Privacy Policy
Last updated July 9, 2026
1. Overview
This policy describes how Openlet handles information when you use the product. We aim to collect only what is needed to run accounts and study features.
2. Information we collect
Account data: name and email. Study data: sets, cards, study sessions, and spaced-repetition metadata tied to your account. Technical data: basic logs needed for security and reliability (for example IP-related request logs on the server).
3. How we use information
We use your data to authenticate you, store and show your study content, improve reliability, and prevent abuse. We do not sell your personal information.
4. Cookies and sessions
We use an HTTP-only session cookie to keep you signed in. You can end sessions by signing out.
5. Sharing
We do not sell personal data. Content may be processed by infrastructure providers that host the app and database (for example a cloud Postgres host). If you use optional AI features with your own API key, content you submit goes to that provider under their policy.
6. Public sharing
If you share a set link, people with the link may view that set’s content. Only share sets you are comfortable making accessible.
7. Retention
We keep account and study data while your account is active. You may request deletion of your account and associated data through project contact channels.
8. Security
We hash passwords and use industry-common practices for sessions and transport. No method of transmission or storage is perfectly secure.
9. Children
Openlet is not directed at children under 13 (or the equivalent age in your region). If you believe a child has created an account, contact us so we can remove it.
10. Changes
We may update this policy. The “last updated” date will change when we do. Continued use after updates means you acknowledge the revised policy.
11. Contact
Privacy questions can be raised via the project repository or contact channels listed on the Openlet site.