Legal
What Cardගොඩ does with your information, written so you can actually check it against the app's behaviour.
Last updated 10 September 2026
Your statements stay on your computer. There is no Cardගොඩ account and no Cardගොඩ server holding your data. Three things can leave your machine, and every one of them is something you switch on: AI statement reading, Google Drive backup, and a problem report you choose to send.
One statement's text, when the offline reader cannot cope. Sent by your own free key, to your own Google account.
A compressed backup, into a private per-app folder. The app cannot see any other file in your Drive.
Your note, the app version and which page you were on. The statement itself only if you tick the box.
Never, under any setting: your bank login, a Cardගොඩ account, an advertising or device ID, or a copy of your database on our servers — there are no servers.
This policy covers the Cardගොඩ desktop application for Windows and macOS, and this website. Cardගොඩ is made by an independent developer in Sri Lanka.
Effectively everything. The app stores its data in a database file on your own machine, under your user account:
Two things are kept in your operating system's keychain — Windows Credential Manager or the macOS Keychain — rather than in the database: your Google Gemini API key, and any statement passwords you asked the app to remember. They are never written into a backup file.
We cannot see any of this. There is no mechanism by which we could: nothing sends it anywhere, and there is nowhere for it to go.
Three things, each one off until you turn it on. This is the section worth reading carefully.
Most statements are read by a parser that runs entirely offline. When a layout defeats it — a scanned page, an unusual table — the app can send that statement's text to Google Gemini to be read.
If you connect Google Drive, the app writes a compressed snapshot of your data to your own Drive.
drive.appdata permission, the narrowest scope
Google offers. That is a private per-application folder: the app cannot
see, read or touch any other file in your Drive, and other apps cannot see
what it writes there.When you use the report button, or send a feature idea, that message goes to a Google Firebase project we operate. Nothing is sent unless you press send. A report contains:
No account identifier, device fingerprint or advertising ID is attached, because none exists.
On launch the app asks GitHub whether a newer version exists. That request reveals your IP address to GitHub, as any web request does. It carries no information about you or your data, and it is the only thing the app contacts on its own.
This site sets no cookies and runs no analytics. We do not know who visits it. See the cookies page, which is short.
Fonts are loaded from Google Fonts, which means Google's servers see your IP address when a page loads. Tutorial videos are hosted on YouTube but nothing is requested from YouTube until you press play — until then the page shows a still image and contacts nobody.
Data on your computer stays until you delete it. Settings → Clear All Data removes it, and asks for the last four digits of one of your cards first so it cannot happen by accident. Uninstalling the app does not delete your data.
Reports you send are kept while they are useful for fixing what they describe. Any statement PDF you attached is deleted once the problem is resolved.
Because we hold no account for you, we cannot identify “your” data beyond a report you tell us about. That is a consequence of not collecting anything, and it is the trade we intend.
Cardගොඩ is meant for adults managing their own credit cards and is not directed at children.
If this policy changes in a way that affects what leaves your computer, the change will be described in the release notes of the version that introduces it, not quietly edited in here.
Questions about this policy, or a request to delete something you sent: see the contact page.