Privacy Policy
Last updated: June 2026
Asilak is built privacy-first. Almost nothing about your learning ever reaches us: there is no account, and your decks, cards and study history stay on your device. This policy explains, in plain terms, the little that we do handle, the choices you have, and your rights under the EU General Data Protection Regulation (GDPR) and the UK GDPR.
Who we are (the data controller)
Asilak is provided by the Asilak team ("Asilak", "we", "us"). For any data-protection question, or to exercise the rights described below, please use the contact form on our website.
No accounts, no profiles
Asilak has no sign-up, no login and no user profiles. We do not ask for your name, email address or any identifying information to use the app. Because there is no account, there is no account to delete — the platform account-deletion requirements simply do not apply. Uninstalling the app removes the learning data stored on that device.
Your learning data stays on your device
Your decks, cards and study history are stored locally on your device in an on-device database. They are not transmitted to us, and we operate no server that holds them. We cannot see, access or recover this data. Keeping your own backups (see below) is therefore worthwhile.
Optional device backup uses your own cloud
Backing up your local data is optional and off until you turn it on. When enabled on a phone, a copy can be saved to your own iCloud (on Apple devices) or through Android's Auto Backup — your private cloud storage, governed by Apple's or Google's terms, not by any server we run. We do not receive a copy of your decks this way.
Cross-device sync is end-to-end encrypted
Cross-device sync is optional and off until you turn it on. When enabled, your decks and study history are end-to-end encrypted on your device before they leave it, and synced through our encrypted backbone (operated for us by Cloudflare). We store only ciphertext and never hold your encryption key, so we cannot read your synced data.
On iPhone and Android, that key never leaves your device's secure storage (the system Keychain or Block Store), so your synced data stays fully end-to-end encrypted — even we can never read or recover it.
On the web and on desktop computers, you can optionally turn on recovery by email, so you can restore your data after clearing your browser or on a new computer. To make that possible we keep an encrypted copy of your key and email a one-time recovery key to your purchase address (through our email provider, Resend). This makes your synced data only as private as your email account: someone who obtained both that email and a copy of our encrypted store could decrypt it. We still store only ciphertext and never see your key or recovery key in the clear. If you want strict end-to-end protection on these platforms, leave email recovery off — but then a lost device or cleared browser cannot be recovered.
Anonymous diagnostics
Asilak collects anonymous diagnostics that help us find and fix problems, processed by Sentry (Functional Software, Inc.) acting as our processor. These reports contain technical information only — non-identifying stage names plus context such as the app version, operating-system version and device model. They never include the content of your cards or decks, and never your name, email or other personal information. Anonymous crash reports are always sent, so that a bug which stops the app working never goes unseen; our lawful basis for these is our legitimate interest (Article 6(1)(f) GDPR) in keeping the app stable and secure. All other, non-crash diagnostics are optional — governed by a "Diagnostics" toggle in Settings, off by default where required by law, and switchable off at any time; our lawful basis for them is your consent (Article 6(1)(a) GDPR), which you can withdraw at any time by switching the toggle off.
Purchases and payment
Asilak is a one-time purchase. Payment is handled entirely by the store you buy from — the Apple App Store or Google Play in-app purchase, or, on Windows, Linux and the web, by Stripe (Stripe, Inc. / Stripe Payments Europe, Ltd.). We never see or store your full card number. The payment processor handles your payment details under its own privacy terms and as our processor where applicable. We may receive a confirmation that a purchase occurred and a non-identifying transaction reference to validate your entitlement and provide support. The lawful basis for processing purchase data is performance of a contract with you (Article 6(1)(b) GDPR); where we retain records to meet tax or accounting duties, the basis is our legal obligation (Article 6(1)(c) GDPR).
No ads, no trackers, no cookies, no data selling
Asilak contains no advertising, no third-party advertising or tracking SDKs, and no analytics that profile you. We do not sell, rent or share your personal data with anyone. This marketing website sets no tracking cookies and uses no cross-site tracking.
Lawful bases for processing
Under the GDPR and UK GDPR we rely on: consent (Article 6(1)(a)) for optional, non-crash diagnostics; performance of a contract (Article 6(1)(b)) to process your one-time purchase and provide the app; legal obligation (Article 6(1)(c)) where we must keep purchase or tax records; and our legitimate interests (Article 6(1)(f)) in keeping the app secure and working correctly — including the anonymous crash reports we always collect — balanced against your rights. Because the app collects no personal learning data, most of what you do in Asilak does not involve processing personal data by us at all.
Your rights
If you are in the EU or the UK, you have the rights to access, rectify, erase, restrict and port your personal data, to object to processing, and to withdraw consent at any time (without affecting processing already carried out). To exercise any of these, use the contact form on our website. Please note that we hold very little: your learning data lives only on your device (and your own cloud if you enabled backup), so for most data the practical way to access, correct, export or erase it is within the app itself or by uninstalling. We will respond to verified requests within the time limits the law requires.
Deleting your data
Asilak has no accounts, and your learning content (decks, cards and study history) is stored on your device. You can delete it at any time, and request deletion of any optional synced copies, as follows:
- In the app, delete individual decks or cards. If cross-device sync (Link) is enabled, these deletions also remove the items from Asilak's encrypted sync storage.
- To remove all data from a device, uninstall Asilak. This permanently deletes the on-device decks, cards, study history and settings.
- To request deletion of any remaining synced data, submit a request through the contact form on our website; we delete the associated end-to-end-encrypted sync data within 30 days.
What is deleted: all learning content (decks, cards, study history) and app settings, including any synced copies, which are end-to-end encrypted, so once your device key is removed they can no longer be decrypted by anyone. What is kept: nothing tied to your identity, because Asilak has no accounts; anonymous crash and diagnostic reports contain no personal data or card content, and are deleted automatically after 90 days. Purchase records are held by Google Play under Google's policies, not by Asilak.
Data retention
Learning data is retained on your device for as long as you keep the app installed and is removed when you delete it; backup copies persist in your own cloud until you delete them there. Diagnostics are retained by our processor only as long as needed to diagnose issues and are then deleted after 90 days. Purchase and tax records are kept only as long as required by applicable law.
International data transfers
Our diagnostics and payment processors may process limited data outside your country, including in the United States. Where personal data is transferred outside the EU or UK, it is protected by an appropriate safeguard such as the European Commission's Standard Contractual Clauses (and the UK Addendum) or an adequacy decision. The specific transfer mechanism for each processor will be confirmed with counsel before launch.
Children
Asilak is a general-purpose, subject-neutral learning tool. It is not directed primarily at children, though it can be used by them and by parents or teachers building decks for a child. Because the app requires no account and keeps learning data on the device, we knowingly collect no personal information from anyone, including children. Under Article 8 GDPR the age at which a child can consent to online services ranges from 13 to 16 depending on the member state (16 by default); in the UK it is 13. Where consent is needed for a child below the applicable age, it must be given or authorised by a holder of parental responsibility. If you believe a child has provided us personal data, use the contact form on our website and we will delete it.
Changes to this policy
We may update this policy as the app evolves or the law changes. We will revise the "last updated" date above and, for material changes, give notice in the app or on this site.
Complaints and supervisory authorities
You have the right to lodge a complaint with a data-protection supervisory authority. In the EU, you may contact the authority in your country of residence, work or where the issue arose. In the UK, the supervisory authority is the Information Commissioner's Office (ICO), ico.org.uk. We would appreciate the chance to address your concern first — please reach us through the contact form on our website.
Contact
Questions about privacy, or to exercise your rights? Use the contact form on our website.