Privacy Policy
Last updated 16 September 2026.
The short version
QuickMem stores your account, your flashcards, and your study progress so they sync across your devices. There is no advertising, no analytics SDK, and no third-party tracking in the app, and we do not sell or rent your data to anyone. The only time your content leaves our systems is when you ask for something that needs an outside service — an AI suggestion, an image search, or cloud read-aloud — and each of those is described below.
Who we are
QuickMem is the operator of the QuickMem mobile app and this website, and is the data controller for the personal data described here. We are based in Washington State, United States. You can reach us at support@quickmem.com about anything in this policy, including a request to see or delete your data — that address is the one to use for every request in this policy, and it is read by a person.
What we collect
Your account
If you create an account, we store your email address and an authentication record. We never see or store your password — sign-in is handled by Google Firebase Authentication, which stores a hashed credential we cannot read. You may also use the app without an account, in which case the app creates an anonymous identifier so your work has somewhere to live on your device.
Your content
Decks, flashcards, hints, tags, any images you attach, and your study progress and review schedule. This is the substance of the app and it is stored so that it syncs between your devices and survives reinstalling. Images you add from your camera or gallery are uploaded to Firebase Storage under your own account's folder.
Friends
If you send a friend request, we store the email address you sent it to so the recipient can find it, and we store a record linking the two accounts once it is accepted. The person you invite will see the email address associated with your account. Nicknames you give a friend are private to you.
Diagnostics
We use Firebase Crashlytics to record crashes and errors. A crash report contains device model, operating system version, app version, and a stack trace — the technical state of the app at the moment it failed. It is not linked to your flashcard content. We also use Firebase App Check with Play Integrity, and Firebase Installations, which produce device signals used to confirm that requests come from a genuine copy of the app rather than a script. We do not use Google Analytics, Firebase Analytics, or any advertising or attribution SDK.
How the app is used
We record how the service is used so we can tell whether it is growing and working: when an account was created, the days it signed in or opened the app, how many cards it reviewed that day, and which app version it is running. This is gathered on our own server from Firebase's own sign-in records and from the counters the app already keeps for your study streak. It is held against your account's internal identifier, it contains no email address, and it goes to nobody else — there is still no analytics SDK in the app and nothing is sent to a third party for this.
This website, separately from the app, uses Cloudflare Web Analytics to count page visits: it is cookieless, it collects no personal data, and it is not connected to your account — the app itself still has no analytics SDK in it.
When you write to support
If you email support@quickmem.com, we keep your message, your address and our replies, so we can answer you and see the history the next time you write. Where that address matches an account, we link the two — that is how we can see how many decks or which app version you have while helping you. This mail is held on a machine we control and is not shared.
Server logs
Reaching us at all means your device's IP address arrives with the request, and the services we run on — Google Firebase and Cloudflare — record it in their own logs along with the time and the kind of device. We do not build anything on top of those logs, we do not use them to profile you, and nothing in this app links them to your flashcards. They exist because a server cannot answer a request without knowing where to answer it, and they age out on those providers' own schedules.
Email we send you
We send you email about your own account: confirming your address when you sign up, resetting a password, telling you an address has changed, replying when you write to support, and — if you stop opening the app — warning you before an unused account is deleted. These go to the address on the account and there is no way to turn them off while keeping the account, because each one exists to protect it.
We do not send marketing email, we do not send you offers, and we do not give your address to anyone who does.
Subscriptions
If you subscribe, the purchase is processed entirely by Google Play or the Apple App Store. We never receive your card number, billing address, or any payment details. We receive an opaque purchase identifier and the subscription's status — active, cancelled, expired, refunded — which is what tells the app whether to unlock the paid features. We also keep a count of how much AI usage your account has consumed in the current period, so we can show you your remaining allowance and stop runaway costs.
When your content leaves our systems
Three features send data to an outside company. All three are things you trigger deliberately.
The AI Helper
When you ask the Helper to generate, explain, simplify, or split cards, the text involved — the topic or source text you supply, and the content of the cards in question — is sent to our server and from there to a third-party AI provider, currently Google (Gemini), which generates the response. We send only the text needed for that request. We do not send your email address, your account identifier, or your other decks. We do not use your content to train any model, and our agreement with the provider does not permit them to either. We may change AI provider; if we do, we will update this page.
We also keep a record of each request on our own server: when it was made, which Helper feature it used, whether it succeeded, what it cost, and the text you typed into it — the topic, the pasted text, the change you asked for, or the question. We do not keep the AI's answer. The record is held against your account's internal identifier, on a machine we control, and goes to nobody else. We keep it so we can help you when you write to support and see how the Helper is actually used, so we can improve it. The text is deleted 90 days after the request, or when your account is deleted, whichever comes first.
Image search
If you search for a picture to put on a card, your search term — and nothing else — is sent through our server to an image provider (Imgur or Pixabay) to fetch results. Your identity is not sent with it.
Cloud read-aloud
QuickMem reads cards aloud using your device's built-in voice engine by default, which sends nothing anywhere. If you choose to configure a cloud voice instead, you supply your own API key for that provider — Google Cloud Text-to-Speech, OpenAI, or ElevenLabs — and the text of the card being read is sent to that provider under your account with them, governed by their terms and billed to you. Your key is stored encrypted on your device and is never sent to us.
Why we are allowed to use it
If you are in the UK or the European Economic Area, the law requires us to name a lawful basis for each thing we do with your data. Ours are:
- To provide the app — your account, your decks and cards, their sync between your devices, and any subscription you buy: performance of a contract with you.
- The AI Helper, image search and cloud read-aloud — each sends data outside only when you ask it to, so this is also performance of a contract, at your request.
- Crash reports, App Check and Firebase Installations — keeping the app working and confirming requests come from a real copy of it rather than a script: our legitimate interests in a service that functions and is not abused.
- Sign-in days, launches and review counts — knowing whether the app is growing and working: our legitimate interests. This is held against an internal identifier, never an email address, and goes to nobody else.
- The record of your AI requests, including what you typed — supporting you and improving the Helper: our legitimate interests. It is held against an internal identifier and goes to nobody else.
- Support correspondence — answering you and keeping the history: our legitimate interests in supporting the people who use the app.
- Keeping records we are required to keep, and responding to lawful requests — legal obligation.
Where we rely on legitimate interests you have the right to object; email us and we will consider it. We do not rely on consent for anything described here, because nothing here is advertising or tracking.
Who else processes your data
We use Google Firebase (Authentication, Cloud Firestore, Cloud Storage, Crashlytics, App Check) to run the service, and Cloudflare to serve this website. Google Play and Apple process subscription payments. These companies act as our service providers and process data on our behalf under their own agreements. Our servers and Firebase data are located in the United States, so if you use QuickMem from elsewhere your data is transferred there.
Where that transfer is out of the UK or the European Economic Area, it is covered by the European Commission's Standard Contractual Clauses (and the UK Addendum) in our providers' data processing terms, and, where the provider is certified under it, the EU–US Data Privacy Framework. You can ask us for details of the safeguard that applies to a particular provider.
When the law requires us to hand it over
We may disclose your information where the law compels us to — a court order, a warrant, or a valid demand from a public authority — and where we genuinely believe it is necessary to investigate a violation of our terms, to protect someone's safety, or to defend a legal claim. We are a small operation and this has never happened; it is written here because it could, and because a policy that implies your data can never leave for any other reason would be untrue.
Where we are allowed to tell you about such a demand, we will.
If QuickMem changes hands
If QuickMem is sold, merged into another company, or wound up, the accounts and their content would transfer with it, because the service cannot keep running without them. If that happens we will say so on this page and in the app before it takes effect, and the new owner is bound by this policy until they give you notice of their own and a chance to delete your account first.
How we protect it
Everything travels over an encrypted connection, and Firebase encrypts what it stores at rest. Access to your decks and cards is enforced per account by Firestore security rules on Google's side, not merely by the app asking politely — a request for somebody else's data is refused by the database. Firebase App Check with Play Integrity is used to confirm requests come from a genuine copy of the app. If you configure a cloud voice, that provider's API key is stored encrypted on your device and never reaches us. Administrative access to the systems behind QuickMem is limited to the operator.
No service can promise perfect security, and we would rather say so than imply otherwise. If we ever discover a breach affecting your personal data, we will notify you and the relevant authority where the law requires it.
How long we keep it
Your account and content are kept for as long as your account exists, with one exception: an account nobody uses is eventually deleted. A registered account that has not been opened or signed into for 120 days is deleted, after we have emailed the address on it at least 30 days beforehand and again about a week before. Opening the app and signing in at any point before then keeps it. An anonymous account — one used without signing up — has no address for us to write to, so it is deleted after 120 days without use and without notice. An account with an active subscription is never deleted for inactivity.
The copy of an AI request the app uses to deliver its answer is deleted a day after it finishes, the next time you open the app; if you never open it again, that copy goes when the account does. Our record of the request keeps what you typed for 90 days, after which the text is deleted and only when it was made, the feature and what it cost remain. The text also goes when the account does. Crash reports follow Firebase's own retention. When you delete your account, or we delete one nobody has used, the content is removed from our live systems within 30 days: we hold a copy for that window so a deletion can be undone if it was a mistake, and after it the copy is destroyed. Content may persist in routine backups for a short period afterwards.
Deleting your data
You can delete your account from inside the app, under Settings. Your account is closed straight away — you are signed out and cannot sign back in — and your flashcards, decks and images are deleted 30 days later. During those 30 days you can email support@quickmem.com from the address on the account to have it restored, or to ask for a copy of your content; after that it is gone for good. If you would rather we did the deleting for you, email that address and we will handle it.
Deleting the app alone does not delete your account, because your content is stored so it survives a reinstall. Deleting your account does not cancel a subscription, and cancelling a subscription does not delete your account: subscriptions are cancelled in Google Play or the App Store, not through us — see the Terms of Service. If you want both, do both.
You can also ask us to delete your account from the web, without opening the app: see Delete your account.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold about you, to object to or restrict how we use it, and to complain to a data protection authority. Email support@quickmem.com to exercise any of these. We do not sell personal information and we do not share it for cross-context behavioural advertising — there is no "do not sell" switch to find because there is nothing to switch off. We will not give you a worse service, or a different price, for exercising any right in this policy. We answer within 30 days; if we refuse, we will say why, and you can complain to your data protection authority.
Children
QuickMem is not directed at children under 13, and we do not knowingly collect personal information from them. Some countries set a higher age for using a service like this without a parent's permission — up to 16 in parts of the European Economic Area — and where you live sets such an age, that age applies instead of 13. If you believe a child below the age that applies to them has created an account, email us and we will remove it.
Links out of the app
A few things open outside QuickMem — this policy and our terms, managing a subscription in Google Play or the App Store, and images returned by a picture search. Once you are there you are on someone else's site, under their privacy policy and not this one. We do not control what they collect.
Changes to this policy
If we change how we handle your data, we will update this page and change the date at the top. If a change is significant, we will tell you in the app before it takes effect.