Skip to content

Privacy Policy

Last updated: October 4, 2026

1. Information We Collect

When you create an account, we collect your email address and a hashed password(we never store your password in plain text). When you use our services, we also collect:

  • Practice question responses and scores (to power your analytics dashboard)
  • Documents you upload for card generation (temporarily stored, deleted within 24 hours)
  • Anki study data encoded in study codes: retention rates by category and, from add-on version 0.8.1, the text of up to 10 of the cards you miss most (300 characters each), so practice questions can test them
  • While you are signed in to the Anki add-on, daily totals of your Anki reviews: for each day, how many reviews you did, how many you didn't answer Again, and the time spent (to show on your analytics page). The first sync sends the past year. No card content, card IDs or individual reviews are sent. You can turn this off with sync_review_statsin the add-on's config.
  • The Anki notes you select when you make a lesson in the Anki add-on (see section 4)
  • The text of a document you match to your cards in the Anki add-on, and the cards that match it (see section 5)
  • What you type into a smart card search in the Anki add-on, and the cards it found, while the search runs (see section 6)
  • Basic usage data: pages visited, features used, error logs

2. How We Use Your Information

  • To provide and improve our services (explanations, card generation, analytics)
  • To process payments through Stripe (we never see your full card number)
  • To send transactional emails (verification, password reset)
  • To detect abuse and enforce rate limits

We do not sell your data to third parties. We do not use your data for advertising.

3. Third-Party Services

  • Stripe — payment processing. Subject to Stripe's Privacy Policy.
  • Anthropic (Claude API) — AI-powered explanations, card generation, lessons, card match and card search. Document content, the text of the notes used for a lesson that is written or adapted by AI, the text of a document you match with the cards graded for it, what you type into a smart card search, and the text of most-missed cards in a study code you practise with, is sent to the API for processing but is not stored by Anthropic for training.
  • TypeSafe (Jev API) — ranks the cards a smart card search found. What you searched for and the first 250 characters of up to 100 of your cards are sent to it for each smart search.
  • Resend — transactional email delivery.

4. Lessons

When you make a lesson in the AnkiBoss Anki add-on, the add-on reads the notes you selected:

  • their text
  • their note IDs (Anki note ID, note GUID and, for AnKing notes, the AnkiHub note ID)
  • their tags
  • how often you have forgotten each card

It works out on your computer which cards are weak. Only a yes/no "weak" flag per note is sent to us, not your review history.

The text of the selected notes is saved with the lesson in your account, so the lesson can show your cards on ankiboss.com. Images from your deck are never uploaded; the add-on shows them from your own collection.

Which steps of a lesson you have marked done is saved with it too, so your place follows you between Anki and ankiboss.com.

If a lesson has to be written or adapted by AI, the text of the selected notes is sent to our AI provider, Anthropic, to write it.

When AI writes or adapts a lesson, we also keep a copy of the lesson itself. The copy isn't linked to your account and doesn't include the text of your notes. It keeps only the lesson, the IDs of the notes it was made from, and a fingerprint of each note that tells us whether you had edited it.

To find images for a lesson, AnkiBoss sends short search phrases (never the text of your notes) to Wikimedia Commons, Open-i and Brave Search. Those images load straight from the sites that host them, which can see your IP address, as with any website you visit.

  • You can delete any lesson on the Lessons page.
  • Deleting your account deletes all your lessons.
  • Deleting a lesson or your account doesn't delete the copy described above, because it isn't linked to you.
  • Lessons are included in your data export.

The add-on asks for your permission the first time you make a lesson.

5. Card Match

When you use Find cards for a document in the AnkiBoss Anki add-on, the add-on reads the document's text on your computer. The file itself is never uploaded.

  • To find your cards, AnkiBoss sends the document's text to be read by AI (our AI provider, Anthropic). The text is not kept.
  • The add-on then searches your cards on your computer and sends up to 400 matching cards (the first 250 characters of each, with their note IDs) to be graded.
  • The cards that match are saved with the result in your account (the first 250 characters of each, its deck and its note ID), so you can see it on ankiboss.com/card-match. The note IDs and grades of the other cards that were graded are kept with it, without their text.
  • To make a repeat match of the same document cheaper, we keep the list of topics AI found in it, under a fingerprint of the document's text. That list isn't linked to you or your account, and it doesn't contain the document's text or your cards.
  • You can delete any match on the Card Match page.
  • Deleting your account deletes all your matches.
  • Card matches are included in your data export.

The add-on asks for your permission the first time you match a document.

6. Card Search

When you use Search my cards in the AnkiBoss Anki add-on, or start a search in Anki's Browse window with ?, the results that appear as you type come from your computer. Nothing is sent until you press Enter.

  • When you press Enter, AnkiBoss sends what you typed to AI (Anthropic), to work out what you mean.
  • The add-on then searches your cards on your computer and sends up to 100 of them (the first 250 characters of each, with their note IDs) to be ranked by AI (TypeSafe).
  • AnkiBoss does not save what you search, or the cards' text. For each smart search it keeps a record with the date, whether it finished, how many cards were ranked, the scores by note ID, and its cost and timing, for 30 days. That record counts your smart searches against your plan's daily allowance.
  • Deleting your account deletes these records.
  • Your data export lists them (dates and counts only).

The add-on asks for your permission the first time you run a smart search.

7. Data Retention

  • Account data is retained until you delete your account.
  • Uploaded documents are automatically deleted within 24 hours of processing.
  • Quiz session data is retained for the lifetime of your account to power analytics.
  • Smart card search records (no search text) are deleted after 30 days.

8. Your Rights

You can at any time:

  • Access your data through your dashboard and analytics pages
  • Correct your email via account settings
  • Delete your account and all associated data from your dashboard
  • Export your data by contacting team@ankiboss.com

9. Security

We use industry-standard security measures including encrypted connections (HTTPS), hashed passwords (bcrypt), scoped authentication tokens, rate limiting, and security headers. However, no system is 100% secure.

10. Cookies & Analytics

We use a single authentication token stored in your browser's localStorage for sign-in, and a small CSRF cookie tied to that session. We do not sell or share this data.

In some environments we run Google Analytics 4 (the @next/third-parties loader) to measure aggregate traffic — page views, referrers, and broad device class. Google Analytics sets first-party cookies (typically _ga and _ga_*) and may process IPs in transit. We do not run advertising trackers, retargeting pixels, or any third-party cross-site analytics beyond GA4. If you would rather not be measured, browser-level DNT/ad blockers will block GA fully.

11. Children

AnkiBoss is designed for medical students and professionals. We do not knowingly collect data from children under 13.

12. Changes to This Policy

We may update this policy from time to time. We will notify registered users of significant changes via email.

13. Contact

Questions about this policy? Email us at team@ankiboss.com.