Back to home

Privacy Policy

Version 2.0 · Effective: April 2026

In brief

Cardly only collects what is needed to operate. Your data is never sold. Plaid (bank connection) and AI (Cardly analysis) features are optional and activated only with explicit consent. You can export or delete your data at any time via settings or support@cardlyapp.ca.

1. Data controller

Fabien Barcelo, operator of Cardly, Montreal, Quebec, Canada · support@cardlyapp.ca.

2. Data collected

Account data: email address, hashed password (bcrypt, non-readable), optional first name, preferences (language, theme).

Manually entered financial data: credit cards, transactions, categories, budgets. This data is created and modified by you.

Banking data via Plaid (Pro plan, optional): if you enable the bank connection, Plaid Inc. retrieves your transactions, balances and account information on your behalf. The Plaid access token is encrypted (AES-256-GCM) before storage. See section 5.

AI interactions (Pro plan, optional): your chat messages and reports generated by AI Advisor are sent to Anthropic (Claude) for processing. See section 6.

Payment data: processed by Stripe Inc. Cardly does not retain any bank card data or account number. We store only a Stripe customer identifier.

Technical data: IP address and user-agent at login and during sensitive actions (audit log), session token, anonymized error logs.

3. Purposes

Your data is used exclusively to: operate the service, display your analyses, process payments, send transactional emails (confirmation, cancellation, optional reminders), ensure security and prevent abuse.

No advertising use, no commercial profiling, no sale or rental of data to third parties.

4. Sharing: technical subprocessors

Your data is shared only with our technical subprocessors, who are contractually bound to protect your data (signed DPA):

  • Vercel Inc. (application hosting, U.S.)
  • Supabase Inc. (PostgreSQL database, U.S.)
  • Stripe Inc. (payments, U.S.)
  • Resend Inc. (transactional emails, U.S.)
  • Plaid Inc. (bank connection, U.S., if Pro plan activated)
  • Anthropic PBC (AI processing via Claude, U.S., if Pro plan activated)

These third parties are all located in the United States. A cross-border transfer of your personal information is therefore necessary for Cardly to operate; you explicitly consent to this by using the service.

5. Plaid: bank connection (Pro plan)

The Plaid feature is strictly optional. Before any connection, Cardly displays a Law 25 consent screen detailing the data collected, its purpose, retention period and your rights. Your consent is timestamped and valid for 12 months; it must then be renewed.

Plaid data stored: bank transactions (date, amount, merchant, category), last-4 mask, current balances, banking institution. Never banking credentials (login, password). The Plaid token is encrypted AES-256-GCM server-side.

Deletion: you can, at any time from Settings → Security, delete all your banking data (Plaid server-side revocation + local deletion). The operation is immediate and irreversible.

6. AI Advisor and AI Chat (Pro plan)

AI features are strictly optional and only activate when you generate a report or send a message. In these cases, a context extracted from your data (aggregated expenses, cards, promos) is sent to Anthropic PBC (Claude) for processing.

Anthropic processes requests transiently and does not use them to train its models (per the "No-Training" policy of the Anthropic API). Data transits through the U.S.

Generated conversations and reports are stored in the Cardly database so you can consult them later. You may delete them individually or in bulk at any time. They are kept for as long as your account exists, and permanently deleted if you close your account (see section 8).

7. Audit log

Cardly maintains an audit log of sensitive actions (Plaid consent, bank connection/disconnection, data deletion, AI report generation, admin changes). This log contains your user ID, email, IP address and user-agent.

When your account is deleted, these entries are anonymized: email, IP and user-agent are erased; only the event and its date remain, for regulatory traceability.

8. Retention periods

  • Account data and financial data: as long as the account is active. Deletion within 30 days after closure.
  • Plaid data: retained as long as the connection is active or until manual deletion. Immediate deletion on request.
  • AI reports and conversations: kept for as long as your account exists. You can delete them yourself at any time.
  • Audit log: kept for as long as your account exists, then anonymized when it is closed.
  • Stripe billing data: 7 years (Canadian legal obligation).
  • Technical logs: 90 days maximum.

9. Your rights (Quebec Law 25 + PIPEDA)

You have the following rights:

  • Right of access: obtain a copy of your data.
  • Right to rectification: correct any inaccurate data.
  • Right to erasure: delete your data (cascade across all tables).
  • Right to portability: JSON/CSV export of your data.
  • Right to object and withdraw consent: disable Plaid, AI, or close your account.
  • Right to de-indexation: Cardly does not publish any public data, so not applicable.

Contact support@cardlyapp.ca to exercise these rights. Response within 30 days.

10. Security

HTTPS/TLS 1.3 encrypted communications, hashed passwords (bcrypt), AES-256-GCM encrypted Plaid tokens, strict per-user data isolation (tenant-scoping on all DB queries), restricted database access, secret rotation, audit log of every administrative action.

11. Cookies

Only the session cookie (next-auth.session-token) and a language preference cookie, strictly necessary for operation. No advertising cookies, no third-party cookies, no cross-site tracking.

12. Minors

Cardly is not intended for users under 18. Contact us at support@cardlyapp.ca to report a minor account.

13. Modifications

Any material change will be notified by email with 30 days' notice. Minor changes (clarifications, wording) are published directly on this page.

14. Contact and complaints

Support: support@cardlyapp.ca

Regulatory complaint: in the event of an unresolved dispute, you may contact the Commission d'accès à l'information du Québec (CAI): cai.gouv.qc.ca, or the Office of the Privacy Commissioner of Canada: priv.gc.ca.

Cardly is operated by Fabien Barcelo, Montreal, Quebec, Canada.

Version 2.0 · Effective: April 2026.

Privacy Policy · Cardly | Cardly