Skip to content
SwiftCards Get SwiftCards for Mac Get SwiftCards

Privacy Policy

Version: July 2026

This English translation is provided for convenience only. In the event of any discrepancies, the German version of this privacy statement shall prevail.

The protection of personal data is very important to KGE. Here we inform you about how we process your personal data when you use our app SwiftCards (section C). You will also find general information about your rights regarding data processing (section D). If you have any questions after reading this privacy statement, please contact us at request@kge-it.de.

A. Who is responsible for processing my personal data?

The controller within the meaning of Article 4 No. 7 GDPR is KGE UG (haftungsbeschränkt), Haardtring 15, 64295 Darmstadt, Germany ("KGE").

B. Data protection information for visitors of our websites

1. Which data are processed when visiting the KGE website?

When accessing the KGE website, various data about the accessing system are automatically stored. This includes the browser type, browser version, operating system, the website from which access is made to the KGE website, the subpages accessed on the KGE website, the date and time of access, the Internet Protocol address (IP address), the Internet service provider, and comparable data. KGE uses these data to make the website accessible, to identify and resolve technical issues, and to prevent and, if necessary, prosecute misuse of KGE's services. In addition, KGE uses these data in anonymized form, i.e., without the possibility of identifying the user, for statistical purposes and to improve the website.

The legal basis for this processing of personal usage data is our legitimate interests under Article 6(1)(f) GDPR.

Matomo

We use Matomo (InnoCraft Limited), an open-source software for statistical analysis of visitor access on this website. Matomo is operated by us on our own servers (no data is shared with third parties for advertising purposes).

Processing is carried out to analyze the use of our website and to improve our offering. In particular, the following data are processed: pages/URLs visited, referrer URL (the page you came from), date/time, shortened/anonymized IP address, technical information about the device/browser (e.g., user agent), approximate location (derived from the anonymized IP).

Cookies: Matomo is configured so that no tracking cookies are set.

IP anonymization: We use IP anonymization so your IP address is only processed in shortened form.

Objection / opt-out: You can object to web analytics at any time. In this case an opt-out will be set so Matomo will no longer record your visit; you can set the opt-out directly here:

The legal basis (where applicable) is Article 6(1)(f) GDPR (legitimate interest) in the statistical analysis and optimization of our website. If consent is required, processing is based on your consent (Article 6(1)(a) GDPR).

2. How long is my personal data stored?

Personal data of visitors to our website are deleted when their knowledge is no longer required for the purposes described in this privacy policy, unless statutory provisions require longer storage. Usage data are regularly stored for a period of 30 days (B.1.).

C. Data protection information for users of our app SwiftCards

I. General

We process personal data that you voluntarily provide as a user of our app (the "App") and data that arises when you use the App. To use the App, after installing and opening it, signing in with your Apple account ("Sign in with Apple") is required. Through the sign-in, we receive a pseudonymous user identifier and — if and to the extent shared by you during sign-in — your name and email address; if you use Apple's "Hide My Email" feature, we only receive a forwarding address assigned by Apple (@privaterelay.appleid.com). There is no further transfer of your access data such as passwords. These data are needed for authentication and identification and are stored in Google Firebase Authentication for this purpose (see section C.V.). The legal basis is Article 6(1)(b) GDPR.

II. AI-based creation of flashcards

The core function of the App is the automated creation of flashcards from study material that you upload in the App (e.g. PDF, Word, PowerPoint, or image files). For this purpose, the uploaded content is transmitted via server functions operated by KGE (Google Cloud Functions) to Google's AI services (Vertex AI / Gemini) and processed there to create the flashcards. Larger files are temporarily stored in Google Firebase Storage for the duration of the processing and are automatically deleted there no later than one day after the upload.

Google processes this content as a processor within the meaning of Article 28 GDPR exclusively to provide the service; under the Google Cloud contractual terms, your inputs and the generated outputs are not used to train Google's AI models. To speed up processing, inputs may be cached for up to 24 hours and logged briefly for abuse detection.

The created flashcards and your decks are stored exclusively locally on your device and are not transmitted to KGE.

Please do not upload study material that contains special categories of personal data within the meaning of Article 9 GDPR (e.g. health data) or personal data of third parties, unless this is necessary for the creation of your flashcards.

The legal basis is Article 6(1)(b) GDPR.

III. Credits and abuse prevention

To provide the credit system (Credits, see our conditions of use), we maintain a server-side credit account that is assigned to your pseudonymous user identifier. It stores the one-time welcome balance, purchased credit packs, the daily subscription allowance, and the respective consumption. The legal basis is Article 6(1)(b) GDPR.

To protect against abuse (e.g. manipulation of the credit balance or unauthorized access to the AI interface), we use Google Firebase App Check: Apple's App Attest service is used to verify that requests originate from an unmodified app instance obtained from the App Store; device-related attestation data are processed for this purpose. We also log technical verification values of individual requests. The legal basis is Article 6(1)(f) GDPR (legitimate interest in preventing abuse).

IV. In-app purchase

If you make an in-app purchase, the transaction and payment are handled exclusively between you and the Apple App Store under its terms and privacy policies: https://www.apple.com/legal/internet-services/itunes/de/terms.html and https://www.apple.com/legal/privacy/de-ww/.

The legal basis is Article 6(1)(b) GDPR.

Subscription management (RevenueCat)

To manage in-app purchases and subscriptions we use RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA. RevenueCat processes technical information (e.g., a pseudonymous app user ID corresponding to your user identifier, purchase and subscription status, and device-related information) to correctly assign and provide purchases and subscriptions. Processing is carried out for contract performance under Article 6(1)(b) GDPR. It is not used for advertising or tracking purposes. Data is transferred to the USA on the basis of appropriate safeguards under Article 46 GDPR (EU Standard Contractual Clauses, see section C.IX.).

V. Firebase, Google Analytics, and App Analytics

Our app uses Google Firebase (more information: https://firebase.google.com/docs), a development platform of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We use the Firebase services Authentication (sign-in, see C.I.), Cloud Functions and Cloud Storage (AI processing, see C.II.), App Check (abuse prevention, see C.III.), and Cloud Firestore (credit management, see C.III.). Google processes the data as a processor on the basis of a data processing agreement (Google Cloud Data Processing Addendum and Firebase Data Processing and Security Terms) exclusively on our instructions. The legal basis is Article 6(1)(b) GDPR.

In addition, we use — only with your consent — Google Analytics for Firebase to analyze and improve app usage. Event data about the use of the App are processed (e.g. features used, app version, device type, duration of individual processing steps); the contents of your study material and your flashcards are excluded from this, no advertising identifiers are collected, and the data are not linked to your user account. Usage data are transmitted to Google in pseudonymized form. The legal basis is your consent (Article 6(1)(a) GDPR), which you can give when first starting the App and withdraw at any time with effect for the future in Settings under "Data Protection". We also use "App Analytics", an analytics service by Apple Inc. This tool processes data about downloads and app usage. We do not receive personal data about you from Apple Inc. The legal basis for this is our legitimate interests under Article 6(1)(f) GDPR.

To keep the App stable we use Firebase Crashlytics, a crash reporting service. If the App crashes or a serious technical error occurs, technical information is transmitted (e.g. crash log/stack trace, app version, operating system version, device model, a pseudonymous installation identifier, and the time of the error). The contents of your study material and your flashcards are not transmitted. The legal basis is our legitimate interest in detecting and fixing technical errors (Article 6(1)(f) GDPR). You can object to crash reporting at any time by disabling it in Settings under "Data Protection".

VI. Feedback

If you send us feedback via the App, we process the message you enter and — for context and troubleshooting — your pseudonymous user identifier, the app version, and information about your operating system and the current session. The session's diagnostic log and the associated AI requests are also transmitted with the feedback; these may contain excerpts from the study material you uploaded. This is pointed out in the feedback form. We use these data exclusively to handle your request and to improve the App. The legal basis is Article 6(1)(b) or (f) GDPR.

VII. Automatic error diagnostics

If the creation of your flashcards fails for technical reasons, the App can transmit an error report to us so that we can reproduce and fix the problem. Such a report contains the session's diagnostic log, the associated AI requests, and the source files you added themselves — it may therefore contain the full content of your study material. Your pseudonymous user identifier, the app version, and information about your operating system and the current session are also transmitted.

Automatic transmission only takes place if you have consented to error diagnostics (when first starting the App or in Settings under "Data Protection"). Without this consent, the App asks you in each individual case whether the report should be sent. The legal basis is your consent (Article 6(1)(a) GDPR); you can withdraw it at any time in Settings with effect for the future. Error reports are used exclusively for error analysis and are automatically deleted no later than 90 days after transmission.

VIII. Disclosure of personal data

We disclose your personal data to third parties:

  • if this is necessary for the purposes described above,
  • at the request of a national authority,
  • on the basis of a court decision,
  • if required by law,
  • to defend ourselves against claims or allegations by third parties,
  • to exercise and protect KGE's rights and security,
  • if you have expressly consented beforehand.

We try to inform you about legal requests regarding your data when appropriate, unless prohibited by law or court order or in an emergency. We may challenge requests if they are excessive, vague, or inadequate. For certain technical processes, KGE uses external service providers who receive access to personal data as required to perform their tasks. These providers are carefully selected, meet high data protection standards, are bound to confidentiality, and process data only on KGE's instructions.

IX. Transfers to third countries

Where we transfer personal data to service providers in the USA (in particular Google LLC and RevenueCat, Inc.), this is done on the basis of the European Commission's adequacy decision on the EU-U.S. Data Privacy Framework (Article 45(3) GDPR), provided the respective recipient is certified under the DPF; Google LLC is DPF-certified. In addition, and for recipients without DPF certification, we base the transfer on the European Commission's Standard Contractual Clauses (Article 46(2)(c) GDPR), where appropriate with additional safeguards.

X. How long we store data

We store your personal data as long as you have an account with us. Beyond that, we store personal data only if required by law or otherwise necessary. In detail: Study material uploaded in the App is deleted from our servers no later than one day after the upload. We store account data and credit balances as long as your account exists; after more than one year of inactivity, we may delete account data in accordance with our conditions of use. We store feedback as long as this is necessary to handle your request and to improve the App. Error diagnostics reports, including the source files they contain, are automatically deleted no later than 90 days after transmission. Your flashcards and decks are stored exclusively locally on your device and are under your sole control.

D. What rights do I have in relation to my personal data?

You have the right to information about the personal data stored by us and, if legal requirements are met, the right to correction, deletion, and restriction of processing. You also have the right to receive the personal data you provided in a structured, common, and machine-readable format and to transfer it to another controller. Where technically possible, you can request that we transmit the data directly to another controller. If processing is based on legitimate interests under Article 6(1)(f) GDPR, you have the right to object under the conditions described in Article 21 GDPR. You can also lodge a complaint with the competent supervisory authority.

SwiftCards

SwiftCards generates flashcards from your material — studying happens in the app you already use. SwiftCards is an independent product and is not affiliated with Anki or Ankitects Pty Ltd.

Privacy Terms Imprint Contact Deutsch English