Version 2.0. Effective 22 August 2026
This policy explains what Vernabla ("we", "our", or "us") collects, how we use it, and your rights.
Vernabla keeps data in your browser in order to work: your sign-in session, your display preferences, and a full local copy of your decks, cards, and review history. The app reads from that copy so it stays fast and keeps working offline, then syncs it to our database.
None of it is used for advertising, tracking, or building a profile of you, and nothing is shared with third parties from your device.
In full, this is everything Vernabla puts on your device:
| What | Where | Why | How long |
|---|---|---|---|
Sign-in sessionsb-…-auth-token | Local storage | Keeps you signed in between visits | Until you sign out or clear site data |
Themevernabla.theme | Local storage | Remembers whether you chose light or dark | Until you clear site data |
Quick-start dismissalvernabla.quickstart.dismissed | Local storage | Stops the getting-started card reappearing after you close it | Until you clear site data |
| Your decks, cards and review history | IndexedDB | The local copy the app reads from, so it works offline | Until you delete your account, clear site data, or someone else signs in on this device |
None of these are advertising or analytics identifiers, and none are readable by another site. We do no cross-site tracking, so there is nothing for a Do Not Track signal to switch off and we do not act on one.
If you sign in on a device where someone else used Vernabla before you, their local copy is cleared before any of it can be displayed. You will never see another person's cards, and yours are never uploaded to their account.
Signing out does not erase the local copy. It stays so that signing back in on your own device is instant rather than a full re-download. On a shared or public computer, signing out is therefore not enough on its own: delete your account, clear the site data, or rely on the protection above, which clears the copy the moment a different account signs in.
Clearing your browser's site data erases all of this. Anything that had already synced comes back when you sign in again; anything that had not is gone.
Paying is the one step that leaves our site. The checkout page belongs to Stripe and sets its own cookies under Stripe's privacy policy, not ours.
Before launch we ran a waitlist. It is closed: the signup form has been removed and no address can be added. We still hold those records for a limited period, described under "Data retention".
For each signup we hold the email address and the consent record captured with it: the exact notice shown at the time, kept word for word, the page it was submitted from, and the date and time. Nothing further is ever sent to those addresses.
We do not sell your personal information, and we do not share it for advertising.
We do not train any model on your content, and we do not license it to anyone else to train theirs.
Card text is sent to OpenAI and Anthropic over their commercial APIs. Once there it is handled under their terms, which are linked in the table below, and what they retain is set by those terms rather than by us.
These are the companies that handle your information on our behalf.
| Provider | What it does for us | What it sees | Its privacy policy |
|---|---|---|---|
| Supabase | Database, authentication, and backend hosting | Your account, decks, cards, review history, and consent records | supabase.com/privacy |
| Cloudflare | Website hosting, content delivery, and cookieless analytics | Your IP address and the pages you request | cloudflare.com/privacypolicy |
| Sentry | Error and crash monitoring, signed-in users only | Technical details of a failure, and your account identifier | sentry.io/privacy |
| OpenAI | Embeddings, the numeric representation behind the semantic map, and sometimes the step that judges which cards are related | The text on the cards being processed | openai.com/policies/privacy-policy |
| Anthropic | Stories, translations, word lookups, the extra context added to a card, and usually the step that judges which cards are related | The text on the cards being processed | anthropic.com/legal/privacy |
| Stripe | Payment processing and subscription billing | Your payment details, which it takes directly and never passes to us | stripe.com/privacy |
Our subprocessors listed above are located in the United States, so your information is processed there. Under Canadian law we remain accountable for information handled on our behalf abroad.
In transit. Every connection to Vernabla is encrypted with HTTPS, including the calls that carry your card text to our AI providers. The site also sets browser-level protections that limit what an injected script could do: a strict Content Security Policy, a ban on the site being embedded in a frame, and a referrer policy that stops the address of the page you are on being handed to other sites.
At rest. Our database provider encrypts stored data at rest. Your password is never stored, only a salted hash of it. Every table holding your data has row-level security enabled, enforced by the database itself, so a request carrying your identity can reach your rows and no one else's.
On your device, not encrypted. The local copy of your decks and cards is stored in your browser without encryption. Your device's own sign-in is what protects it, and the shared-device case is handled as described above: another person's local copy is cleared before it can be displayed to you.
If something goes wrong. If a breach affects your personal information and creates a real risk of significant harm to you, we will notify you and the relevant regulator, as the law requires.
Your account and content are kept for as long as your account exists. You can delete your account at any time from within the app. That erases your decks, cards, review history, embeddings, subscription record, purchase consent records, and AI usage counts from our database. We do not run a separate backup system, so there is no further copy on our side waiting to expire.
Deletion is immediate. It happens while you wait rather than on a scheduled sweep: one request cancels any subscription, clears your rows, and removes your sign-in identity. We do not hold your data for a grace period first. The one exception is where the law requires us to keep something for longer, such as a preservation obligation once a legal claim is on foot. Where that applies we keep only what we are required to keep, for only as long as we must, and erase it afterwards.
Stripe keeps its own record of payments you made, under its own retention policy and legal obligations. Deleting your account here does not erase that, and we cannot delete it on your behalf.
Sentry keeps its error reports under its own retention schedule. Those reports hold the technical details of a failure and your account identifier, and deleting your account here does not remove them. They age out on Sentry's schedule rather than ours.
The waitlist is a closed list. We keep the remaining waitlist records until 12 months after launch, then delete the list in its entirety, opted-out addresses included. We hold them that long so we can show, if asked, that each recipient had agreed to receive the announcement.
Deleting your account does not erase your waitlist entry, if you have one. The two are not linked: the waitlist is keyed by email address, your account by an internal id. Account deletion marks that waitlist record as opted out and erases the IP address recorded with your signup, and stops anything further being sent to it. The address remains until the 12-month purge above, together with the notice you were shown and the page you submitted it from, as evidence that the announcement was one you had agreed to. If you would rather it were gone sooner, ask us and we will erase it outright.
We email you about your account: confirming sign-up, resetting a password, receipts, and notices about your subscription. These are necessary to provide the Service rather than marketing, so they have no unsubscribe link. You stop receiving them by closing your account.
The launch announcement was the only marketing email we have sent, and the waitlist that authorised it is closed. If we ever want to send you marketing, we will ask you to opt in to it separately. An account with us, or an old waitlist signup, is not permission for it.
Vernabla is not intended for children. You must be at least 16 years old to hold an account, and we ask you to confirm that when you sign up. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us their information, email [email protected] and we will delete the account and its data.
You have the right to access, correct, or delete your personal information, and to receive a copy of it. To exercise any of these, email us at [email protected]. We will respond within 30 days. You can also delete your account yourself at any time from within the app; what that erases, and the one thing it does not, are set out under "Data retention".
For a waitlist address, a deletion request made to us by email is honoured by erasing the record outright. The list is closed, so there is no longer any reason to keep a suppression entry to stop a future signup being emailed. Deleting your account is the separate case described under "Data retention": it silences the address but does not, by itself, erase it.
If we change this policy, we will update the version number and effective date above. If a change materially affects how we handle information you have already given us, we will tell you by email before it takes effect.
This policy is governed by the laws of Alberta, Canada.
Questions about this policy, or to exercise your rights, contact us at [email protected].