Privacy policy
Last updated 19 September 2026
Mimicard is a vocabulary app for learning Japanese. This page explains what we store about you, why, who else handles it, and how to get it changed or deleted. The short version: we keep what you need for your account and your deck, nothing for advertising, and you can delete it yourself at any time.
Who is responsible
Mimicard is run by Samuel Andersen, Birkekrogen 6, 9574 Bælum, Denmark (CVR-nr. 46777212), who is the data controller for the information described here. For anything about your data, write to privacy@mimicard.com.
What we store
- Your account: your email address, your password as a one-way scrypt hash (we cannot see the password itself), and when the account was created and confirmed.
- Your deck: the words, readings, meanings, example sentences, breakdowns and notes you add, your review progress (levels, due dates, counts of reviews and misses), and your settings, such as daily goal, streak and theme.
- Sign-ins and devices: a record of each signed-in session and each device token you create (its name, when it was created and last used). The session and token values themselves are stored only as hashes. Words a device sends wait in your inbox until you add or discard them.
- Security records: when we send you an email, the address and your IP address, so the forms can't be used to flood someone's inbox. Failed sign-in attempts are counted per IP address in memory. Our web server logs each request with the IP address, time, requested address and browser type.
- Emails you send us.
We don't ask for your name, and we don't collect payment details, location, contacts or anything from other apps. There are no analytics or advertising trackers.
Why, and on what legal basis
- To provide the app: keeping your account and deck, syncing them between your devices, and sending the emails the account needs (confirming your address, resetting your password, telling you when your email address changes). This is necessary to provide the service you signed up for (GDPR Article 6(1)(b)).
- To keep the service and your account safe: the security records above, used to stop abuse, block password guessing and fix problems. This is our legitimate interest (Article 6(1)(f)).
- To answer you when you write to us (Article 6(1)(f)).
We don't sell your data, use it for advertising or profiling, or send you newsletters.
Who else handles your data
- AlexHost SRL hosts our server in Chișinău, Moldova. Moldova is outside the EU and has no EU adequacy decision, so this transfer is covered by the European Commission's Standard Contractual Clauses in AlexHost's data processing agreement.
- Resend sends our account emails. It handles your email address and the message, and stores its data in the United States, covered by the EU–US Data Privacy Framework and Standard Contractual Clauses.
- ImprovMX forwards email sent to our mimicard.com addresses to our inbox.
- Google (the Gemini API) works out which words you meant when you use Make cards. It receives the lines you typed, not who you are, and may keep them and use them to improve its services. Google processes them in the United States, covered by the EU–US Data Privacy Framework. We keep each line and the card made from it for 90 days, so the same line typed again doesn't have to be sent twice.
- Backups of the database are kept on the server for 14 days, and a copy is kept on the operator's own computer in Denmark.
When you look up a word or fetch example sentences, our server asks Jisho.org, Tatoeba and kanjiapi.dev about that word. They receive the word, not who asked.
Pronunciation uses your browser's built-in speech. Some browsers send the text to their maker's online voice service (for example Google or Microsoft), which is covered by that browser's own privacy terms.
How long we keep it
- Account and deck: until you delete your account. Deleting it removes everything from the live database straight away; copies in backups are gone within 30 days.
- Decks made without an account: deleted after 7 days. Making an account keeps the deck and everything you have done with it.
- Accounts that are never confirmed: deleted after 14 days. The app shows the date while the address is unconfirmed.
- Email links: expire after 1 hour (password reset) to 3 days (confirming an address), and are deleted once used or expired.
- Security records: the email-and-IP record for 1 day, failed sign-in counts for 15 minutes, web server logs for 14 days.
- Emails you send us: as long as needed to deal with them.
Cookies and storage in your browser
We set one cookie to keep you signed in, for up to a year or until you sign out. Looking around without making an account sets the same cookie, for the deck we make for you. The app also keeps a copy of your deck in your browser's local storage, so it opens quickly and works for a while without a connection. All of this is needed for the app to work, which is why there is no cookie banner. There are no tracking cookies.
If you pay for a plan
Payments are handled by Stripe Payments Europe, Ltd., who act as their own controller for the card details you give them. We never see or store your card number. What we keep is the identifier Stripe gives your customer record, which plan you are on, and when it runs to. That is enough to know whether your account is paid, and says nothing about the card itself.
Stripe emails your receipts and keeps the payment records it is required to keep by law; their handling of your data is covered by Stripe's privacy policy. If you delete your account, the plan record goes with it, but Stripe keeps its own accounting record of a payment already made, as Danish bookkeeping law requires of any seller.
Your rights
You can see and change everything in your deck in the app, download all of it with Export data on the Account page, change your email address and password on the Account page, and delete your account there too. You also have the right to access, correct, delete, restrict or object to our use of your data, and to receive it in a portable format. For any of these, write to privacy@mimicard.com and we'll answer within a month.
If you think we handle your data wrongly, you can complain to the Danish Data Protection Agency, Datatilsynet, or the data protection authority where you live.
Security
The site is served only over HTTPS. Passwords, sessions and tokens are stored as hashes, the database can be read only by the app itself, and sign-in attempts are limited. If a breach puts your data at risk, we'll tell you and Datatilsynet as the law requires.
Children
Mimicard is not meant for children under 13, who should not create an account.
Changes
If this policy changes, the date at the top changes with it. If a change affects how your data is used, we'll email you before it takes effect.