Privacy Policy
Last updated: August 16, 2026
Digital Card ("the app", "we", "us") is a digital business-card and contact manager available on the web and as a mobile app. This policy explains what information the app collects, how it is used, and the choices you have. The app is self-hosted: it runs on a server operated by the organization or individual who deployed it ("the operator"), and your data stays on that server.
Information we collect
We collect only what the app needs to work:
- Account information. When you sign in with Google we receive your name, email address, and profile photo URL. When you sign in with Apple we receive a stable account identifier and, the first time only, your email address. We use this to create and secure your account.
- Content you create. Business cards you scan or add (including card photos and the contact details read from them — name, title, company, phone, email, website, address, and notes), your own digital card, folders, and any cards or folders you choose to share.
- Financial records (optional module). If the operator has enabled the Money module for your account, documents, bills, amounts, categories, accounts, and related records you enter are stored so the app can show your ledger, budgets, and reports. This information is entered by you and is visible only to you.
- Technical data. A session cookie (web) or an authentication token (mobile) to keep you signed in, and security logs that record events such as failed sign-in attempts and server errors, along with the IP address and request path involved. Security logs never contain your password, tokens, or card contents.
Device permissions (mobile app)
The mobile app requests these permissions only when you use the related feature:
- Camera — to photograph a business card so its details can be read and filled in.
- Photo library — to let you pick an existing photo of a card instead of taking a new one.
You can decline or revoke these permissions in your device settings; the rest of the app continues to work.
How we use your information
To provide and maintain the service: sign you in, read and store your cards, let you search and share them, run the Money module if enabled, and keep the service secure. We do not use your information for advertising, we do not build advertising profiles, and the app contains no third-party advertising or tracking software.
How your information is shared
- We do not sell your personal information.
- Sign-in providers. Google and/or Apple process your authentication when you choose to sign in with them, under their own privacy policies.
- Only when you choose. Cards or folders are shared with other people solely when you share them. A card you publish becomes viewable by anyone who has its public link or QR code.
- Analytics & diagnostics. We use Google Analytics on the website and Google Firebase (Crashlytics & Performance Monitoring) in the mobile app to understand usage and to detect and fix crashes and performance problems. These tools collect app-interaction, device, and diagnostic data (including crash logs) and are processed by Google under its privacy policy. Where applicable, IP addresses are anonymised.
- Content moderation. If enabled by the operator, uploaded images may be sent to Google Cloud Vision to screen for explicit content before they are stored or shared.
- Legal. The operator may disclose information if required by law or to protect the security of the service.
Storage and security
Data is stored in the operator's PostgreSQL database, and uploaded images on the operator's server. Traffic is protected with HTTPS/TLS and HSTS. The app is hardened following OWASP and NIST guidance, including CSRF protection, rate limiting, strict content-security headers, and hashed, rotating authentication tokens. No system is perfectly secure, but we take reasonable measures to protect your data.
Retention and deletion
Your data is kept until you delete it or request account deletion. You can request permanent deletion of your account and all associated data at any time — see Delete your account for the steps. After deletion, minimal security-log entries may be retained for a short period for fraud prevention and integrity, then discarded.
Children
This app is intended for business and personal-finance use by adults aged 18 and over. It is not directed to, or designed for, children, and its target audience is adults only. We do not knowingly collect personal information from children under 18. If you believe a child has provided us with personal information, contact us at admin@zyraxtech.com and we will delete it.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected here with a new "Last updated" date.
Contact
Questions or privacy requests: admin@zyraxtech.com.