Cardstock: Habit Cards
Last updated: October 10, 2026
This policy describes the iOS app Cardstock, listed on the App Store as “Cardstock: Habit Cards.” It covers the app only. The AboveTheFold.dev website has its own policy at /privacy.
Cardstock is published by AboveTheFold.dev, Athens, Greece. For this policy, AboveTheFold.dev is the controller of the personal information described here. Contact us at hello@abovethefold.dev or through the contact form.
Cardstock stores these things in the app on your device:
We do not run accounts, and we do not receive a copy of your cards. We do not have our own analytics or crash reporting. Habit names, marks, and drawings are not sent to us.
If you’re signed into iCloud, your cards sync through your private iCloud account. Turn it off in iOS Settings → [your name] → iCloud.
The app has no sync switch of its own. When iCloud is available for Cardstock, cards sync in your private iCloud database. We cannot read that database. If you are not signed into iCloud, or iCloud is off for the app, cards stay on that iPhone only.
Apple’s privacy policy is at apple.com/legal/privacy.
Reminders are scheduled on your iPhone. There is no push-notification server.
The Deck is an optional purchase through Apple. Apple charges your Apple ID. We never see your payment card number. The price is shown in the app before you pay.
Two companies process purchase and paywall data so the purchase can be unlocked and the paywall can be shown. They do not receive habit names, X or O marks, or drawings. We do not sign you in with them, and we do not send them your name or email.
RevenueCat records purchase and subscription transactions. Its SDK also uses an anonymous app user ID, plus device and app information such as device type and operating system. RevenueCat’s own description of end-user data is device and operating-system details, and transaction details such as the time the app was last used and the Apple receipt. RevenueCat does not collect health data, payment card numbers, or precise location.
Superwall shows the paywall. Its SDK collects paywall and usage events, an anonymous app user ID, and device attributes. Those attributes include a vendor identifier, device model, locale, app version, subscription status, and similar technical details. Superwall also derives region, country, and city from the IP address. It does not receive the contents of your cards.
Purchase data handled by Apple and RevenueCat is used to provide the purchase you asked for. That is performance of a contract (GDPR Article 6(1)(b)).
Paywall and usage events handled by Superwall are used to operate and improve the purchase flow. That is a legitimate interest (GDPR Article 6(1)(f)).
iCloud sync happens in your own private iCloud account. Apple provides that sync to you, and we cannot read it.
We do not sell your information. We do not share it for cross-context behavioral advertising. We do not use it to track you across other companies’ apps and websites for advertising. The app opens a web address on its own only when you tap a link, such as this page.
Cards remain on your iPhone, and in your iCloud account when sync is available, until you delete them. We have no server copy of your cards to erase.
Apple and RevenueCat keep purchase records for as long as they need them to provide the purchase, prevent fraud, and meet legal duties. Superwall keeps the paywall data described above under its own policy.
Deleting the app and the iCloud copy removes the cards. Apple may still keep its own record of a purchase. Apple’s refund and purchase tools remain Apple’s.
Cardstock is not directed at children under 13. We do not knowingly collect personal information from children under 13.
Where the GDPR or UK GDPR applies, you can ask to access, correct, delete, or restrict your personal information, object to certain uses, and ask for a copy in a portable format. You can also complain to your data protection authority. In Greece, that is the Hellenic Data Protection Authority.
To make any of these requests, email hello@abovethefold.dev. We reply within 30 days. Because we hold no account or copy of your cards, most requests about card data are handled by deleting the app and its iCloud copy. Purchase records are kept by Apple and RevenueCat, and we can help you reach them.
Where the CCPA applies, you can ask what personal information is collected, ask for deletion or correction, and opt out of the sale or sharing of personal information. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
This page is the current policy. When it changes, the new text is posted here. If you keep using Cardstock after that change, the updated policy applies.