Version 2.0 · Effective: April 2026
In brief
Cardly only collects what is needed to operate. Your data is never sold. Plaid (bank connection) and AI (Cardly analysis) features are optional and activated only with explicit consent. You can export or delete your data at any time via settings or support@cardlyapp.ca.
Fabien Barcelo, operator of Cardly, Montreal, Quebec, Canada · support@cardlyapp.ca.
Account data: email address, hashed password (bcrypt, non-readable), optional first name, preferences (language, theme).
Manually entered financial data: credit cards, transactions, categories, budgets. This data is created and modified by you.
Banking data via Plaid (Pro plan, optional): if you enable the bank connection, Plaid Inc. retrieves your transactions, balances and account information on your behalf. The Plaid access token is encrypted (AES-256-GCM) before storage. See section 5.
AI interactions (Pro plan, optional): your chat messages and reports generated by AI Advisor are sent to Anthropic (Claude) for processing. See section 6.
Payment data: processed by Stripe Inc. Cardly does not retain any bank card data or account number. We store only a Stripe customer identifier.
Technical data: IP address and user-agent at login and during sensitive actions (audit log), session token, anonymized error logs.
Your data is used exclusively to: operate the service, display your analyses, process payments, send transactional emails (confirmation, cancellation, optional reminders), ensure security and prevent abuse.
No advertising use, no commercial profiling, no sale or rental of data to third parties.
Your data is shared only with our technical subprocessors, who are contractually bound to protect your data (signed DPA):
These third parties are all located in the United States. A cross-border transfer of your personal information is therefore necessary for Cardly to operate; you explicitly consent to this by using the service.
The Plaid feature is strictly optional. Before any connection, Cardly displays a Law 25 consent screen detailing the data collected, its purpose, retention period and your rights. Your consent is timestamped and valid for 12 months; it must then be renewed.
Plaid data stored: bank transactions (date, amount, merchant, category), last-4 mask, current balances, banking institution. Never banking credentials (login, password). The Plaid token is encrypted AES-256-GCM server-side.
Deletion: you can, at any time from Settings → Security, delete all your banking data (Plaid server-side revocation + local deletion). The operation is immediate and irreversible.
AI features are strictly optional and only activate when you generate a report or send a message. In these cases, a context extracted from your data (aggregated expenses, cards, promos) is sent to Anthropic PBC (Claude) for processing.
Anthropic processes requests transiently and does not use them to train its models (per the "No-Training" policy of the Anthropic API). Data transits through the U.S.
Generated conversations and reports are stored in the Cardly database so you can consult them later. You may delete them individually or in bulk at any time. They are kept for as long as your account exists, and permanently deleted if you close your account (see section 8).
Cardly maintains an audit log of sensitive actions (Plaid consent, bank connection/disconnection, data deletion, AI report generation, admin changes). This log contains your user ID, email, IP address and user-agent.
When your account is deleted, these entries are anonymized: email, IP and user-agent are erased; only the event and its date remain, for regulatory traceability.
You have the following rights:
Contact support@cardlyapp.ca to exercise these rights. Response within 30 days.
HTTPS/TLS 1.3 encrypted communications, hashed passwords (bcrypt), AES-256-GCM encrypted Plaid tokens, strict per-user data isolation (tenant-scoping on all DB queries), restricted database access, secret rotation, audit log of every administrative action.
Only the session cookie (next-auth.session-token) and a language preference cookie, strictly necessary for operation. No advertising cookies, no third-party cookies, no cross-site tracking.
Cardly is not intended for users under 18. Contact us at support@cardlyapp.ca to report a minor account.
Any material change will be notified by email with 30 days' notice. Minor changes (clarifications, wording) are published directly on this page.
Support: support@cardlyapp.ca
Regulatory complaint: in the event of an unresolved dispute, you may contact the Commission d'accès à l'information du Québec (CAI): cai.gouv.qc.ca, or the Office of the Privacy Commissioner of Canada: priv.gc.ca.
Cardly is operated by Fabien Barcelo, Montreal, Quebec, Canada.
Version 2.0 · Effective: April 2026.