Site
Sign in to your flash-card account.
Enter your username and password.
Sign in to your flash-card account.
Enter your username and password.
Enter the 8-digit PIN sent to your email.
Enter your username or verified email address. If the account is eligible, an 8-digit PIN will be emailed to you.
Welcome, . Replace your temporary password before continuing.
Create, organize, and study your sets. Folder names stay protected with your study data.
Readable exports are generated in your browser. Protected backups keep the encrypted representation stored by the server.
Import CSV, JSON, or a protected backup. JSON can be uploaded as a file or pasted directly.
Accepts a single set object, an array of set objects, a portable JSON export, or a protected backup JSON payload. Imported data is validated before anything is stored.
Downloads the encrypted server representation. It does not contain a decryption key because the server does not possess that key.
Add or change the email used for verification and password reset. Changing it requires your current password and a new verification PIN.
Verify your account email to make it eligible for email password reset when that feature is enabled.
Revoke sessions you no longer recognize.
Download the server-held records associated with your account. This is separate from readable card exports and is available once every 28 days.
Permanently deletes your account, sessions, encrypted study sets, and encrypted folder organization. This cannot be undone.
Space / ↑ / ↓ flip · ← / → move cards outside Challenge mode
User access/device metadata and administrative activity are available here. Study payloads remain stored in their protected server representation; the administrator interface does not decrypt card content.
Resetting a user password deletes that user's saved sets and folder organization because the administrator cannot re-encrypt them under the new password.
Changing these settings requires administrator password re-verification. Self-registration is disabled by default.
SMTP credentials are configured only in the server .env file and are never shown here.
These editors replace the complete public documents. The built-in defaults are shown initially. Supported placeholders: {{SITE_NAME}}, {{ABUSE_EMAIL}}, {{ACCESS_RETENTION_DAYS}}, {{AUDIT_RETENTION_DAYS}}, {{ACCOUNT_EXPORT_COOLDOWN_DAYS}}, {{LEGAL_UPDATED_AT}}.
Sensitive administrative actions, imports/exports, configuration changes, and user administration are recorded without passwords, keys, card plaintext, session bearer tokens, or CSRF secrets.
Folder names are encrypted in your browser along with your study organization.
Browse only one folder level at a time, then move this set into the location shown below.
Browse to the new parent for this folder. FlashVault hides invalid destinations that would create a cycle.
Choose which columns contain the front and back of each card. Review the preview before importing.