Privacy
This page explains the privacy architecture built into FaceCards. It should be read alongside the final lawyer-reviewed Privacy Notice before public launch.
What FaceCards is designed not to store
Flashcard questions, answers, decks, screenshots, camera video, face photographs, eye images, facial-landmark history and biometric identity templates are outside the intended backend data model.
Local processing
Tracking and calibration run inside the FaceCards app. Camera frames are analysed on the device and FaceCards does not upload raw camera frames, face images or eye images to its servers. FaceCards may sync derived calibration settings, such as measured thresholds and camera labels, to the account so a saved calibration can be reused.
MediaPipe
FaceCards uses Google MediaPipe Tasks for on-device computer-vision processing. Google states that MediaPipe Solutions may collect limited operational information such as SDK/session, inference, performance, application/input metadata and system-environment metrics. FaceCards does not intentionally send raw camera images to Google. The final production Privacy Notice and consent flow must accurately describe the MediaPipe version actually shipped and any telemetry it performs.
Account and security data
FaceCards stores the account information needed to sign in, verify email addresses, recover passwords and operate licences. Security-sensitive verification, reset and deletion links are stored only as token hashes. Rate-limit identifiers are also hashed rather than storing raw IP/email combinations in the limiter table.
Devices and purchases
Registered controller devices and purchase/entitlement records are needed to enforce the active-device cap and unlock FaceCards across supported platforms. Users can remove old devices themselves. If an account is deleted, user-owned product data is deleted; purchase records may be detached from the user and retained where accounting or legal obligations require it.
Usage analytics
The aggregate analytics model is intentionally small: sessions, active minutes, gesture-trigger totals, platform and app version. It has no user foreign key and does not record what a person studied.
