Draft: this policy is not final yet and may change before cardmi launches.
Privacy Policy
Last updated: October 8, 2026
The short version:
- We don't sell your information, we don't show ads, and we don't track you across other apps or websites.
- Cutting you out of a photo happens on your phone. cardmi doesn't recognise faces or make face templates.
- A photo leaves your phone only when you choose an AI style (it's deleted once drawn) or when you sign in and your cards are backed up.
- Guests' cards stay on their phone.
- You can delete your account and data any time in Settings › Delete account.
- cardmi is for people 13 and older.
Contents
- Who we are
- What we collect
- What stays on your phone
- Your photos and AI styles
- How we use your information
- Who can see what
- Companies that help us run cardmi
- Other times we share information
- How long we keep it
- Your choices and controls
- Your privacy rights
- California residents
- If you live outside the US
- Children and teens
- Security
- Changes to this policy
- Contact
1. Who we are
cardmi is an app and website (cardmi.app) that turns photos into collectible trading cards. The operator of cardmi ("we", "us") is responsible for your information. This policy covers the cardmi iPhone app and cardmi.app. Our Terms of Service also apply.
2. What we collect
Information you give us
- Account information (only if you sign in): the sign-in method (Apple, Google or an email link), your email address (if you use Sign in with Apple and choose to hide your email, we get a private relay address), and a user ID. Sign-in providers may also share the name on that account.
- Profile: your display name and @handle, if you choose them.
- Your cards: card pictures (your photo, the cut-out, any AI style, and the finished card), and what you write or choose: names, quotes, zodiac signs, abilities and attacks (including ones you write yourself), stickers, frames, foils, and whether a card is of you or a friend. Signed-in players' cards are backed up to our servers; a guest's cards stay on the phone.
- Photos you choose for AI styles (see section 4).
- Social activity: friend requests, friends, blocks, gifts and trades (which cards, who sent them to whom, gift notes and whether they were accepted).
- Reports: if you report a card, the card, the reason you picked, and your user ID. If you email us, your email address and what you write.
- Your age: cardmi asks your birth year (and sometimes month) when you first open it. Only whether you passed the age check is kept, and only on your phone (see section 3).
Information collected automatically
- Game records: your coin balance and every coin added or spent, your rarity rolls and rerolls, and items you own. These are kept by our servers, including for guests (who have an anonymous account), so coins and purchases work and can't be faked.
- Purchases: what you bought (coin packs and packs), when, and Apple's transaction IDs, through Apple and RevenueCat. Apple handles payment; we never see your card or bank details.
- Device and security information: an install ID, device-attestation signals from Apple (App Attest and DeviceCheck, which confirm a request comes from the real cardmi app on a real iPhone), and records used for rate limits (for example how many styles a device drew today). These stop abuse such as free coins or refunds being claimed over and over.
- Push token: if you turn on notifications, a token that lets us send them to your phone.
- App usage (analytics): events such as "card saved", "style chosen" or "share exported", plus general device information (model, iOS version, app version, language, country or region derived from your connection). Firebase Analytics is set up without Apple's advertising identifier, and we never attach your user ID, name or email to these events.
- Crash reports: if the app crashes, a crash report (what went wrong in the code, device model, iOS version). We don't attach your user ID to crash reports.
- Website and server logs: when you visit cardmi.app or the app contacts our servers, our hosting providers automatically log technical information like IP address, browser type and the time of the request, for security and to keep the service running. cardmi.app doesn't use advertising or tracking cookies.
What we don't collect
We don't collect your contacts, your location, your photo library (cardmi only uses photos you pick, and only adds to Photos when you save), microphone audio, health information, or payment card details. We don't collect biometric identifiers: no face recognition, face matching, face geometry or face templates.
3. What stays on your phone
- Cutting you out of a photo is done on your phone by Apple's built-in tools. It separates a person from the background; it doesn't identify who they are.
- Your birth year from the age check never leaves your phone; only "passed" is kept.
- Motion data used to make foils shine when you tilt your phone never leaves it.
- Guests' cards and drafts are stored on the phone (except AI-style pictures, which are made on our servers; see below).
- The photo you take or pick stays on your phone unless you choose an AI style, or you're signed in and your card is backed up.
4. Your photos and AI styles
- When you choose an AI style (such as Anime, Pixel or Chibi), the cut-out of your photo is uploaded to our server and sent to OpenAI, which draws the style. Before your first AI style, cardmi tells you this and asks you to confirm you have permission to use the photo.
- The uploaded photo is deleted from our servers as soon as the style is drawn; an automatic rule deletes anything left over within 24 hours. The drawn picture is saved with your card.
- Under OpenAI's API data policies, OpenAI does not use the data we send to train its models, and may keep it for up to 30 days to detect abuse before deleting it, unless the law requires longer.
- Our server runs automatic checks on the drawn picture (that it isn't blank, broken or a copy of the input). These checks don't analyse or recognise faces.
- If you use "Looks broken?", the picture is removed from your card and kept privately for up to 30 days so we can check what went wrong, then deleted.
- Safety check on shared cards: each card you share with friends (gifts, trades and cards shown on your friends' Home) is checked once by OpenAI's moderation service, to catch nudity, sexual content and violence before friends see it.
- We may switch to another AI provider with similar protections; if we do, we'll update this policy first.
5. How we use your information
- To run cardmi: create and save your cards, draw AI styles, back up your binder, restore it on a new phone, and move a guest's cards to a new account.
- For coins and purchases: deliver what you buy, keep your balance, restore purchases, and handle refunds.
- For social features: friend requests, showing your cards to friends, delivering gifts and trades, and blocking.
- To send notifications you turned on: for example when a friend sends you a gift or a trade.
- To keep cardmi safe: run the age check, filter rude words, check shared cards, review reports, remove content that breaks our rules, prevent fraud, cheating and abuse, and protect our systems.
- To fix and improve cardmi: find and fix crashes and bugs, and understand which features people use (in a way not linked to who you are).
- To talk to you: answer your emails and tell you about important changes.
- To follow the law: keep records the law requires, respond to lawful requests, and enforce our Terms.
We don't use your information for advertising, we don't build advertising profiles, and we don't use your photos or cards to train AI models. We don't make decisions about you based solely on automated processing that have legal or similarly significant effects; automatic safety checks can hide a card, and you can ask us to review that.
6. Who can see what
- Only you: your drafts, your binder (except what friends can see below), your coins, purchases and settings, and a guest's cards.
- Anyone signed in to cardmi: can find you by your @handle to send a friend request, and see your display name and @handle.
- Your friends: your display name, @handle, main card and latest cards; gifts and trades you send them, including gift notes. Copies of cards you gift or trade stay with your friends, even if you delete your account.
- Anyone you share with outside cardmi: pictures and videos you export show the card, the cardmi logo, your @handle and "make yours at cardmi.app". A card link (cardmi.app/c/…) doesn't show the card on the web; it only opens it in the app on a phone where the card already is.
- Our team: only when needed, for example to review a reported card or answer your email.
7. Companies that help us run cardmi
These companies process information for us, under contracts that let them use it only to provide their service to us (and, for some, to keep their service secure and meet legal obligations):
| Company | What they do for cardmi | Information involved |
|---|---|---|
| Google (Firebase and Google Cloud), United States | Sign-in, database, file storage, server code, push notifications, analytics, crash reports, App Check, remote settings, website hosting | Account, profile, cards, game records, social activity, reports, device and security information, push token, analytics and crash data, logs |
| OpenAI, United States | Drawing AI styles; the safety check on shared cards | The photo cut-out for a style; card pictures being shared with friends |
| RevenueCat, United States | Processing and checking App Store purchases | Your user ID and purchase history |
| Apple | App Store payments and refunds, Sign in with Apple, push notification delivery, device attestation | Purchases, sign-in, push token, device checks |
| Google Sign-In | Signing in with Google, if you choose it | Sign-in information |
| Porkbun | Forwarding emails sent to our cardmi.app addresses | Emails you send us |
When you share to TikTok, Instagram, Facebook or another app, cardmi passes your picture or video to that app (sometimes by saving it to your Photos first) and that app's own privacy policy applies to what happens next. We don't receive information about you from those apps.
8. Other times we share information
- The law and safety: when we believe in good faith it's required by law or legal process, or needed to protect the safety, rights or property of anyone, including you, other players and us, or to prevent fraud or abuse.
- Child safety: we report apparent child sexual exploitation to the National Center for Missing & Exploited Children (NCMEC), with the information the law requires, and keep it as the law requires.
- Business changes: if cardmi is sold, merged or reorganised, information may move to the new owner, who must keep protecting it as this policy says.
- With your permission: any other time you ask us to or agree.
- Aggregated or de-identified information that can't reasonably identify you, for example "how many cards were made this week".
We don't sell your personal information, and we don't share it for cross-context behavioural advertising.
9. How long we keep it
| Information | How long |
|---|---|
| Account, profile, backed-up cards, friends, gifts and trades | Until you delete them or your account. Copies you gifted or traded stay with your friends. |
| Photos uploaded for an AI style | Deleted once the style is drawn; anything left over within 24 hours. OpenAI may keep them up to 30 days (see section 4). |
| "Looks broken?" pictures and reported cards | Up to 30 days for review, then deleted. |
| Material we must report to NCMEC | As long as the law requires. |
| Coin, roll and ledger records | Until you delete your account. |
| Purchase records | As long as needed for refunds, fraud prevention, accounting and tax, even after you delete your account. |
| Device abuse records (rate limits) | As long as needed to prevent abuse; they're linked to an install, not to your name. |
| Analytics events | Up to 14 months. |
| Crash reports | Up to 90 days. |
| Emails you send us | As long as needed to help you, or longer if needed for a legal reason. |
Deleted information may stay in backups for a short time before it's overwritten. We may keep information longer if the law requires it, or to resolve disputes or enforce our Terms.
10. Your choices and controls
- Use cardmi as a guest: you can make and share cards without an account.
- Skip AI styles: Raw (your plain photo) never leaves your phone for drawing.
- Edit or delete cards in your binder, and change your display name.
- Notifications: turn them off in cardmi's Settings or in iPhone Settings.
- Photos and camera access: change it any time in iPhone Settings › cardmi.
- Block players and remove friends at any time.
- Delete your account: Settings › Delete account removes your account, profile, @handle, backed-up cards and pictures, coin and roll records, friends, gifts, trades, blocks, reports, push token and your RevenueCat customer record. Deleting the app alone does not delete your account. Coins and packs are lost when you delete your account.
- Do Not Track: cardmi doesn't track you across other sites, so it treats every visit the same whether or not your browser sends a Do Not Track or Global Privacy Control signal.
11. Your privacy rights
Depending on where you live, you may have the right to:
- know what personal information we have about you and get a copy of it;
- correct information that's wrong;
- delete your information;
- object to or restrict some uses, or withdraw consent you gave;
- opt out of the sale or sharing of your information (we don't sell or share it for advertising);
- appeal if we turn down your request.
To use these rights, email hello@cardmi.app from the email on your account if you have one, or include your @handle. We'll verify that the request is really from you (for example by asking you to reply from the email on your account, or to tell us details only the account holder would know) and reply within 45 days (we may extend this once by another 45 days if needed, and we'll tell you). You can use an authorised agent; we'll ask for proof they're allowed to act for you. We won't treat you differently for using your rights.
12. California residents
If you live in California, the California Consumer Privacy Act (as amended by the CPRA) gives you the rights in section 11. In the last 12 months we collected these categories of personal information, from you, your device and our service providers, for the purposes in section 5, and disclosed them for business purposes only to the service providers in section 7:
| Category | Examples |
|---|---|
| Identifiers | Email address, user ID, @handle, display name, install ID, push token, IP address |
| Commercial information | Purchases, coin balance and spending |
| Internet or network activity | How you use the app (analytics events), crash reports, server and website logs |
| Audio, electronic or visual information | Photos you use for cards and card pictures |
| Inferences | None. We don't build profiles about you. |
- We do not sell personal information or share it for cross-context behavioural advertising, and we have not done so in the last 12 months. We have no actual knowledge of selling or sharing information of consumers under 16.
- We don't use or disclose sensitive personal information for purposes that would give you the right to limit it. We don't collect biometric information, precise location, or government ID numbers.
- Shine the Light: we don't share personal information with other companies for their own direct marketing.
- Players under 18: you can remove cards and other content you posted by deleting them in the app, or ask us to by emailing hello@cardmi.app. Copies you sent to friends, or that others copied or shared, may not be fully removed.
13. If you live outside the US
cardmi is run from the United States and our servers are in the United States. If you use cardmi from elsewhere, your information is transferred to and processed in the US, where privacy laws may differ from those where you live. Where the law requires a legal basis (for example in the European Economic Area or the UK), we rely on: performing our contract with you (running cardmi and delivering purchases); our legitimate interests (keeping cardmi safe, preventing abuse, fixing and improving it), which we balance against your rights; your consent (for example notifications, and sending a photo for an AI style, which you can withdraw by not using AI styles or deleting the card); and legal obligations. You can also complain to your local data protection authority.
14. Children and teens
- cardmi is for people 13 and older, and the app asks for a birth year to block anyone younger. We don't knowingly collect personal information from children under 13. If we learn that we have, we delete it. If you think a child under 13 is using cardmi, email hello@cardmi.app.
- Teens should use cardmi with a parent's or guardian's permission. Parents can contact us at hello@cardmi.app about their teen's information.
- We designed cardmi with teens in mind: no ads, no public profiles or public feed, friends only by @handle, a filter on written text, safety checks on shared cards, reporting and blocking.
15. Security
We protect your information with measures such as encryption in transit, access rules that let each player read and write only their own data, App Check so only the real cardmi app can reach our servers, keys kept in a secure secret store (never in the app), and deleting data we no longer need. No system is perfectly secure, so we can't guarantee security. If we learn of a breach that affects your information, we'll tell you as the law requires.
16. Changes to this policy
We'll update this page and the date at the top when this policy changes. For important changes we'll tell you in the app before they take effect, and where the law requires, we'll ask for your consent.
17. Contact
- Privacy questions and requests: hello@cardmi.app
- Reporting a card or a picture of you: Report content or report@cardmi.app