Policy ledger
Privacy Policy
Effective August 2, 2026
This Privacy Policy describes how Marcbex LLC (“we,” “our,” or “us”) collects, uses, and protects information when you use kardfolio, our credit card portfolio management service. kardfolio helps you track credit card benefits, monitor signup bonus progress, and organize your card portfolio.
This Policy explains our information practices. Your use of kardfolio is also governed by our Terms of Service.
Information We Collect
Account Information
- Email address (for authentication and communication)
- Account preferences and settings
- Profile information you choose to provide
- Subscription tier, status, purchase channel, and provider identifiers
Card Portfolio Information
- Card products, nicknames, last four digits, credit limits, and relevant dates
- Benefits, offers, rewards, usage, and signup bonus progress
- Labels, notes, and other portfolio details you choose to enter
We do not connect to your bank account, retrieve financial transactions, or store full payment card numbers.
Usage Data
- How you interact with our service
- Device information (browser type, operating system)
- IP address and general location
- Performance data and error logs
- Push notification tokens and delivery information
- Feedback and support information you choose to submit
- In the iOS app, session replay data that may include visual representations of screens, taps, and network performance metadata. Text input fields are configured to be masked.
How We Use Your Information
- Provide and maintain our credit card tracking service
- Send notifications about benefit expirations and resets
- Track your signup bonus progress and spending milestones
- Improve our service and develop new features
- Ensure account security and prevent unauthorized access
- Provide customer support and respond to your requests
- Process subscriptions and maintain access to paid features
- Send account, service, and product communications, subject to available preferences and unsubscribe options
AI Assistant (Kai)
Kai is an optional AI-powered assistant that helps you understand and optimize your credit card benefits. Here's how we handle your data when using Kai:
What Kai Accesses
When you use Kai, it can access information about your kardfolio wallet including your card names, benefit details, and usage progress. This context helps Kai provide personalized recommendations. Kai sees only the last 4 digits of your card numbers (for identification purposes), never full card numbers, account credentials, or financial transactions.
How Conversations Are Processed
Kai sends your message and relevant wallet context to OpenRouter and selected AI model providers to generate a response. We do not save Kai conversation history to your kardfolio account or database. We configure routing to exclude providers that use submitted data for model training, but OpenRouter and model providers may process or retain data under their applicable settings and policies. When Kai uses web search, relevant query information may also be sent to a search provider.
Local Session Storage
For your convenience, recent Kai conversations may be temporarily cached in your browser's local storage for up to 24 hours. This data never leaves your device and is cleared when you explicitly end the conversation using the close button or start a new chat.
Metadata We Collect
We collect operational metadata about Kai interactions, such as the selected model, response time, token usage, request status, and an account identifier. These metrics do not include the content of your conversations, prompts, responses, or wallet context.
Information Sharing
We do not sell, rent, or trade your personal information to third parties. We may share your information only in these limited circumstances:
- Service Providers: Trusted partners who help operate our service (including Supabase and Vercel for hosting, authentication, and data storage; PostHog and Vercel for analytics and diagnostics; Stripe, Apple, and RevenueCat for subscriptions; Resend and push notification providers for communications; OpenRouter and selected AI or search providers for Kai; and Cloudflare, Upstash, Inngest, Linear, and Slack for infrastructure, security, support, and operations). We share only the information reasonably necessary for them to perform these services.
- Legal Requirements: When required by law or to protect our rights and users' safety
- Business Transfers: In connection with a merger, acquisition, or sale of assets
Data Security
We implement industry-standard security measures to protect your information:
- All data is encrypted in transit using HTTPS
- Data is stored securely in Supabase's managed PostgreSQL database
- Access to personal information is limited on a need-to-know basis
- Regular security assessments and updates
- Secure authentication through Supabase
- We never store complete credit card numbers
Cookies & Local Storage
kardfolio uses cookies and browser local storage to provide essential functionality and improve your experience:
Essential Cookies
- Authentication: Supabase sets secure cookies to maintain your login session. These are required for the service to function.
Local Storage
- Kai Conversations: Recent AI assistant conversations are temporarily cached in your browser for up to 24 hours. This data never leaves your device and is cleared when you close the conversation.
- UI Preferences: Settings like sidebar state and display preferences are stored locally for convenience.
- Analytics: PostHog may cache feature flag states locally to improve performance and may use cookies or local storage to distinguish sessions and remember feature flag or analytics state.
We do not sell personal information or use analytics for cross-context behavioral advertising. You can clear cookies and local storage through your browser settings.
Do Not Track
Because there is no uniform standard for browser “Do Not Track” signals, kardfolio does not currently respond to them.
Your Privacy Rights
You have the following rights regarding your personal information:
- Access: Request a copy of your personal information
- Correction: Update or correct inaccurate information
- Deletion: Delete your account directly from account settings or request deletion by contacting us
- Portability: Use available product tools to export wallet data or contact us to request a copy of personal information associated with your account
- Notification Control: Manage your push notification preferences and device permissions
To exercise these rights, you can use the self-service options in your account settings or contact us at support@kardfolio.app.
Data Retention
We retain your information while your account is active and as reasonably necessary to provide, secure, and maintain the service. When account deletion completes successfully, your active kardfolio data and authentication record are deleted.
We also request deletion from applicable service providers. Limited information may remain in encrypted backups, security or audit records, operational logs, provider systems, or where retention is required by law. We may retain a minimal deletion record to prevent delayed provider events from recreating a deleted account. kardfolio does not use that deletion record to personalize the service.
Age Restrictions
Our service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through the service and update the effective date shown on this page.
Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at support@kardfolio.app.
