← All apps

Factstore — Privacy Policy

Last updated: 2026-04-24

1. Overview

Factstore is a flashcard learning app with optional family profiles, quiz tracking, and AI-assisted card generation. This privacy policy explains what personal data the app processes, for what purposes, on which legal bases, and what rights you have.

2. Controller

Stonemiller
Föttingerweg 13
90431 Nürnberg, Germany
Email: support@stonemiller.freshdesk.com

3. Data We Process

3.1 Data stored locally on your device

By default, Factstore stores all of your data exclusively on your device in a local SQLite database. This includes:

This local data is never transmitted to our servers unless you explicitly enable the cloud sync feature.

3.2 Cloud sync (optional, opt-in)

If you enable cloud sync in the settings and create an account, the data listed in 3.1 as well as the following is transmitted to and stored at our processor Supabase (see §5):

Cloud sync is fully optional. The app is fully functional offline without an account. A single account can be shared by a family — profiles within the app keep learning progress separate per member.

3.3 AI-assisted card generation (optional, user-configured)

Factstore can optionally generate flashcards from text you provide, using an AI provider you configure in the settings:

3.4 Error reports and user feedback

We use Sentry (see §5) to detect and fix crashes and errors. When an error occurs, the following is transmitted:

If you submit the in-app Feedback form, we transmit:

We do not collect:

4. Purposes and Legal Bases (GDPR Art. 6)

PurposeLegal basis
Local app functionalityArt. 6(1)(b) — contract performance
Cloud sync (when enabled)Art. 6(1)(a) — consent / Art. 6(1)(b) — contract
AI card generation (when configured)Art. 6(1)(a) — consent (by configuring and using the feature)
Error monitoringArt. 6(1)(f) — legitimate interest in reliable software
User feedbackArt. 6(1)(a) — consent (by submitting the form)

5. Third-Party Processors

We use the following processors under Art. 28 GDPR data processing agreements:

6. International Data Transfers

Some processors (notably Supabase Inc., Sentry, and Google) are based in the United States and may process data outside the EU/EEA. For such transfers we rely on the EU-US Data Privacy Framework and/or the EU Standard Contractual Clauses (SCCs) where applicable.

7. Retention

8. Your Rights (GDPR Art. 15–22)

You have the right to:

To exercise these rights, contact us at support@stonemiller.freshdesk.com.

9. Supervisory Authority

You may lodge a complaint with the data protection authority of your EU member state. For the controller's place of residence (Germany), the competent authority is the State Commissioner for Data Protection of the respective federal state.

10. Security

All cloud-synced data is transmitted via HTTPS/TLS. Passwords are hashed by Supabase's authentication service (bcrypt-based) and never stored in plain text. Row-level security (RLS) ensures that each authenticated user can access only their own data.

11. Children's Privacy

Factstore is a learning app that can be used by learners of any age, including children, typically under the guidance of a parent or teacher. The app does not require a real-world identity: profiles within the app may use any name or nickname. When a parent or guardian enables cloud sync, they act as the data controller for any child profiles they create; no data is transmitted unless cloud sync is explicitly enabled.

12. Changes to This Policy

We may update this policy as the app evolves. Material changes will be announced in the app or on this page. The “Last updated” date above reflects the current version.

13. Contact

For any privacy-related questions, please contact support@stonemiller.freshdesk.com.