Nodvera · CardDue

CardDue — Privacy Policy

Effective date: 8 August 2026
App: CardDue · Version: 1.0.0 · Package / bundle id: com.nodvera.carddue
Publisher: Nodvera

1. Scope

This Privacy Policy explains how the CardDue mobile application identified above (the "App") processes your personal data. It covers the App only. Third party services you reach through the App (Google Play, the App Store, sharing apps installed on your device, your bank's own apps) are governed by their own privacy policies.

By using the App you accept the processing described in this policy.

2. No account required

You do not need to register, create an account, or provide an e-mail address, phone number or identity document to use the App. The App has no user account system.

3. What data is processed and where it is stored

All tracking data you enter is stored on your device only. The processed data is:

DataDescription
Card nicknameA name you choose to tell your cards apart
Bank nameFree text you type in
Card networkYour Visa / Mastercard / Troy selection
Last 4 digits only of the card numberTo visually distinguish the card
Statement day and due dayAs a day of the month
Statement debt, minimum payment, credit limitAmounts you enter
Currency codeISO 4217 code (TRY by default)
Payment historyAmount, date, note and full/partial flag of payments you record
Reminder settingsHow many days before, at what time, and whether reminders are on
App preferencesTheme, language, onboarding state, your optional display name, app lock and notification preferences
Pro entitlement recordIf you made a purchase: platform, product id, transaction id, the store's verification data, purchase and expiry dates

Card and payment records are kept in an AES-256 encrypted Hive database on your device. App preferences and the Pro entitlement record are kept in the App's private local storage area, protected by the device operating system.

Your card details, payment history and app preferences are not sent to our servers; only you see them, on your own device. For the billing-related part of the Pro entitlement record, see section 8.

4. What is explicitly never requested or stored

The App never asks for and never stores:

The App does not connect to any bank and does not fetch your debt, limit or statement automatically. You enter every amount and date manually.

5. On-device storage, encryption and app lock

No software can guarantee absolute security. Your device's screen lock, operating system updates and physical security remain your responsibility.

6. Permissions and why each exists

PermissionWhy it is needed
POST_NOTIFICATIONSTo show local reminders on your device as a due date approaches (Android 13 and above)
RECEIVE_BOOT_COMPLETEDSo scheduled reminders survive a device restart
USE_BIOMETRIC / USE_FINGERPRINTFor biometric verification in the optional app lock
VIBRATESo notifications can vibrate according to your device settings
INTERNET, ACCESS_NETWORK_STATE, com.android.vending.BILLINGFor in-app purchases and subscription verification; these are added by the in_app_purchase plugin

The App does not request location, camera, microphone, contacts, SMS or call log permissions.

7. Notifications

Payment reminders are scheduled and displayed on the device itself (flutter_local_notifications). No push server is used to deliver them, and notification content does not leave the device.

8. Purchases and billing verification

When you buy Pro features, the payment is handled entirely by Google Play or the Apple App Store. You never enter card details into the App; your payment details are not passed to the App and are not visible to us. Those transactions are governed by the respective store's own privacy policy.

After a purchase, the verification data returned by the store (receipt / purchase token), the product id, the transaction id and the relevant dates are stored on your device.

A server-side verification service may be used to check that a purchase is valid. When such verification takes place, the data that may leave your device is strictly limited to:

Your card nicknames, bank names, last 4 digits, debt amounts, credit limits and payment history are never sent over this channel. In a build where billing verification is not enabled, or if you make no purchase, this data is not produced at all.

9. No analytics, advertising or crash reporting

The App contains no analytics SDK, no advertising SDK and no crash reporting SDK. Your in-app behaviour is not tracked, no profile is built, no advertising identifier is read, and no data is passed to third party ad networks. We do not sell your personal data.

10. Data export and your responsibility

Pro users can export their card and payment records as JSON and CSV. The files are written to the device's temporary directory and handed to you through the operating system's system share sheet; the App does not upload them anywhere on its own.

Important: Exported files are not encrypted. Once you send a file to an e-mail, a messaging app, a cloud drive or any other destination, protecting its contents becomes your responsibility, and the file then falls under that destination service's privacy terms. The file contains no full card number and no CVV, but it does contain card names, bank names, last 4 digits, debt amounts and your payment history.

11. Retention and deletion

12. Your rights

Because your data lives on your device and under your control, you can exercise most of the rights described by GDPR and the Turkish KVKK directly through the App:

RightHow the App delivers it
AccessAll your records are visible on the App's screens
PortabilityJSON/CSV export with Pro
RectificationYou can edit card and payment records at any time
ErasureDelete records individually, or uninstall the App to remove everything
Objection / restrictionThe App performs no profiling and no automated decision-making

If you have a request concerning the limited data covered by billing verification, please contact us at the address below.

13. Children

The App is intended for users aged 18 and over and is not directed at children. We do not knowingly collect data from children; the App has no data-collecting server in the first place. If you believe a child has used the App, you can remove the data on the device by uninstalling the App.

14. Changes to this policy

We may update this policy as the App changes or as legal requirements change. The updated text will be published at this address and the effective date will be revised. For significant changes we will give notice in the App or in the store release notes. Continuing to use the App after a change means you accept the current policy.

15. Contact

For privacy questions: