Privacy
In effect since 24 August 2026
This page describes what Rayaad collects, why, where it is processed, and how long it is kept. It is written from the same inventory the app’s export, deletion, and logging are built from, so it describes what the software does rather than what a policy usually says.
What we collect and why
| What | Why | Where it is processed | How long |
|---|---|---|---|
| Your email address and sign-in credentials | So you can sign in, and so we can reply if you write to us | Supabase Auth (Frankfurt, Germany) | Until you delete your account |
| Your display name and app settings | To keep the app the way you left it on every device | Rayaad’s database (Supabase, Frankfurt) | Until you delete your account |
| Your language pairs, decks, cards, and notes | They are what the app is for | Rayaad’s database, and locally on each device you use | Until you delete them, or delete your account |
| Your review history — which card, which answer, when | Scheduling replays it; your statistics are computed from it | Rayaad’s database, and locally on each device | Until you delete your account |
| What you type into card generation and bulk import | To produce the cards or audio you asked for | Rayaad’s database; the text is sent to the AI provider below | Until you delete your account |
| Text sent for translation, card generation, or speech | The provider cannot answer without it | LatentKit (AI gateway), or a configured speech provider | Under that provider’s own retention policy |
| Synthesised audio clips | So a word is paid for and generated once, not once per person | Rayaad’s server (Hetzner, Germany) | Named by a hash of the text — never linked to an account |
| Operational logs and browser error reports | To diagnose failures without asking you to reproduce them | Rayaad’s database | 30 days; redacted, and never containing card text |
| Nine product events (listed below) | To see how far invited testers get before something stops them | Rayaad’s database, against a random identifier | 180 days |
| A summary of your progress, and a sample of the target-language side of your cards | To estimate the level you are studying at, so suggested words are pitched near it | Rayaad’s database; the summary is sent to the AI provider below | Until you delete your account. Only when you ask for suggestions or switch them on |
| Suggested cards, your edits to them, and whether you kept or skipped each one | So a set can be reviewed, and so we can tell whether the feature is any good | Rayaad’s database; the chosen words are sent to the AI provider below | Until you delete your account. No card is ever added without you accepting it |
| A record of what we were charged by AI providers | To check the bill against what the app actually asked for | Rayaad’s database | Kept after account deletion, with every link to you removed |
Suggested words
Rayaad can suggest words you do not have yet. It is off until you turn it on for a language, or ask for a set once — and this is what happens when you do.
To work out roughly what level you are studying at, the app sends the AI provider a summary of your progress in that language — how many cards, how many reviews, how well they have stuck — together with a sample of up to two hundred cards’ target-language side. The side in the language you already speak is never sent, and neither is your name, your email, your deck names, or any identifier for you. What comes back is one of six level bands and a confidence number.
The words themselves are then chosen by the app, not by the model: they come from a ranked word list, filtered to the ones you do not already have, have not been offered recently, and have not already turned down. Only those chosen words are sent to the provider, which writes a card for each. You see every card before anything happens to it.
Nothing is ever added to a deck unless you accept it. You can edit any card, keep the ones you want, and skip the rest; a set you ignore expires on its own and is not treated as a refusal. Turning the feature off stops new sets and leaves anything already waiting for you to decide about.
What we do not do
There are no advertisements in Rayaad. We do not sell or share your data, there is no cross-site tracking, and there is no third-party analytics, crash-reporting, or advertising SDK in the web app, the extension, or the mobile app.
We do not say “no tracking”, because that would not be true: we count nine things, listed next.
The nine product events
Each event records only its name, which surface it came from, the time our server received it, and a random identifier that belongs to your account. There is no place in that record for your email address, your account id, a card, a deck, a language, a page address, a device identifier, or an IP address — the storage has no column for any of them.
- onboarding finished
- a catalog deck installed
- a first review completed
- a review session finished
- a listen session finished
- the extension connected
- the extension’s first word swap
- a card generation finished
- an export downloaded
You can switch this off in Settings → General → Product analytics. Doing so also deletes the events already recorded for your account.
The browser extension
The extension reads the page you are on to find words you have already learned and swap them in. That reading happens entirely inside your browser.The address of the page, and the text on it, are never sent to Rayaad or to anyone else.What the extension downloads is your own word list; what it sends back is a review, exactly as if you had done it in the app.
It also asks for permission per site rather than for every site at install time, so the pages it can see are the ones you chose.
Data stored on your own devices
Each device keeps a local copy of your decks, cards, and review history so the app works without a connection, and the mobile app may cache audio clips for offline listening. That copy is scoped to the account that is signed in, and is erased when you sign out, when you switch accounts, and when an account is deleted.
Who processes data on our behalf
- Supabase — accounts, sign-in, and the database. Hosted in Frankfurt, Germany.
- Hetzner — the servers running the API, the background worker, and the audio store. Germany.
- Cloudflare — serving the web app, this site, and their domains.
- LatentKit — the gateway that routes AI requests, and the model provider behind it, for card generation and speech.
- Our logging and alerting providers — an off-site log store and the address operational alerts are sent to, so a failure is diagnosable when the server itself is not reachable.
Getting your data, and getting rid of it
Export. Settings → Sync → Export account data downloads a single file containing your profile and settings, your language pairs, decks, and cards, your card scheduling state, your complete review history, your generation history, your product events, every level estimate made for you with the summary it was made from, and every set of suggested words — what the model proposed, what you changed, and what you kept. It is not filtered.
Deletion. You can delete your account yourself fromthis page or from Settings. Your access ends immediately, and your sign-in, your content, your review history, your generation history, your level estimates, your suggested-word sets, and your product events are removed. Two things are deliberately kept: a record of what AI providers charged us — with your account id, your job references, and all content removed, so it can no longer be connected to you — and a one-way, unreadable note that a deletion happened, which exists so that restoring an old backup cannot bring your account back.
Security
Traffic is encrypted in transit. Sign-in tokens are checked on every request, and the server refuses a request from an account that has been deleted even if the token itself has not yet expired. Logs are redacted before they are stored and again before they leave the server. We never ask for your password by email.
Children
Rayaad is not directed at children, and during the invited beta accounts are created only for people who were invited directly.
Changes, and how to reach us
If this page changes in a way that affects what is collected or how long it is kept, the date at the top changes with it. Questions, corrections, and requests about your data go tosupport@rayaad.com.

