Privacy Policy
Last updated 27 August 2026 · WorldCards for iOS and Android
WorldCards is a travel collectible: you go to a real place, and you collect an illustrated card for it. That requires knowing where you are. It does not require remembering where you have been, and this app does not.
The short version.
We store your email address and the list of cards you have collected. We read your location while the app is open to check that you are near the place you are collecting, and then we discard it — no coordinate you have been at is ever written to our database. We use one analytics tool, PostHog, hosted in the EU, to see how the app is used and to receive crash reports. There is no advertising and no ad-tech tracking. You can delete everything from the Profile tab.
Who we are
WorldCards is published by Keru Studio. For anything in this policy, including a request to access or erase your data, write to privacy@world.cards.
For the purposes of the GDPR, Keru Studio is the data controller for the personal data described below.
What we collect and why
| Data | Why | Legal basis | Kept for |
|---|---|---|---|
| Email address | It is your account. We email you a one-time code to sign you in; there is no password. | Performance of a contract | Until you delete your account |
| Your collection | Which cards you have collected and when, so your collection is there when you sign in on another device. | Performance of a contract | Until you delete your account |
| Display name | Optional. Shown to you in the app; you set it and can change or clear it at any time under Settings. | Performance of a contract | Until you delete your account |
| Set completions | Which sets you have completed, such as your first card in a region. | Performance of a contract | Until you delete your account |
| Approximate location | To show places near you on the map, and to verify you are within range of a place when you collect it. | Performance of a contract | Not stored. Used in the moment, then discarded. |
| How you use the app | Which screens you open and which actions you take — signing in, collecting a card, opening a card, sharing one. We use it to see which parts of the app work and which do not. See Analytics and crash reports. | Legitimate interests — improving the app | 12 months |
| Crash and error reports | When the app crashes or hits an error, the technical details of the failure: the error, where in the code it happened, the app version, and the device model and OS version. | Legitimate interests — keeping the app working | 12 months |
That is the complete list. We do not collect your contacts, your photos, your device advertising identifier, or your browsing behaviour outside this app.
Location, specifically
Location is the sensitive one, so here is exactly what happens.
- Foreground only. The app reads your location only while it is open on screen. It does not request background location permission on either platform, so it cannot read your position when you are not using it.
- Used to draw the map. Your position is used on your device to centre the map and to show which collectible places are near you.
- Used once, to verify a collection. When you collect a card, your current coordinates are sent to our server, compared against the known coordinates of that place, and used to decide whether you are close enough. The result of that check is stored — the coordinates are not. They are not written to any table, and they are not retained in any log we keep.
- No location history exists. Because of the above, there is no record on our servers of where you have physically been. What exists is the list of places whose cards you hold, which is a list of public landmarks, not a trail.
- You can say no. If you decline the location permission, the app still runs — you can browse the map and your collection. You cannot collect new cards, because being there is the game.
Analytics and crash reports
We use PostHog to understand how the app is used and to find out when it breaks. It is the only analytics tool in the app, and it runs on PostHog’s European servers.
- What we record. Events for the things you do in the app: signing in, finishing onboarding, starting and completing a collection, opening a card, opening the share sheet, deleting your account. Each event carries the card involved and its rarity — not your location.
- It is tied to your account. These events are linked to your user account and your email address, so we can tell one person’s session apart from another’s and answer support questions about your own account.
- Crash reports. When the app crashes or throws an error, the report includes the technical stack trace, the app version, and your device model and OS version. It does not include the contents of your collection.
- We do not record your screen. There is no session recording or screen replay in this app. What we receive is the list of events above, and nothing else about what you saw or did between them.
- Never your location. No analytics event or crash report carries your coordinates. The rule in the section above holds everywhere: your position is not written down.
- No advertising. None of this is used for advertising, ad targeting, or profiling, and none of it is sold or shared with anyone beyond PostHog acting on our instructions.
We rely on legitimate interests for analytics and crash reporting: we cannot fix what we cannot see, and the data is limited to what the app itself does. You can object to this at any time by writing to privacy@world.cards, and we will turn it off for your account.
Who else touches your data
We use a small number of service providers, and no others:
| Provider | What for | Where |
|---|---|---|
| Supabase | Our database and sign-in system. Holds your email, your display name, your collection and your set completions. | Frankfurt, Germany (EU) |
| PostHog | Product analytics and crash reports. Receives your email address as your account identifier. | European Union |
| Mapbox | Draws the map. Receives requests for map tiles for the area you are viewing. We have turned off its own usage telemetry. | United States |
| Apple & Google | Distribute the app and may report anonymous crash and performance data under their own policies, subject to your device settings. | Per their policies |
Your account data and your analytics data are both stored in the European Union. Map tile requests reach Mapbox in the United States under their standard contractual clauses. We do not sell your personal data, and we do not share it for advertising or profiling — there is no advertising or profiling in this app.
Your rights
Under the GDPR you have the right to access, correct, export, restrict, object to, and erase your personal data. In practice:
- Erasure. Settings → Delete my account removes your account, your collection and your set completions immediately and permanently. See Deleting your account below.
- Access or export. Email privacy@world.cards and we will send you a copy of everything associated with your account within 30 days.
- Correction. You can change your display name yourself under Settings. To change your email address, write to us.
- Objection. To opt out of analytics and crash reports, write to us and we will disable them for your account. Your collection and sign-in are unaffected.
- Complaint. If you think we have handled your data badly you may complain to your national supervisory authority. In France this is the CNIL.
Deleting your account
You can delete your WorldCards account and everything attached to it from inside the app. It takes effect immediately and cannot be undone.
In the app
- Open WorldCards and go to the Profile tab.
- Tap the gear icon in the top-right corner to open Settings.
- Tap Delete my account.
- Confirm. Your account is erased straight away and you are signed out.
What gets deleted
All of it, permanently:
- Your account, your email address and your display name
- Your entire collection — every card you have collected
- Every set completion you have been awarded
- Your sign-in sessions on every device
We never stored your location, so there is no location history to erase.
Deleting from inside the app does not by itself reach the analytics records held by PostHog, which live outside our database. If you want those erased too, email privacy@world.cards and we will delete them; otherwise they expire on the schedule in the table above. Ask us before you delete your account if you can — once the account is gone we need your email address to find the records.
This is not reversible. A deleted collection cannot be restored, and signing up again with the same email gives you a new, empty account. If you simply want to step away, sign out instead — your collection will be waiting.
Retention after deletion
Deletion is immediate, not scheduled. Your rows are removed from our live database when you confirm. Encrypted database backups are kept for up to 30 days for disaster recovery and then expire, after which no copy of your data remains.
If you cannot reach the app
If you have lost access to your device or cannot sign in, email privacy@world.cards from the address you signed up with and ask us to delete your account. We will confirm your identity by that email address and complete the deletion within 30 days, normally much sooner.
Children
WorldCards is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, write to us and we will delete it.
Security
Traffic between the app and our servers is encrypted in transit. Your sign-in session is held in the iOS Keychain or the Android Keystore, not in ordinary app storage. Every row in our database is restricted at the database level so that one account can only ever read its own data.
Changes to this policy
If we change what we collect, we will update this page and change the date at the top. If the change is significant, we will tell you in the app before it takes effect.