Deutsche Fassung: Datenschutzerklärung

Cardiyo — Privacy Policy

Last updated: 13 August 2026 Published at cardiyo.io/privacy.

This policy covers the Cardiyo app for iOS and Android and the website at cardiyo.io. A German version is published at cardiyo.io/de/datenschutz. The two are written to say the same thing. If they ever differ, the version in your own language is the one that applies to you — we will not use a translation gap against you.


1. The short version

This is a plain-language summary. It does not replace the rest of the policy, but nothing below contradicts it.

  • Your scan photo is not kept. When you photograph a card, the picture is sent to our scanner, matched against our card catalogue, and discarded. We keep no copy. There is no image of your card — or of anything else that was in the frame — in any Cardiyo database or storage bucket.
  • The app contains no analytics, advertising or tracking software. No analytics SDK, no ad network, no attribution or tracking SDK ships in the app. We do not track you across other companies' apps or websites.
  • We do not sell your personal data. Not to anyone, for any purpose.
  • We keep the scan record, not the photo. After a scan we store which card was recognised, the text read off it, the language, how many catalogue matches were found, and the card's value at that moment.
  • Your collection is the most sensitive thing we hold. What you own, what you paid, what you sold it for. We treat it that way — and section 6 says the one other thing we use it for.
  • Links to eBay earn us a commission. Section 10 explains exactly what that means.
  • You can delete your account in the app. Settings → Profile → Delete account. Section 18 says exactly what that removes, what stays behind, and how to have that erased too.
  • We are based in India. India has no adequacy decision from the European Commission. Section 16 explains what that means for you.

2. Who we are

The person responsible for your personal data — the "controller" under Article 4(7) of the General Data Protection Regulation (GDPR) — is:

Karansingh Pruthvisingh Rajput, trading as WebbyWolf Innovations First Floor, H.No-1004/4, Navapur, Agashi Road, Char Rasta Virar West, Vasai Virar, Palghar Maharashtra 401301, India

Email: [email protected]

WebbyWolf Innovations is the trading name under which Karansingh Pruthvisingh Rajput operates, and it is registered for Indian Goods and Services Tax. It is not a separate legal entity: there is no limited company, GmbH or corporation behind Cardiyo. The person legally responsible is the individual named above — the same name shown as the seller on the App Store.

For every question about your data, the contact point is [email protected]. We answer data-protection requests ourselves, directly.

Provider information (Impressum): cardiyo.io/impressum (English) · cardiyo.io/de/impressum (German).

Data protection officer: we have not appointed one. Article 37 GDPR requires a data protection officer where a controller's core activity is large-scale regular and systematic monitoring of people, or large-scale processing of special categories of data. Neither describes Cardiyo: we record what you scan into your own collection, we do not monitor anyone's behaviour across services, and we process no health, biometric or comparable data. Cardiyo is also run by one person, so the German threshold of at least 20 people engaged in automated processing (§ 38 BDSG) is not met either, however that rule is applied to a controller outside the EU. If that assessment changes we will appoint one and say so here. For any question about your data, write to [email protected] — that address is the contact point for everything in this policy.


3. What we collect, why, and on what legal basis

What Why Legal basis (GDPR Art. 6) Do you have to provide it?
Email address and password To create and secure your account, verify your email, and let you reset your password Art. 6(1)(b) — performance of the contract Yes. Without them we cannot open an account.
Display name Shown to you in the app Art. 6(1)(b) Yes, to have a profile.
Profile picture (avatar) Shown on your profile. The file is stored in a public storage bucket, so the image itself can be opened by anyone who has its web address, even without a Cardiyo account Art. 6(1)(b) No, entirely optional — and if you would rather not have a publicly reachable image, do not upload one.
Your collections — cards, sealed products and coins, quantities, condition, variant, grading details, purchase price, sale price, sold status To store and show your collection, its value, and your profit or loss. Also used in summary form to target notifications — see section 6 Art. 6(1)(b) No, but the app is a collection manager. Without it there is little to use.
Scan records — see section 5 To show "recently scanned", to count your daily scans against the free limit, and to find and fix recognition errors Art. 6(1)(b) for the feature; Art. 6(1)(f) — our legitimate interest in a scanner that gets more accurate — for diagnosis Created automatically when you scan.
The scan photograph To identify the card — see section 4 Art. 6(1)(b) Only when you scan. Not retained.
Push token, platform (iOS/Android), device model To deliver notifications to your device — see section 9 Art. 6(1)(b) for service and account notices; Art. 6(1)(a) — your consent — for drop alerts and for anything that promotes Cardiyo No. We store a token only once you have allowed notifications at the operating-system level. If you never allow them, we hold none.
A summary of your account used to choose who receives a notification — whether you have Pro, your app language and market, and how many cards you own, what they are worth in total and which sets they come from So a notification reaches the people it is actually relevant to instead of everyone Art. 6(1)(f) — our legitimate interest in sending fewer and more relevant notifications. You can object (see the box below) Derived from data you already gave us.
Notification delivery records — which notification went to which device, and whether it arrived So the same alert is not sent twice, and so we can tell whether delivery is working Art. 6(1)(f) — our legitimate interest in a push system that works Created automatically when we send.
Subscription status (whether Cardiyo Pro is active, and until when) To unlock the Pro features you paid for Art. 6(1)(b) Only if you subscribe.
App settings — theme, font, currency, language, scanner preferences To make the app work the way you set it Art. 6(1)(b) No.
Support emails you send us To answer you Art. 6(1)(b) where your message concerns your account or your subscription — answering you is part of our contract. Art. 6(1)(f) — our legitimate interest in answering people who write to us — where you are not a Cardiyo user or the message is about something else No.
The fact that you tapped an eBay link, carried to eBay as our campaign identifier To earn the commission that funds the app Art. 6(1)(f) — our legitimate interest in being paid for the referral. You avoid it entirely by not tapping through No.
Technical request data — IP address, request time, error details — processed by our hosting providers To operate the service and keep it available, and to limit repeated sign-in and password-reset attempts Art. 6(1)(f) — our legitimate interest in a secure, working service Unavoidable when any device connects to any server.
A snapshot of your account, collections and scan history, written when you delete your account So your data can be restored if a deletion goes wrong Art. 6(1)(f) — our legitimate interest in not losing a user's data to a failed deletion, weighed against your interest in being forgotten. Section 18 is honest about the state of this today Created automatically at deletion.

We do not collect your precise location, your contacts, your calendar, your advertising identifier, or health or payment-account data. We do not use the microphone. We do not ask for a date of birth.

A right you should notice here, not in the annex. Several rows above run on our legitimate interests rather than on your contract with us: operating and securing the service, looking at scan records to find out why a scan went wrong, choosing who a notification goes to, and the affiliate referral. Where we rely on legitimate interests you have the right to object at any time, on grounds relating to your particular situation. Email [email protected]. We will stop unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms.


4. The camera: what happens when you scan a card

This is the section most people open this policy to read, so it is the most detailed one here.

What is captured. When you press scan — or when auto-capture fires because the card is steady — the app captures a photograph of what the camera sees. That is the card, and whatever else is in the frame. In rapid and batch modes the app keeps capturing while you work through a stack, so one session produces many photographs. Every one of them is handled the same way, and none is kept.

If someone else is in the frame. We only get what your camera sees, so a person nearby could end up in the picture. Because we keep nothing, no record of them survives the seconds the match takes, and there is nothing about them for us to hold, use or hand over. Framing the card on its own is still the better habit — it also makes the scan more accurate.

Where it goes. In the app, the photograph normally goes over an encrypted connection straight to our own scanner service at pyscanner.cardiyo.io. We operate that service ourselves; it runs on infrastructure provided by Railway. The request carries your sign-in token, so the scanner knows which account is scanning. If that direct connection fails — and always on the website — the photograph instead travels through our own API, which is hosted for us by Expo (650 Industries, Inc., United States), and Expo's servers pass it on to the scanner. Either way, the photograph is not sent to Google, Apple, OpenAI or any other image-recognition company, and either way it is not kept.

What it is used for. The scanner reads the card's name, number and set from the image, works out the card's language, and searches our catalogue for the matching print — or, for a sealed product, the matching product. It sends back what it found, and where a print is ambiguous, the runner-up candidates for you to choose between.

Whether we keep it. We do not. The photograph is held only for as long as the match takes and is discarded when the result is returned. No copy is saved into any Cardiyo database or storage bucket. We have verified this in the code that ships: the scanner service performs no object-storage write, and the function that saves a scan record writes text fields only. There is no archive of card photos, no training set built from your scans, and nothing for us to hand over or lose.

We think this is the right way to build a scanner, and it is why we can make the promise so flatly. Be clear about what it does not mean: the photograph is transmitted to our server for the moment it takes to match it. The matching does not happen on your phone.

If you would rather not use the camera at all. You do not have to. You can find any card by searching the catalogue by name, number or set, or by using the guided picker that walks you through language → era → set → card. Everything in the app works the same way with a manually added card.

Photo library. Choosing a picture from your photo library needs its own permission, which you grant separately. A photo you choose is handled exactly like a camera capture: sent for matching, then discarded, never stored. We only ever receive the specific image you choose. We cannot see the rest of your library.


5. What a scan leaves behind

The photograph is not kept. A record of the scan is. These are different things, and mentioning only the first would be misleading.

For each scan we store:

  • which card in our catalogue was matched, if any
  • whether a card was recognised at all, and how many catalogue matches were found
  • the raw text the recogniser read off the card — name, number and set — which can differ from the matched card
  • the card's language
  • the card's value at the moment you scanned it
  • the time of the scan

This powers the "recently scanned" list, counts your scans against the free daily limit, and lets us investigate a scan that went wrong. Scans that matched nothing are recorded too, because failed scans are how the scanner gets better.

The record is tied to your account and is kept for as long as your account exists. Deleting your account removes it from the live database — with the qualification set out in section 18.


6. Your collection data

Your collection is a list of what you own, what you paid for it, and what you sold it for. That allows conclusions about your finances, and we treat it as the most sensitive data in the app.

We use it to show you your collection, its total value, your profit or loss against what you paid, your set completion and your collection's value over time.

We also use a summary of it — how many cards you have, what they are worth in total, which sets you own cards from, and whether you have Cardiyo Pro — to decide who a given notification is sent to, so an alert reaches the people it is relevant to instead of everyone. That summary never leaves our own database.

Beyond showing it to you and choosing who gets a notification, we use your collection for nothing else. It is not shared, it is not aggregated into a product we sell, and it is not passed to any card marketplace.

Collections in the app are private to your account. Public collector profiles exist on the Cardiyo website only — see section 20.


7. Automated decisions, and profiling

The card recogniser is automated. It is not automated decision-making in the sense of Article 22 GDPR: it produces a suggestion about a piece of cardboard, not a decision about you. It has no legal effect and no similarly significant effect on you. You see the result, you can reject it, you can pick a different candidate, or you can add the card by hand.

Cardiyo does not score you, rank you against other users, or decide anything about you automatically. It does sort users into groups by simple facts — whether you have Pro, roughly how large your collection is, which sets you collect, what language you use — to decide who a notification goes to. The GDPR calls that profiling, so we name it rather than hide behind the word. Nothing follows from it except that a notification reaches you or does not, and you can object at any time (Annex A).

Collector ranks and the deck power score are calculated from your own collection and shown only to you. They are a feature, not an assessment of you.


8. Prices, and where they come from

Cardiyo's prices are mirrored daily from TCGplayer (United States, USD), Cardmarket (Europe, EUR), eBay, and PokemonPriceTracker (graded prices and population reports).

Two things about that matter for honesty rather than for privacy, and we would rather say them here than nowhere:

  • eBay live listings are asking prices — what someone hopes to get. eBay sold listings are recorded sales — what someone actually got. The app keeps them apart and so does this policy. A live listing is never presented as a sale.
  • Every price in Cardiyo is an estimate of a market, not a valuation of your card, and not financial or investment advice. Where we have no price for a print, the tile stays empty. We never borrow a price from another language and we never interpolate one.

No personal data is involved in any of this. Reading a price tells the price source nothing about you.


9. Notifications

Cardiyo sends notifications in categories, and they are not all the same thing.

Pokémon Center drop alerts are off until you switch them on in the app. That switch is your consent under Article 6(1)(a) GDPR, and you can withdraw it in the same place at any time — as easily as you gave it, with no effect on anything already sent.

Service and account notices — your subscription lapsed, something about your account needs attention — cannot be switched off inside the app, because a service you pay for has to be able to tell you when it stops working. The legal basis is Article 6(1)(b), performance of the contract. You can still stop all notifications by turning them off for Cardiyo in your phone's own settings.

Anything that promotes Cardiyo — a new feature, a Pro offer — will only ever go to people who have agreed to receive that kind of message. You can object to promotional messages at any time, for no reason and with no balancing against our interests (Article 21(2) GDPR): write to [email protected].

Today the app has exactly one notification switch: Pokémon Center drop alerts. No promotional notification category exists yet; if one is added, it will be off by default and gain its own switch in Settings before the first such message is sent.

The token. To deliver anything we store a push token for your device, along with the platform (iOS or Android) and the device model your phone reports — for example "iPhone 15 Pro". This is the model name, not a name you chose. The token is registered when you sign in and notifications are already allowed at the operating-system level; if you have never allowed them, we hold no token.

Delivery runs through the Expo push service, and from there through Apple's Push Notification service on iOS and Firebase Cloud Messaging on Android. Those services need the token and the message text to deliver it. They do not receive your email address, your collection or your scan history.

If you uninstall the app, the delivery service reports the token as no longer registered and we remove it.


10. eBay affiliate links

When Cardiyo opens eBay, the link normally carries our eBay Partner Network campaign identifier, 5339183987. That makes it an affiliate link: if you buy something after following it, eBay may pay us a commission. You pay the same price either way. On the few eBay country sites the programme does not let us track, the link is passed through unchanged and earns us nothing.

We tell you this because you are entitled to know when a link earns us money.

What it means for your data: when you tap through you go to eBay, and from that moment eBay is responsible for what happens and eBay's own privacy policy applies. eBay sees the request your browser makes — including your IP address — and the campaign identifier showing the visit came from Cardiyo. We do not pass eBay your account, your email address, your collection or your scan history, and we do not receive your identity back from eBay.


11. Subscriptions and payments

Cardiyo Pro is an auto-renewing subscription. The current price is shown in the app and in the store before you buy; the Terms of Use set out the commercial terms.

We never see your payment details. You buy the subscription through Apple's App Store or Google Play. Apple or Google is the seller, takes the payment, and handles refunds and cancellations. Your card number, bank details and billing address go to them and never reach us. Apple and Google handle that data as independent controllers under their own privacy policies.

We use RevenueCat to know whether your subscription is active. RevenueCat receives the store receipt and your Cardiyo account identifier — the same identifier our own database uses for you. It is not your name and not your email address, but it is not anonymous either: it identifies your account. RevenueCat does not receive your collection, your scans or your email address from us.

You manage or cancel the subscription in your Apple or Google account settings, not in Cardiyo. Cancelling stops the renewal; it does not delete your Cardiyo account.


12. Who else processes your data

The table below lists every third party that handles personal data connected to Cardiyo. The first five are our processors: they act only on our instructions, under an Article 28 data processing agreement, and may not use your data for their own purposes. Apple and Google are different: for their own store and account data they decide the purposes themselves, as independent controllers.

Who Role What they receive Why
Supabase Processor Your account, collections, scan records, push tokens, notification records, avatar file, and the emails sent to verify your address or reset your password Our database, sign-in system and file storage. Effectively everything the app stores lives here.
650 Industries, Inc. ("Expo", United States) Processor Requests your app makes to our API, including your sign-in token; the scan photograph, in transit only, on the fallback and website scan paths; push tokens and message text Hosts our app's API and delivers push notifications
Railway (United States) Processor The scan photograph, in memory only, for the moment it takes to match, and your sign-in token Runs our scanner service
Cloudflare, Inc. (United States) Processor The network request when your app loads a card image, including your IP address Stores and delivers our catalogue of card images. Those images are pictures of Pokémon cards and contain no personal data. Your scan photos are never stored here or anywhere else.
RevenueCat, Inc. (United States) Processor Store receipt and your Cardiyo account identifier Tells us whether your Pro subscription is active
Apple and Google Independent controllers for store and account data; processors for push delivery Your purchase and store-account data; push tokens and message text Sell the subscription and deliver notifications

We do not add a processor to this list quietly. If we start using a new one that handles your personal data, this table changes and section 21 explains how we tell you.


13. What we do not do

Everything in this section has been verified against the code that ships, not assumed.

  • No third-party analytics. No Sentry, no Firebase Analytics, no PostHog — no analytics SDK of any kind in the app.
  • No advertising. No ad network, no ad SDK, no ads.
  • No tracking or attribution SDKs. No AppsFlyer, no Adjust, no Meta SDK. Cardiyo does not track you across other companies' apps or websites, and it never asks for permission to under Apple's App Tracking Transparency, because there is nothing to ask about.
  • No third-party sign-in. Cardiyo uses email and password only. No Google, Facebook or Apple account is linked, so no social network learns that you use Cardiyo.
  • No sale of personal data, and no sharing of it for anyone else's marketing.
  • No storage of your scan photographs.

We are describing Cardiyo. We are not making a claim about any other app.


14. How long we keep things

Data Kept for
Scan photographs Not kept. Discarded as soon as the match is returned.
Account, profile, collections, scan records As long as your account exists
Notification delivery records and your notification settings As long as your account exists
Push token Until you turn the relevant alerts off, until you uninstall the app and the delivery service reports the token as dead, or until your account is deleted
Subscription status As long as your account exists
Profile picture file As long as your account exists; removed completely on request after deletion (section 18)
Subscription event log (messages the stores send us) While your account exists; erased in full when you request complete erasure (section 18)
Support emails For as long as the matter they concern is open, and afterwards as long as we may need them to handle follow-ups or legal claims
Deletion archive (section 18) Kept so that a faulty deletion can be reversed; erased in full when you request complete erasure (section 18)
Server and hosting logs (IP address, request time, errors) Only as long as they are useful for operating and securing the service, after which our providers rotate them out. We do not read these logs to build a picture of you; we look at them when something breaks.

15. Security

Traffic between the app and our servers is encrypted in transit. Your password is stored only as a hash by our authentication provider, never in readable form. Access to the production database is restricted to the operator and to the services that need it.

One exception to "private to your account": your profile picture file is stored so that it can be fetched by web address without signing in. Everything else the app stores is reachable only through your account.

We will not claim your data is perfectly safe, because nobody can. What we will say is that we do not hold the two things that would hurt most in a breach: we have no payment details, and we have no photographs from your camera.


16. Where your data is processed, and transfers outside the EU

We operate from India. Cardiyo is run by one person, in India. That is where decisions about your data are made and where the operator accesses it from. The data itself mostly sits elsewhere — on the servers of the providers named in section 12: our database in the European Union, the rest largely in the United States. When you use the app you hand your data to us as the controller rather than to an intermediary, and under the European Data Protection Board's Guidelines 05/2021 that first step is not a "transfer" in the sense of Chapter V GDPR, because there is no separate exporter and importer. The GDPR still applies to us in full, because we offer our service to people in the EU.

India has no adequacy decision from the European Commission. That is a plain fact and we will not dress it up: the Commission has not decided that India offers a level of protection essentially equivalent to EU law. What protects you is that we remain fully subject to the GDPR under Article 3(2)(a), that you can assert every right in Annex A directly against us, and that you can complain to your own supervisory authority under Article 77.

Where your data actually rests. Our database — your account, collections and scan records — runs in Supabase's eu-west-1 region in Ireland: for EU users, that data is stored inside the EU. Passing data to a provider outside the EU is a transfer and needs a safeguard under Article 46 GDPR:

Provider Country Safeguard
Supabase Data stored in the EU (Ireland) Data rests in the EU; the Supabase Data Processing Addendum with Standard Contractual Clauses covers any access from outside it
Cloudflare United States Standard Contractual Clauses under the Cloudflare Data Processing Addendum; Cloudflare also participates in the EU–US Data Privacy Framework
RevenueCat United States Standard Contractual Clauses under the RevenueCat Data Processing Addendum
Expo (650 Industries) United States Standard Contractual Clauses as incorporated in the provider's data-processing terms
Railway United States Standard Contractual Clauses as incorporated in the provider's data-processing terms

The Standard Contractual Clauses are standard data protection clauses adopted by the European Commission under Article 46(2)(c) GDPR (Implementing Decision (EU) 2021/914). Ask us at [email protected] for a copy of the safeguards that apply to your data.


17. If something goes wrong: data breaches

If personal data we hold is exposed, lost, or accessed by someone who should not have it, we will report it to the competent supervisory authorities without undue delay and within 72 hours of becoming aware of it, as Article 33 GDPR requires. Because we have no establishment in the EU there is no single lead authority for us, so the report goes to each authority concerned.

We will tell you directly, without undue delay, whenever the breach is likely to result in a high risk to your rights and freedoms (Article 34 GDPR) — and also whenever your collection, your email address or your scan history is involved, even if we assess the risk as lower than that. We will say what happened, what data was involved, what we have done, and what you should do.


18. Deleting your account

You can delete your account inside the app: Settings → Profile → Delete account. You do not have to email us and you do not have to give a reason.

What deletion removes from the live service: your sign-in credentials, your profile, all of your collections and every entry in them, your scan history, your push tokens, your notification settings and your subscription status. Your account stops existing and you can no longer sign in.

What deletion does not remove by itself. Three things remain after an in-app deletion, and we state them rather than let you assume otherwise:

  • A recovery snapshot. Before the account is torn down, our system writes a copy of your user record — including your email address — your collections and your scan history into a separate archive, so that a deletion that goes wrong can be reconstructed.
  • Your profile picture file. Deleting the account removes your database records, but not the picture file itself, which remains reachable at its web address.
  • Store subscription messages. Messages the app stores send us about a subscription — started, renewed, expired — are kept as log rows, and those rows contain the account identifier the store used.

If you want all of it gone, ask. Email [email protected] from the address you registered with and ask for complete erasure. We will then delete the recovery snapshot, the profile picture file and the store message rows by hand, and confirm to you when it is done. This is your right under Article 17 GDPR, and we honour it on request.

What survives deletion regardless, and why: your purchase history is held by Apple or Google, not by us, and we cannot delete it — it is subject to their retention rules and tax obligations. If we have exchanged emails with you, those remain in our support mailbox for the period in section 14.

Cancelling a subscription is separate. Deleting your Cardiyo account does not cancel a paid subscription. Cancel it in your Apple or Google account settings first, or you will keep paying for an account that no longer exists.


19. Children

Cardiyo is a Pokémon app and we know that many Pokémon collectors are young.

You must be at least 16 years old to have a Cardiyo account, wherever you live. Two different rules point at that number. First, a Cardiyo account is a contract, and in Germany and most of the EU a person under 18 cannot enter one on their own: under 16 we will not open an account at all, and between 16 and 18 you need the agreement of a parent or guardian. Second, drop alerts run on your consent rather than on the contract, and Article 8 GDPR sets the consent age at 16 in Germany; where a Member State applies a lower age, a parent or guardian must give that consent.

We do not knowingly collect data from anyone below that age. We do not ask for a date of birth, so we cannot verify age at sign-up — we say that rather than imply a check we do not perform. If you are a parent or guardian and believe your child has an account, write to [email protected] and we will delete the account and its data.

One thing we can state without qualification: Cardiyo does no behavioural tracking and shows no targeted advertising to anyone, children included, because the app contains no component capable of it.


20. The website

cardiyo.io is a separate surface from the app. Nothing in this section describes how the app behaves.

The website runs no analytics, advertising or marketing scripts and sets no cookies beyond what is strictly necessary to sign you in and keep the site working. Because there is nothing to consent to, there is no cookie banner.

The website offers public collector profiles. Nothing about your collection becomes public unless you use that feature; what you choose to publish there is visible to anyone with the link.


21. Changes to this policy

We will update this policy when what we do changes — a new processor, a new feature that collects something new, a change to how long we keep something.

The "last updated" date at the top always reflects the current version. If a change materially affects you — a new purpose, a new category of recipient, a new retention rule — we will tell you in the app before it takes effect, and where the change requires your consent we will ask for it rather than assume it.

We will not quietly broaden what we do with your data and rely on you re-reading this page.


22. Contact

For anything in this policy, including any request under Annex A or Annex B:

Email: [email protected]

Karansingh Pruthvisingh Rajput, trading as WebbyWolf Innovations First Floor, H.No-1004/4, Navapur, Agashi Road, Char Rasta Virar West, Vasai Virar, Palghar Maharashtra 401301, India

We answer data protection requests within one month. If a request is complex we may extend that by two further months, and we will tell you within the first month if we need to.


Annex A — Your rights in the European Economic Area

These rights come from the GDPR. Exercising them is free of charge. Write to [email protected], or use the in-app route where one exists.

Right of access (Art. 15). You can ask what personal data we hold about you and receive a copy, together with the purposes, the recipients and the retention periods.

Right to rectification (Art. 16). You can correct data that is wrong and complete data that is missing. Your profile and every collection entry are editable in the app at any time.

Right to erasure (Art. 17). You can have your data deleted. Settings → Profile → Delete account does this, with the limits described in section 18.

Right to restriction of processing (Art. 18). In certain cases — for example while we check data whose accuracy you dispute — you can require us to store your data without using it.

Right to data portability (Art. 20). You can receive the data you provided in a structured, machine-readable format and have it sent to another controller where technically feasible. Cardiyo Pro also exports your collection to CSV or Excel in the app, as a convenience — that is a product feature, not the right. If you are not a Pro subscriber, email [email protected] and we will send you the same export free of charge.

Right to object (Art. 21). Where we rely on legitimate interests — operating and securing the service, the diagnostic use of scan records, choosing who receives a notification, and the affiliate referral — you can object at any time on grounds relating to your particular situation. We will stop unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms. Where a notification promotes Cardiyo itself, that is direct marketing: you can object with no reason given and no balancing at all, and we must stop (Art. 21(2)).

Right to withdraw consent (Art. 7(3)). Where we rely on your consent — drop alerts, and any promotional notification — you can withdraw it at any time, as easily as you gave it. Withdrawal does not affect the lawfulness of anything done before.

Rights in relation to automated decision-making (Art. 22). We carry out no automated decision-making producing legal or similarly significant effects. We do profile you in the limited sense described in section 7 — grouping users to target notifications — and you can object to that under the right to object above.

Notification (Art. 19). If you have data corrected or erased, we will inform each recipient it was disclosed to, unless that proves impossible or involves disproportionate effort.

Right to lodge a complaint (Art. 77). You can complain to a data protection supervisory authority — in the Member State where you live, where you work, or where you believe the infringement happened.

We have no establishment in the EU, so there is no single "lead" authority for us and we will not pretend otherwise. In Germany each federal state has its own supervisory authority: complain to the one for the state where you live. A list of all German authorities with contact details is published by the Datenschutzkonferenz at datenschutzkonferenz-online.de. In Austria the competent authority is the Datenschutzbehörde (dsb.gv.at). You do not have to contact us first — but if you tell us about a problem, we would rather fix it.


Annex B — India (Digital Personal Data Protection Act, 2023)

We are based in India, so India's Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 apply to our processing. Under that Act we are the Data Fiduciary (in substance: the controller) and you are the Data Principal (in substance: the data subject).

A note on timing, so this annex is not misleading. The Act is being brought into force in stages. The Rules were notified on 13 November 2025, and most of the operative obligations — notice, security safeguards, breach reporting, retention and erasure, children's consent, and the rights below — commence eighteen months after that notification, in May 2027. We describe these obligations so you know what to expect, and we will meet each one as it comes into force. We are not claiming today that a framework already binds us which does not yet bind anyone.

What we process and why. The same data, for the same purposes, as set out in sections 3 to 12 of the main policy. Those sections are the itemised description of the personal data and the specific purposes.

Your rights as a Data Principal. These are not identical to the GDPR rights in Annex A, so we list them separately rather than merging the two:

  • Right to access information about the personal data we process, the processing activities, and the identities of other Data Fiduciaries and Data Processors with whom it has been shared.
  • Right to correction, completion, updating and erasure of your personal data.
  • Right to nominate another individual to exercise your rights in the event of your death or incapacity.
  • Right to grievance redressal — see below.

The Act provides no right to data portability, no right to object and no right to restriction. If you are in the EEA, Annex A gives you those rights and they apply regardless of anything in this annex.

Withdrawing consent. Where we process on the basis of your consent, you can withdraw it as easily as you gave it. Drop alerts are switched off in the same place they are switched on.

Person to contact about processing. Under section 8(9) of the Act, the contact for questions about our processing of your personal data is [email protected]. We are not a Significant Data Fiduciary and have not been notified as one, so no Data Protection Officer is required.

Grievance redressal. Raise any grievance with us at [email protected]. We will respond within the period the Rules require, and in any event within 90 days. That period applies to grievances under the Indian Act; if you are in the EEA, your requests are answered on the GDPR timetable in section 22 — one month — and the 90-day figure does not apply to you. If you are not satisfied with our response, or we do not respond, you may complain to the Data Protection Board of India, and appeal a Board order to the Telecom Disputes Settlement and Appellate Tribunal.

Personal data breaches. We will report a breach to the Data Protection Board within the time the Rules require, and we will inform you as described in section 17 of the main policy — which we apply to every user, wherever they are.

Transfers out of India. The Act allows the Government to restrict transfers to specified countries. No country has been restricted. Our providers are named in section 12.

Children. Under the Act a child is anyone under 18, and processing a child's data requires verifiable parental consent. We do no tracking, no behavioural monitoring and no advertising directed at children — the app contains no component capable of it.