Privacy policy
Last updated 26 September 2026
Mimicard is a vocabulary app for learning Japanese. This page explains what we store about you, why, who else handles it, and how to get it changed or deleted. The short version: we keep what you need for your account and your deck, nothing for advertising, and you can delete it yourself at any time.
Who is responsible
Mimicard is run by Samuel Andersen, Birkekrogen 6, 9574 Bælum, Denmark (CVR-nr. 46777212), who is the data controller for the information described here. For anything about your data, write to privacy@mimicard.com.
What we store
- Your account: your email address, your password as a one-way scrypt hash (we cannot see the password itself), and when the account was created and confirmed.
- Your deck: the words, readings, meanings, example sentences, breakdowns and notes you add, your review progress (levels, due dates, counts of reviews and misses), and your settings, such as daily goal, streak and theme.
- Sign-ins and devices: a record of each signed-in session and each device token you create (its name, when it was created and last used). The session and token values themselves are stored only as hashes. Words a device sends wait in your inbox until you add or discard them.
- Security records: when we send you an email, the address and your IP address, so the forms can't be used to flood someone's inbox. Failed sign-in attempts are counted per IP address in memory. Our web server logs each request with the IP address, time, requested address and browser type.
- How the app is used: counts of what happens in the app, each with a time and the internal id of the account it happened on: a deck being started, cards answered, words added, a starter pack taken, lines sent to Make cards, an account made, confirmed or paid for. If the link you arrived on carried a campaign tag, or you came from another site, that tag or that site's name is stored once, with the deck you started. No IP address, no email address and none of your words are in this record. It tells us whether the app is being used, not who is using it.
- Emails you send us.
We don't ask for your name, and we don't collect payment details, location, contacts or anything from other apps. There are no advertising trackers and no third-party analytics. The usage counts above are made and kept on our own server, and go to nobody else.
Why, and on what legal basis
- To provide the app: keeping your account and deck, syncing them between your devices, and sending the emails the account needs (confirming your address, resetting your password, telling you when your email address changes). This is necessary to provide the service you signed up for (GDPR Article 6(1)(b)).
- To keep the service and your account safe: the security records above, used to stop abuse, block password guessing and fix problems. This is our legitimate interest (Article 6(1)(f)).
- To know whether the app is used at all: the usage counts above, so we can see whether anyone is here and whether a change helped. This is our legitimate interest (Article 6(1)(f)).
- To answer you when you write to us (Article 6(1)(f)).
We don't sell your data, use it for advertising or profiling, or send you newsletters.
Who else handles your data
- AlexHost SRL hosts our server in Chișinău, Moldova. Moldova is outside the EU and has no EU adequacy decision, so this transfer is covered by the European Commission's Standard Contractual Clauses in AlexHost's data processing agreement.
- Resend sends our account emails. It handles your email address and the message, and stores its data in the United States, covered by the EU–US Data Privacy Framework and Standard Contractual Clauses.
- ImprovMX forwards email sent to our mimicard.com addresses to our inbox.
- Google (the Gemini API) works out which words you meant when you use Make cards. It receives the lines you typed, not who you are, and may keep them and use them to improve its services. Google processes them in the United States, covered by the EU–US Data Privacy Framework. We keep each line and the card made from it for 90 days, so the same line typed again doesn't have to be sent twice.
- Backups of the database are kept on the server for 14 days, and a copy is kept on the operator's own computer in Denmark.
When you look up a word or fetch example sentences, our server asks Jisho.org, Tatoeba and kanjiapi.dev about that word. They receive the word, not who asked.
Pronunciation uses your browser's built-in speech. Some browsers send the text to their maker's online voice service (for example Google or Microsoft), which is covered by that browser's own privacy terms.
How long we keep it
- Account and deck: until you delete your account. Deleting it removes everything from the live database straight away; copies in backups are gone within 30 days.
- Decks made without an account: deleted after 7 days. Making an account keeps the deck and everything you have done with it.
- Accounts that are never confirmed: deleted after 14 days. The app shows the date while the address is unconfirmed.
- Email links: expire after 1 hour (password reset) to 3 days (confirming an address), and are deleted once used or expired.
- Security records: the email-and-IP record for 1 day, failed sign-in counts for 15 minutes, web server logs for 14 days.
- Usage counts: 30 days.
- Emails you send us: as long as needed to deal with them.
Cookies and storage in your browser
We set one cookie to keep you signed in, for up to a year or until you sign out. Looking around without making an account sets the same cookie, for the deck we make for you. The app also keeps a copy of your deck in your browser's local storage, so it opens quickly and works for a while without a connection. If you arrive on a link that carries a campaign tag, the tag is kept in local storage for six hours, so that a deck you start can record where the visit came from. All of this is needed for the app to work, which is why there is no cookie banner. There are no tracking cookies.
If you pay for a plan
Payments are handled by Stripe Payments Europe, Ltd., who act as their own controller for the card details you give them. We never see or store your card number. What we keep is the identifier Stripe gives your customer record, which plan you are on, and when it runs to. That is enough to know whether your account is paid, and says nothing about the card itself.
Stripe emails your receipts and keeps the payment records it is required to keep by law; their handling of your data is covered by Stripe's privacy policy. If you delete your account, the plan record goes with it, but Stripe keeps its own accounting record of a payment already made, as Danish bookkeeping law requires of any seller.
Your rights
You can see and change everything in your deck in the app, download all of it with Export data on the Account page, change your email address and password on the Account page, and delete your account there too. You also have the right to access, correct, delete, restrict or object to our use of your data, and to receive it in a portable format. For any of these, write to privacy@mimicard.com and we'll answer within a month.
If you think we handle your data wrongly, you can complain to the Danish Data Protection Agency, Datatilsynet, or the data protection authority where you live.
Security
The site is served only over HTTPS. Passwords, sessions and tokens are stored as hashes, the database can be read only by the app itself, and sign-in attempts are limited. If a breach puts your data at risk, we'll tell you and Datatilsynet as the law requires.
Children
Mimicard is not meant for children under 13, who should not create an account.
Changes
If this policy changes, the date at the top changes with it. If a change affects how your data is used, we'll email you before it takes effect.