Last updated: 2026-09-05
At a glance
- You can use the site as a guest, with no account — including to buy a subscription. We keep a small anonymous session identifier in a cookie on your browser so guest progress and unlock state work; Stripe collects your email at checkout.
- An account is optional. Creating one (with Google, Apple, or a one-time email link — we never ask for or store a password) is only needed if you want your unlock to follow you across devices.
- Your name, partner's name, and onboarding questionnaire answers stay in your browser's local storage. We never receive them.
- Custom packs you write are stored on our server, so they can follow your account across devices once you sign in.
- Stripe processes subscription payments. We never receive or store your card number.
- Acquisition attribution: when you first arrive, we record once how you got here — any campaign tags in the link (UTM parameters), the referring website, ad-click identifiers (such as Google gclid, Meta fbclid, or TikTok ttclid), and which version of our landing page you saw. It remains stored on that browser session; if you create an account, the session may be linked to it but these measurement records are not copied across devices. We also record, once per session, the first time each of a few things happens: you open any page of the app, you open the packs page, you open a deck, you play a few cards from it, you reach the end of a deck, the paywall is shown to you, you attempt checkout, and Stripe Checkout is created. If creation fails, we store a broad technical category, not Stripe error text or payment details. If you take our relationship quiz, we also record the furthest screen you reached in it, as a screen number — never your answers. Only the time each one first happened is stored in this record — never which deck, which cards you saw, or anything you say to each other — and it lets us tell how far people get before subscribing. Separately, and only if you accept the cookie banner, we load Google Analytics and TikTok advertising measurement — decline and neither loads, and we also stop reporting your subscription events to them from our server. We do not run crash-reporting SDKs.
- We do not sell your personal information.
1. Information kept only in your browser
The following is saved in your browser's local storage to make the site work. It is not sent to us:
- Your first name / nickname and your partner's name, as entered during onboarding.
- Your onboarding questionnaire answers (relationship type, age range, and similar preferences) used to personalize your experience.
- Your deck progress and which packs you've viewed.
You can erase this by using Replay onboarding in Settings, or by clearing your browser's site data for talkcards.online.
2. Information we collect
a. Guest session
When you first visit the site, we set a signed, httpOnly cookie (tc_session) containing a random session identifier. It carries no personal information by itself — it lets us remember your free-tier custom-pack count and unlock state (mock or purchased) between visits on the same browser. It is not readable by page scripts and is not used for advertising.
Two further measurement records are kept against that browser session, each written once and never overwritten. Acquisition attribution: when you first arrive, how you got here — any campaign tags in the link (UTM parameters), the referring website, ad-click identifiers (such as Google gclid, Meta fbclid, or TikTok ttclid), and which version of our landing page you saw. And a short list of product milestones: the first time you open any page of the app, open the packs page, open a deck, play a few cards from it, reach the end of a deck, are shown the paywall, attempt checkout, and Stripe Checkout is created. If creation fails, we store a broad technical category, not Stripe error text or payment details. If you take our relationship quiz, we also keep the furthest screen you reached in it, as a screen number only — your answers to the quiz are never sent to us or stored. Only the time each milestone first happened is stored in this record — never which deck, which cards you saw, or anything you say to each other. Creating an account may link that session to the account, but does not copy these measurement records to another browser or device. Together they let us see which sources and landing pages bring people to TalkCards, and how far people get before subscribing. This is the same processing summarised under "Acquisition attribution" at the top of this page.
Separately, we record your answer to the cookie banner — whether you accepted or declined, and when — against your session and, if you have one, your account. Unlike the two records above, this one is updated every time you change your mind: it is what lets a withdrawal reach a subscription you already have, rather than only future visits.
b. Account (fully optional, even to purchase)
If you sign in, we use Better Auth (software we run ourselves) with these providers:
- Google Sign-In — your Google account email, name, and profile picture, as permitted by Google's consent screen.
- Sign in with Apple — your email address (which may be an Apple-generated private relay address) and, only if you choose to share it on your first authorization, your name.
- Email link — your email address, used only to send you a one-time sign-in link. We use Resend to deliver that email.
We never collect or store a password — sign-in is always via one of the above.
When you sign in, we merge your guest session (unlock status, custom packs) onto your account so it follows you across devices.
c. Custom packs
The packs and questions you write are stored on our server (a database we operate), tied to your guest session or your account. Server storage is what lets a custom pack follow you if you sign in on another device.
d. Payments — Stripe
Subscriptions are sold and processed by Stripe. Stripe handles your payment method; we never receive or store your card number. We receive from Stripe your Stripe customer id, subscription id and status, and the plan/price you purchased, which we use to unlock content and let you manage or cancel your subscription through Stripe’s Customer Portal.
e. Server logs
Like most websites, our server keeps standard access logs for every request (including your IP address, timestamp, and the page or API route requested), retained for security, abuse-prevention, and debugging purposes, for no longer than reasonably necessary for those purposes.
f. Analytics cookies (only with your consent)
When you accept the cookie banner, we load two third-party measurement tools. If you decline, neither is loaded — no analytics or advertising cookies are set and no data is sent to either provider, including from our own servers. You can withdraw consent at any time using Cookie settings in the site footer (which reopens the banner); withdrawal also deletes the measurement cookies and stops the server-side reporting described below, including for a subscription you already have.
- Google Analytics 4 (provided by Google) — measures how the site is used (pages viewed, funnel steps). It sets Google’s analytics cookies and sends usage events. We also report subscription events from our own server — a trial starting, a payment, a renewal, a failed payment. These carry the identifier from Google’s own analytics cookie and, if you are signed in, our internal account identifier — a pseudonymous id, stable for your account, that the site already sends from your browser while you are signed in. They never carry your name or email. They are sent only while your consent stands: if you decline, or later withdraw, we send nothing, including for subscriptions you already have. We use it only to understand and improve the site.
- TikTok Pixel and Events API (provided by TikTok) — measures which TikTok ads lead to visits, checkout starts, trials, and purchases. The browser Pixel may set TikTok advertising cookies. For consented conversion journeys, our server may send the same conversion with a matching event identifier so TikTok can count it once; matching information may include the TikTok click identifier, TikTok first-party cookie identifier, IP address, and browser user agent from the originating session. We do not send TikTok your email, phone number, or TalkCards user identifier, and do not enable Advanced Matching.
3. How we use information
We use the information described above to:
- Operate the site and provide the features you request, including unlocking purchased content and syncing custom packs across your devices once you’re signed in.
- Create and maintain your account, and verify and manage your subscription (including billing through Stripe's Customer Portal).
- Keep your guest session working between visits.
- Maintain security, prevent abuse, and enforce our free-tier limits.
- Respond to support requests you send us.
4. Legal bases (EEA/UK users)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (creating your account, processing your subscription, storing the custom packs you ask us to store); and our legitimate interests (guest sessions, security, server logs, preventing abuse, and measuring which sources and landing-page versions bring visitors to the Site and how far they get before subscribing — the acquisition attribution and product milestones described in section 2(a)). For the analytics and advertising tools in section 2(f) (Google Analytics and TikTok), and for the server-side reporting described there, our legal basis is your consent, which you give or refuse in the cookie banner and can withdraw at any time — we do not use them until you accept. All other processing uses only the strictly necessary session cookie. You have the right to lodge a complaint with your local data-protection authority.
5. How information is shared
We do not sell your personal information. We share information only as follows:
- Service providers we use to run the site: Google and Apple (sign-in), Resend (magic-link email delivery), and Stripe (payments). Depending on the service, a provider may act as our processor, as an independent controller, or in another role defined by its own terms.
- Analytics and advertising measurement (only if you consent to the cookie banner): Google (Google Analytics) and TikTok (Pixel and Events API). See section 2(f).
- Legal and safety: if required to comply with applicable law, legal process, or a governmental request, or to protect the rights, property, or safety of our users, the public, or us.
- Business transfers: if we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will use reasonable means to notify users of any such change affecting this Policy.
6. Third-party privacy policies
- Google: policies.google.com/privacy
- Apple: apple.com/legal/privacy
- Resend: resend.com/legal/privacy-policy
- Stripe: stripe.com/privacy
- TikTok: tiktok.com/legal/page/eea/privacy-policy/en
7. International data transfers
Our service providers may process data in countries other than yours, including the United States and the European Union. Where required, these transfers are covered by appropriate safeguards (such as the European Commission's Standard Contractual Clauses) under the providers' own data processing terms.
8. Data retention
- Information kept only in your browser remains until you clear it or use Replay onboarding.
- The guest session cookie persists on your browser until you clear cookies or it is superseded by signing in; it is not itself a long-term record of you as an individual.
- Account data (email, name/picture if provided by a sign-in provider, custom packs, entitlement status) is retained for as long as your account exists. You can ask us to delete it at any time (see below).
- Stripe retains billing records for as long as required by its own obligations (including tax and accounting law); see Stripe's privacy policy.
9. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or restrict the use of your personal information, or to object to certain processing.
- On-device data: you control it directly — use Replay onboarding in Settings, or clear your browser’s site data.
- Account data: email talkcards.support@gmail.com to request access to, correction of, or deletion of your account, sign-in data, or custom packs. We will verify your request and act on it within a reasonable time.
- Sign-in provider settings: you can also review or revoke TalkCards' access from your Google or Apple account settings directly.
- Accuracy: we rely on the accuracy of the information you or your sign-in provider supply, and will correct our records promptly upon request.
To exercise any right or ask a question, email talkcards.support@gmail.com. You will not be discriminated against for exercising your rights.
10. United States — state privacy rights
This section applies to residents of U.S. states with comprehensive privacy laws (including California, Virginia, Colorado, Connecticut, Utah, and Texas).
- Categories collected. In the past 12 months we have collected: identifiers (your email and, if provided by a sign-in provider, name/profile picture; an anonymous session id; your IP address via standard server access logs); commercial information (subscription/purchase records via Stripe); and user-generated content (custom packs you write). We do not collect your onboarding answers or partner's name on our servers — those stay in your browser.
- No sale; measurement only. We do not sell your personal information, and we do not share it to build cross-context behavioral advertising audiences. If you accept measurement cookies, we send limited on-site and subscription events to Google Analytics and TikTok solely to measure how the site and our own ads perform. We do not send either provider your name or email; TikTok also does not receive your phone number or TalkCards user identifier from us. You can opt out at any time by declining the cookie banner or using Cookie settings in the footer.
- Your rights. Subject to applicable law, you may request to access, correct, or delete your personal information. You will not be discriminated against for exercising these rights, and you may use an authorized agent where the law allows.
- How to exercise. Email talkcards.support@gmail.com; we will verify your request as required by law.
11. Canada
We handle personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws, including Quebec's Law 25. The person responsible for the protection of personal information at TalkCards is Volha Budzko, reachable at talkcards.support@gmail.com.
- We collect and use information based on your consent (express, where you sign in or subscribe) and, for routine operational data like the guest session, on implied consent and PIPEDA’s "reasonable purposes" standard, for the purposes described in this Policy.
- You may request access to, or correction of, your personal information by emailing talkcards.support@gmail.com.
- You may also send a complaint directly to talkcards.support@gmail.com; we will investigate and respond within a reasonable time before you escalate it further.
- You may file a complaint with the Office of the Privacy Commissioner of Canada or, in Quebec, the Commission d'accès à l'information.
12. Children's privacy
The site is intended for users aged 17 and older and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with information, contact us at talkcards.support@gmail.com and we will delete it. Because TalkCards requires users to be 17 or older, this already exceeds Quebec's 14-year threshold for parental consent to the collection of personal information, so no separate under-14 consent process applies.
13. Security
We take reasonable technical and organizational measures to protect information, and we rely on established providers (Google, Apple, Resend, Stripe) with their own security programs. However, no method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security.
14. Changes to this Policy
We may update this Policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, provide additional notice. We encourage you to review this Policy periodically.
15. Contact us
TalkCards (operated by Volha Budzko, individual entrepreneur)
Email: talkcards.support@gmail.com
If you have questions or requests regarding this Policy or your personal information, please contact us at the email above.