Legal

Privacy Policy

Effective: 30 May 2026 Last updated: 30 May 2026

Cardenius is built on a simple principle: your contact data belongs to you. We store it locally on your device by default, never sell it, and never share it with advertisers.

Contents

  1. Who we are
  2. What we collect
  3. How we use it
  4. Sharing & disclosure
  5. Storage & security
  6. Data retention
  7. Your rights
  8. Third-party services
  9. Children's privacy
  10. Changes to this policy
  11. Contact us

1. Who we are

Cardenius is an AI-powered business card scanner and contact management application for Android and iOS, developed and operated by Milan Nai ("we", "us", "our"). Our registered base of operations is Ahmedabad, Gujarat, India; the App is available to users worldwide.

This Privacy Policy explains how we collect, use, and protect information when you use the Cardenius mobile application ("the App"). By using the App, you agree to the practices described here.

2. What we collect

Information you provide directly

DataPurposeWhere stored
Phone numberAccount creation and OTP authentication via FirebaseFirebase Auth (Google)
Display name, email, companyYour user profileFirestore (Google) + device SQLite
Scanned card data (names, phones, emails, addresses)Your contact databaseDevice SQLite only
Card images (front and back photos)Visual reference for scanned cardsDevice local storage only
Your digital card designMy Card feature — your personal visiting cardDevice SQLite only

Information collected automatically

DataPurposeService
Crash reports and error logsApp stability and bug fixingFirebase Crashlytics
App usage analytics (screens visited, feature usage)Understanding how the app is used to improve itFirebase Analytics
Ad interaction data (free tier only)Serving relevant ads to free usersGoogle AdMob

Optional features (only if you enable them)

Camera and microphone

The App requests camera permission to photograph business cards for scanning. No images are transmitted to our servers. Images shared with the Google Gemini Vision API for AI extraction are governed by Google's Privacy Policy.

3. How we use it

We do not use your data for profiling, targeted advertising beyond AdMob's standard serving, or any automated decision-making that produces legal effects.

4. Sharing & disclosure

We do not sell your personal data. We share data only in these limited circumstances:

5. Storage & security

All contact data, card images, and personal card designs are stored in your device's private app storage (SQLite database and local file system). This data is not accessible to other apps.

Cloud backups are encrypted with AES-256 before leaving your device. The encryption key is derived from an app-level secret combined with an optional user passphrase. We cannot decrypt your backup files.

Authentication data (phone number, tier status) is stored in Firebase with access restricted by Firestore security rules — only you can read or write your own document.

6. Data retention

7. Your rights

You have the following rights regarding your personal data:

If you are in the European Economic Area or United Kingdom, you have additional rights under GDPR/UK GDPR including the right to lodge a complaint with your local supervisory authority.

8. Third-party services

ServiceProviderData sharedPolicy
Firebase AuthGooglePhone numberFirebase Privacy
Cloud FirestoreGoogleUser profile, tier statusFirebase Privacy
Firebase CrashlyticsGoogleCrash traces, device infoFirebase Privacy
Firebase AnalyticsGoogleApp usage eventsFirebase Privacy
Gemini Vision APIGoogleCard images (for AI extraction)Google Privacy
Cloud Vision APIGoogleCard images (for OCR)Google Privacy
Maps SDK for AndroidGoogleDevice location (if granted)Google Privacy
Google AdMobGoogleAd interaction data (free tier)Google Privacy
Google DriveGoogleEncrypted backup file (optional)Google Privacy
DropboxDropbox Inc.Encrypted backup file (optional)Dropbox Privacy
Apple App Store (StoreKit)Apple Inc.Transaction data for iOS subscriptionsApple Privacy

9. Children's privacy

Cardenius is designed for working professionals and is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us at privacy@cardenius.com and we will delete it promptly.

10. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you through the App. Your continued use of the App after the effective date constitutes acceptance of the updated policy.

11. Contact us

For privacy-related questions, data deletion requests, or any concerns about this policy:

Milan Nai

Cardenius App

Ahmedabad, Gujarat, India

📧 privacy@cardenius.com

We aim to respond to all privacy inquiries within 7 business days.