Privacy notice

Last updated

Who is responsible

CardSnap is responsible for the personal data described here (the "controller" under the EU General Data Protection Regulation). Contact for anything privacy-related: kkourentzes@gmail.com.

The short version

  • QR codes are read on your device. Nothing about a QR scan is sent anywhere. Scanning, showing and sharing QR cards is free and needs no account.
  • Reading a card from a photo needs a Google sign-in, because it uses a paid AI service. The photo is sent once to be read and is not kept by us.
  • Your contacts are not on our servers. They stay on your device, in your own Google Drive, or in a backup file you keep.
  • If you sign in, we keep your Google account ID, your email address, your plan and how many photos you had read each month — never the photos or anything read from them.

What we process, and why

Card photos

When you press the shutter in photo mode, the image is sent to our server and forwarded to OpenAI (model gpt-4.1-mini) to be read. We do not write it to disk, log it, or keep it after the answer comes back. We ask OpenAI not to store the response; under OpenAI's API terms it may still keep the request for up to 30 days to monitor for abuse, then deletes it, and does not use it to train its models. A copy of the photo stays in your browser's storage with the card it belongs to, so you can re-read a detail later; it is deleted with the card or with "Delete all local data" in Settings.

Legal basis: performing the service you asked for (Art. 6(1)(b) GDPR).

Your account (only if you sign in)

Photo reading is limited to signed-in users so the free allowance of 10 photos a month can be counted per person. When you sign in with Google we receive, and keep: your Google account ID, your email address (which Google has verified), when you first and last signed in, your plan (Free or Pro, and until when, and whether it came from a payment or a promotional code), and a count of photos read per calendar month. Signing in sets one cookie, cs_session, which is signed so it cannot be forged, cannot be read by page scripts, and lasts 30 days or until you sign out.

Legal basis: performing the service (Art. 6(1)(b)). Kept for as long as your account exists.

Abuse prevention and cost control

To limit how many photos one connection can send per hour, we store a hash of your IP address combined with the current hour and a secret, for two hours. The IP address itself is not stored and the hash cannot be turned back into it. We also keep a running total of what photo reading costs each month — a sum, with nothing about who scanned what.

Legal basis: legitimate interest in security and in keeping the service affordable (Art. 6(1)(f)).

Usage counts

The app counts anonymous events — installs, scans, shares, errors — to see whether it works. Each carries a device identifier that is re-derived every day from a secret that never leaves your phone, so activity cannot be linked across days. No IP address, no card contents and no account are attached. You can switch this off in Settings. Counts are kept for up to 90 days.

Legal basis: legitimate interest in understanding and fixing the app (Art. 6(1)(f)), with an opt-out.

Google Drive sync (only if you turn it on)

We ask Google for one permission, drive.file, which reaches only files this app creates. The access token stays in your browser tab and is never sent to our server. You can revoke it at any time at myaccount.google.com/permissions.

Hosting

The site runs on Cloudflare's network. Like any web host, Cloudflare processes your IP address to deliver pages, and keeps short-lived request logs (a few days) for operating and securing the service.

Stored on your device

  • Your contacts, their photos, your own cards and settings, in your browser's storage (IndexedDB and localStorage). They never leave the device unless you choose Drive sync or export a file.
  • A cs_locale cookie remembering the language you chose.
  • The cs_session cookie described above, only while signed in.

None of these is used for advertising or tracking across sites.

Who else receives data

  • OpenAI (United States) — card photos, to read them. Processor under OpenAI's data processing terms.
  • Google — sign-in, and Drive if you use sync. Google acts under its own privacy policy for your Google account.
  • Cloudflare — hosting, storage of the account and usage records, usage counts. Processor under Cloudflare's data processing terms.

We do not sell personal data or share it with anyone else.

Transfers outside the EU

OpenAI processes in the United States, and Cloudflare and Google operate globally. Transfers rely on the EU–US Data Privacy Framework where the recipient is certified, and on the European Commission's Standard Contractual Clauses otherwise.

The person on the card

A business card holds someone else's personal data. When you scan one, what you do with it next is your responsibility — in the EU a real obligation under the GDPR, particularly if you go on to contact them.

Your rights

You can ask for access to, correction of, or deletion of your account data, ask us to restrict or stop processing it, or ask for a copy in a portable format. Write to kkourentzes@gmail.com from the address you signed in with; we answer within one month. Deleting your account removes its record and its usage counts. We hold no copy of your contacts to hand over or delete: remove them in the app with "Delete all local data", and in your own Google Drive if you synced.

You also have the right to complain to a data protection supervisory authority, in particular in the EU country where you live or work.

Children

The app is not directed at children under 16, and we do not knowingly create accounts for them.

Changes

If what the app does with data changes, this page changes with it and the date at the top moves. A change that needs your agreement will be asked for in the app before it applies.

Back