Effective June 30, 2026
Cards is published by Goodfoot Media LLC ("Goodfoot," "we," "us"). This Privacy Policy explains what personal information we collect when you use the Cards website and the Cards extension, why we collect it, who receives it, and how long we keep it. It covers customers in the United States, the European Union, and the United Kingdom.
For any privacy question or request, contact us at support@cards.management or by mail at:
Goodfoot Media LLC 250 Mercer St New York, NY 10012 United States
Cards supports individual accounts and individual purchases only. You must be at least 18 years old to use Cards. Cards is not directed to children and we do not knowingly collect personal information from anyone under 18.
Cards is an orchestration tool. It installs a plugin marketplace, writes configuration files, provisions isolated git worktrees, and launches the coding agent you have already installed on your own machine. Cards does not itself run shell commands, modify your workspace files, or call any AI model provider's API.
Your cards — their descriptions, prompts, plans, comments, attachments, and generated outputs — are stored locally as git repositories on your own disk. Goodfoot does not collect that local content. Inference runs through the coding agent and model provider you choose; that traffic goes directly from your machine to that provider under the provider's own terms and privacy practices, and Cards does not see it.
When you register, our authentication provider WorkOS processes your sign-in and returns your name and email address to us. We store your account identifier, name, email, and registration timestamp to create and maintain your account.
If you upgrade to Pro, our payments provider Polar acts as Merchant of Record and processes your payment. Polar handles the hosted payment form and your card details; we do not receive or store full payment card numbers. We retain the billing records (subscription status, invoices, refunds, and chargebacks) associated with your account.
When you create an account, we record that you accepted the Terms of Service: the accepted Terms version, the timestamp, and the acceptance context.
We store the entitlement and license records that determine whether your account has Pro access, and the security claim records used to deliver your license to the extension.
When you contact support or make a privacy request, we keep your message and our correspondence.
Our website and APIs run on Cloudflare. Cloudflare processes request metadata (such as IP address and the derived country) needed to route traffic and protect the service. We receive webhook events from WorkOS and Polar to keep account and subscription state in sync, and we keep security and audit logs of significant account events.
The Cards extension sends sanitized diagnostic and usage telemetry to Microsoft Azure Application Insights to help us find and fix defects and understand which features are used. This telemetry does not include your local card content.
We rely on a small set of providers, each with a specific role:
Goodfoot is not responsible for the acts or omissions of third parties outside its reasonable control. When you independently choose a coding agent, model provider, IDE fork, or other service to use with Cards, that service's own terms and privacy practices govern your use of it; Cards does not control or endorse those independent services.
We use your information to provide and secure Cards, to process payments, to send service and legal notices, to answer support and privacy requests, to keep records required by law, and to improve the product. For users in the EU and UK, our lawful bases under the GDPR and UK GDPR are: performance of our contract with you (account creation, authentication, subscription, and support); compliance with legal obligations (billing, tax, and dispute records); and our legitimate interests in securing the service and improving the product, balanced against your rights.
Goodfoot does not sell personal information, run advertising networks, or share personal information for cross-context behavioral advertising. Cards has no advertising SDK, marketing pixel, or behavioral-advertising integration.
Cards uses only three cookies at launch, all of which are essential to authentication and security. Cards does not use web analytics, advertising, personalization, A/B testing, experimentation, or any other non-essential browser storage. Because these cookies are strictly necessary, Cards does not show an accept/reject banner and does not set a consent-preference cookie. A concise notice appears immediately before sign-in explaining that choosing to sign in causes these essential cookies to be set.
| Cookie | Purpose | Lifetime | Scope | Attributes |
|---|---|---|---|---|
workos_session |
Keeps you signed in by holding your sealed WorkOS session. | Session-length, refreshed while you stay signed in. | Set for the Cards site host. | HttpOnly, Secure, SameSite=Lax. |
oauth_state |
Carries the anti-CSRF state value during the WorkOS sign-in round trip. | Short-lived; cleared once sign-in completes. | Set for the Cards site host. | HttpOnly, Secure, SameSite=Lax. |
auth_claim |
Binds the extension's registration claim to your browser session so the license is delivered to the right install. | Short-lived; cleared once the claim is fulfilled. | Set for the Cards site host. | HttpOnly, Secure, SameSite=Lax. |
If Cards ever introduces non-essential storage, we will update this disclosure and provide a separate consent and preference mechanism before activating it.
Every user, regardless of location, may request access to, correction of, deletion of, or a portable copy of the personal information we control. Additional rights — including objection, restriction, appeal, and the right to complain to a regulator — apply where required by the law that applies to you. This baseline does not mean we voluntarily adopt every jurisdiction-specific regime for every user.
To make a request or appeal, write to support@cards.management. We verify identity through your signed-in account and verified email, aim to respond within 30 days, and will document any extension permitted by applicable law. An appeal receives a fresh review through the same channel. The owner of Goodfoot Media LLC is accountable for handling and documenting requests until that responsibility is formally delegated.
Account deletion is a separate request from canceling Pro. We do not promise immediate or complete erasure. When we process a deletion request, some records may be retained where required or permitted by law — for example billing, tax, fraud, audit, and dispute records — and backup copies expire on our providers' schedules rather than instantly. We will still evaluate and fulfill deletion requests case by case to the extent required by applicable US, EU, and UK law, and we remove direct identifiers when they are no longer necessary for the retained purpose.
Our default retention schedule:
Goodfoot is based in the United States and uses providers that may process data in the United States and elsewhere. Where we transfer personal information from the EU or UK, we rely on the safeguards offered by our providers, including standard contractual clauses where applicable.
This policy describes our current processing. Future optional cloud-hosted, AI, or other features may be governed by supplemental terms and privacy disclosures presented to you before you enable or use them. Supplemental terms apply only prospectively to material you submit under the new feature; no clause retroactively repurposes content collected under an earlier, incompatible privacy representation.
We will provide at least 30 days' advance notice of material changes to this policy by email and through a conspicuous in-product notice. A change that requires your consent will ask for a separate consent action rather than treating silence as acceptance. An urgent legal or security change may take effect sooner when necessary, with prompt notice explaining the timing. Prior versions of this policy, with their effective dates, remain available in our version history; contact support@cards.management for a prior version.