cardmi

Draft: this policy is not final yet and may change before cardmi launches.

Privacy Policy

Last updated: October 8, 2026

The short version:

Contents

  1. Who we are
  2. What we collect
  3. What stays on your phone
  4. Your photos and AI styles
  5. How we use your information
  6. Who can see what
  7. Companies that help us run cardmi
  8. Other times we share information
  9. How long we keep it
  10. Your choices and controls
  11. Your privacy rights
  12. California residents
  13. If you live outside the US
  14. Children and teens
  15. Security
  16. Changes to this policy
  17. Contact

1. Who we are

cardmi is an app and website (cardmi.app) that turns photos into collectible trading cards. The operator of cardmi ("we", "us") is responsible for your information. This policy covers the cardmi iPhone app and cardmi.app. Our Terms of Service also apply.

2. What we collect

Information you give us

Information collected automatically

What we don't collect

We don't collect your contacts, your location, your photo library (cardmi only uses photos you pick, and only adds to Photos when you save), microphone audio, health information, or payment card details. We don't collect biometric identifiers: no face recognition, face matching, face geometry or face templates.

3. What stays on your phone

4. Your photos and AI styles

5. How we use your information

We don't use your information for advertising, we don't build advertising profiles, and we don't use your photos or cards to train AI models. We don't make decisions about you based solely on automated processing that have legal or similarly significant effects; automatic safety checks can hide a card, and you can ask us to review that.

6. Who can see what

7. Companies that help us run cardmi

These companies process information for us, under contracts that let them use it only to provide their service to us (and, for some, to keep their service secure and meet legal obligations):

Company What they do for cardmi Information involved
Google (Firebase and Google Cloud), United States Sign-in, database, file storage, server code, push notifications, analytics, crash reports, App Check, remote settings, website hosting Account, profile, cards, game records, social activity, reports, device and security information, push token, analytics and crash data, logs
OpenAI, United States Drawing AI styles; the safety check on shared cards The photo cut-out for a style; card pictures being shared with friends
RevenueCat, United States Processing and checking App Store purchases Your user ID and purchase history
Apple App Store payments and refunds, Sign in with Apple, push notification delivery, device attestation Purchases, sign-in, push token, device checks
Google Sign-In Signing in with Google, if you choose it Sign-in information
Porkbun Forwarding emails sent to our cardmi.app addresses Emails you send us

When you share to TikTok, Instagram, Facebook or another app, cardmi passes your picture or video to that app (sometimes by saving it to your Photos first) and that app's own privacy policy applies to what happens next. We don't receive information about you from those apps.

8. Other times we share information

We don't sell your personal information, and we don't share it for cross-context behavioural advertising.

9. How long we keep it

Information How long
Account, profile, backed-up cards, friends, gifts and trades Until you delete them or your account. Copies you gifted or traded stay with your friends.
Photos uploaded for an AI style Deleted once the style is drawn; anything left over within 24 hours. OpenAI may keep them up to 30 days (see section 4).
"Looks broken?" pictures and reported cards Up to 30 days for review, then deleted.
Material we must report to NCMEC As long as the law requires.
Coin, roll and ledger records Until you delete your account.
Purchase records As long as needed for refunds, fraud prevention, accounting and tax, even after you delete your account.
Device abuse records (rate limits) As long as needed to prevent abuse; they're linked to an install, not to your name.
Analytics events Up to 14 months.
Crash reports Up to 90 days.
Emails you send us As long as needed to help you, or longer if needed for a legal reason.

Deleted information may stay in backups for a short time before it's overwritten. We may keep information longer if the law requires it, or to resolve disputes or enforce our Terms.

10. Your choices and controls

11. Your privacy rights

Depending on where you live, you may have the right to:

To use these rights, email hello@cardmi.app from the email on your account if you have one, or include your @handle. We'll verify that the request is really from you (for example by asking you to reply from the email on your account, or to tell us details only the account holder would know) and reply within 45 days (we may extend this once by another 45 days if needed, and we'll tell you). You can use an authorised agent; we'll ask for proof they're allowed to act for you. We won't treat you differently for using your rights.

12. California residents

If you live in California, the California Consumer Privacy Act (as amended by the CPRA) gives you the rights in section 11. In the last 12 months we collected these categories of personal information, from you, your device and our service providers, for the purposes in section 5, and disclosed them for business purposes only to the service providers in section 7:

Category Examples
Identifiers Email address, user ID, @handle, display name, install ID, push token, IP address
Commercial information Purchases, coin balance and spending
Internet or network activity How you use the app (analytics events), crash reports, server and website logs
Audio, electronic or visual information Photos you use for cards and card pictures
Inferences None. We don't build profiles about you.

13. If you live outside the US

cardmi is run from the United States and our servers are in the United States. If you use cardmi from elsewhere, your information is transferred to and processed in the US, where privacy laws may differ from those where you live. Where the law requires a legal basis (for example in the European Economic Area or the UK), we rely on: performing our contract with you (running cardmi and delivering purchases); our legitimate interests (keeping cardmi safe, preventing abuse, fixing and improving it), which we balance against your rights; your consent (for example notifications, and sending a photo for an AI style, which you can withdraw by not using AI styles or deleting the card); and legal obligations. You can also complain to your local data protection authority.

14. Children and teens

15. Security

We protect your information with measures such as encryption in transit, access rules that let each player read and write only their own data, App Check so only the real cardmi app can reach our servers, keys kept in a secure secret store (never in the app), and deleting data we no longer need. No system is perfectly secure, so we can't guarantee security. If we learn of a breach that affects your information, we'll tell you as the law requires.

16. Changes to this policy

We'll update this page and the date at the top when this policy changes. For important changes we'll tell you in the app before they take effect, and where the law requires, we'll ask for your consent.

17. Contact