Information should have a job.
We collect information needed to provide, secure, support, and improve Cards—not simply because it might become useful later.

Cards exists to coordinate work—not to exploit the people doing it. This policy explains what information Cards collects, why it is needed, how it is handled, and the choices available to you.
We collect information needed to provide, secure, support, and improve Cards—not simply because it might become useful later.
Workspace membership, role, and the work being performed determine which information a person can access.
Cards does not use AI to decide someone’s motives, competence, character, or employee performance.
The information Cards receives depends on how you interact with the service. It may be provided directly by you, created through normal product use, or generated by the systems required to operate Cards.
Cards uses information to operate and secure accounts; coordinate work; maintain project, review, time, financial, and client-facing records; respond to beta and support requests; send service communications; investigate errors; prevent abuse; maintain backups; and meet legal obligations.
Cell phone numbers submitted through public forms are used for the purpose stated beside the field. Beta applicants may separately and optionally consent to transactional SMS about their application, onboarding appointments, and beta milestones, and may separately consent to promotional SMS about product updates, launch announcements, pricing, and offers. Consent is not a condition of applying for or participating in the beta. Message frequency varies; message and data rates may apply. Reply STOP to opt out or HELP for help. Opting out of one SMS purpose does not withdraw consent for a different purpose unless you ask us to do so.
Retention depends on the type of information, why it was collected, the choices of the organization controlling the workspace, operational and legal requirements, and the need to preserve an accurate history of work.
Cards uses authentication, workspace isolation, role and permission boundaries, private file storage, server-validated commands, protected audit history, malware scanning, controlled support access, encrypted off-site backups, and separate staging and production environments.
Cards monitors application errors and service availability. Session replay is disabled, and performance tracing remains disabled pending a separate privacy review. No system can guarantee that an incident or outage is impossible; current operational boundaries are described in more detail on the Trust page.
Cards is intended for organizations and workplace users, not children. We do not knowingly collect personal information from children through the service.
When this policy changes, Cards will update the effective date and provide additional notice when a change materially affects how information is collected, used, or shared.
For a privacy question, access request, correction, export, or deletion request, contact Cards Support. We may need to verify your identity and account relationship before acting on a request.
Contact Cards SupportDepending on where you live and your relationship to a Cards workspace, you may have rights regarding your personal information.
Ask us what a term means, how a control works, or what information applies to your account.