This Privacy Policy explains what the Carddis app (the “App”) does with your information. Carddis is operated by an individual developer (contact details at the end of this policy), who is the data controller for the purposes of the GDPR and UK GDPR.
Carddis has no account, no server and no database of yours. Your cards, their numbers, your photos of them and everything else you put in stay on your own device. We cannot see them, we cannot recover them, and there is nothing of yours for us to hand over to anyone.
The App keeps the following in a database and a media folder inside its own private storage:
A loyalty card number is a number issued to you by a shop. Carddis stores it so it can be drawn back as a scannable code at the till. Carddis is not a payment wallet: it is not built for bank cards, and it never asks for a PIN, a CVV or an expiry date.
Carddis contains no analytics SDK, no advertising SDK, no crash reporter and no tracking of any kind. There is no sign-up, so we never learn your name or your email address. We do not know which shops you hold cards for, we do not know when or where you use them, and we do not build a profile of you. This is not a policy position but a fact about how the App is built: there is nowhere for that information to go.
The camera is used for two things: to read a barcode or QR code, and to photograph a card. Recognition happens entirely on the device — Apple's Vision framework on iOS, Google's on-device ML Kit model bundled into the app on Android. No image and no video is streamed anywhere, and nothing from the viewfinder is stored unless you deliberately keep the photo. Photo-library access is used only to open a picture you choose. Both permissions are requested by the system at the moment you first use the feature, and the App works without them — you can type a card number in by hand.
Two requests, and no more. Neither carries a card number or a photograph.
When you type a card's name, that name is sent, shortly after you stop typing, to Brandfetch's public catalogue search so the App can offer the shop's logo; for a name written in Cyrillic, transliterations of it are sent as well. Images offered or accepted are then downloaded from Brandfetch's servers. Only the name you typed is sent — never the card number, never a photo, never the rest of your wallet. Nothing depends on it: decline the suggestion, or stay offline, and the App draws a monogram instead.
If you buy Carddis Pro, purchase handling goes through RevenueCat. It receives an anonymous identifier generated for that installation, your purchase receipt and basic device and country information — enough to tell the App whether Pro is active and to restore it on a new device. It never receives anything about your cards. Payment itself is handled entirely by Apple or Google; we never see your payment card details.
| Provider | What it receives | Where |
|---|---|---|
| Brandfetch (Brandfetch AG) | The card name you type, when a logo is looked up | Switzerland / EU |
| RevenueCat, Inc. | Purchase receipts and an anonymous installation identifier — only if you buy Pro | United States |
| Apple Inc. / Google LLC | Payment processing for a purchase | Global |
Each of these receives data under its own privacy policy. We will update this table whenever a provider is added or removed.
Because nothing of yours is stored on a server, there is no database of yours to transfer anywhere. The limited data above is processed by providers in Switzerland, the European Union and the United States; where personal data is transferred out of the European Economic Area or the United Kingdom, those transfers rely on the European Commission's Standard Contractual Clauses, which our providers incorporate into their agreements with us.
Your cards stay on your device for as long as you keep the App installed. Deleting the App deletes all of them — there is no copy anywhere else, and nothing to restore. Purchase records held by RevenueCat, Apple or Google are kept under their own retention rules, because they are part of a billing relationship rather than something we hold.
Delete an individual card in the App — its photos and any logo it alone used go with it — or remove the App to delete everything at once. There is no account to close and no request to send us. See Your data and how to delete it for the details.
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to receive a copy in a portable format, to have it deleted, and to object to or restrict processing. In Carddis's case those rights are largely satisfied by the design: the data is already in your hands, and we hold none of it. For the purchase data described above, email us and we will help. We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use it for automated decision-making. If you are in the EEA or the UK you also have the right to lodge a complaint with your local data protection authority.
Carddis is intended for a general audience and is not directed to children. It collects nothing from anyone, but if you believe a child has used the App in a way that concerns you, contact us.
Your cards sit in the App's private storage, protected by your device's own sandbox and, where you have enabled it, its encryption. Requests to the internet are made over HTTPS. Keep a device passcode: Carddis does not lock itself, so anyone holding an unlocked phone can open it and read a card number.
We may update this policy as the App changes. The date and version at the top reflect the latest revision. If a change materially affects what leaves your device or who receives it, we will say so in the App.
Questions, requests or complaints about your privacy? Email mail@timeofjohnny.com. We aim to reply within a few business days.