Privacy policy
Last updated: July 25, 2026
ankify is a spaced-repetition service and Chrome extension for reviewing LeetCode work. This policy explains what data is processed and why.
Data we process
- Google account identity used for authentication: user id, name, email address, profile image, sessions, and account linkage.
- Study data you choose to capture or create: LeetCode problem metadata and statements, submission code and results, notes, cards, quizzes, answers, review events, and scheduling state.
- Configuration data: review settings and encrypted AI-provider key envelopes. Raw AI keys are encrypted before storage.
- Basic operational and page-usage telemetry provided by the hosting platform. We do not sell personal data or use it for advertising.
Chrome extension behavior
- The extension runs only on LeetCode problem pages. It reads the current problem and your recent submission details from LeetCode when you capture or sync.
- It may check whether the open problem has a recent accepted submission so it can show a capture reminder. Submission source code is not sent to ankify until you choose capture or sync.
- The extension stores its API origin, preferences, and drafts in Chrome local storage. It reuses the ankify web session cookie through credentialed requests and does not store a separate ankify API token.
How data is used and shared
- Data is used to provide authentication, capture, review scheduling, quizzes, cards, history, data export, and account support.
- Hosting and database processing may be provided by Vercel and Turso. Google processes OAuth sign-in. When you use AI features, the selected context is sent to the AI provider whose key you configured (Anthropic, OpenAI, DeepSeek, or a compatible provider) under that provider's terms.
- We do not disclose your study data to unrelated third parties unless required by law or necessary to protect the service.
Retention, security, and your choices
- Data is retained while your account exists. You can export a streaming NDJSON copy or permanently delete the account and its associated database rows from Settings.
- You can sign out of the web session or remove the stored AI key at any time. Provider keys are encrypted at rest with AES-GCM, and access to user-owned records is scoped by user id.
- No internet service can guarantee absolute security. Sign out of ankify if a device or browser profile is compromised.
Questions or privacy requests
Open an issue in the project repository: github.com/Jiminyang1/ankify/issues