Privacy at Cards

Your work is not raw material.

Cards exists to coordinate work—not to exploit the people doing it. This policy explains what information Cards collects, why it is needed, how it is handled, and the choices available to you.

Effective date
August 4, 2026

This policy applies to the Cards website, product, beta application, and support experience.
Our Starting Point

Collect with purpose. Use with restraint.

01

Information should have a job.

We collect information needed to provide, secure, support, and improve Cards—not simply because it might become useful later.

02

Context determines visibility.

Workspace membership, role, and the work being performed determine which information a person can access.

03

People make judgments about people.

Cards does not use AI to decide someone’s motives, competence, character, or employee performance.

01 · Information We Collect

Only what the relationship requires.

The information Cards receives depends on how you interact with the service. It may be provided directly by you, created through normal product use, or generated by the systems required to operate Cards.

Account and identityName, email address, authentication information, organization, workspace membership, role, and account preferences.
Work contentProjects, Cards, comments, decisions, files, assignments, schedules, time records, client reviews, and other information your organization chooses to place in Cards.
Applications and contactName, work email, cell phone number, role, organization, organization size, and information included in beta, contact, or support requests.
Service and securityTechnical events needed to authenticate requests, protect the service, diagnose errors, maintain availability, and preserve an accountable history of important actions.
Connected servicesInformation needed to provide an integration you or your organization chooses to enable, such as meeting or transactional email services.
02 · How We Use Information

To provide the service people asked for.

Cards uses information to operate and secure accounts; coordinate work; maintain project, review, time, financial, and client-facing records; respond to beta and support requests; send service communications; investigate errors; prevent abuse; maintain backups; and meet legal obligations.

Cell phone numbers submitted through public forms are used for the purpose stated beside the field. Beta applicants may separately and optionally consent to transactional SMS about their application, onboarding appointments, and beta milestones, and may separately consent to promotional SMS about product updates, launch announcements, pricing, and offers. Consent is not a condition of applying for or participating in the beta. Message frequency varies; message and data rates may apply. Reply STOP to opt out or HELP for help. Opting out of one SMS purpose does not withdraw consent for a different purpose unless you ask us to do so.

03 · How Information Is Shared

Access is limited by purpose and context.

Information may be visible to authorized members of your organization according to their role and the work they are permitted to access. Client users receive client-visible records connected to the projects and reviews shared with them, rather than unrestricted access to internal workspace information.

Cards uses service providers for application hosting and delivery, database, authentication, private storage, transactional email, beta relationship management, appointment scheduling, SMS delivery, error and availability monitoring, meeting integration, malware scanning, and CardBot processing. These providers receive only the categories of information needed to perform their services under their own governing terms.

Mobile information and SMS consent are not sold or shared with third parties for their own marketing or promotional purposes. They may be disclosed to service providers that help Cards deliver messages you requested, subject to purpose and confidentiality restrictions.

Cards may disclose information when legally required, to protect the service or people from harm, or as part of a business transaction subject to appropriate notice and safeguards. Cards does not sell personal information.

04 · Retention and Deletion

Keep what supports the record. Remove what no longer should.

Retention depends on the type of information, why it was collected, the choices of the organization controlling the workspace, operational and legal requirements, and the need to preserve an accurate history of work.

  • Active workspace information is generally retained while the account or customer relationship remains active.
  • Removed attachments are recoverable for 30 days before the binary is deleted. A minimal history marker may remain so the work record does not silently change.
  • Backup copies may persist for a limited recovery period before aging out through the backup lifecycle.
  • Some audit, billing, legal, fraud-prevention, and security records may be retained when necessary to meet legitimate obligations.
05 · Protection and Monitoring

Monitor the system, not the person.

Cards uses authentication, workspace isolation, role and permission boundaries, private file storage, server-validated commands, protected audit history, malware scanning, controlled support access, encrypted off-site backups, and separate staging and production environments.

Cards monitors application errors and service availability. Session replay is disabled, and performance tracing remains disabled pending a separate privacy review. No system can guarantee that an incident or outage is impossible; current operational boundaries are described in more detail on the Trust page.

06 · Children and Policy Changes

A service built for workplace use.

Cards is intended for organizations and workplace users, not children. We do not knowingly collect personal information from children through the service.

When this policy changes, Cards will update the effective date and provide additional notice when a change materially affects how information is collected, used, or shared.

Questions should reach a person.

For a privacy question, access request, correction, export, or deletion request, contact Cards Support. We may need to verify your identity and account relationship before acting on a request.

Contact Cards Support
Your Choices

Privacy rights should be usable.

Depending on where you live and your relationship to a Cards workspace, you may have rights regarding your personal information.

01
Ask what personal information Cards holds about you.
02
Request access to or a copy of applicable personal information.
03
Correct information that is inaccurate or incomplete.
04
Request deletion or restriction where applicable.
05
Object to or ask questions about particular uses of information.
Shared Understanding

If the policy is unclear, the work is not finished.

Ask us what a term means, how a control works, or what information applies to your account.