Version 2 · Last updated on 2026-09-06
Buboflash (buboflash.eu, the browser extension, and any downloadable programs) is run by
Piotr Wasik. For data-protection purposes he is the controller.
Contact for anything on this page: piotr.wasik@gmail.com, or by post to Piotr Wasik, 75 Wilmot Street, London E2 0BT, United Kingdom.
Your username, a hash of your password, your timezone, your notification preferences, and whatever you choose to put in your profile (headline, what you are learning, what you can help other learners with, languages). Your email address if you choose to give one — it is optional.
Why: to have an account at all, and to let other users find and follow you. Where you gave an email: to email you when you have asked to be emailed, and to reach you about your account or the service when something needs your attention. Without an email we cannot reach you at all — including to help with a lost password.
Your flashcards, annotations, notes, tags, searches, and the PDFs you upload.
Why: it is the service.
Every repetition: which card, when, how you graded it, and the scheduling state that follows from it.
Why: it is what the scheduler runs on. Without it the product does nothing. Two further uses, both inside the service: we use learning histories in aggregate across users to improve the models the service runs on — today the scheduler that decides when everyone's cards come back; over time also models that work out what material actually teaches, which can include analysing the text of cards and annotations, so the service can schedule better, suggest what to study, and search by meaning — and we may use your own activity to suggest material to study here. Your history stays yours and exportable (Your Freedom Matters § 1). A suggestion is computed for you and shown to you; it is not shared or used to advertise anything.
Each time you sign in we record the session: your IP address, your browser's user-agent
string, your Accept-Language header, your username and email, when the session started and
was last used, and how many requests it served.
Why: a session is bound to the IP address and browser it was created with, so that a stolen session cookie cannot be replayed from somewhere else. That is a security control and it is the reason the IP is there.
We delete these after 12 months; see § 8.
If you install the browser extension and switch Annotations in tabs on, and you are logged in to Buboflash, the address of every page you open is sent to our server so it can answer "do you have annotations here?". The page content is not sent. This is set out in full on the extension privacy page, and § 5 below is the part of it that belongs here.
When you annotate or tag a page on someone else's site, our server fetches that page itself and keeps the page's extracted text, so that the page is searchable alongside your own material.
We do not keep a copy of the page itself. When you open a page inside Buboflash it is fetched fresh from the site each time, so what you see is what that site is publishing today rather than a snapshot we took years ago.
Server logs have a section of their own: § 5.
We may create and use information that no longer identifies anyone — counts, averages, statistics across many users — for any purpose, including publishing it. The test is the honest one: the moment something could be traced back to you, it is personal data again and everything else on this page applies to it.
The law lets us process personal data only on one of a fixed list of grounds, and requires us to say which ground each use rests on. Here is the mapping:
| what we do | the ground the law calls it |
|---|---|
| run your account, keep what you make, schedule your learning | performance of a contract — it is the service you signed up for |
| keep session records and server logs | legitimate interests — keeping the service secure |
| improve the models on aggregated data, suggest material to study, understand how the service is used (counts and patterns, never a study of one person) | legitimate interests — making the service better without identifying anyone where identification is not needed |
| send you emails you asked for | your request |
| reach you about your account or the service, where you gave an email | legitimate interests |
| anything else | only with your consent, and only where this notice says so |
Your email address itself is optional.
| who | what they get | when | transfer mechanism |
|---|---|---|---|
| Google (reCAPTCHA) | your IP address and the browser signals reCAPTCHA collects | only on the create-account form | Google is in the United States. Google LLC is certified under the UK Extension to the EU–US Data Privacy Framework, which is the legal safeguard for that transfer. |
| OVH, our hosting provider in Germany | everything on this page, as the infrastructure it sits on | always | OVH is in the European Union; the UK treats EU countries as adequate, so no additional safeguard is needed. |
| the site you are annotating | our server's IP address, not yours | when our server fetches a page for you | N/A |
We do not currently send email at all. If we start — a mail provider would then see your email address and name — we will name the provider here before the first mail goes out.
The last row is worth stating positively: when you open a webpage inside Buboflash, the site you are reading sees a request from our server, not from you.
Our server keeps a short-term log of the requests it handles — who made them and when — so that faults can be diagnosed and abuse spotted. Page addresses are removed from it before it is written. If you use the browser extension, the log records that your extension asked, when, and for which account — never which page you were on. The web server in front does the same: it logs the path of each request without its parameters.
So the address of a page you merely visit is retained nowhere; the address of a page you annotate becomes part of the annotation itself, which is the service (§ 2e). We do not build a picture of what you read. Logs are deleted on a schedule (§ 8), and we do not keep the contents of your requests or your sign-in tokens in them.
Buboflash sets two cookies of its own. Neither is used for tracking or advertising (§ 3).
| cookie | what it does | how long |
|---|---|---|
| session cookie | keeps you signed in for the current visit | until you close the browser |
remember-me |
signs you back in without your password on your next visit — and is what keeps the browser extension signed in, since it runs across browser restarts | 90 days from your last visit — each visit renews it |
Why there is no cookie banner. Both cookies are necessary to run a service you asked for — and the second one is set only if you tick Log me in automatically when you sign in. The law requires consent for cookies that are not strictly necessary — analytics, advertising, tracking — and Buboflash has none of those. A banner asking you to accept a cookie the site cannot work without would be asking a question with one possible answer, so we have not put one up. What the law does require is that we tell you, which is what this section is.
Google reCAPTCHA sets its own cookie on the create-account page only — nowhere else on the site. It is there to keep automated signups out. See § 4.
The app also keeps some working data in your browser's own storage — unsent revision grades so a dropped connection cannot lose a grade, and unsaved drafts. It is part of making the service work, it never leaves your browser except as the action it exists to complete, and it is not tracking.
You can ask us to show you what we hold about you, correct it, delete it, or give it to you in a portable form. You can object to processing and withdraw consent where consent is what we rely on. You can complain to the Information Commissioner's Office, the UK's data-protection regulator, at ico.org.uk if you think we have got it wrong.
We keep your account, what you make and your learning history for as long as you have an account, and delete them when you close it. Copies in our routine backups are used for nothing except recovering from failures — including recovering one person's material after a defect that hurt only them — and fall away as backups are replaced: within three months for the weekly copies, within three years for the monthly ones. Things we keep only for as long as they are useful — sign-in records, server logs, and the text we extract from pages you annotate or tag — we delete on a schedule rather than holding indefinitely.
Server logs are kept for 14 days. Sign-in records are kept for 12 months. Database backups are stored for up to 3 years. The text we extract from a page is deleted when the last annotation or tag on that page goes.
Write to the address in § 1 — email or post, we read both — and we would rather hear from you first. The right to complain to the Information Commissioner's Office is in § 7.
See also: Terms of Service, Your Freedom Matters, Browser Extension Privacy.