Security

Your data is in trusted hands.

Last updated: July 2026

Capri Cards does not operate its own data servers. The app is built on base44's platform, AI is powered by OpenAI's API, account sign-in is handled directly by Google, Microsoft, Apple, and other identity providers, audio is hosted on Cloudflare, and payments are processed through Stripe. Each of these providers maintains rigorous, independently audited security programs - so the infrastructure protecting your data is held to enterprise-grade standards.

App Platform
base44

Capri Cards is built on base44, an AI application platform that handles our backend infrastructure, database, and authentication. Your notes, flashcards, quizzes, and account data all live within base44's environment.

base44 is SOC 2 Type II and ISO 27001 certified, and maintains compliance with GDPR. Their platform uses row-level security to ensure each user can only access their own data, and payment data is never stored within their environment. Authentication is handled via Google SSO or email with anti-bot controls and email verification.

base44 undergoes regular third-party penetration testing based on OWASP methodologies, and operates a bug bounty program open to independent security researchers.

SOC 2 Type II ISO 27001 GDPR Compliant
AI Processing
OpenAI

Capri Cards uses OpenAI's API to power its AI features, including generating notes, flashcards, quiz questions, and audio lecture scripts. We use the GPT-4o mini model, a fast and efficient model well-suited for structured content generation.

When you upload material, it is sent to OpenAI's API to generate your study content. OpenAI's API data usage policy prohibits the use of API inputs to train their models. Content you submit is not stored by OpenAI beyond the time required to process your request, and it is never used to improve OpenAI's models or shared with other users.

OpenAI maintains SOC 2 Type II compliance and enterprise-grade data security practices. You can review their commitments at openai.com/security.

GPT-4o mini SOC 2 Type II API inputs not used for training
Account Authentication
Google, Microsoft, Apple & Others

When you sign in to Capri Cards using a social login, your authentication is handled directly and entirely by the provider you choose - Google, Microsoft, Apple, or another supported identity provider. Capri Cards never sees, handles, or stores your password.

These providers verify your identity using the OAuth 2.0 standard and return a secure token that grants you access to your account. The security of your login - including two-factor authentication, suspicious activity detection, and account recovery - is managed by the provider you trust and already use.

OAuth 2.0 Password never stored by Capri Cards Google · Microsoft · Apple
AI Safety
Content Filtering & Student Guidelines

Our AI is optimized to help you learn and nothing else. Before study materials are processed, they pass through a content screening step that automatically blocks material related to violence, self-harm, hate speech, or sexually explicit content.

The AI is programmed to ignore off-topic or inappropriate prompts and stay focused exclusively on generating accurate, high-quality study materials. If content you did not expect appears in a created set, the system is designed to identify and block it to keep the study environment clean and on track.

Proactive content filtering Designed for students Focused on study content only
Privacy Feature
Share Safety Scan

When a student initiates a card set share, Capri Cards runs an AI safety scan across all card content before a Share Code is created. This scan is specifically designed to detect personal contact information that could be used to identify or reach a real person outside of an educational context.

The scan flags phone numbers, email addresses, home addresses, and social media handles, including formats that are deliberately obfuscated, such as phonetically written numbers, characters substituted with lookalikes, content split across multiple cards, and other techniques commonly used to evade keyword-based filters. If anything is flagged, the student sees exactly which cards triggered the scan and why. The share cannot proceed until flagged content is removed.

Share Codes are time-limited (30 minutes) and resolve server-side to a card set ID. No personal account information is embedded in or derivable from the code. Recipients receive an independent copy of the card set and notes only. Audio lectures are not included. No persistent connection is stored between the sharing account and any recipient account.

AI PII detection before every share Obfuscation-aware scanning No account connections stored
Audio Storage
Cloudflare

AI-generated audio lectures are hosted on Cloudflare's global network. Cloudflare is one of the world's largest cloud infrastructure providers, serving a significant portion of internet traffic with industry-leading security and reliability.

Audio files are served over HTTPS and are accessible only to the authenticated user who created them. Cloudflare's infrastructure includes DDoS protection, encryption in transit, and continuous security monitoring.

HTTPS Encryption DDoS Protection Global CDN
Payment Processing
Stripe

All subscription payments are processed by Stripe, a PCI DSS Level 1 certified payment provider. Capri Cards never sees, handles, or stores your card number, CVV, or any other payment details. That information goes directly to Stripe and stays there.

Stripe is trusted by millions of businesses worldwide and maintains the highest level of certification in the payment card industry. All payment data is encrypted in transit and at rest within Stripe's environment.

PCI DSS Level 1 Payment data never stored by Capri Cards
Our Commitments
What Capri Cards does

Your flashcards, notes, and classes are private to you. We do not sell your data or your study materials to anyone, and we do not store payment card information of any kind. Your uploaded content is used solely to generate your study materials and is never used to train AI models.

  • Full Control: Download your data or delete your account at any time. When you choose to delete your account, all associated data is permanently and cleanly removed.
  • Secure Sessions: Your account uses industry-standard authentication with sessions that automatically sign you out after a period of inactivity.
  • Encrypted Connections: All traffic between you and the app is encrypted in transit, keeping your interactions private.
  • Strict Access Control: Our systems are built so that you can only ever access your data. No user can access another user's study sets, notes, or account information.

For full details on what we collect and how we use it, see our Privacy Policy.