Privacy Policy

Last updated 27 August 2026

Cardtell is a party card game. This policy describes exactly what the app and its server store, why, and for how long. It is written to match what the software actually does rather than to cover every possibility.

The short version

What we store

On your device

WhatWhy
An identity token Lets you return to your seat and your cards after your phone locks or your connection drops. Stored in the operating system keychain (iOS Keychain / Android Keystore). In a web browser it is stored in localStorage, which is less protected.
Your display name and chosen avatarSo you do not re-enter them each game.
Settings, and whether you have seen the intro and age confirmationSo you are not asked again.

All of this is removed when you uninstall the app or clear your browser storage.

On our server

WhatWhyKept for
A random player identifier Generated by us, not derived from your device or anything about you. It is how the game knows which hand of cards is yours. While the room is open
Your display name and avatar choice Shown to other players in the same room. While the room is open
Which cards a group has already been dealt So you are not shown the same cards every time you play. Stored against a one-way cryptographic value derived from your room code — we cannot work out your room code from it. Indefinitely, until unused
Server logs, including IP addresses Diagnosing faults, and limiting abuse such as connection floods. We log the outcome of security checks, never your identity token. Rotated automatically, typically a few weeks
Only if you sign in: your name, your email address, the username you choose, your avatar, and — if you used Apple or Google — that provider's own identifier for you So your purchases and your player follow you to a new phone. Your username is what other players see in a room. Apple accounts often use a relay address rather than your real one; we take whatever we are given and do not try to resolve it. Until you delete the account
Only if you sign in with an email address: a cryptographic hash of your password, and the six-digit codes we email you The hash is what lets us check a password without holding one — it cannot be turned back into your password, and we cannot tell you what your password is. The codes confirm the address is yours, or let you set a new password. The hash until you delete the account; a code expires fifteen minutes after we send it
Only if you write a card: the text, and which player wrote it Cards written during a game are reviewed before they can ever be shown to anyone outside that room. If somebody reports a card, the text is copied into a moderation queue for us to read. Until reviewed
Only if you block somebody: that you blocked them So their written cards stay hidden from you on your next game. It is one-way and private: the person you blocked is not told. Until you unblock them
Only if you buy something: what you are entitled to use So a purchase works on your other devices. See Purchases below. While the entitlement lasts

What we do not collect

Crash reporting

Builds of the app may include Sentry, a crash reporting service. When the app fails, it sends the error, the type of device and operating system, and a short trail of which screens you had visited. It is configured to strip request bodies and web addresses, and it identifies the report only by the same random player identifier described above — never your name or your email. We use it to find and fix crashes and for nothing else. Sentry's own privacy policy is at sentry.io/privacy.

Age

Cardtell is rated 18+ and is not intended for children. The card content is adult humour. You are asked to confirm that you are 18 or over before playing. We do not knowingly collect information from children, and we do not ask anybody for a date of birth — the confirmation is a declaration, not a record. If you believe a child has used the app and you want anything removed, contact us below.

Purchases

If you buy a subscription or an add-on, the payment is handled entirely by Apple or Google. We never see your card details. The confirmation that a purchase is valid reaches us through RevenueCat, which sits between the app stores and our server for exactly that purpose; it is told the random player identifier and what was bought, and nothing else about you. We store a record of what you are entitled to use so those items work across your devices.

Who else is involved

Each of these receives only what is described here, and each is required to protect it to the same standard this policy sets out. None of them is permitted to use it for their own purposes.

Your rights

Depending on where you live, you may have rights to access, correct or delete personal information we hold about you, and to withdraw consent you have given.

Changes

If this policy changes materially we will update the date at the top and, where the change affects how your information is used, tell you in the app.

Contact

Questions or requests: support@cardtell.fun

← Back to Cardtell