Last Updated: September 28, 2026
This policy covers one app: Card Lab: Trading Card Maker, in which children and families design their own trading cards, on iPhone, iPad and Android. Most of our other apps are covered by the general Illumination Development privacy policy, which does not apply here. That policy describes accounts, reward balances and redemption records that this app does not have.
The short version
We never receive your cards. There is no account and no sign-up. Every card you make, every deck, and every photo you put on a card is written to storage on your device and stays there. There is no sync, no cloud backup of ours and no server holding a copy. A card leaves the device only when you share it yourself.
There is nothing for sale and no tracking prompt. The app carries one advertising banner, from Google AdMob, and every advertising request is tagged as child-directed, which means Google does not personalize it.
What does leave the device is that advertising, anonymous usage analytics, crash reports and an update check, plus a support message if a grown-up chooses to send one. Each is described in full below.
What stays on the device
The app keeps these things on the phone or tablet:
- Your cards — everything on each one: its kind and layout, name, words, numbers, type, frame and background, the stickers placed on it and anything drawn on it.
- Your decks — the groups you put cards into.
- Card photos — a copy of any photo you put on a card, kept in the app's own storage.
- Your vibration setting.
None of it is transmitted to us. There is no profile, no gallery and no way for anyone else to see what you have made. If the device backs itself up to iCloud or to Google, that copy is governed by Apple's or Google's terms and your own backup settings, and we have no access to it.
Photos
A photo is used only when the maker chooses to add one, by taking a picture with the camera or picking one from the photo library. The camera and photo library are opened only at that moment, never in the background. The app receives only the one photo chosen, copies it into its own storage and uses it only as that card's picture. It does not browse your library, and it never uploads the photo.
Sharing and printing
A card can be shared as a picture of its front and back, and cards or a whole deck can be made into sheets ready to print. A picture goes to your device's own share sheet, and only when you tap Share. Printing opens your device's own print screen on iPhone and iPad, and the share sheet on Android. Where anything goes from there — Messages, a printer, a file, another app — is your choice, made in the system's own screen, and we do not see it.
What the app sends
None of what follows includes a card, a photo, a drawing or anything written on a card. None of it includes a name or an email address either, unless a grown-up types them into Contact support.
An anonymous identifier
On first launch the app signs in anonymously to Google Firebase. This produces a random identifier for the installation — not a name, not an email address, not a phone number, and nothing you typed. There is no password and nothing to sign up for. It is used as the key for the installation's analytics and crash reports, and it is shown in Contact support (as “Install ID”) so that a message sent to us can be matched to the crash reports from the same device. Delete my data deletes it.
Usage analytics
The app reports a small set of events to Google Analytics: which screen is open, that a new card was started and a card was saved (what kind and layout of card it is, whether it is new, and whether its picture is a photo, a drawing, stickers or none), that a card was duplicated or deleted, that cards were shared (as a picture or a sheet, and how many), that a photo was added (and whether from the camera or the library), where in the step-by-step helper a card was left unfinished, that the privacy policy was opened, how long the app took to start, and when an error message was shown. It never reports a card's name, its words, its picture or anything you typed.
Alongside those, Google Analytics collects its own app-instance identifier, coarse device information such as the model, the operating system version and the app version, and an approximate location that Google derives from the IP address. The app itself never asks for location permission. We use analytics to see which parts of the app are used and where makers get stuck, and for nothing else.
Crash and diagnostic reports
If the app crashes or hits a handled error, Google Crashlytics sends a report: the stack trace, the app version, the device model and operating system, and the anonymous identifier above. This is how bugs get found. Analytics and crash reporting are both switched off entirely in the debug builds we use during development.
A check for updates
The app can receive small fixes to its own code without a new store download, using a service called Shorebird. When the app starts it asks Shorebird's servers whether a fix is waiting. According to Shorebird's documentation, that request carries the app's identifier, its version and the number of the fix it already has, the device's platform and processor type, and a random install identifier Shorebird uses to count how many copies of the app are in use. It carries nothing about the maker and nothing they have made. Like any request over the internet it reaches Shorebird from the device's IP address, and Shorebird's handling of it is governed by Shorebird's own privacy policy.
Advertising
The app is free and carries advertising from Google AdMob and no one else. There is one placement: a banner on the home screen. There is no advertising while a card is being made, no full-screen or video advertisements, and no rewards for watching one. There is nothing to buy: no in-app purchases of any kind.
To serve the banner, the Google Mobile Ads SDK contacts Google and may collect device information — device signals, coarse device and app data, an approximate location derived from the IP address, and the request, impression and click themselves. Google's use of it is governed by Google's own privacy policy.
Every request is child-directed
Before the first advertisement is ever asked for, the app sets two things on every Google request:
- Child-directed treatment, which tells Google to treat the audience as children. Under Google's policies that means the advertisements are not personalized.
- A maximum content rating of “G”, so the creatives shown are the ones Google rates suitable for general audiences.
On iPhone and iPad: no tracking prompt
Many free apps show Apple's App Tracking Transparency prompt asking for permission to track you. Card Lab does not. The tracking framework is not built into the app and nothing in it requests Apple's Identifier for Advertisers, so it never receives it. You will not find Card Lab under iOS Settings → Privacy & Security → Tracking; that is correct and not a fault.
On Android: the advertising ID
The app does not ask for your advertising ID. The Google Mobile Ads SDK declares the advertising-ID permission by default, and Card Lab removes it, so the app cannot read the ID at all. Advertisements still show: non-personalized advertisements need no advertising ID, and they are the only kind the app asks for.
In the EEA, the UK and Switzerland
Google's consent message is shown before any advertisement is requested, gathering consent for the storing of and access to information on the device as Google's EU user consent policy requires. The request is flagged as coming from a user below the age of consent, so the choices offered are the reduced set appropriate to that.
You can change your answer at any time — Settings → Ad privacy options, behind the grown-up check, reopens the same choices. That entry appears only where a consent regime applies, which is why people elsewhere will not see it. Consenting does not turn on personalized advertising here: the child-directed setting above overrides it. Your decision is stored on your device by Google's consent SDK.
Contacting support
Settings → Contact support is the one place the app asks for anything about a person, and it sits behind a grown-up check (a multiplication question) so that a child does not reach it by accident. To send a message it needs a name, an email address, a topic and the message itself. Before sending, the form shows exactly what else is attached: the app name and version, the device's platform and operating system version, and the anonymous identifier described above.
All of that is delivered as an email to our support inbox, through a small Google Apps Script service that exists only to forward it, with the sender's address set as the reply-to so that we can answer. The email address is used to reply and for nothing else.
The form is entirely optional. The app works fully without it, and if it is never used we never receive a name or an email address.
Delete my data
Settings → Delete my data, behind the same grown-up check, does these things, immediately and without asking us:
- It permanently erases every card and every deck, and every card photo the app has stored.
- It resets the Google Analytics identifiers held on the device, so later analytics start from a new app-instance identifier.
- It deletes the anonymous Firebase identifier described above, and signs in afresh with a new, unrelated one.
Because the copy on your device is the only copy there is, deleting the app removes your cards and photos too. Analytics events and crash reports already sent to Google are kept by Google under its own retention periods, keyed to identifiers that no longer lead back to this installation. Support messages already sent are kept in our inbox, because a delivered email cannot be recalled. You can ask about either by writing to privacy@illuminationdevelopment.com.
What the app does not do
- No account, sign-in, username or profile.
- No upload, sync or backup of your cards, decks or photos to us or anyone else. They leave the device only through the share sheet, when you choose.
- No in-app purchases, nothing for sale, and no way to spend money.
- No rewards, no coins and nothing earned by watching advertisements.
- No chat, no gallery, no marketplace, nothing shared between people using the app, and no way to reach another person through it.
- No location permission. The only location involved is the approximate one Google derives from the IP address, described above.
- No camera or photo library access except when the maker chooses to add a photo. No microphone, contacts, calendar or health data.
- No tracking prompt, and no Identifier for Advertisers requested on iPhone or iPad.
- No personalized advertising, and no advertising network other than Google AdMob.
- We do not sell personal information, and we do not share it for cross-context behavioral advertising, in the specific senses the CCPA and CPRA give those terms.
Children
Card Lab is made for a general audience that includes children, and is rated 4+ on the App Store. It is not in Apple's Kids Category, and we would rather say so than claim a badge it does not carry.
It is built to the child-directed standard anyway, because children are among the people it is made for. Every advertising request is flagged child-directed and capped at the “G” content rating, no advertisement is personalized, there is no tracking prompt, there is nothing to buy, cards and photos never leave the device unless shared, and there is no way to reach a stranger. The privacy policy, Contact support, Ad privacy options and Delete my data are all behind a grown-up check.
The general Illumination Development policy states that our services are not intended for children under 13. That statement is about our reward apps and does not apply to this app, which is why this page exists.
We do not knowingly collect personal information from children. If you believe a child has sent us personal information through Contact support, write to privacy@illuminationdevelopment.com and we will delete it.
Your rights
Under the GDPR, the UK GDPR, the CCPA and CPRA, and comparable laws elsewhere, you have rights to access, correct, port and delete the personal information a company holds about you. The only things this app gives us that name anyone are the name and email address in a support message a grown-up chose to send; everything else is keyed to a random identifier. You can erase what is on the device yourself with Delete my data, and ask us about anything else — a support message, or data Google already holds — by writing to privacy@illuminationdevelopment.com.
Information held by Google from serving advertisements, running analytics and receiving crash reports, and by Shorebird from the update check, is subject to Google's privacy policy and Shorebird's and the controls described above.
A note about this web page
The app does not display this page — tapping Privacy Policy in Settings opens it in the device's browser, and this website uses Google Analytics to see which pages people find useful. That is described in the general policy, and it applies to your visit to this page, not to your use of the app.
Changes to this policy
If any of this stops being true, this page changes before the version that changes it reaches either store, and the App Store privacy label and Google Play Data safety form change with it. Revisions are posted here with an updated date.
Contact
Email: privacy@illuminationdevelopment.com
You can also reach us through our contact and support page.