Privacy Policy
Effective date: August 14, 2026
1. Introduction
Card Perks ("we," "our," or "us") operates the Card Perks mobile application (the "App") and this website. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App or website. Please read it carefully. If you disagree with its terms, please discontinue use of the App.
2. Information We Collect
Information you provide directly
- Account information: When you create an account, we collect your email address and the credentials used to sign in. Authentication is provided by Google Firebase Authentication (email/password or similar methods we enable).
- User-generated content: Credit card selections (including custom cards you create that aren't in our catalog), perk tracking data, and benefit usage you log within the App.
- Points and loyalty program balances (self-reported): You may manually enter your own airline, hotel, or card-issuer loyalty point balances so the App can display an estimated dollar value. This information is entirely self-reported: the App is not connected to any airline, hotel, or loyalty program account through Plaid, OAuth, screen-scraping, or any other integration, and we never receive your loyalty program login credentials or real, live balances. Points tracked in the App are not redeemable for anything within Card Perks.
Information collected automatically
- Advertising and device data (free tier): The free tier may show Google AdMob interstitial and other ad formats. AdMob and Google may collect identifiers (such as the Advertising ID on Android or the Identifier for Advertisers on iOS where available), IP address, device type, operating system, app version, coarse location, and similar data to deliver and measure ads. On iOS, Apple’s App Tracking Transparency (ATT) applies where relevant. In the European Economic Area, United Kingdom, and other regions where required, we use Google’s User Messaging Platform (UMP) or similar in-app consent flows so you can consent or manage preferences before certain data is used for advertising.
- Product interaction and App operation: We use Firebase Authentication and Cloud Firestore to store and sync your account and perk data. Firebase may process technical data associated with those services (for example, authentication tokens and security-related metadata).
- Subscription status: We use RevenueCat (or an equivalent subscription platform) to know whether your subscription is active and which features you may use. Payment transactions are still processed by Apple or Google; we do not receive your full payment card number.
- AI Wallet Concierge chat (Card Perks Pro): If you use the AI Wallet Concierge chat feature, your free-text question and up to the last 20 messages of that conversation's history are sent, via a server-side Firebase Cloud Function, to Anthropic's Claude API to generate a response. To make responses relevant to your cards, we also send a prose summary of your own card wallet (card names, fees, perk titles/values/usage, and expiration dates), a summary of your tracked points and loyalty program balances, and, where relevant, our public card catalog (which is not user-specific). We do not send your account, email, or authentication identifiers, payment information, or device data to Anthropic as part of these requests. Chat history is stored in Firestore for as long as your account is active and is permanently deleted, along with your points and loyalty program data, when your account is deleted — see Section 7; we do not apply a separate retention period to this data.
Information from third parties
- Social sign-in (if/when available): If we add Google Sign-In or other social sign-in, we will receive only the profile information needed to create your account and will update this policy to describe what we receive.
Data categories (App Store / Play alignment)
Depending on how you use the App and your device settings, we or our processors may process categories such as: identifiers (for example Advertising ID, device or account identifiers), purchase and subscription information, usage data and product interaction, diagnostics or performance data where AdMob or device services collect it, contact information (email), self-reported points and loyalty program balances, and, for Card Perks Pro subscribers who use the AI Wallet Concierge, AI chat/assistant interactions and the wallet and points summaries sent to generate responses. This summary is intended to align with our in-store disclosures; the subsections above describe each use in more detail.
3. How We Use Your Information
We use the information we collect to:
- Create and manage your account
- Provide, operate, and maintain the App and its features
- Sync your data across devices via Firebase Firestore
- Generate responses to your questions in the AI Wallet Concierge chat feature (Card Perks Pro) using Anthropic's Claude API
- Generate annual summary and earnings overview dashboards from your own card, perk, and account data
- Send you push notifications about expiring perks and benefit deadlines (only with your explicit permission)
- Send you occasional (roughly monthly) product update and new feature announcement emails to the address on your account, each including an unsubscribe link (see Section 9)
- Understand aggregate usage and product interaction to improve App features and performance, consistent with your settings and applicable law
- Deliver and measure advertising on the free tier through Google AdMob
- Diagnose and fix crashes and technical issues (where we use such tools)
- Verify subscription entitlements through RevenueCat (or our subscription provider) while payments are processed by Apple or Google
- Respond to your inquiries and provide customer support
- Comply with legal obligations
We do not sell your personal information for money. On the free tier, third-party ads are served through Google AdMob as described in this policy and in Google’s documentation; AdMob may use identifiers and device data subject to your ATT choices, UMP/consent where applicable, and Google’s policies.
4. Third-Party Services and Data Sharing
We share data only with the service providers necessary to operate the App. Third parties below are required by contract or law to protect your data and use it as described in their policies and this policy:
- Google Firebase — We use Firebase Authentication and Cloud Firestore for accounts and synced data. We do not use Firebase Analytics or Firebase Crashlytics in the App unless we enable them later and update this policy.
- Google AdMob — Serves ads on the free tier. Google AdMob and its advertising partners may collect and use device advertising identifiers (including the Google Advertising ID on Android and the Identifier for Advertisers on iOS, where available), device information, IP address, and app interaction data to deliver, measure, and personalize ads. See Google's Privacy Policy at https://policies.google.com/privacy.
- RevenueCat — Processes subscription status and entitlements so we can unlock Pro features in the App. Apple and Google remain the merchants for payments; we do not receive your full card number.
- Anthropic — Powers the AI Wallet Concierge chat feature available to Card Perks Pro subscribers. We send your question, recent chat history, a summary of your card wallet, and a summary of your points/loyalty balances (and, where relevant, our public card catalog) to Anthropic's Claude API through a server-side Cloud Function to generate a response. We do not send account/authentication identifiers, payment information, or device data. See Anthropic's Privacy Policy at https://www.anthropic.com/legal/privacy.
- Apple App Store / Google Play — Subscription billing and payment processing. We do not receive or store your payment card information.
We may also disclose your information: (a) if required by law or valid legal process; (b) to protect the rights or safety of Card Perks or others; or (c) in connection with a merger, acquisition, or sale of assets, with advance notice to you.
We do not sell your data to unrelated data brokers. On the free tier, third-party advertising networks (including Google, through AdMob) may serve ads and process data as described in this policy and in their own privacy policies.
5. Advertising (Google AdMob)
If you use the free tier of Card Perks, we use Google AdMob to show ads. This section summarizes how advertising data is used so you can review it without opening the App.
- Advertising identifiers: Google AdMob may collect device advertising identifiers, such as the Google Advertising ID (Android) and the Identifier for Advertisers (IDFA) on iOS when your device settings and applicable law allow it.
- Personalized ads: Third-party ad networks integrated through Google AdMob may use these identifiers and related device or usage data to show personalized ads, subject to your consent choices (including Apple's App Tracking Transparency on iOS and Google's User Messaging Platform in the EEA, UK, and other regions where required).
- Google's policy: Google's collection and use of data for advertising is described in the Google Privacy Policy.
- Opt out of personalized ads: You can manage Google ad personalization in Google Ads Settings. On iOS, you can limit tracking in Settings → Privacy & Security → Tracking. On Android, you can reset or opt out of the Advertising ID in your Google account or device settings. In-app consent prompts (UMP) may also let you change ad preferences where required by law.
6. Data Storage and Security
Your data is stored using Google Firebase (Firestore), which encrypts data in transit (TLS) and at rest. We implement industry-standard security practices to protect your information. Data is stored on servers in the United States.
No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
If you enable App Lock, biometric authentication (Face ID or Touch ID) is handled entirely on your device through your device's operating system. Biometric data never leaves your device and is not accessible to us; App Lock is optional.
7. Data Retention and Deletion
We retain your account and usage data for as long as your account is active. If you request deletion of your account, we will delete your personal data within 30 days of the request, except where we are required to retain certain data for legal, security, or fraud-prevention purposes. Any retained data will be clearly described in your deletion confirmation.
This includes AI Wallet Concierge chat history and your points/loyalty program data (described in Section 2): both are stored only for as long as your account exists and are permanently deleted as part of the same account-deletion process described below — we do not apply any separate retention period to this data.
How to delete your account and data:
- In the App: Go to Settings → Account → Delete Account.
- Via email: Send a deletion request to support@cardperksapp.com from the email address associated with your account. We will process your request within 30 days.
Deleting your account will permanently remove your profile, card selections, and perk tracking data. Subscription billing through the App Store or Google Play must be cancelled separately through your store account settings before account deletion to avoid future charges.
8. Push Notifications
The App may send push notifications to remind you of expiring perks and benefit deadlines. These notifications are only sent with your permission, which your device will request. You may opt out of push notifications at any time through your device's notification settings (iOS: Settings → Notifications → Card Perks; Android: Settings → Apps → Card Perks → Notifications).
9. Newsletter and Product Update Emails
We may email the address associated with your account with occasional product update and new feature announcements — typically no more than about once a month. These are standard service-related communications tied to your existing account relationship with us, so we do not require a separate opt-in checkbox for them.
- Every product update email includes a one-click unsubscribe link. Unsubscribing stops future product update emails but does not affect required transactional or account/security emails (for example, password resets or account-deletion confirmations), which we continue to send regardless of your marketing preferences.
- Consistent with the CAN-SPAM Act, these emails use an accurate, identifiable "from" address, include our postal address (4030 Wake Forest Road, Ste 349, Raleigh, NC 27609) and support email, and we honor opt-out requests promptly.
- If you are located in the EEA or UK, you retain the right to object to this processing at any time; see Section 10 below.
10. Your Privacy Rights and Choices
All users
- Access and correction: You may view and update your account information within the App at any time.
- Deletion: See Section 7 for account and data deletion instructions.
- Data portability: You may request a copy of your personal data by emailing support@cardperksapp.com.
- Product update emails: Every product update or newsletter email includes a one-click unsubscribe link (see Section 9). Unsubscribing does not affect required transactional or account/security emails.
- Advertising and tracking choices: On iOS, you can manage App Tracking Transparency (ATT) in Settings. On Android, you can reset or limit the Advertising ID and ad personalization in Google Settings. In the EEA/UK and where required, use the in-app UMP (or similar) consent prompts to manage personalized ads. You can also adjust Google ad personalization in Google Ads Settings. These choices may limit how AdMob uses data for ads but may not remove all ads from the free tier.
California residents (CCPA / CPRA)
You have the right to know what personal information we collect and how it is used, request deletion of your data, correct inaccurate data, and opt out of any sale of personal information (we do not sell personal information). To exercise these rights, contact us at support@cardperksapp.com. We will not discriminate against you for exercising your privacy rights.
EEA and UK residents (GDPR / UK GDPR)
You have the right to access, rectify, erase, restrict processing of, and port your personal data, and to object to certain processing. Our legal bases include: contract performance (account and App functionality), legitimate interests (security and fraud prevention, and sending service-related product update emails as described in Section 9, which you may object to at any time), consent where required (including personalized advertising where we rely on UMP or similar consent), and consent for push notifications where we ask for it. To exercise your rights or lodge a complaint with your local supervisory authority, contact us at support@cardperksapp.com.
11. Children's Privacy
The App is not directed to children under the age of 13 (or 16 in the EU/UK where applicable). We do not knowingly collect personal information from children under these ages. If you believe we have inadvertently collected such information, please contact us immediately at support@cardperksapp.com and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the effective date at the top of this page and, where appropriate, by sending a notification through the App or to the email address on your account. Your continued use of the App after changes are posted constitutes acceptance of the updated policy.
13. Contact Us
If you have questions, concerns, or requests about this Privacy Policy or your personal data, please contact us: