CardSum Privacy Terms Support

Privacy Policy

Last updated: October 5, 2026

PhotosProcessed to identify the card, never stored on our servers.
CollectionsPrivate cards and named collections. Link a sign-in method to recover your backup.
Your dataNever sold. Used to run CardSum, improve the service, and measure ads.

At CardSum, we take your privacy seriously. This Privacy Policy explains how we handle your information when you use our mobile application, available on Android (Google Play Store) and iOS (Apple App Store) — the verdict above, the comps below.

Card photos

When you scan a card, the photo is sent over an encrypted connection to our servers and passed to a specialized card-identification service. The photo is processed for that single scan and is not stored on our servers after the scan completes.

A small thumbnail of your capture is kept on your device only, so your collection can show the card you actually scanned. Thumbnails are never uploaded and are excluded from device cloud backups.

Your account

CardSum signs you in anonymously the first time you use it. You receive an internal account ID without having to provide a name or email address. You can optionally link a Google account, an Apple ID, or an email address and password from the camera's Settings → Account section. If you do, we store the identifiers that sign-in method provides (such as your email address) with your account. Authentication is provided by Google Firebase.

Your cards and collections

Saved card identities, values at scan time, scan dates, named collection names, and which cards belong to each collection are kept on your device and synchronized with your account's private space in our database when a connection is available. A card can belong to more than one named collection. Your cards and collections are not shared with other users or sold to anyone.

Link a sign-in method to recover your account's backup after reinstalling the app or moving to another device. An anonymous account alone does not give you a sign-in method for recovering that backup. Card thumbnails remain on the device where they were saved and are not part of the account backup.

Device preferences and Auto-save

Your appearance choice, scan preferences (haptics and auto-return), sorting preference, and current Auto-save destination are stored on your device. The destination selects a named collection for future saves; every saved card also appears in All cards. Changing it does not move earlier saves. Collection names and local collection-search text are not included in our analytics events.

Analytics

We use Google Analytics for Firebase to understand how the app is used: which screens are visited, whether scans succeed, session statistics, and general device information (model, OS version, country). This data is associated with your internal account ID, not your name or email. We use it to fix problems and improve the app.

Crash reports

If the app crashes, Firebase Crashlytics sends us a diagnostic report: what the app was doing, the device model and OS version, and a stack trace. No scan photos and no card data ride along. Crash reports are tied to an anonymous crash identifier, not your account. Firebase retains these records for 90 days before beginning their removal from its live and backup systems, as described in its privacy documentation. In-app account deletion does not erase these reports.

Ads measurement

To know which ads actually bring collectors in, we work with measurement providers: AppsFlyer (install attribution) and Meta (ad performance). On iOS, an advertising identifier is used for this only if you allow it in Apple's tracking prompt — decline and measurement stays aggregate. On Android, Google's advertising ID is used in line with Play policy, and you can reset or delete it in your device settings. Measurement never involves your scans or your collection, and CardSum shows no third-party ads inside the app.

Subscriptions

Payment for CardSum Pro is handled entirely by the Google Play Store or Apple App Store — we never see your payment details. Subscription status is managed through Adapty, a subscription-infrastructure provider, which receives your internal account ID and purchase state. If you link a sign-in method and an email address is available, we also send that address to your Adapty profile to help manage your account and subscription.

Who we share data with

  • Google Firebase — authentication, database, analytics, crash reporting, and server infrastructure
  • A card-identification service — processes scan photos transiently to identify cards
  • Adapty — subscription status and account management, including your linked account's email address when available
  • AppsFlyer — install attribution measurement
  • Meta — ad performance measurement

These providers process data on our behalf to run the service. We do not sell personal data.

Data retention and deletion

Your account data, saved cards, and collection organization are kept until you remove them or delete the account. Removing a card or a named collection creates a temporary deletion record so the change can reach your other devices. These records are cleared during a successful sync after 30 days. Deleting a named collection keeps its cards in All cards and any other collections.

To delete the whole account, open the camera's Settings gear → Account → Delete account & data. The deletion row is separate from the backup card. Type DELETE and confirm. You can also request deletion by email — see the full instructions. When deletion completes, it removes the current account, its saved cards, named collections and memberships, cloud backup, scan usage history, and CardSum's purchase-event records tied to that account. The app clears local card images and preferences on the device performing deletion and resets its analytics and billing identity.

If you want to delete a previously backed-up account, sign in to that account first. Deleting the current anonymous account does not delete a different linked account.

Resetting the app's identity does not itself erase historical records held by analytics or subscription providers. Contact us for requests concerning those records; we handle these requests through support within 30 days, subject to verifying the account and any required retention. Crash reports follow the retention period above. App stores manage their own transaction records. Deleting your account does not cancel a store subscription; cancel it separately through your store to stop future renewals.

Children

CardSum is not directed at children under 13, and we do not knowingly collect personal information from them.

International processing

Data is processed on our providers' infrastructure, which may be located outside your country. We rely on their standard safeguards for international transfers.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data. Email us and we will handle it.

Changes

If this policy changes in a way that matters, we will update this page and note the new date at the top.

Contact

CardSum — contact@elfarabey.com

Privacy Terms Delete account Support

© 2026 HorizonSoft.