Your privacy is important to us. This Privacy Policy explains how Cardy ("the App") collects, uses, and protects your information.
1. Information We Collect
Account Information: When you sign up, we collect your name, email address, and birthday. Your birthday is used to calculate your card profile using our mathematical card calendar system.
Mood and Emotional Data: If you use the check-in feature, we collect your mood selection, chosen topics, and any free-text you provide. This data reflects your emotional state and is treated as sensitive information. It is used solely to generate your personalized reflection.
Journal Entries: If you use the journaling feature, we collect the text you write. Journal entries are stored with your account and used only to display your personal journal history.
Contacts: If you choose to import birthdays from your contacts, we access contact names and birthdays only. This data is used solely to calculate card profiles for your contacts and is not linked to your identity.
Usage Data: We collect anonymous usage data to improve the App, such as which features are used and general app performance metrics.
2. How We Use Your Information
We use your information to:
- Calculate and display your card profile
- Generate personalized daily card stories and reflections
- Generate personalized AI reflections based on your mood, check-in data, and card profile
- Send you optional push notifications about your daily cards
- Improve the App and develop new features
3. AI-Generated Content
Cardy uses AI (provided by Anthropic) to generate personalized reflections. To create these reflections, we send the following to Anthropic's servers for processing:
- Your name and birthday
- Your card profile (birth cards and daily cards)
- Your mood selection, chosen topics, and free-text from check-ins
This data is sent securely via our servers and is not stored by Anthropic beyond the duration of the request. We do not use your data to train AI models. AI-generated content is for entertainment and personal exploration only.
4. Data Sharing
We do not sell your personal information. We share data only with:
- Supabase (database and authentication provider)
- Anthropic (AI reflection generation, as described in Section 3)
- RevenueCat (subscription management)
- Apple (App Store and Sign In with Apple)
These providers process data solely to deliver their services and are bound by their own privacy policies.
5. Data Storage and Security
Your data is stored securely using Supabase with row-level security policies. We use industry-standard encryption for data in transit and at rest. Check-in and journal data is retained for as long as your account is active. You may delete individual check-ins or journal entries at any time within the App.
6. Your Rights
You can:
- Access and update your profile information in the App settings
- Delete individual check-ins and journal entries within the App
- Delete your account and all associated data from the App settings
- Opt out of push notifications through your device settings
- Request a copy of your data by contacting us
If you are a resident of California, you have additional rights under the CCPA, including the right to know what data we collect, to request deletion, and to opt out of the sale of personal information (we do not sell your data). If you are a resident of the EU/EEA, you have rights under GDPR including access, rectification, erasure, and data portability. To exercise these rights, contact us at support@cardy.today.
7. Children's Privacy
Cardy is not intended for children under 13. We do not knowingly collect information from children under 13. If we learn we have collected data from a child under 13, we will delete it promptly.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes through the App.
9. Contact
If you have questions about this Privacy Policy, please contact us at support@cardy.today.