Privacy Policy
Last updated: July 29, 2026
Who we are
Cardinate is operated by Nasr Almansoob ("we", "us"), acting as the data controller for personal data processed through the service. Contact: support@cardinate.app.
What we collect
When you sign up, we collect your email address and (optionally) a display name. When you connect a bank, we receive account balances, transactions, and credit-card metadata (APR, statement balance, minimum payment, due date) from Plaid on your behalf.
How we use it
We use this data exclusively to power features you see in-app: categorising transactions, building payoff plans, and showing balance trends. We do not sell your data, do not share it with advertisers, and do not use it to train AI models.
Third-party processors
- Plaid Inc.: bank connectivity. Plaid's privacy notice: plaid.com/legal.
- Supabase / AWS: encrypted Postgres storage and authentication.
- Stripe, Inc.: payment processing for Pro subscriptions. Stripe receives your email address and card details and handles billing, invoicing and tax calculation. We never see or store your full card number. See Stripe's privacy notice.
- Amplitude, Inc.: product analytics, and session replay on a 10% sample of sessions to help us find bugs. Replay is recorded with full masking: text and form inputs are obscured, so balances, card names and amounts are not captured. Analytics only run after you accept in the cookie banner. See Amplitude's privacy notice.
- Cloudflare, Inc.: content delivery and protection for cardinate.app. Cloudflare processes your IP address and request metadata. See Cloudflare's privacy policy.
- logo.dev: bank and merchant logos. Your browser requests each logo directly, so logo.dev receives your IP address and the name of the institution or merchant being displayed. It does not receive balances, transaction amounts or account details. See logo.dev's privacy policy.
- Professional advisers and authorities: legal/accounting advisers, or authorities where required by law.
Cookies, analytics and session recording
Cardinate uses cookies and local storage that are necessary for the product to work: keeping you signed in, and remembering your theme and display preferences. These are always on, because without them the app cannot function.
Separately, we use product analytics to understand which features get used and where people get stuck, including session replay on a 10% sample of sessions to help us reproduce bugs. These only start after you accept in the banner shown on your first visit. If you decline, nothing is recorded and no analytics events are sent.
Session replay is recorded with full masking. Text and form inputs are obscured before anything leaves your browser, so balances, account names, transaction amounts and anything you type are not captured. We see the shape of the page and where you clicked, not your financial data.
Data access
To operate, support, secure, and improve Cardinate, authorized personnel and our infrastructure providers (such as Supabase, AWS, Plaid, and Stripe) may access your data when necessary, for example, to provide support, investigate a technical issue, or comply with a legal obligation. We never access your data in order to sell or share it, and we limit access to what's needed for these purposes.
Data retention
- We keep your data for as long as your account exists.
- When you delete your account, your data is removed from our live database immediately.
- Encrypted backups held by our hosting provider age out on their own rolling schedule. Individual records cannot be erased from a backup.
- Billing records and referral credits are kept in anonymized form, with no link back to you, for tax and accounting.
Your rights
You can export your data, disconnect any bank, or delete your account entirely at any time from Settings → Danger Zone. Deletion immediately revokes Plaid access and removes your data from our live database. Email support@cardinate.app for any other request under GDPR / CCPA (access, rectification, erasure, restriction, portability, objection, withdraw consent, or complain to your supervisory authority).
Security
All traffic is TLS 1.2+. Cardinate never receives your bank login. Plaid handles the sign-in and gives us a read-only token, so we can see your balances but never move your money. Your data is encrypted at rest, and row-level security ensures one user can never read another's data. We support optional two-factor authentication (TOTP). Turn it on at Settings → Security.
Contact
Questions? support@cardinate.app