Privacy Policy
Last updated: 4 July 2026
Cardashian (“the app”, “we”, “us”) is a personal wallet for your loyalty and membership cards. This policy explains what data the app handles and your choices. We designed the app to be local-first: your cards live on your device, and most features work without sending anything to us.
What we handle
- Your cards (store name, card number/barcode, optional images, expiry, balance, category): stored on your device. If you sign in, they are also synced to your private account in Google Firebase so you can restore them on a new device.
- Account details: if you sign in with Apple, we receive your email address and (if you choose to share it) your name to create and secure your account. Guest mode creates no account and keeps your data only on your device.
- Location: if you enable nearby-store reminders, your device uses your location on-device to check whether you are near a store you have a card for — these checks are not sent to us. Separately, when you search for a store to add or place on the map, your approximate location is sent to our store-lookup services (OpenStreetMap/Nominatim and our own lookup function) so we can return nearby matches. We do not build or store a history of where you have been.
- Camera & photos: used when you scan a barcode or add a card image. Images are stored on your device; if you sign in they are included in your synced cards, and if you share a card any images on it are included in the shared copy.
- Notifications: expiry and nearby reminders are scheduled locally on your device. The app does not use remote push notifications.
Sharing a card
If you use the “Share” feature to send a card to someone, the card’s details (including any images on it) are uploaded to our database so the recipient can open the link and add the card. Anyone who has the link can view that card until it expires or you remove it, so only share cards with people you trust. Shared links stop working after 14 days, are removed once the recipient adds the card, and you can revoke any link you created at any time from Settings → Shared cards.
Community store map
Store names, categories, and map locations are maintained by users to build a shared, community map. If you add a store’s location or confirm one when prompted, the store’s details and coordinates — together with your account identifier — are saved to a shared database that other users can read. Your own position is never published; only the store’s location is. Entries that other users don’t confirm may be removed over time; once enough users confirm an entry, it is kept as part of the map.
Third-party services
- Google Firebase (by Google) — authentication, optional cloud sync of your cards, the shared community store map and shared-card links, and a lookup function for store locations. See Google’s privacy policy.
- Sign in with Apple (by Apple) — used only if you choose to sign in with Apple. See Apple’s privacy policy.
- OpenStreetMap / Nominatim — used to find store locations near you.
What we don’t do
We do not sell your data, we do not show ads, and we do not include third-party advertising or analytics/tracking SDKs.
Your rights & deleting your data
You can delete individual cards at any time. If you have an account, Settings → Delete account permanently deletes your account and synced cards and settings, and signs you out. Uninstalling the app removes all on-device data. Cards you have shared expire automatically within 14 days, and you can revoke them sooner from Settings → Shared cards. Contributions you have made to the community store map may remain in our shared database after you delete your account, because other users may rely on them and they are not stored with your private data — contact us at hello@limedot.io if you want those removed. Depending on your location (e.g. the EU/EEA under GDPR), you may also have rights to access, correct, or export your data — contact us at the same address.
Data retention
On-device data remains until you delete it or uninstall the app. Synced account data is kept until you delete your account. A shared-card link stops working 14 days after it is created, and is removed when the recipient adds the card, when you revoke it, or when you next open Settings → Shared cards after it has expired. Community store entries are retained to build the shared map; entries that other users don’t confirm may be cleaned up over time, and you can ask us to remove a contribution.
Children
The app is not directed to children under 13 (or the minimum age in your country) and we do not knowingly collect their data.
Changes
We may update this policy; we’ll revise the date above when we do.
Contact
SIA “Limedot” (reg. No. 50203718151), Miera iela 61 k-1 - 1, Rīga, LV-1013, Latvia — hello@limedot.io — limedot.io.