Everything in your pocket.
Nothing on the internet.
Loyalty and credit cards, tickets, vouchers, holdings and business cards. All in one place, and none of it ever leaves your iPhone.
Loyalty and credit cards, tickets, vouchers, holdings and business cards. All in one place, and none of it ever leaves your iPhone.
Notes in notebooks, with fields you name yourself. Mark any value secret and it stays behind your passkey until you ask for it.
The app contains no networking code at all. Nothing to phone home to, and nothing to phone home with.
Not just a code: the date and time, the venue, your seat. One booking holds a separate code for every passenger.
The cards you choose on your Apple Watch, the ones near you in a widget. Synced from your iPhone, never the cloud.
Point at a receipt and the amount, merchant, date and category lift themselves off it. Your iPhone reads it, not a server.
QR, NFC, or a barcode in any symbology Brightcard supports. The exact one the shop issued, drawn on your device.
Store a code with its expiry and face value, and get a reminder before it runs out. Spent ones archive themselves.
Snap a photo and the number, holder, expiry and CVC fill themselves in. Masked until you look, and never on your Watch.
Most apps stop at loyalty cards. Brightcard takes both kinds: the one you scan at the till and the one you read the number off. Tickets, vouchers, holdings and contacts each get a tab of their own, so everything you actually carry lives in one private place. You can finally delete the other four apps.
Scan any card: QR, an NFC tag, or a barcode in Code 128, EAN-13/8, UPC-A, Code 39, ITF, PDF417 or Aztec. The exact symbology is preserved, so it scans first try at the register.
Concerts, matches, flights and trains, with the date and time it starts, the venue and your seat. One booking can hold a separate code per passenger, each marked used on its own.
A passport, ID card, driving licence or residence permit, kept the way you’d keep a photocopy in a locked drawer, for you and for your family. Point the camera at the two lines of capitals and the numbers fill themselves in as they’re read; then hold the phone against the document and Brightcard reads the chip itself, over NFC, for the issuer’s own copy of the details and the photo. Link one to a trip and you’ll be warned when a passport expires too close to the date on the ticket. Masked behind your passkey, and like a credit card, never on your Watch and never in a widget.
The card details you need to hand, without digging out your wallet. Snap a photo and it fills itself in: number, holder, expiry, CVC. Masked until you look, on a card face you can read at a glance. These stay on your iPhone: never on your Watch, never in a widget, never on a server.
Store codes with an expiry date and face value, and get a local reminder before they lapse. Used vouchers archive themselves, out of your way.
Track balances and history for anything you own, plus expense reports with an optional budget, that read the amount, merchant, date and category straight off a receipt photo or PDF, on your device. Bills split with other people get a section of their own.
Keep notes in notebooks, with fields you name yourself, and mark a value secret so it stays hidden until you ask. A password can finally live next to the account it belongs to. Attach the photos, scans and PDFs that belong with a note, or speak it instead of typing; the words are transcribed on your iPhone.
Add someone by photographing their card. The name, company, title, phone, email and address are read on your device, and the photo is never saved. Keep a persona for each side of you (work, freelance, social) and share the right one by QR or vCard, or drop it straight into Contacts. No app required on the other end.
Show the cards, tickets and vouchers you choose on your wrist, synced from your iPhone, never the cloud.
Flag a card or see the ones near you, without a code ever leaving the lock.
Save cards from physical NFC tags: rare in a private, no-account wallet.
PACE and BAC, implemented in the app: no SDK, no network. Read-only: it cannot write to your document.
The camera reads a document’s printed numbers as you hold it: nothing to type, and no photo kept.
Send a card, group, or whole wallet to someone, encrypted, unlocked by a code you share out loud.
No password to leak. Access is a Secure Enclave passkey behind Face ID.
Numbers, secrets and scans are encrypted field by field, so a jailbreak or a pulled backup finds ciphertext: not your data.
Keep personal, work and family cards in separate wallets, each a tap away.
Pin what you use most, group the rest, and find any item in a couple of keystrokes.
Speak instead of typing, transcribed on your iPhone, never sent to a server. Pick the language you’re speaking, whatever language the app is in. Free.
Turn text up across the whole app: cards grow with it, so names stay readable instead of being cut off.
English, Türkçe, Nederlands, Español, Deutsch and Français, switch any time, no relaunch needed.
A trip, an onboarding, a club sign-up, someone always ends up collecting passports and details in a group chat, where they stay forever. Brightcard makes that a collection: you say what you need and until when, people answer from their own phone, and every answer arrives sealed to you alone. And on the other side of it: only someone you’ve saved as an organiser can ask you for anything at all.
Choose the fields, a name, a document number, an expiry, and whether each is required. Ask for the numbers rather than a photograph of the page when the numbers will do. Yes/no and pick-one questions come back countable instead of forty spellings of “yes”.
Every reply is encrypted to your device and stored sealed: not decrypted into a list you then have to guard. Nothing passes through a server, because there still isn’t one: a request travels as a file or a QR code, and the answer comes back the same way.
Because each answer has its own key, taking one back means destroying that key, so the copy in your store, and in any backup, becomes unreadable. Not a request you promise to honour. A thing that has happened.
State when the documents should be gone, and they go, the collection records that the promise was kept, so an empty collection reads as purged on the 14th rather than as one nobody answered.
A request only opens if it’s signed by someone already in your Contacts and marked by you as an organiser. A file from anyone else doesn’t get a logo, a name, or a “trust this sender?” prompt, there is no path from a stranger to your documents, because exchanging contacts is the introduction.
Being willing to hear from someone isn’t agreeing to whatever they thought to ask. Approval is per item and starts at no, you can cap what a given organiser is ever allowed to ask for, and turning them off stops them asking again.
What you see day to day is three of seven, Dana and Sam outstanding: not everybody’s passport in a list. Someone on Android or sending by email can be entered by hand, and it’s marked as exactly that: entered by you, not signed by them.
Collections is part of Brightcard Pro. Answering someone else’s request is free, being asked for your documents shouldn’t cost you anything.
Every splitting app wants everyone to sign up, and every one of them ends with a number you’re asked to take on trust. Brightcard does the opposite: the people you split with are names you write down. No invitations, no accounts, no notifications. And every figure comes with the working that produced it, so nobody has to take a number on trust.
Add people from the contacts already in your wallet, or just type a name. They’re never invited, notified or contacted, and they don’t need the app. The name is copied, not linked, so a dinner settled last year still says who was there after you’ve renamed or deleted the contact.
Bills arrive both ways. Charge three coffees to whoever had them, or record that Ava’s share was €21 because that’s what got worked out at the table. A line naming nobody (the service charge, the shared bottle) splits evenly across everyone present.
The totals are worked out from the lines, not typed at the end, so when the shares come to more than was actually spent, because a subtotal landed on top of lines that already covered it, the app says so instead of absorbing it. That’s how someone gets asked for money nobody spent.
What the other person sees is the whole working: the dates, the merchant, the currency, every line and the receipts themselves: not a total with your word behind it. And when you do hand it over, you pick what goes in first, because a report holds plenty that’s nobody else’s business.
Brightcard can’t make or request a payment, and never touches your bank. Marking someone as settled up changes a note on your device and nothing in the world. That is the honest description of what every ledger of this kind actually does.
When someone asks you for expenses through Collections, reply from the report you already have instead of typing the figures again. Every line starts unticked: only what you choose, and the receipts belonging to it, ever leaves the phone.
A split lives in your wallet like everything else, behind your passkey, and travels only in an encrypted backup or a file you send yourself. There’s no shared ledger in the cloud to go down, get breached, or start charging rent.
Splitting a bill is part of the free tier. It works inside the same expense reports Brightcard already keeps.
There’s no sign-up and no Brightcard backend. Not “we don’t send much”: the app contains no networking code at all. There is nothing to phone home to, and nothing to phone home with.
Many wallets quietly send your card details to a server to generate a signed pass. Brightcard draws every barcode and QR on your iPhone, so your cards never take a trip to the cloud.
Access is a Secure Enclave passkey behind Face ID / Touch ID. The key never leaves your device and isn’t known to us. No password to store or steal.
Backups and person-to-person transfers are AES-256 encrypted with a key only you hold. Share the file however you like; the code travels separately.
No analytics, no advertising identifier, no third-party trackers. The App Store privacy label says it plainly: nothing is collected.
Everything lives in the app on your device. Delete an item, or the app, and it’s gone. We hold nothing, so there’s nothing of yours for us to lose.
“On-device” is easy to say. It should be possible to check. Search Brightcard’s source for the ways an app sends data, and there is nothing to find:
URLSessionURLRequestdataTaskNWConnection0 results. The app cannot make a request, because the code to make one isn’t there.The exceptions, in full, because a claim with unstated exceptions is a slogan: iCloud Keychain syncs your encryption key between your own devices, the App Store handles a purchase, and a file goes wherever you choose to send it. All three are yours to turn off or never use, and all three are spelled out in the privacy policy.
A fair look at where a private, on-device wallet lands next to the typical loyalty app and the wallet already on your phone.
| Brightcard | Typical loyalty apps | Apple Wallet | |
|---|---|---|---|
| Add any card by scanning | ● | ● | —issuer passes only |
| Works with no account | ● | — | —Apple ID |
| Stays on your device (no cloud) | ● | — | ◐passes sync to iCloud |
| No ads, no tracking | ● | —often ad/offer-funded | ● |
| Credit card details, masked & on-device | ● | — | ◐for paying, not for reading |
| Tickets with date, time, venue & seat | ● | — | ◐issuer passes only |
| A code per passenger on one booking | ● | — | —one pass each |
| Vouchers & expiry reminders | ● | ◐ | — |
| Balances, expense reports & split bills | ● | — | — |
| On-device receipt scanning | ● | — | — |
| Dictate a note, transcribed on-device | ● | — | — |
| Notes & passwords in the same wallet | ● | — | — |
| Keep an identity document (passport, ID, licence) | ● | — | — |
| Read a passport or ID chip over NFC | ● | — | — |
| Add a contact by photographing their card | ● | — | — |
| Digital business cards & personas | ● | — | — |
| Apple Watch (cards, tickets & vouchers) | ● | ◐ | ● |
| Home Screen widget (no code shown) | ● | ◐shows the card | — |
| Read NFC tags | ● | ◐ | ● |
| Encrypted transfer to another person | ● | — | ◐live share |
| Collect documents from a group, sealed & time-limited | ● | — | — |
| Separate wallets (personal / work / family) | ● | — | — |
| Import Apple Wallet .pkpass | ● | — | ●native format |
| Price | $12.99 once | Free · ads | Free |
● yes · ◐ varies / partial · , no
No subscription, ever. Pay one time and Pro is yours forever, on all your devices. Free limits only ever block adding. Nothing you already saved is hidden or taken away.
Everything in Free, plus:
Yes. There’s no Brightcard account and no server; the app makes no network requests to us. Your cards, balances and receipts live in the app on your iPhone and leave only when you explicitly share or export something.
Because everything is on-device, keep an encrypted backup. Brightcard can export a backup file only your key can open, and your key is safely held in your iCloud Keychain so your own Apple devices can restore it.
Yes, a Secure Transfer packages a card, group or whole wallet into an encrypted file plus a short code you share separately. It works across different Apple Accounts, with no server in between.
A group chat keeps everything, forever, on everyone’s phone and on a server. A collection asks for named fields instead of “send me a photo of your passport”, and each answer comes back encrypted to you under its own key, so a participant can withdraw and the key is destroyed, which makes their copy unreadable wherever it sits, including in your backups. You also set the date the whole thing is purged, and the app carries it out. There is still no server: a request travels as a file or a QR code, and so does the answer.
No. A request is only opened if it was signed by someone already saved in your Contacts and marked by you as an organiser who may ask, and it’s checked against the key on that saved contact, not the one travelling in the file, so their name can’t be borrowed. Anything else simply doesn’t open; there’s no fingerprint to squint at and no “trust this sender?” button, because judging a stranger in the moment is the step worth removing rather than decorating. Even once someone’s approved, nothing is granted by default: you agree item by item, you can cap what they may ever ask for, and turning them off stops future requests. What it can’t do is reach what they already hold, and the app says so rather than implying otherwise.
Yes. Brightcard Pro is a single $12.99 purchase: no subscription. Owning it unlocks Pro on every device signed in to your Apple Account.
No. Reading a receipt or a business card uses Apple’s on-device Vision framework. The image and the text it extracts never leave your iPhone, and a business-card photo isn’t even kept: it is read, offered to you to check, and discarded with the form.
No. Speech is turned into text by Apple’s on-device recogniser as you speak, and the audio is discarded: nothing is recorded, kept or transmitted, and only the text you end up with is saved. The one piece of network activity is iOS fetching that language’s recognition model the first time you use it; after that dictation works with no connection at all. Brightcard deliberately does not use the older speech API that can send audio to Apple’s servers, so where a language can’t be transcribed locally the button is simply absent.
You can, and it’s a record rather than a means of payment: Brightcard can’t pay for anything, talks to no bank and has no payment integration, so adding a card here doesn’t register it anywhere. The number is stored on your device behind your passkey, masked to the last four digits by default, and uncovering the number, the CVC or a secret detail, or copying the number, asks for Face ID, Touch ID or your passcode first, one at a time. It all re-hides when you leave the card or put the app away. Payment cards are excluded from the Apple Watch and from widgets, not switched off by default, excluded, because a number you can read over someone’s shoulder defeats the masking. The CVC field is optional: leave it blank and nothing is stored. If the card is contactless you can tap it to the phone to copy the number and expiry across instead of typing them, read-only, no bank contacted, nothing authorised, and the CVC can’t be obtained that way by anyone, because it isn’t on the chip in readable form. And as with everything else here, there’s no server to send it to.
Not the parts worth stealing. This is worth being precise about, because a lock screen and encryption are different promises. A passkey gate decides what an app draws, it stops a person holding your phone, but it doesn’t stop code. iOS unlocks an app’s container at first unlock and leaves it unlocked, so anything able to read that container, malware with a sandbox escape, a jailbreak, a backup pulled through a trusted computer, could read whatever sat there as ordinary text.
So the sensitive fields aren’t stored as text. Card numbers, security codes, PINs, note secrets, document scans and receipts are individually encrypted (AES-GCM), and the key lives in the keychain marked so it can only be read on this device, while it is unlocked, never in a backup, never on another phone. Plaintext exists only after you’ve actually authenticated. Pull the database off a jailbroken phone and what you get is ciphertext.
The limits, stated plainly: this protects the data at rest, not a device already compromised while you’re using it: no app can defend against that, and any that claims to is overselling. Names, colours and dates stay readable so lists can draw before anything is revealed. And we don’t detect or block jailbreaks; that’s a check that’s easily defeated. We simply assume the container can be read, and make sure that isn’t enough.
No, and that’s the whole design. The people in a split are names you write down, picked from the contacts you keep in Brightcard or typed in. Nobody is invited, notified or signed up, they don’t need the app, and no request goes anywhere. No money moves either: Brightcard can’t make or ask for a payment, so marking someone as settled up changes a note on your device and nothing in the world. What it does do is keep the lines the split was worked out from, so the person being asked for money can check the sum rather than trust a figure, and when the shares and the actual spend disagree, it says so instead of quietly absorbing the difference. Hand it over as a PDF with the receipts attached, and you pick which expenses go in before it leaves.
Nothing leaves your phone until you decide it does, there is no sync, no upload and no server to sync to, so an expense sits on the device until you personally act on it. Exporting is that act, and it’s deliberate every time: the app never exports on a schedule, in the background, or because a report reached some size. When you do ask for a PDF, it’s drawn on the device from the records you already hold and handed straight to the iOS share sheet, so where it goes is your choice, Mail, Messages, AirDrop, Files. It never passes through us, and we couldn’t read it if it did.
The export asks first which expenses to include, because a report usually holds the pharmacy and last month’s rent alongside the trip someone actually asked about; whether the page says who has settled up is a separate choice, made at the moment of sharing rather than stored on the record. Answering an expense request through Collections works the same way but stricter, every line starts unticked, and only what you tick, with the receipts belonging to it, is sent.
The honest part: a file you’ve sent is someone else’s copy, and no app can take it back. Everything else here can be undone, an item deleted, a reply shredded, but a PDF that has left cannot. That’s exactly why the app asks before it goes rather than after, and why the safe default is to send the least that answers the question.
It’s a place to keep notes and the odd secret alongside them, a Wi-Fi password, a door code, a licence key: not a managed password service. Secrets are stored on your device behind your passkey, with the same protection as your card numbers, and masked until you tap to reveal them. There’s no account, no sync service and no recovery: if you lose the device and your backup, the contents are gone.
Yes, Tickets are their own section, because a ticket isn’t a voucher: it happens at a date and time, at a venue, in a seat. One booking can hold a code per passenger or leg, each marked used on its own, and the whole ticket archives only once every code has been used.
Free covers 12 items across 2 wallets. Reaching the cap only stops you adding a new item, everything already in your wallet stays visible and fully usable. The same is true if you ever restore a backup that’s larger than the free tier.
Bring all of it into one private place, and keep it there.