Privacy Policy - CardCroc

1. Data Controller

Florian Drechsler
Panitzstr. 14
04129 Leipzig, Germany
Email: contact@fdrechsler.de

2. Data Collection and Processing

CardCroc collects and processes the following data:

  • Learning progress and statistics (stored locally)
  • App settings and preferences (stored locally)

If you sign in, the following data is processed by Firebase Authentication:

  • Email address
  • Display name
  • Authentication provider ID (e.g. Google, Apple)
  • Unique user ID (UID)

No additional personal data is collected beyond what is required for authentication.

3. Data Storage

Your learning data is stored locally on your device in an SQLite database and is not transmitted to external servers.

If you use the sign-in feature, your authentication data (email, display name, UID) is processed and stored by Google Firebase, with servers located in the United States.

You can export your local data at any time using the export function in Settings.

4. Third-Party Services

CardCroc uses Firebase Authentication (provided by Google LLC) to enable optional account sign-in. When you sign in, your email address, display name, and authentication provider information are processed by Firebase.

Firebase Authentication servers are located in the United States. Data processing is governed by Google's Data Processing Agreement (DPA) in compliance with GDPR.

No analytics, tracking, or advertising services are used. The app does not use Firebase Analytics.

5. International Data Transfers

When you use the sign-in feature, your authentication data is transferred to and processed in the United States by Google Firebase.

These transfers are protected by:

  • The EU-US Data Privacy Framework (DPF), under which Google LLC is certified
  • Standard Contractual Clauses (SCCs) as approved by the European Commission

Google's DPF certification can be verified at https://www.dataprivacyframework.gov.

6. Legal Basis for Processing

The legal basis for processing your data is:

  • Consent (Art. 6(1)(a) GDPR): You provide explicit consent before creating an account. You may withdraw consent at any time by deleting your account.
  • Contract performance (Art. 6(1)(b) GDPR): Processing is necessary to provide the authentication service you requested.

7. Your Rights (GDPR)

Under the General Data Protection Regulation (GDPR), you have the following rights:

  • Right to access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to withdraw consent (Art. 7(3) GDPR)

For local data, you can exercise these rights directly by deleting or exporting your app data.

For authentication data, you can delete your account in the app settings, which will erase all data stored in Firebase.

8. Account Deletion and Data Erasure

You can delete your account at any time from the Account section in Settings. Account deletion will:

  • Permanently remove your Firebase Authentication account and all associated data (email, display name, UID)
  • Revoke Apple Sign-In tokens (if you signed in with Apple)

Your local learning data is not affected by account deletion and remains on your device. To remove local data, uninstall the app or use the reset function in Settings.

9. Contact

For questions regarding data protection, please contact:
Florian Drechsler
Email: contact@fdrechsler.de

Further legal information can be found in our Legal Notice.

Last updated: February 2026