Version 1.2 • Last updated 25 July 2026 • Effective immediately • Applies to the Cardeem Android app (com.cardeem.app)
1. Who We Are
MaxLeaf builds Cardeem, a reminder app for credit-card benefits: it helps you use the milestone rewards, lounge visits, fee waivers, and cashback caps your cards already give you, before they reset or expire. Because Cardeem collects no personal data, MaxLeaf acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 only in respect of the anonymous crash reports described in Section 4.
2. What Cardeem Is Not
- Not a bank, NBFC, or credit information company. Cardeem offers no financial products, facilitates no transactions, and is not regulated by the Reserve Bank of India. It is an informational reminder tool.
- Not connected to your bank. Cardeem has no integration or data relationship with any card issuer. We receive nothing from your bank, and your bank is never told you use Cardeem.
- Not a wallet or payment app. No cardholder data as defined by PCI-DSS — card numbers, CVVs, expiry dates — is ever collected, processed, or stored, by design. There is no field in the app that could accept a card number.
- Not an SMS or inbox reader. Unlike many finance apps, Cardeem never requests SMS, call-log, contacts, location, camera, or microphone permissions. It does not read your transaction messages or emails.
3. What the App Stores (On Your Device Only)
- The list of credit cards you select from our catalog (card names only — never numbers)
- Optional details you add: nicknames, card-open month, statement day, annual-fee override
- Your reminder preferences and offer notes
- Which offers you marked as used, and app settings
None of this leaves your device. Cardeem works fully offline. Reminders are generated and scheduled locally on your phone — there is no push-notification server that knows what your reminders say.
4. The One Thing That Leaves Your Device: Crash Reports
If the app crashes, a technical crash report is sent to Sentry (our error-monitoring provider, hosted in the European Union) so we can fix bugs. Before sending, the app scrubs the report of personal identifiers. Crash reports are not linked to your identity (there are no identities — the app has no accounts), are never sold or shared for advertising, and are automatically deleted within 90 days.
5. What We Never Collect
- Card numbers, CVVs, expiry dates, balances, statements, or transactions
- Bank or issuer credentials of any kind
- Your name, email, phone number, contacts, photos, or location
- Advertising identifiers — Cardeem contains no ads and no analytics SDKs
6. Data Deletion
Uninstall the app (or clear its storage in Android settings). That is a complete and permanent erasure — there is no server-side copy to ask us to delete.
7. Your Rights (India — Digital Personal Data Protection Act, 2023)
Because Cardeem stores your data only on your own device and collects no personal data, the practical exercise of access, correction, and erasure rights is direct: the data is in your hands, and deletion is uninstallation.
8. Children's Privacy
Cardeem deals with credit-card products and is not intended for, or directed at, anyone under 18. We do not knowingly collect any data from minors (we collect no personal data from anyone). The app's Google Play listing is restricted to users aged 18 and over.
9. Grievances
For any privacy question or grievance, write to support@maxleaf.in with the subject "Cardeem privacy". We aim to respond within 72 hours and resolve grievances within 30 days. If you believe your grievance has not been resolved, you may escalate to the Data Protection Board of India under the DPDPA, 2023.
10. Changes to This Policy
If a future version of Cardeem adds accounts or sync (it may), this policy will be updated first, the in-app disclosure will change, and nothing will be collected without the updated policy being published at this URL.