PRIVACY POLICY

What the app knows about you: nothing.

Cardfold has no accounts, no server and no analytics. Your cards live in local storage on the phone, and this page explains the few moments when anything at all leaves it.

Last updated 7 September 2026Applies to Cardfold 1.0 for Android

In short

No account, no server

There is nothing to sign up for and nowhere for your cards to be uploaded.

Everything stays local

Cards, covers, categories, dates and places sit in the phone's own storage.

Two outside connections

Map tiles while you pick a place, and Google Play when you buy Pro. Nothing else.

No analytics, no ads

No trackers, no advertising SDKs, no profiles, nothing sold to anyone.

01

Who we are

Cardfold is an app for keeping loyalty cards, published on Google Play. There is no company with a support department behind it: it is written and looked after by one developer, and the address at the bottom of this page reaches that person directly.

02

What the app stores, and where

Everything you put into a card stays in the phone's own storage: the shop name, the card number and its code format, the colour or the photo cover you picked, the category, an expiry date if you set one, and — if you pinned the card to a shop — a pair of coordinates. Your settings sit next to them: language, colour scheme, theme.

  • Card data and settings local storage on the device, private to the app

  • Photo covers a folder that belongs to the app, which other apps cannot read

  • Nothing else no copy is made anywhere, and uninstalling takes all of it with it

03

What the app never does

  • No accounts nothing to sign up for, no email address asked for, no profile

  • No analytics no measurement SDK, no crash reporting service, no advertising

  • No sharing your cards are not sold, rented or handed to anyone, in any form

  • No background work with the app closed it does nothing at all, apart from firing a local reminder you asked for

04

Permissions, one by one

Android asks for each of these separately, and the app asks only at the moment it genuinely needs one. Refusing any of them leaves the rest of the app working.

  • Camera reads a barcode when you add a card. The frame is not saved and not sent anywhere. Without the permission you type the number in by hand.

  • Photos asked for only when you pick a cover. The image you choose is copied into the app's own folder; nothing else in your library is visible to the app.

  • Location asked for only if you tie a card to a place. The reading is taken while the card list is open, to put the card of the shop you are standing in on top. The coordinates you saved never leave the device.

  • Notifications used for the reminder about a card that is about to expire. The reminder is scheduled by the phone itself — there is no push server and no device token.

  • Fingerprint or face used by the app lock. The check is done by the operating system, which tells the app yes or no; your biometrics are never seen by it.

05

When the app goes online

Three moments, and they can all be named:

  • The map while you are picking a place for a card, the screen loads the Leaflet library from cdnjs.cloudflare.com and map tiles from tile.openstreetmap.org. Those servers see your IP address and the piece of the map being drawn, as any website would. They never receive your cards, and the requests stop when you close the picker.

  • A purchase buying or restoring Pro goes through Google Play billing. Google takes the payment and tells the app one thing: whether the purchase exists. Payment details are never seen by the app.

  • The store page the review button opens Google Play, where Google's own terms take over.

That is the entire list. Adding, showing, editing and sorting cards work in airplane mode.

06

Your backup file

Export writes your cards, categories and covers into a single JSON file and hands it to the system share sheet. From that moment it is an ordinary document: where it goes and who can open it is entirely your decision. The file is not encrypted, so it deserves the care you would give a photograph of your cards.

07

Purchases

Cardfold Pro is a one-time purchase, processed by Google Play. The app itself keeps a single flag saying that it is unlocked. Restoring the purchase on another device is a question asked of the store, not of us — no record of who bought what exists on our side, because there is no side.

08

Deleting everything

Uninstalling the app removes the cards, the covers and the settings along with it. There is no copy anywhere else and no request to send us. The one thing that outlives the uninstall is the Pro purchase: it belongs to the Google account that made it, and comes back when you restore it.

09

Changes and contact

If this policy changes, the date at the top of the page changes with it, and anything that actually affects you is mentioned in the release notes on Google Play. Questions about privacy — or about anything else in the app — are welcome at the address below.

Questions about this policy

Write in English, Ukrainian or Russian — whichever is easier. A person reads it, usually within a couple of days.

Write to us