Language
Privacy Notice
Last updated: 19. August 2026. This text is generated from the same source as the version inside the app and is therefore word for word identical to it.
What this policy covers
This is the privacy policy of the Qardbox app, not of this website. It describes what the app does on your device and in your iCloud. What this website processes is set out in the privacy notice for the website.
Overview
This privacy notice informs pursuant to Article 13 GDPR about the type, scope and purpose of processing personal data when using Qardbox. The provider operates no server and collects no usage, tracking or advertising data.
What this means for you in practice
This notice says what happens to your data when you use Qardbox. It is short because little happens: there is no server belonging to the developer, no account, and no sign-in. What you write into the app stays on your device, and if you switch on iCloud sync, in your own iCloud account.
Every section appears twice: the legally precise wording on top, and the same thing in everyday language in the box below.
Purposes and legal basis
The purpose of processing is to provide the flashcard function including spaced repetition scheduling (FSRS). The legal basis is Art. 6(1)(b) GDPR (fulfilment of a contract to which the data subject is party); local storage is strictly necessary for the function requested by the user (§25(2) TDDDG).
What this means for you in practice
Your entries are processed for exactly one purpose: so the app does what you opened it for. It stores your cards and works out when you should see which one again.
You do not have to give consent for this, and there is none to refuse either. The law does not provide for consent where processing is necessary for the service you asked for anyway. That is why no consent banner appears in Qardbox.
What data and where it stays
Only user-created content (cards, subjects, notes), learning states and ratings (FSRS), and app settings are processed. This data is stored locally on the device. No transmission to the controller takes place.
What this means for you in practice
What is processed is what you create yourself: your subjects, your cards with question, solution, categories, and note, plus your ratings and the review dates calculated from them, and your settings in the app.
All of that sits on your device. The developer gets to see none of it, and not out of restraint but because there is no server it could go to.
iCloud synchronization and third country
If iCloud synchronisation is enabled (disabled by default), the data is processed in the user’s private iCloud database at Apple. The controller has no access to this database; they know neither the user’s Apple ID nor hold any key material. A third-country element may arise from Apple’s infrastructure; Apple Inc. is certified under the EU-US Data Privacy Framework. The content fields of the cards (question, solution, categories, note) and the subject names are declared as encrypted fields in the database; with the “Advanced Data Protection” feature enabled they are therefore subject to end-to-end encryption to which Apple has no access either. The remaining fields, in particular ratings, timestamps, and review dates, are not covered by this.
What this means for you in practice
Sync is off out of the box; you switch it on deliberately. After that your data sits in YOUR private iCloud, not with us: the developer has no access to it and does not even know your Apple ID.
What your cards actually say is protected in particular. Question, solution, categories, note, and the subject names are set up as encrypted fields. If you switch on Advanced Data Protection in your iCloud settings, Apple cannot read them either.
Said honestly: that applies to the contents, not to everything. When you studied and how you rated a card stays unencrypted. From that you can tell THAT you studied, not WHAT.
Recipients of the Data
No personal data is transferred to third parties. There are no recipients and no categories of recipients within the meaning of Art. 4 no. 9 GDPR. In particular, no data is transmitted to analytics, advertising, or tracking services, to payment providers, or to credit agencies; the app integrates no third-party services and establishes no connection to servers of the controller. If the user enables iCloud synchronisation, Apple processes the data under the contractual relationship existing between the user and Apple; in doing so, Apple does not act as a processor on behalf of the controller.
What this means for you in practice
To nobody. There are no ad networks, no analytics services, no payment provider, and no server belonging to the developer that anything could go to.
The one exception is one you switch on yourself: if you use iCloud, your data sits with Apple, in your own account. That is your agreement with Apple, not ours.
Reading aloud also stays on your device: iOS generates the speech itself, and the card text is not sent anywhere for it.
No Obligation to Provide Data
The user is under no legal or contractual obligation to provide personal data. Entering content is factually necessary in order to use the study function, but takes place exclusively locally on the device and does not constitute provision to the controller. Failure to provide data has no consequence other than that the corresponding functions of the app cannot be used.
What this means for you in practice
You do not have to give the developer anything, and you do not give them anything either. What you type in, you need for yourself: no cards, no quiz.
Anyone who enters nothing suffers nothing worse than an empty app. It never asks for an account, an email address, or a name.
Storage duration and deletion
There are no provider-side retention periods. Data is stored until the user deletes it (Article 17 GDPR). Deletion happens in the app or by uninstalling; with Sync active, deletions are propagated to iCloud.
What this means for you in practice
There is no deadline after which anything is deleted, and none after which anything would have to be kept. Your data stays as long as you leave it there.
You can delete it individually in the app, entirely via Settings, Privacy, “Delete All Data”, or by removing the app. If iCloud sync is on, those deletions take effect there too.
There is no provider who would still hold a copy afterwards.
Your data-subject rights (Art. 15–21)
The data subject has the rights to access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20) and objection (Article 21). These rights are immediately exercisable in the app as the user has complete control over their locally stored data.
What this means for you in practice
Your rights are already built in: access = you see everything directly in the app. Rectification = you edit any card. Erasure = Settings → Privacy → Delete all data. Data copy = Settings → Privacy → Save data copy.
No automated decision-making
No automated decision-making including profiling within the meaning of Article 22 GDPR takes place. The FSRS algorithm serves only the local calculation of review dates and has no legal or similarly significant effect.
What this means for you in practice
The app does not judge you and decides nothing about you. It does not categorise you, does not compare you with anyone, and passes nothing about you on.
The FSRS algorithm works out exactly one thing: when you should next see a particular card. That happens on your device and affects nothing outside the app.
Children
The service is not specifically directed at children. Since no personal data is transmitted to the controller, no data from children is collected; consent of the holder of parental responsibility under Article 8 GDPR is therefore not required.
What this means for you in practice
The app is not aimed at children in particular, but it does not exclude them either. Since nothing is transmitted to the developer anyway, no data is collected from children either.
So there is neither an age check nor parental consent here: there is simply nothing to consent to.
Data security
Technical and organisational measures appropriate to the risk are taken (Art. 32(1) GDPR). These include, in detail: encryption of data at rest through iOS Data Protection at operating-system level, transport encryption using TLS 1.3 during synchronisation, restriction of access to the private database bound to the user’s Apple ID, the absence of any logging of content, and the declaration of the content fields as encrypted fields, which results in end-to-end encryption when Advanced Data Protection is enabled. The measures are chosen taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing.
What this means for you in practice
On the device your data is protected by iOS encryption, as long as your device has a passcode. On its way to iCloud it is additionally encrypted in transit.
The contents of your cards are never written down anywhere, neither in logs nor in crash reports. And with Advanced Data Protection they are encrypted in iCloud in such a way that Apple cannot read them either.
Supervisory authority and right to complain
Without prejudice to other administrative or judicial remedies, the data subject has the right to lodge a complaint with a data protection authority (Article 77 GDPR). The authority responsible for the seat of the controller is competent (see below).
What this means for you in practice
If you get the impression that something is not right with your data, you can lodge a complaint with a data protection supervisory authority. The authority at the controller’s place of establishment is competent; its address is at the end of this notice.
It costs you nothing and brings you no disadvantages. Other legal remedies remain unaffected, so you do not have to choose one route.
Changes to this policy
The controller reserves the right to amend this privacy policy where this becomes necessary because of changed app functionality or a changed legal situation. The policy contained in the installed app version is always authoritative; it is delivered with the app update. Versions provided outside the app (PDF, website) are generated from the same source and reflect the same state.
What this means for you in practice
This policy can change when the app does something new or the law changes. What applies is always what is in the app itself, in the version you have installed: a new policy reaches you with an app update, not quietly overnight.
The PDF and website versions come from the same source as the one in the app. They therefore cannot say something different, only be older.
What is NOT required here
These usual data protection obligations have been reviewed and are justifiably not applicable here because Qardbox collects no data and operates no server.
No data processing agreement (Article 28)
There is no data processing agreement. The controller engages no service providers to process personal data. Apple provides iCloud to the user under its own terms and is therefore not a processor for the provider.
What this means for you in practice
We do not pass your data to any service provider who processes it on our behalf. So there is no such contract.
No data protection officer (Article 37, Section 38 BDSG)
There is no obligation to appoint a data protection officer. The requirements of Article 37 (1) GDPR and Section 38 (1) BDSG (including permanent employment of at least 20 people in automated processing) are not met.
What this means for you in practice
An official data protection officer is legally only required above a certain size. This is not reached with a solo developer. The contact is the controller themselves.
No data protection impact assessment (Article 35)
A data protection impact assessment is not required. Processing does not have a likely high risk to rights and freedoms; there is no extensive profiling, systematic monitoring, or extensive processing of special categories.
What this means for you in practice
Such a risk assessment is only mandatory for particularly intrusive processing. Since practically nothing is processed here, it is not needed.
No third country transfer by the provider (Article 44 et seq.)
The controller transmits no data to third countries. Standard contractual clauses or other guarantees under Article 46 GDPR are therefore not applicable. Any third country transfer arises solely in Apple's responsibility within the user's iCloud.
What this means for you in practice
We send nothing abroad. If your iCloud has international involvement, that is Apple's responsibility and Apple is certified for it.
No consent management (Article 7)
Processing is not based on consent, but on Article 6(1)(b) GDPR. Consent management is not required; local storage of the data needed for the app to function is strictly necessary under Section 25(2) TDDDG and therefore exempt from consent.
What this means for you in practice
There are no cookie banners or consent prompts because the app needs no consent: it only stores what is necessary for its function.
No ISO 27001 certification
ISO/IEC 27001 certification is not a legal requirement. For this app's scope and risk, building a certified information security management system would be disproportionate; measures taken are appropriate to risk (Article 32).
What this means for you in practice
Such a large security certificate is not required for a free learning app and would be excessive. The actual security measures are still in place.
Controller
Controller within the meaning of Article 4 No. 7 GDPR and service provider under Section 5 NetzDG.
Simon Harre
Walter-Klausch-Str. 15
14482 Potsdam
Deutschland
privacy@qardbox.com
Competent supervisory authority
You can file a complaint with this authority under Article 77 GDPR.
Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht
Land Brandenburg
Stahnsdorfer Damm 77
14532 Kleinmachnow