Overview
CardWarden is a mobile app that helps you securely organize and manage your cards, including loyalty cards, payment cards, membership cards, and more. The app works fully offline if you choose not to create an account. Creating an account is only needed to enable optional cloud features such as backup, device sync, and family sharing.
Your privacy is at the heart of how CardWarden is built. We use a zero-knowledge encryption model, which means your sensitive card data is encrypted on your device before it ever leaves it. Even we cannot see, access, or read your card details. This policy explains what information we collect, how we use it, and how your data is protected.
Information We Collect
CardWarden collects only the minimum information needed to provide its features. What we collect depends on how you use the app:
If you use the app without an account (offline only):
- We do not collect any personal information. All your data stays on your device.
If you create an account (for cloud backup, sync, or family sharing):
- Email address — Collected during account creation (via email sign-up, Google Sign-In, or Apple Sign-In) to identify your account and enable cloud features.
- Encrypted card data — Your card details are encrypted on your device using your master password before being stored in the cloud. The server only receives and stores encrypted data that cannot be read by anyone, including us.
Kids Mode (for children under 13):
- Kids Mode is designed for families with children to have peace of mind. A parent or guardian with a CardWarden account can invite a child to join their family using the "Add a child" feature. A child in Kids Mode does not need to provide an email address or create an account of their own, and CardWarden does not collect any personal information from the child. The child has read-only access to cards that have been explicitly shared with them by the parent or guardian, and nothing else — they cannot see any other cards, pockets, or account data.
Push notifications (optional):
- If you enable push notifications, a push notification token is stored on our server so we can deliver notifications to your device. A randomly generated identifier is used to associate the token with your app session. This identifier changes if you reinstall the app and cannot be used to track you across apps or devices. We do not collect your device ID or any hardware identifiers.
- Family sharing notifications — When you enable notifications for a shared family pocket, limited card metadata may be included in the notification payload in unencrypted form. This includes the card's display name, card type (e.g. "Gift Card"), event type (e.g. "card added"), and for balance changes, the amount and currency. This is the only exception to CardWarden's zero-knowledge model and is necessary because mobile devices cannot perform decryption while the app is in the background or the device is locked. This metadata does not include card numbers, PINs, CVVs, expiry dates, notes, or any other sensitive card details. It is transmitted over encrypted channels (TLS) and is not stored on our servers beyond the instant of delivery — it is cleared immediately after the notification is dispatched.
Anonymous usage analytics:
- We collect anonymous, non-personal analytics to help us understand how the app is used and improve it. This includes: operating system and version, device model, language/region setting, app version, and a randomly generated session identifier. This data is processed by a privacy-focused analytics provider hosted in the European Union. No personal identifiers, advertising IDs, or tracking cookies are collected.
Subscriptions and billing:
- Paid features are managed through the platform store (Google Play or Apple App Store). We use a billing partner to manage subscription status. We do not collect, process, or store your payment details such as credit card numbers or billing addresses. An anonymous identifier is used to link your subscription to your account.
Information We Do Not Collect
CardWarden does not collect, store, or share any of the following:
- Your card numbers, PINs, notes, or any card details (these are encrypted and unreadable by us). The only exception is the limited notification metadata described above under "Family sharing notifications", which includes only the card's display name, type, and balance changes — never card numbers, PINs, or other sensitive details.
- Device identifiers (hardware ID, IMEI, advertising ID)
- Location data
- Contacts, call logs, or calendar data
- Browsing history
- SMS or message content
- Crash reports or diagnostic logs
How We Protect Your Data
CardWarden is built on a zero-knowledge encryption architecture. Here is what that means in plain terms:
- Your data is encrypted on your device — Sensitive card details such as card numbers, PINs, notes, expiry dates, and balances are encrypted on your phone before they are ever sent to the cloud. Only encrypted, scrambled data leaves your device.
- Only you hold the key — Your master password is used to generate the encryption key. We never receive, store, or have access to your master password. Without it, your data cannot be decrypted — not even by us.
- Recovery phrase — During account setup, you receive a 12-word recovery phrase. This is the only way to recover your data if you forget your master password. We do not store this phrase and cannot help you recover it if lost.
- Industry-standard encryption — We use well-established, widely trusted encryption methods to protect your data at rest, in transit, and during sharing.
- Hardware-level protection — On supported devices, encryption keys are stored in your device's secure hardware (such as the Secure Enclave or hardware keystore), adding an extra layer of protection beyond software alone.
- Family sharing is encrypted too — When you share a card pocket with family members, a secure key exchange ensures that only the intended recipients can decrypt the shared data. The server facilitates the exchange but never has access to the contents.
In short: the CardWarden team cannot see your card data. What is stored on our servers is meaningless without your master password, which only you know.
Device Permissions
CardWarden may request the following device permissions. Each is used solely for the purpose described and no data accessed through these permissions is sent to our servers or shared with third parties.
- — Used to scan barcodes and card details using your device camera. All image processing happens on your device and images are never uploaded or stored remotely.
- — Used to let you unlock the app with your fingerprint or face. Biometric data is handled entirely by your device operating system. CardWarden never accesses, receives, or stores your biometric data.
- — Used to display reminders (such as card expiry or payment due dates) and account-related notifications.
- — Used to restore any scheduled reminders after your device is restarted.
How We Share Your Information
We do not sell, rent, or trade your personal information to anyone. We work with a limited number of service providers to operate the app:
- Cloud hosting and authentication — To store your encrypted data and manage your account. These providers only receive encrypted data and your email address. They cannot decrypt your card details.
- Push notification delivery — To send notifications to your device. Only your push notification token is shared.
- Billing partner — To manage subscription status. Only an anonymous account identifier is shared. Your payment details are handled directly by Google Play or the Apple App Store.
- Analytics provider — To receive anonymous usage statistics. No personal information is shared.
All service providers are bound by their own privacy policies and data protection obligations. We do not share your information with any other third parties, advertisers, or data brokers.
Data Retention and Deletion
Your encrypted data and account information are retained for as long as your account is active. You can delete your account and all associated data at any time from within the app. Once deleted, your data is permanently removed from our servers and cannot be recovered.
Anonymous analytics data cannot be tied back to you or your account and is retained separately for product improvement purposes.
Children's Privacy
CardWarden is not directed at children under the age of 13, and children under 13 may only use the App through Kids Mode as described above under "Kids Mode." We do not knowingly collect personal information from children. A child using Kids Mode does not create an account or provide an email address, and has read-only access only to cards explicitly shared with them by their parent or guardian. If you believe a child has provided us with personal information outside of this intended use, please contact us and we will promptly delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be reflected on this page with an updated effective date. We encourage you to review this page periodically. Continued use of the app after any changes constitutes your acceptance of the revised policy.
Contact Us
If you have any questions or concerns about this Privacy Policy or how your data is handled, please contact us at thesimplestnet@gmail.com.