Skip to content
๐Ÿ—“๏ธ Scheduled maintenance โ€” Sep 18โ€“19, 04:00โ€“08:00 UTC daily. All services will be unavailable. Details โ†’

Privacy Policy

Privacy Policy

Effective Date: September 2, 2026

The short version. This summary is for convenience only โ€” the full policy below is what applies.

  • The main website sets no cookies and uses anonymous analytics. No account is needed.
  • Your flashcards only pass through our tunnel servers โ€” they are never stored, logged, or read.
  • Two optional features are different. Hosted Anki runs a copy of Anki on our servers, so your collection and media are stored there while your instance exists and are permanently removed when you delete it. Your AnkiWeb password is never stored โ€” you enter it yourself inside the remote desktop. The media library stores the files you upload or generate (text you submit for audio generation is processed by Microsoft Azure) until you delete them.
  • The community forum and the cloud service each need their own account; the forum and the SaaS dashboard use cookies to keep you signed in.
  • We do not log the IP addresses of tunnel or MCP connections. Service logs are kept for up to 31 days; performance metrics for 7 days.
  • The newsletter stores only your email address; you can unsubscribe at any time.
  • Email support@ankimcp.ai to see or delete the data we hold about you.

This Privacy Policy describes how ankimcp.ai (“Website”), the AnkiMCP software (“Software”), and the AnkiMCP SaaS cloud service (“SaaS Service”) handle your information.

1. Information We Collect

Website Analytics

We use Umami, a privacy-focused, self-hosted analytics platform. Umami collects:

  • Page views and referrer URLs
  • Browser type and operating system
  • Country-level location (from IP, which is not stored)

Umami does not use cookies, does not track users across sites, and does not collect personal information. All data is aggregated and anonymous.

Newsletter

If you subscribe to our newsletter via MailerLite, we collect your email address. MailerLite acts as our data processor and stores your email on their servers. You can unsubscribe at any time using the link in every email.

Hosting

This website is served through a third-party hosting provider, which may collect technical information such as IP addresses in server logs as part of operating the infrastructure.

Community Forum (forum.ankimcp.ai)

We operate a self-hosted Discourse community forum. When you use the forum, we collect:

  • Account information: email address, username, and display name. Accounts are created through our self-hosted Keycloak identity provider, which supports Google and GitHub social login as well as email/password registration.
  • Posts and messages: all content you publish, including topics, replies, and direct messages.
  • Uploaded files: images and attachments you upload to posts.
  • IP addresses: logged for security and anti-abuse purposes.
  • Activity data: page views, read tracking, visit history, and notification preferences.
  • Cookies: the forum sets _t (authentication token) and _forum_session (session) cookies, which are required for the forum to function.

All forum data is stored in a self-hosted PostgreSQL database on AnkiMCP infrastructure โ€” no third-party SaaS is involved in data storage. Email notifications from the forum are delivered via a third-party email delivery service.

SaaS Cloud Service (AnkiMCP SaaS)

The AnkiMCP SaaS cloud service lets LLM clients (such as ChatGPT and Claude.ai) interact with your Anki โ€” either your local installation via secure tunnels, or a copy of Anki we run for you on our servers (the experimental Hosted Anki feature). When you use the SaaS Service, we collect and process the following information.

SaaS Account Information

When you create a SaaS account, we collect:

  • Authentication data: your email address, display name, and Keycloak user ID. If you sign in via Google or GitHub, we also receive your avatar image URL from the social login provider.
  • Account identifiers: a unique user ID assigned to your account.
  • Authentication method: which social login provider you used, or that you registered with email/password.
  • Cookies: when you sign in to the SaaS dashboard (web.ankimcp.ai), it sets httpOnly authentication and session cookies. These are required for sign-in and are not used for tracking.

SaaS accounts are managed through our self-hosted Keycloak identity provider, which also handles forum authentication.

Tunnel Connection Data

When you connect your local AnkiMCP client (the add-on or the CLI) to the SaaS tunnel server, we collect:

  • Connection metadata: connection timestamps (connect/disconnect). We do not log the IP addresses of tunnel or MCP connections in our application logs.
  • Connection state: whether your client is currently connected, for display on your dashboard and to route LLM requests.

Connection state is short-lived routing data on the tunnel server and is not persisted to a database. Connection timestamps appear in service logs, which are retained for up to 31 days. Our network infrastructure provider (Cloudflare) may process connection metadata, including IP addresses, at the network edge under its own privacy policy.

LLM OAuth Data

When an LLM client connects to your tunnel, we process:

  • OAuth client registrations: LLM clients register via Dynamic Client Registration with our self-hosted Keycloak identity provider. We store the client ID and associated metadata. We do not store OAuth access tokens or refresh tokens โ€” those are managed by Keycloak and issued directly to the LLM client.
  • Client-to-user mappings: we maintain a mapping between registered OAuth clients and your tunnel so that LLM requests can be routed to your client.
Authless Access

The tunnel is authenticated by default. You can optionally enable Authless access in your Tunnel Dashboard. When you do:

  • We generate a private URL containing a secret identifier for your tunnel and store that identifier to route requests to you.
  • Requests made through that URL are not tied to a signed-in client or account: anyone who knows the URL can access your Anki through your tunnel until you disable authless access or regenerate the URL. Treat the URL like a password and do not share or publish it.
  • We process the same connection metadata (such as timestamps) for authless requests as for authenticated ones.
Subscription Data

We store:

  • Subscription tier: your current plan (Free, Plus, or Pro).
  • Tier history: an audit trail of tier changes (upgrades, downgrades) with timestamps.
  • Expiration date: when your current subscription period ends (for paid plans).

Payments for paid tiers are handled by our third-party Payment Provider โ€” see the Terms of Service (Payments section) for the current status. Your payment details โ€” card number, billing address, and related checkout information (which may include your IP address, collected for tax-location and fraud-prevention purposes) โ€” are collected and processed by the Payment Provider on its own checkout pages, under its own privacy policy. Card numbers never reach our servers and we do not store them. Where the Payment Provider acts as merchant of record, it is the seller of record for your purchase and an independent controller of the payment data it collects.

Payments for paid tiers are processed by Polar Software, Inc. (polar.sh), which acts as the merchant of record for your purchase. Polar's buyer terms and privacy policy apply to your purchase in addition to these Terms.

Payments were processed by Paddle (merchant of record) until September 1, 2026. Paddle retains the payment data it collected under its own privacy policy.

Service Monitoring (OpenTelemetry)

We use OpenTelemetry to collect service health metrics and request traces. This includes:

  • Performance metrics: request latency, error rates, and service availability.
  • Request traces: request paths, HTTP status codes, and timing data across services.
  • Service identifiers: your user ID may appear in trace metadata for debugging purposes.

OpenTelemetry data is used exclusively for service reliability and debugging. It does not capture the content of your Anki flashcards or LLM conversations.

Data Transit (Anki Flashcard Data)

This is important to understand: when you use the SaaS tunnel, your Anki flashcard data passes through our tunnel server on its way between the LLM client and your local Anki installation. Here is how we handle it:

  • No persistent storage: Anki data is relayed in real-time over WebSocket connections. It is temporarily present in server memory during transit but is never written to disk, logged, or stored in any database.
  • No inspection or analysis: we do not read, index, analyze, or use the content of your flashcards or LLM requests/responses.
  • Encryption in transit: connections between your AnkiMCP client (the add-on or the CLI) and our tunnel server, and between LLM clients and our tunnel server, use TLS encryption.
  • Your data stays yours: all Anki data remains on your local machine. The tunnel is a pass-through โ€” we are a conduit, not a data controller, with respect to your flashcard content.
Hosted Anki Data (Experimental)

Hosted Anki is different from the tunnel. To run a copy of Anki on our servers, we store your Anki data rather than only relaying it. When you use Hosted Anki:

  • Stored collection and media: your Anki collection and media files are stored on persistent storage on AnkiMCP infrastructure. We store this so your hosted instance can run and be reached by your AI (and by you through the remote desktop). We store it only to operate the feature โ€” we do not read, index, analyze, or use its content for any other purpose.
  • Remote desktop sessions: when you open your hosted Anki through the in-browser remote desktop, the session streams the running desktop to your browser. We may process operational data needed to run and route the session (such as session and connection state, timing, and IP address for the connection), but we do not record the contents of your screen or capture what you type.
  • AnkiWeb password is never stored: if you sync your hosted instance with AnkiWeb, you enter your AnkiWeb credentials yourself, inside your remote desktop session, directly with AnkiWeb. Your AnkiWeb password is never stored, transmitted to, or accessible by AnkiMCP.
  • Retention: your stored collection and media persist for as long as your hosted instance exists. When you delete the instance (or when it is removed after account deletion), that data is permanently removed and cannot be recovered. You are responsible for your own backups โ€” see Data Retention below.

2. Information We Do Not Collect

  • No cookies are set by the main website (ankimcp.ai). The community forum (forum.ankimcp.ai) and the SaaS dashboard (web.ankimcp.ai) use cookies for authentication โ€” see the respective sections above.
  • No user accounts are required on the main website (ankimcp.ai). The community forum and the SaaS cloud service each require separate accounts โ€” see the respective sections above.
  • No personal data is collected through website analytics.
  • The AnkiMCP software, when used in local-only mode (without the SaaS tunnel), runs entirely on your machine and does not send any data to our servers or any third party. When used with the SaaS tunnel service, flashcard data passes through our servers in transit but is not stored โ€” see Data Transit above. Cloud features you choose to use do store what you put into them: files in your media library are stored there, including audio generated by text-to-speech and the source text kept in that file’s description.
  • No flashcard content is stored, logged, or analyzed by the SaaS tunnel. We do not have access to the contents of your Anki decks when you use the tunnel. (Two features are exceptions, because storage is what they do: the media library, which keeps the files you upload or generate, and the optional, experimental Hosted Anki feature, which runs Anki on our servers and stores your collection and media there โ€” see Hosted Anki Data above.)
  • No AnkiWeb password is ever collected, stored, transmitted to, or accessible by AnkiMCP. If you sync Hosted Anki with AnkiWeb, you enter your AnkiWeb credentials yourself inside your remote desktop session, directly with AnkiWeb.

3. Third-Party Services

We rely on the following third-party services:

ServicePurposeTheir Privacy Policy
Hosting provider (third-party)Website hostingN/A
CloudflareNetwork edge for SaaS connections (TLS, DDoS protection)Cloudflare Privacy Policy
Umami (self-hosted)Anonymous analyticsUmami Privacy
MailerLiteNewsletter deliveryMailerLite Privacy Policy
Polar Software, Inc. (merchant of record)Payment processing and checkout (since Sep 2026)Polar Privacy Policy
Paddle (until Sep 1, 2026)Payment processing (historical โ€” retains past payment data)Paddle Privacy Policy
Microsoft Azure (AI Speech)Speech synthesis โ€” text you submit for audio generation is processed by Microsoft AzureMicrosoft Privacy Statement
Discourse (self-hosted)Community forumDiscourse Privacy Policy
Keycloak (self-hosted)Authentication for forum, SaaS accounts, and LLM OAuthKeycloak Privacy
Email delivery service (third-party)Forum email notificationsN/A
PostgreSQL (self-hosted)SaaS user data and subscription storageN/A (self-hosted, no third-party access)
NATS (self-hosted)Internal event streaming between SaaS servicesN/A (self-hosted, no third-party access)
OpenTelemetry (self-hosted)SaaS service health monitoringN/A (self-hosted, no third-party access)

A note on self-hosted infrastructure: PostgreSQL, NATS, Keycloak, and OpenTelemetry are all hosted on AnkiMCP-controlled infrastructure. Apart from the third-party services listed above โ€” in particular our Payment Provider for payments and Microsoft Azure for speech synthesis โ€” your SaaS data is stored and processed on that infrastructure. When you use text-to-speech, the text you submit is sent to Microsoft Azure to be turned into audio; the generated audio file is then stored in your media library, together with a description that records the text it was made from.

4. Your Rights

You have the right to:

  • Unsubscribe from the newsletter at any time via the unsubscribe link in emails
  • Request deletion of your email from our newsletter list
  • Request information about what data we hold about you

Since we use cookieless, anonymous analytics, there is no personal website analytics data to delete or export.

Forum users additionally have the right to:

  • Edit or delete your own posts and direct messages
  • Export your data via the Discourse profile settings (account data download)
  • Delete your account via profile settings or by contacting us โ€” this anonymizes your posts (see Data Retention below)
  • Control notifications โ€” manage email notification preferences in your forum profile

SaaS users additionally have the right to:

  • Access your data โ€” view your account information, connection history, and subscription status through the SaaS dashboard.
  • Delete your account โ€” request complete deletion of your SaaS account and all associated data by contacting support@ankimcp.ai. Account deletion removes your user record, OAuth client mappings, and subscription history, except records we are legally required to retain (for example for tax or accounting purposes). This action is irreversible.
  • Cancel your subscription โ€” downgrade from a paid tier to the free tier at any time through the dashboard.
  • Disconnect your client โ€” disconnect your local AnkiMCP add-on or CLI from the tunnel at any time, immediately stopping all data transit through our servers.
  • Delete Hosted Anki data โ€” if you use Hosted Anki, delete your hosted instance at any time to permanently remove the collection and media stored for it from our servers.
  • Request data export โ€” request a copy of all personal data we hold about your SaaS account by contacting support@ankimcp.ai.

5. Data Retention

  • Newsletter emails are retained until you unsubscribe or request deletion
  • Analytics data is aggregated and anonymous โ€” no individual user data is stored
  • Forum posts are retained for as long as the forum operates. Soft-deleted posts are permanently purged after 30 days.
  • Forum IP addresses are retained for security and anti-abuse purposes
  • Forum account deletion anonymizes your posts (author replaced with a generic label) but does not remove the post content, as other users may have relied on or replied to it
  • SaaS account data (email, name, avatar, Keycloak ID) is retained for the lifetime of your account and deleted upon account deletion
  • Service logs are retained for up to 31 days and then automatically purged. IP addresses of tunnel and MCP connections are not logged
  • OAuth client registrations are retained while your account is active. They are deleted when you delete your account
  • Subscription history and usage statistics (tier changes, monthly request counts, timestamps) are retained for the lifetime of your account for audit purposes and deleted upon account deletion, except records we are legally required to retain (for example for tax or accounting purposes), which are kept for the statutory period and then deleted
  • Diagnostic traces are retained for up to 30 days and performance metrics for up to 7 days, then automatically purged. This data does not contain flashcard content
  • In-memory tunnel state (active connection data) exists only while your client is connected and is lost when the connection ends or the server restarts
  • Media library files (uploaded files and generated audio, including the source text stored in a file’s description) are retained until you delete them and are permanently deleted upon account deletion
  • Hosted Anki data (your stored collection and media) is retained for as long as the hosted instance exists and is permanently deleted when you delete the instance or when it is removed following account deletion. Superseded backup versions are automatically removed within 7 days. Deletion is irreversible, so you are responsible for maintaining your own backups (for example, via AnkiWeb sync or by exporting your collection)

6. Children’s Privacy

This website and software are not directed at children under 13. We do not knowingly collect personal information from children.

7. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date.

8. Contact

For privacy-related questions or requests, contact us at support@ankimcp.ai.