Privacy, in plain type.
Overview
The short version: misu stores your cards and your study history so it can schedule your reviews. We don't run ads, we don't use analytics trackers, and we don't sell data — there's nothing to sell it for. This policy covers the misu app and misu.io, operated by A3 Studio L.L.C-FZ ("misu", "we").
What we collect
Account. An email address, or the identifier your sign-in provider (Apple or Google) shares with us. Sign in with Apple lets you hide your real email; that works fine with misu.
Your content. The cards, decks, and templates you make, and anything you attach to them — photos, images, audio. This is the whole point of the app, and it's yours (see the Terms).
Study activity. Which cards you reviewed and how they went. The FSRS scheduler needs this history to time your next reviews; it's also what grows your garden and prints your monthly receipt.
Purchase state. Whether you have misu Plus and when it renews, via your app store (Apple or Google) and RevenueCat. We never see your card number or billing address — the store keeps those.
Crash reports. If the app crashes, a technical report (device model, OS version, what the code was doing) goes to Sentry so we can fix it. Crash reports don't include your cards.
Onboarding answers. Your level, pace, why you're learning, and where you heard about misu — used to set up your plan and to know which of our efforts actually work.
What we don't collect
No advertising identifiers, no third-party analytics, no cross-app tracking (our App Store privacy manifest declares none, and iOS would hold us to it). No location, no contacts, no background microphone. We don't send promotional email. We don't sell or rent personal information to anyone, and we don't share it for advertising.
How we use it
To run misu: syncing your deck between devices, scheduling reviews, generating card content you ask for, processing your subscription, sending the reminders you turn on, and fixing crashes. That's the list. Notifications are optional and controlled in iOS Settings.
Card generation
When a card autofills or artwork is generated, the input you provided — the word, sentence, or photo — is sent through our gateway to the generation services we use, used to make your card, and returned. We use it for nothing else: we don't build training datasets from your content, and your cards aren't used to train anyone's models. Generated content is stored as part of your card like anything else you'd attach.
Camera, microphone & photos
Camera and photo access exist to turn what you see into cards; microphone access exists for audio you record onto cards. Capture and photo-subject extraction happen on your device — only what you actually attach to a card is uploaded, as your content. Permissions are requested when first needed and controlled in iOS Settings.
Who touches your data
We use a small set of service providers to run misu, each processing data only to provide their service to us: Apple and Google (distribution, payments, sign-in), RevenueCat (subscription state), Cloudflare (API and media storage), Turso (encrypted database sync), Sentry (crash reports), and the generation services behind card autofill and artwork (which receive only the inputs described above). We share personal information with no one else, except where the law genuinely requires it.
Security & storage
misu is local-first: your deck lives on your device and works offline, syncing over encrypted connections when you're signed in. Data at our providers is protected by industry-standard measures. Honesty requires the standard caveat: no method of electronic storage is 100% secure, and nobody can promise absolute security — we protect your data within commercially reasonable means.
Retention & deletion
We keep your data for as long as you have an account, because it is your account. Delete your account and we delete your personal information from our systems within 30 days, except minimal records we're legally required to keep (like transaction history). You can also just delete the app — anything that never synced dies with it.
Your rights
You can access, export, correct, and delete your information, object to or restrict our processing of it, and complain to your local data-protection authority. Exercise any of these in the app's Settings or by emailing support@misu.io — we'll respond within 30 days and won't treat you differently for asking.
Regional laws
EU & UK (GDPR). Our legal bases are performing our contract with you (running the app you signed up for), your consent (optional things like notifications), and legitimate interests (fixing crashes, preventing abuse). All the rights above apply, plus data portability.
US states (California, Colorado, Virginia and similar laws). You have the rights above; we don't "sell" or "share" personal information as those laws define it, and we've collected none of the "sensitive" categories they enumerate beyond what you put on your own cards.
Australia (Privacy Act), Canada (PIPEDA). We handle personal information consistently with these frameworks; contact us to exercise access or correction rights.
Children
misu isn't directed at children under 13 (or the higher minimum age in your country), and we don't knowingly collect their data. If you believe a child has an account, email us and we'll delete it.
Business transfers
If misu is ever acquired or its assets transferred, your information may be part of the transferred assets — but this policy would still bind its use, and we'd notify you before anything changed materially.
Changes & contact
If this policy changes materially, we'll say so in the app and update the date at the top of this page before the changes apply. Questions, requests, complaints: support@misu.io. Operated by A3 Studio L.L.C-FZ.