Deckly

Privacy Policy

Last updated: 12 July 2026

Deckly turns content you choose — a video, podcast, article, PDF or your own text — into a deck of note cards. This policy explains exactly what we collect, why, who processes it, and how you delete it.

The short version. We do not track you. We do not show ads. We do not sell or share your data with data brokers, and we run no advertising or analytics SDKs. We collect the minimum needed to sign you in, produce your cards, and enforce plan limits. You can delete your account and all of its data from inside the app at any time.

1. Who we are

Deckly is operated by Anıl Sancar (“Deckly”, “we”, “us”). Contact: anilsancarr@gmail.com.

2. What we collect

DataWhyWhere it lives
Account identifier — your Apple user ID, and your email address if you choose to share it when using Sign in with Apple (this may be Apple’s private relay address) To create your account, keep your library and plan limits tied to you across devices Supabase (our database)
Content you submit — the link, text or PDF you ask us to distill To produce your cards. This is the core function of the app Sent to our server and to Google Gemini for processing (see §3)
Deck records — title, source type, source URL, language, template, card count. Card content itself is stored on our server only when a deck is produced in the background (long podcasts) so it can be delivered to your device To sync and deliver your decks Supabase
Usage records — a row per distillation: source type, content duration, model used, timestamp To enforce free/Pro plan limits and prevent abuse Supabase
Subscription status — your purchase state and an app user ID matching your account To unlock Deckly Pro and restore purchases RevenueCat + Supabase
Push token — a device notification token, only if you enable notifications To tell you when a long deck is ready, and for the optional weekly digest Supabase
On-device data — your decks, settings, onboarding answers, plan counter, and the “Card of the Day” widget image To run the app offline Only on your device (app storage, Keychain, and the app’s widget container)

What we do not collect

3. Who processes your data

We use a small number of service providers. They process data on our behalf and only for the purposes below.

We do not sell your personal data, and we do not share it for advertising or for any purpose that would count as “sharing” or “targeted advertising” under laws such as the GDPR, the CCPA/CPRA, or Türkiye’s KVKK.

4. Why we may process your data (legal bases)

5. How long we keep it

6. Your rights and choices

7. Security

Traffic is encrypted in transit (HTTPS/TLS). Our database enforces row-level security so an account can only ever read its own rows. API keys for our AI and database providers are held server-side and are never shipped inside the app. No system is perfectly secure, but we design for least privilege and keep the data we hold to a minimum.

8. International transfers

Our servers and providers are located in the United States and other countries. If you use Deckly from the European Economic Area, the United Kingdom, or Türkiye, your data will be transferred outside your country. We rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, where required.

9. Children

Deckly is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their data. If you believe a child has given us personal data, contact anilsancarr@gmail.com and we will delete it.

10. Changes

If we change this policy we will update the date at the top and, for significant changes, tell you in the app. Continuing to use Deckly after a change means you accept the updated policy.

11. Contact

Questions, requests, or complaints: anilsancarr@gmail.com