Cards.Fast Cards.Fast

Privacy Policy

Effective August 21, 2026. Last updated October 4, 2026.

Adapted from the General Legal U.S. Privacy Policy template (CC0). This is not legal advice.

Eric Kuhn, doing business as Cards.Fast ("Cards.Fast," "we," "us," or "our"), operates app.cards.fast and www.cards.fast (the "Service"). There is no separate company, no published street address, and no data-protection officer.

This Privacy Policy describes how we handle personal information we collect through the Service. The Terms of Use cover your contract with us.

If you have questions or want to exercise a privacy right, email support@cards.fast.

What we collect

You give us

  • Account data: email address and a password (stored as a hash).
  • Your Content: cards, decks, tags, sources, review ratings, Inbox decisions, and similar study data.
  • Agent data: cards and other writes an agent makes after you connect a personal token or sign in from ChatGPT, Claude, or Grok.
  • Family seats: the email addresses of the people you invite, if you pay for Family.
  • Support messages you send us.

Payments

Payment cards are collected by Stripe, not by us. We receive whether you are paid, which plan and interval you chose (Individual, $5 a month or $36 a year; Family, $10 a month or $60 a year), limited Stripe identifiers, and enough data to send a receipt. All mail, including receipts, comes from notifications@email.cards.fast. See Stripe's privacy policy.

We generate

  • A personal MCP token digest (the raw token is shown once; we store a digest).
  • OAuth client registrations and access-token digests when you sign in from ChatGPT, Claude, Grok, or another MCP client.
  • Session and security logs: sign-in time, IP address, user agent, and similar diagnostics.
  • Transactional email events (sent, bounced) for password reset, welcome, family invite, share, week check-in, and paid receipts.

Automatic

  • Device and usage data the browser or host sends: IP address, browser, pages viewed, and approximate location (city or region from IP).
  • Cookies or similar storage needed to keep you signed in and to run the Service. We do not run a separate cookie banner page. We do not use advertising pixels.
  • Signup source: on your first visit to www.cards.fast we set a 7-day cookie with the landing page, the referring site’s host name, and any UTM tags (source, medium, campaign). If you create an account in that time, we save those on your account so we know how people find us.
  • Page analytics on www.cards.fast only. We run our own copy of Umami at stats.cards.fast. For each visit it records the page and its title, the address of the page that linked you (the referrer), including its path and query string, the full query string of the link you arrived on (that is how campaign tags such as utm_source, utm_medium, and utm_campaign, and any ad click ID, are read), browser, operating system, device type, screen size, language, and country, region, and city (looked up from your IP address in a GeoIP database). It sets no cookies. Your IP address is not stored. Umami keeps only a salted hash of it with your browser details, and the salt changes each month. Umami is not on app.cards.fast and never sees your cards or study. We do not share this data with anyone.

We do not ask for government ID, precise GPS, income, photos of you, or contacts.

We do not knowingly collect information from children under 13.

How we use it

  • To run the Service: accounts, study, Inbox, export, and hosted MCP.
  • To take payment and send receipts through Stripe.
  • To email you about the account you asked for (password reset, first-registration welcome, family invite, share, week check-in, paid receipt). Those are service emails, not a newsletter.
  • To keep the Service secure and to debug failures.
  • To comply with law and to protect the Service and other people.

We do not sell your personal information for money.

  • We do not use Your Content to train a Cards.Fast model.
  • We do not run interest-based advertising.

How we share it

We share personal information only as follows.

Stripe, to charge $5 a month or $36 a year for Individual, or $10 a month or $60 a year for Family, and to run the customer portal (Settings → Manage billing).

Hosting and email providers, to run the app and deliver the emails above.

An agent you connect. If you sign in from ChatGPT, Claude, or Grok, or put your token into Grok Bot, Cursor, Claude Code, or another client, that client can read and write through https://app.cards.fast/mcp as you. We do not control those products. Their privacy policies apply to what they see.

Professional advisors, if we have them, when they need it to advise us.

Authorities, when we believe in good faith that the law requires it, or to protect people or the Service.

A buyer of the project, if Cards.Fast is sold or transferred, in which case this policy would apply to the successor unless they post a new one.

We have no corporate affiliates and no advertising partners.

Retention

We keep account and study data while your account exists, and for a reasonable time after if we need it for backups, billing disputes, or law.

You can delete cards in the Service. To ask us to delete an account, email support@cards.fast from the address on the account.

Token digests last until you regenerate or revoke, or the token expires (90 days).

Your choices

  • Update your email and password in the Service.
  • Regenerate or revoke your personal token in Settings. That stops cards login and any agent still holding the old token. Disconnect ChatGPT, Claude, or Grok under Connected agents in Settings.
  • Cancel paid access in Settings → Manage billing (Stripe).
  • Opt out of a future newsletter if we ever send one, using the unsubscribe link. Service emails (receipts, password reset) will still go out.
  • Email support@cards.fast to request access, correction, or deletion.

We do not respond to browser "Do Not Track" signals.

Security

We use ordinary technical safeguards (hashed passwords, token digests, HTTPS, access limits). No method is perfect. You are responsible for your password and token.

International users

The Service is operated from the United States. If you use it from another country, your information is processed in the United States, where privacy law may differ from yours.

Children

The Service is for people 13 and older. If you are 13 to 17, you need a parent’s or guardian’s permission to use it.

No one under 13 may create an account. In line with the Children’s Online Privacy Protection Act (COPPA), the U.S. children’s privacy law, we do not knowingly collect personal information from children under 13. If you believe a child under 13 has given us information, email support@cards.fast. We will delete the account and its information.

A parent or guardian may let a child under 13 study on the parent’s or guardian’s own account, under their supervision. The parent or guardian is the account holder. We do not create accounts or Family seats for children under 13, and we do not ask the child for personal information. Keep a child’s personal information, such as their name or school, out of cards.

U.S. state privacy rights

If you live in a U.S. state that gives residents privacy rights (including California, Colorado, Connecticut, Virginia, and others), you may have the right to know, access, correct, delete, or appeal, and to opt out of sale, sharing, or targeted advertising.

We do not sell personal information for money. We do not share personal information for targeted advertising. We do not use profiling that produces legal or similarly significant effects. We do not process sensitive personal information to infer characteristics about you.

To exercise a right, email support@cards.fast from the address on your account. We may need to verify it is you. You may use an authorized agent if the law allows; we may ask for proof.

California Shine the Light. We do not disclose personal information to third parties for their own direct marketing. To ask, email support@cards.fast with the subject "Shine the Light Request," your name, and mailing address, and confirm you are a California resident.

Nevada. We do not sell covered information for monetary consideration. To opt out of a future sale, email support@cards.fast.

We do not publish a toll-free number or a webform.

Changes

We may change this policy. If a change is material, we will update the date and post the new policy, and we may email you. Using the Service after the effective date means you acknowledge the new policy.

Contact

Eric Kuhn, Cards.Fast
Email: support@cards.fast
App: https://app.cards.fast

No street address is published. Contact is support@cards.fast.