InCardible InCardible
Security Pricing
Download App
Privacy Policy

Your data, your control

Last updated: April 2026

What we collect

InCardible collects only the financial data necessary to provide credit card reward tracking and optimization. This includes:

  • Credit card statement and transaction alert emails — we extract the subject line, date, and financial amounts only
  • Card information — issuer name, card network, and last 4 digits of your card number
  • Transaction data — amount, merchant name, date, and spending category
  • Google account profile — name, email address, and profile picture (via Google OAuth)

What we do NOT store

We are deliberate about minimizing stored data. InCardible does not store:

  • Full email bodies — only parsed financial fields are retained
  • Banking passwords or credentials of any kind
  • Full credit card numbers — only the last 4 digits
  • CVV, PIN, or any card security codes

How your data is protected

  • OAuth tokens are encrypted with AES-256 at rest
  • All data in transit is protected via HTTPS/TLS
  • We request the minimum Gmail scope required — gmail.readonly
  • Database access is restricted to application-level service accounts with least-privilege permissions

Gmail access

InCardible requests read-only access to your Gmail account to identify and parse credit card statement and transaction alert emails. We never send, delete, or modify any emails in your inbox. The Gmail readonly scope is the only permission we request, and you can revoke it at any time from your Google account settings.

InCardible's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

AI processing

Transaction data may be processed by AI/LLM models for categorization, reward calculation, and personalized recommendations only in closed env. This processing is performed solely to deliver our service to you. Your data is not used for model training or shared with AI providers for their own purposes.

Third-party sharing

We do not sell, rent, or share your personal financial data with third parties. We may use third-party infrastructure providers (hosting, database) to operate the service, subject to their own privacy policies and our data processing agreements.

Contact

If you have questions or concerns about this privacy policy, please contact us at incardible.app@gmail.com.

Home · Terms of Service