Privacy Policy

Last updated: December 19, 2024

At CARDANA, we take your privacy seriously. This policy explains how we collect, use, and protect your personal information across all CARDANA products and services.

1. Information We Collect

Account Information: When you create an account, we collect your name, email address, and authentication credentials (including information from Google OAuth if you choose to sign in with Google).

Usage Data: We collect information about how you interact with our services, including features used, content created, and preferences set.

Generated Content: Content you create using CARDANA services (text, images, videos, audio) is stored to provide the service and improve your experience.

Payment Information: Payment processing is handled by Stripe. We do not store your full credit card details on our servers.

Device & Technical Information: We collect browser type, IP address, device identifiers, and similar technical data to ensure service security and functionality.

2. How We Use Your Information

We use collected information to:

  • Provide, maintain, and improve CARDANA services
  • Process transactions and manage your account
  • Personalise your experience through adaptive learning and cognitive fingerprinting
  • Communicate with you about updates, features, and support
  • Ensure security and prevent fraud
  • Comply with legal obligations

3. Cognitive Fingerprinting & Personalisation

CARDANA uses adaptive intelligence to personalise your experience. This includes:

  • Learning your preferences, communication style, and working patterns
  • Adapting responses and recommendations based on your interactions
  • Building a "cognitive fingerprint" that improves service quality over time

You can view, export, or delete your personalisation data at any time through your account settings.

4. Data Sharing & Third Parties

We do not sell your personal information. We may share data with:

  • Service Providers: Third-party services that help us operate (e.g., Supabase for database, Stripe for payments, AI model providers like OpenAI, ElevenLabs, and others)
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

5. AI Model Providers

CARDANA integrates with various AI providers to deliver our services. When you use features powered by these providers:

  • Your prompts and inputs may be processed by third-party AI systems
  • We do not share your account information with AI providers
  • Generated content is stored on CARDANA infrastructure, not with AI providers

Current AI providers include OpenAI, Anthropic, ElevenLabs, Replicate, FAL.ai, and others as the platform evolves.

6. Data Security

We implement industry-standard security measures including:

  • Encryption in transit (TLS/SSL) and at rest
  • Secure authentication via Supabase Auth
  • Regular security audits and monitoring
  • Access controls and employee training

7. Your Rights

Depending on your location, you may have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your data ("right to be forgotten")
  • Export your data in a portable format
  • Opt out of certain processing activities
  • Withdraw consent where applicable

To exercise these rights, contact us at privacy@cardana.app.

8. Data Retention

We retain your data for as long as your account is active or as needed to provide services. After account deletion:

  • Personal data is deleted within 30 days
  • Generated content is permanently removed
  • Anonymised analytics may be retained for service improvement

9. Cookies & Tracking

We use essential cookies for authentication and service functionality. We do not use third-party advertising trackers. Analytics are privacy-focused and do not track individual users across sites.

10. Children's Privacy

CARDANA services are not intended for children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us immediately.

11. International Transfers

Your data may be processed in countries other than your own. We ensure appropriate safeguards are in place for international data transfers in compliance with applicable laws.

12. Changes to This Policy

We may update this policy from time to time. We will notify you of significant changes via email or through the service. Continued use after changes constitutes acceptance of the updated policy.

13. Contact Us

For privacy-related questions or concerns: