⚠ DRAFT — NOT THE PUBLISHED POLICYThis page is not in force. It is served noindex and must not be linked from checkout, from the OAuth consent screen, or from anywhere a customer can reach.

Trader details still unanswered: legal_form, registration_number, vat_status in server/legal/identity.json.

Described here but not built yet — 8 item(s):This banner disappears on its own once those are real.

cardigani · version 2026-09-03

Privacy Policy

What we hold, why, for how long, and what you can make us do about it.

This policy is written to be read. It says what personal data cardigani processes, on what basis, how long it is kept and what rights you have.

Every claim here describes something the software actually does today. Where a thing is not built, this policy says so rather than describing an intention.

The short version

Your decks are yours. They are shown to nobody else. There are no shared libraries, no discovery feed, no public boards.

Nothing here trains an AI. cardigani sends your cards to no model, ours or anyone's. There is no AI in this product.

Nothing is sold or brokered. No advertising, no data brokers, no analytics resale.

No tracking scripts. The site loads no analytics tag, no advertising pixel and no third-party font.

You can take everything out, and you can delete it all. Both are buttons in the product, not requests you have to email us about.

Who is responsible

The data controller is Ivan Aleksandrov Naydenov ([свободна професия / ЕООД — MASTER-PLAN Q1]), bul. Iztochen 75, fl. 2, ap. 16, 4000 Plovdiv, Bulgaria, Bulgaria, registration number [BULSTAT/EIK].

For anything to do with your data, write to support@cardigani.app. We answer within one month, as Art 12(3) requires.

No Data Protection Officer is appointed. One is required under Art 37 only for public authorities, or where the core activity is large-scale systematic monitoring or large-scale special-category processing. A one-person index-card tool is none of those.

What is collected, and why

cardigani asks for as little as it can. There is no profile, no display name, no avatar, no address book.

DataWhyLegal basis
Your decks — every card's text, its position, size, rotation and connections, plus the deck's name and folderThis is the service. Without it there is nothing to reopenContract — Art 6(1)(b)
The board snapshot (a thumbnail image of your arrangement)So the library shows you the board rather than a filenameContract
Google account identifier and email addressSo that your decks come back to you and to nobody elseContract
Payment identifiers from our payment provider — a customer id, what you bought, whether it is activeTo know whether your account is paid. We never see or store your card numberContract; legal obligation (Art 6(1)(c)) for invoices and tax records
Server logs — IP address with its last part removed before it is written (so no whole address is ever stored), time, path, response code, the page that linked here, errorsSecurity, fault diagnosis, and enforcing the rate limits belowLegitimate interests (Art 6(1)(f)) — keeping the service up and unabused
Page counts — how many times a day the front page was opened, the demo board was tried, and a price button was pressedSo the one page that sells cardigani can be improved. A count per day and nothing else: no address, no browser details, no cookie, no identifier — there is no way to tell two visitors apart, or to tell that you came backLegitimate interests — and, because nothing is stored on your device, outside the ePrivacy consent rule
Write counts per account, held in memory onlyRate limiting. Never written to disk, gone when the process restartsLegitimate interests
Product news — your email address and the moment you ticked the box, with the version of this policy in forceTo send you a few mails a year about what shipped, only if you asked, from our own mail server. Every one has a one-click way out, and the switch is also in your accountConsent — Art 6(1)(a). Withdrawable at any time, in one click

What is deliberately not collected

No advertising identifiers. No cross-site trackers. No profiling. No automated decision-making with legal or similarly significant effect (Art 22). No special-category data is asked for — and you should not put any on a card, because a card is a free-text field and we cannot detect what is in it.

cardigani does not read your cards for any purpose of its own. Nothing inspects, classifies or summarises their content. The one thing that touches it is your own search: so that a deck can be found by a word you wrote on a card, the words on your cards are kept alongside the deck in a form your search can match — for you, in your library, and for nobody else.

Cookies, and how visits are counted

One cookie, and only after you sign in: the session cookie that keeps you signed in. It is strictly necessary for a service you asked for, so under the ePrivacy Directive Art 5(3) it needs no consent banner — and cardigani shows none.

No analytics script, no tracking pixel, no third party. Visits are counted from the web server's own log, in which every IP address is shortened before it is written; the front page's demo and price buttons each add one to a daily count when used. Those counts hold no address, no browser details, no cookie and no identifier of any kind, so they cannot tell two visitors apart and are not about a person. Storage the visitor asked for is exempt from the consent rule; counting a request the server already answered stores nothing on your device at all.

Who else is involved

These providers process data on our instructions, under Art 28 terms. We will update this list before adding another.

ProviderWhat they doWhere
Hetzner Online GmbHThe server your decks are stored onGermany (EU)
Cloudflare, Inc.DNS, the network in front of the site, and forwarding mail sent to our support address. Traffic passes through whichever of their locations is nearest youGlobal edge; EU–US transfers under Standard Contractual Clauses
Google Ireland Ltd / Google LLCSign-in only. We receive your email address and account identifier and nothing else. We request no other scopeEU/US
Stripe Payments Europe, Ltd.Payments, invoices and receipts. Card details go to them and never to usIreland (EU), with US transfers under Standard Contractual Clauses

Where your decks live

Your decks are stored on a server in Germany, and backed up to storage controlled by the operator in Bulgaria. Both are in the EU.

Requests reach that server through Cloudflare's network, which has locations worldwide, so the *transport* of a request may pass outside the EU even though the *storage* does not. Cloudflare acts as our processor under Standard Contractual Clauses.

Sign-in and payment involve providers with US parent companies, also under Standard Contractual Clauses.

How long things are kept

DataRetention
Decks, thumbnails, foldersUntil you delete them. Deleting your account deletes them immediately
Backups14 days, then automatically removed. This is why deletion is not instantaneous everywhere: a deck you delete today is gone from the live service at once and out of the last backup within a fortnight
Account and sign-in identifiersUntil you delete your account
Invoices and tax recordsAs Bulgarian law requires — these survive account deletion because we are not free to destroy them
Server logs14 days. Both the web server's own logs and the application's are rotated on that clock and then deleted. This number was checked against the machine rather than chosen — the logs kept 14 days, so the policy says 14
In-memory rate-limit counters60 seconds, and never written to disk
Product-news consentUntil you withdraw it — one click in any news mail, or the switch in your account. Deleting your account removes it

Your rights, and which ones are buttons

Under the GDPR you may access, rectify, erase, restrict and object to processing of your personal data, and port it elsewhere.

Portability (Art 20) is built in. *Export my data* produces a zip containing every deck as JSON — with the full text of every card — plus every board snapshot as a PNG, and a readme explaining both. A commonly used, machine-readable format you can open without us.

Erasure (Art 17) is built in. *Delete my account* removes your decks and their snapshots from the live service straight away. Backups age out on the 14-day clock above. Invoices survive, because tax law requires it.

Rectification (Art 16) — your cards are editable by you at any time; that is the whole product.

For anything else, write to support@cardigani.app.

You may also complain to a supervisory authority. Ours is the Commission for Personal Data Protection (КЗЛД), 2 Prof. Tsvetan Lazarov Blvd, Sofia 1592, Bulgaria — kzld.bg, and you may equally complain to the authority where you live.

Security — what is actually true

Traffic is encrypted in transit (TLS 1.2 or better, enforced; the .app domain is on the HSTS preload list, so browsers refuse plain HTTP outright). Administrative access to the server is over a private network, not the public internet. Passwords are never handled, because sign-in is delegated to Google.

What is not claimed: this is a small service run by one person on one server. There is no 24-hour security operations centre, no formal certification, and no encryption of the database at rest beyond the disk it sits on. We would rather tell you that than write security theatre.

If a personal data breach occurs we will notify the supervisory authority within 72 hours and, where Art 34 requires it, you.

Children

cardigani is not intended for people under 16 and we do not knowingly hold their data. If you believe a child has an account, write to support@cardigani.app and it will be removed.

Changes to this policy

Each version carries a date, and the version in force when you agreed is recorded against your account. Material changes are notified by email at least 30 days before they take effect.