Privacy Policy
This Privacy Policy explains how Sanchivo handles information in connection with Cardypedia, including its online features, advertising, support services, and related website.
1. Who we are
Cardypedia is operated under the Sanchivo developer name. This policy applies to the Cardypedia mobile application and the related Sanchivo support and policy pages.
For privacy questions or requests, contact support@sanchivo.com.
2. Information we handle
Account and authentication information
Cardypedia supports Guest accounts and Google Sign-In. When you use Google Sign-In, authentication information and basic account information made available through Google, such as an account identifier, email address, and display name, may be processed to sign you in and create or identify your Cardypedia account. Google authentication is also used with Firebase Authentication when required for supported account features such as profile photo storage.
For Guest accounts, Cardypedia creates an app-generated identifier on your device. This identifier is used to maintain the Guest account and is not your IMEI, phone number, or another hardware identifier. A Guest label is derived from this identifier for account use.
Profile and social information
We process information needed for Cardypedia profiles and social features, which may include your internal user identifier, Cardypedia ID, display name, selected avatar, optional profile photo, avatar frame, friends, friend requests, blocked users, recent players, invitations, and online or in-game activity status.
Profile information such as your Cardypedia ID, display name, avatar or profile photo, and avatar frame is intended to be visible to other Cardypedia users where the app displays your public profile or table identity. The recent-players feature is limited to a recent set of players rather than an unlimited history.
Profile photos
Profile photo upload is available only to supported Google-signed-in accounts. If you choose a photo from your device, Cardypedia processes the selected image, crops and resizes it, and converts it to a JPEG before upload. The app requests the selected image rather than full image metadata. Uploaded profile photos are stored using Firebase Storage and are intended to be visible as part of your public Cardypedia profile.
Online gameplay and activity information
When you use online play, we process information necessary to create and join rooms, reserve seats, run matches, reconnect players, enforce game rules, show presence, handle invitations, maintain relevant game results or statistics, and protect the service from abuse. This may include user identifiers, game and match identifiers, room access settings, seat and turn state, timestamps, connection events, results, and other gameplay events required to operate the game.
Direct messages and room chat
Cardypedia includes direct messages and in-room chat. Direct-message conversations are stored on the Cardypedia backend and are currently limited to the latest 80 messages per conversation; older messages are removed from that conversation history as the limit is exceeded.
Room chat is handled as temporary match history. The active match keeps up to the latest 50 room-chat messages so current or reconnecting players can see recent table conversation. Room chat is not stored as a general persistent chat history in the social backend. However, if a room-chat message is reported, a snapshot of that message and its context may be stored as part of a moderation report.
Messages are visible to their intended recipients or room participants. Please do not include sensitive personal information in messages or public profile fields.
Reports, moderation, and safety records
If a player, profile, chat message, or gameplay event is reported, we may store the report reason, reporter and reported-user identifiers, limited profile snapshots, relevant message content, game or match context, timestamps, report status, and information needed to detect duplicate or abusive reporting. These records are used for moderation, safety, abuse prevention, dispute handling, and enforcement of our rules.
Advertising and consent information
Cardypedia uses Google Mobile Ads (AdMob) to display advertising and Google User Messaging Platform (UMP) to manage privacy and consent choices where required. Depending on your device, region, consent choices, and Google SDK configuration, Google Mobile Ads may process data such as IP address (which may be used to estimate general location), advertising or app-set identifiers, ad and app interactions, and diagnostic or performance information for advertising, analytics, ad measurement, and fraud prevention.
Where required, Cardypedia requests updated consent information and displays Google's consent or privacy-options interface. Advertising is requested only when the Google consent system indicates that ad requests are permitted. Available ad modes and data use may vary according to your choices and applicable law.
Support and account-deletion communications
If you contact Sanchivo for support, we process the information you provide, such as your email address, selected support category, message content, screenshots or attachments you choose to send, and information needed to investigate and respond to your request.
When you use the support form on sanchivo.com, the form sends your email address, selected support category, and description through a Sanchivo support endpoint hosted on Cloudflare. When you use the web account-deletion request form, it sends your email address, any Cardypedia ID you choose to provide, and any optional deletion reason through the same protected support infrastructure. Cloudflare Turnstile is used to help detect automated abuse, and Resend is used to deliver these requests to support@sanchivo.com. These providers may process ordinary request, security, and delivery metadata as needed to provide and protect those services.
Technical and local device information
Cardypedia stores certain information locally on your device, including app preferences, authentication state, the app-generated Guest identifier where applicable, and session information. Nakama authentication and refresh tokens are stored using secure device storage.
Our backend, hosting, network, and advertising providers may also process ordinary technical information such as IP address, timestamps, request or connection metadata, device or app information, and error or diagnostic information as needed to deliver, secure, troubleshoot, and protect their services.
3. How we use information
We use information described in this policy to:
- authenticate users and maintain Guest or Google-linked Cardypedia accounts;
- provide online games, matchmaking, rooms, reconnect, invitations, profiles, and social features;
- display public profile information and recent-player information to other users where appropriate;
- provide direct messaging and room chat;
- operate reporting, moderation, blocking, safety, and anti-abuse systems;
- provide and measure advertising and manage privacy choices;
- respond to support requests;
- maintain service reliability, security, fraud prevention, and troubleshooting; and
- comply with applicable legal obligations and enforce our terms and rules.
4. When information is shared
We do not publish private account data as a general directory. Information is shared only as needed for the features and services described in this policy, including with:
- Other Cardypedia users, for public profile information, table identity, game activity, room chat, direct messages, and other social interactions you use;
- Google services, including Google Sign-In, Firebase Authentication, Firebase Storage, Google Mobile Ads, and UMP, when those services are used;
- Hosting, security, and support-delivery providers, including Cloudflare for website hosting, security, the support endpoint and Turnstile, and Resend for delivery of website support requests;
- Authorities or other parties when legally required, or when reasonably necessary to protect users, Sanchivo, or the service from fraud, abuse, security threats, or unlawful activity.
We do not directly sell Cardypedia account or profile information for money. Advertising providers may process or disclose data for advertising purposes as described above, and some jurisdictions may legally classify certain advertising-related disclosures as a "sale" or "sharing." Where applicable, privacy and consent choices are provided through the available Google privacy controls.
5. Data retention
We keep account, profile, social, and gameplay-related information for as long as reasonably necessary to provide the service, maintain account features, protect the service, or meet legal obligations. Different categories have different retention behavior:
- Direct-message conversations are currently capped at the latest 80 messages per conversation.
- Room chat is temporary match history and is currently capped at the latest 50 messages within the match state.
- Presence and some invitation or operational records are short-lived and expire as part of normal service operation.
- Moderation and abuse-prevention records may be retained for as long as reasonably necessary for safety, enforcement, dispute handling, fraud prevention, or legal obligations.
- Support correspondence may be retained as needed to resolve requests, maintain support history, prevent abuse, or meet legal requirements.
We do not promise a fixed retention period where the service does not currently enforce one. Where backups, security logs, or provider records exist, deletion from those systems may not be immediate and copies may remain until they are overwritten, rotated, or otherwise removed in the ordinary course, subject to applicable law.
6. Account deletion
Cardypedia provides an in-app account deletion flow. If you cannot access the app, you can also submit a manual deletion request through our Account Deletion page. A web request does not automatically delete an account; Sanchivo may require reasonable account-specific verification before completing a manual deletion.
When an online Cardypedia account is deleted, the backend deletes the account and its user-owned profile, social-state, and activity records. The service also attempts to remove the deleted user from related friend requests, friend lists, block lists, recent-player entries, invitation relationships, and associated direct-message conversations. For Guest accounts, the locally stored Guest identifier and Guest label are also removed when the account deletion process completes.
If a Google-signed-in account has an uploaded profile photo, Cardypedia attempts to remove the active Firebase Storage avatar as part of account cleanup. This remote cleanup is best-effort; if an automatic deletion cannot be completed, residual data may persist temporarily until it can be removed or expires through provider or operational cleanup.
Deleting an account does not necessarily delete moderation, safety, fraud-prevention, legal, dispute, or security records that must reasonably be retained for those purposes. Such retained records are not used to recreate the deleted Cardypedia account.
7. Your privacy choices and rights
Depending on your location, you may have rights to request access to, correction of, deletion of, restriction of, objection to, or portability of certain personal information, and to withdraw consent where processing is based on consent. These rights may be subject to legal exceptions.
You can change supported advertising privacy choices through the privacy-options interface in Cardypedia when Google UMP indicates that such an entry point is required. You may also control certain advertising identifiers through your Android device settings.
To make a privacy request, contact support@sanchivo.com. We may need to verify that the request relates to the correct account before acting on it.
8. Legal bases for EEA and UK users
Where the GDPR or similar law applies, our processing may rely on one or more of the following, depending on the activity: performance of the service you request, legitimate interests in operating and securing Cardypedia and preventing abuse, consent where required (including certain advertising choices), and compliance with legal obligations.
9. International processing
Cardypedia uses online service providers that may process information in countries other than the country where you live. Where required by applicable law, we and our providers use appropriate safeguards for international data transfers.
10. Security
We use reasonable technical and organizational measures designed to protect information, including access-controlled backend records and secure on-device storage for authentication tokens. No system or method of transmission can be guaranteed to be completely secure.
11. Children
Cardypedia is not intended to knowingly collect personal information from children in a way that violates applicable law. If you are a parent or guardian and believe a child has provided personal information in circumstances that require parental consent, contact us so we can review the situation and take appropriate action.
12. The Sanchivo website
The Sanchivo website does not operate its own user accounts or first-party analytics system. Most pages are static. The Support and Account Deletion pages include request forms that send the information you enter to a Sanchivo support endpoint hosted on Cloudflare and then, after security checks, to our support mailbox through Resend.
Cloudflare may process ordinary request data such as IP address, browser or request metadata, and security signals to deliver and protect the website and support endpoint. Cloudflare Turnstile also processes security signals to distinguish legitimate users from automated abuse. Support and account-deletion correspondence may be retained as described in the Data retention section above.
13. Third-party privacy information
Third-party services process information under their own terms and privacy documentation where applicable. You can learn more from Google's privacy and product documentation, including:
- Google Privacy Policy
- Firebase privacy and security information
- Google Mobile Ads data disclosure information
14. Changes to this policy
We may update this Privacy Policy when Cardypedia's features, service providers, legal requirements, or data practices change. The "Last updated" date at the top of this page shows when the policy was most recently revised. Material changes will be reflected in the published policy and, where required, communicated through the app or another appropriate method.
15. Contact
For privacy questions, account-deletion assistance, or privacy-rights requests, contact: support@sanchivo.com.