Cardiki
Open the app
Draft — under legal review. Not yet in force.

Privacy Policy

Last updated: 8 October 2026

Cardiki is a place to reflect, and some of what you write here is personal. This policy explains what we collect, why, who helps us process it, how long we keep it and the choices you have. The short version: we collect what we need to run the app, your journal is encrypted and only used for readings if you say so, nothing you write is used to train AI, and we never sell your data.

1. Who we are

[to be confirmed by counsel], of [to be confirmed by counsel] ("Cardiki", "we", "us"), provides the Cardiki apps and cardiki.com and is the controller of the personal data described here. You can reach us about privacy at privacy@cardiki.com, and about anything else at support@cardiki.com.

  • Our representative in the European Union [to be confirmed by counsel]: [to be confirmed by counsel]
  • Our representative in the United Kingdom [to be confirmed by counsel]: [to be confirmed by counsel]

2. What we collect

DataWhy we use itLegal basisHow long we keep it
Email address, password hash, or Apple or Google sign-in IDYour account and its securityContractUntil your account is deleted, plus 30 days
Birth year and age bracketChecking you are old enough to use CardikiLegal obligationLife of the account
Country and languageShowing the app in your language and the right crisis lines for your regionContractLife of the account
Readings: spread, cards drawn and your questionGiving you readings and your reading historyContract (question text is used for personalisation only with journal consent)Until you delete them
Journal entries and mood tagsYour journal, and personalised readings and insightsExplicit consentUntil you delete them
What we send to the AI and what it writes backWriting your interpretationContract; explicit consent when journal context is includedKept only as part of your reading; our AI provider keeps nothing, or at most 7 days
Safety event codes (a category and a response type, never your text)Checking our safety protocol is workingLegitimate interest13 months
Push notification token and reminder preferencesSending the daily reminder you choseConsentUntil you turn reminders off
Stripe customer ID, App Store and Google Play receipts, records of what you agreed to at checkoutBilling, tax, and proving you agreed to a subscriptionContract; legal obligation7 years in the US, 6 years in the UK; checkout consent records at least 3 years
Device type, app version and crash diagnosticsKeeping the app reliableLegitimate interest90 days
Pseudonymous product analyticsUnderstanding which features help peopleConsent in the EU and UK; legitimate interest with the right to opt out in the US13 months, then kept only as totals
Support conversationsAnswering your questionsContract24 months
Marketing email consentNewsletters, if you ask for themConsentUntil you withdraw it; we keep a suppression list so we never email you again

We do not collect your precise location, contacts, photos or advertising identifiers, and we do not use geofencing.

3. How we use your data

We use your data to run Cardiki: drawing cards, writing interpretations, keeping your journal and history, sending the reminders you chose, processing payments, keeping the service secure, answering support requests, and improving the app using pseudonymous analytics.

AI processing. To write an interpretation we send our AI provider the cards you drew, the spread, your question and your stated focus. If you have turned on "Personalise with my journal", we also send recent mood tags and short excerpts of your journal. We never send your name, email address or account identifiers. We have asked our provider not to retain this data, and under its commercial terms it may not use it to train models.

No training. Nothing you write in Cardiki is ever used to train or fine-tune any AI model, by us or by anyone else.

No sale, no ads. We do not sell or share your personal data for advertising, and we do not use advertising pixels.

Safety. Before a question reaches the AI, automated checks look for signs that someone may be in crisis, so we can show support resources instead of a reading. We log only a category code and a response code, never the text. Our safety protocol explains this in full.

We rely on: contract, to provide the service you signed up for; explicit consent, for journal entries and mood tags, which can reveal information about your health and beliefs, and for analytics and push notifications; legal obligation, for age checks, tax and billing records; and legitimate interests, for security, diagnostics and safety metrics, where we have balanced our interests against yours.

Journal consent. The first time you save a reflection we show an unticked box, "Personalise with my journal". Ticking it lets us store mood tags, use your journal in readings and build pattern insights. You can withdraw consent in Settings at any time. Processing stops immediately, and we offer to delete insights derived from your journal.

5. Who processes data for us

We share personal data only with service providers that process it on our instructions under a data processing agreement:

  • our AI provider (Anthropic), to write interpretations;
  • our cloud hosting and database provider;
  • Stripe, Apple and Google, for payments and sign-in;
  • Apple Push Notification service and Firebase Cloud Messaging, for reminders;
  • our transactional email provider, for sign-in links and receipts;
  • our analytics, error monitoring and support desk providers;
  • our content delivery network.

We may also disclose data where the law requires it, to protect someone's safety in an emergency, or as part of a merger or acquisition, in which case this policy will continue to apply to your data.

6. International transfers

Some providers process data outside the country where you live, including in the United States. When we transfer personal data from the EU or UK, we rely on the EU-US Data Privacy Framework where the recipient is certified, or on the European Commission's Standard Contractual Clauses and the UK addendum, with additional safeguards where needed.

7. How long we keep it

Retention periods for each kind of data are in the table in section 2. In addition: when you delete your account we lock it straight away and erase it within 30 days, and backups containing it are purged within 90 days. If an account is inactive for 24 months, we delete it after sending two warnings to the email on file.

8. Security

All traffic uses TLS 1.2 or later. Your journal entries and questions are encrypted in our application with a key unique to your account, which is itself protected by a master key held in a key management service. They are decrypted only for the moment needed to show them to you or write a reading. Journal text never appears in push notifications, analytics or crash reports. Access to production systems is limited to staff who need it.

If a breach affects your personal data, we notify the relevant supervisory authority within 72 hours where required and tell you without undue delay.

9. Your rights

Depending on where you live, you have the right to:

  • access the personal data we hold about you;
  • export it in a portable format (Settings, then Export, gives you JSON and Markdown);
  • delete it (Settings, then Delete account, or on the web);
  • correct inaccurate data;
  • withdraw consent at any time, without affecting processing that happened before;
  • object to processing based on legitimate interests;
  • limit the use of sensitive personal information;
  • opt out of the sale or sharing of personal data. We do not sell or share it, and we honour Global Privacy Control signals as an opt-out;
  • appeal if we decline a request, by replying to our decision.

To make a request, use the in-app tools or email privacy@cardiki.com. We may need to confirm it is you. We respond within 30 days in the EU and UK and within 45 days in the US, and we aim to complete exports within 72 hours. We will not treat you differently for exercising your rights.

10. Children

Cardiki is for people aged 16 and over. We ask for a date of birth before the first reading and keep only the year and an age bracket. If you are under 16, we do not create an account and do not keep the date you entered. If we learn that someone under 13 has used Cardiki, we suspend the account and delete it within 72 hours. For users aged 16 and 17 we apply high-privacy defaults: quiet hours are on, there is no behavioural advertising, and we avoid features designed to lengthen sessions.

11. Cookies and similar technologies

The website uses a small number of strictly necessary cookies and local storage entries to keep you signed in and remember settings such as your theme. With your consent, we also use first-party analytics. In the EU and UK we ask before setting any analytics cookies, and "Reject all" is as easy as "Accept all". In the US we honour Global Privacy Control. You can change your choice at any time from the cookie settings link. We use no advertising cookies or third-party tracking pixels.

12. Consumer health data

Mood tags and journal text can count as consumer health data under laws such as Washington's My Health My Data Act and Nevada's equivalent law. Our Consumer Health Data Privacy Policy explains how we collect, use and share it, and the rights you have.

13. Changes to this policy

We will post any changes here and update the date at the top. If a change is material, we will tell you in the app or by email before it takes effect, and ask for your consent again where the law requires it.

14. Complaints

If you are unhappy with how we handle your data, please contact privacy@cardiki.com first. You also have the right to complain to a supervisory authority: in the EU, the data protection authority in the country where you live or work; in the UK, the Information Commissioner's Office (ico.org.uk); in California, the California Privacy Protection Agency (cppa.ca.gov).