Privacy Policy
Last updated 27 August 2026
Cardtell is a party card game. This policy describes exactly what the app and its server store, why, and for how long. It is written to match what the software actually does rather than to cover every possibility.
The short version
- You can play without an account. If you choose to sign in, we store your name, your email address and the username you pick. If you signed in with an email address rather than with Apple or Google, we also store a cryptographic hash of your password — never the password itself.
- We do not sell your data, and there are no advertising trackers in the app.
- If it is switched on, a crash reporting service receives technical details when the app fails. That, and the service that checks your purchases are genuine, are the only third parties that receive anything about your use of the app.
- Your display name and avatar are shown to the other players in your room. Nothing else is.
What we store
On your device
| What | Why |
|---|---|
| An identity token | Lets you return to your seat and your cards after your phone locks or your
connection drops. Stored in the operating system keychain (iOS Keychain /
Android Keystore). In a web browser it is stored in localStorage,
which is less protected. |
| Your display name and chosen avatar | So you do not re-enter them each game. |
| Settings, and whether you have seen the intro and age confirmation | So you are not asked again. |
All of this is removed when you uninstall the app or clear your browser storage.
On our server
| What | Why | Kept for |
|---|---|---|
| A random player identifier | Generated by us, not derived from your device or anything about you. It is how the game knows which hand of cards is yours. | While the room is open |
| Your display name and avatar choice | Shown to other players in the same room. | While the room is open |
| Which cards a group has already been dealt | So you are not shown the same cards every time you play. Stored against a one-way cryptographic value derived from your room code — we cannot work out your room code from it. | Indefinitely, until unused |
| Server logs, including IP addresses | Diagnosing faults, and limiting abuse such as connection floods. We log the outcome of security checks, never your identity token. | Rotated automatically, typically a few weeks |
| Only if you sign in: your name, your email address, the username you choose, your avatar, and — if you used Apple or Google — that provider's own identifier for you | So your purchases and your player follow you to a new phone. Your username is what other players see in a room. Apple accounts often use a relay address rather than your real one; we take whatever we are given and do not try to resolve it. | Until you delete the account |
| Only if you sign in with an email address: a cryptographic hash of your password, and the six-digit codes we email you | The hash is what lets us check a password without holding one — it cannot be turned back into your password, and we cannot tell you what your password is. The codes confirm the address is yours, or let you set a new password. | The hash until you delete the account; a code expires fifteen minutes after we send it |
| Only if you write a card: the text, and which player wrote it | Cards written during a game are reviewed before they can ever be shown to anyone outside that room. If somebody reports a card, the text is copied into a moderation queue for us to read. | Until reviewed |
| Only if you block somebody: that you blocked them | So their written cards stay hidden from you on your next game. It is one-way and private: the person you blocked is not told. | Until you unblock them |
| Only if you buy something: what you are entitled to use | So a purchase works on your other devices. See Purchases below. | While the entitlement lasts |
What we do not collect
- No phone number, date of birth or postal address. If you sign in with an email address we store a hash of your password, never the password itself.
- No contacts, photos, microphone, camera or precise location.
- No advertising identifiers, and no advertising SDKs.
- We do not record the cards you are dealt or who won. Scores exist only while the game is running.
Crash reporting
Builds of the app may include Sentry, a crash reporting service. When the app fails, it sends the error, the type of device and operating system, and a short trail of which screens you had visited. It is configured to strip request bodies and web addresses, and it identifies the report only by the same random player identifier described above — never your name or your email. We use it to find and fix crashes and for nothing else. Sentry's own privacy policy is at sentry.io/privacy.
Age
Cardtell is rated 18+ and is not intended for children. The card content is adult humour. You are asked to confirm that you are 18 or over before playing. We do not knowingly collect information from children, and we do not ask anybody for a date of birth — the confirmation is a declaration, not a record. If you believe a child has used the app and you want anything removed, contact us below.
Purchases
If you buy a subscription or an add-on, the payment is handled entirely by Apple or Google. We never see your card details. The confirmation that a purchase is valid reaches us through RevenueCat, which sits between the app stores and our server for exactly that purpose; it is told the random player identifier and what was bought, and nothing else about you. We store a record of what you are entitled to use so those items work across your devices.
Who else is involved
Each of these receives only what is described here, and each is required to protect it to the same standard this policy sets out. None of them is permitted to use it for their own purposes.
- Oracle Cloud — hosts the game server and its database.
- Apple and Google — app distribution, sign-in, and payment processing. When you sign in, they give us your name and an email address; we give them nothing.
- RevenueCat — checks with Apple or Google that a purchase is genuine, and tells our server what you are entitled to use. It receives the random player identifier described above and the details of the purchase itself. It never receives your name, your email address or your card details.
- Sentry — crash reports, where enabled. See Crash reporting above.
- Expo — used to build and sign the app. It does not receive player data.
Your rights
Depending on where you live, you may have rights to access, correct or delete personal information we hold about you, and to withdraw consent you have given.
- If you have an account: delete it from inside the app, under Settings → Delete account. That removes your name, your email address and the link between your sign-in and your player. You can also request deletion from the web if you have already uninstalled the app.
- If you play as a guest: deleting the app removes your identity token, after which the random identifier on our server cannot be linked to you by anyone, including us.
- A group's stored card history: contact us with the room code.
Changes
If this policy changes materially we will update the date at the top and, where the change affects how your information is used, tell you in the app.
Contact
Questions or requests: support@cardtell.fun
← Back to Cardtell