How to join the beta, how the game works, and how to reach a person.
CardLocked is in closed testing. It's free, there is nothing to buy inside the app, and it's for adults only. Android is on Google Play and iPhone is on TestFlight. The two run side by side.
Android — Google Play. You need an Android phone and the Google account you use in the Play Store on that phone. Google only lets listed testers install, and the invite only works for that exact address, so step one is getting it on the list.
iPhone — TestFlight. You need an iPhone on a current iOS and Apple's TestFlight app from the App Store (it costs nothing).
Please stay in for the whole test — at least two weeks. Leaving early frees your seat and sets the test back.
Testers and users talk in the CardLocked Discord — adults only. Anything about a specific lock still goes through Support inside the app.
Found something wrong? Use Support inside the app (Dashboard → More → Support) so we can see the lock you mean — every ticket gets a reply — or email aj@cardlocked.app.
💡 Anything about a specific lock is fastest as an in-app ticket: it arrives with the lock attached, so nobody has to ask you which one.
Dashboard → More → Support, or Settings → Help & Support → Help Center. Open a ticket, read the reply in the thread.
Every ticket gets a replyWhat every card does, in one page. Also in the app under Settings → Help & Support → Card Guide.
The deck →Open the app and tap + on your dashboard. Give the lock a name, choose how often you may draw a card (anywhere from once a minute to once a week), pick how many of each card go in the deck, and type the combination of a padlock or safe you already own — 3 to 8 numbers, and each number can go up to 99 for a dial safe (1234, or 12 · 24 · 36). Run it yourself, or name another adult to run your deck.
A lock you run yourself starts the moment you create it. If you named a keyholder, the lock sits pending until they accept — they have 24 hours. If they don't answer in time, the lock is cancelled and your combination is emailed back to you.
When a draw comes due, tap a face-down card. The deck is shuffled and kept on our side, so you can't see what's coming or reorder it, and the only way to get rid of a card is to draw it. By default missed draws bank up (Cumulative Card Picks); switch that off and a missed draw is simply lost.
Only two cards cost you a turn — reds and stickies. Everything else resolves and lets you draw again.
Not sure how long a deck will keep you? Tap Simulate This Lock while you're building it and the app plays it out 2,000 times.
A keyholder is another CardLocked user you name yourself. Nothing starts until they accept, and the invitation lapses after 24 hours. From then on they run your deck: they can add cards (choosing the exact value of any yellow), take cards away, freeze and unfreeze you, rename the lock, hide the card counts from you, switch the card games on or off, and end the lock whenever they like — and you can't overrule any of it. Ending a lock is unlimited and carries no penalty for them, and your combination is emailed to you when they do.
What a keyholder can never touch: your combination, your draw schedule, strict mode, and your emergency password. Those are yours from the moment you create the lock.
When you invite one you also pick Protected Mode (they may add at most 10 cards per action and you can read the lock's history) or I Trust My Keyholder (no limit, and the history is hidden from you). Your keyholder always sees your deck, even if you've hidden it from yourself. When the lock ends you can rate them.
Blackjack, a wheel and slots, played for red cards. They're off unless you turn them on for a lock (on a keyholder-run lock, only the keyholder can). Win and reds come off your deck; lose and more go on.
You bet 1–25 cards a game times the lock's stakes multiplier, never more than one card for every 25 reds in your deck, and the tables close once the deck drops below 25 reds. Every hand, spin and pull is decided on our side.
A saved lock is a design — the deck and its rules. Save one from the create screen and you can reuse it, or hand it to someone as a QR code (Saved Locks → share). What travels is the deck and the rules, never your combination, your emergency password or your keyholder: whoever uses it sets their own combination and picks their own keyholder, or nobody. To load one, use Saved Locks → Scan QR, or take a screenshot of the code and use Load from Photos.
A group is one deck run for a room. The creator designs it and gets a six-character code; everyone who joins with the code gets their own shuffle and their own private combination, and the creator runs all of them. Groups can require approval to join, and public groups show up under Browse.
An emergency release is always available and always free — there is no purchase, no fee, and there never will be one. What using it costs you depends on the lock you built, and every warning tells you exactly which case applies before you confirm.
With a keyholder you have two ways out instead of one: your keyholder can release you early any time they like, and the emergency release is still there for a real emergency — it works exactly the same on any lock with a stored combination. The one exception is a lock with a Physical Keyholder: a real person holding a real key. That lock has no combination in the app and no in-app release at all, because the app does not control physical keys.
A restricted account can still sign in, see its locks, use the emergency release on its own solo locks, file support requests, and delete itself. And whatever you build: never rely on an app to control a physical lock. Keep an independent means of release — a spare key, bolt cutters, something you control.
You need to click the verification link we emailed you before your first sign-in. Check your spam folder; if it isn't there, the sign-in screen has a Resend Email button. Forgotten your password? Forgot Password? on the sign-in screen emails you a reset link that works for one hour.
In the app, go to Dashboard → More → Support (or Settings → Help & Support → Help Center) and open a ticket. Pick the category that fits — Emergency Unlock, Lock Stuck, Keyholder Issue, Technical Issue, Account Issue (sign-in, profile, or appealing a restriction) or Other — attach the lock it's about, and tell us what you expected and what happened instead. Replies show up in the ticket thread. Every ticket gets a reply: an assistant answers the common questions straight away, and anything it can't settle — plus every emergency and every appeal — goes to a person. Say so in the thread if you want a person, and one takes over.
If the app crashes, it files an error report as a ticket on its own, with the device model and the technical details we need.
Your combination is stored encrypted on our server and handed back to you on release — it is never kept on your phone. Your password is stored only as an argon2 hash, and everything between the app and our server travels over HTTPS. There are no ads, no tracking, no analytics, no profile of you, and nothing about you is ever sold. The pillory keeps a keyed one-way hash of a voter's network address, browser cookie or phone ID for about a week, only to stop repeat votes — it can't be reversed or matched across locks. Blocking someone is silent and works both ways. Read the Privacy Policy for the full picture.
A way to let other people add cards to your lock. On a keyholder lock you allow it when you build the lock and your keyholder sets it up and runs it; on a self lock you set it up yourself, for a time you choose. Either way there is a pillory link: anyone who opens it in a browser can add cards to your deck, no account needed. You can also list the lock in the public pillory (Dashboard, then More, then Pillory), where every signed-in CardLocked user sees your username, your avatar, the reason line you wrote, that you're in a lock right now, and what a vote adds — never your lock's name, your cards, your combination or your emergency settings — and can add cards from the app.
A vote adds red cards, or yellow cards that roll their own value when you draw them, in the amounts you chose. Nothing in the pillory ever removes a card. Each network connection or account gets one vote a day per lock, a lock takes at most 20 votes a day, and it can never add more than the cap you set (100 cards unless you chose otherwise). Every vote is written to the lock's history.
On a keyholder lock your keyholder decides, at any time, whether the pillory is on, what a vote adds and the limit (never more than 1,000 cards over the whole lock or 20 votes a day), whether the link is on, whether the lock is listed, and what the reason line says — you allowed that when you created the lock. A lock made in an older version of the app keeps the amounts you set; your keyholder runs only the link, the listing and the reason on it. On a self lock you set all of that when you create the lock, plus how long you are in for; when the time is up the link stops working and the lock comes off the public pillory by itself, and nothing about it can change. A link that opens to a closed page belongs to a pillory that has ended, been turned off, or run out of time.
The reason line is one line of plain text that strangers read, so it has to stay clean: no contact details, no profanity, nothing explicit. The app refuses a line that breaks that rule. If one slipped through, report the user from their profile (a pillory row opens it) or send a support request.
In the app, go to Settings, scroll to the bottom (under Help & Support) and tap Delete Account, then confirm with your password. Deletion is refused while a lock of yours is still running: end it first — play it out, ask your keyholder, or use the emergency release, whose usual rules apply — then delete. Locks you run for others are handed back to the people whose locks they are. If you can't get into the app, see the account deletion page — emailed requests are handled within 30 days, usually much faster.
Every ticket gets a reply. An assistant handles the common questions; a person handles the rest, and every email.
For anything about a lock, please use the in-app ticket so we can see it.