Cardira · Gearoenix Ltd

Privacy Policy

Effective 1 August 2026 · Applies to Cardira for Android and iOS

The short version. Cardira has no server and no accounts. The words you add, your review progress, your dictionaries and your settings are stored only on your own device. We cannot see them, and we never receive them.

The only companies that collect anything are Google (which serves the ads, together with any advertising partners we have switched on) and Apple or Google when you choose to leave a tip. They use your device's advertising identifier and technical data such as your IP address. In the UK, the EEA and Switzerland you are asked for consent before that happens, and you can change your answer at any time.

We run no analytics, no crash reporting and no tracking across other apps or websites. Uninstalling Cardira deletes everything it holds.

1. Who we are

Cardira is published by Gearoenix Ltd, a company registered in England and Wales, company number 17239319, registered office Flat 18 37 Wellington Road, London, England, E6 2DD.

For anything in this policy, write to cardira-privacy@gearoenix.com.

Where we are a controller of personal data, we are the controller for the purposes of the UK GDPR and the Data Protection Act 2018. As explained below, our own processing is very small: the app sends us nothing.

2. What stays on your device

Cardira stores the following in a database and a small settings file inside its own private storage on your device:

None of this is sent to us or to anyone else. There is no account to create, no sign-in, no sync and no backend service. We have no technical means of reading your word list.

3. Advertising

Cardira is free and is funded by advertising and voluntary tips. Ads are served by Google AdMob, and — where we have enabled them — by advertising partners that bid for the same ad space through AdMob Mediation.

These companies act as independent controllers of the data they collect. Typically they collect and use:

Google's own explanation of how it uses this data is at business.safety.google/privacy, and Google's list of the advertising partners it works with is at support.google.com/admob/answer/9012903.

Which partners are switched on

Every advertising partner below is built into the app, but a partner can only receive a request once we activate it in the AdMob console. As at the effective date of this policy, the only advertising partner able to receive a request is Google (AdMob). The remaining partners are integrated and inactive.

Status as at 1 August 2026. This table is updated, and our store privacy disclosures are re-filed, before any partner is activated.
Advertising partnerStatus
Google (AdMob)Active
AppLovinIntegrated, inactive
Meta Audience NetworkIntegrated, inactive
Unity AdsIntegrated, inactive
ironSource AdsIntegrated, inactive
Liftoff MonetizeIntegrated, inactive
PangleIntegrated, inactive
MintegralIntegrated, inactive
InMobiIntegrated, inactive
ChartboostIntegrated, inactive
DT ExchangeIntegrated, inactive
MolocoIntegrated, inactive
PubMatic OpenWrapIntegrated, inactive
BidMachineIntegrated, inactive
myTargetIntegrated, inactive
maioIntegrated, inactive
LY Ads NetworkIntegrated, inactive

Advertising partners are added and removed over time as commercial arrangements change. The list above is the authoritative record of who is active; the current, complete list of partners that Google may pass your data to is maintained by Google at the link above and is presented to you in the consent screen described in section 4.

Where the ads appear

Ad content is capped at the “G” (general audiences) rating for Google-served ads, and we require the same family-safe setting of every partner we activate.

Before Cardira makes any network request to an advertising or billing service, it shows you a first-run screen explaining what is collected, and waits for you to tap Agree & Continue. Nothing loads until you do.

If you are in the UK, the European Economic Area or Switzerland, Google's User Messaging Platform then shows you a consent form built to the IAB Transparency and Consent Framework. That form lists the advertising vendors and purposes, and asks you to consent or refuse. This covers both the UK GDPR requirement for a lawful basis and the requirement in regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 to obtain consent before information is stored on or read from your device for advertising.

To change or withdraw your consent, open Cardira and go to Settings → Ad privacy options. The same form reappears and your new choice takes effect immediately, for the future.

If you refuse, or withdraw later, we do not remove the ads — we ask Google for non-personalised ads instead. Non-personalised ads are chosen from the general context rather than from a profile about you, but they still involve a request to Google containing your IP address and coarse technical data, and Google still stores an identifier on your device for frequency capping and fraud prevention.

You can also use your operating system's own controls at any time:

5. Tips and purchases

Cardira offers optional one-off “tips” to support the work. They unlock nothing — see our Terms of Use.

A tip is sold and processed entirely by the Apple App Store or Google Play using the store's own billing system. We never see or receive your name, card number, billing address or any other payment detail. What we receive from the stores is aggregated sales and payout reporting, which does not identify you.

Your relationship with the store is governed by its own privacy policy: Apple and Google.

Cardira records only a number on your own device: how many tips you have given. That number is not sent anywhere, and because tips are consumable purchases it does not survive reinstalling the app.

6. Opening a dictionary

Cardira's main purpose is to open a word's page on a third-party dictionary website. When you tap Open, the page loads in a browser tab inside the app (Chrome Custom Tabs on Android, Safari View Controller on iOS).

That is ordinary web browsing, and it is initiated by you. The dictionary's website will see your IP address, your browser's user agent and any cookies your browser already holds for that site, exactly as if you had typed the address yourself. Those sites' own privacy policies apply. We do not send them anything about you, we do not tell them the request came from Cardira, and we do not copy, cache or store their content.

If you add your own dictionary, Cardira makes one request to that website to fetch its icon, at the moment you save it. The icon is then cached on your device and never fetched again. We deliberately fetch it directly from the site rather than through a third-party icon service, because a proxy would tell that service which dictionaries you read.

7. What we deliberately do not do

8. Permissions

Cardira is designed so that you are never shown an operating-system permission dialog.

On Android the app declares only install-time permissions that are granted silently and never prompt: INTERNET and ACCESS_NETWORK_STATE; com.google.android.gms.permission.AD_ID and the related ACCESS_ADSERVICES_* permissions used by Google Mobile Ads; and com.android.vending.BILLING used by Google Play billing. Location, storage and notification permissions that advertising SDKs would otherwise add are explicitly removed from the app's manifest.

On iOS the app requests no privacy-gated capability at all — no App Tracking Transparency prompt, no notifications, no photo or file access.

9. Backups, export and import

Export is always something you start. From Settings you can export your words and your own dictionaries to a JSON file. The file is written wherever you choose using your device's own file picker or share sheet, which is why no storage permission is needed. Once the file leaves the app it is yours; where you save it, and who you send it to, is under your control, not ours. Import works the same way in reverse and merges a file you select into the app.

Because there is no server, your device holds the only copy of your data. Cardira's database is included in your operating system's ordinary device backup (Android Auto Backup, or an iCloud or computer backup on iOS) if you have that enabled. Those backups are handled by Google or Apple under their own terms; we have no access to them.

10. Deleting your data

Uninstalling Cardira deletes everything it holds — your words, your progress, your own dictionaries, your settings and your supporter tally. There is nothing left behind on a server, because there is no server, and there is no account for us to close.

Any export file you created yourself stays where you put it; delete it in the usual way if you no longer want it.

To have the advertising data held by Google or an advertising partner deleted, you need to ask that company — it is theirs, not ours. Google's controls are at myadcenter.google.com. Resetting your advertising ID on your device breaks the link between the old identifier and any future data.

11. Children

Cardira is intended for users aged 13 and over (16 and over where local law sets a higher age for consent to this kind of processing). It is not directed to children, it is not listed in any children's category, and it is not part of Google Play's Designed for Families programme.

We do not knowingly collect personal data from children. Because we hold no user data at all, there is nothing for a parent to request from us; if you believe a child has used the app and you want the advertising data associated with the device removed, reset the device's advertising ID and contact Google. If you have a concern, write to cardira-privacy@gearoenix.com.

12. Lawful bases

Under Article 6 of the UK GDPR, the processing connected with Cardira breaks down as follows.

WhatWho processes itLawful basis
Your words, progress, dictionaries and settings Nobody but you. The data stays in the app's private storage on your device. Not our processing — no personal data reaches us. Storing it on your device is strictly necessary to provide the service you asked for, so no separate consent is required under PECR reg. 6(4).
Serving ads, and storing or reading the advertising identifier for that purpose Google and any active advertising partner, as independent controllers. We decide to include them, so we are accountable for asking you first. Consent — Article 6(1)(a) UK GDPR and regulation 6 PECR, collected through the first-run gate and Google's consent form, and withdrawable at any time (section 4).
Non-personalised ads where you refuse or withdraw consent, and detecting invalid traffic and ad fraud Google and any active advertising partner Legitimate interests — Article 6(1)(f): security, fraud prevention and frequency capping. You can object; see section 15.
Taking payment for a tip Apple or Google, as the seller and merchant of record Contract — Article 6(1)(b), between you and the store. We receive only aggregated reporting.
Answering an email you send us Gearoenix Ltd Legitimate interests — Article 6(1)(f): responding to the enquiry you chose to send. Where the email is a data-rights request or a legal notice, legal obligation — Article 6(1)(c).

We do not process special category data, we make no automated decisions producing legal or similarly significant effects, and there is no profiling by us.

13. International transfers

We transfer nothing ourselves, because we receive nothing. The advertising and billing companies described above are global and will process data outside the United Kingdom, including in the United States. They do so under their own transfer arrangements — typically the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, and, for certified US recipients, the UK Extension to the EU–US Data Privacy Framework. Their privacy policies, linked above, set out the current position.

14. Retention

15. Your rights

Under the UK GDPR you have the right to be informed, and rights of access, rectification, erasure, restriction, portability and objection, as well as the right to withdraw consent at any time.

The honest position is that we hold almost nothing to exercise them against. Your learning data is on your device, under your control: you can read it, correct it, export it and delete it inside the app without asking us. If you have emailed us, we do hold that correspondence, and those rights apply to it in the ordinary way.

Where the data is held by Google, Apple or an advertising partner, they are the controller and you will get a faster and more complete answer by going to them directly. We will help you work out who to ask if that is not obvious.

To exercise a right, email cardira-privacy@gearoenix.com. We do not charge for this and we will respond within one month, which we may extend by up to two further months for complex requests — we will tell you if that happens and why.

16. Complaints

Please tell us first. If you think we have handled your data badly, email cardira-privacy@gearoenix.com with “Data protection complaint” in the subject line. As required by the Data (Use and Access) Act 2025, we will acknowledge your complaint within 30 days, look into it without undue delay, keep you posted if it takes longer than expected, and tell you the outcome.

You do not have to come to us first, and complaining to us does not affect your right to complain to the regulator. You can contact the Information Commissioner's Office:

If you are in the EEA you may instead complain to your own national supervisory authority.

17. Third-party brands and icons

Cardira is an independent app. It is not affiliated with, endorsed by, or sponsored by any of the dictionaries it links to. All product names, logos and brands are the property of their respective owners.

Each dictionary is shown by its unmodified icon at icon size together with its plain-text name, purely so you can tell which site a word will open in. We ship no artwork derived from anyone else's icon or logo.

If you own a brand shown in the app and would like its icon removed, email cardira-privacy@gearoenix.com and we will remove it within five working days. You do not need to send a formal notice, and we will not argue the point first.

18. Changes to this policy

If we change this policy we will update the effective date at the top, and keep the previous version available on request. Where a change is significant — for example, activating a new advertising partner — we will update this page and re-file our Google Play Data safety and Apple App Privacy disclosures before the change takes effect, and, where the law requires it, ask for your consent again through the in-app consent form.

19. Contact

Gearoenix Ltd
Flat 18 37 Wellington Road, London, England, E6 2DD
Company number 17239319
cardira-privacy@gearoenix.com