Privacy Policy
Last updated: 2026-08-13
Piccard ("we", "us", or "our") operates the Piccard web application at piccard.app (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using the Service, you agree to the practices described here.
Who We Are
Piccard is a vocabulary and flashcard learning application. We are the data controller responsible for your personal data as described in this policy. If you have questions, contact us at support@piccard.app.
Information We Collect
Information you provide directly
- Google account data. If you sign in with Google, we request the
emailandprofilescopes. We receive and store your Google account ID, email address, name, and profile picture URL. We do not request access to your Google contacts, documents, or other Google data. - Card content. When you create flashcards, we store the words, translations, definitions, example sentences, pronunciation, tags, and other text you generate or edit. This includes content generated by our AI from your input.
- Images you upload. If you upload a photo to generate flashcards, the image is stored by our cloud infrastructure provider and used to produce vocabulary cards. The image is also sent to a third-party AI service for processing (see Third Parties below).
- Text you submit. Any text you type to generate cards (words, phrases, sentences, questions) is processed by our AI service.
Information collected automatically
- Device identifier. When you first open the Service, we generate a random unique identifier stored in your browser's local storage. This identifier associates your cards and learning history with your device before you sign in, and is merged into your Google account when you do sign in.
- Session token. When you sign in, we issue a session token stored as an HTTP-only cookie and in your browser's local storage. This keeps you logged in for up to 30 days.
- Review and learning history. We record every flashcard review you submit, including your rating, the time of review, and spaced-repetition scheduling data (interval, ease factor, mastery status).
- Usage data. We count the number of card generation calls you make for quota and billing purposes. We also log standard request information (HTTP method, URL path, timestamp) for error diagnosis.
- Error data. When an error occurs, our error-monitoring service receives the error message, stack trace, and the URL and HTTP method of the request. We do not send your personal information to the error-monitoring service.
Information from payment processing
- Stripe customer data. If you buy an energy top-up, we store your Stripe customer ID, your energy balance, and a record of your top-up payments, plus the email associated with your Stripe account. We do not store or process your full card number — Stripe handles all payment card data directly.
How We Use Your Information
- To provide the Service: create and store your flashcards, schedule reviews, track your learning progress.
- To authenticate you and keep your data associated with your account across devices.
- To generate flashcards from your text or image input using AI.
- To enforce energy-balance limits (your balance funds each AI generation).
- To process energy top-up payments and maintain your balance.
- To diagnose and fix bugs, errors, and performance issues.
- To communicate with you about your account, billing, and important service changes.
- To comply with legal obligations.
We do not sell your personal data. We do not use your data for targeted advertising.
Third Parties Who Process Your Data
Cloud infrastructure provider (hosting, database, storage)
The Service runs on a global cloud-infrastructure provider that processes and stores data on our behalf, including: application hosting, the database that holds your user account, cards, review history, and billing state; and file storage for uploaded and AI-generated images. This provider may process data in multiple regions worldwide.
Google (authentication)
Google is used for "Sign in with Google." When you use this feature, Google provides us with your email, name, and profile picture. We only request the minimum scopes needed (email and profile). See Google's Privacy Policy.
Third-party AI service (content generation)
When you generate cards from text or an image, your input text and any uploaded image are sent to a third-party AI content-generation service for processing. The service processes this data to produce flashcard content (translations, definitions, example sentences, pronunciation). This provider may process your input outside your country of residence.
Payment processor (Stripe)
Stripe processes all payment transactions. We never see or store your full card number. We store your Stripe customer ID and a record of your top-up payments to maintain your energy balance. See Stripe's Privacy Policy.
Error-monitoring service
We use a third-party error-monitoring service to track and diagnose errors. The data sent includes error messages, stack traces, HTTP method, and URL path. Personal data transmission is disabled by default, and content from your cards is not sent to this service.
Piccard Browser Extension ("Piccard Word Lookup")
Piccard also offers a Chrome browser extension called Piccard Word Lookup. It operates separately from the web application:
- What it reads. When you select (highlight) a word on a web page, the extension reads the selected text to show an inline definition tooltip. Reading is triggered only by your manual selection — the extension does not scan, collect, or transmit page content on its own.
- Offline lookup. Definitions are resolved from dictionary data bundled inside the extension. No network request is made to perform the lookup.
- Deep-link to Piccard. The only outbound action is opening a link to piccard.app (a normal browser navigation) when you choose to save a word as a flashcard. If you then create an account or cards on piccard.app, the data practices in the rest of this policy apply.
- No account, no telemetry. The extension does not require an account, does not collect personal data, does not use analytics or tracking, and does not store your selections beyond what is needed to display the current tooltip.
YouTube caption capture
On youtube.com video pages the extension offers an optional "mine captions" panel. This works as follows:
- Triggered only by you. The panel opens only when you click the Piccard button on a YouTube video. It never runs in the background and nothing happens automatically.
- What it reads. To list caption lines, the extension reads the video's caption track on your device, from the caption data YouTube has already delivered to your browser for that page. It fetches that caption text using your existing logged-in YouTube session. It does not download the video, does not record or stream audio/video, does not call the YouTube Data API, and does not bypass or circumvent any access control, login, or copy-protection mechanism.
- What leaves the page. Only the single caption line you click is sent onward — its text, the video ID, and the line's start/end time, passed to piccard.app as a normal link. No full transcript is ever exported or transmitted. The extension does not send your captions, viewing history, or any YouTube data to Piccard's servers.
- Replay. A card created from a caption links back to the original video through YouTube's standard privacy-enhanced embed (
youtube-nocookie.com). The video is streamed from YouTube when you replay it; Piccard does not copy or host the video. - Server-side firewall. Piccard's servers never fetch
youtube.com. The caption reading happens entirely in your browser; only the one caption line you choose reaches Piccard.
This feature is governed by the same no-account, no-telemetry, no-analytics commitments as word lookup.
Open-license dictionary data
The extension bundles derived subsets of open-license dictionaries:
- English → Korean/Chinese: open-english-korean-dict (jhseo1211), licensed CC BY-SA 4.0. The derived
en-ko.jsonis a share-alike transform of this source. - Japanese → English: JMdict/EDRDG, the property of the Electronic Dictionary Research and Development Group (EDRDG), used in conformance with its CC BY-SA 3.0 licence. The derived
jmdict-ja.jsonis a transform of thejmdict-simplifiedexport.
Korean → English dictionary bundling is planned but not yet shipped.
Cookies and Local Storage
We use the following storage mechanisms on your device:
- Session cookie — HTTP-only, SameSite=Lax, 30-day lifetime. Keeps you signed in.
- OAuth cookies — HTTP-only, deleted immediately after the Google sign-in flow completes (10-minute max lifetime).
- Browser local storage — used to store your anonymous device identifier, your session token (for API requests), and cached profile data (name, email, picture URL) so the UI loads efficiently.
We do not use third-party advertising cookies, tracking pixels, or analytics cookies.
Data Retention
We retain your data for as long as your account is active. Specifically:
- Cards, review history, and learning data are kept until you delete individual cards or request account deletion.
- Uploaded images are kept in cloud storage until the associated cards are deleted.
- Account and profile data (email, name, picture) are kept until you request account deletion.
- Billing data (Stripe customer ID, top-up payment records) is kept for the duration required by applicable tax and financial regulations.
- Error logs are retained by our error-monitoring service according to their retention policy.
- Session data is automatically deleted when you log out or your session expires (30 days).
We do not currently have automated data deletion or scheduled cleanup processes. If we introduce one in the future, we will update this policy.
Image Access
Images you upload are stored with randomly generated, non-guessable identifiers. However, image URLs are served without authentication — anyone who knows the exact URL can view the image. We do not expose image URLs publicly; they are only returned to you when you view your cards. You should not share image URLs if the content is sensitive.
AI-Generated Content
Flashcards generated by our AI may contain inaccuracies. Translations, definitions, and example sentences are produced by a language model and may be incorrect, outdated, or culturally inappropriate. We are not responsible for the accuracy of AI-generated learning content. You should verify important translations independently.
Your Privacy Rights
GDPR (European Economic Area, United Kingdom, Switzerland)
If you are located in the EEA, UK, or Switzerland, you have the following rights:
- Access — request a copy of your personal data
- Rectification — request correction of inaccurate data
- Erasure — request deletion of your personal data ("right to be forgotten")
- Restriction — request that we limit processing of your data
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests
- Withdraw consent — withdraw consent for processing based on consent
To exercise these rights, email support@piccard.app. We will respond within one month. You also have the right to lodge a complaint with your local data protection authority.
CCPA / CPRA (California)
If you are a California resident, you have the right to:
- Know — request disclosure of the categories and specific pieces of personal data we collect
- Delete — request deletion of your personal data
- Opt out — opt out of the "sale" or "sharing" of your personal data. We do not sell or share your data as defined by California law.
- Non-discrimination — we will not discriminate against you for exercising these rights
To exercise these rights, email support@piccard.app.
China PIPL (People's Republic of China)
If you are located in the PRC, we process your data as described in this policy. For cross-border transfers of your personal data to recipients outside the PRC (including to our cloud infrastructure provider, the AI service, and authentication provider in the United States and other regions), we rely on your consent to this Privacy Policy. You have the right to withdraw consent, though this may affect our ability to provide the Service. You may contact support@piccard.app to exercise your rights under PIPL, including access, correction, deletion, and portability.
Other jurisdictions
If your jurisdiction grants additional privacy rights, we will honor them as required by applicable law. Contact us at support@piccard.app.
Children's Privacy
The Service is not directed to children under 13 (or 16 in some jurisdictions). We do not knowingly collect personal data from children under 13. If you believe we have collected data from a child under 13, contact us at support@piccard.app and we will delete it. Children under 13 should not use the Service. Parents or guardians who believe their child has provided personal data should contact us for prompt deletion.
International Data Transfers
The Service runs on global cloud infrastructure and relies on third-party processors that may operate in multiple regions. Your data, including text and images submitted for AI processing, may be processed in countries other than your own, including the United States. We rely on standard contractual clauses, adequacy decisions, and the privacy protections described in this policy to ensure appropriate safeguards are in place when transferring data internationally, as required by applicable law.
Security
We take reasonable measures to protect your data:
- All API traffic is encrypted via HTTPS/TLS
- Session cookies are HTTP-only and set with SameSite attributes
- Authentication uses OAuth 2.0 with PKCE for Google sign-in
- Passwords are never stored (we do not use password-based authentication)
- Input validation and sanitization are applied at API boundaries
- Error reporting does not transmit personal data by default
However, no method of transmission or storage is completely secure. We cannot guarantee absolute security.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, for significant changes, provide a notice in the Service. Your continued use of the Service after a change takes effect constitutes acceptance of the updated policy.
Contact
For privacy questions, data requests, or to exercise your rights, contact us at:
- Email: support@piccard.app
We will respond to all legitimate requests in accordance with applicable law.