Privacy Policy
Last updated: August 2026
Information We Collect
- Email address used for authentication
- Basic profile info from OAuth providers
- Feedback submitted by users
- Device information (IP address, time zone, and language settings)
- App usage data (last active timestamp) for notification delivery
- Subscription purchase history and the Cardly user ID associated with it
How We Use Your Data
- Authenticating and managing accounts
- Providing and improving Cardly features
- Responding to feedback and support requests
- Sending important updates and notifications
Third-Party Services
- Supabase for authentication and data storage
- OAuth providers such as Discord, GitHub and Google for authentication only
- OneSignal for push notifications
- Polar for website payment processing and subscription management
- Apple for iOS payment processing and subscription management
- RevenueCat for validating mobile purchases, subscription access, and subscription analytics
Payment information is processed securely by Polar or Apple. Cardly and RevenueCat receive subscription and purchase status, but Cardly does not store or have access to your full payment-card details.
Cookies & Storage
Cardly uses cookies and local storage to maintain login sessions and preferences. These are required for core functionality and are not used for advertising or tracking.
Data Retention
We retain personal data only as long as necessary to operate the service. Account data is kept until the account is deleted.
Sharing & Security
We do not sell personal data. Information is shared only with services required to operate Cardly or when legally required.
Policy Updates
This Privacy Policy may be updated from time to time. Changes will be posted on this page.
Data Deletion
You may request deletion of your account or data by contacting us.
Contact
Email: mistake02.fatal@gmail.com