Last updated 8 October 2026
Privacy Policy
This policy explains what cardosec collects, why, who it is shared with, and the choices you have. cardosec is a speaking-practice tool for cybersecurity, available at cardosec.com. Questions: hello@cardosec.com.
The short version
- We never record or store your audio.
- We store your Google email and name, your settings, and your practice history, so your progress follows you across devices.
- If you add an AI provider key, it is encrypted and never shown again. Your answers go to that provider only when you ask for AI feedback.
- No advertising, no tracking cookies, and we don't sell your data.
- You can delete your account and everything in it from Account → Delete account.
What we collect
| Data | When | Why |
|---|---|---|
| Google account email, name and account ID | When you sign in with Google | To create your account and sign you in. We only receive verified emails, and never your Google password. |
| Settings and welcome answers (name, goal, experience, focus domains, timers, theme) | When you set them | To set up practice the way you chose, on any device. |
| Practice history: which card, mode, time spoken, key points you ticked, AI score, and your retention-quiz answers (which card, and how much you recalled) | When you finish a drill or a quiz | Your field log, streak, readiness map, strength report, quizzes and weak-spot targeting. |
| AI provider keys (Anthropic, OpenAI) and chosen model | If you add one | To grade your answers on your own provider account. Encrypted with AES-256-GCM, tied to your account; only the last four characters are ever shown. |
| Usage data: when your account last used cardosec, how often features are used (for example AI grading or Surprise Me) | While you use cardosec | To understand what's working and improve the product. |
| Anonymous counts: guest sessions, drills and quizzes, card page views | When cardosec is used without an account | Aggregate daily totals only, with no identifiers. |
| Technical logs (IP address, browser, request details) | Every request, kept briefly by our hosting provider | Security, abuse prevention and fixing errors. |
Your voice and your answers
cardosec does not record or store audio. When transcription is on, your browser's own speech-recognition service turns speech into text. Google Chrome, for example, sends audio to Google for this. That processing is between you and your browser vendor. You can turn transcription off in Settings and type your answer instead.
When AI feedback is on and you finish a drill, the text of your answer, the card, and the time you spoke are sent through our server to the AI provider whose key you added (Anthropic or OpenAI), and the feedback comes back to you. We don't store your transcript or the feedback text. Only the score is saved, in your practice history. The provider handles the request under its own terms and privacy policy, on your account.
Trying cardosec without an account
In guest mode, your settings, drills and quiz results are kept in your browser's local storage on that device only, and never sent to our database. If you then sign in, the drills from guest mode are added to your new account and removed from the browser. Guests can't use AI feedback.
Who we share data with
We don't sell or rent personal data, and we don't use it for advertising. We use these providers to run cardosec:
- Cloudflare: hosting and database. Your account data is stored with Cloudflare.
- Google: sign-in.
- Anthropic or OpenAI: only if you add your own key and use AI feedback, as described above.
- Fontshare and Google Fonts: the site's typefaces are loaded from them, so they see your IP address and browser details.
- GoDaddy: email, if you write to us.
We may disclose information if the law requires it, or to protect cardosec and its users from fraud or abuse.
Cookies and local storage
We use two cookies, both strictly necessary: a sign-in session cookie (lasts 30 days) and a short-lived cookie that protects the Google sign-in step (10 minutes). Local storage remembers your theme and holds guest-mode data. No analytics or advertising cookies.
How long we keep data
Account data is kept until you delete your account. Expired sign-in sessions are removed daily. When you delete your account, your profile, settings, practice history, keys and usage records are deleted from our database straight away. Copies remain in our daily database backups until they expire after 30 days.
Your choices and rights
- Delete: Account → Delete account removes everything immediately.
- Correct or access: your settings and history are visible in the app. For a copy of your data or any other request, email hello@cardosec.com.
- Remove a key: Account → AI keys → Remove.
- Clear history: Field log → Clear log (also clears quiz results).
Depending on where you live (for example under India's Digital Personal Data Protection Act, 2023, or the GDPR), you may have further rights, including withdrawing consent and complaining to a data-protection authority. Write to us first and we'll help.
Security
All traffic uses HTTPS. Sign-in tokens are stored only as hashes, API keys are encrypted at rest, and requests that change data from other websites are rejected. No system is perfectly secure; if you find a vulnerability, please tell us at hello@cardosec.com.
Children
cardosec is meant for people aged 18 or over. If you're under 18, please use it only with a parent or guardian's consent. If you think a child's data has been collected without that consent, contact us and we'll delete it.
International transfers
Our providers may process data outside your country, including in the United States. We rely on their safeguards for these transfers.
Changes
We'll update this page when practices change, and tell signed-in users about significant changes in the app or by email before they take effect.