1. Information We Collect
- Account information: your email address
- Name and date of birth, only if you add them: many banks build the statement PDF password from these, so we use them only to try to open a password-locked statement
- Verified sender addresses: the email addresses you register for forwarding statements
- Credit card metadata: card name, last 4 digits, bank name, credit limit
- Statement data: transaction amounts, merchant names, categories parsed from statements
- Statement passwords: the PDF password your bank sets, stored encrypted so future statements open automatically
- Device information: device type, OS version for crash reporting
- Push notification token, if you allow notifications
2. How We Receive Your Statements
You forward statement emails to an address the app shows you after you sign up.
- Forwarded email is received and processed on our behalf by our email infrastructure provider before it reaches our servers
- We identify forwarded statements by the sender address you have verified on your account. We do not issue a separate private address to each user
- Email sent to us from an address that is not verified on any account is discarded without being parsed
- We read the statement attachment and the message metadata needed to route it to your account. We do not read, index or retain the rest of your mailbox, and we have no access to it
3. How We Use Your Information
- To parse and display your credit card statements
- To send due date reminders and spend alerts
- To generate spend analytics and card recommendations
- To operate, secure and support the service
- We never sell your data to third parties
- We do not use your statement data to train artificial intelligence models
4. Statement and Document Handling
- A statement file is deleted as soon as it has been read
- A statement we cannot read yet — it needs its password, we cannot tell which of your cards it belongs to, or its figures need a second look — is kept encrypted for up to 7 days, so it can be read without you forwarding it again, and is then deleted
- A statement that arrives after your plan's reads for the month are used up is kept encrypted until a few days after they reset on the 1st, so at most about a month, and is then read or deleted
- The structured data extracted from a statement — amounts, dates, merchant names — is retained in your account so the app can show you your history
5. Data Security
- Sensitive data, including statement passwords and card details, is encrypted at rest with AES-256
- Data is transmitted over HTTPS only
- Supabase Row Level Security ensures users can only access their own data
- We never ask for, receive or store your bank login credentials, your full card number, or your PIN
- The app's own PIN lock is kept on your phone only and never sent to us
6. Third-Party Services
We use the following third-party services, each with their own privacy policy. Statement content may be processed by the artificial intelligence providers listed below:
7. Data Retention
- Statement files: deleted as soon as they are read; one we cannot read yet is kept encrypted for up to 7 days, or until a few days after your monthly reads reset (see section 4)
- Parsed statement data, card metadata and account information: retained for as long as your account is active
- On account deletion: your account data is deleted within 30 days, except where we are required to retain records by law
- Anonymised, aggregated data that cannot identify you may be retained to operate and improve the service
8. Your Rights (DPDP Act 2023)
- Access your data: email privacy@cardkundali.app
- Correct your data: edit it in the app, or contact us
- Delete your account and data: in the app, open the You tab and tap Delete my account, or see how to request account deletion
- Data portability: available on request
- Withdraw consent: deleting your account withdraws your consent to further processing
9. Grievance Redressal
If you have a complaint about how your data is handled, contact our Grievance Officer at privacy@cardkundali.app. We will acknowledge your complaint within 7 days and aim to resolve it within 30 days.
10. Children
CardKundali is not intended for use by anyone under 18. We do not knowingly collect data from children.
11. Changes to This Policy
We may update this policy. The date at the top of this page reflects the most recent change. Material changes will be communicated in the app before they take effect.
12. Contact
For privacy-related queries, email privacy@cardkundali.app