Legal

Privacy Policy

Effective · Version 3

Contents
  1. 1. Who we are
  2. 2. The short version
  3. 3. Data stored on your device and in iCloud
  4. 4. Optional account
  5. 5. Purchases and subscriptions
  6. 6. AI screenshot recognition
  7. 7. Device credential
  8. 8. App Store price lookups, exchange rates and service icons
  9. 9. WebDAV and game information lookups
  10. 10. Feedback
  11. 11. Server logs
  12. 12. What we do not do
  13. 13. Retention
  14. 14. Where data is stored and international transfers
  15. 15. Sharing and disclosure
  16. 16. Your rights
  17. 17. Children
  18. 18. Security
  19. 19. Changes to this policy
  20. 20. Contact

1. Who we are

Cardeyra (“Cardeyra”) is an iPhone app for managing memberships and subscriptions. It is operated by “卡栖 Cardeyra 开发者” (the “Cardeyra developer”, “we” or “us”). This policy explains how we handle your information when you use the Cardeyra app and this website. You can reach us through the feedback form on the Support page.

2. The short version

  • Your subscriptions, payment details and wallet data are stored on your device. With iCloud sync (Pro) turned on, they are stored in your own private iCloud database, which the developer cannot access.
  • An account is optional. Without signing in, the core features of the app work as usual.
  • Payments are handled by Apple. We never receive your payment card details.
  • No ads or cross-app tracking.
  • Our server is located in mainland China (Shanghai).

3. Data stored on your device and in iCloud

The subscriptions, amounts, payment methods, wallet balances, tags and custom fields, attached photos and reminder settings you enter in the app are stored on your device. With iCloud sync (Pro) turned on, this data is synced to your own private iCloud database and protected by your Apple Account. The developer cannot access, read or back up this data. You can also use WebDAV backup (Pro); backup files are sent directly to a service you configure yourself (see section 9).

4. Optional account

You may sign in with an account (with Apple, Google, an email verification code, or a mainland China phone number, depending on the App Store region) to sync your Pro entitlement across devices and platforms. After you sign in, our server stores:

  • an account identifier, your email address (which may be a private relay address provided by Apple) and an optional name;
  • sign-in device information: platform, model, system version and app version;
  • sign-in times.

How each sign-in method works:

  • Apple: completed in Apple’s sign-in sheet. We receive the account identifier, the email address (possibly a private relay address) and the name you choose to share.
  • Google: completed on Google’s page, in the system’s web sign-in sheet. Your Google password goes only to Google and never reaches us. We receive the account identifier, email address and name that Google provides.
  • Email verification code: we send a one-time code to the address you enter and keep that address. The email is delivered by a third-party email delivery provider, which receives your address and the message solely to deliver it and whose servers may be outside mainland China. The code is valid for 10 minutes and we keep only a hash of it. We never store a password. The same applies when you delete your account on the website with an email code.

You can delete your account at any time in the app (Settings → Account → Delete Account) or, for an email account, on the delete account page. After deletion we remove the account identifier, email, name, phone number, sign-in device records and sessions; purchase records are handled as described in section 5.

Phone number sign-in

Phone sign-in supports mainland China +86 numbers. SMS codes are sent and checked by Alibaba Cloud Phone Number Verification Service; it receives your number and the verification code you submit. Codes expire after 5 minutes. Cardeyra does not store the codes. After verification, we store the full number as an account identifier on our server and show a masked number in the app. Deleting your account in the app removes the number and phone identity. A phone account is not automatically merged with accounts using other sign-in methods.

One-tap sign-in uses Alibaba Cloud’s number authentication SDK and your mobile carrier (China Mobile, China Unicom or China Telecom). Before initializing the SDK, we ask for your consent to the privacy policies; you can choose SMS instead. The SDK processes IP address, network type, device manufacturer/model and operating system to authenticate the mobile number. After you authorize the carrier page, an authentication token is sent to our server and exchanged with Alibaba Cloud for your number. The SDK’s bundled privacy manifest also declares other data for analytics, not linked to your identity and not used for tracking. See the Alibaba Cloud Phone Number Verification privacy policy and the carrier agreement on the authorization page for their processing rules.

For rate limits and abuse prevention, we retain keyed hashes of the SMS number, IP address and installation identifier for about two days, without storing plaintext values in those records. The one-tap daily budget stores only a date and call count; old counts are removed after about two days.

5. Purchases and subscriptions

Purchases of Pro (lifetime or yearly) are handled by Apple, and we do not receive your payment card details. When you are signed in, our server verifies and stores your App Store transaction records: transaction number, product, purchase date, expiry date, storefront region, price and currency, and refund status. We use them to restore and sync your Pro entitlement. After you delete your account, transaction records are unlinked from it and kept only for accounting and compliance.

6. AI screenshot recognition

Screenshot recognition uses on-device OCR by default, and images are not uploaded. Only when you tap AI recognition is the selected image sent to our server and forwarded to the model provider currently configured (one of DeepSeek, MiniMax, Alibaba Cloud Qwen or ByteDance Volcano Engine Doubao) for recognition; the result is returned to your device. The server does not store the image or the recognized text. It records only the model used, the status of the call, duration, token usage and a device identifier, for quota accounting and abuse prevention. Model providers process the content they receive under their own rules, so please do not include sensitive information in screenshots that you do not want processed.

7. Device credential

On first launch the app generates a random installation credential and stores it in the system Keychain. Our server stores only its hash, to identify usage quotas and prevent abuse. It contains no personal information and is not used for cross-app tracking.

8. App Store price lookups, exchange rates and service icons

  • Price lookups: the app sends an app ID and a storefront region to our server, which reads Apple's public pages and returns the result. No personal information is included.
  • Exchange rates: the app fetches public rates directly from open.er-api.com and api.frankfurter.app. Requests contain no personal information, though those services may see your IP address.
  • Service icons: loaded from Apple's public icon addresses or from our server.

9. WebDAV and game information lookups

If you use WebDAV backup or configure a game information lookup service, the app connects directly to the service you configured. The credentials are stored only in your device's Keychain and are never sent to us. These services are run by third parties you choose, and their privacy rules are not governed by this policy.

10. Feedback

When you submit feedback through the website or the app, we receive the message you write and your (optional) email address, to reply to you and improve the product.

11. Server logs

Our server records IP addresses and request times for security and rate limiting. Logs are rotated and deleted after about 14 days.

The IP address recorded in a sign-in session is also cleared about 14 days after that sign-in. Continued account use does not extend its retention. Clearing the IP address does not sign you out.

12. What we do not do

  • We show no ads and do not sell your information;
  • We do not track you across apps or websites;
  • We include no advertising SDKs. The phone authentication SDK and its data processing are described in section 4.

13. Retention

InformationRetention
Data on your device and in iCloudControlled by you: clearing it in the app or deleting the app removes the on-device data; iCloud data is managed by you in iCloud
Account informationWhile the account exists; removed when you delete the account
Transaction recordsUnlinked from your account when it is deleted, and kept for as long as accounting and compliance require
AI recognition usage recordsKept only as long as needed for statistics and abuse prevention
FeedbackKept for as long as necessary after it is handled; the email address in feedback is deleted when you delete your account
Server logsAbout 14 days
IP address in a sign-in sessionAbout 14 days from that sign-in

14. Where data is stored and international transfers

Our server is located in mainland China (Shanghai). If you are outside mainland China, data is transferred to and processed in mainland China when you use features that involve the server (signing in, purchase verification, AI recognition, price lookups, feedback). The basis and safeguards are:

  • these transfers are necessary to provide the features you choose to use, or are based on your consent; if you do not use them, the core features of the app (on-device data, iCloud sync) are unaffected;
  • transfers use HTTPS encryption, and sensitive information such as keys is stored encrypted on the server;
  • we process only the minimum data needed for the feature, store only a hash of the device credential, and restrict internal access;
  • you can withdraw consent at any time (stop using the feature or delete your account) and exercise the rights in section 16.

In addition, when you use an email verification code (to sign in, or to delete your account on the website), the email address you enter is sent to an email delivery provider located outside mainland China (currently Resend), solely to deliver the code email to you. By entering your address and requesting a code you consent to this transfer; it does not happen if you do not use email codes.

15. Sharing and disclosure

We do not disclose your information to third parties except: to Apple (sign-in and purchases are handled by Apple); to Google when you choose Google sign-in (Google authenticates you); to our email delivery provider when you use an email code to sign in or to delete your account on the website (currently Resend, used only to deliver the code email); to Alibaba Cloud and your mobile carrier when you choose phone sign-in, as described in section 4; to the model provider when you choose AI recognition; to comply with laws or respond to lawful requests from authorities; and to protect our rights or those of others (for example, to prevent fraud and abuse).

16. Your rights

You have the right to access, correct, export and delete your personal information and to withdraw consent, and you may also complain or object to particular processing. Contact us through the feedback form on the Support page (choose “Privacy & data”) and we will reply within 15 working days. You can delete your account at any time in the app or on this website.

Where EU or UK data protection law applies, our legal bases are: performance of a contract (providing the features you use), your consent (account sign-in, AI recognition) and legitimate interests (security and abuse prevention). You also have the right to lodge a complaint with your local data protection authority.

17. Children

Cardeyra is intended for adults. Users under 14 (mainland China) or under 13 (elsewhere) should use it only with the consent and supervision of a parent or guardian, who should read this policy. If we learn that we have collected a child's information without parental consent, we will delete it promptly.

18. Security

We use reasonable technical and organizational measures to protect data, including encryption in transit, encrypted storage of sensitive information and access controls. No system can guarantee absolute security.

19. Changes to this policy

We may update this policy. Material changes will be announced prominently on the website and the effective date will be updated.

20. Contact

Contact the “卡栖 Cardeyra 开发者” through the feedback form on the Support page.


Terms of Use Contact us