Privacy Policy

Scard  ·  Last updated: April 2026

1. Overview

Scard ("we", "our", "the App") is developed by luvleelab. We built this app with a privacy-first mindset: you need no account to use it, and business card data you scan is stored locally on your device.

This policy explains what data is processed, where it goes, and your rights under the EU General Data Protection Regulation (GDPR) and other applicable laws.

2. Data We Collect

We do not collect or store personally identifiable information on our servers. The app does not require you to create an account or provide your name, email, or any personal details to us.

The following data is processed entirely on your device and never sent to us:

All of this data is stored locally using Apple's SwiftData framework and stays within your device or your personal iCloud account (if you have iCloud backups enabled).

3. AI-Enhanced Field Extraction

What happens: When you scan a card and an internet connection is available, the raw OCR text recognised from the card (plain text blocks only — not the image) is sent to an OpenAI language model for intelligent field extraction (name, job title, company, phone, email, address, etc.).

Here is the full data flow:

  1. Apple's Vision framework reads text from the card image on-device.
  2. The resulting plain-text blocks are sent over HTTPS to a Cloudflare Worker proxy operated by luvleelab. The request includes a random app token for abuse prevention; it does not include your identity, device ID, or IP address (Cloudflare Workers do not expose the client IP to worker code).
  3. The proxy forwards only the text content to OpenAI's API (model: GPT-4o-mini). No images are ever transmitted.
  4. OpenAI returns structured field data, which is used to pre-fill the card detail screen. You can review and edit all fields before saving.

What is NOT sent: The card image, your device identifier, your name, your Apple ID, your location, or any other personal attribute.

Offline fallback: When no internet connection is available, AI extraction is skipped and the app uses an on-device regex parser instead. All core functionality remains available offline.

OpenAI data retention: OpenAI may retain API inputs and outputs for up to 30 days for safety monitoring, after which they are deleted. OpenAI does not use API data to train its models by default. See OpenAI's API data usage policy for details.

GDPR legal basis: Processing is based on legitimate interests (Art. 6(1)(f) GDPR) — specifically, providing accurate field extraction that significantly improves the utility of the service. The text transmitted is limited to what is strictly necessary for this purpose, and it is not linked to your identity.

4. Third-Party Services

Service Purpose Data shared
OpenAI (via Cloudflare Worker) AI field extraction from OCR text Plain-text OCR blocks from the scanned card; no images, no user identity
Cloudflare Proxy infrastructure for the AI feature Request metadata only (standard HTTP headers); no persistent storage
RevenueCat Subscription and in-app purchase management App Store receipt data; anonymous RevenueCat user ID; no personal details
Mixpanel Anonymous usage analytics (feature adoption, crash-free sessions) Anonymous event data; no names, emails, or card content
Sentry Crash reporting and error monitoring Stack traces and device type; IP addresses are not stored; no card content

Each of these providers acts as a data processor under GDPR and is bound by their own data processing agreements. Links to their privacy policies: OpenAI · Cloudflare · RevenueCat · Mixpanel · Sentry.

5. Permissions

You can revoke any permission at any time in iOS Settings → Privacy & Security.

6. Data Storage & Retention

All card data is stored locally on your device using Apple's SwiftData. We have no access to this data. If you delete the app, all locally stored data is removed.

iCloud backup: if you have iCloud backup enabled, your device data (including app data) may be included in that backup. This is governed by Apple's privacy policy, not ours.

7. Your GDPR Rights

If you are located in the European Union or European Economic Area, you have the following rights regarding any personal data we process:

Because the only personal data we process is the anonymous analytics and crash data described above, most of these rights are exercised directly through the third-party services. For any requests, contact us at luvleelab@gmail.com and we will assist you within 30 days.

You also have the right to lodge a complaint with your national data protection authority.

8. Children's Privacy

Scard is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

9. Changes to This Policy

We may update this policy when we add new features or change how data is processed. Material changes will be communicated via an in-app notice or an update to the "Last updated" date at the top of this page. Continued use of the App after a change constitutes acceptance of the updated policy.

10. Contact

Questions or requests regarding this policy:
luvleelab@gmail.com