Effective date: 28 September 2026
Controller: Kaperkunde
KVK number: 42061326
Address: Prof. E.M. Meijerslaan 1, Amstelveen, The Netherlands
Website: https://studyguild.my
Support: support@kaperkun.de
Abuse reports: abuse@kaperkun.de
Privacy/GDPR requests: privacy@kaperkun.de
Legal notices: legal@kaperkun.de
Study Guild is a free, shared flashcard community: members pool cards in public guilds and each trains their own stack of them. This notice says plainly what we keep about you, what it is for, who else ever sees it, and how to take it with you or have it deleted.
It sits on top of the Kaperkunde Privacy Policy, which is the company-wide document and covers your rights, how to complain, international transfers, security, and the promises that hold across everything Kaperkunde runs. This notice adds what is particular to Study Guild. It never takes away anything the company policy gives you.
Who you are dealing with
Study Guild is built and run by Kaperkunde, the independent software business of Kevin Lohman, registered in the Netherlands (KVK 42061326), at Prof. E.M. Meijerslaan 1, Amstelveen. Kaperkunde is the data controller for everything described here under the General Data Protection Regulation.
Anything on this page, and any request about your data, goes to privacy@kaperkun.de. A person reads it. Support goes to support@kaperkun.de, and a card or a guild that should not be there to abuse@kaperkun.de.
Guilds are public
This is the one thing to know before anything else. A guild is a shared deck on the open web.
Its name, subject and description, and every card in it — question, answer, pictures and links
— can be read by anyone, signed in or not. Guild pages are listed in the site's sitemap,
described to search engines in their structured data, summarised for AI crawlers at
/llms.txt, and reachable by any assistant a member has connected. Once a card is in a guild
it is published in that sense, and it stays published: the
terms of use say when a card becomes the
guild's rather than yours.
Beside what you add stands your public name: your username if you have set one, otherwise your first name and the initial of your last name ("Kevin L."). It shows on the cards you wrote or improved, among a guild's top contributors, on the public contributor leaderboard (every member with at least one card is on it), and on the page a visitor lands on from your invite link. Your full name and your email address are shown to nobody but you. If you would rather not appear under your own first name, set a username in Settings.
So write into a guild only what you are happy to have read by strangers: no personal details, yours or anybody else's, and nothing you need to keep private. What is not public is your own training — which guilds you are in, how each card is doing for you, your streak and your sessions — and your account. Those are yours alone.
What we hold
- Your account. The email address you signed up with, your name, a username if you chose one, and your password — stored hashed, so nobody at Kaperkunde can read it. Each sign-in session records the IP address and browser it was started from. Emailed sign-in links and password-reset links are kept until they expire or are used.
- Your settings. Your time zone, which your browser reports once so that "today" follows your clock; your daily goal; whether the daily reminder is on and at what time; and the colour you chose for each guild.
- What you add to guilds. The guilds you founded; every card and every wording of a card you wrote, with any picture or link on it; your votes; and a log of the cards you added next to a card that asked nearly the same thing, and whether you said yours asked something different. That log exists so we can review the duplicate check and tune it, not to judge you. The pictures you upload are counted, too, so that nobody can flood the site.
- Your training. Your stacks and their settings; each card's rank, due date and history in your stack; every answer you give (which card, right or wrong, the rank it moved to, the XP, and your local day); your training sessions and their results; and the totals they add up to — Guild XP, level, streak, best streak, contributor score, and the last day you trained.
- Invitations. Your invite link for each guild, and who joined through whose link. Both members can see that much: you see how many joined through yours, and the guild page tells a visitor who invited them.
- Reminders. The day the last reminder went out to you, so you never get two.
- Assistants you connect. How the app described itself when it asked for access, what you allowed it to do and when, and the access tokens it holds — stored hashed, so a copy of our database would not let anyone act as you.
- Ordinary server logs. Requests to the site, with IP address and timestamp, kept briefly so we can fix things that break and stop people abusing the service.
That is the whole list. There is no analytics, no advertising, no tracking pixel and no profiling of you anywhere in Study Guild. The only cookies we set are the ones that keep you signed in and, if you open a member's invite link, one that remembers the invitation for thirty days so that joining the guild credits the member who invited you — which is why you have never been asked to dismiss a cookie banner here.
Pictures on cards
A picture you put on a card is cropped and re-encoded before it is stored, and every piece of metadata in the file — the camera, the date, the place it was taken — is dropped in the process. What is kept is the picture itself, and it is public: a card's picture can be seen by anyone who can see the card. Once a picture is on a card it does not change; editing the card points it at a new picture, and the old one stays with the earlier wording. A picture uploaded for a card that was never saved is deleted after a day.
Rate limits
To keep one runaway script from spoiling the site for everyone, we count requests to the sign-in pages by IP address, and cards, guilds and pictures by member, over the last minute or hour. These counts live in memory and are gone as soon as the window passes; they are never written down.
Why we hold it
Your account, the guilds you are in and the cards you add are there because we cannot run the service you asked for without them — that is the contract between us. Your training history is the substance of that service: it is how a card knows its rank and when it is due. Your votes and edits are shared work, and the guild needs to know who did what. The logs, the rate limits and the duplicate log rest on our legitimate interest in keeping the service up, secure and worth using.
We email you about your account (a welcome when you sign up, sign-in links, password resets) and, while training reminders are on, once a day at the time you chose — but only on days you have cards due and have not met your goal. Reminders are on when you join, at 20:00 in your zone, because a daily habit is the point; the welcome email says so, and every reminder carries a link that turns them off in one click, as does Settings. We send no marketing mail.
How long
| What | How long |
|---|---|
| Your account, settings and training history | Until you ask us to delete the account |
| Cards, guilds and edits you contributed | As long as the guild. Once other members use a card it belongs to the guild (terms); deleting your account takes your name off it, not the card |
| A card you delete yourself | Gone from the guild at once. The row stays hidden, so the guild's history of edits and duplicate decisions still adds up, and is erased with your account |
| A picture on a card | As long as any wording of the card points at it |
| A picture uploaded but never put on a card | One day |
| Sign-in sessions | Thirty days from their last use; signing out ends one, a password reset ends all the others |
| Emailed sign-in links | Ten minutes |
| Password-reset links | One hour |
| The invitation cookie | Thirty days, or until you join the guild it was for |
| Who joined through whose invite link | As long as both accounts |
| An assistant's access | Until you disconnect it. Its access tokens last an hour and its refresh tokens sixty days; disconnecting stops it at once, whatever it still holds |
| Server logs | Thirty days |
Everything else goes when the account does.
Who else ever sees it
We do not sell your data, share it, rent it, give it away, or hand it to advertisers, data brokers or AI training sets.
Everyone, for what you put in a guild. Guilds are public, as said above, and the open web is the open web: search engines and other crawlers read public pages, as they can any page on the internet. That is publication, not sharing on our part — nothing about your account travels with a card, and your training and your email never leave the database.
One processor for the servers. Study Guild runs on servers rented from Hetzner, in the European Union. Everything else the service is made of — the database, the pictures, the mail server that sends your sign-in links and reminders — is Kaperkunde's own software running on those servers. No analytics service, no content delivery network, no mail provider.
One processor for the duplicate check. A guild asks each question once, and telling "What is the capital of France?" from "Which city is France's capital?" takes an understanding of meaning that we buy in. Whenever you add or edit a card, whether or not it is then saved, its text — the question and the answer, with formatting removed — is sent to Voyage AI, which turns it into a list of numbers we keep and compare. The same goes for a guild's name when it is founded and for a search an assistant runs on your behalf. Nothing about you goes with it: no name, no email, no account, and never a picture. Voyage AI is in the United States, so this is a transfer outside the EEA under the safeguards §6 of the Privacy Policy describes, and it processes the text under its data processing agreement. Its terms would let it keep what it receives to train its own models; we have opted out of that, so it deletes each text as soon as it has computed the numbers.
Assistants you connect. An assistant you allow into your account acts as you, within the limits you set; see the next section.
The full list, and what each one is for, is in the Study Guild subprocessor list. If it ever has to change, that list and this page will say so, and who they are, before it does.
The exception every service has to name: if we are ever legally required to hand something over, we will, and we will tell you unless we are forbidden to.
An assistant you connect
Study Guild can be added to Claude, or to any other assistant that speaks the Model Context Protocol, as a connector. Doing so is your choice, made on a page that shows exactly what the app asks for before anything is shared: reading guilds, cards and your stacks, and — only if you tick it — adding and improving cards, founding guilds, uploading pictures, voting and deleting your own cards. The connection is a token held by that app, not a copy of your password, and you can take it back at any time under Settings → Connected apps. Disconnecting takes effect on the app's very next request.
What that assistant reads, it reads as you, and what it does with it is between you and whoever makes it — it is your assistant, not ours, and not a Kaperkunde subprocessor. What it adds to a guild is added in your name, exactly as if you had typed it.
Kaperkunde does not train anything on your cards, your training or your searches, and no assistant changes that.
What you add is the guild's, and what stays yours
You keep every right you have in the cards and pictures you make. What changes when you add one to a guild is that the guild gets to use it: to show it, to hold it in every member's stack, to vote on it and to improve its wording. A card nobody else has voted up is still yours to delete. Once others have taken it up it stays with the guild, under your public name, or under "a former member" once your account is gone. The terms of use set this out in full. Your training — how each card is doing for you — is never anybody's but yours.
Taking it with you, or taking it down
Email privacy@kaperkun.de and we will send you a machine-readable copy of your account, the cards and guilds you contributed and your whole training history, or delete your account, whichever you ask for. Either way you hear back within 30 days, and normally a great deal sooner than that. This is how Kaperkunde's company-wide export promise is kept here — see §4.1 of the Privacy Policy — until the export has a button of its own in Settings.
Deleting your account removes it, your settings, your sessions, your connected assistants, your votes and your entire training history. Cards and guilds you contributed that other members have taken up stay with their guilds, credited to "a former member"; a card of yours that nobody else has studied or voted on goes with you. Deleted data may remain in backups until those expire or are overwritten.
Your rights, and who to complain to
These are the same across everything Kaperkunde runs and are set out in §9 and §10 of the Privacy Policy: access, correction, erasure, restriction, objection, portability, withdrawing consent, and a complaint to the Dutch Autoriteit Persoonsgegevens if we get it wrong. We will not make you jump through hoops for any of it.
You need to be 16 or over to use Study Guild, as §11 of the Privacy Policy sets out for all our services.
Changes to this notice
If anything here changes in a way that matters to you, we will tell you rather than quietly editing the page. The effective date at the top shows the current version, and every version is kept in the public repository this notice is published from.
The terms of use say what we each agree to.
