Privacy Policy
MAi Cards is your personal second memory: you deliberately save fragments of life as memory cards, AI helps structure them, and you get them back by browsing, searching, or asking in your own words. This policy explains what we collect, why, and the choices you have.
1. Who we are
The Service is operated by RYS AI under the brand MAi Cards (mai-cards.com). For privacy requests, email support@mai-cards.com or see Support.
We design MAi Cards as deliberate memory — what you choose to save — not ambient “record everything” surveillance.
2. Information we collect
2.1 Account & identity
- Guest use. You may enter without a full sign-in. We still create a server-side guest identity so your cards and chats can sync. Guests are not password accounts; if the device session is lost before you “save” a real sign-in, that guest data may become hard to recover.
- Signed-in use. Email one-time codes (no passwords), Google Sign-In, and Sign in with Apple. We process identifiers such as email address, provider subject IDs, and display name/avatar when the provider supplies them. Sign-in methods that share a verified email are linked to one account.
- Sessions. Auth sessions are stored so you stay signed in while active (about 30 days of inactivity ends a session; your data remains until you delete it).
2.2 Memory content you create
- Memory cards — the text you capture (title, body, tags), photos you deliberately attach, selected photo regions, version history (including AI-refined versions), trash state, and related metadata (timestamps, language cues for structuring).
- Chat with your memory — conversation threads, messages you send, assistant replies, and citation links to cards the answer used.
- Voice input. When you use hold-to-speak or chat dictation, the microphone captures audio that is streamed for speech-to-text. See §4 for how that audio is handled.
- Plan / entitlement. Whether you are on Free or VIP, and store purchase / restore signals needed to unlock paid AI allowance.
Cards may begin as text or photos. Full selected photos are stored with the card; a selected region guides text extraction but does not discard the rest of the photo. Voice is used to talk to your memory (chat).
2.3 Technical & usage data
- Device and app information needed to run the Service (app version, platform, locale/language preference, basic diagnostics).
- Security and reliability signals: rate limits, abuse prevention, failed request patterns, and operational logs.
- AI usage metering (tokens consumed, model route, success/failure) so we can apply free/VIP daily budgets and keep the product sustainable — not for advertising profiles.
- On-device aligned card cache. Current cards and opaque synchronization / result-receipt metadata may be kept on the device for fast browsing and word search. They are bound to the exact signed-in identity and session. Logging out, switching account, or linking a guest into a real account clears or replaces the prior local identity’s cache; this does not delete its server data.
- Direct Search history. Searches you intentionally submit (or use to open a result) may be kept only on that device, newest-first, deduplicated, and capped at 10. This history is device-bound, excluded from backup / device transfer, and is never synced to our servers. You can clear it in Search; logout, account switch, and guest-to-real linking clear it for the prior identity.
- Content-free Direct Search operations data. We may retain provider cost/attempt status, monotonic Search-session timing and outcome buckets, request disposition, and at most one verified result-open success. These records and their retention contain no query text, selected tags, card/result content, card/version/result identifiers, or result receipts.
2.4 Support
If you email us, we receive the content of your message and any contact details you include.
3. How we use information
- Provide the product — store and sync your cards and chats; show only your data (every query is scoped to your account).
- AI structuring — after you save a card, models may generate a title, tidied body, and tags as a new version, without erasing what you originally wrote.
- Recall & chat — embeddings and search over your cards so you can find memories by meaning; the assistant answers questions about your saved life from your cards and shows citations. Casual conversation may use general knowledge but is not presented as a saved memory.
- Direct Card Search — find and open your current cards without generating an answer. Exact word search can run from the latest aligned device cache; when meaning search is available, the query is sent transiently through our server to the configured embedding provider and used to rank your own current cards. Query text and selected tags are not written to Direct Search history or analytics on our servers.
- Speech recognition — turn spoken words into text so you can talk to your memory.
- Accounts, security, and quotas — authenticate you, prevent abuse, enforce free-tier daily AI budgets and VIP allowances.
- Payments — process and restore in-app subscriptions via the app stores and our entitlement partner.
- Support and legal — respond to requests and meet lawful obligations.
We do not sell your personal information. We do not use your memory cards to train public third-party foundation models for the general public. Capture (saving a card) does not wait on AI and is never blocked by the AI quota.
4. Voice, AI, and third-party processors
To run MAi Cards we use infrastructure and model providers. Important ones today include:
- Application hosting & database — cloud app hosting and managed PostgreSQL for accounts, cards, chats, and entitlements (authoritative copy of your memory is on the server).
- Cache / rate limiting — shared Redis-style infrastructure for sessions, quotas, and abuse protection.
-
Speech-to-text: Alibaba Cloud (DashScope). Voice
audio is relayed through our servers to DashScope for transcription
(e.g. Paraformer). Product rules:
- Audio is relayed for recognition, not kept as a permanent voice library in MAi Cards.
- Transcript text is not written to operational logs.
- Before your first voice session, the app shows a consent sheet that names this processor and links here. Consent is remembered on the device. You can stop voice use by turning off the microphone permission in system Settings.
- AI text models & embeddings (e.g. via DashScope / Qwen family and config-routed models) — structure cards, embed card text for semantic recall, transiently embed a Direct Search meaning query, extract text from card photos, and power chat. Model choice is configuration-driven and may change for quality or cost without changing this policy’s core purposes.
- Sign-in providers — Apple, Google, and email delivery for one-time codes.
- Payments — Apple App Store / Google Play and RevenueCat for mobile subscriptions and restore. Web/Stripe billing is not part of the current mobile launch path.
These processors receive only what is needed for their function, under their terms and our configuration. They are not a free pass for others to browse your memory: the product’s rule is that memory answers about your life are built from your cards, with citations where applicable.
5. Ownership isolation
Every card and conversation belongs to exactly one account (guest or signed-in). The Service is designed so one user cannot query another user’s memory. That isolation is a core product rule, not a marketing slogan.
6. Where data is stored & international users
We use managed cloud providers. Data may be processed in regions where those providers operate. The product’s launch focus is global (including English and overseas Chinese users); mainland China regulatory filings are a later, deliberate phase. If you are in the EEA, UK, or similar jurisdictions, international transfers may apply; contact us for details about your rights.
7. Retention
- Account, cards, version history, and chats are kept while your account is active so the product can work as long-term memory.
- Cards you delete go to Trash first (recoverable); “Delete forever” is the irreversible step. Automatic purge of old trash may be added later.
- Voice audio is not retained as a permanent archive (see §4).
- AI metering and security logs are kept as needed for billing integrity, abuse prevention, and debugging, then reduced.
- Direct Search session / cost / verified-open records are content-free as described in §2.3. An unfinished Search session is automatically finalized as interrupted after 24 hours; retaining its operational record does not add query, tag, card, result, or receipt content.
- Device-only Direct Search history remains until you clear it, the app clears the prior exact identity on logout/account change/link, or the app is removed. It is not backed up or synced.
- After full account deletion (in-app when available, or via support), we delete or de-identify personal content within a reasonable period, except limited records we must keep for law, security, fraud, or accounting (e.g. store transaction references).
8. Your choices & rights
- Edit cards; move them to Trash; delete forever from Trash.
- Delete individual chat conversations in the app.
- Upgrade a guest by signing in so you can recover the account later.
- Sign out (Settings) if you have a real sign-in method.
- Revoke microphone permission to stop voice features.
- Manage Google / Apple account permissions with those providers.
- Cancel or manage VIP in your App Store / Play account settings; use Restore purchases in the app if you reinstall.
- Request access, correction, export, or deletion of personal data by emailing support@mai-cards.com (and via in-app account deletion when that control ships).
Depending on where you live, you may have rights under GDPR, UK GDPR, CCPA/CPRA, or similar laws. Contact us to exercise them. We will not discriminate against you for exercising privacy rights.
9. Children
MAi Cards is not directed to children under 13 (or the minimum digital consent age in your country). We do not knowingly collect personal information from children. If you believe a child has used the Service and provided personal data, contact us and we will take appropriate steps.
10. Security
We use industry-standard measures such as HTTPS, authenticated sessions, and user-scoped data access. No method of transmission or storage is perfect. Protect your device with a passcode and treat email/Apple/Google access as the keys to your memory.
11. No advertising tracking by us for ads
The product’s purpose is your memory, not ad targeting. We do not run a third-party advertising network inside the app for selling your card content. App store platforms may have their own analytics or purchase tooling under their policies.
12. Changes
We may update this policy as features ship (for example image capture or new processors). We will post the new version here and update the “Last updated” date. Material changes may also be highlighted in the app when appropriate.
13. Contact
Privacy questions: support@mai-cards.com · Support · Terms of Use.
This policy is written to match how MAi Cards actually works today (product rules in our internal product-spec). It is provided for transparency and store compliance; it is not formal legal advice. Have counsel review for your entity, fundraising, or regulated markets.