Privacy Policy
Effective: August 30, 2026
CardAlign does not require an account. Local-first does not mean every enabled feature keeps data only on your device. Card photos are processed on your device first, but photo capture, import, and photo-based assessment require you to accept the current Terms of Use and this Privacy Policy before CardAlign uploads and retains the evidence described below.
Who is responsible and what this policy covers
CardAlign is operated by Ding Haipeng, an individual developer and the service provider and data controller responsible for the CardAlign iOS app and cardalign.site. This policy covers data processed when you use the app, website, purchases, support, and beta testing.
Agreement required for photo features
Before CardAlign asks for camera or photo-library access, the app presents links to the Terms of Use and this Privacy Policy and requires an affirmative “Agree and Continue” action. If you do not agree, photo capture, import, and photo-based assessment remain unavailable. Because there is no account, acceptance is recorded on the device with the policy version and time.
CardAlign’s self-hosted product analytics and Sentry stability diagnostics do not start before you accept. After acceptance, they may start on this and later launches; neither channel is configured to send card photos.
Data we process
- Card evidence: original and corrected card images, image crops, borders and corner coordinates, measurements, quality signals, candidate areas, your confirmations or exclusions, condition findings, simulated results, capture source, and timestamps.
- Identifiers and technical data: a persistent pseudonymous installation identifier, sample and card-profile identifiers, app/build/model versions, iOS version, locale, upload status, integrity hashes, and limited diagnostic data.
- Product usage data: app opens and coarse workflow events needed to understand reliability and feature use. Product analytics do not include card photos, card names, exact scores, or finding counts.
- Purchase data: credit-pack product, entitlement, purchase synchronization, and transaction status handled through Apple StoreKit and RevenueCat. CardAlign does not receive your full payment-card number.
- Support and testing data: messages and any screenshots, recordings, reports, or files you choose to send; TestFlight may also provide Apple crash and testing information.
Why we use card-image evidence
- Provide the requested capture, calibration, measurement, condition review, simulated reference, history, and report features.
- Generate and verify results and preserve the completeness of the evidence, including detecting selective omission, substitution, or tampering that could make a result misleading.
- Operate, secure, diagnose, and support the service; investigate abuse; reproduce problems; and handle support requests or disputes.
- Verify purchases and entitlements, maintain service records, analyze coarse product reliability and usage, and comply with legal obligations.
We do not sell card images or use them for third-party advertising. If we introduce a materially different use, we will update this policy and obtain any additional consent required by law before that use begins.
On-device and server records
Camera capture, import, calibration, candidate-area scanning, local history, and report creation start on your device. After acceptance, eligible original and corrected images and related evidence are queued and uploaded to CardAlign. Deleting a local history item removes the local record and associated local files, but does not by itself delete the server evidence copy.
An exported .cardalignbackup file may contain card images, history, recognition results, and reports. It is not additionally encrypted by CardAlign, so keep or share it only in a location you trust.
Service providers and disclosure
We disclose data only as needed to operate the service, follow your request, protect rights and safety, complete a business transfer subject to safeguards, or comply with law. Our main provider categories are:
We require service providers to process data only for our documented purposes and instructions and to provide protection no less protective than this policy and applicable law.
- CardAlign hosting and object-storage providers — store uploaded card evidence and related service records on our behalf.
- Apple — provides the App Store, StoreKit, TestFlight, camera and photo permissions, and payment processing. Provider privacy policy.
- RevenueCat — processes pseudonymous app identifiers and purchase or entitlement information for in-app purchase functionality. Provider privacy policy.
- Sentry — receives crash and app-hang diagnostics. Card photos, screenshots, view text, session replay, and default personally identifying fields are disabled in our Sentry configuration. Provider privacy policy.
Retention
Uploaded card evidence and related records are retained until you request deletion or CardAlign determines they are no longer needed for the purposes above. We may retain limited records longer where an active dispute, security investigation, fraud prevention need, backup cycle, or legal obligation requires it, and then delete or de-identify them when that reason ends. Temporary upload objects, credentials, and local retry queues use shorter operational lifecycles.
Local history remains on your device until you delete it in the app or remove the app. Deleting the app does not automatically delete server records. Purchase, TestFlight, and provider records are retained under the relevant provider’s policy and applicable law.
Your choices and rights
- You can delete local history and associated local images in the app.
- You can avoid attaching card images or reports to support messages unless they are needed for your request.
- Depending on applicable law, you may request access, a copy, correction, deletion, restriction, objection, or withdrawal of consent for data linked to you.
- Withdrawing agreement stops future use of the photo features; it does not make earlier processing unlawful or automatically erase evidence that must temporarily be kept for an active legal, security, or dispute reason.
Because CardAlign has no account system, we may ask for the approximate upload date, card side or workflow, app version, and other information reasonably needed to locate and verify the relevant records. We will not ask for more information than necessary to handle the request.
Security
We use measures such as encrypted network transport, short-lived upload credentials, integrity hashes, access controls, private object storage, and restricted administrative access. No storage or transmission method is completely secure, so we cannot guarantee absolute security.
International processing
Our providers may process purchase, diagnostic, or support data outside your country or region. We use legally required contractual or other safeguards and will provide additional notice or obtain separate consent before a transfer where applicable law requires it.
Children
CardAlign’s photo features are intended only for users aged 14 or older. Users under 14 may not accept the Terms and Privacy Policy or use photo capture, import, or photo-based assessment. If you believe a child’s data was provided contrary to this restriction, contact us so we can investigate and delete it where required.
Changes to this policy
We may update this policy as the product, providers, or law changes. We will publish the revised date and, for a material change affecting card-image evidence or consent, show an in-app notice and require renewed agreement before the affected photo features continue.
Contact
Privacy questions, rights requests, withdrawal, or deletion requests can be sent to support@cardalign.site.