GDPR — your data rights
Updated: 2026-09-23
Your data is processed under the General Data Protection Regulation. Here is what rights you have and how each of them is met.
Data controller
Dalius Dobravolskas, trading as ffff.lt, Lithuania. For anything about your data, write to info@ffff.lt.
Processors
Hetzner Online GmbH (Industriestrasse 25, 91710 Gunzenhausen, Germany). Its machine runs the application, the database files and the mail server the sign-in links come from: it is all one server. There is an Article 28 data processing agreement with them.
Google Ireland Limited, in the narrow sense that your browser fetches the site's typefaces from Google Fonts and Google therefore logs the request — your IP address and browser. Nothing about your account or your projects is sent with it.
Because the server stands in the European Union, Card-a-mon does not transfer your projects and artwork to third countries. There are no other processors: no analytics, no advertising, no mail-sending service, no backups in anybody else's cloud.
AI assistants you connect
An AI assistant you connect over MCP is not a processor of Card-a-mon's. It is a recipient you choose: when you approve it, you instruct Card-a-mon to hand it what it asks for from your projects, and from then on the company that runs it handles that data under its own terms, as a controller in its own right. That company may be outside the European Union, in which case the transfer is made at your request. Card-a-mon gives an assistant access only to the account that approved it, and only until you disconnect it.
Your rights
- Access. Everything kept about you is in the application itself: your address and the AI assistants you have connected on the account page, and your projects and their artwork in the editor.
- Rectification. Your projects, their cards and their artwork are yours to change at any time in the editor.
- Erasure. You delete the account and all of its data yourself on the account page. It takes one click, needs no request and no waiting, and cannot be undone. A connected assistant can be removed on its own from the same page. What an assistant's provider already received is held by that provider; erasure there is a request to them.
- Portability. The account page has a download button: it hands you the SQLite database this account is kept in. Its
projectstable holds one row per project, with the card set document as JSON, and itsimagestable holds every image you uploaded, as its own bytes. SQLite is an open, documented format that needs no licence and that any number of tools read. - Restriction and objection. The data is processed only to run the service you asked for, so objecting to the processing leaves no service to provide — deleting the account is what that amounts to. Sharing with an AI assistant rests on your approval alone, and disconnecting it withdraws that at once. For a restriction, write to the address above.
Legal basis
Performance of a contract: to run the editor you signed up to use, and to give an AI assistant access to your projects when you ask for it by approving the connection. Legitimate interest: to keep the service safe, which is what the cap on sign-in link requests comes from.
How long things are kept
Your data is kept until you delete the account. Inactive accounts are not deleted automatically. A sign-in link lasts fifteen minutes and works once; a session lasts 30 days, and signing out ends it at once. A connected AI assistant keeps its access until you disconnect it or leave it unused for 60 days; the token it sends with each request lasts an hour. A registration that is never approved is removed within a day.
Security
- Each account's projects and artwork are in a database file of their own.
- HTTPS only, with HSTS; the session cookie is HttpOnly and Secure.
- Sign-in links, sessions and AI assistants' tokens are stored as digests, never as the secret itself.
- An AI assistant's token opens only the account that approved it, and never works as a sign-in to the site.
- Images fetched from a link are only downloaded from public internet addresses, never from the server's own network.
- Pages are served under a content security policy that allows no inline script, and the app pages are marked not to be cached to disk.
- The server and the data are in the European Union, in Germany.
- Email addresses appear in the log only as a short digest.
Breach notification
If data did leak and that put your rights at risk, you will be told, and so will the supervisory authority, within 72 hours, as the GDPR requires.
Supervisory authority
If you are unhappy with how your data is handled you may complain to the Lithuanian State Data Protection Inspectorate: vdai.lrv.lt.