Privacy Policy
CardAssist Online is operated by NK Advisory. This policy explains what we collect, why, and how to delete it. Plain English, no dark patterns.
What we collect
When you sign up we store your name, email, and (for password accounts) a salted+hashed password. If you sign in with Google we store your Google profile name and picture URL — we never see your password.
Once you start using the product we store:
- Which cards from our catalog you've added to your wallet.
- Transactions you log (amount, merchant, category, MCC, mode, the card used). We never store card numbers.
- Goals, milestone progress, leakage events you've dismissed.
- If you install the Chrome extension: anonymised telemetry about cart totals and which routing hint we surfaced (no merchant secrets, no PII).
How we use it
Strictly to power CardAssist Online for you: ranking cards, computing rewards, surfacing milestone progress, and producing leakage insights. We don't sell or share any of it.
We use OpenAI for the AI assistant feature only when you explicitly chat with it; in that case your message is sent to OpenAI under their data-processing terms. The rest of the product runs on deterministic math — no AI inference required.
Deleting your data
You can delete individual transactions and milestones from the app at any time. To delete your entire account, email info@cardassist.online from the email address on the account — we'll permanently wipe it within 7 days and send you a confirmation.
Security
Passwords are hashed with bcrypt. Sessions are bearer JWTs scoped to your account. We host on hardened cloud infrastructure with TLS in transit. As of beta we recommend not storing anything you wouldn't comfortably keep in a spreadsheet.
