Skip to content
CardCura

Privacy Policy

Effective September 10, 2026

This policy explains what CardCura, operated by OpenKedge LLC, collects, why it is used, when it is disclosed, how long it is kept, and the controls available to adults managing a child profile.

Key points

  • CardCura collects limited child profile and family-ledger information under adult control.
  • Adults can record program attendance and optional notes; a paired child device can submit routine check-ins.
  • Child photos are optional; advertising, data sales, and bank connections are not part of the service.
  • A family admin can permanently delete a child profile, and adult-account closure is available by verified request.

The short version

CardCura collects limited information to provide a parent-controlled allowance, routine, and savings ledger. Most child information is entered by an adult, but a paired child device can submit routine check-ins and uses a short-lived session identifier.

  • We do not sell personal information, use it for targeted advertising, or show ads.
  • We do not connect to a bank or collect card, bank-account, or routing numbers.
  • A child does not create an account, provide an email address, or type free-form text into the Kid Portal.
  • A custom child photo is optional, Premium-only, and controlled by a family admin.
  • Parents can review, correct, archive, and permanently delete a child profile.

Who this policy covers

CardCura is operated by OpenKedge LLC. This policy covers the public website, Parent Hub, Kid Portal, family invitation flow, shared savings-goal pages, and related support communications.

The service is designed for adults managing family information for children roughly 4 to 10 years old. An adult creates and controls every child profile. Children cannot create accounts.

Information we collect

We collect the categories below. Some are personal information under child-privacy laws even when they are deliberately limited.

  • Adult account information: email address, display name, chosen avatar, password hash, account role, family relationships, and session records.
  • Child profile information: a nickname or first name, birth month and year, optional birth day, illustrated avatar, active theme, and optional custom avatar photo uploaded by a Premium family admin.
  • Family activity: routines, routine check-ins, rewards, purchases, balances, savings goals, quick-entry text, recurring-reward schedules, program schedules, attendance, optional star ratings and notes, approval requests, notifications, and the adult associated with an action.
  • Access and invitation information: family roles, invitation records, QR-pairing records, hashed session tokens, expiry and revocation times, and last-seen times.
  • Subscription information: plan status and, when a billing provider is used, provider profile, product, renewal, activation, and expiry details. CardCura does not receive the full payment-card number.
  • Support information: messages and any information you choose to include when contacting us.
  • Technical information: standard request and security logs may include an IP address, browser or device information, requested URL, and timestamp.

Where information comes from and how we use it

Adults provide account, child-profile, family-role, ledger, routine, goal, program, attendance, rating, and note information. A paired child device provides routine check-ins and presents its session cookie when requesting the Kid Portal. Service infrastructure generates security and access records.

We use this information to authenticate users, show the correct family data, calculate balances and progress, route approvals and notifications, operate Premium features, secure and troubleshoot the service, respond to support requests, and meet legal obligations.

We do not use child information to build advertising profiles, serve targeted ads, or train an advertising system.

Children, parent direction, and consent

A parent or other authorized adult creates each child profile and initiates device pairing. By adding a child or optional photo, the adult confirms they are authorized to provide and manage that information.

The Kid Portal is intentionally limited. A child can view their own balance, routines, goals, and transaction history and can mark a routine complete. That check-in is a request for adult review; it does not change the balance by itself. The Kid Portal has no free-text field, family-management control, purchase control, or account-creation flow.

A paired child session stops working after 12 hours and does not renew itself through ordinary use. A parent can revoke it sooner.

Parents may review, correct, or permanently delete child information in the Parent Hub, refuse further collection by revoking paired sessions, or contact privacy@cardcura.com for assistance.

When information is disclosed

We disclose information only as needed to operate the service, at an adult user’s direction, or for legal and safety reasons.

  • Authorized family members see only the children and actions allowed by their Family admin, Guardian, Contributor, or Viewer access.
  • A paired child device sees only that child’s Kid Portal information.
  • Hosting, database, security, support, and billing providers may process information under contract to provide their services to us.
  • We may disclose information when required by law, to investigate abuse or security incidents, or to protect a child or another person.
  • If the business is reorganized, acquired, or sold, information may transfer with the service subject to this policy and applicable law.
  • We do not sell personal information or disclose it for cross-context behavioral advertising.

Cookies and session identifiers

CardCura currently uses two strictly necessary cookies: an adult Parent Hub session lasting 30 days and a paired Kid Portal session lasting 12 hours. Both contain random secrets and are unavailable to page JavaScript.

We currently use no analytics, advertising, retargeting, or cross-site tracking cookies. The Cookie Policy lists each cookie and its purpose.

How long we keep information

Child profiles, ledgers, routines, goals, programs, attendance, and related family records are kept while the family uses the service. Archiving is reversible and does not delete information. The service has no automatic child-profile deletion date because an ongoing family ledger is the purpose for which the information is kept.

A family admin can permanently delete an archived child. That removes the child row and dependent ledger, goal, routine, program, attendance, approval, notification, and paired-session records from the active database.

Adult account information is kept while the account remains open. Account closure is currently handled by a verified request to our privacy email; it is not yet available as an in-app button.

Session credentials stop authorizing access when they expire or are revoked. We may retain limited security, legal, fraud-prevention, and backup records for as long as reasonably necessary for those purposes, then delete or de-identify them.

How we protect information

Passwords are stored using scrypt hashes. Session secrets are stored as SHA-256 hashes rather than in reusable plaintext. Access checks run on the server against the signed-in adult’s role or the paired child session.

Custom avatar photos are cropped and compressed in the browser before upload and are served only after an authorization check. Public savings pages do not select them.

No service can guarantee absolute security. Please use a unique password, protect pairing codes and shared links, and contact us if you suspect unauthorized access.

Your choices and privacy requests

All families may ask to access, correct, or delete personal information, regardless of where they live. We may need to verify the adult account and authority over a child before completing a request.

  • Edit child profile details and illustrated avatars in the Parent Hub.
  • Remove an optional custom child photo.
  • Revoke a paired child device and create a new pairing code.
  • Archive or permanently delete a child profile.
  • Remove an invited adult or change their role.
  • Email privacy@cardcura.com to request adult-account access, correction, or closure, or to raise a child-privacy concern.

Changes to this policy

We will update this page and its effective date when the policy changes. If a material change affects how child information is collected, used, or disclosed, we will provide additional notice to the responsible adult and obtain any consent required by law before applying the new practice.

Operator and contact information

CardCura is operated by OpenKedge LLC. Contact us about privacy, child information, access, correction, or deletion using the details below.

  • Email: privacy@cardcura.com