Deckly
Privacy Policy
Last updated: 12 July 2026
Deckly turns content you choose — a video, podcast, article, PDF or your own text — into a deck of note cards. This policy explains exactly what we collect, why, who processes it, and how you delete it.
The short version. We do not track you. We do not show ads. We do not sell or share your data with data brokers, and we run no advertising or analytics SDKs. We collect the minimum needed to sign you in, produce your cards, and enforce plan limits. You can delete your account and all of its data from inside the app at any time.
1. Who we are
Deckly is operated by Anıl Sancar (“Deckly”, “we”, “us”). Contact: anilsancarr@gmail.com.
2. What we collect
| Data | Why | Where it lives |
| Account identifier — your Apple user ID, and your email address if you choose to share it when using Sign in with Apple (this may be Apple’s private relay address) |
To create your account, keep your library and plan limits tied to you across devices |
Supabase (our database) |
| Content you submit — the link, text or PDF you ask us to distill |
To produce your cards. This is the core function of the app |
Sent to our server and to Google Gemini for processing (see §3) |
| Deck records — title, source type, source URL, language, template, card count. Card content itself is stored on our server only when a deck is produced in the background (long podcasts) so it can be delivered to your device |
To sync and deliver your decks |
Supabase |
| Usage records — a row per distillation: source type, content duration, model used, timestamp |
To enforce free/Pro plan limits and prevent abuse |
Supabase |
| Subscription status — your purchase state and an app user ID matching your account |
To unlock Deckly Pro and restore purchases |
RevenueCat + Supabase |
| Push token — a device notification token, only if you enable notifications |
To tell you when a long deck is ready, and for the optional weekly digest |
Supabase |
| On-device data — your decks, settings, onboarding answers, plan counter, and the “Card of the Day” widget image |
To run the app offline |
Only on your device (app storage, Keychain, and the app’s widget container) |
What we do not collect
- No advertising identifiers (no IDFA), no ad networks, no cross-app or cross-site tracking.
- No third-party analytics or attribution SDKs.
- No access to your photo library contents. Deckly can save an exported card to Photos with your permission; it never reads your photos.
- No location, contacts, microphone, or health data.
3. Who processes your data
We use a small number of service providers. They process data on our behalf and only for the purposes below.
- Apple — Sign in with Apple, App Store purchases, push delivery.
- Supabase — our database, authentication, and server functions (hosted in the United States).
- Google (Gemini API) — the content you submit is sent to Google’s Gemini models to generate your cards. For podcasts, the audio file is uploaded to Google’s file API for transcription and summarization. Do not submit content you are not comfortable sending to a third-party AI service, and do not submit confidential or sensitive material.
- RevenueCat — subscription and purchase management.
- Expo — delivery of push notifications.
We do not sell your personal data, and we do not share it for advertising or for any purpose that would count as “sharing” or “targeted advertising” under laws such as the GDPR, the CCPA/CPRA, or Türkiye’s KVKK.
4. Why we may process your data (legal bases)
- To perform our contract with you — creating your account, producing your cards, delivering decks, managing your subscription.
- Our legitimate interests — enforcing plan limits, preventing abuse and fraud, keeping the service secure and working.
- Your consent — push notifications and saving cards to Photos. You can withdraw either at any time in iOS Settings.
- Legal obligation — where we must keep records (for example, tax records relating to purchases).
5. How long we keep it
- Account, deck records, usage records, subscription status and push tokens are kept while your account exists.
- When you delete your account, all of it is deleted — your account and every associated record (decks, usage history, entitlements, push tokens) is removed from our database immediately.
- Content you submit is processed to create your deck and is not retained by us as a separate copy; audio uploaded for podcast distillation is handled by Google under their retention terms.
- Purchase records held by Apple and RevenueCat are retained under their own policies and may persist for accounting purposes.
- On-device data is removed when you delete your account or uninstall the app.
6. Your rights and choices
- Delete everything, yourself: open the app → Settings → Delete Account. This permanently deletes your account and all associated data. It cannot be undone.
- Access, correction, portability, objection, restriction: depending on where you live (for example, under the GDPR, the CCPA/CPRA, or the KVKK), you may have these rights. Email anilsancarr@gmail.com and we will respond within the period required by law.
- Notifications and Photos access: revoke at any time in iOS Settings.
- Deleting your account does not cancel an active subscription. Manage or cancel subscriptions in your Apple account: apps.apple.com/account/subscriptions.
- You may lodge a complaint with your local data protection authority.
7. Security
Traffic is encrypted in transit (HTTPS/TLS). Our database enforces row-level security so an account can only ever read its own rows. API keys for our AI and database providers are held server-side and are never shipped inside the app. No system is perfectly secure, but we design for least privilege and keep the data we hold to a minimum.
8. International transfers
Our servers and providers are located in the United States and other countries. If you use Deckly from the European Economic Area, the United Kingdom, or Türkiye, your data will be transferred outside your country. We rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, where required.
9. Children
Deckly is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their data. If you believe a child has given us personal data, contact anilsancarr@gmail.com and we will delete it.
10. Changes
If we change this policy we will update the date at the top and, for significant changes, tell you in the app. Continuing to use Deckly after a change means you accept the updated policy.
11. Contact
Questions, requests, or complaints: anilsancarr@gmail.com