Those providers are sub-processors of OpenRouter and may be based in the USA or in further third countries. Which provider is used depends on the subject area and the quality tier selected, and may change.
The USA is a third country without a blanket adequacy decision covering all recipients. The transfer is based on the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR), which form part of our agreement with OpenRouter.
Despite those safeguards, it cannot be entirely ruled out that US authorities may demand access to data under US law, and that you would not have remedies comparable to those under EU law. We draw your attention to this risk explicitly.
A copy of the safeguards is available on request at support@decksmd.app.
5. Account and sign-in
Using DecksMD Pro requires an account.
| Data | Purpose | Legal basis |
|---|---|---|
| Email address, user ID | Account management, sign-in, linking the subscription | Art. 6(1)(b) |
| Password hash or Google sign-in | Authentication | Art. 6(1)(b) |
| Account status, timestamps | Performance of the contract | Art. 6(1)(b) |
Sign-in is handled by Supabase; the project runs in a region inside the EU. Account emails (signup confirmation, password reset) are sent through Resend, which processes your email address and delivery status in the USA under standard contractual clauses (Art. 46(2)(c) GDPR). These emails contain no open-tracking pixels and no click tracking. If you sign in with Google, Google transmits the data required for this (name, email address) to us; Google’s privacy policy applies additionally.
6. Device linking
Linking your vault to your account creates a device token.
- We store only a cryptographic hash of the token, never the token itself. The token cannot be derived from that value.
- We also store your vault name as a label, a random device ID, and the times of linking and last use.
- One-time linking codes are likewise stored only as a hash and expire after five minutes.
Legal basis: Art. 6(1)(b) GDPR (performance of the contract) and Art. 6(1)(f) GDPR — legitimate interest in securing access and in making linked devices visible and revocable to you.
7. Consumption and billing
Per account we store the tokens consumed and the cost incurred for the current day and month, the remaining free allowance, and monthly totals for previous months.
Purpose: enforcing the agreed usage limits, billing, and detecting abuse. Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR (legitimate interest in abuse prevention and cost control).
8. Payment processing
Sales run through Lemon Squeezy LLC as Merchant of Record. You enter payment details (card data, billing address, tax details) directly with Lemon Squeezy; we neither receive nor store payment data.
From Lemon Squeezy we receive by webhook: subscription, customer, order and variant IDs, status, renewal and end dates, and the email address. We need these to link your subscription to your account and enable access.
Legal basis: Art. 6(1)(b) GDPR; for tax retention, Art. 6(1)(c) GDPR.
9. Website, logs and analytics
Hosting: The website runs on Vercel, the service on Cloudflare. Our database runs with its primary location inside the EU. On access the providers process technically necessary connection data including IP address. Legal basis: Art. 6(1)(f) GDPR (secure and functional provision).
Analytics: We use Vercel Web Analytics. It operates without cookies and without cross-device recognition, collecting aggregate metrics such as pages viewed, country of origin and device type. No personal profile is created. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in statistical evaluation of usage).
Fonts: The typeface we use (Inter) is served from our own servers. There is no connection to Google Fonts or any other font CDN, so no IP address is transmitted to a third party for this purpose.
Cookies: We set only technically necessary cookies for your sign-in session. No advertising or tracking cookies are set, so no consent is required (§ 25(2)(2) TDDDG).
Admin log: Administrative changes to accounts (such as blocking or enabling) are logged with a timestamp and the acting person. Legal basis: Art. 6(1)(f) GDPR (accountability).
10. Recipients at a glance
| Recipient | Role | Data processed | Location |
|---|---|---|---|
| Cloudflare, Inc. | Service and database operation | Connection data, account data | EU (database), global |
| OpenRouter, Inc. | AI processing | The content you submit | USA |
| Supabase, Inc. | Authentication | Email address, user ID | EU |
| Resend (Plus Five Five, Inc.) | Sending account emails | Email address, delivery status | USA |
| Lemon Squeezy LLC | Merchant of Record, payments | Payment and subscription data | USA |
| Vercel, Inc. | Website hosting, analytics | Connection data, usage statistics | USA/EU |
| Google LLC | Only if you sign in with Google | Name, email address | USA |
We do not pass your data to anyone beyond these recipients unless legally obliged to.
The service providers we use may change over time. We update this overview accordingly; the version published on this page is the applicable one.
11. Retention
- Account data: for the life of the account; removed on deletion unless a retention obligation applies.
- Subscription and invoice data: up to ten years under commercial and tax retention rules (§ 147 AO, § 257 HGB).
- Device tokens: until the device is revoked or the account is deleted.
- Linking codes: five minutes.
- Monthly consumption totals: until the account is deleted.
- Your content: not stored (section 3).
12. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing based on legitimate interests (Art. 21).
An informal message to support@decksmd.app is enough. We reply within the statutory period of one month. A self-service account deletion feature is in preparation; until then we delete your account manually on such a request.
You also have the right to lodge a complaint with a supervisory authority. Ours is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit Alt-Moabit 59–61, 10555 Berlin, Germany www.datenschutz-berlin.de
13. Changes to this policy
We update this policy when the service or the legal position changes. The version published on this page applies; the date above shows its status.