CCardo
Last updated 24 August 2026

Privacy should be understandable.

Cardo is made and operated by Mikhail Baikenov, an individual, who is the data controller for everything described here. Questions, requests for a copy of your data, and requests for erasure can be sent to hello@cardo.cards, and are answered within 30 days.

The short version

  • You can use the mobile app without an account. In that case, cards and learning history stay on that device.
  • A photo is sent for recognition only after the in-app disclosure is accepted. Recognition requests are processed transiently.
  • If you sign in and cloud photo backup is enabled, your personal photo cards are stored privately and delivered through short-lived signed links.
  • The browser extension saves only encounters you explicitly catch. It does not upload your full transcript, video, screenshot, or browsing history.
  • You can delete individual cards and their backed-up media, or delete the account from inside the app.

Data Cardo processes

Cards and learning

Card text, language pair, examples, deck membership, review schedule, achievements, XP and learning events. Without an account these are local. With an account, private decks and cards can sync through Cardo’s Supabase service.

Photos

For recognition, the selected image passes through Cardo’s server to Google Gemini and is not intentionally retained as a recognition request. If the signed-in user keeps cloud photo backup enabled, a copy is stored in a private Backblaze B2 bucket. The app obtains it through an expiring signed URL after account authorization.

Voice and audio

When you use dictation or speaking exercises, the recording is sent to Cardo’s server and the configured speech provider for transcription. Cardo does not intentionally keep the raw recording after the request. Generated pronunciation audio may be cached.

Browser extension

When you choose “Save to Cardo”, the extension may store the selected word, surrounding sentence, page title and URL. On YouTube it can also store the video id and timestamp. The extension reads captions visible to its learning layer, but does not upload or save the entire transcript, a video frame, or general viewing history. Dictionary lookups may use Wiktionary; translated examples may use Tatoeba and are attributed at the sentence level.

Account, purchases and diagnostics

Email and authentication identifiers are processed by Cardo’s Supabase authentication service. Subscription status is checked with RevenueCat. Product analytics events and crash diagnostics may include app version, action names and technical error details; they should not include photo bodies, audio bodies, passwords or full private context.

Why and how long

Data is processed to provide cards, sync, scheduling, subscriptions, security and product reliability. Local data remains until you remove it or the app. Cloud cards and private media remain until you delete the card or account. Operational security logs and anonymous product metrics may be retained for a limited period defined in production operations.

Your choices

  • Decline or withdraw photo recognition in Settings.
  • Turn cloud photo backup off in Settings.
  • Use Cardo without signing in.
  • Delete a card, which also requests deletion of its backed-up media.
  • Delete the account in the Account screen.
  • Request access, correction, export or deletion at hello@cardo.cards.

Children and international processing

Cardo is not directed to children under the minimum digital-consent age applicable in their country. Service providers may process data outside your country using the safeguards made available by those providers and applicable law.

Changes

Material changes will update the date above and, where required, be shown in the app before the changed processing begins.