Legal
Privacy Policy
Last updated August 6, 2026
Cardfolio helps you capture and organize business-card information, create your own digital card, and share selected details. This policy explains what the Cardfolio app and website handle, why, and the controls available to you.
What changed:My Card is no longer device-only. When you are signed in, every personal-card draft you create or change is saved on your device and automatically mirrored to Cardfolio's Supabase database. This includes its contact fields, design and layout choices, visibility settings, asset references, QR configuration, and publication status. If you are offline, a change may remain on the device until the app can sync it.
Card images are never sent to OpenAI. When cloud-enhanced parsing is used, Cardfolio sends extracted text—not the original card image— through its backend to OpenAI.
1. Information we handle
Account and authentication information
When you create or use an account, Cardfolio processes your email address, Supabase user identifier, authentication provider, account timestamps, and session information. If you choose Google or Sign in with Apple, that provider processes the sign-in and supplies the account information needed to authenticate you. Cardfolio does not receive your provider password.
Saved business cards
Cardfolio processes the card image and the information you scan, import, enter, or edit. This can include a person's name, employer, job title, email address, phone number, website, social profile, physical address, notes, raw extracted text, favorite status, extraction confidence, and creation date. This information may belong to another person, and you are responsible for having an appropriate reason to collect and use it.
Saved contact cards are written to your device first and then backed up to an account-protected Supabase record. This applies to every account, including free accounts. Because the device copy is written first, a card you save while offline stays only on that device until the app is next able to reach the server.
Card images are treated differently from card details. The compressed card image is always stored on the device that captured it. It is uploaded to private Supabase storage only on accounts with an active subscription. On a free account the image never leaves the device, so a card opened on another device shows its details without the photo. Cards saved before this change may also have no uploaded image, and the original cannot be recovered from another device.
My Card and private assets
My Card data is stored locally and synced to an account-protected Supabase record. It may include your contact and professional details, social links, internal card name, templates, colors, typography, canvas layout, field-visibility choices, QR settings, revision and sync information, and publication metadata. A headshot, logo, or QR image you choose is kept in account-scoped app storage and may be uploaded to private or publication storage when needed to sync or publish the card.
Published cards, links, and handles
Publishing creates a separate public snapshot containing only the fields you selected for public visibility. You may share that snapshot with an unguessable bearer link. Cardfolio stores a cryptographic hash, rather than the raw share token, on its servers. If you claim a public handle, the handle and its published card are intentionally discoverable and may be viewed by anyone who visits or guesses that address. Published assets are delivered using short-lived signed URLs.
Shared-card imports
When you add another person's shared card, Cardfolio creates a private, recipient-owned contact and records the public card identifier, imported version, resulting card identifier, and prior imported snapshot. These records support duplicate warnings and preserve your edits when a sender updates shared fields. The sender's account identifier is not copied into your contact.
Profile imports
Cardfolio extracts selectable text from a resume PDF on your device. On supported devices, profile extraction may also occur on-device. If remote parsing is used, Cardfolio sends the extracted text—not the PDF file—through its backend to OpenAI. If you connect LinkedIn for your own card, LinkedIn may provide authorized profile or verification details, such as your name, profile image, email address, profile URL, or workplace information. Cardfolio exchanges the temporary authorization code through its backend and does not persist your LinkedIn access token. Cardfolio does not scrape other people's LinkedIn profiles. If you connect GitHub, GitHub may provide your immutable account ID, username, profile URL, name, avatar, bio, company, website, and an optional verified email address. Cardfolio records an account-control attestation but does not persist the GitHub access token. This verifies control of the GitHub account, not legal identity, employment, or repository authorship.
Collections, subscriptions, and trials
Cardfolio stores collection names, display choices, and card membership under your account. For subscriptions, it processes product and entitlement status, transaction identifiers, purchase and expiration dates, revocation status, and store environment. Apple processes payment details; Cardfolio does not receive your full payment-card number. Cardfolio may also store your lowercased, whitespace-trimmed email address, user identifier, product identifier, transaction identifier, and claim date to determine trial eligibility and reduce repeat trial use.
Device features you choose to use
Camera and selected Photos access let you capture or choose an image for scanning. Add-only Photos access lets you save a card or QR image when you request it. Contacts access lets Cardfolio add the card you choose to iOS Contacts; Cardfolio does not browse or upload your existing address book. Files access is used only for documents or export locations you select through Apple's system pickers.
2. How we use information
- Authenticate your account, maintain your session, and isolate one account's data from another.
- Extract, display, edit, search, organize, sync, cache, import, export, and delete cards and related images.
- Autofill profile details from a resume or authorized LinkedIn or GitHub response when you request it.
- Create public snapshots, resolve share links and handles, and deliver published assets.
- Provide subscription features, verify entitlements, and determine trial eligibility.
- Count public social-link taps, prevent abuse, diagnose failures, and secure the service.
- Respond to support requests and comply with legal obligations.
Cardfolio does not sell personal information and does not use it for cross-app advertising or tracking. In-app feature diagnostics use Apple's unified logging system and are limited to allowlisted categories such as template, publication status, field count, and error category; card text, images, tokens, and URLs are not included in those diagnostic events.
3. Storage and service providers
Supabase
Cardfolio uses Supabasefor authentication, account-scoped database records, private file storage, public-card assets, and server functions. Supabase therefore processes the account and cloud data described above on Cardfolio's behalf. Private database rows and storage objects use account-scoped access controls; information you publish is made available through Cardfolio's public-card functions.
OpenAI
When cloud-enhanced card or profile parsing is used, Cardfolio sends extracted card or resume text to OpenAI through a server function to identify structured fields. Card images and resume PDF files are not sent to OpenAI. OpenAI processes the submitted text as an API service provider under its applicable business terms and business-data privacy commitments.
Apple, Google, LinkedIn, and GitHub
Apple provides Sign in with Apple, device permission controls, and App Store subscriptions, billing, refunds, and related purchase services.Google provides Google account sign-in when selected. LinkedIn provides its authorization and profile or verification services when selected. GitHub provides account authorization and profile information when selected. Each provider also processes information under its own terms and privacy policy.
4. Public cards and website activity
Anyone can view, copy, download, or independently save information you publish. Bearer links are designed to be difficult to guess but can be forwarded. Public handles are enumerable by design and should be treated like a public webpage. Removing a field from a later snapshot or revoking publication cannot recall copies already made elsewhere.
To protect public-card endpoints from abuse, Cardfolio derives a salted one-way hash from a visitor's network address and stores that hash with a short rate-limit window and attempt count. The raw address is not written to Cardfolio's rate-limit table. Expired rate-limit rows are periodically removed. When a visitor follows a social link from a public card, Cardfolio records only an aggregate count for that link and hour—not an individual click history. Card owners may see these aggregate counts.
5. Retention and deletion
Cardfolio keeps account and cloud-synced information while your account is active or as needed to provide the service. Deleting an individual saved card removes its cloud database record and cloud image when present, along with the app's local copy on the device performing the deletion. Deleting My Card removes its private cloud record and local copy; unpublishing or revoking it disables future access through Cardfolio.
You can delete your account from Profile → Delete Account. Account deletion removes the authentication account, cloud card and collection records, private card images, subscription entitlement and trial records associated with the account, My Card, public handles, active public links and published assets, aggregate link counts tied to those public cards, recipient-owned import receipts, and the account's local Cardfolio directory on the device performing deletion.
Revocation cannot erase screenshots, downloaded images, copied text, messages, vCards, third-party caches, or contacts independently saved by recipients. Contacts that other Cardfolio users imported into their own accounts remain under those recipients' control. Deleting your Cardfolio account does not cancel an Apple subscription; cancel it separately through your Apple account settings. Limited records may be retained where required for security, fraud prevention, dispute resolution, or law.
6. Your choices
- Review and correct extracted or imported information before saving it.
- Edit or delete saved contact cards and My Card.
- Choose exactly which My Card fields are public, use a bearer link, claim or release a public handle, or revoke publication.
- Decline Camera, Photos, Contacts, Files, LinkedIn, or cloud-enhanced parsing features and use available manual alternatives.
- Export selected cards as CSV and export available account data, including My Card and import receipts, as JSON.
- Manage or cancel subscriptions through Apple.
- Delete your Cardfolio account from the app or contact us with a privacy request.
7. Security
Cardfolio uses encrypted network connections, private storage buckets, account-scoped row-level access controls, short-lived signed asset links, and server-side authorization checks designed to protect information. No system can guarantee absolute security, so protect your device, account credentials, bearer links, and recovery methods.
8. Children
Cardfolio is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
9. Changes to this policy
We may update this policy as Cardfolio changes. The latest version and its effective date will remain available on this page. If a change materially affects how we handle information, we will provide additional notice when reasonably required.
10. Contact
Questions, privacy requests, or requests concerning information about you that another Cardfolio user stored can be sent to cardfolio@aaryanshah.dev.