1. Scope
This Privacy Policy explains how the CardDue mobile application identified above (the "App") processes your personal data. It covers the App only. Third party services you reach through the App (Google Play, the App Store, sharing apps installed on your device, your bank's own apps) are governed by their own privacy policies.
By using the App you accept the processing described in this policy.
2. No account required
You do not need to register, create an account, or provide an e-mail address, phone number or identity document to use the App. The App has no user account system.
3. What data is processed and where it is stored
All tracking data you enter is stored on your device only. The processed data is:
| Data | Description |
|---|---|
| Card nickname | A name you choose to tell your cards apart |
| Bank name | Free text you type in |
| Card network | Your Visa / Mastercard / Troy selection |
| Last 4 digits only of the card number | To visually distinguish the card |
| Statement day and due day | As a day of the month |
| Statement debt, minimum payment, credit limit | Amounts you enter |
| Currency code | ISO 4217 code (TRY by default) |
| Payment history | Amount, date, note and full/partial flag of payments you record |
| Reminder settings | How many days before, at what time, and whether reminders are on |
| App preferences | Theme, language, onboarding state, your optional display name, app lock and notification preferences |
| Pro entitlement record | If you made a purchase: platform, product id, transaction id, the store's verification data, purchase and expiry dates |
Card and payment records are kept in an AES-256 encrypted Hive database on your device. App preferences and the Pro entitlement record are kept in the App's private local storage area, protected by the device operating system.
Your card details, payment history and app preferences are not sent to our servers; only you see them, on your own device. For the billing-related part of the Pro entitlement record, see section 8.
4. What is explicitly never requested or stored
The App never asks for and never stores:
- Your full credit card number
- The card expiry date
- The CVV / CVC security code
- Internet banking usernames, passwords, one-time codes or any other bank login credentials
- National ID numbers, addresses, location data, contacts or gallery content
The App does not connect to any bank and does not fetch your debt, limit or statement automatically. You enter every amount and date manually.
5. On-device storage, encryption and app lock
- Card and payment records are stored AES-256 encrypted.
- The encryption key is held in the platform secure store (
flutter_secure_storage; backed by the Android Keystore on Android and the Keychain on iOS). The key is not written into the App's data files and does not leave the device. - If you enable the optional app lock (PIN and/or biometrics), your PIN is not stored in plain text: a SHA-256 digest is computed together with a random salt, and only that digest is kept in the secure store.
- Biometric verification is performed by the device operating system. Fingerprint or face data is never passed to the App; the App only receives a "verified" or "failed" result.
No software can guarantee absolute security. Your device's screen lock, operating system updates and physical security remain your responsibility.
6. Permissions and why each exists
| Permission | Why it is needed |
|---|---|
POST_NOTIFICATIONS | To show local reminders on your device as a due date approaches (Android 13 and above) |
RECEIVE_BOOT_COMPLETED | So scheduled reminders survive a device restart |
USE_BIOMETRIC / USE_FINGERPRINT | For biometric verification in the optional app lock |
VIBRATE | So notifications can vibrate according to your device settings |
INTERNET, ACCESS_NETWORK_STATE, com.android.vending.BILLING | For in-app purchases and subscription verification; these are added by the in_app_purchase plugin |
The App does not request location, camera, microphone, contacts, SMS or call log permissions.
7. Notifications
Payment reminders are scheduled and displayed on the device itself (flutter_local_notifications). No push server is used to deliver them, and notification content does not leave the device.
8. Purchases and billing verification
When you buy Pro features, the payment is handled entirely by Google Play or the Apple App Store. You never enter card details into the App; your payment details are not passed to the App and are not visible to us. Those transactions are governed by the respective store's own privacy policy.
After a purchase, the verification data returned by the store (receipt / purchase token), the product id, the transaction id and the relevant dates are stored on your device.
A server-side verification service may be used to check that a purchase is valid. When such verification takes place, the data that may leave your device is strictly limited to:
- a billing installation identifier (a random value specific to that installation, not linked to your identity or your card data),
- the platform (Google Play or App Store),
- the purchased product id,
- the store's purchase verification token / receipt,
- the resulting entitlement (subscription or licence) status.
Your card nicknames, bank names, last 4 digits, debt amounts, credit limits and payment history are never sent over this channel. In a build where billing verification is not enabled, or if you make no purchase, this data is not produced at all.
9. No analytics, advertising or crash reporting
The App contains no analytics SDK, no advertising SDK and no crash reporting SDK. Your in-app behaviour is not tracked, no profile is built, no advertising identifier is read, and no data is passed to third party ad networks. We do not sell your personal data.
10. Data export and your responsibility
Pro users can export their card and payment records as JSON and CSV. The files are written to the device's temporary directory and handed to you through the operating system's system share sheet; the App does not upload them anywhere on its own.
Important: Exported files are not encrypted. Once you send a file to an e-mail, a messaging app, a cloud drive or any other destination, protecting its contents becomes your responsibility, and the file then falls under that destination service's privacy terms. The file contains no full card number and no CVV, but it does contain card names, bank names, last 4 digits, debt amounts and your payment history.
11. Retention and deletion
- Data stays on your device until you delete it. There is no fixed retention period; you are the party holding the data.
- Inside the App you can delete individual cards and payments, or archive cards.
- Uninstalling the App removes all local data (the encrypted database, the preferences, and the key / PIN digest in the secure store).
- There is no server-side account to delete. If billing verification took place and a record exists server-side, that record is tied only to the billing identifier; it is not linked to your card data, your name or your payment history.
- Your purchase and subscription records are additionally held in your Google Play or App Store account; you can exercise your rights over those records through the relevant store.
12. Your rights
Because your data lives on your device and under your control, you can exercise most of the rights described by GDPR and the Turkish KVKK directly through the App:
| Right | How the App delivers it |
|---|---|
| Access | All your records are visible on the App's screens |
| Portability | JSON/CSV export with Pro |
| Rectification | You can edit card and payment records at any time |
| Erasure | Delete records individually, or uninstall the App to remove everything |
| Objection / restriction | The App performs no profiling and no automated decision-making |
If you have a request concerning the limited data covered by billing verification, please contact us at the address below.
13. Children
The App is intended for users aged 18 and over and is not directed at children. We do not knowingly collect data from children; the App has no data-collecting server in the first place. If you believe a child has used the App, you can remove the data on the device by uninstalling the App.
14. Changes to this policy
We may update this policy as the App changes or as legal requirements change. The updated text will be published at this address and the effective date will be revised. For significant changes we will give notice in the App or in the store release notes. Continuing to use the App after a change means you accept the current policy.
15. Contact
For privacy questions:
- E-mail: support@nodvera.io
- Publisher: Nodvera
- Published at: https://nodvera.io/en/carddue/privacy.html
- Turkish version: https://nodvera.io/carddue/privacy.html