Saved decks stay in your browser. Imports and hosting make network requests. Here is what happens, and what you control.
What this covers
This policy describes DeckGrab, StudyDeck and the DeckGrab browser extension, maintained through the linked open-source projects. The sites help you import, create and study flashcards. You do not need an account with us. We do not sell your study content or run advertising networks.
What stays in your browser
DeckGrab saves your current deck, edits and import details in browser storage. StudyDeck stores your sets, cards and scores in its browser database, along with study-session progress, difficult-card selections and preferences. Both sites remember that you dismissed the welcome screen. Some temporary results last only for the browser session.
Saved decks are not automatically uploaded to a deck database or synced between devices. The two websites have separate storage. Pasted text and supported file imports are processed in your browser. Exported files are saved wherever you choose on your device.
What happens when you import
- Direct link import: the Quizlet set address you submit is sent to our Cloudflare-hosted import endpoint. It requests the public set from Quizlet and returns any accessible text cards. Our application does not write these requests or cards to a server-side deck database.
- Browser extension: the extension opens or reuses the requested Quizlet tab, reads accessible text cards and the set title/count, and transfers that information directly to the requesting DeckGrab or StudyDeck tab. It does not copy your password or authentication cookies. Quizlet still handles its own sign-in and access checks.
- Bookmarklet and site-to-site handoff: cards may be carried in the part of a link after
#. That fragment is not sent in the normal HTTP request, but can be visible to page scripts, your browser history, browser sync or anyone you share the full link with. Do not share a populated import link if the cards are private. - Clipboard and downloads: copying, pasting and exporting uses your device’s clipboard or download tools when you request those actions.
Extension permissions and data use
The DeckGrab extension reads the selected set’s terms, definitions, title, expected card count and Quizlet address to carry out the import you requested. It checks matching open Quizlet tab addresses so it can reuse the correct set. This handles website content and selected page addresses; it does not collect your general browsing history.
Quizlet site access lets the packaged reader collect accessible cards and show its Grab cards controls. The extension’s bridge runs on DeckGrab and StudyDeck so those sites can request an import and receive its progress and result. The active-tab permission supports the toolbar action you invoke. There is no permission to read cookies, browser history, or every website.
The extension does not send cards to a separate extension-operated collection server, sell them, use them for advertising, or use them for credit or lending decisions. It returns the selected cards to the study website you chose, using browser messages or a URL fragment. The receiving site saves them locally only when you accept the preview. Reader and parser code is packaged with the extension; it does not download executable code.
Installing or removing the extension does not upload or erase decks saved by the websites. Uninstalling stops the extension’s access; clear the individual website’s data if you also want to remove its saved cards. Browser and extension-store providers handle installation and updates under their own policies.
Hosting and traffic analytics
Cloudflare hosts and delivers these websites and the direct-import endpoint. Network requests can involve technical information such as your IP address, browser information, requested URL and request time. Cloudflare may process this information for delivery, reliability and security under its Privacy Policy.
The sites use Cloudflare Web Analytics to understand traffic and page performance. This is separate from your saved deck database. Cloudflare describes its analytics as not tracking individuals across customer websites. See Cloudflare’s data-collection documentation. Do not put sensitive information in page addresses or public support messages.
Your choices and retention
Your locally saved study data remains until you remove it, clear that website’s browser data, use a temporary/private session that ends, or the browser removes storage. Export anything you want to keep before clearing data. StudyDeck also lets you export or delete individual sets; clearing all site data removes remaining local preferences and session records. We cannot recover data that existed only in your browser.
You can remove the extension or change its site permissions in your browser. You can block analytics requests with browser controls without changing the saved cards. Hosting-provider records follow that provider’s retention practices; clearing browser storage does not delete provider records. If applicable law gives you rights to access, correct, delete, restrict or object to processing, or to complain to a privacy authority, contact the maintainers about data within our control. There is no server-side account profile to download or delete.
External services and safety
Quizlet, GitHub and optional payment/support links are separate services with their own policies. Using a donation link takes you to the payment provider; these sites do not collect card numbers or payment credentials. Information you send through a support service is handled there, and may remain in its records.
We do not ask for a birth date, school account or student profile. Avoid including sensitive personal information in study cards. Parents and guardians can use the browser’s controls to review or remove locally saved data. No browser storage or network service is guaranteed secure, so export important work and take care on shared devices.
Questions and changes
Questions about this policy or a privacy request? Contact the project maintainers through StudyDeck on GitHub. GitHub pages and issues can be public: ask for a private contact method before sharing personal information, and do not post private decks, passwords or account details.
We will update the date on this page when the policy changes. A material change in how study content is handled will also be explained in the product before the new practice starts.